[ 
https://issues.apache.org/jira/browse/CXF-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123846#comment-18123846
 ] 

Fabio Burzigotti commented on CXF-9253:
---------------------------------------

Hi [~ffang] - and what about 4.1.9 release notes? I don't see anything 
mentioning WSS4J as an hard requirement 
[here|[https://github.com/apache/cxf/commit/5671d90da0efc5424a2284c859f9d1d735f9e30a].]
 WDYT?

> 4.1.9 breaks WSS4J WSHandler:checkSignatureConfirmation unless 4.0.2 is used
> ----------------------------------------------------------------------------
>
>                 Key: CXF-9253
>                 URL: https://issues.apache.org/jira/browse/CXF-9253
>             Project: CXF
>          Issue Type: Bug
>          Components: Core
>    Affects Versions: 4.1.9
>            Reporter: Fabio Burzigotti
>            Priority: Major
>             Fix For: 4.1.9
>
>
> WSS4J 4.0.2 introduced two changes related to signature values:
> 1. 
> [https://github.com/apache/ws-wss4j/commit/2d4a0e7da15be3e97d83b20b739886cea724b5b4]
>  - change in WSHandler, to store strings instead of integers for signature 
> values.
> 2. 
> [https://github.com/apache/ws-wss4j/commit/347cead366e516710281d1c2a7b58a1513c28ec5]
>  - change in WSHandler, to support producers that still use integer signature 
> values. 
> Apache CXF 4.1.9 behavior changed from 4.1.8, on order to align with (1), see 
> [CXF 4.1.9 PR #3529|https://github.com/apache/cxf/pull/3529/changes] 
> unconditionally changed the _sendSignatureValues_ format. Accordingly WSS4J 
> [was bumped to 4.0.2|https://github.com/apache/cxf/pull/3527]
> The latter represents a hard requirement to depend on such version, but it is 
> shipped via a micro release, that would usually be integrated with no further 
> changes expected.
> As a confirmation, we've experimented with JBossWS CXF tests and one failure 
> is caused by the Apache CXF version bump, unless WSS4J is bumped too (4.0.1 
> -> 4.0.2), since the producer doesn't take the 4.0.1 use case (int signature 
> values) into account.
> It seems reasonable to introduce the new behavior (storing strings) in 4.1.9, 
> but maybe - given it's a patch release - it could preserve the legacy 
> behavior as a default, externalize opt-in via configuration property, to 
> eventually deprecate and then replace in a minor/major update.
> An alternative could be to have it documented that users upgrading to Apache 
> CXF 4.1.9 must also update WSS4J to 4.0.2.
> WDYT?



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to