[
https://issues.apache.org/jira/browse/CXF-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Freeman Yue Fang updated CXF-9253:
----------------------------------
Issue Type: Task (was: Bug)
> 4.1.9 breaks WSS4J WSHandler:checkSignatureConfirmation unless 4.0.2 is used
> ----------------------------------------------------------------------------
>
> Key: CXF-9253
> URL: https://issues.apache.org/jira/browse/CXF-9253
> Project: CXF
> Issue Type: Task
> Components: Documentation
> Affects Versions: 4.1.9
> Reporter: Fabio Burzigotti
> Priority: Major
> Fix For: 4.1.9
>
>
> WSS4J 4.0.2 introduced two changes related to signature values:
> 1.
> [https://github.com/apache/ws-wss4j/commit/2d4a0e7da15be3e97d83b20b739886cea724b5b4]
> - change in WSHandler, to store strings instead of integers for signature
> values.
> 2.
> [https://github.com/apache/ws-wss4j/commit/347cead366e516710281d1c2a7b58a1513c28ec5]
> - change in WSHandler, to support producers that still use integer signature
> values.
> Apache CXF 4.1.9 behavior changed from 4.1.8, on order to align with (1), see
> [CXF 4.1.9 PR #3529|https://github.com/apache/cxf/pull/3529/changes]
> unconditionally changed the _sendSignatureValues_ format. Accordingly WSS4J
> [was bumped to 4.0.2|https://github.com/apache/cxf/pull/3527]
> The latter represents a hard requirement to depend on such version, but it is
> shipped via a micro release, that would usually be integrated with no further
> changes expected.
> As a confirmation, we've experimented with JBossWS CXF tests and one failure
> is caused by the Apache CXF version bump, unless WSS4J is bumped too (4.0.1
> -> 4.0.2), since the producer doesn't take the 4.0.1 use case (int signature
> values) into account.
> It seems reasonable to introduce the new behavior (storing strings) in 4.1.9,
> but maybe - given it's a patch release - it could preserve the legacy
> behavior as a default, externalize opt-in via configuration property, to
> eventually deprecate and then replace in a minor/major update.
> An alternative could be to have it documented that users upgrading to Apache
> CXF 4.1.9 must also update WSS4J to 4.0.2.
> WDYT?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)