Hello list,
I have setting up a Axis2-Webservice on Tomcat, which support
ws-secureconversation(rampart) and ws-reliablemessaging (sandesha2).
I changed in the following sections of the sandesha2 modul.xml to
(http://wso2.org/library/1027)
<sandesha2:SecurityManager>
org.apache.sandesha2.security.rampart.RampartBasedSecurityManager
</sandesha2:SecurityManager>
I use the policy from the rampart-sample04.
When I run the Client the SOAP response look like below. I have no idea
whats going wrong.
thanks,
Dominik
<?xml version='1.0' encoding='UTF-8'?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/">
<soapenv:Header xmlns:wsa="http://www.w3.org/2005/08/addressing">
<wsse:Security
xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"
soapenv:mustUnderstand="1">
<wsu:Timestamp
xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
wsu:Id="Timestamp-55">
<wsu:Created>2011-09-01T09:59:10.937Z</wsu:Created>
<wsu:Expires>2011-09-01T10:04:10.937Z</wsu:Expires>
</wsu:Timestamp>
<wsc:SecurityContextToken
xmlns:wsc="http://schemas.xmlsoap.org/ws/2005/02/sc"
xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
wsu:Id="sctId-A2DAA77225B598D7E9131487115060920">
<wsc:Identifier>A2DAA77225B598D7E9131487115060919</wsc:Identifier>
</wsc:SecurityContextToken>
<wsc:DerivedKeyToken xmlns:wsc="http://schemas.xmlsoap.org/ws/2005/02/sc"
xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
wsu:Id="derivedKeyId-58">
<wsse:SecurityTokenReference>
<wsse:Reference URI="#sctId-A2DAA77225B598D7E9131487115060920"
ValueType="http://schemas.xmlsoap.org/ws/2005/02/sc/sct" />
</wsse:SecurityTokenReference>
<wsc:Offset>0</wsc:Offset>
<wsc:Length>16</wsc:Length>
<wsc:Nonce>YZzNZ169Vp16iz4XcbiKaA==</wsc:Nonce>
</wsc:DerivedKeyToken>
<xenc:ReferenceList xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<xenc:DataReference URI="#EncDataId-59" />
<xenc:DataReference URI="#EncDataId-60" />
</xenc:ReferenceList>
<wsc:DerivedKeyToken xmlns:wsc="http://schemas.xmlsoap.org/ws/2005/02/sc"
xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
wsu:Id="derivedKeyId-56">
<wsse:SecurityTokenReference>
<wsse:Reference URI="A2DAA77225B598D7E9131487115060919"
ValueType="http://schemas.xmlsoap.org/ws/2005/02/sc/sct" />
</wsse:SecurityTokenReference>
<wsc:Offset>0</wsc:Offset>
<wsc:Length>16</wsc:Length>
<wsc:Nonce>84jaxpUEYAC0e38VJbMYvw==</wsc:Nonce>
</wsc:DerivedKeyToken>
<xenc:EncryptedData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
Id="EncDataId-60"
Type="http://www.w3.org/2001/04/xmlenc#Element">
<xenc:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" />
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<wsse:SecurityTokenReference>
<wsse:Reference URI="#derivedKeyId-58" />
</wsse:SecurityTokenReference>
</ds:KeyInfo>
<xenc:CipherData>
<xenc:CipherValue>PNHW5HQP5fuQULZFSXHhY7RKkinEtyE1ua66iwGcCYbkmLKRYg2Bg78m6VVwhbkT91PZpzgCDn/m
zdnWgCMbgT7uqGwTcaB2HpwFJTucHC6U2leq5M/ndOIOAntPda5vjxgm6sxZiDFFN0s4u9xLw6m+
RKq+EAujt7FwoC+fhUzoL02Fn9L8OMsBVstXvsrb2KaYEveBpDqsfGQysJn4XkadVJFqKSfc8ctv
5slePIl05Sf+/1yXCMgfbUZDyXfTPhrK0y9ETs5yi9DEgNQnV7OsRc8fR9B5sw+XwrsXzN+3fBkL
qy/f2W/l63SjCkzfzYmykLwK2/QwsxjO10pq1ir3GJPBNzKmTbWIzuia86fOp/KS/gNTv+ig/8kG
hsxP+klPI+ovMZJLtMIGS3SrN61vhKXRogJESXMH0hobWwxpiWVOLYVfWoH9uvH8jZbIfaUfNv0W
q3w+mXN6x+UAuf9d0cSOCbuhj/mUPI3Xp8gZgMNXZKIuwdQ2NeEy7yhw47UMG0k/J7iwcOk4AzhK
AwWyeqPzWApoRDdSObL4Vwc0NLOnP7sGJJDC7T//ELFob0FlWdh8N3INgjA8F/1R4HsvlNUqVEu+
R1WKdIthF7NL47Ymsp6HcbdqeVYnwMNnMYA5195dUhtSWBgHHtDLnqJ0t6YjYydIN2IEPQz7iYQZ
qWOWH8VZslWUcoN6/pikvVBb+neSG9oHE9aU1wdHax7X+AvpGAh3PWjIEWwfdlKabl5fiWOX4zQr
GSC3LWrnET9ZXqNqTAbGp58690l9RcaZVFE5BUB9WK6lFXdA2/PJndIsid1ZZe8ktxf2BY6KgJVS
9Zpizb3+tE/62cnnFrV/kfMkfjZNoiExAWHVwwnYd1YSSCfbbkTBvjxyvnN43lMui9ctRpm8m40q
IlTCupfopk2V3BGdvEj4C/2jhjg9F69TUddog4X18hZSwOPrVlNe+iseh52aNibpEAG8cRmbx781
HdeBzQIn0KwugNr0IsCetlPkwt2S3+dTP7e5JfrS61hzbw5NBjJctu2xjB30ZI/kU0V/GtK3RN7q
Ywcz37iMcuEx/y5wJJ6H4RtHOP3cngKvTa4vA0tkrSBMELTqDXC3X/iRzxge9AS5nufS0m466Bxf
+RrceHX3SeXWQ+j2RUPDxHV+swfsDUz6TlAg04y2daDrEC/kZziunoPoJZe7dXUlyS/o9Ot39s98
BMG2C2+O/7parC+xB5sq8D1lTSR2AZRWw3yDwgJkTq213J3eneLnFOaBjBNZ/3T4gQMvrdLCbqhx
8j2PXI/hGoZGKT5JhDoOcJ4Axqf3ompiL2yvaUuMuK1N9nHXMneq8gUjLoOTHYIP0AGb35SxNZ0M
LfAIcv6zQdFTYVMj2x6aGkSDWbXa9nnxXL6j/OuJroxlLiNCoTUJtVe7k1Gy4CkNmZGukUKUTCQz
tSLewdlCsZen2amNqAUnOXaKLmQEqwIpBntV9sgnUKKrKiiaRvLPke83FUkO05woUIeQZKaWxG19
ccpXZbM9GuPAqJsPoHBdKJdGLypIP20Fm4w5CQ==
</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedData>
</wsse:Security>
<wsrm:SequenceFault xmlns:wsrm="http://schemas.xmlsoap.org/ws/2005/02/rm">
<wsrm:FaultCode>wsrm:CreateSequenceRefused</wsrm:FaultCode>
<wsrm:Detail>org.apache.sandesha2.SandeshaException: Proof of possession
not verified.
at
org.apache.sandesha2.security.rampart.RampartBasedSecurityManager.checkProofOfPossession(RampartBasedSecurityManager.java:164)
at
org.apache.sandesha2.msgprocessors.CreateSeqMsgProcessor.processInMessage(CreateSeqMsgProcessor.java:108)
at
org.apache.sandesha2.msgreceivers.RMMessageReceiver.invokeBusinessLogic(RMMessageReceiver.java:94)
at
org.apache.axis2.receivers.AbstractMessageReceiver.receive(AbstractMessageReceiver.java:110)
at
org.apache.axis2.engine.AxisEngine.receive(AxisEngine.java:181)
at
org.apache.axis2.transport.http.HTTPTransportUtils.processHTTPPostRequest(HTTPTransportUtils.java:172)
at
org.apache.axis2.transport.http.AxisServlet.doPost(AxisServlet.java:146)
at
javax.servlet.http.HttpServlet.service(HttpServlet.java:637)
at
javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233)
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
at
org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at
org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:298)
at
org.apache.coyote.http11.Http11AprProcessor.process(Http11AprProcessor.java:864)
at
org.apache.coyote.http11.Http11AprProtocol$Http11ConnectionHandler.process(Http11AprProtocol.java:579)
at
org.apache.tomcat.util.net.AprEndpoint$Worker.run(AprEndpoint.java:1665)
at java.lang.Thread.run(Thread.java:662)
</wsrm:Detail>
</wsrm:SequenceFault>
<wsa:To>http://192.168.100.103:8080/axis2/services/anonService2/
</wsa:To>
<wsa:ReplyTo>
<wsa:Address>http://www.w3.org/2005/08/addressing/none</wsa:Address>
</wsa:ReplyTo>
<wsa:MessageID>urn:uuid:09f64552-5746-413b-ad0d-ffddd526a39e
</wsa:MessageID>
<wsa:Action>http://www.w3.org/2005/08/addressing/fault</wsa:Action>
<wsa:RelatesTo>urn:uuid:492EB9C49C637AC9831314871081730
</wsa:RelatesTo>
</soapenv:Header>
<soapenv:Body
xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
wsu:Id="Id-5313520">
<xenc:EncryptedData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
Id="EncDataId-59"
Type="http://www.w3.org/2001/04/xmlenc#Content">
<xenc:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" />
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<wsse:SecurityTokenReference
xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
<wsse:Reference URI="#derivedKeyId-58" />
</wsse:SecurityTokenReference>
</ds:KeyInfo>
<xenc:CipherData>
<xenc:CipherValue>Db3ASBSqmfUAMSlyI/0BKalWw2iC6NkbaIeoN8edjc4c5a8JgpEHobJayGP3i7FNDrWGU1x4eA/r
j0/y8Uap6cL+mEsJrmlpRwhNgIo+slOAEGzwSh4iaVxkx1LA2I6buSScp9Ivlya3CZdQdOdr8Wsl
HBFetOz5panbsicFnoYJRlZ5NJQuQ1dJj5cVtZ4gIKekdKZIeFnl3s0bEFROjeWw5jSQ0jqm+P6G
nw4HG0hjCY/dMpDsOvedV1Y/6NnJVbDsMa5cBwlVP5By2gKlIQUnxZZLyuoaF+z6QeDfmnbWqj52
1s9+LSJWDc9qyZWvWVD42Z6C2mf6bV93aYaKiHB3B5rLDUHhX/n4b+Au8YTkc9wu5o7Tueco4Q0V
f9oqkdZuhdTeP7Y72HQRvnPmrdZ0vrJyZRP+btLt2ANytd8FovcLMYFOFT7Kug30zYhjfyMFnLQU
fOUBJuiOHsY63zNUAusSlanFqGEUPtWpHJzsDuoO250y7XUzsdX6daMrRpXbUNG5f3ktHNHznn9W
KZIqffSa+rUjYZtGTDY/UXYX0rDj73aPBUfve1x77P2EaCcjHn4TVnnkAWQGA92ZYu4lCPvFgvXi
YrXBKs1CLSYaJ8S2i47L/SC9u6TJHPzEhHzygGjBghCde0ePHChLHcAK9HACIY38dSiopP6ViBjr
NCs8UoHEIzslaoso39i5kHVi41P+VbxA+S9YxRZlUB8Na5Ytr0zijP87graHFvjmtojATfi6lFdw
+2zgHSNG6oJVoeSfLYP4pSOw+XblUKeezb69yGyfirw3ijDeq+Cn6/Q9iYTRUTDv3IfnVr7DWvAT
Y4MdUj7CKvztNRu6cUBrOYhL/OTUpWcf92Ttg/rIiGi20CiAgoUvGyLoJ7C7pDqEAaKXx8JzE+tN
Ee9FgWYwiF43P3sCX6wbYM3E312pQRaAS2qT5DbM7qB9eJ2+ZYpLuz26FiUtc89McXeuJR2LUnDK
D0fbjIh0uL4/4dQw9xDenuacScD5Pt6i/52H9TSpQ0Xxca1+93iLhyEwKLxJIBUQgM8Hpp5RdTi6
ezMGn9uVrqw3Nbjb021bw9q4aggfBXN0hvVtcQoBI92v+LSwrqqpKEWwM0TPybxSgMxAC9kUheNW
+0O+2YaGx5QYZCbf3qGpuDtqWF4RvkGfGHoY2wgyNHWZqd56Lj9vEhh8QHLjfPO+BBsOmUF73WHT
wtBEuOK6NCkugysTF5qHrn6sKc6icX2JkTJnOVkdOBb16fF/ErNG0UxJ7G4WZ0qMsPfESi+S8KSb
G3Mq22/FFK3clCX7PlPydPQXgfw+jRe2PYVfu2XjWoJK8A8c3+y/790qM7ygU241NM+nsmr3SqKq
hXbKzKy2xasuUAleV1ZAHlP90oSOPHzWbPukJLvnr5UfhbOb4xTfZ46XrzPPsftbBoAWLWDOqCm4
Aa1R+ykByiluctaAJC5yCzmgRjR61S7QJmZjJKFNRaRxu8ddxtAvCvyuGrJG1d40fPTekNW/b3Ju
buycJ6imaNT8vat9p/dqPmMupI7u4pyJC/7DX8k1Q1jqnTOArx58Zka6T1NLeUQmTfRtcul+LnJ1
KlqLAy7n9gPKjH4gCSTMM0GBv9OCcIT4m0JDTiTte1//5xFd2RRMvSIUr/7rXNUXEK21z+3fnGN9
rqcaW5Fhu56J27By/oQgvtFDBiPkHMCwg+/mx66MiZy07lsncWqV1QDf/GbynTtU6oqI5feFTSvn
xoNm2Q7SaqDXsOaS6v1iFIGULJB3mX+LsMgUwaFpmXmYk2WTdSG0RwgBLn9FgMSG6Uu6vRJm5r0h
91gRSEEwdrwYNq6hU2fDYcAaoQV5t8P+CDuw98uSYjHGILW3UAjw6i5/CoMiU6APcwQn5D3N9xkQ
4X6Z3qKLk6+ePnCDzD0HdTT9PFhZhCR28yZAmimeiZWTqMCAk13S75gffyn/KIulFdtThbFpa01u
xaFjuW10LenGI3zhsbv3RLqjDwiELGCkf5aKx0BAcI3QUyN7Q2SObgQaWNSh16LT8MaAvb04Bsc9
Wa6NVwbvX2sbP1eDBwE27VzgpKfTy+9x86Uazp+ejwwT9Wsx6CGnSErAalm5XvYANWhMX5T5I1gn
U8qD+jQ8Desjb1ueckvTDapTIdXM4aGt5vB4ML9ADbbQOx+kfpRj/CYRslwTuQ4PS8JoK6naaMAW
4LXPj6A8us3tuCeUIn43q2CeRFwSuJPAojvBtSUnm84XcdR7n2x5pqltI8UMjSlfoD/swX40XL8+
Hq6GNBPk/50H2jrEwfbK+2wI5s+1GeijlGueAJczgNov8rsVlbrrGv8KN7a/i3IttqDvWF6dehux
ZKESS4oIiCZjZ6+WxnIyXw0e3drRJphS0QIfF7dflNpbVjhRtV9VOA8hOt7WNPjD2MQqZut+UkAU
iLCKRodRYf6jj6IDZpwcrE4XeZj44zQu99X1oE1c1WaJ0jk6aLTBd2aNrY966TpPVANy6b6VEwGo
mk6/UJ82kv54CUBn9xgp0/zDzFvtjMPyfKsj65WKiQ6gNceUzG2AsereVX35AifuFo6koqutHCWO
80XQl6NV9LJPUjIbcOEu4FjnSOUCinw8wykzgAsGel0yFLpbCblB3OqfcherJd7mtfbAk9LnrYTc
vdDffig05wycTYb+LBPZGb/fBng7ZqE++0nNjCEicHBZgARyoXmkUSTV8ooKqXU4zghMqQL1+yoW
o9vLxR2hbgtJS9GmTEXEmxfvjob7tgYQcUdq/8LR+cKZ2AXAMYoM0q74oyoVcMgdxBWq1m1dfi9v
MvSBRcCXZi2jzmNqgnHdNJ4H6VseRQTnSjYH0SM2hiQGEZgRR0PsfzKKlpbV/Cc+9so3pIReJzUE
oiUJ3prhDdz2hR9BSHePRuXbd6EyK50GQbe5z1VNGxg86ijLySS6wapuhDqD187jUryvZS0xdjGr
uJywQ0S9NTxRIgYt1vghYWxA2jhwvnWYwCeqgeQk40rWLnBLd36wnWes27dntOX7tJddQ5PAdfaU
ekSOKqQBe2kRRbt2FhK8h6EiEpMwOu3z
</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedData>
</soapenv:Body>
</soapenv:Envelope>
---------------------------------------------------------------------
To unsubscribe, e-mail: java-user-unsubscr...@axis.apache.org
For additional commands, e-mail: java-user-h...@axis.apache.org