Hi, The WS-Trust 1.3 specification defines the ValidateTarget element that may contain the token being validated.
In rampart this is not possible, it must be included in the header and referenced by validatetarget. I implemented the TokenValidator interface, for having a custom validation for my custom token (saml2). How can avoid the Rahasdata behavior (line 193)? Otherwise, how can I create a policy that has the token inclusion? Thanks, Massimiliano ---------------------------------------------------------------- This message was sent using IMP, the Internet Messaging Program.