axis-java-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Andreas Veithen (JIRA)" <>
Subject [jira] [Commented] (RAMPART-415) Upgrade Rampart to use latest wss4j 1.6.16
Date Tue, 15 Jul 2014 19:23:05 GMT


Andreas Veithen commented on RAMPART-415:

Applied the patch that updates Bouncy Castle.

Regarding the test failure in 1.6: if I understand this correctly, the issue also exists in
trunk, but it is not detected by the tests (i.e. we are in the situation I feared in

> Upgrade Rampart to use latest wss4j 1.6.16
> ------------------------------------------
>                 Key: RAMPART-415
>                 URL:
>             Project: Rampart
>          Issue Type: Improvement
>    Affects Versions: 1.6.2
>            Reporter: Detelin Yordanov
>            Assignee: Andreas Veithen
>             Fix For: 1.7.0, 1.6.3
>         Attachments: rampart16_wss4j.patch, rampart_bcprov.patch, rampart_wss4j.patch
> Rampart uses an outdated wss4j 1.6.4 version, while wss4j 1.6.16 was released just recently.
I think it is important for Rampart to use latest stable wss4j, additionally my team is willing
to contribute some Rampart extensions which require wss4j 1.6.16. I tested Rampart trunk with
wss4j 1.6.16 and noticed two failing tests:
> - org.apache.rampart.RampartTest.testWithPolicy, scenario 7
> - org.apache.rahas.impl.util.CommonUtilTest.testGetDecryptedBytes
> The first issue is caused by a change in wss4j to add an "id" to the "Reference List"
security processing results even when the value is an empty literal. I discussed the issue
on wss4j mailing list and a fix for this will be available in next wss4j 1.6.17 version, see:
> Meanwhile, I proposed a temporary fix in Rampart that skips results with empty Ids (attached).
> The second issue is triggered by a change in xmlsec 1.5.2 which adds cloning of KeyInfo
elements, however the root cause seems to be a change is how Rahas TestUtil constructs a SOAP
> [Avoid direct references to Axiom implementation classes|]
> I have raised this issue on Axis2 dev list:
> I will update this issue once a solution is found. I can help with further issues if
such are found. Please note that all Rampart tests pass successfully with wss4j 1.6.16 after
applying the provided Rampart wss4j workaround and reverting the Rampart Axiom-related changes
done in revision [1299913|].

This message was sent by Atlassian JIRA

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message