Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 5E98E200CC6 for ; Tue, 18 Jul 2017 15:28:00 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 5CE4A165261; Tue, 18 Jul 2017 13:28:00 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 54FFB16523E for ; Tue, 18 Jul 2017 15:27:59 +0200 (CEST) Received: (qmail 69806 invoked by uid 500); 18 Jul 2017 13:27:58 -0000 Mailing-List: contact dev-help@cxf.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@cxf.apache.org Delivered-To: mailing list dev@cxf.apache.org Received: (qmail 69786 invoked by uid 99); 18 Jul 2017 13:27:57 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 18 Jul 2017 13:27:57 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id 68AF9180313; Tue, 18 Jul 2017 13:27:57 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: -0.302 X-Spam-Level: X-Spam-Status: No, score=-0.302 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=2, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=disabled Authentication-Results: spamd3-us-west.apache.org (amavisd-new); dkim=pass (1024-bit key) header.d=vustaff.onmicrosoft.com Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id NHJn2T4zb4rQ; Tue, 18 Jul 2017 13:27:53 +0000 (UTC) Received: from lime.its.vu.edu.au (lime.its.vu.edu.au [140.159.23.9]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTP id 962055F2EC; Tue, 18 Jul 2017 13:27:52 +0000 (UTC) Received: from c.pxy.vu.edu.au (bip1.vu.edu.au [140.159.22.250]) by lime.its.vu.edu.au (8.14.4/8.14.4) with ESMTP id v6IDRiXh022274; Tue, 18 Jul 2017 23:27:44 +1000 Received: from VUEXCASHT2.ad.vu.edu.au ([10.60.21.2]) by c.pxy.vu.edu.au (8.14.4/8.14.4) with ESMTP id v6IDRiAN005235; Tue, 18 Jul 2017 23:27:44 +1000 Received: from AUS01-ME1-obe.outbound.protection.outlook.com (203.13.203.58) by ad.vu.edu.au (10.60.21.2) with Microsoft SMTP Server (TLS) id 14.3.351.0; Tue, 18 Jul 2017 23:27:43 +1000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vustaff.onmicrosoft.com; s=selector1-vu-edu-au; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=QOBrVGpYOshu5UgQQhhYbefUCoG1t3Pj46l/gR15Zf4=; b=W6YSEWPcxWNA3f1a/zM+jDsLDOg7cVdBb2S08Sk/9flEUtZVd6AZ5zy5L2JsMjVJoHzw3oT4zVnE4Qlp679tUJxNIW2Py9CPiYYuJoq1qRtIQooOquGzvf6+d+0Jjq+0coiKx1XoYrys3V547VfJmSZob+ob38thQHoSOkV6EWc= Received: from ME1PR01MB1058.ausprd01.prod.outlook.com (10.169.167.9) by ME1PR01MB1060.ausprd01.prod.outlook.com (10.169.167.11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Tue, 18 Jul 2017 13:27:43 +0000 Received: from ME1PR01MB1058.ausprd01.prod.outlook.com ([10.169.167.9]) by ME1PR01MB1058.ausprd01.prod.outlook.com ([10.169.167.9]) with mapi id 15.01.1261.024; Tue, 18 Jul 2017 13:27:42 +0000 From: Siva Kulendrasingam To: Daniel Kulp , "dev@cxf.apache.org" , "coheigea@apache.org" Subject: Re: CXF - WS Security Issue Thread-Topic: CXF - WS Security Issue Thread-Index: AdL+jiDR0/7kMRbuRkWxD6aZDE0GuwABEzywABIY0IAAISib8AAR1bSAAAh+OwAAAC7o2w== Date: Tue, 18 Jul 2017 13:27:42 +0000 Message-ID: References: , In-Reply-To: Accept-Language: en-AU, en-US Content-Language: en-AU X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: apache.org; dkim=none (message not signed) header.d=none;apache.org; dmarc=none action=none header.from=vu.edu.au; x-originating-ip: [49.199.125.95] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;ME1PR01MB1060;20:vd3sF8BRWAWAFBHooqedZXeJSLOj8PVqbd4B/HbqxGtpHJ2j8ebMHC+ih9f5vEatf659tOHUD2OUB3AavktAgCSZAE2RRn4k+/xPCFXUU7eb54TCJ3iDYwM8tV09i9Ft/SaIh8PkgMQsCMsMGrgAxbMvXEpcJQP9lZYGpEEtNNw= x-ms-office365-filtering-correlation-id: 7cd3e861-34e5-4fa7-7604-08d4cde0c519 x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095);SRVR:ME1PR01MB1060; x-ms-traffictypediagnostic: ME1PR01MB1060: x-exchange-antispam-report-test: UriScan:(125970659754112)(158342451672863)(278927263835790)(133145235818549)(26388249023172)(236129657087228)(192374486261705)(48057245064654)(92977632026198)(167848164394848); x-microsoft-antispam-prvs: x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(2017060910075)(5005006)(8121501046)(3002001)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(6041248)(20161123558100)(20161123560025)(201703131423075)(201702281529075)(201702281528075)(201703061421075)(201703061406153)(20161123564025)(20161123562025)(20161123555025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095);SRVR:ME1PR01MB1060;BCL:0;PCL:0;RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);SRVR:ME1PR01MB1060; x-forefront-prvs: 037291602B x-forefront-antispam-report: SFV:NSPM;SFS:(10009020)(39410400002)(39850400002)(39840400002)(39400400002)(39450400003)(279900001)(15404003)(24454002)(13464003)(377454003)(50986999)(76176999)(54356999)(7696004)(2201001)(2906002)(2420400007)(15380165006)(189998001)(7110500001)(229853002)(88552002)(3660700001)(3280700002)(93886004)(74316002)(42882006)(2950100002)(77096006)(5660300001)(15650500001)(606006)(6436002)(33656002)(19625305001)(2900100001)(8676002)(9686003)(236005)(54896002)(6306002)(14454004)(55016002)(72206003)(99286003)(478600001)(16297215004)(74482002)(6506006)(86362001)(25786009)(8936002)(7736002)(81166006)(966005)(53546010)(53376002)(38730400002)(551544002)(5890100001)(53386004)(2501003)(66066001)(3846002)(53936002)(6116002)(587094005)(6246003)(102836003)(18265965002);DIR:OUT;SFP:1101;SCL:1;SRVR:ME1PR01MB1060;H:ME1PR01MB1058.ausprd01.prod.outlook.com;FPR:;SPF:None;MLV:sfv;LANG:en; spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: multipart/alternative; boundary="_000_ME1PR01MB10587A305AA856D0029A0B91ABA10ME1PR01MB1058ausp_" MIME-Version: 1.0 X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Jul 2017 13:27:42.6769 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: d51ba343-9258-4ea6-9907-426d8c84ec12 X-MS-Exchange-Transport-CrossTenantHeadersStamped: ME1PR01MB1060 X-OriginatorOrg: vu.edu.au X-Scanned-By: MIMEDefang 2.75 on 140.159.23.9 X-Scanned-By: MIMEDefang 2.78 on 140.159.23.3 archived-at: Tue, 18 Jul 2017 13:28:00 -0000 --_000_ME1PR01MB10587A305AA856D0029A0B91ABA10ME1PR01MB1058ausp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Thanks Dan. Will try the suggestions and update you. Siva ________________________________ From: Daniel Kulp Sent: Tuesday, 18 July 2017 11:21:28 PM To: dev@cxf.apache.org; coheigea@apache.org Cc: Siva Kulendrasingam Subject: Re: CXF - WS Security Issue Actually, you don=92t need to write anything as we already have this in CXF= . If you add: To your spring config, it should be automatically ignored. Dan > On Jul 18, 2017, at 5:18 AM, Colm O hEigeartaigh wr= ote: > > Yeah, this is not a standard policy, and so CXF doesn't support it out of > the box. You can either remove the policy jar from the classpath, as you'= ve > already noted, or else write a CXF interceptor to "assert" (and so ignore= ) > the policy. > > Colm. > > On Tue, Jul 18, 2017 at 2:04 AM, Siva Kulendrasingam < > Siva.Kulendrasingam@vu.edu.au> wrote: > >> Thanks Colm. >> >> From the WSDL, I could see the following >> >> >> >> > "> >> >> > open.org/wss/2004/01/oasis-200401-wss-username-token- >> profile-1.0#UsernameToken"> >> > org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText= " >> /> >> >> >> >> >> >> I attached the WSDL for your reference. >> >> Stack Trace: >> Jul 18, 2017 10:53:17 AM org.apache.cxf.wsdl.service.factory.ReflectionS= erviceFactoryBean >> buildServiceFromWSDL >> INFO: Creating Service {http://au/edu/vu/its/as/ws/ >> callista/VuCalendarWS.wsdl}VuCalendarWS from WSDL: >> http://devsdvd.vu.edu.au:9990/VuCalendar/VuCalendarWSSoapHttpPort?wsdl >> Invoking getTeachCalendarsPerAcad... >> Jul 18, 2017 10:53:17 AM org.apache.cxf.ws.policy.AssertionBuilderRegist= ryImpl >> handleNoRegisteredBuilder >> WARNING: No assertion builder for type {http://www.bea.com/wls90/ >> security/policy}Identity registered. >> Jul 18, 2017 10:53:17 AM org.apache.cxf.phase.PhaseInterceptorChain >> doDefaultLogging >> WARNING: Interceptor for {http://au/edu/vu/its/as/ws/ >> callista/VuCalendarWS.wsdl}VuCalendarWS#{http://au/edu/ >> vu/its/as/ws/callista/VuCalendarWS.wsdl}getTeachCalendarsPerAcad has >> thrown exception, unwinding now >> org.apache.cxf.ws.policy.PolicyException: None of the policy alternative= s >> can be satisfied. >> at org.apache.cxf.ws.policy.EffectivePolicyImpl.chooseAlternative( >> EffectivePolicyImpl.java:199) >> at org.apache.cxf.ws.policy.EffectivePolicyImpl.chooseAlternative( >> EffectivePolicyImpl.java:192) >> at org.apache.cxf.ws.policy.EffectivePolicyImpl.initialise( >> EffectivePolicyImpl.java:96) >> at org.apache.cxf.ws.policy.PolicyEngineImpl. >> getEffectiveClientRequestPolicy(PolicyEngineImpl.java:204) >> at org.apache.cxf.ws.policy.PolicyOutInterceptor.handle( >> PolicyOutInterceptor.java:98) >> at org.apache.cxf.ws.policy.AbstractPolicyInterceptor. >> handleMessage(AbstractPolicyInterceptor.java:44) >> at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept( >> PhaseInterceptorChain.java:308) >> at org.apache.cxf.endpoint.ClientImpl.doInvoke(ClientImpl.java:518= ) >> at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:427) >> at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:328) >> at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:281) >> at org.apache.cxf.frontend.ClientProxy.invokeSync( >> ClientProxy.java:96) >> at org.apache.cxf.jaxws.JaxWsClientProxy.invoke( >> JaxWsClientProxy.java:139) >> at com.sun.proxy.$Proxy35.getTeachCalendarsPerAcad(Unknown Source) >> at au.edu.vu.its.as.ws.callista.vucalendarws.wsdl.VuCalendarWS_ >> VuCalendarWSSoapHttpPort_Client.main(VuCalendarWS_ >> VuCalendarWSSoapHttpPort_Client.java:49) >> >> Exception in thread "main" javax.xml.ws.soap.SOAPFaultException: None of >> the policy alternatives can be satisfied. >> at org.apache.cxf.jaxws.JaxWsClientProxy.invoke( >> JaxWsClientProxy.java:161) >> at com.sun.proxy.$Proxy35.getTeachCalendarsPerAcad(Unknown Source) >> at au.edu.vu.its.as.ws.callista.vucalendarws.wsdl.VuCalendarWS_ >> VuCalendarWSSoapHttpPort_Client.main(VuCalendarWS_ >> VuCalendarWSSoapHttpPort_Client.java:49) >> Caused by: org.apache.cxf.ws.policy.PolicyException: None of the policy >> alternatives can be satisfied. >> at org.apache.cxf.ws.policy.EffectivePolicyImpl.chooseAlternative( >> EffectivePolicyImpl.java:199) >> at org.apache.cxf.ws.policy.EffectivePolicyImpl.chooseAlternative( >> EffectivePolicyImpl.java:192) >> at org.apache.cxf.ws.policy.EffectivePolicyImpl.initialise( >> EffectivePolicyImpl.java:96) >> at org.apache.cxf.ws.policy.PolicyEngineImpl. >> getEffectiveClientRequestPolicy(PolicyEngineImpl.java:204) >> at org.apache.cxf.ws.policy.PolicyOutInterceptor.handle( >> PolicyOutInterceptor.java:98) >> at org.apache.cxf.ws.policy.AbstractPolicyInterceptor. >> handleMessage(AbstractPolicyInterceptor.java:44) >> at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept( >> PhaseInterceptorChain.java:308) >> at org.apache.cxf.endpoint.ClientImpl.doInvoke(ClientImpl.java:518= ) >> at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:427) >> at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:328) >> at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:281) >> at org.apache.cxf.frontend.ClientProxy.invokeSync( >> ClientProxy.java:96) >> at org.apache.cxf.jaxws.JaxWsClientProxy.invoke( >> JaxWsClientProxy.java:139) >> ... 2 more >> >> >> Thanks >> Siva >> -----Original Message----- >> From: Colm O hEigeartaigh [mailto:coheigea@apache.org] >> Sent: Monday, 17 July 2017 6:58 PM >> To: dev@cxf.apache.org >> Subject: Re: CXF - WS Security Issue >> >> What does the security policy of the service look like? What's the exact >> stack trace you get? >> >> Colm. >> >> On Mon, Jul 17, 2017 at 1:22 AM, Siva Kulendrasingam < >> Siva.Kulendrasingam@vu.edu.au> wrote: >> >>> Dear Team, >>> >>> We are trying to consume a web service hosted in Weblogic server using >>> the CXF client connector in Mule, but getting the following error. >>> >>> "None of the policy alternatives can be satisfied.. Failed to route >>> event via endpoint: org.mule.module.cxf.CxfOutboundMessageProcessor". >>> >>> It seems that the following BEA Weblogic policy is not supported by CXF= . >>> >>> >>> If we remove the cxf-rt-ws-policy-2.7.15.jar, then it works as >>> org.apache.cxf.ws.policy.PolicyOutInterceptor interceptor is not get >>> registered. >>> >>> How this issue would be approached? >>> >>> CXF Version: 2.7.15 >>> >>> WSDL: >>> >>> >> doc:name=3D"Message Properties"> >>> >> value=3D"getAllAcadCalendars" /> >>> >>> >> Payload"> >> /> >>> >>> >>> >> clientClass=3D"au.edu.vu.its.as.ws.callista.vucalendarws. >>> VuCalendarWS_Service" >>> wsdlLocation=3D"${ws.callista.calendar.url}?WSDL" port=3D" >>> VuCalendarWSSoapHttpPort" >>> doc:name=3D"SOAP"> >>> >>> >> /> >> class=3D"org.apache.cxf.interceptor.LoggingOutInterceptor" /> >>> >>> >> address=3D"http://devsdvd.vu.edu.au:9990/VuCalendar/ >> VuCalendarWSSoapHttpPort" >>> /> >>> >>> >>> >> class=3D"org.springframework.beans.factory.config.MapFactoryBean"> >>> >>> >>> >> key=3D"user" value=3D"${ws.callista.user}" /> >> key=3D"passwordType" value=3D"PasswordText" /> >> key=3D"passwordCallbackClass" >>> value=3D"au.edu.vu.its.as.mule.ClientPasswordCallback" /> >>> >>> >>> >> class=3D"org.apache.cxf.ws.security.wss4j.WSS4JOutInterceptor"> >>> >>> >>> >>> Thanks >>> Siva >>> >> >> >> >> -- >> Colm O hEigeartaigh >> >> Talend Community Coder >> http://coders.talend.com >> > > > > -- > Colm O hEigeartaigh > > Talend Community Coder > http://coders.talend.com -- Daniel Kulp dkulp@apache.org - http://dankulp.com/blog Talend Community Coder - http://coders.talend.com --_000_ME1PR01MB10587A305AA856D0029A0B91ABA10ME1PR01MB1058ausp_--