Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
2.4
-
None
-
Blocked on External
Description
There are a couple of problems with using Derived Keys pointing towards SAML Assertions when using the symmetric binding:
1) The SymmetricBindingHandler can't handle creating a reference to SAML Assertion if the security token does not have a (un)attached Reference to the Assertion.
2) In the holder-of-key case, using a derived key will cause the holder-of-key requirements processing to fail.
Creating a JIRA + patch for this, as it depends on a fix in WSS4J 1.6.1 which is not released yet.