Uploaded image for project: 'WSS4J'
  1. WSS4J
  2. WSS-270

No need to ensure Crypto object is non-null for SAML signature verification using a secret key

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.5.11
    • 1.6, 1.5.12
    • None
    • None

    Description


      WSS4J currently throws an Exception if the Crypto object is non-null when trying to verify a signature, where the KeyInfo of the signature points to a SAML Assertion. However, for certain cases we query the CallbackHandler for a key, and so the check on Crypto can be delayed.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: