Menu

#143 Need separate configuration of incoming WSS

closed
nobody
None
5
2007-12-19
2007-12-04
No

Background: Assume the following scenario: Request is signed using own private key and encrypted using server public key. The server is signing the response with its private key and encrypts the response with your own public key. This means that the request is encrypted with the servers certificate, but is decrypted using your own certificate using the private key.

Consequences: Currently the response is handled via WSSecurityEngine.processSecurityHeader using the same certificates when creating the request. This results in the response not being decrypted.

Need: To be able to specify different certificates for request and response processing.

I am using: soapui 2.0beta2

Discussion

  • Ole Lensmar

    Ole Lensmar - 2007-12-04

    Logged In: YES
    user_id=838515
    Originator: NO

    Hi!

    this should be possible by assigning different keystores/certificates to the incomingwss and outgoingwss configurations?

    or am I misunderstanding?

    regards!

    /Ole
    eviware.com

     
  • Erik W. Rasmussen

    Logged In: YES
    user_id=190247
    Originator: YES

    That is correct! One can currently assign keystores/certificates to the outgoingwss but not the incomingwss.

     
  • Ole Lensmar

    Ole Lensmar - 2007-12-04

    Logged In: YES
    user_id=838515
    Originator: NO

    Hi!

    ok.. but the Incoming WSS tab currently allows you to assign seperate keystores ("cryptos", that needs to be changed) for signature verifying and decryption? Or is this not what you need / want?

    regards!

    /Ole
    eviware.com

     
  • Erik W. Rasmussen

    Logged In: YES
    user_id=190247
    Originator: YES

    Eeh yes, but using soapui 2.0beta2 that is not possible (maybe that is an error?).

    Explanation: In the "Outgoing Configurations" tab one can assign different keystores and operations (signing, encryption etc.). But in the "Incoming Configurations" tab there is no such possibility.

     
  • Ole Lensmar

    Ole Lensmar - 2007-12-04

    Logged In: YES
    user_id=838515
    Originator: NO

    Hi..

    hmm.. you should be able to select them directly in the incoming configurations table.. ie add a new incoming configuration and select in the different drop-downs in the table !? Please mail me so I can send you a screenshot :-) (ole@eviware.com)

    regards!

    /Ole
    eviware.com

     
  • Erik W. Rasmussen

    Logged In: YES
    user_id=190247
    Originator: YES

    Aha ...

    turns out that I haven't figured out that the it was a table where drop downs existed (they are not marked). So now it actually works! Thanks!

    This feature request can be closed :-)

     
  • Ole Lensmar

    Ole Lensmar - 2007-12-04

    Logged In: YES
    user_id=838515
    Originator: NO

    Great!

    sorry for the clumsy UI.. and thanks for your valuable testing!

    regards,

    /Ole
    eviware.com

     
  • Ole Lensmar

    Ole Lensmar - 2007-12-04
    • status: open --> pending
     
  • SourceForge Robot

    Logged In: YES
    user_id=1312539
    Originator: NO

    This Tracker item was closed automatically by the system. It was
    previously set to a Pending status, and the original submitter
    did not respond within 14 days (the time period specified by
    the administrator of this Tracker).

     
  • SourceForge Robot

    • status: pending --> closed