2014-11-20 93 views
0

我正试图把一个肥皂服务的小型CXF客户端,其wsdl中有SignedSupportingTokens ws-security策略。我已配置CXF客户端如下SignedSupportingTokens wssecurity策略cxf客户端

<jaxws:client id="secretService" name="{http:/mySecretServiceEndpoint//}Service" createdFromAPI="true"> 
     <jaxws:properties> 
      <entry key="ws-security.signature.properties" value="keystore/secret.properties" /> 
      <entry key="ws-security.encryption.properties" value="keystore/secret.properties" /> 
      <entry key="ws-security.timestamp.timeToLive" value="600" /> 
     </jaxws:properties> 
    </jaxws:client> 

不幸的是,它不能发出具有以下错误的消息。

Caused by: org.apache.cxf.ws.policy.PolicyException: None of the policy alternatives can be satisfied. 
    at org.apache.cxf.ws.policy.EffectivePolicyImpl.chooseAlternative(EffectivePolicyImpl.java:199) 
    at org.apache.cxf.ws.policy.EffectivePolicyImpl.chooseAlternative(EffectivePolicyImpl.java:192) 
    at org.apache.cxf.ws.policy.EffectivePolicyImpl.initialise(EffectivePolicyImpl.java:96) 
    at org.apache.cxf.ws.policy.PolicyEngineImpl.getEffectiveClientRequestPolicy(PolicyEngineImpl.java:205) 
    at org.apache.cxf.ws.policy.PolicyOutInterceptor.handle(PolicyOutInterceptor.java:98) 
    at org.apache.cxf.ws.policy.AbstractPolicyInterceptor.handleMessage(AbstractPolicyInterceptor.java:44) 
    at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept(PhaseInterceptorChain.java:307) 
    at org.apache.cxf.endpoint.ClientImpl.doInvoke(ClientImpl.java:514) 
    at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:423) 
    at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:326) 
    at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:279) 
    at org.apache.cxf.frontend.ClientProxy.invokeSync(ClientProxy.java:96) 
    at org.apache.cxf.jaxws.JaxWsClientProxy.invoke(JaxWsClientProxy.java:138) 

我想知道CXF默认支持SignedSupportingTokens策略吗?我需要注册一些处理程序还是缺少其他的东西?我对WS-SecurityWS-SecurityPolicy没有太多的经验,任何回应将不胜感激。

+0

感谢Leonel的编辑,现在看起来好多了。 – andrew 2014-11-20 23:29:00

回答

1

回答我自己的问题,因为它可能有助于某一天! CXF确实支持SignedSupportingTokens以及更多,就我而言,服务WSDL对于SignedSupportingToken具有不同的名称空间,CXF客户端的Dint理解(无法匹配)。

我能够通过使用ws-security拦截器来配置客户端来解决此问题。