Jump to content
The TIBCO Platform is a real-time, composable data platform that will bring together an evolving set of your TIBCO solutions - and it's available now! See more information here ×
  • Signing WS-Security elements in a SOAP message in TIBCO ActiveMatrix BusinessWorks™ 5


    Kurian Kuruvilla

    When the Integrity option is selected in an outbound security policy, TIBCO ActiveMatrix BusinessWorks™ 5 (BW) signs the SOAP Body element only. It is a common requirement to sign WS-Security elements along with the SOAP Body element. This article explains how to configure BW to sign WS-Security elements in a SOAP message.

    First, let’s take a look at a sample outbound SOAP message that is generated when the Security Policy shared resource is configured with Integrity and Timeout options. Only the SOAP Body element SOAP-ENV:Body is signed.

    TC_Signature-Copy.thumb.png.0654ed5cae56a07739bbaddb4dbbd430.png

    Now, let’s say, the requirement is to have the signature include the Timestamp element along with the SOAP Body element. To sign additional elements along with SOAP Body, specify the elements along with the SOAP Body element in the Message Elements for Signature field under the Outbound tab of Security Policy Association shared resource. In this case, it would be SOAP-ENV:Body and wsu:TImestamp. Steps below.

    1. Select the Security Policy Association shared resource.

    2. Go to the Outbound tab and add the following to the Message Elements for Signature field 

    SOAP-ENV:Body and wsu:Timestamp

    3. Under Prefix Namespace Pair, add the prefixes SOAP-ENV and wsu and select the corresponding namespaces.

    TC_Signature2.png.7b5bfcc7320b1bfd7283e597cceae81f.png

    The signature in the outbound request should now include the Timestamp element in addition to the SOAP Body element.


    TC_Signature1-Copy.thumb.png.53d110be55e4d80e542ce9c5161363ba.png

    A sample project is available here.

    To get the signed SOAP message logged to the Designer console or application log file, set the logger com.tibco.spin to DEBUG.

    5.14.0

    Add the following to TIBCO_HOME/bw/5.x/lib/log4j.xml

    <logger name="com.tibco.spin">
    <level value="DEBUG"/>
    <appender-ref ref="tibco_bw_log"/>
    </logger>

    5.14.1, 5.15.x

    Add the following to TIBCO_HOME/bw/5.x/lib/log4j2.properties

    logger.spin.name = com.tibco.spin
    logger.spin.level = DEBUG
    logger.spin.additivity = false
    logger.spin.appenderRef.bw_log.ref = tibco_bw_log

     

    • Like 1

    User Feedback

    Recommended Comments

    There are no comments to display.



    Create an account or sign in to comment

    You need to be a member in order to leave a comment

    Create an account

    Sign up for a new account in our community. It's easy!

    Register a new account

    Sign in

    Already have an account? Sign in here.

    Sign In Now

×
×
  • Create New...