1 | |
|
2 | |
|
3 | |
|
4 | |
|
5 | |
|
6 | |
|
7 | |
|
8 | |
|
9 | |
|
10 | |
|
11 | |
|
12 | |
|
13 | |
|
14 | |
|
15 | |
|
16 | |
package org.kuali.rice.ksb.security.soap; |
17 | |
|
18 | |
import org.apache.cxf.binding.soap.SoapMessage; |
19 | |
import org.apache.cxf.ws.security.wss4j.WSS4JInInterceptor; |
20 | |
import org.apache.log4j.Logger; |
21 | |
import org.apache.ws.security.components.crypto.Crypto; |
22 | |
import org.apache.ws.security.components.crypto.Merlin; |
23 | |
import org.apache.ws.security.handler.RequestData; |
24 | |
import org.apache.ws.security.handler.WSHandlerConstants; |
25 | |
import org.kuali.rice.core.api.config.property.ConfigContext; |
26 | |
import org.kuali.rice.core.api.exception.RiceRuntimeException; |
27 | |
import org.kuali.rice.core.api.util.ClassLoaderUtils; |
28 | |
import org.kuali.rice.ksb.config.wss4j.CryptoPasswordCallbackHandler; |
29 | |
|
30 | |
import java.util.Properties; |
31 | |
|
32 | |
|
33 | |
|
34 | |
|
35 | |
|
36 | |
|
37 | |
|
38 | |
|
39 | |
|
40 | |
|
41 | 0 | public class CXFWSS4JInInterceptor extends WSS4JInInterceptor{ |
42 | |
|
43 | 0 | private static final Logger LOG = Logger.getLogger(CXFWSS4JInInterceptor.class); |
44 | |
|
45 | |
private final boolean busSecurity; |
46 | |
|
47 | 0 | public CXFWSS4JInInterceptor(boolean busSecurity) { |
48 | 0 | this.busSecurity = busSecurity; |
49 | 0 | this.setProperty(WSHandlerConstants.ACTION, WSHandlerConstants.SIGNATURE); |
50 | 0 | this.setProperty(WSHandlerConstants.PW_CALLBACK_CLASS, CryptoPasswordCallbackHandler.class.getName()); |
51 | 0 | this.setProperty(WSHandlerConstants.SIG_KEY_ID, "IssuerSerial"); |
52 | 0 | this.setProperty(WSHandlerConstants.USER, ConfigContext.getCurrentContextConfig().getKeystoreAlias()); |
53 | 0 | } |
54 | |
|
55 | |
@Override |
56 | |
public Crypto loadSignatureCrypto(RequestData reqData) { |
57 | |
try { |
58 | 0 | return new Merlin(getMerlinProperties(), ClassLoaderUtils.getDefaultClassLoader()); |
59 | 0 | } catch (Exception e) { |
60 | 0 | throw new RiceRuntimeException(e); |
61 | |
} |
62 | |
} |
63 | |
|
64 | |
@Override |
65 | |
public Crypto loadDecryptionCrypto(RequestData reqData) { |
66 | 0 | return loadSignatureCrypto(reqData); |
67 | |
} |
68 | |
|
69 | |
protected Properties getMerlinProperties() { |
70 | 0 | Properties props = new Properties(); |
71 | 0 | props.put("org.apache.ws.security.crypto.merlin.keystore.type", "jks"); |
72 | 0 | props.put("org.apache.ws.security.crypto.merlin.keystore.password", ConfigContext.getCurrentContextConfig().getKeystorePassword()); |
73 | 0 | props.put("org.apache.ws.security.crypto.merlin.alias.password", ConfigContext.getCurrentContextConfig().getKeystorePassword()); |
74 | 0 | props.put("org.apache.ws.security.crypto.merlin.keystore.alias", ConfigContext.getCurrentContextConfig().getKeystoreAlias()); |
75 | 0 | props.put("org.apache.ws.security.crypto.merlin.file", ConfigContext.getCurrentContextConfig().getKeystoreFile()); |
76 | |
|
77 | 0 | if (LOG.isDebugEnabled()) { |
78 | 0 | LOG.debug("Using keystore location " + ConfigContext.getCurrentContextConfig().getKeystoreFile()); |
79 | |
} |
80 | 0 | return props; |
81 | |
} |
82 | |
|
83 | |
|
84 | |
|
85 | |
|
86 | |
|
87 | |
|
88 | |
@Override |
89 | |
public void handleMessage(SoapMessage mc) { |
90 | 0 | if (busSecurity) { |
91 | 0 | super.handleMessage(mc); |
92 | |
} |
93 | 0 | } |
94 | |
|
95 | |
} |