Postman调用SOAP服务时Username Password Token认证失败
问题:Postman调用SOAP服务身份验证失败(SOAP UI可正常调用)
问题场景
使用Postman调用SOAP Web服务时收到身份验证失败错误,但相同凭证在SOAP UI中能正常调用。需要在Postman中成功调用该服务,以便将XML请求体用于Java代码(通过RestTemplate调用SOAP服务)。
请求XML Body
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:niec="http://www.xxxxxxx.com/ws/xxxxxxxCustservice/v1/xxxxxxxCustLookup" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"> <soapenv:Header> <wsse:Security soapenv:mustUnderstand="1"> <wsse:UsernameToken> <wsse:Username>username</wsse:Username> <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">password</wsse:Password> <wsse:Nonce>ZHNoYmFzZGE5OA==</wsse:Nonce> <wsu:Created>2024-02-01T14:07:00Z</wsu:Created> </wsse:UsernameToken> <wsu:Timestamp> <wsu:Created>2024-02-02T14:16:00Z</wsu:Created> <wsu:Expires>2024-02-02T14:21:00Z</wsu:Expires> </wsu:Timestamp> </wsse:Security> </soapenv:Header> <soapenv:Body> <niec:xxxxxxxCustLookupRequest> <niec:prnNum>819977777770</niec:prnNum> <niec:versionNumber>1.0</niec:versionNumber> </niec:xxxxxxxCustLookupRequest> </soapenv:Body> </soapenv:Envelope>
错误响应
<env:Envelope xmlns:env="http://schemas.xmlsoap.org/soap/envelope/"> <env:Header/> <env:Body> <env:Fault> <faultcode>env:Client</faultcode> <faultstring> com.sun.xml.wss.impl.WssSoapFaultException: Authentication of Username Password Token Failed; nested exception is com.sun.xml.wss.XWSSecurityException: com.sun.xml.wss.impl.WssSoapFaultException: Authentication of Username Password Token Failed</faultstring> </env:Fault> </env:Body> </env:Envelope>
解决方法
1. 替换静态Nonce和时间戳
SOAP UI会自动生成动态Nonce和当前UTC时间戳,而你在Postman中使用的是固定过期值:
- 生成新的随机Nonce:用16字节随机数做Base64编码
- 更新
wsu:Created为当前UTC时间(格式:yyyy-MM-dd'T'HH:mm:ss'Z') - 调整Timestamp的
Created和Expires为有效时间范围(比如Expires比Created晚5分钟)
2. 重新计算Password Digest
Password Digest必须严格按照Base64(SHA1(Nonce字节值 + Created字符串字节值 + 明文密码字节值))规则生成:
- 取Nonce的Base64解码后的原始字节
- 取Created字符串的UTF-8字节
- 取明文密码的UTF-8字节
- 拼接三者后做SHA1哈希,再将哈希结果Base64编码,得到正确的Password Digest
3. 检查XML格式和命名空间
- 确保
<soapenv:Envelope>包含完整的xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"命名空间声明 - 验证所有XML标签闭合正确,嵌套层级无误
4. 核对Postman请求配置
- 请求方法设为
POST - Content-Type设置为
text/xml;charset=UTF-8或application/soap+xml(匹配服务要求) - 禁用Postman自动添加的Basic Auth等身份验证,避免与WS-Security头冲突
验证后的示例请求
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:niec="http://www.xxxxxxx.com/ws/xxxxxxxCustservice/v1/xxxxxxxCustLookup" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"> <soapenv:Header> <wsse:Security soapenv:mustUnderstand="1"> <wsse:UsernameToken> <wsse:Username>your-actual-username</wsse:Username> <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">calculated-digest-value</wsse:Password> <wsse:Nonce>new-random-nonce-base64</wsse:Nonce> <wsu:Created>2024-05-20T10:30:00Z</wsu:Created> </wsse:UsernameToken> <wsu:Timestamp> <wsu:Created>2024-05-20T10:30:00Z</wsu:Created> <wsu:Expires>2024-05-20T10:35:00Z</wsu:Expires> </wsu:Timestamp> </wsse:Security> </soapenv:Header> <soapenv:Body> <niec:xxxxxxxCustLookupRequest> <niec:prnNum>819977777770</niec:prnNum> <niec:versionNumber>1.0</niec:versionNumber> </niec:xxxxxxxCustLookupRequest> </soapenv:Body> </soapenv:Envelope>
内容的提问来源于stack exchange,提问作者amar pathak
相关产品推荐
相关产品推荐

