如何使用Java与Axis2实现WS-Policy及WS-SecureConnection?
Hey there! Let's work through integrating WS-Policy and WS-SecureConnection into your existing Axis2 WS-Security implementation. You've already got Timestamp, Signature, and Encryption working via direct action configs—now we'll shift to using WS-Policy for more declarative security rules, and set up WS-SecureConnection (HTTPS) for transport-level security.
WS-Policy lets you declare security requirements in a standardized XML format, rather than hardcoding them in services.xml or axis2.xml. This makes your security rules more portable and easier to maintain.
Step 1: Create a WS-Policy File
First, create a policy file (e.g., secure_service_policy.xml) and place it in your service's META-INF folder. This file mirrors your current security constraints in a policy-compliant structure:
<wsp:Policy xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" xmlns:sp="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy"> <!-- Asymmetric Binding for signature/encryption --> <sp:AsymmetricBinding> <wsp:Policy> <sp:InitiatorToken> <wsp:Policy> <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/AlwaysToRecipient"> <wsp:Policy> <sp:WssX509V3Token10/> </wsp:Policy> </sp:X509Token> </wsp:Policy> </sp:InitiatorToken> <sp:RecipientToken> <wsp:Policy> <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/AlwaysToInitiator"> <wsp:Policy> <sp:WssX509V3Token10/> </wsp:Policy> </sp:X509Token> </wsp:Policy> </sp:RecipientToken> <sp:AlgorithmSuite> <wsp:Policy> <sp:Basic256/> </wsp:Policy> </sp:AlgorithmSuite> <sp:Layout> <wsp:Policy> <sp:Lax/> </wsp:Policy> </sp:Layout> <sp:IncludeTimestamp/> <sp:OnlySignEntireHeadersAndBody/> </wsp:Policy> </sp:AsymmetricBinding> <!-- Enforce Timestamp with expiration --> <sp:WssTimestampToken10> <wsp:Policy> <sp:RequireExpirationTime/> <sp:MaxAge>300</sp:MaxAge> <!-- 5-minute validity window --> </wsp:Policy> </sp:WssTimestampToken10> <!-- Require Signature on SOAP Body --> <sp:SignedParts> <sp:Body/> </sp:SignedParts> <sp:WssSignatureToken10> <wsp:Policy> <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/Never"/> </wsp:Policy> </sp:WssSignatureToken10> <!-- Require Encryption of SOAP Body --> <sp:EncryptedParts> <sp:Body/> </sp:EncryptedParts> <sp:WssEncryptionToken10> <wsp:Policy> <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/Never"/> </wsp:Policy> </sp:WssEncryptionToken10> </wsp:Policy>
Step 2: Update services.xml to Use the Policy
Replace your existing InflowSecurity and OutflowSecurity parameters with a reference to the policy file. You'll keep your service class, password callback, and security properties configs:
<service name="SecureService"> <description> Secure Service </description> <parameter name="ServiceClass" locked="false">SecureService</parameter> <!-- Reference the WS-Policy file --> <parameter name="policy" locked="false">META-INF/secure_service_policy.xml</parameter> <!-- Retain password callback and security props --> <parameter name="passwordCallbackClass" locked="false">PWCallback</parameter> <parameter name="signaturePropFile" locked="false">security.properties</parameter> <operation name="binary"> <messageReceiver class="org.apache.axis2.rpc.receivers.RPCMessageReceiver"/> </operation> </service>
Step 3: Client-Side Policy Configuration
For your client, you have two options:
- Let Axis2 auto-detect the policy from the service's WSDL (if generating the client from the WSDL), or
- Explicitly reference the policy in your client's
axis2.xmlby replacing the existingInflowSecurity/OutflowSecurityblocks with:<parameter name="policy" locked="false">path/to/secure_service_policy.xml</parameter>
WS-SecureConnection uses HTTPS for transport-level encryption. Here's how to configure it in Axis2:
Step 1: Configure HTTPS Transport in axis2.xml
Update the HTTPS transportReceiver (server-side) to include keystore details (you'll need a Java keystore with your SSL certificate):
<transportReceiver name="https" class="org.apache.axis2.transport.http.SimpleHTTPServer"> <parameter name="port" locked="false">6443</parameter> <!-- Keystore configuration --> <parameter name="keystore" locked="false">path/to/your/keystore.jks</parameter> <parameter name="keystorePassword" locked="false">your_keystore_password</parameter> <parameter name="keyPassword" locked="false">your_key_password</parameter> <parameter name="truststore" locked="false">path/to/your/truststore.jks</parameter> <parameter name="truststorePassword" locked="false">your_truststore_password</parameter> </transportReceiver>
Also update the HTTPS transportSender (client-side) for SSL communication:
<transportSender name="https" class="org.apache.axis2.transport.http.CommonsHTTPTransportSender"> <parameter name="PROTOCOL" locked="false">HTTP/1.1</parameter> <parameter name="Transfer-Encoding" locked="false">chunked</parameter> <!-- Client-side SSL config --> <parameter name="keystore" locked="false">path/to/client_keystore.jks</parameter> <parameter name="keystorePassword" locked="false">client_keystore_pass</parameter> <parameter name="truststore" locked="false">path/to/client_truststore.jks</parameter> <parameter name="truststorePassword" locked="false">client_truststore_pass</parameter> </transportSender>
Step 2: Update Service Endpoint to HTTPS
Modify your client code to use the HTTPS endpoint (e.g., https://localhost:6443/axis2/services/SecureService) instead of the HTTP one.
- Ensure your
security.propertiesfile still references the correct keystore/truststore paths and theJohnalias. - Your existing
PWCallbackclass remains unchanged—it's still used to retrieve passwords for keystores and user authentication. - Test incrementally: First verify WS-Policy works without HTTPS, then add WS-SecureConnection to avoid debugging two changes at once.
内容的提问来源于stack exchange,提问作者snakethesniper

