You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Java与Axis2实现WS-Policy及WS-SecureConnection?

Hey there! Let's work through integrating WS-Policy and WS-SecureConnection into your existing Axis2 WS-Security implementation. You've already got Timestamp, Signature, and Encryption working via direct action configs—now we'll shift to using WS-Policy for more declarative security rules, and set up WS-SecureConnection (HTTPS) for transport-level security.

1. Integrating WS-Policy

WS-Policy lets you declare security requirements in a standardized XML format, rather than hardcoding them in services.xml or axis2.xml. This makes your security rules more portable and easier to maintain.

Step 1: Create a WS-Policy File

First, create a policy file (e.g., secure_service_policy.xml) and place it in your service's META-INF folder. This file mirrors your current security constraints in a policy-compliant structure:

<wsp:Policy xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"
            xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
            xmlns:sp="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy">

    <!-- Asymmetric Binding for signature/encryption -->
    <sp:AsymmetricBinding>
        <wsp:Policy>
            <sp:InitiatorToken>
                <wsp:Policy>
                    <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/AlwaysToRecipient">
                        <wsp:Policy>
                            <sp:WssX509V3Token10/>
                        </wsp:Policy>
                    </sp:X509Token>
                </wsp:Policy>
            </sp:InitiatorToken>
            <sp:RecipientToken>
                <wsp:Policy>
                    <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/AlwaysToInitiator">
                        <wsp:Policy>
                            <sp:WssX509V3Token10/>
                        </wsp:Policy>
                    </sp:X509Token>
                </wsp:Policy>
            </sp:RecipientToken>
            <sp:AlgorithmSuite>
                <wsp:Policy>
                    <sp:Basic256/>
                </wsp:Policy>
            </sp:AlgorithmSuite>
            <sp:Layout>
                <wsp:Policy>
                    <sp:Lax/>
                </wsp:Policy>
            </sp:Layout>
            <sp:IncludeTimestamp/>
            <sp:OnlySignEntireHeadersAndBody/>
        </wsp:Policy>
    </sp:AsymmetricBinding>

    <!-- Enforce Timestamp with expiration -->
    <sp:WssTimestampToken10>
        <wsp:Policy>
            <sp:RequireExpirationTime/>
            <sp:MaxAge>300</sp:MaxAge> <!-- 5-minute validity window -->
        </wsp:Policy>
    </sp:WssTimestampToken10>

    <!-- Require Signature on SOAP Body -->
    <sp:SignedParts>
        <sp:Body/>
    </sp:SignedParts>
    <sp:WssSignatureToken10>
        <wsp:Policy>
            <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/Never"/>
        </wsp:Policy>
    </sp:WssSignatureToken10>

    <!-- Require Encryption of SOAP Body -->
    <sp:EncryptedParts>
        <sp:Body/>
    </sp:EncryptedParts>
    <sp:WssEncryptionToken10>
        <wsp:Policy>
            <sp:X509Token sp:IncludeToken="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy/IncludeToken/Never"/>
        </wsp:Policy>
    </sp:WssEncryptionToken10>

</wsp:Policy>

Step 2: Update services.xml to Use the Policy

Replace your existing InflowSecurity and OutflowSecurity parameters with a reference to the policy file. You'll keep your service class, password callback, and security properties configs:

<service name="SecureService">
    <description>
        Secure Service
    </description>
    <parameter name="ServiceClass" locked="false">SecureService</parameter>
    <!-- Reference the WS-Policy file -->
    <parameter name="policy" locked="false">META-INF/secure_service_policy.xml</parameter>
    <!-- Retain password callback and security props -->
    <parameter name="passwordCallbackClass" locked="false">PWCallback</parameter>
    <parameter name="signaturePropFile" locked="false">security.properties</parameter>
    
    <operation name="binary">
        <messageReceiver class="org.apache.axis2.rpc.receivers.RPCMessageReceiver"/>
    </operation>
</service>

Step 3: Client-Side Policy Configuration

For your client, you have two options:

  • Let Axis2 auto-detect the policy from the service's WSDL (if generating the client from the WSDL), or
  • Explicitly reference the policy in your client's axis2.xml by replacing the existing InflowSecurity/OutflowSecurity blocks with:
    <parameter name="policy" locked="false">path/to/secure_service_policy.xml</parameter>
    
2. Setting Up WS-SecureConnection (HTTPS)

WS-SecureConnection uses HTTPS for transport-level encryption. Here's how to configure it in Axis2:

Step 1: Configure HTTPS Transport in axis2.xml

Update the HTTPS transportReceiver (server-side) to include keystore details (you'll need a Java keystore with your SSL certificate):

<transportReceiver name="https" class="org.apache.axis2.transport.http.SimpleHTTPServer">
    <parameter name="port" locked="false">6443</parameter>
    <!-- Keystore configuration -->
    <parameter name="keystore" locked="false">path/to/your/keystore.jks</parameter>
    <parameter name="keystorePassword" locked="false">your_keystore_password</parameter>
    <parameter name="keyPassword" locked="false">your_key_password</parameter>
    <parameter name="truststore" locked="false">path/to/your/truststore.jks</parameter>
    <parameter name="truststorePassword" locked="false">your_truststore_password</parameter>
</transportReceiver>

Also update the HTTPS transportSender (client-side) for SSL communication:

<transportSender name="https" class="org.apache.axis2.transport.http.CommonsHTTPTransportSender">
    <parameter name="PROTOCOL" locked="false">HTTP/1.1</parameter>
    <parameter name="Transfer-Encoding" locked="false">chunked</parameter>
    <!-- Client-side SSL config -->
    <parameter name="keystore" locked="false">path/to/client_keystore.jks</parameter>
    <parameter name="keystorePassword" locked="false">client_keystore_pass</parameter>
    <parameter name="truststore" locked="false">path/to/client_truststore.jks</parameter>
    <parameter name="truststorePassword" locked="false">client_truststore_pass</parameter>
</transportSender>

Step 2: Update Service Endpoint to HTTPS

Modify your client code to use the HTTPS endpoint (e.g., https://localhost:6443/axis2/services/SecureService) instead of the HTTP one.

3. Key Notes to Remember
  • Ensure your security.properties file still references the correct keystore/truststore paths and the John alias.
  • Your existing PWCallback class remains unchanged—it's still used to retrieve passwords for keystores and user authentication.
  • Test incrementally: First verify WS-Policy works without HTTPS, then add WS-SecureConnection to avoid debugging two changes at once.

内容的提问来源于stack exchange,提问作者snakethesniper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:41:01