You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在IBM WAS 8.5上实现无Spring的Apache CXF WS-Security与LTPAToken配置

无Spring环境下Apache CXF集成WAS LTPATokenCallbackHandler实现WS-Security

我之前在IBM WAS环境下做过类似的无Spring+CXF集成LTPA令牌的WS-Security配置,分享一下具体的实现步骤和注意点:

核心思路

因为不用Spring框架,我们需要通过编程方式配置CXF的WS-Security拦截器,直接将WAS提供的LTPATokenCallbackHandler绑定到CXF的安全拦截器中,替代Spring XML配置的方式。


步骤1:配置CXF客户端/服务端的WS-Security拦截器

根据你是客户端(发送LTPA令牌)还是服务端(验证LTPA令牌),分别配置对应的WSS4J拦截器:

客户端配置(发送LTPA令牌)

import org.apache.cxf.endpoint.Client;
import org.apache.cxf.frontend.ClientProxy;
import org.apache.cxf.ws.security.wss4j.WSS4JOutInterceptor;
import com.ibm.wsspi.wssecurity.auth.callback.LTPATokenCallbackHandler;

import java.util.HashMap;
import java.util.Map;

// 假设这是你通过CXF生成的服务端口实例
YourServicePortType servicePort = ...;

// 构建WS-Security输出拦截器的配置参数
Map<String, Object> securityOutProps = new HashMap<>();
// 指定要执行的安全动作:LTPA令牌处理
securityOutProps.put("action", "LTPA");
// 绑定WAS提供的回调处理程序
securityOutProps.put("callbackHandler", new LTPATokenCallbackHandler());

// 创建并添加拦截器到客户端绑定
WSS4JOutInterceptor outInterceptor = new WSS4JOutInterceptor(securityOutProps);
Client client = ClientProxy.getClient(servicePort);
client.getOutInterceptors().add(outInterceptor);

服务端配置(验证LTPA令牌)

import org.apache.cxf.jaxws.EndpointImpl;
import org.apache.cxf.ws.security.wss4j.WSS4JInInterceptor;
import com.ibm.wsspi.wssecurity.auth.callback.LTPATokenCallbackHandler;

import java.util.HashMap;
import java.util.Map;

// 假设这是你的服务实现实例
YourServiceImpl serviceImpl = new YourServiceImpl();
EndpointImpl endpoint = (EndpointImpl) Endpoint.publish("/your-service-path", serviceImpl);

// 构建WS-Security输入拦截器的配置参数
Map<String, Object> securityInProps = new HashMap<>();
securityInProps.put("action", "LTPA");
securityInProps.put("callbackHandler", new LTPATokenCallbackHandler());

// 添加拦截器到服务端端点
WSS4JInInterceptor inInterceptor = new WSS4JInInterceptor(securityInProps);
endpoint.getInInterceptors().add(inInterceptor);

步骤2:确保WAS依赖包可用

LTPATokenCallbackHandler属于WAS的WS-Security SPI组件,所以需要确保:

  • 如果是在WAS服务器上部署应用,WAS运行时会自动提供相关依赖(比如wsspi.wssecurity.jar),无需手动打包到应用中;
  • 如果是本地调试,需要从WAS安装目录中找到对应的依赖jar包,添加到项目类路径。

步骤3:验证配置(可选)

可以启用CXF的日志拦截器,查看SOAP消息中是否正确包含LTPA令牌:

import org.apache.cxf.interceptor.LoggingInInterceptor;
import org.apache.cxf.interceptor.LoggingOutInterceptor;

// 客户端添加日志拦截器
client.getInInterceptors().add(new LoggingInInterceptor());
client.getOutInterceptors().add(new LoggingOutInterceptor());

// 服务端添加日志拦截器
endpoint.getInInterceptors().add(new LoggingInInterceptor());
endpoint.getOutInterceptors().add(new LoggingOutInterceptor());

对比Spring XML配置

如果是Spring环境,你可能会用类似这样的XML配置:

而我们的无Spring实现,本质上就是用代码把这些XML配置的逻辑直接落地——实例化拦截器、设置参数、绑定回调处理程序,最终添加到CXF的拦截器链中。

注意点

  • LTPATokenCallbackHandler在WAS运行环境中会自动读取服务器的LTPA配置(比如密钥库、令牌有效期等),无需额外初始化参数;
  • 如果本地调试时遇到找不到类的问题,检查是否正确添加了WAS的WS-Security相关依赖;
  • 确保你的CXF版本与WAS支持的CXF版本兼容(部分WAS版本内置了特定版本的CXF,避免版本冲突)。

内容的提问来源于stack exchange,提问作者SatyaS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:46:22