在IBM WAS 8.5上实现无Spring的Apache CXF WS-Security与LTPAToken配置
无Spring环境下Apache CXF集成WAS LTPATokenCallbackHandler实现WS-Security
我之前在IBM WAS环境下做过类似的无Spring+CXF集成LTPA令牌的WS-Security配置,分享一下具体的实现步骤和注意点:
核心思路
因为不用Spring框架,我们需要通过编程方式配置CXF的WS-Security拦截器,直接将WAS提供的LTPATokenCallbackHandler绑定到CXF的安全拦截器中,替代Spring XML配置的方式。
步骤1:配置CXF客户端/服务端的WS-Security拦截器
根据你是客户端(发送LTPA令牌)还是服务端(验证LTPA令牌),分别配置对应的WSS4J拦截器:
客户端配置(发送LTPA令牌)
import org.apache.cxf.endpoint.Client; import org.apache.cxf.frontend.ClientProxy; import org.apache.cxf.ws.security.wss4j.WSS4JOutInterceptor; import com.ibm.wsspi.wssecurity.auth.callback.LTPATokenCallbackHandler; import java.util.HashMap; import java.util.Map; // 假设这是你通过CXF生成的服务端口实例 YourServicePortType servicePort = ...; // 构建WS-Security输出拦截器的配置参数 Map<String, Object> securityOutProps = new HashMap<>(); // 指定要执行的安全动作:LTPA令牌处理 securityOutProps.put("action", "LTPA"); // 绑定WAS提供的回调处理程序 securityOutProps.put("callbackHandler", new LTPATokenCallbackHandler()); // 创建并添加拦截器到客户端绑定 WSS4JOutInterceptor outInterceptor = new WSS4JOutInterceptor(securityOutProps); Client client = ClientProxy.getClient(servicePort); client.getOutInterceptors().add(outInterceptor);
服务端配置(验证LTPA令牌)
import org.apache.cxf.jaxws.EndpointImpl; import org.apache.cxf.ws.security.wss4j.WSS4JInInterceptor; import com.ibm.wsspi.wssecurity.auth.callback.LTPATokenCallbackHandler; import java.util.HashMap; import java.util.Map; // 假设这是你的服务实现实例 YourServiceImpl serviceImpl = new YourServiceImpl(); EndpointImpl endpoint = (EndpointImpl) Endpoint.publish("/your-service-path", serviceImpl); // 构建WS-Security输入拦截器的配置参数 Map<String, Object> securityInProps = new HashMap<>(); securityInProps.put("action", "LTPA"); securityInProps.put("callbackHandler", new LTPATokenCallbackHandler()); // 添加拦截器到服务端端点 WSS4JInInterceptor inInterceptor = new WSS4JInInterceptor(securityInProps); endpoint.getInInterceptors().add(inInterceptor);
步骤2:确保WAS依赖包可用
LTPATokenCallbackHandler属于WAS的WS-Security SPI组件,所以需要确保:
- 如果是在WAS服务器上部署应用,WAS运行时会自动提供相关依赖(比如
wsspi.wssecurity.jar),无需手动打包到应用中; - 如果是本地调试,需要从WAS安装目录中找到对应的依赖jar包,添加到项目类路径。
步骤3:验证配置(可选)
可以启用CXF的日志拦截器,查看SOAP消息中是否正确包含LTPA令牌:
import org.apache.cxf.interceptor.LoggingInInterceptor; import org.apache.cxf.interceptor.LoggingOutInterceptor; // 客户端添加日志拦截器 client.getInInterceptors().add(new LoggingInInterceptor()); client.getOutInterceptors().add(new LoggingOutInterceptor()); // 服务端添加日志拦截器 endpoint.getInInterceptors().add(new LoggingInInterceptor()); endpoint.getOutInterceptors().add(new LoggingOutInterceptor());
对比Spring XML配置
如果是Spring环境,你可能会用类似这样的XML配置:
而我们的无Spring实现,本质上就是用代码把这些XML配置的逻辑直接落地——实例化拦截器、设置参数、绑定回调处理程序,最终添加到CXF的拦截器链中。
注意点
LTPATokenCallbackHandler在WAS运行环境中会自动读取服务器的LTPA配置(比如密钥库、令牌有效期等),无需额外初始化参数;- 如果本地调试时遇到找不到类的问题,检查是否正确添加了WAS的WS-Security相关依赖;
- 确保你的CXF版本与WAS支持的CXF版本兼容(部分WAS版本内置了特定版本的CXF,避免版本冲突)。
内容的提问来源于stack exchange,提问作者SatyaS
相关产品推荐
相关产品推荐

