如何在Oracle Service Bus 12c中通过CSF密钥库调用带基础认证的HTTP外部SOAP服务
Using CSF Credentials for Basic Auth in OSB 12c Business Services
Got it, let's walk through exactly how to set this up—ditching the direct Service Account auth in your Business Service and using CSF (Credential Store Framework) for reusable, best-practice credential storage, with no credentials in the SOAP header as you need.
Step 1: Create a CSF Credential in WebLogic EM
First, you need to store your target service's basic auth credentials in the WebLogic Credential Store:
- Log into your Enterprise Manager (EM) console, navigate to your WebLogic Domain → Security → Credentials.
- Click Create Map to make a dedicated credential map (e.g.,
OSB_HTTP_Auth_Map—this helps organize your credentials logically). Hit OK. - Select your new map, then click Create Key:
- Enter a unique Key name (e.g.,
Target_WebService_BasicAuth). - For Type, pick
Password. - Fill in the User Name and Password for your target HTTP service's basic auth.
- Add a description if you want, then save.
- Enter a unique Key name (e.g.,
Step 2: Configure the OSB Business Service
Now update your Business Service to pull credentials from the CSF store instead of direct auth:
- Open the Service Bus Console, find your target Business Service and go to its Edit page.
- Switch to the Transport Details tab, then select Authentication from the left menu.
- Don't select Basic Authentication (the method you used before). Instead, choose Custom Authentication.
- Here's the key config:
- Authentication Type: Choose
Basic(since we're using basic auth). - Credential Source: Select
CSF Key. - CSF Map: Enter the name of the map you created in Step 1 (e.g.,
OSB_HTTP_Auth_Map). - CSF Key: Enter the key name you created (e.g.,
Target_WebService_BasicAuth).
- Authentication Type: Choose
- Make sure the Add Credentials to SOAP Header checkbox is UNCHECKED—this ensures no credentials end up in the SOAP header, just like you need.
- Save your changes.
Step 3: Verify Permissions (If Needed)
If you run into authorization errors when testing, make sure the OSB runtime service account has permission to access the CSF key:
- Back in EM's Credentials page, select your CSF key and click Edit.
- Go to the Grants section, add the OSB service account (e.g.,
OSBServiceAccount) and grant it Read access. Save the changes.
Bonus Best Practices
- Reuse the same CSF map/key across multiple Business Services that need the same credentials—no more duplicating auth configs.
- When you need to update credentials, just edit the CSF key in EM—no need to touch your OSB service configurations.
- Keep your CSF map names and key names descriptive so other admins can easily identify what they're used for.
内容的提问来源于stack exchange,提问作者Nawaz
相关产品推荐
相关产品推荐

