Anyone using Spring-ws with SAML authentication?

We see spring-ws as a platform for implementing web services that will be deployed to weblogic. We need to use WS-Security with SAML tokens released by our Identity Management Platform (TFIM).

The spring-ws documentation for XwsSecurityInterceptor does not mention SAML, and it is not clear to me whether it will work in this context.

I suggest that alternatives could be our own interceptor, which uses OpenSAML or somehow uses SAML support in weblogic.

Does anyone have any experience? It would be nice to strive for a solution that is known to be workable.

+4
source share
1 answer

Apache WSS4J supports SAML tokens, and Spring -WS comes with Wss4jSecurityInterceptor, so I think you could get it out of the box.

+1
source

Source: https://habr.com/ru/post/1286505/


All Articles