Bug 1065068

Summary: [GSS] (6.2.x) STR-Transform SAML 2.0 Sender Vouches for IssuedToken in WS-Policy doesn't work
Product: [JBoss] JBoss Enterprise Application Platform 6 Reporter: Kyle Lape <klape>
Component: Web ServicesAssignee: Alessio Soldano <asoldano>
Status: CLOSED CURRENTRELEASE QA Contact: Rostislav Svoboda <rsvoboda>
Severity: unspecified Docs Contact: Russell Dickenson <rdickens>
Priority: unspecified    
Version: 6.2.1CC: asoldano, klape, psakar, smumford, vtunka
Target Milestone: CR2   
Target Release: EAP 6.2.2   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-02 12:49:39 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1040729    

Description Kyle Lape 2014-02-13 20:14:00 UTC
When an STS issues a SenderVouches SAML 2.0 Assertion, a CXF client does not correctly sign the Assertion via a SecuritTokenReference transform in the service request.

Comment 1 Kyle Lape 2014-02-13 20:15:14 UTC
This is released in CXF 2.7.10, so it would be included if we upgraded to 2.7.10.

Comment 4 Petr Sakaƙ 2014-03-10 09:41:11 UTC
The issue is in regards to the WS-Trust functionality provided by CXF, which is considered tech preview in EAP 6.2 and as such is not tested by QE. We verified only that upgraded version of CXF contained in EAP-6.2.2.CP.CR2 did not introduced any regresion

Comment 5 Scott Mumford 2014-03-12 22:39:12 UTC
Does this issue require an entry in the EAP 6.2.2 Release Notes?

If so, please populate the details in the Doc Text field to allow ECS to begin drafting a note for it.

Note: "$THING was broken and now $THING is fixed" is not a suitable release note draft.