Search code examples

WS-Security Websphere Configuration

I'm trying to develop a web service that uses WS-Security using Websphere 7 and JAX-WS. Looking through some guides, it appears that I MUST create a application server user registry and maintain username/passwords inside of that server. Is there anyway to avoid having to create usernames in the server itself and somehow capture the header and do validation based upon another a custom security configuration like a single sign-on?

I'm able to create a handler to get the header, but when mustUnderstands is set to 1 in the request (which is mandatory), it gets rejected before my handler sees the message.

I'm only looking to use the UsernameToken part of WS-Security.

Any help is appreciated.

An example of my request

<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="">
    <wsse:Security xmlns:wsse="" soapenv:mustUnderstand="1">
      <wsse:UsernameToken xmlns:wsu="" Id="unt_20">
        <wsse:Password Type="">some_password</wsse:Password>

Is it possible to create a custom security implementation so I can use my existing user validation scheme?


  • Another possible answer is to create a Trust Association Interceptor (TAI). This basically extends your current security.

    Here is a useful link to get started: