【问题标题】:Websphere Liberty server can't load WebTrustAssociationFailedException in custom TAIWebsphere Liberty 服务器无法在自定义 TAI 中加载 WebTrustAssociationFailedException
【发布时间】:2015-04-17 20:34:44
【问题描述】:

我正在为实现 OAuth2 的 Websphere Liberty 服务器构建信任关联拦截器 (TAI)。它运行良好,除了当我遇到错误并抛出 WebTrustAssociationFailedException 时,我在服务器日志中收到如下错误:

[4/17/15 15:26:55:523 CDT] 000000b1 com.ibm.ws.webcontainer.security.internal.TAIAuthenticator   E CWWKS9107E: Trust Association Init is unable to load Trust Association class com.ibm.websphere.security.WebTrustAssociationFailedException: called with invalid state param
    at com.ibm.tivoli.monitoring.OAuthTai.OAuthTAI.getBearerToken(OAuthTAI.java:299)
    at com.ibm.tivoli.monitoring.OAuthTai.OAuthTAI.negotiateValidateandEstablishTrust(OAuthTAI.java:420)
    at com.ibm.ws.webcontainer.security.internal.TAIAuthenticator.authenticate(TAIAuthenticator.java:102)
    at com.ibm.ws.webcontainer.security.WebAuthenticatorProxy.handleTAI(WebAuthenticatorProxy.java:163)
    at com.ibm.ws.webcontainer.security.WebAuthenticatorProxy.authenticate(WebAuthenticatorProxy.java:84)
    at com.ibm.ws.webcontainer.security.WebAppSecurityCollaboratorImpl.authenticateRequest(WebAppSecurityCollaboratorImpl.java:724)
    at com.ibm.ws.webcontainer.security.WebAppSecurityCollaboratorImpl.determineWebReply(WebAppSecurityCollaboratorImpl.java:567)
    at com.ibm.ws.webcontainer.security.WebAppSecurityCollaboratorImpl.performSecurityChecks(WebAppSecurityCollaboratorImpl.java:438)
    at com.ibm.ws.webcontainer.security.WebAppSecurityCollaboratorImpl.preInvoke(WebAppSecurityCollaboratorImpl.java:389)
    at com.ibm.wsspi.webcontainer.collaborator.CollaboratorHelper.preInvokeCollaborators(CollaboratorHelper.java:443)
    at com.ibm.ws.webcontainer.osgi.collaborator.CollaboratorHelperImpl.preInvokeCollaborators(CollaboratorHelperImpl.java:267)
    at com.ibm.ws.webcontainer.filter.WebAppFilterManager.invokeFilters(WebAppFilterManager.java:1026)
    at com.ibm.ws.webcontainer.webapp.WebApp.handleRequest(WebApp.java:4499)
    at com.ibm.ws.webcontainer.osgi.DynamicVirtualHost$2.handleRequest(DynamicVirtualHost.java:282)
    at com.ibm.ws.webcontainer.WebContainer.handleRequest(WebContainer.java:954)
    at com.ibm.ws.webcontainer.osgi.DynamicVirtualHost$2.run(DynamicVirtualHost.java:252)
    at com.ibm.ws.http.dispatcher.internal.channel.HttpDispatcherLink$TaskWrapper.run(HttpDispatcherLink.java:584)
    at com.ibm.ws.threading.internal.Worker.executeWork(Worker.java:439)
    at com.ibm.ws.threading.internal.Worker.run(Worker.java:421)
    at java.lang.Thread.run(Thread.java:795)

上面错误中看到的“called with invalid state param”的消息是我抛出异常时提供的消息。

我不明白为什么找不到此类。在构建期间,我从 com.ibm.ws.webcontainer_1.0.1.jar 获得这个类。我原以为服务器已经内置了这个。我的 server.xml 已为它启用:

<feature>appSecurity-2.0</feature>

但鉴于它没有找到它,我将这个 jar 添加到服务器上的我的库中,以便它可以从那里获取它,但这没有什么区别。抛出此异常时,我仍然收到上述错误。由于它是定义的TAI接口的一部分,而接口中的其他类如TAIResult没有问题,我很困惑。

【问题讨论】:

    标签: java security websphere single-sign-on websphere-liberty


    【解决方案1】:

    最简单的方法是使用 Java EE 安全性保护您的应用程序,并创建 TAI 以拦截对该应用程序的调用,并根据传递的带有用户 ID 的令牌创建 TAIResult:

    public static TAIResult create(int status, String principal);

    这将在 WAS 注册表中找到一个主要用户,对其进行身份验证并创建 LTPA 令牌。

    您当然不希望或不需要将凭据(例如密码)传递给 WebSphere; TAI 进程不需要实际的密码 - 框架的本质是允许通过其他方式建立信任关系。

    此外 - 也没有迫切需要推出您自己的 TAI 类和相关的专有 SSO 协议(令牌、加密等)。

    WebSphere 7+ 附带了开箱即用的 OAuth 和 SAML TAI(尽管需要配置才能设置它们)。这为您提供了两种开放标准规范可供选择。您最终不会在 WebSphere 端编写任何代码。这些 SSO 协议被广泛采用和成熟——经过整个 Web 开发人员行业的审查,如果实施得当,几乎没有或根本没有攻击向量。这些方法也不需要 DNS 或域对齐 - 它们旨在跨域工作。

    【讨论】:

    • 谢谢桑迪亚。但是,我不能使用股票 TAI,因为我们需要一些自定义行为。所以我真的只是想弄清楚为什么无法识别异常类。
    【解决方案2】:

    结果证明这是一个错误消息的简单案例。似乎是说找不到WebTrustAssociationFailedException 类,但事实并非如此。它实际上只是报告抛出了异常。 Websphere 团队有一个内部缺陷来纠正该消息,它将在未来的版本中修复。现在可以放心地忽略它。

    【讨论】:

      猜你喜欢
      • 2016-08-18
      • 2014-12-25
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-04-08
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多