IBM Support

PK79617: The WebServices-Security UNTGUIPROMPTCALLBACKHANDLER is not adding NONCE or TIMESTAMP which causes authentication failure

Fixes are available

7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for AIX
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for IBM i
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for Windows
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for HP-UX
7.0.0.5: Java SDK 1.6 SR5 Cumulative Fix for WebSphere Application Server
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for Solaris
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for Linux
Java SDK 1.5 SR10 Cumulative Fix for WebSphere Application Server
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for IBM i
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for AIX
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for Windows
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for HP-UX
7.0.0.7: Java SDK 1.6 SR6 Cumulative Fix for WebSphere Application Server
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for Solaris
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for Linux
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for IBM i
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for Windows
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for AIX
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for HP-UX
7.0.0.9: Java SDK 1.6 SR7 Cumulative Fix for WebSphere Application Server
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for Solaris
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for Linux
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for IBM i
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Windows
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for HP-UX
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for AIX
7.0.0.11: Java SDK 1.6 SR7 Cumulative Fix for WebSphere Application Server
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Solaris
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Linux
6.1.0.29: Java SDK 1.5 SR11 Cumulative Fix for WebSphere Application Server
6.1.0.31: Java SDK 1.5 SR11 FP1 Cumulative Fix for WebSphere Application Server
6.1.0.33: Java SDK 1.5 SR12 FP1 Cumulative Fix for WebSphere
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for AIX
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for HP-UX
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for IBM i
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for Linux
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for Solaris
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for Windows
7.0.0.13: Java SDK 1.6 SR8FP1 Cumulative Fix for WebSphere Application Server
6.1.0.35: Java SDK 1.5 SR12 FP2 Cumulative Fix for WebSphere
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for AIX
7.0.0.15: Java SDK 1.6 SR9 Cumulative Fix for WebSphere Application Server
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for HP-UX
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for IBM i
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for Linux
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for Solaris
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for Windows
6.1.0.37: Java SDK 1.5 SR12 FP3 Cumulative Fix for WebSphere
7.0.0.17: WebSphere Application Server V7.0 Fix Pack 17
7.0.0.17: Java SDK 1.6 SR9 FP1 Cumulative Fix for WebSphere Application Server
7.0.0.19: WebSphere Application Server V7.0 Fix Pack 19
7.0.0.21: WebSphere Application Server V7.0 Fix Pack 21
7.0.0.23: WebSphere Application Server V7.0 Fix Pack 23
7.0.0.25: WebSphere Application Server V7.0 Fix Pack 25
7.0.0.27: WebSphere Application Server V7.0 Fix Pack 27
7.0.0.29: WebSphere Application Server V7.0 Fix Pack 29
6.1.0.47: WebSphere Application Server V6.1 Fix Pack 47
7.0.0.31: WebSphere Application Server V7.0 Fix Pack 31
7.0.0.27: Java SDK 1.6 SR13 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.33: WebSphere Application Server V7.0 Fix Pack 33
7.0.0.35: WebSphere Application Server V7.0 Fix Pack 35
6.1.0.39: Java SDK 1.5 SR12 FP4 Cumulative Fix for WebSphere Application Server
6.1.0.41: Java SDK 1.5 SR12 FP5 Cumulative Fix for WebSphere Application Server
6.1.0.43: Java SDK 1.5 SR13 Cumulative Fix for WebSphere Application Server
6.1.0.45: Java SDK 1.5 SR14 Cumulative Fix for WebSphere Application Server
6.1.0.47: Java SDK 1.5 SR16 Cumulative Fix for WebSphere Application Server
7.0.0.19: Java SDK 1.6 SR9 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.21: Java SDK 1.6 SR9 FP2 Cumulative Fix for WebSphere
7.0.0.23: Java SDK 1.6 SR10 FP1 Cumulative Fix for WebSphere
7.0.0.25: Java SDK 1.6 SR11 Cumulative Fix for WebSphere Application Server
7.0.0.27: Java SDK 1.6 SR12 Cumulative Fix for WebSphere Application Server
7.0.0.29: Java SDK 1.6 SR13 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.45: Java SDK 1.6 SR16 FP60 Cumulative Fix for WebSphere Application Server
7.0.0.31: Java SDK 1.6 SR15 Cumulative Fix for WebSphere Application Server
7.0.0.35: Java SDK 1.6 SR16 FP1 Cumulative Fix for WebSphere Application Server
7.0.0.37: Java SDK 1.6 SR16 FP3 Cumulative Fix for WebSphere Application Server
7.0.0.39: Java SDK 1.6 SR16 FP7 Cumulative Fix for WebSphere Application Server
7.0.0.41: Java SDK 1.6 SR16 FP20 Cumulative Fix for WebSphere Application Server
7.0.0.43: Java SDK 1.6 SR16 FP41 Cumulative Fix for WebSphere Application Server

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The WebServices-Security UNTGUIPromptCallbackHandler is not
    adding nonce or timestamp to UsernameTokens when configured to
    do so. This results in an authenticaion failure.  A SOAP Fault
    is sent back to the WebServices client.
    .
    Retrieving document at 'file:/C:/Documents and
    Settings/Administrator/IBM/rationalsdp/devworks2/HelloWorldConsu
    mer/bin/META-INF/wsdl/'.
    Retrieving schema at 'HelloWorldProviderService_schema1.xsd',
    relative to 'file:/C:/Documents and
    Settings/Administrator/IBM/rationalsdp/devworks2/HelloWorldConsu
    mer/bin/META-INF/wsdl/'.
    javax.xml.ws.soap.SOAPFaultException:
    security.wssecurity.WSSContextImpl.s02:
    com.ibm.websphere.security.WSSecurityException: Exception
    org.apache.axis2.AxisFault:
    CWWSS6521E: The Login failed because
    of an exception: javax.security.auth.login.LoginException:
    .
    CWWSS5327E: A null value is not allowed for the created time of
    the time stamp. The Application Server expected the wsu:Created
    element. ocurred while running action:
    com.ibm.ws.wssecurity.handler.WSSecurityConsumerHandler$1@3c493c
    49
     at org.apache.axis2.jaxws.marshaller.impl.alt.
    MethodMarshallerUtils.createSystemException
    (MethodMarshallerUtils.java:1249)
     at
    org.apache.axis2.jaxws.marshaller.impl.alt.MethodMarshallerUtils
    .demarshalFaultResponse(MethodMarshallerUtils.java:975)
     at org.apache.axis2.jaxws.marshaller.impl.alt.
    DocLitWrappedMethodMarshaller.demarshalFaultResponse
    (DocLitWrappedMethodMarshaller.java:558)
     at org.apache.axis2.jaxws.client.proxy.JAXWSProxyHandler.
    getFaultResponse(JAXWSProxyHandler.java:445)
     at org.apache.axis2.jaxws.client.proxy.JAXWSProxyHandler.
    createResponse(JAXWSProxyHandler.java:408)
     at org.apache.axis2.jaxws.client.proxy.JAXWSProxyHandler.
    invokeSEIMethod(JAXWSProxyHandler.java:332)
     at org.apache.axis2.jaxws.client.proxy.JAXWSProxyHandler.
    invoke(JAXWSProxyHandler.java:159)
     at $Proxy37.sayHello(Unknown Source)
     at com.ibm.dwexample.ClientTest.main(ClientTest.java:13)
    .
    

Local fix

  • Use the UNTGenerateCallbackHandler instead.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: WebSphere Application Server users of        *
    *                 UNTGUIPromptCallbackHandler to retrieve      *
    *                 user data for WS-Security UsernameToken      *
    ****************************************************************
    * PROBLEM DESCRIPTION: UNTGUIPromptCallbackHandler is not      *
    *                      adding nonce or timestamp to            *
    *                      UsernameTokens when configured to do so.*
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When using the UNTGUIPromptCallbackHandler to retrieve user
    data for the WS-Security UsernameToken login module, the nonce
    and timestamp configuration are ignored. The UsernameToken
    is generated without nonce and timestamp. As a result, the
    token will be rejected by recipient if nonce and timestamp are
    required.
    

Problem conclusion

  • The UNTGUIPromptCallbackHandler is fixed to correctly pass
    nonce and timestamp configuration to the WS-Security
    UsernameToken login module.  The UsernameToken is generated
    with the correct nonce and timestamp if required.
    
    The fix for this APAR is currently targeted for inclusion in
    fix packs 6.1.0.27 and 7.0.0.5.  Please refer to the
    Recommended Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980 |
    

Temporary fix

Comments

APAR Information

  • APAR number

    PK79617

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2009-01-28

  • Closed date

    2009-05-29

  • Last modified date

    2009-05-29

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R61W PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 December 2021