Central note for WS Security on 7.00
[7.00] [cxf ws security] [windows7.00] [ws security]
- SAPCRYPTOLIB 555pl26: bugfixes and WS-Security updateSymptom SAPCRYPTOLIB bugfixes and WS-Security Update The following covers changes for pl25 (SAP-internal only) plus pl26: 1. New: Additional functionality required by SAP WebServicesSecurity2. Fix for crash in SSL-Server (icman/sapwebdisp) when trying...
Symptom
This notes describes issues related to security processing for Web service messages.
Reason and Prerequisites
With 700:
You receive error message: CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110You receive canonicalization errors.You are using ESR services generated with 6.40 or 7.00 < SP14 and have issues with authorization checks. Due to changed services names, existing roles using old service names may not be correct. Corrected per note.You are using SAML authentication and authentication fails as the SAML assertion is sent in the default namespace (i.e.
ABAP Kernel 700_REL
Error in XML canonicalization for non-ASCII characters
SSF parameter errors
Fixed in Patch Level #179
SAML Assertion in default namespace
Fixed in Patch Level #207
WS Security implementation (ABAP)
7.00 SP18:
Incorrect parameters to to crypto api causes error message
CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110. Either upgrade to SP18, or implement the correction attached to this note.
Added a backward compatible authorization check for older ESR services. Either upgrade to SP18, or implement the correction attached to this note.