|
|
The WS-Security Policy policy supports only WSDL (SOAP 1.1 and 1.2) APIs.
|
The Web Services Security (WS-Security) policy protects a SOAP service by validating the <wsse:Security> header of each inbound request. You can enable either or both of these controls:
-
UsernameToken validation: Authenticates the <wsse:UsernameToken> against the client applications that have contracts with the API. The username is the client ID, and the password is the client secret.
-
XML signature validation: Verifies the <ds:Signature> in the Security header and confirms that the signing X.509 certificate chains to a certificate authority (CA) that you trust.
The WS-Security Policy policy is fail-closed. Every enabled control must succeed before Omni Gateway forwards the request to the upstream service. Omni Gateway forwards the original headers and body unchanged, and doesn’t modify responses. When a check fails, Omni Gateway returns a WS-Security SOAP fault, and the request never reaches the upstream service.
The policy accepts plain SOAP requests with a text/xml or application/soap+xml content type, and multipart SOAP requests with a multipart/related content type, such as MTOM/XOP and SOAP with Attachments (SwA).
-
To validate UsernameTokens, client applications must have a contract with the API. For more information, see Approve or Reject Access Requests.
-
To validate XML signatures, get the PEM-encoded certificates of the CAs that issue your client signing certificates.