Webservice X509 security policy not working with soapUI (Doc ID 1316497.1)

Last updated on JUNE 09, 2016

Applies to:

Oracle WebLogic Server - Version 10.3.3 and later
Information in this document applies to any platform.

Symptoms

Webservice deployed on Weblogic Server (WLS) is configured to use the below X509 security policy-

Wssp1.2-2007-Wss1.0-X509-Basic256.xml


Both server and test client (soapUI) are also verified to have configured with the same X509 security policy, which is one of the canned security policies supported by WLS.  But when invoking the webservice, the client (soapUI) gets HTTP 500 errors, with client log as below-

---[HTTP response 500]---
<?xml version='1.0' encoding='UTF-8'?><env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"><env:Body><env:Fault xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"><Code xmlns="http://www.w3.org/2003/05/soap-envelope"><Value>env:Sender</Value><Subcode><Value>wsse:InvalidSecurity</Value></Subcode></Code><Reason xmlns="http://www.w3.org/2003/05/soap-envelope"><Text xml:lang="en-US">Error on verifying message against security policy Error code:3000</Text></Reason><Detail xmlns="http://www.w3.org/2003/05/soap-envelope"><java:string xmlns:java="java.io">weblogic.wsee.security.wss.policy.SecurityPolicyInspectionException: Error on verifying message against security policy Error code:3000
</java:string></Detail></env:Fault></env:Body></env:Envelope>--------------------

<?xml version='1.0' encoding='UTF-8'?><env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"><env:Body><env:Fault xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"><Code xmlns="http://www.w3.org/2003/05/soap-envelope"><Value>env:Sender</Value><Subcode><Value>wsse:InvalidSecurity</Value></Subcode></Code><Reason xmlns="http://www.w3.org/2003/05/soap-envelope"><Text xml:lang="en-US">Error on verifying message against security policy Error code:3000</Text></Reason><Detail xmlns="http://www.w3.org/2003/05/soap-envelope"><java:string xmlns:java="java.io">weblogic.wsee.security.wss.policy.SecurityPolicyInspectionException: Error on verifying message against security policy Error code:3000

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms