I use JBoss 4.2.3.GA. In previous task I've used base encryption mechanism which JBoss supports (WS-Security). I.e. I used keystore, truststore files for encryption and signing messages. As usually (in standard way) in jboss-wsse-* files were defined aliases of keys that must be used during crypt process. I used ws security configuration from JBoss in Action book.

That's Ok. Encryption works fine.

But in my current task I need to specify aliases for keys manually and dynamically. Task description:

  • I have several profiles. In every profile can be specifiey alias of public key that must be used for encrypting message.

  • I have keystore containing private/public key of server and public keys of clients that will send message to server

  • I need get alias from profile and encrypt message (on client side) using public key specified by this alias.

  • So I need somehow to load data from keystore (it must resides in file system folder, i.e. outside ear file), get appropriate public key from it and then do encryption.
  • After that I need to send message to remote web service (server side) that has private keys for decryption.
  • Here I see several variants for server side logic: web service makes decryption using standard JBoss mechanism or I can do it manually loading keystore data and do decryption manually.

So the questions are about:

  1. Is there a way to specify for JBoss the file system directory to load keystores from?
  2. Can I specify alias for encryption for standard JBoss WSS mechanism to allow jboss to use this information in crypt process?
  3. If I must to do manual encryption/decryption then How can I wrap several Java-objects into WS message and then encrypt it using necessary alias and how to send this message to remote web service manually?

I just don't know how to star

Edit
Report