Troubleshooting
Problem
IBM WebSphere DataPower appliance models (XS40, XI50, XI50B, XB60, XM70) have the ability to create WebSphere Application Server Lightweight Third Party Authentication (LTPA) credentials in the AAA post processing action. An LTPA credential contains a client's identity. These LTPA credentials can be either in the form of an HTTP Cookie, or within a WS-Security binary security token. AAA Policies in the DataPower models that generate WS-Security LTPA binary security tokens do not include a wsse:Timestamp. This might be rejected by the WebSphere Application Server (or other products built on top of WebSphere Application Server) after the application of WebSphere Application Server fix pack 7.0.0.13 (or APAR PM16014).
Symptom
After application of fix pack 7.0.0.13, services on a DataPower appliance will receive faults in response to requests that were valid with previous fix packs. A typical fault will be:
<faultcode>axis2ns2:InvalidSecurity</faultcode>
<faultstring>security.wssecurity.WSSContextImpl.s02: com.ibm.websphere.security.WSSecurityException: Exception org.apache.axis2.AxisFault: CWWSS5730E: A required timestamp is not found. ocurred while running action: com.ibm.ws.wssecurity.handler.WSSecurityConsumerHandler$1@35733573</faultstring>
Log InLog in to view more of this document
Was this topic helpful?
Document Information
Modified date:
16 June 2026
UID
swg21453755