IBM Support

LTPA Tokens in wsse:BinarySecurityToken format generated by the DataPower appliance can be rejected by WebSphere Application Server with WAS Fix pack 7.0.0.13 and newer

Troubleshooting


Problem

IBM WebSphere DataPower appliance models (XS40, XI50, XI50B, XB60, XM70) have the ability to create WebSphere Application Server Lightweight Third Party Authentication (LTPA) credentials in the AAA post processing action. An LTPA credential contains a client's identity. These LTPA credentials can be either in the form of an HTTP Cookie, or within a WS-Security binary security token. AAA Policies in the DataPower models that generate WS-Security LTPA binary security tokens do not include a wsse:Timestamp. This might be rejected by the WebSphere Application Server (or other products built on top of WebSphere Application Server) after the application of WebSphere Application Server fix pack 7.0.0.13 (or APAR PM16014).

Symptom

After application of fix pack 7.0.0.13, services on a DataPower appliance will receive faults in response to requests that were valid with previous fix packs. A typical fault will be:

<faultcode>axis2ns2:InvalidSecurity</faultcode>
<faultstring>security.wssecurity.WSSContextImpl.s02: com.ibm.websphere.security.WSSecurityException: Exception org.apache.axis2.AxisFault: CWWSS5730E: A required timestamp is not found. ocurred while running action: com.ibm.ws.wssecurity.handler.WSSecurityConsumerHandler$1@35733573</faultstring>

[{"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"General","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"4.0.2;4.0.1;5.0.0;6.0.0;6.0.1","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
16 June 2026

UID

swg21453755