View Javadoc
1   /**
2    * Licensed to the Apache Software Foundation (ASF) under one
3    * or more contributor license agreements. See the NOTICE file
4    * distributed with this work for additional information
5    * regarding copyright ownership. The ASF licenses this file
6    * to you under the Apache License, Version 2.0 (the
7    * "License"); you may not use this file except in compliance
8    * with the License. You may obtain a copy of the License at
9    *
10   * http://www.apache.org/licenses/LICENSE-2.0
11   *
12   * Unless required by applicable law or agreed to in writing,
13   * software distributed under the License is distributed on an
14   * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15   * KIND, either express or implied. See the License for the
16   * specific language governing permissions and limitations
17   * under the License.
18   */
19  
20  package org.apache.wss4j.dom.handler;
21  
22  import java.security.Provider;
23  import java.security.cert.Certificate;
24  import java.util.ArrayList;
25  import java.util.Collection;
26  import java.util.LinkedList;
27  import java.util.List;
28  import java.util.Map;
29  import java.util.regex.Pattern;
30  
31  import javax.security.auth.callback.CallbackHandler;
32  import javax.xml.namespace.QName;
33  
34  import org.apache.wss4j.common.ConfigurationConstants;
35  import org.apache.wss4j.common.EncryptionActionToken;
36  import org.apache.wss4j.common.SignatureActionToken;
37  import org.apache.wss4j.common.bsp.BSPEnforcer;
38  import org.apache.wss4j.common.bsp.BSPRule;
39  import org.apache.wss4j.common.cache.ReplayCache;
40  import org.apache.wss4j.common.crypto.AlgorithmSuite;
41  import org.apache.wss4j.common.crypto.Crypto;
42  import org.apache.wss4j.common.crypto.PasswordEncryptor;
43  import org.apache.wss4j.common.ext.WSSecurityException;
44  import org.apache.wss4j.dom.SOAPConstants;
45  import org.apache.wss4j.dom.WSConstants;
46  import org.apache.wss4j.dom.WSDocInfo;
47  import org.apache.wss4j.dom.engine.WSSConfig;
48  import org.apache.wss4j.dom.message.WSSecHeader;
49  import org.apache.wss4j.dom.validate.Validator;
50  import org.apache.xml.security.encryption.Serializer;
51  
52  /**
53   * This class holds per request data.
54   */
55  public class RequestData {
56  
57      private Object msgContext;
58      private SOAPConstants soapConstants;
59      private String actor;
60      private String username;
61      private String pwType = WSConstants.PASSWORD_DIGEST; // Make this the default when no password type is given.
62      private Crypto sigVerCrypto;
63      private Crypto decCrypto;
64      private SignatureActionToken signatureToken;
65      private EncryptionActionToken encryptionToken;
66      private WSSConfig wssConfig;
67      private List<byte[]> signatureValues = new ArrayList<>();
68      private WSSecHeader secHeader;
69      private int derivedKeyIterations = 1000;
70      private boolean useDerivedKeyForMAC = true;
71      private CallbackHandler callback;
72      private CallbackHandler attachmentCallbackHandler;
73      private boolean enableRevocation;
74      private boolean requireSignedEncryptedDataElements;
75      private ReplayCache timestampReplayCache;
76      private ReplayCache nonceReplayCache;
77      private ReplayCache samlOneTimeUseReplayCache;
78      private Collection<Pattern> subjectDNPatterns = new ArrayList<>();
79      private Collection<Pattern> issuerDNPatterns = new ArrayList<>();
80      private final List<BSPRule> ignoredBSPRules = new LinkedList<>();
81      private boolean appendSignatureAfterTimestamp;
82      private int originalSignatureActionPosition;
83      private AlgorithmSuite algorithmSuite;
84      private AlgorithmSuite samlAlgorithmSuite;
85      private boolean disableBSPEnforcement;
86      private boolean allowRSA15KeyTransportAlgorithm;
87      private int processorNestingDepth;
88      private boolean addUsernameTokenNonce;
89      private boolean addUsernameTokenCreated;
90      private Certificate[] tlsCerts;
91      private PasswordEncryptor passwordEncryptor;
92      private String derivedKeyTokenReference;
93      private boolean use200512Namespace = true;
94      private final List<String> audienceRestrictions = new ArrayList<>();
95      private boolean requireTimestampExpires;
96      private boolean storeBytesInAttachment;
97      private Serializer encryptionSerializer;
98      private WSDocInfo wsDocInfo;
99      private Provider signatureProvider;
100 
101     /**
102      * Whether to add an InclusiveNamespaces PrefixList as a CanonicalizationMethod
103      * child when generating Signatures using WSConstants.C14N_EXCL_OMIT_COMMENTS.
104      * The default is true.
105      */
106     private boolean addInclusivePrefixes = true;
107 
108     /**
109      * Set the timestamp precision mode. If set to <code>true</code> then use
110      * timestamps with milliseconds, otherwise omit the milliseconds. As per XML
111      * Date/Time specification the default is to include the milliseconds.
112      */
113     private boolean precisionInMilliSeconds = true;
114 
115     private boolean enableSignatureConfirmation;
116 
117     /**
118      * If set to true then the timestamp handling will throw an exception if the
119      * timestamp contains an expires element and the semantics are expired.
120      *
121      * If set to false, no exception will be thrown, even if the semantics are
122      * expired.
123      */
124     private boolean timeStampStrict = true;
125 
126     /**
127      * If this value is not null, then username token handling will throw an
128      * exception if the password type of the Username Token does not match this value
129      */
130     private String requiredPasswordType;
131 
132     /**
133      * This variable controls whether a UsernameToken with no password element is allowed.
134      * The default value is "false". Set it to "true" to allow deriving keys from UsernameTokens
135      * or to support UsernameTokens for purposes other than authentication.
136      */
137     private boolean allowUsernameTokenNoPassword;
138 
139     /**
140      * The time in seconds between creation and expiry for a Timestamp. The default
141      * is 300 seconds (5 minutes).
142      */
143     private int timeStampTTL = 300;
144 
145     /**
146      * The time in seconds in the future within which the Created time of an incoming
147      * Timestamp is valid. The default is 60 seconds.
148      */
149     private int timeStampFutureTTL = 60;
150 
151     /**
152      * The time in seconds between creation and expiry for a UsernameToken Created
153      * element. The default is 300 seconds (5 minutes).
154      */
155     private int utTTL = 300;
156 
157     /**
158      * The time in seconds in the future within which the Created time of an incoming
159      * UsernameToken is valid. The default is 60 seconds.
160      */
161     private int utFutureTTL = 60;
162 
163     /**
164      * This variable controls whether types other than PasswordDigest or PasswordText
165      * are allowed when processing UsernameTokens.
166      *
167      * By default this is set to false so that the user doesn't have to explicitly
168      * reject custom token types in the callback handler.
169      */
170     private boolean handleCustomPasswordTypes;
171 
172     /**
173      * This variable controls whether (wsse) namespace qualified password types are
174      * accepted when processing UsernameTokens.
175      *
176      * By default this is set to false.
177      */
178     private boolean allowNamespaceQualifiedPasswordTypes;
179 
180     /**
181      * Whether the password should be treated as a binary value.  This
182      * is needed to properly handle password equivalence for UsernameToken
183      * passwords.  Binary passwords are Base64 encoded so they can be
184      * treated as strings in most places, but when the password digest
185      * is calculated or a key is derived from the password, the password
186      * will be Base64 decoded before being used. This is most useful for
187      * hashed passwords as password equivalents.
188      *
189      * See https://issues.apache.org/jira/browse/WSS-239
190      */
191     private boolean encodePasswords;
192 
193     /**
194      * Whether to validate the SubjectConfirmation requirements of a received SAML Token
195      * (sender-vouches or holder-of-key). The default is true.
196      */
197     private boolean validateSamlSubjectConfirmation = true;
198 
199     private boolean expandXopInclude;
200 
201     public Object getMsgContext() {
202         return msgContext;
203     }
204 
205     public void setMsgContext(Object msgContext) {
206         this.msgContext = msgContext;
207     }
208 
209     public SOAPConstants getSoapConstants() {
210         return soapConstants;
211     }
212 
213     public void setSoapConstants(SOAPConstants soapConstants) {
214         this.soapConstants = soapConstants;
215     }
216 
217     public String getActor() {
218         return actor;
219     }
220 
221     public void setActor(String actor) {
222         this.actor = actor;
223     }
224 
225     public String getUsername() {
226         return username;
227     }
228 
229     public void setUsername(String username) {
230         this.username = username;
231     }
232 
233     public String getPwType() {
234         return pwType;
235     }
236 
237     public void setPwType(String pwType) {
238         this.pwType = pwType;
239     }
240 
241     public Crypto getSigVerCrypto() {
242         return sigVerCrypto;
243     }
244 
245     public void setSigVerCrypto(Crypto sigVerCrypto) {
246         this.sigVerCrypto = sigVerCrypto;
247     }
248 
249     public Crypto getDecCrypto() {
250         return decCrypto;
251     }
252 
253     public void setDecCrypto(Crypto decCrypto) {
254         this.decCrypto = decCrypto;
255     }
256 
257     /**
258      * @return Returns the wssConfig.
259      */
260     public WSSConfig getWssConfig() {
261         return wssConfig;
262     }
263 
264     /**
265      * @param wssConfig The wssConfig to set.
266      */
267     public void setWssConfig(WSSConfig wssConfig) {
268         this.wssConfig = wssConfig;
269     }
270 
271     /**
272      * @return Returns the list of stored signature values.
273      */
274     public List<byte[]> getSignatureValues() {
275         return signatureValues;
276     }
277 
278     /**
279      * @return Returns the secHeader.
280      */
281     public WSSecHeader getSecHeader() {
282         return secHeader;
283     }
284 
285     /**
286      * @param secHeader The secHeader to set.
287      */
288     public void setSecHeader(WSSecHeader secHeader) {
289         this.secHeader = secHeader;
290     }
291 
292     /**
293      * Set the derived key iterations. Default is 1000.
294      * @param iterations The number of iterations to use when deriving a key
295      */
296     public void setDerivedKeyIterations(int iterations) {
297         derivedKeyIterations = iterations;
298     }
299 
300     /**
301      * Get the derived key iterations.
302      * @return The number of iterations to use when deriving a key
303      */
304     public int getDerivedKeyIterations() {
305         return derivedKeyIterations;
306     }
307 
308     /**
309      * Whether to use the derived key for a MAC.
310      * @param useMac Whether to use the derived key for a MAC.
311      */
312     public void setUseDerivedKeyForMAC(boolean useMac) {
313         useDerivedKeyForMAC = useMac;
314     }
315 
316     /**
317      * Whether to use the derived key for a MAC.
318      * @return Whether to use the derived key for a MAC.
319      */
320     public boolean isUseDerivedKeyForMAC() {
321         return useDerivedKeyForMAC;
322     }
323 
324     /**
325      * Set whether to enable CRL checking or not when verifying trust in a certificate.
326      * @param enableRevocation whether to enable CRL checking
327      */
328     public void setEnableRevocation(boolean enableRevocation) {
329         this.enableRevocation = enableRevocation;
330     }
331 
332     /**
333      * Get whether to enable CRL checking or not when verifying trust in a certificate.
334      * @return whether to enable CRL checking
335      */
336     public boolean isRevocationEnabled() {
337         return enableRevocation;
338     }
339 
340     /**
341      * @return whether EncryptedData elements are required to be signed
342      */
343     public boolean isRequireSignedEncryptedDataElements() {
344         return requireSignedEncryptedDataElements;
345     }
346 
347     /**
348      * Configure the engine to verify that EncryptedData elements
349      * are in a signed subtree of the document. This can be used to
350      * prevent some wrapping based attacks when encrypt-before-sign
351      * token protection is selected.
352      *
353      * @param requireSignedEncryptedDataElements
354      */
355     public void setRequireSignedEncryptedDataElements(boolean requireSignedEncryptedDataElements) {
356         this.requireSignedEncryptedDataElements = requireSignedEncryptedDataElements;
357     }
358 
359     /**
360      * Sets the CallbackHandler used for this request
361      * @param cb
362      */
363     public void setCallbackHandler(CallbackHandler cb) {
364         callback = cb;
365     }
366 
367     /**
368      * Returns the CallbackHandler used for this request.
369      * @return the CallbackHandler used for this request.
370      */
371     public CallbackHandler getCallbackHandler() {
372         return callback;
373     }
374 
375     public CallbackHandler getAttachmentCallbackHandler() {
376         return attachmentCallbackHandler;
377     }
378 
379     public void setAttachmentCallbackHandler(CallbackHandler attachmentCallbackHandler) {
380         this.attachmentCallbackHandler = attachmentCallbackHandler;
381     }
382 
383     /**
384      * Get the Validator instance corresponding to the QName
385      * @param qName the QName with which to find a Validator instance
386      * @return the Validator instance corresponding to the QName
387      * @throws WSSecurityException
388      */
389     public Validator getValidator(QName qName) throws WSSecurityException {
390         // Check the custom Validator Map first
391         if (getMsgContext() instanceof Map<?,?>) {
392             @SuppressWarnings("unchecked")
393             Map<QName, Validator> validatorMap =
394                 (Map<QName, Validator>)((Map<?,?>)getMsgContext()).get(ConfigurationConstants.VALIDATOR_MAP);
395             if (validatorMap != null && validatorMap.containsKey(qName)) {
396                 return validatorMap.get(qName);
397             }
398         }
399         if (wssConfig != null) {
400             return wssConfig.getValidator(qName);
401         }
402         return null;
403     }
404 
405     /**
406      * Set the replay cache for Timestamps
407      */
408     public void setTimestampReplayCache(ReplayCache newCache) {
409         timestampReplayCache = newCache;
410     }
411 
412     /**
413      * Get the replay cache for Timestamps
414      * @throws WSSecurityException
415      */
416     public ReplayCache getTimestampReplayCache() throws WSSecurityException {
417         return timestampReplayCache;
418     }
419 
420     /**
421      * Set the replay cache for Nonces
422      */
423     public void setNonceReplayCache(ReplayCache newCache) {
424         nonceReplayCache = newCache;
425     }
426 
427     /**
428      * Get the replay cache for Nonces
429      * @throws WSSecurityException
430      */
431     public ReplayCache getNonceReplayCache() throws WSSecurityException {
432         return nonceReplayCache;
433     }
434 
435     /**
436      * Set the replay cache for SAML2 OneTimeUse Assertions
437      */
438     public void setSamlOneTimeUseReplayCache(ReplayCache newCache) {
439         samlOneTimeUseReplayCache = newCache;
440     }
441 
442     /**
443      * Get the replay cache for SAML2 OneTimeUse Assertions
444      * @throws WSSecurityException
445      */
446     public ReplayCache getSamlOneTimeUseReplayCache() throws WSSecurityException {
447         return samlOneTimeUseReplayCache;
448     }
449 
450     /**
451      * Set the Signature Subject Cert Constraints
452      */
453     public void setSubjectCertConstraints(Collection<Pattern> subjectCertConstraints) {
454         if (subjectCertConstraints != null) {
455             subjectDNPatterns.addAll(subjectCertConstraints);
456         }
457     }
458 
459     /**
460      * Get the Signature Subject Cert Constraints
461      */
462     public Collection<Pattern> getSubjectCertConstraints() {
463         return subjectDNPatterns;
464     }
465 
466     /**
467      * Get the Signature Issuer DN Cert Constraints
468      * @return
469      */
470     public Collection<Pattern> getIssuerDNPatterns() {
471         return issuerDNPatterns;
472     }
473     /**
474      * Set the Signature Issuer DN Cert Constraints
475      *
476      */
477     public void setIssuerDNPatterns(Collection<Pattern> issuerDNPatterns) {
478         this.issuerDNPatterns = issuerDNPatterns;
479     }
480 
481     /**
482      * Set the Audience Restrictions
483      */
484     public void setAudienceRestrictions(List<String> audienceRestrictions) {
485         if (audienceRestrictions != null) {
486             this.audienceRestrictions.addAll(audienceRestrictions);
487         }
488     }
489 
490     /**
491      * Get the Audience Restrictions
492      */
493     public List<String> getAudienceRestrictions() {
494         return audienceRestrictions;
495     }
496 
497     public void setIgnoredBSPRules(List<BSPRule> bspRules) {
498         ignoredBSPRules.clear();
499         ignoredBSPRules.addAll(bspRules);
500     }
501 
502     public BSPEnforcer getBSPEnforcer() {
503         if (disableBSPEnforcement) {
504             return new BSPEnforcer(true);
505         }
506         return new BSPEnforcer(ignoredBSPRules);
507     }
508 
509     public boolean isAppendSignatureAfterTimestamp() {
510         return appendSignatureAfterTimestamp;
511     }
512 
513     public void setAppendSignatureAfterTimestamp(boolean appendSignatureAfterTimestamp) {
514         this.appendSignatureAfterTimestamp = appendSignatureAfterTimestamp;
515     }
516 
517     public AlgorithmSuite getAlgorithmSuite() {
518         return algorithmSuite;
519     }
520 
521     public void setAlgorithmSuite(AlgorithmSuite algorithmSuite) {
522         this.algorithmSuite = algorithmSuite;
523     }
524 
525     public AlgorithmSuite getSamlAlgorithmSuite() {
526         return samlAlgorithmSuite;
527     }
528 
529     public void setSamlAlgorithmSuite(AlgorithmSuite samlAlgorithmSuite) {
530         this.samlAlgorithmSuite = samlAlgorithmSuite;
531     }
532 
533     public int getOriginalSignatureActionPosition() {
534         return originalSignatureActionPosition;
535     }
536 
537     public void setOriginalSignatureActionPosition(int originalSignatureActionPosition) {
538         this.originalSignatureActionPosition = originalSignatureActionPosition;
539     }
540 
541     public boolean isDisableBSPEnforcement() {
542         return disableBSPEnforcement;
543     }
544 
545     public void setDisableBSPEnforcement(boolean disableBSPEnforcement) {
546         this.disableBSPEnforcement = disableBSPEnforcement;
547     }
548 
549     /**
550      * The maximum depth to which a processor may hand a token it has just uncovered to another
551      * processor. Decrypting an EncryptedData whose plaintext is itself a security structure does
552      * exactly that, and does it recursively, so a sender who nests those structures is choosing
553      * how much of the receiver's stack to consume. Each level costs very little to write - every
554      * one of them may point its KeyInfo at a single EncryptedKey, which is decrypted once and
555      * cached - so the chain has to be bounded.
556      * <p/>
557      * Real messages stay well inside this. An EncryptedAssertion reaches depth 2: the assertion's
558      * EncryptedData, then the decrypted Assertion handed to the SAML processor, which dispatches
559      * no further. Re-encrypting an already encrypted assertion reaches 3. Sibling tokens in the
560      * same header do not accumulate - each is entered and left in turn - so the bound constrains
561      * nesting only.
562      */
563     public static final int MAXIMUM_PROCESSOR_NESTING_DEPTH = 5;
564 
565     /**
566      * Record that processing is about to descend into a token uncovered by another token, and
567      * refuse to go deeper than {@link #MAXIMUM_PROCESSOR_NESTING_DEPTH}. Every caller must pair
568      * this with {@link #exitNestedToken()} in a finally block.
569      *
570      * @throws WSSecurityException if the message nests tokens too deeply
571      */
572     public void enterNestedToken() throws WSSecurityException {
573         if (processorNestingDepth >= MAXIMUM_PROCESSOR_NESTING_DEPTH) {
574             throw new WSSecurityException(
575                 WSSecurityException.ErrorCode.INVALID_SECURITY, "empty",
576                 new Object[] {"Tokens are nested more than "
577                               + MAXIMUM_PROCESSOR_NESTING_DEPTH + " deep"});
578         }
579         processorNestingDepth++;
580     }
581 
582     /**
583      * Record that processing has come back out of a nested token.
584      */
585     public void exitNestedToken() {
586         processorNestingDepth--;
587     }
588 
589     public boolean isAllowRSA15KeyTransportAlgorithm() {
590         return allowRSA15KeyTransportAlgorithm;
591     }
592 
593     public void setAllowRSA15KeyTransportAlgorithm(boolean allowRSA15KeyTransportAlgorithm) {
594         this.allowRSA15KeyTransportAlgorithm = allowRSA15KeyTransportAlgorithm;
595     }
596 
597     public Certificate[] getTlsCerts() {
598         return tlsCerts;
599     }
600 
601     public void setTlsCerts(Certificate[] tlsCerts) {
602         this.tlsCerts = tlsCerts;
603     }
604 
605     public PasswordEncryptor getPasswordEncryptor() {
606         return passwordEncryptor;
607     }
608 
609     public void setPasswordEncryptor(PasswordEncryptor passwordEncryptor) {
610         this.passwordEncryptor = passwordEncryptor;
611     }
612 
613     public SignatureActionToken getSignatureToken() {
614         return signatureToken;
615     }
616 
617     public void setSignatureToken(SignatureActionToken signatureToken) {
618         this.signatureToken = signatureToken;
619     }
620 
621     public EncryptionActionToken getEncryptionToken() {
622         return encryptionToken;
623     }
624 
625     public void setEncryptionToken(EncryptionActionToken encryptionToken) {
626         this.encryptionToken = encryptionToken;
627     }
628 
629     public String getDerivedKeyTokenReference() {
630         return derivedKeyTokenReference;
631     }
632 
633     public void setDerivedKeyTokenReference(String derivedKeyTokenReference) {
634         this.derivedKeyTokenReference = derivedKeyTokenReference;
635     }
636 
637     public boolean isUse200512Namespace() {
638         return use200512Namespace;
639     }
640 
641     public void setUse200512Namespace(boolean use200512Namespace) {
642         this.use200512Namespace = use200512Namespace;
643     }
644 
645     public boolean isRequireTimestampExpires() {
646         return requireTimestampExpires;
647     }
648 
649     public void setRequireTimestampExpires(boolean requireTimestampExpires) {
650         this.requireTimestampExpires = requireTimestampExpires;
651     }
652 
653     public boolean isValidateSamlSubjectConfirmation() {
654         return validateSamlSubjectConfirmation;
655     }
656 
657     public void setValidateSamlSubjectConfirmation(boolean validateSamlSubjectConfirmation) {
658         this.validateSamlSubjectConfirmation = validateSamlSubjectConfirmation;
659     }
660 
661     public boolean isAllowNamespaceQualifiedPasswordTypes() {
662         return allowNamespaceQualifiedPasswordTypes;
663     }
664 
665     public void setAllowNamespaceQualifiedPasswordTypes(boolean allowNamespaceQualifiedPasswordTypes) {
666         this.allowNamespaceQualifiedPasswordTypes = allowNamespaceQualifiedPasswordTypes;
667     }
668 
669     public int getUtFutureTTL() {
670         return utFutureTTL;
671     }
672 
673     public void setUtFutureTTL(int utFutureTTL) {
674         this.utFutureTTL = utFutureTTL;
675     }
676 
677     public boolean isHandleCustomPasswordTypes() {
678         return handleCustomPasswordTypes;
679     }
680 
681     public void setHandleCustomPasswordTypes(boolean handleCustomPasswordTypes) {
682         this.handleCustomPasswordTypes = handleCustomPasswordTypes;
683     }
684 
685     public int getUtTTL() {
686         return utTTL;
687     }
688 
689     public void setUtTTL(int utTTL) {
690         this.utTTL = utTTL;
691     }
692 
693     public int getTimeStampTTL() {
694         return timeStampTTL;
695     }
696 
697     public void setTimeStampTTL(int timeStampTTL) {
698         this.timeStampTTL = timeStampTTL;
699     }
700 
701     public int getTimeStampFutureTTL() {
702         return timeStampFutureTTL;
703     }
704 
705     public void setTimeStampFutureTTL(int timeStampFutureTTL) {
706         this.timeStampFutureTTL = timeStampFutureTTL;
707     }
708 
709     public boolean isAllowUsernameTokenNoPassword() {
710         return allowUsernameTokenNoPassword;
711     }
712 
713     public void setAllowUsernameTokenNoPassword(boolean allowUsernameTokenNoPassword) {
714         this.allowUsernameTokenNoPassword = allowUsernameTokenNoPassword;
715     }
716 
717     public boolean isTimeStampStrict() {
718         return timeStampStrict;
719     }
720 
721     public void setTimeStampStrict(boolean timeStampStrict) {
722         this.timeStampStrict = timeStampStrict;
723     }
724 
725     public boolean isAddInclusivePrefixes() {
726         return addInclusivePrefixes;
727     }
728 
729     public void setAddInclusivePrefixes(boolean addInclusivePrefixes) {
730         this.addInclusivePrefixes = addInclusivePrefixes;
731     }
732 
733     public boolean isPrecisionInMilliSeconds() {
734         return precisionInMilliSeconds;
735     }
736 
737     public void setPrecisionInMilliSeconds(boolean precisionInMilliSeconds) {
738         this.precisionInMilliSeconds = precisionInMilliSeconds;
739     }
740 
741     public boolean isEnableSignatureConfirmation() {
742         return enableSignatureConfirmation;
743     }
744 
745     public void setEnableSignatureConfirmation(boolean enableSignatureConfirmation) {
746         this.enableSignatureConfirmation = enableSignatureConfirmation;
747     }
748 
749     public String getRequiredPasswordType() {
750         return requiredPasswordType;
751     }
752 
753     public void setRequiredPasswordType(String requiredPasswordType) {
754         this.requiredPasswordType = requiredPasswordType;
755     }
756 
757     public boolean isEncodePasswords() {
758         return encodePasswords;
759     }
760 
761     public void setEncodePasswords(boolean encodePasswords) {
762         this.encodePasswords = encodePasswords;
763     }
764 
765     public boolean isStoreBytesInAttachment() {
766         return storeBytesInAttachment;
767     }
768 
769     public void setStoreBytesInAttachment(boolean storeBytesInAttachment) {
770         this.storeBytesInAttachment = storeBytesInAttachment;
771     }
772 
773     public boolean isExpandXopInclude() {
774         return expandXopInclude;
775     }
776 
777     public void setExpandXopInclude(boolean expandXopInclude) {
778         this.expandXopInclude = expandXopInclude;
779     }
780 
781     public Serializer getEncryptionSerializer() {
782         return encryptionSerializer;
783     }
784 
785     public void setEncryptionSerializer(Serializer encryptionSerializer) {
786         this.encryptionSerializer = encryptionSerializer;
787     }
788 
789     public boolean isAddUsernameTokenCreated() {
790         return addUsernameTokenCreated;
791     }
792 
793     public void setAddUsernameTokenCreated(boolean addUsernameTokenCreated) {
794         this.addUsernameTokenCreated = addUsernameTokenCreated;
795     }
796 
797     public boolean isAddUsernameTokenNonce() {
798         return addUsernameTokenNonce;
799     }
800 
801     public void setAddUsernameTokenNonce(boolean addUsernameTokenNonce) {
802         this.addUsernameTokenNonce = addUsernameTokenNonce;
803     }
804 
805     public WSDocInfo getWsDocInfo() {
806         return wsDocInfo;
807     }
808 
809     public void setWsDocInfo(WSDocInfo wsDocInfo) {
810         this.wsDocInfo = wsDocInfo;
811     }
812 
813     public Provider getSignatureProvider() {
814         return signatureProvider;
815     }
816 
817     /**
818      * Set a security Provider instance to use for Signature
819      */
820     public void setSignatureProvider(Provider signatureProvider) {
821         this.signatureProvider = signatureProvider;
822     }
823 }