Implementing WSS (web service security) in Go lang

Viewed 59

I'm building in Golang and trying to integrate with a service that requires WSS to authenticate requests. Seems like core Go libraries don't offer a lot of XML/SOAP support and offers basically no WSS (web service security) support. I was playing around with implementing WSS manually using Go's XML parsing but as i looked more into it, WSS relies on XML Canonicalization and XML Signature/Encryption which seem to be their own lengthy standards and would blow up the scope of this project. I've tried reading through the java implementation of WSS to get a better sense for what is required to implement WSS.

Does Go natively support WSS or at least XML encryption?

I saw Calling SOAP with Golang which isn't exactly what i need since it seems to offer WSDL support but not any WSS support. There are plenty of posts describing how to use SOAP in Golang if you're authenticating with mTLS like How to make a SOAP call in Golang over HTTPS but again the service I'm using expects WSS. Then there's this reddit post that points out that Go's XML parser doesn't support namespacing very well (which is a point against manually implementing WSS): https://www.reddit.com/r/golang/comments/jn24j8/whats_the_status_of_xmlsoap_support_in_go/.

Seems like python/java offer native WSS support but im stuck building in a Go service. Open to other suggestions as well

0 Answers
Related