Local Service No Authentication Policy
Some services override the global service policy with a no authentication local security policy:
oracle/no_authentication_service_policy
 
The following table shows the oracle/ no_authentication_service_policy service policy attached to composites:
SOA Composite
Attached To
CreateCustomerInteraction
OUWAMUtilitiesReqABCSImp
CreateCustomerInteractionOUWAMUtilities
ReqABCSImpl
For more information about security validation and csf-key, refer to the Working with Security section in the Fusion Middleware Developer's Guide for Oracle SOA Core Extension.