13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Example 7-4 Secured and non-secured Web Services togetherunprotectedRPCRouterunprotectedRPCRoutercom.ibm.soap.server.http.WASRPCRouterServletFaultListenerorg.apache.soap.server.DOMFaultListenerprotectedRPCRouterApache-SOAP RPC Routerno descriptioncom.ibm.soap.server.http.WASRPCRouterServletfaultListenerorg.apache.soap.server.DOMFaultListenerThis security configuration can even be defined using Application Assembly Tool(AAT). For more information, look at Chapter 10, “Administering <strong>WebSphere</strong>security” on page 2337.1.3 WS-<strong>Security</strong>The Web Services <strong>Security</strong> specification (WS-<strong>Security</strong>) provides a set ofmechanisms to help developers of Web Services secure SOAP messageexchanges. Specifically,WS-<strong>Security</strong> describes enhancements to the existingSOAP messaging to provide quality of protection through the application ofmessage integrity, message confidentiality, and single message authentication toSOAP messages. Additionally, WS-<strong>Security</strong> describes how to encode binarysecurity tokens (a security token represents a collection of claims such as name,identity, key, group, privilege, capability and so on) and attach them to SOAPmessages.<strong>Security</strong> tokens assert claims which can be coupled with digital signatures toprovide mechanisms for demonstrating evidence of the sender’s knowledge ofthe keys described by the security token. In addition, the definition of a SOAPheader element provides a mechanism for "binding" or "associating" thesignature with the claims in the security token.146 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!