13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

WS-<strong>Security</strong> describes enhancements to SOAP messaging to provide quality ofprotection through message integrity, message confidentiality, and singlemessage authentication. These mechanisms can be used to accommodate awide variety of security models and encryption technologies.WS-<strong>Security</strong> also provides a general-purpose mechanism for associatingsecurity tokens with messages. No specific type of security token is required byWS-<strong>Security</strong>. It is designed to be extensible, for example, to support multiplesecurity token formats, or in the case of a client providing proof of identity andproof of a particular business certification.Additionally, WS-<strong>Security</strong> describes how to encode binary security tokens. Thespecification describes how to encode X.509 certificates and Kerberos tickets aswell as how to include opaque encrypted keys. It also includes extensibilitymechanisms that can be used to further describe the characteristics of thecredentials that are included with a message.Web Services security specificationsWS-<strong>Security</strong> only provides the foundation for other security specifications.Layered on this, we have a policy layer model (WS-Policy), a trust model(WS-Trust), and a privacy model (WS-Privacy). These specifications provide uswith the foundation to establish secure interoperable Web Services across thedomain. The follow-on specifications include secure conversation(WS-SecureConversation), federated trust (WS-Federation), and authorization(WS-Authorization). All these specifications should provide security frameworkspecifications related to auditing, management, and privacy.Follow-On SpecificationsWS-SecureConversationWS-FederationWS-AuthorizationInitial SpecificationsWS-<strong>Security</strong>SOAP FoundationWS-Policy WS-Trust WS-PrivacyWS-<strong>Security</strong>SOAP FoundationFigure 7-14 Web Services security specificationsThe following sections will provide more details on the initial specifications.WS-PolicyWS-Policy describes the capabilities and constraints of the security policies onintermediaries and endpoints. This way, senders and receivers can define theirrequirements and capabilities.Chapter 7. Securing Enterprise Integration components 147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!