13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

WS-Policy will be fully extensible and will not place limits on requirements andcapabilities that may be described. However, the specification will likely identifyseveral basic service attributes, encoding formats, security token requirementsand supporting algorithms. This specification will define a generic SOAP policyformat, which can support more than just security policies. This specification willalso define a mechanism for attaching service policies to SOAP messages.WS-TrustWS-Trust describes a framework for trust models that enables Web Services tosecurely interoperate. This establishes the model for both direct and brokeredtrust relationships.The WS-Trust specification will describe how existing direct trust relationshipsmay be used as the basis for brokering trust through the creation of securitytoken issuance services. These security token issuance services build onWS-<strong>Security</strong> to transfer the requisite security tokens in a manner that ensuresthe integrity and confidentiality of those tokens. This specification will alsodescribe how several existing trust mechanisms may be used in conjunction withthis trust model.Finally, the trust model will explicitly allow for, but will not mandate, delegationand impersonation by principals. Note that delegation is consistent withimpersonation, but provides additional levels of traceability.WS-PrivacyWS-Privacy describes a model for how Web Services and requesters statesubject privacy preferences and organizational privacy practice statements.By using a combination of WS-Policy, WS-<strong>Security</strong>, and WS-Trust, organizationscan state and indicate conformance to stated privacy policies. This specificationwill describe a model for how a privacy language may be embedded intoWS-Policy descriptions and into WS-<strong>Security</strong>.Web Services security modelA SOAP message acts as a requester to the Web Service and the response fromthe Web Service is also a SOAP message. So protecting the message contentfrom illegal access (confidentiality) or illegal modification (integrity) is the primarysecurity concern of Web Services.Today's Web Service application topologies include a broad combination ofmobile devices, gateways, proxies, load balancers, demilitarized zones (DMZs),outsourced data centers, and globally distributed, dynamically configuredsystems. All of these systems rely on the ability of message processing148 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!