13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

RequesterWebServiceFigure 7-18 Direct Trust using basic authentication and Transport-Level <strong>Security</strong>The client opens a connection to the Web Service using secure transport. Itsends its request and includes a security token that contains its username andpassword. The service authenticates the information, processes the request andreturns the result.Figure 7-19 Sequence of events for Scenario using In this scenario, the message confidentiality and integrity are handled usingexisting transport security mechanisms.Figure 7-19 shows the sequence of events for this scenario.1. The client opens a connection to the Web Service using a secure transportsuch as SSL.2. The client constructs a SOAP message. There is a element in the header, this element contains the client's usernameand password for the service. The password can be sent as plain textbecause the transport layer is secure.3. The message is sent to the service.4. The service extracts the element and validates the username and password.5. Since the validation succeeded, the service processes the request andreturns the result.Chapter 7. Securing Enterprise Integration components 151

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!