Web services security (WS-Security) specification has been out for more than a year now. However, the real life implementation of the technology has followed a slow pace, attempting to map the footsteps of Web services development. This session will present the WS-Security implementations currently in the Java community, as well as the trends and standardization in process. It provides a quick introduction to the various aspects of WS-Security, including the use and significance of key WS-Security concepts such as tokens, XML encryption, canonicalization, XML signature, and policy. It will briefly touch upon related security standards such as SAML, XACML, XrMS, Kerberos and XKMS, and other important aspects of Web services security such as single sign-on, federation and secure conversation. This paper will then provide examples of implementations of WS-Security by Web service tool vendors such as Apache AXIS, BEA WebLogic, IBM WebSphere, and Microsoft .NET. Detailed comparisons will be made with real-life demonstrations of interoperability between these platforms using WS-Security-enabled Web services.
http://dev2dev.bea.com/technologies/soa/xmlmessaging/articles/WS-Security.jsp
Web服务安全(WS-Security)规范已发布一年多,但技术落地缓慢。本文介绍Java社区中WS-Security的实现、趋势和标准化进程,涵盖其各方面概念,提及相关安全标准及重要方面,还给出工具厂商的实现示例,并进行平台间互操作性的详细对比。
720

被折叠的 条评论
为什么被折叠?



