+

Search Tips   |   Advanced Search

Set encryption to protect message confidentiality at the server or cell level


The encryption information for the default consumer specifies how to process the encryption information on the receiver side if these bindings are not defined at the application level. WAS provides default values for the bindings. However, an administrator must modify the defaults for a production environment.

Configure the encryption information for the consumer binding on the server level and the cell level. In the following steps, use the first step to access the server-level default bindings and use the second step to access the cell-level bindings.

 

  1. Access the default bindings for the server level.

    1. Click Servers > Server Types > WebSphere application servers > server_name.

    2. Under Security, click JAX-WS and JAX-RPC security runtime.

      In a mixed node cell with a server using Websphere Application Server version 6.1 or earlier, click Web services: Default bindings for WS-Security

  2. Click Security > Web services to access the default bindings on the cell level.

  3. Under Default consumer bindings, click Encryption information.

  4. Click New to create an encryption information configuration, click Delete to delete an existing configuration, or click the name of an existing encryption information configuration to edit the settings.

    If creating a new configuration, enter a unique name for the encryption configuration in the Encryption information name field. For example, we might specify con_encinfo.

  5. Select a data encryption algorithm from the Data encryption algorithm field. This algorithm is used to encrypt the data. WAS supports the following pre-configured algorithms:

    The data encryption algorithm that you select for the consumer side must match the data encryption algorithm that you select for the generator side.

  6. Select a key encryption algorithm from the Key encryption algorithm field. This algorithm is used to encrypt the key. WAS supports the following pre-configured algorithms:

    If we select None, the key is not encrypted.

    The key encryption algorithm that you select for the consumer side must match the key encryption algorithm that you select for the generator side.

  7. Under Additional properties, click Key information references.

  8. Click New to create a key information configuration, click Delete to delete an existing configuration, or click the name of an existing key information configuration to edit the settings. If creating a new configuration, enter a unique name for the key information configuration in the name field. For example, we might specify con_enckeyinfo.

  9. Select a key information reference from the Key information reference field. This selection refers to the name of the key information used for encryption.

    See Set the key information for the consumer binding using JAX-RPC on the server or cell level.

  10. Click OK and Save to save the configuration.

 

Results

we have configured the encryption information for the consumer binding at the server or cell level.

 

Next steps

Specify a similar encryption information configuration for the generator.

 

Related concepts


Basic Security Profile compliance tips

 

Related tasks


Set encryption using JAX-RPC to protect message confidentiality at the server or cell level
Secure messages using JAX-RPC at the request and response consumers