Define and manage policy set bindings
Policy set bindings contain platform specific information, like keystore, authentication information or persistent information, required by a policy set attachment. Use this task to create and manage bindings.
In Version 7.0 and later, there are two types of bindings, application specific bindings and general bindings.
Application specific bindings
We can create application specific bindings only at a policy set attachment point. These bindings are specific to and constrained to the characteristics of the defined policy. Application specific bindings are capable of providing configuration for advanced policy requirements, such as multiple signatures; however, these bindings are only reusable within an application. Furthermore, application specific bindings have very limited reuse across policy sets.
When creating an application specific binding for a policy set attachment, the binding begins in a completely unconfigured state. We must add each policy, such as WS-Security or HTTP transport, to override the default binding and fully configure the bindings for each policy that we have added. For WS-Security policy, some high level configuration attributes such as TokenConsumer, TokenGenerator, SigningInfo, or EncryptionInfo might be obtained from the default bindings if they are not configured in the application specific bindings.
For service providers, we can only create application specific bindings by selecting Assign Binding > New Application Specific Binding for service provider resources that have an attached policy set. See service providers policy sets and bindings collection. Similarly, for service clients, we can only create application specific bindings by selecting Assign Binding > New Application Specific Binding for service client resources that have an attached policy set. See service client policy set and bindings collection.
General bindings
General bindings were introduced in Version 7.0. These bindings can be configured to be used across a range of policy sets and can be reused across applications and for trust service attachments. Though general bindings are highly reusable, they are however not able to provide configuration for advanced policy requirements, such as multiple signatures. There are two types of general bindings:
- General provider policy set bindings
- General client policy set bindings
We can create general provider policy set bindings by accessing Services > Policy sets > General provider policy set bindings > New in the general provider policy sets panel or by accessing Services > Policy sets > General client policy set bindings > New in the general client policy set and bindings panel. See defining and managing service client or provider bindings. General provider policy set bindings might also be used for trust service attachments.
Important: The general bindings that are shipped with the product are provider and client sample bindings. These bindings are initially set as the cell default bindings. Do not use these bindings in their current state in a production environment. To use the sample bindings, modify them to meet the security needs in a production environment. Alternatively, create a copy of the bindings and then modify the copy. For example, change the key and keystore settings to ensure security, and modify other settings to match the environment. We must also configure the username and password for Username or LTPA token authentication. See the topic Configuring the username and password for WS-Security Username or LTPA token authentication for more information.
Depending on the assigned security role when security is enabled, you might not have access to text entry fields or buttons to create or edit configuration data. Review the administrative roles documentation to learn more about the valid roles for the application server.
To view or work with the current policy sets bindings, perform the following:
- To view the current policy set and application specific bindings from the administrative console, click Services > Policy sets > Application policy sets >policy_set_name > Attached applications and then click an application.
Depending on the application selected, we can manage the bindings attached to the following policy sets:
- Service provider policy sets and bindings
- Service client policy sets and bindings
To learn more about managing the bindings attached to policy sets, see the service provider or service client policy sets and bindings information.
Sort on the Attached policy set column on either of the policy sets and bindings pages to select the service resources with the same policy set attached. Likewise, sort on the Binding column to select the service resources that share the same custom binding to attach to a different policy set. If we sort on the Policy Set or the Binding column, the hierarchical relationship of the service resources in the first column is not accurate. We can sort again on the Application/Service/Endpoint/Operation column to restore the hierarchical relationship. The entries in the Application/Service/Endpoint/Operation column display in ascending order.
- To work with an existing bindings from the administrative console, click Services > Policy sets > Application policy sets >policy_set_name > Attached applications. Click an application name, and then click either the Service provider policy sets and bindings or the Service client policy sets and bindings. Then click a binding name in the Bindings column of the table.
If no applications appear when you click Attached applications, we do not have any applications attached to the selected policy set. To attach a policy set and binding to an application using the administrative console, click Applications > Enterprise Applications > application name. Then, click either Service provider policy sets and bindings or Server client policy sets and bindings to attach resources to the policy set and to assign bindings. .
- [Optional] To work with general bindings, click Services > Policy sets > General client policy set bindings or Services > Policy sets > General provider policy set bindings.
We can complete the following actions for general bindings:
- Import policy set bindings using the administrative console
- Export policy sets bindings settings
- Define and manage service client or provider bindings
- Create new or configuring existing general binding settings
- Copy policy set binding settings
- Delete policy set bindings
Results
When you finish this task, you would have performed one or more of the following:
- Created an application specific or general policy set binding
- Imported a policy set binding
- Exported a policy set binding
- Deleted a policy set binding
- Modified an application attachment to apply an application specific binding for single security domain
- Modified an application attachment to apply an application specific binding for multiple security domain
Subtopics
- Import policy set bindings using the administrative console
We can import predefined client or provider policy set bindings using the administrative console.
- Web services policy set bindings
A set of bindings is a named object that is associated with a specific policy set and service resource that is attached to the policy set.
- Define and manage service client or provider bindings
Service client or provider bindings are general bindings. We can create, copy, and manage general bindings such as the client or provider policy set bindings. These bindings provide system-specific configuration and can be reused across policy set attachments.
- Export policy sets bindings settings
This task only applies to general client or provider bindings. Use this page to export either a client or provider policy set binding for reuse.
- Copy policy set binding settings
Use this page to view and copy general policy set bindings for either a single security or a multiple security domain environment.
- Delete policy set bindings
Use this task to delete general policy set bindings using the administrative console.
- Create application specific bindings for policy set attachment
After you attach a policy set to a service artifact such as an application, service, or endpoint, we can define application specific bindings for the attached policy set.
- Set server default bindings for policy sets
We can set server default bindings if we want the policy set attachments for service providers and clients that are deployed to the server to use bindings that are different than those specified for the cell. If we use multiple security domains, your default server bindings will also override the security domain default bindings.
- Set default policy set bindings
We can set provider and client default policy set bindings used as the global security default policy set bindings. The specified global security default bindings apply to all web services unless the bindings are overridden at the attachment point, at the server, or at a security domain.
- Modify default bindings at the server or cell level for policy sets
We can define default bindings for HTTP transport, JMS transport, SSL transport, WS-Addressing, WS-ReliableMessaging, and WS-Security policies.
- Reassigning bindings to policy sets attachments
After creating a custom attachment binding, we can reassign that binding to another service artifact if necessary. We can reset a service artifact, such as an application, service, or endpoint to use the inherited bindings or default bindings.
- Policy set bindings settings
Use this page to view or define general, application specific, or trust service specific bindings configuration information for policies that we can associate with the selected policy set. This bindings configuration information is specific to a system. Use the links on this page to work with bindings for each specific policy.
- Web Services Addressing policy set binding
Use this page to modify the endpoint reference binding for Web Services Addressing (WS-Addressing). The product enforces this binding on JAX-WS web service applications that use WS-Addressing. This panel applies only to the WAS Network Deployment version of the product.
Create new or configuring existing general binding settings Keys and certificates WS-Security authentication and protection Administrative roles Service client policy set and bindings collection Service provider policy sets and bindings collection