IBM WebSphere Application Server provides security infrastructure and mechanisms to protect sensitive Java EE resources and administrative resources, and addresses enterprise end-to-end security requirements on authentication, resource access control, data integrity, confidentiality, privacy, and secure interoperability.

Several communication links are provided from a browser on the Internet, through web servers and product servers, to the enterprise data at the back-end. Some typical configurations and common security practices are examined. WAS security is built on a layered security architecture. The security protection offered by each security layer and common security practice for good quality of protection in end-to-end security is also examined.


