+

Search Tips   |   Advanced Search

Security considerations for web services

There security concerns that arise when we are securing web services.

In WebSphere Application Server, when we enable integrity, confidentiality, and the associated tokens within a SOAP message, security is not guaranteed. This list of security concerns is not complete. We must conduct our own security analysis for the environment.

Secure web services involves more work than just enabling XML digital signature and XML encryption. To properly secure a Web service, we must have knowledge about the PKI. The amount of security needed depends upon the deployed environment and the usage patterns. However, there are some basic rules and best practices for securing web services. IBM recommends reading some books on PKI and also read information on the Web Services Interoperability Organization (WS-I) Basic Security Profile (BSP).


Related:

  • Overview of standards and programming models for web services message-level security
  • Time stamp
  • Basic Security Profile Version 1.0