WS-Security
WS-Security (Web Services Security) is a communications protocol providing a means for applying security to Web Services. On April 19 2004 the WS-Security 1.0 standard was released by Oasis-Open. On February 17 2006 they released version 1.1.
Originally developed by
The protocol contains specifications on how integrity and confidentiality can be enforced on Web
Services messaging. The WSS protocol includes details on the use of SAML and
Kerberos, and certificate formats such as
WS-Security describes how to attach signature and encryption headers to SOAP messages. In addition, it describes how to attach security tokens, including binary security tokens such as X.509 certificates and Kerberos tickets, to messages.
WS-Security incorporates security features in the header of a SOAP message, working in the application layer. Thus it ensures end-to-end security.
Associated specifications
The following draft specifications are associated with WS-Security:
- WS-SecureConversation
- WS-Federation
- WS-Authorization
- WS-Policy
- WS-Trust
- WS-Privacy
See also
- List of Web service specifications
- WS-I Basic Security Profile
- Web Services
- SAML
- XML firewall
- XACML
X.509
Alternative(s)
In point-to-point situations
Applying TLS can significantly reduce the overheads involved by removing the need to encode keys and message signatures into
External links
- OASIS Web Services Security TC (Contains links to download specification documents)
- WS-Security Specification
- WS-I Basic Security Profile
- Web Services Security Documentation
- Web Service Security Patterns
- WSS4J (WS-Security Java Implementation from Apache)
This entry is from Wikipedia, the leading user-contributed encyclopedia. It may not have been reviewed by professional editors (see full disclaimer)





