Best way to secure web services


hello, reading wse.

the question simple, need secure nobody can put sniffer in middle see soap request body , headers in plain text.

as long know can done using ssl on internet information services.

so question why should go further , implement x509 certificates?

i recall argument encrypting sensitive portions of message, ws-security could offer improved performance compared encrypting traffic. try up, can find opposite argument.

holt adams @ ibm writes, "it's safe enabling security through ws-security technologies @ least twice cost of proving similar capabilities using traditional ssl http" (see best practices web services, part 9). may have misremembered this, i'll concede performance point.

the x509 approach still worth considering authenticating client server. of course, passwords may suffice purpose.

a few other relevant documents:

overview of web services security (bea)

securing applications use web services (msdn)

implementing ws-security (ibm)

ws-security standard (oasis)



Archived Forums A-B  >  ASMX Web Services and XML Serialization



Comments

Popular posts from this blog

Azure DocumentDB Owner resource does not exist

job syspolicy_purge_history job fail in sqlserver 2008

Trying to register with public marketplace error with 'Get-AzureStackStampInformation'