943,681 Members | Top Members by Rank

Nov 12th, 2008
0

security in SOAP

Expand Post »
Hello,

I would like to clarify one thing about SOAP security. My situation is like this:

there is a web service server and some web service clients that I need to bring up using SOAP. This web service will only be used with my own clients and, perhaps some other clients written by third parties. Howver, all clients will connect directly to the web service. And I need this system secured. There will be no intermediary (no other third party) web services between clients and my own web service. I believe that in this scenario, there is no need for WS-Security features. To my mind, all it takes is https and some method for authentication and authoriazation. Please explain to me why this is not right (if it is not right, of course).

Thank you,
kellogs
Last edited by kellogs; Nov 12th, 2008 at 10:10 pm.
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
kellogs is offline Offline
1 posts
since Nov 2008
Nov 13th, 2008
0

Re: security in SOAP

You are correct that in many cases WS-Security has no advantage over simple SSL. Your case may be one of them. Note that WS-Security can still be helpfull in your situation from the following reasons:

- Flexibily for future changes. For example you might decide to use a non-HTTP transport in the future from performance reasons. WS-Security will still be valid - SSL not.

- Better tooling for authentication. I find it harder in some cases to use HTTP Basic authentication over WS-Security username profile.

<URL SNIPPED>
Web Services Security, Performance And Testing Blog


Click to Expand / Collapse  Quote originally posted by kellogs ...
Hello,

I would like to clarify one thing about SOAP security. My situation is like this:

there is a web service server and some web service clients that I need to bring up using SOAP. This web service will only be used with my own clients and, perhaps some other clients written by third parties. Howver, all clients will connect directly to the web service. And I need this system secured. There will be no intermediary (no other third party) web services between clients and my own web service. I believe that in this scenario, there is no need for WS-Security features. To my mind, all it takes is https and some method for authentication and authoriazation. Please explain to me why this is not right (if it is not right, of course).

Thank you,
kellogs
Last edited by peter_budo; Nov 13th, 2008 at 7:23 pm. Reason: Keep It On The Site - Do not manually post "fake" signatures in your posts. Instead, you may create a sitewide signature within the user control panel.
Reputation Points: 10
Solved Threads: 1
Newbie Poster
yaronn01 is offline Offline
3 posts
since Nov 2008

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in RSS, Web Services and SOAP Forum Timeline: RSS Feeds??
Next Thread in RSS, Web Services and SOAP Forum Timeline: Customising RSS to provide links onto ma website





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC