|
Chapter 1 gives an in-depth overview of web services security from a business point of view, describing the security challenges in a web services environment, why traditional network security isn't enough, and how to measure the ROI on web services security.Chapter 2 discusses the architecture of web services security including the various interoperable standards, challenges in implementing web services security in .NET and Java applications, and the need for centralized policy definition and enforcement. Chapter 3 discusses the architecture of Oracle Web Services Manager. In this chapter, we explore the various components of Oracle WSM, such as gateway, agent, policy management, routing, monitoring, etc. Chapter 4 talks in-depth about how to implement authentication and authorization in web services using Oracle WSM. It explains how to define security policy and protect web services with a detailed step-by-step example. Chapter 5 discusses in-depth about encryption and decryption in web services and how to implement them using Oracle WSM with a detailed step-by-step example. This chapter also discusses how to test using a Microsoft .NET application and Oracle WSM test pages. Chapter 6 addresses the most important part of web services security: digital signature. In this chapter, you will learn how to define security policy to digitally sign and verify SOAP messages with a detailed step-by-step example. Chapter 7 discusses the internals of Oracle WSM policy manager and how to implement a custom policy with an example scenario and a step-by-step description. No matter what features the Oracle WSM product offers, there may be reasons why you might want to implement certain custom security policies. Chapter 8 discusses the deployment strategy, database options, high availability requirements and various options to deploy Oracle WSM. It is important that Oracle WSM is highly available to meet business needs. Chapter 9 discusses the requirements to monitor the availability of Oracle WSM, how to define and monitor the service level agreements, performance metrics, etc. Chapters 10 and 11 discuss the internals of XML encryption and XML signature standards and how they are used within WS-* security. Chapter 12 discusses how to combine both digital signature and encryption to ensure both confidentiality and integrity of the message. In this chapter, we will discuss how to implement sign and encrypt in Oracle WSM with a step-by-step example. Chapter 13 concludes the book with a discussion on Enterprise Security—web services and single sign-on and the need to bridge the gap between SSO products such as Oracle Access Manager and Oracle WSM with the introduction to security token service. Download free ebooks of oracle:Oracle Web Services Manager:Securing Your Web Services
|
Free database ebooks
Chapter 1 gives an in-depth overview of web services security from a business point of view, describing the security challenges in a web services environment, why traditional network security isn't enough, and how to measure the ROI on web services security.