In the (near) past, security was handled by the user interface. The user interface acted as the sole entry point to the application, and therefore all application security was oriented around user permissions. Added web services is like having great locks on your front door but opening all the windows in your house. Lots of entry points, each of which needs security. There’s a few basic enterprise web service security concepts that need to be understood to understand web service security. Web service security may operate from a user context, an application context, or both. User Context: Application 1 includes in the (web) service request to application 2 information about the user who performed an action causing the request. Application 2 then decides if the service is permitted based on the user requesting it in application 1. This requires applications 1 and 2 to have a common user security framework (application 2 has to recognize application 1’s user and b...
Enough hype! Real ROI - Let's put these technologies to work!