| ||||
problem with WS-securityif hourglass model of web services is right (with the tightest point being WSDL abstract port types and concrete protocol bindings) then security clearly should be split into abstract part that is applied to portTypes and then another part that describes how abstract notions of security (identity, roles, rights etc.) are mapped into underlying protocols such as SOAP. WS-security seems to be much too SOAP specific without enough abstract part that could be applied to other protocols or different security mechanisms ...created sat nov 23 2002 6pm cst [2002/11/23 CST] permalink |
This blog is about: Find more
about
Blogroll:
Projects::
RSS
Filter Entries: |
Disclaimer: personal opinions and observations that may or may not be taken seriously, or even based on shared reality and generally are very unreliable and personal and snapshots of volatile writer mind ...
NOTE: THIS PAGE IS UNDER CONSTANT DEVELOPEMENT