iTnews

Web services security finally grows up

By Robert Jaques on Apr 3, 2007 1:00PM
Web services security finally grows up

Gartner hails WS-SX ratification as key development.

Recent ratification of two key standards means that web services security has finally reached a level of maturity acceptable to many enterprises, Gartner has reported.

The analyst firm's comments come after the Organisation for the Advancement of Structured Information Standards (Oasis) approved two key web services security components as agreed standards.

The Oasis Web Services Secure Exchange Technical Committee formally ratified WS-SecureConversation version 1.3 for establishing and maintaining extended secure sessions.

In addition it passed WS-Trust version 1.3, for obtaining and exchanging security credentials.

The ratification moves web services secure messaging from basic and limited implementation to a more extended and contextual model, according to Gartner.

However, the real value of these standards lies in the benefits they can provide for implementations of brokered authentication or security token services (STS), the analyst firm believes.

Web services typically authenticate clients across heterogeneous environments, but removing the need for a direct relationship with the client application and web service through a "trust negotiator" requires robust security.

"The availability of these new standards means that web services security has finally reached an acceptable maturity level," noted a new Gartner analysis by analysts Earl Perkins and Ray Wagner.

"The issuance and dissemination of credentials between different trust domains via an STS can now be achieved using a syntax that is familiar to most developers.

"The Oasis standards also provide for a scalability that had not been available before in transactional web services that required an STS, at least not in a standardised form with which most vendors involved in SOA applications and infrastructure comply.

"This adds to a credible toolset for federation efforts, which has proved elusive to many enterprises due to the issues of brokered authentication availability and scalability the standards address.

"WS-Trust alone is vital to enabling the credential use necessary for networked, consumable web services."

The Gartner research noted that some early adopters of web services continue to believe that existing security standards are "bloated and overly complex" and have rolled out simplified proprietary offerings.

"For simple requirements, mixed web security and 'classic' authentication coupled with services will still have a place," said the Gartner report.

"Other early adopters believe that IBM's and Microsoft's view of web services and SOA security, and particularly their roles in the development of WS-SecureConversation and WS-Trust and the standards' place in their architectures, gives them an advantage in this area.

"However, the standards have enough diversity of support within the developer and infrastructure community that their ratification must be viewed as a positive development for vendor and enterprise customer alike."
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
finallygrowssecurityservicesupweb

Partner Content

"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Don't miss Australia’s premiere IoT Conference on 9th June
Promoted Content Don't miss Australia’s premiere IoT Conference on 9th June

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Robert Jaques
Apr 3 2007
1:00PM
0 Comments

Related Articles

  • Officeworks stands up its own enterprise identity platform
  • IMF, 10 countries simulate cyber attack on global financial system
  • WA gov creates cyber security uplift team
  • Student hacker behind ctx and phpass repo-jacking steps forward
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

What to expect from the incoming Labor government

What to expect from the incoming Labor government

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

Digital Nation

CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.