There are a considerable number of options available to architects and developers when it comes to Web service security. The WEB SERVICE SECURITY guide helps developers and architects make the most appropriate security decisions in the context of the solution's requirements. This asset contains reliable, accurate guidance on how to design and implement secure Web services.
Chapter 1 Introduction
Overview
Common Scenarios
Core Web Service Security Patterns
Chapter 2 Authentication Patterns
Introduction
Direct Authentication
Brokered Authentication
Brokered Authentication: Kerberos
Brokered Authentication: X.509 PKI
Brokered Authentication: Security Token Service (STS)
More Information
Chapter 3 Message Protection Patterns
Introduction
Data Confidentiality
Data Origin Authentication
More Information
Chapter 4 Implementing Transport and Message Layer Security
Introduction
Implementing Direct Authentication with UsernameToken in WSE 3.0
Implementing Message Layer Security with Kerberos in WSE 3.0
Implementing Message Layer Security with X.509 Certificates in WSE 3.0
Implementing Message Layer Security with a Security Token Service (STS) in WSE 3.0
References for Transport Layer Security
More Information
Additional Web Service Security Patterns and Guidance
Chapter 5 Resource Access Patterns
Introduction
Trusted Subsystem
Protocol Transition with Constrained Delegation Technical Supplement
More Information
Chapter 6 Service Boundary Protection Patterns
Introduction
Message Replay Detection
Implementing Message Replay Detection in WSE 3.0
Message Validator
Implementing Message Validation in WSE 3.0
Exception Shielding
Implementing Exception Shielding
More Information
Chapter 7 Service Deployment Patterns
Introduction
Perimeter Service Router
Implementing Perimeter Service Router in WSE 3.0
More Information
Chapter 8 Technical Supplements
Introduction
Kerberos Technical Supplement for Windows
X.509 Technical Supplement
More Information
Appendix Appendix
Introduction
Problem/Solution Index
WSE 3.0 Security: Interoperability Considerations
Policy Advisor for WSE 3.0
Patterns: A Common Vocabulary for Information Technology Professionals
Glossary
References
Appendix Bibliography
General Information
Chapter 1, "Authentication Patterns"
Chapter 2, "Message Protection Patterns"
Chapter 3, "Implementing Transport and Message Layer Security"
Chapter 4, "Resource Access Patterns"
Chapter 5, "Service Boundary Protection Patterns"
Chapter 6, "Service Deployment Patterns"
Chapter 7, "Technical Supplements"
Appendix
Community Workspace and Wiki
Appendix Patterns & Pratices
Title:
Web Service Security: Scenarios, Patterns, and Implementation Guidance for Web Services Enhancements (WSE) 3.0
Founded in 1975, Microsoft® is the worldwide leader in software, services, and solutions that help people and businesses realize their full potential. Since 1988, Microsoft has been building accessibility options right into its products to enable everyone to personalize their PCs to make them easier and more comfortable to see, hear, and use.