Use Policy Frameworks to Enforce Web Service Requirements with WS-Policy

Jeffrey Hasan · Apress eBooks · 2004

Service-Oriented Web Services enforce specific usage requirements that clients must meet in order to use the service. Web services cannot simply respond to any request that comes in. Instead, they must be selective and can only process incoming requests that conform to their stated requirements. For example, a Web service may require that all incoming service requests be digitally signed and encrypted. Furthermore, a Web service may specifically require that the digital signature be based on an X.509 certificate, rather than another type of security token. Clients that send nonconforming service requests to the Web service, such as unsigned, unencrypted requests, will receive a SOAP fault as their response message.

Read the paper · More papers on PaperTik