Table of Contents
- Title and Copyright Information
- Preface
- 1 Overview of Web Services Security
-
2
Configuring Message-Level Security
- Overview of Message-Level Security
- Main Use Cases of Message-Level Security
- Using Policy Files for Message-Level Security Configuration
- Configuring Simple Message-Level Security
- Updating a Client Application to Invoke a Message-Secured Web Service
- Example of Adding Security to a JAX-WS Web Service
- Creating and Using a Custom Policy File
-
Configuring the WS-Trust Client
- Supported Token Types
-
Configuring WS-Trust Client Properties
- Obtaining the URI of the Secure Token Service
- Configuring STS URI for WS-SecureConversation: Standalone Client
- Configuring STS URI for SAML: Standalone Client
- Configuring STS URI Using WLST: Client On Server Side
- Configuring STS Security Policy: Standalone Client
- Configuring STS Security Policy Using WLST: Client On Server Side
- Configuring the STS SOAP and WS-Trust Version: Standalone Client
- Configuring the SAML STS Server Certificate: Standalone Client
- Sample WS-Trust Client for SAML 2.0 Bearer Token Over HTTPS
- Sample WS-Trust Client for SAML 2.0 Bearer Token with WSS 1.1 Message Protections
- Configuring and Using Security Contexts and Derived Keys
- Associating Policy Files at Runtime
- Using Security Assertion Markup Language (SAML) Tokens For Identity
- Associating a Web Service with a Security Configuration Other Than the Default
- Valid Class Names and Token Types for Credential Provider
- Using System Properties to Debug Message-Level Security
- Using a Client-Side Security Policy File
- Using WS-SecurityPolicy 1.2 Policy Files
- Choosing a Policy
- Unsupported WS-SecurityPolicy 1.2 Assertions
- Using the Optional Policy Assertion
- Configuring Element-Level Security
- Smart Policy Selection
- Example of Adding Security to Reliable Messaging Web Service
- Securing Web Services Atomic Transactions
- 3 Configuring Transport-Level Security
-
A
Using Oracle Web Services Manager Security Policies
- Overview of OWSM Security Policies
- Attaching OWSM Security Policies to JAX-WS Web Services
- Attaching OWSM Security Policies to JAX-WS Web Service Clients
- Disabling a Globally Attached OWSM Policy
- Configuring Policies
- Overriding the Policy Configuration for the Web Service Client
- Monitoring and Testing the Web Service