member login

WebServices dot org

Todays Featured Content:

Layer 7 Technologies Announces Support for Solaris(TM) 10 on SPARC

Leading XML Security and Networking Vendor Adds Support for SPARC Platforms to Family of Products to Help Secure, Simply and Scale XML and SOA Deployments

Fast and Flexible Security Solutions for Cross-Domain Web Services Integrations

This paper presents general, benefit, and architectural information about the SecureSpan™ family of products.

A Practical Guide to Policy Authoring for SOA Governance

This Webcast, presented by Layer 7 CTO and WS-Policy co-editor, Dr. Toufic Boubez, will cover how to declaratively *define SOA Policy for SOA Governance applications.* Consistent, standards based policy definition is the first step in implementing an SOA Governance framework.

ZapForum Podcast: Understanding Identity & SOA

Learn what identity is and how it fits into SOA, understand the relationships between identity and governance and between identity and policy. Grasp the nature of federated identity, and the standards that support it

Featured Content provided by Layer 7 Technologies
iTKO Announces Release of LISA 4.5 SOA Testing, Validation & Virtualization Solution

Leading SOA Testing & Virtualization Platform Proven and Enhanced for Customer Needs, including new Service Virtualization Capabilities for High-Performance Implementations


Members Approve WS-Security v1.1 as OASIS Standard

Wednesday 15 February 2006

Actional, Adobe, AmberPoint, BEA Systems, BMC Software, CA, EMC, Forum Systems, Fujitsu, Hewlett-Packard, Hitachi, IBM, Intel, Microsoft, Neustar, Nokia, Oracle, Reactivity, RSA Security, SAP, Sun Microsystems, Tibco, VeriSign, and Others Collaborate to Advance Foundational Standard for Web Services Security

OASIS, the international e-business standards consortium, today announced that its members have approved WS-Security version 1.1 as an OASIS Standard, a status that signifies the highest level of ratification. Developed through an open process by the OASIS Web Services Security (WSS) Technical Committee, WS-Security delivers a technical foundation for implementing security functions such as integrity and confidentiality in messages implementing higher-level Web services applications.

"

Gartner analyst, Ray Wagner, advised, "Enterprises should adopt WS-Security formatting for all across-the-firewall Web service deployments, even in cases where no security needs have been identified. Gartner believes that WS-Security will be the standard for the majority of Web services, and committing to it now will allow enterprises to easily modify the security profile of deployed Web services in the future."

"

WS-Security builds on existing security technologies to deliver an industry standard way of securing Web services message exchanges. Providing a framework within which authentication and authorization take place, WS-Security lets users apply existing security technology and infrastructure in a Web services environment.

"

"We have made significant, but complementary, additions to WS-Security-many of which are the direct result of user feedback," said Kelvin Lawrence of IBM, co-chair of the OASIS WSS Technical Committee. "WS-Security v1.1 enhancements include extra profiles for Kerberos, the Security Assertion Markup Language (SAML) OASIS Standard, SOAP with Attachments and Rights Expression Language (REL)."

"
"

"The new release also enables secure, message-based Web services scenarios incorporating existing security technologies," added Chris Kaler of Microsoft, co-chair of the OASIS WSS Technical Committee. "Applications can share information on network access regardless of the underlying platform."

"
"

Patrick Gannon, president and CEO of OASIS, stated, "The OASIS WSS Technical Committee is a fine example of the open standards process, where the needs and interests of a broad base of constituents-large and small companies, vendors and users, private enterprises, multi-national corporations, and government agencies-are addressed to the benefit of all. We look forward to seeing adoption of this new level of WS-Security in the same way that the 1.0 standard was embraced."

"

The OASIS WSS Technical Committee remains open to new participation and particularly seeks input from those in the international community to advance WS-Security. All interested parties are encouraged to exchange information on implementing WS-Security via the wss-dev mailing list ( http://www.oasis-open.org/mlmanage/ ). As with all Consortium projects, archives of the OASIS WSS Technical Committee's work are accessible to both members and non-members, and OASIS hosts an open mail list for public comment on the standard.

Support for WS-Security

Forum Systems

"

"This is a significant step for the industry, since advanced Web services are not possible without capabilities such as the Kerberos Token Profile and SOAP with Attachments. Not unlike Secure Sockets Layer (SSL) for network communication, WS-Security will be the defacto standard for secure Application-Oriented networking," said Walid Negm, Vice President of Marketing, Forum Systems.

"

Fujitsu

"

"Fujitsu is pleased to see the new version of WS-Security become an OASIS Standard. We have been committed to the standardization of Web services technologies. With the addition of attachments support and other enhancements, the new standard will enable us to provide a wider range of solutions. This will help our customers realize secure systems based on Web services technologies," said Yasushi Ishida, Executive Architect, Software Unit, Fujitsu Limited.

"

Hitachi

"

"Hitachi is very pleased to see WS-Security v1.1 approved as an OASIS Standard. Initial reactions from the press and users when Web services was in its infancy was that the security issues would be so great to make practical deployment an impossibility. With the publication of WS-Security v1.1 as an OASIS Standard, the community at-large may be assured that the underlying tools necessary to secure Web services deployments are at hand and are practical. Usage of these standards and their composition with higher level protocols will form the basis of practical secure deployments. This inhibitor to deployment is now removed," said Takao Nakamura, Executive General Manager, Software Division, Hitachi, Ltd.

"

Microsoft

"

"Microsoft is excited to have collaborated with the co-authors of the WS-Security 1.1 specification. Its ratification as a standard is a significant milestone for Web services and the industry overall incorporating feedback from products deployed using the WS-Security 1.0 industry standard," said Chris Kaler, Security Architect at Microsoft Corp and co-chair of the OASIS Web Services Security Technical Committee. "WS-Security is a core component of the WS-* Web services architecture for secure, reliable and transacted Web services and is supported broadly across the industry. We look forward to continued adoption of the Web services standards, with the end goal of a common architecture for software interoperability."

"

Nokia

"

"Nokia is pleased to see the completion of WS-Security v1.1 as an OASIS Standard. Nokia has been an active contributor in creating this standard and believes it will benefit mobile Web services," said Frederick Hirsch, Senior Architect at Nokia. "WS-Security v1.1 is a major step forward in open standardization of the Web services stack, given the importance of interoperable security for Web services."

"

Oracle

"

"WS-Security v1.1 answers the need for secure authentication of Web services," said Prateek Mishra, director, Security Standards, Oracle. "Our work in the OASIS WSS Technical Committee demonstrates Oracle's commitment to bringing security standards to the market, incorporating them into our products, and passing along the benefits to our customers. We were pleased to work alongside other technology vendors to develop WS-Security v1.1, and look forward to helping to accelerate its adoption."

"

Reactivity

"

"The approval of WS-Security v1.1 as an OASIS Standard is critical to the future growth of Web services and service oriented architectures (SOA) that our enterprise customers are implementing," according to Andrew Nash, chief technology officer at Reactivity. "WS-Security standards enable our customers to do what matters most---building and deploying successful Web services and SOA projects that scale with the company as they add new partners, customers and services to their network."

"

Sun Microsystems

"

"Sun is pleased to participate in the evolution of WS-Security and to see it reach this important milestone. Through the OASIS process, other organizations, like the Liberty Alliance and WS-I, can reference this specification with confidence," said Bill Smith, director of business alliances at Sun Microsystems. "As part of Sun's objective to provide developers with the out-of-the-box tools they need to easily create identity-based security for their Web services applications, we look forward to broadening our support for WS-Security across the Solaris Enterprise System in products like Sun Java System Access Manager, Sun Java System Federation Manager and Sun Java System Application Server."

"

VeriSign

"

"WS-Security is already the industry foundation for adding security to Web services. The new WS-Security v1.1 standard is an important milestone that includes significant enhancements to the original specification. It also profiles and adds support for several new security token types, such as SAML, Kerberos, X.509 certificates, and others," said Siddharth Bajaj, director, Advanced Products and Research, VeriSign.

"

 

Additional information:

OASIS WSS Technical Committee
http://www.oasis-open.org/committees/wss

Cover Pages Technology Report
http://xml.coverpages.org/ws-security.html