This article describes how to leverage the Web Services Security specification to secure an existing Web service. It demonstrates how to use message-level security (MLS) provided by Web Services Security in IBM WebSphere Application Server V5.0.2 to sign the message using X.509-based Digital Signatures for integrity, and how to encrypt the message using XML Encryption for confidentiality. It also demonstrates how to use both these provisions in tandem with transport-level security (TLS) provided by SSL/HTTPS. (Submitted by Anonymous Fri Apr 16, 2004 ) |