Skip to main content

By clicking Submit, you agree to the developerWorks terms of use.

The first time you sign into developerWorks, a profile is created for you. Select information in your developerWorks profile is displayed to the public, but you may edit the information at any time. Your first name, last name (unless you choose to hide them), and display name will accompany the content that you post.

All information submitted is secure.

  • Close [x]

The first time you sign in to developerWorks, a profile is created for you, so you need to choose a display name. Your display name accompanies the content you post on developerworks.

Please choose a display name between 3-31 characters. Your display name must be unique in the developerWorks community and should not be your email address for privacy reasons.

By clicking Submit, you agree to the developerWorks terms of use.

All information submitted is secure.

  • Close [x]

Updated: Web Services Security Policy Language

Contributors:  IBM, Microsoft, RSA Security, VeriSign

Summary:  The recently updated Web Services Security Policy Language (WS-SecurityPolicy) specification indicates the policy assertions which apply to Web Services Security: SOAP Message Security, WS-Trust, and WS-SecureConversation.

Date:  13 Jul 2005 (Published 18 Dec 2002)
Level:  Advanced

Activity:  6595 views
Comments:  

The recently updated Web Services Security Policy Language (WS-SecurityPolicy) specification indicates the policy assertions which apply to Web Services Security: SOAP Message Security, WS-Trust, and WS-SecureConversation.

With the re-publication of the WS-SecurityPolicy specification, IBM, Microsoft, and 12 co-authors are committing to submit it and two other security specifications to a worldwide standards body in September. The commitment is a key action on completing the Web Services Security framework and Web Services Security roadmap that IBM and Microsoft created in 2002 to help the industry produce and implement a standards-based architecture that is comprehensive, yet flexible enough to meet the Web services security needs of businesses (see Resources).

Web services are a loosely-coupled, language-neutral, platform-independent way of linking applications within organizations, across enterprises, and across the Internet. A key benefit of the emerging Web services architecture is the ability to deliver integrated, interoperable solutions -- which makes it critical to ensure the integrity, confidentiality, and overall security of these services.

The recently updated Web Services Security Policy Language (WS-SecurityPolicy) specification defines a set of security policy assertions which apply to Web Services Security: SOAP Message Security, WS-Trust, and WS-SecureConversation. This document takes the approach of defining a base set of assertions that describe how messages are to be secured. Flexibility with respect to token types, cryptographic algorithms, and mechanisms used, including using transport-level security, is part of the design and allows for evolution over time. The intent is to provide enough information for compatibility and interoperability to be determined by Web services participants, along with all information necessary to actually enable a participant to engage in a secure exchange of messages.

Get the specification and related material

DescriptionDateAccess method
Web Services Security Policy Language V1.1 specification (PDF, 755 KB)July, 2005HTTP download
WS-SecurityPolicy XSD July 2005HTTP Web page

If you would like to contribute technical comments on this specification, please do so through our Feedback page.

The following three specifications will be submitted to OASIS (Organization for the Advancement of Structured Information Standards):

  • WS-SecurityPolicy: Defines general security policy assertions which apply to Web Services Security: SOAP Message Security, WS-Trust, and WS-SecureConversation.

  • WS-Trust: Defines extensions that build on WS-Security to both provide a framework for requesting and issuing security tokens and broker trust relationships.

  • WS-SecureConversation: Defines extensions that build on WS-Security and WS-Trust to provide secure communication across one or more messages. Specifically, this specification defines mechanisms for establishing and sharing security contexts and for deriving keys from established security contexts (or any shared secret).

If you would like to view the earlier version of this specification, click on the following link:


Resources

Comments



Help: Update or add to My dW interests

What's this?

This little timesaver lets you update your My developerWorks profile with just one click! The general subject of this content (AIX and UNIX, Information Management, Lotus, Rational, Tivoli, WebSphere, Java, Linux, Open source, SOA and Web services, Web development, or XML) will be added to the interests section of your profile, if it's not there already. You only need to be logged in to My developerWorks.

And what's the point of adding your interests to your profile? That's how you find other users with the same interests as yours, and see what they're reading and contributing to the community. Your interests also help us recommend relevant developerWorks content to you.

View your My developerWorks profile

Return from help

Help: Remove from My dW interests

What's this?

Removing this interest does not alter your profile, but rather removes this piece of content from a list of all content for which you've indicated interest. In a future enhancement to My developerWorks, you'll be able to see a record of that content.

View your My developerWorks profile

Return from help

static.content.url=http://www.ibm.com/developerworks/js/artrating/
SITE_ID=1
Zone=SOA and web services
ArticleID=153090
SummaryTitle=Updated: Web Services Security Policy Language
publish-date=07132005