|
|
|

Rift Threatens Web Services Security Spec
By: Darryl K. Taft
2002-10-07
Article Rating:    / 0
There are 0 user comments on this Enterprise Applications story.
Rift Threatens Web Services Security Spec (
Page 1 of 2 ) An emerging rift among supporters of a proposed Web services security specification could slow the ratification of the standard and hamstring enterprises trying to settle on a way to make Web services transactions safer.
Microsoft Corp. and IBM, which, along with VeriSign Inc., published the original Web Services-Security specification, are now in two camps that have contrasting views over what should be done with the specification, also known as WS-Security.
The specification, which came under the control of OASIS, or Organization for the Advancement of Structured Information Standards, in June, defines a set of SOAP (Simple Object Access Protocol) message headers, which are designed to ensure Web services application integrity.
Microsoft, of Redmond, Wash., and companies such as Iona Technologies Inc., of Cambridge, Mass., which are members of OASIS WS-Security Technical Committee, want to push the specification through as is. They contend it is complete enough to give users the security they need now for Web services and can be improved later.
However, officials at IBM, Sun Microsystems Inc., Commerce One Inc., Entrust Inc. and Cisco Systems Inc., among othersand also part of the technical committeesaid they believe more needs to be added to the specification. A short list of additional features includes some form of extensions for WSDL (Web Services Description Language) that would enable developers to express how to control the level of encryption, the type of encryption and what gets encrypted. This faction is proposing a Quality of Protection working group to investigate what other additions the specification may need before being released.
"We need the ability to comprehensively control Web services security as it relates to specifying a Web service at design time using WSDL and at run-time using SOAP [and] WSDL," said Zahid Ahmed, XML Web services architect at Commerce One, in Pleasanton, Calif.
The WS-Security Technical Committee may discuss these issues in a conference call meeting this week.
|
|
x}r㶲s\@♵M푦d[kŶ,xMT(S$IVre oHKL&{Ɩpi Fh|GggD0 pE1>yΤ.w߽!dߛF0mTE[Ϡ^ȈZ#}wu9 ;;#|69߽w
A:|@vD)5'Ӡ5ߙ QcW6g2zʼn9m2fE63GE^QxyG`aFA<Q܇CѺ8QQw,8$ayc$aL$tobQY
)+Jd/B(?cs?C=|'Ț _h@a5w0vK]K_nCQeK֠}lv i!h
!gݻH͠L@d jI::`iTi11܋Hч(@g`wXSVP֣f̴;gu[gc=ױ}ǣ!&$fF=~0[QO+.m4ZI1'C8:)X ۱2˭]2 C}t;mgE-2GlRۄؼ?0}$OLE7
ؗY֍aEYh@YZkuE9,}hUm8e2-Q}/sj_.;gW([0u]+i0n{'Owy@α{A~A7"DT*jZ*ΒDCa:b= uzP%oP~y)ڡVR\ꇣ$0L"AK3zĢ>Q}?M-~k~>EF,sA4
衊Ġ+W:k֟19zqszr|qӹ54Y09;R^ٗ{$NWm2
ǣ1)H|S: Y t7QZ,/dR&rZ~@X*V QhF5
x%2ȌcPutC;H}ƚNmҔ
)B!aF`u{n5
@̀kfkPXT`k4R 9lbvfyM)odr!CUCZ9nVȨ9ESAEI7CD r<#|!XsI((Gc{fws
9tepv}^nVՉ:YX[u5fjZnY?iYw9yn?^OH{⧋vІ%F
,I!e%VG%UGVݏUU*P\?,CEe_U
8ʕ85n!S[ö@.s+(~>(#@>O=51m;>D#ʠ:괱b{\gf&hC:}ҍ:LZ wbH[
sX >$n탊J$>6ZЉχ˦MfB:{ǻښA"(QС4}мayjQ]*~s`=d}
w,߃9#馥MT<ģ|D }p
C|'s\(L7^"2(%%E2 DEMi@(P!$-4`r-lbo(OHXZp։p
T6=H:w&@T*es㕰RN飲B^/_
2[3CE外ɴh4Z*?ȉ#"09X
4gj
huc}\V5mZO4iMhȄ-Gn]]yel`aD%LEw\,OVXsq?7߀xEs;Jh`p=XͰ b՜兏e5dѬeB7g
Ʃ9
\
W?fx,qٛ:uVw]ˤF|a) lqF!
+=Ͱ'q\Ý =5q
؇å&|UzI2ۿi
|T!]\qαrB&k:H(A3bmy30e[
kKFM&WQ֙y)5_MT$3(Q2ӧLE+)I:3-h8E4W-{%ZdYj?EIT*{ەi]jk- RW7 Bʶb/άl0tjQtTV0RHH*6@\Z3-#%."?ԉW0ZOpSw{K5ǰ^\큢K*+G&,-s5^a5sv@d@h` DolvCbx5^zǎAs,\OTZ|mPTzP;u'JiX$l
M3r&\$(e8,[b){Wб3a|ec;meKKq>OmV!҇ {LrCmPǦ"}Zd!ӮW+,Z!?ՊRR$' q/#Y
hTر,>1h}6[u{ABWMKӞ#瀚bN!3pPS@1"N;/t/U#/Oј.#
{DTe6fMT_P-lt|pE% i4Q.)J5A)` L] TFSy0$u`m>(cpF,`^V.^@>C%%@Pб"FaK鬡aKUѫSOm{hAy-h\>,*'~Ö'"!hG=<6?fCU^f "ZTblxcCjvXVkoVX9)3KG0Ɓ3S\ ;u4-cge@o(@gf-!WAGUTe1_0י i̸T*I;D#w%
'L-`fQ=/YQmc18D"pLΨ'?x]@1pem`}ɲITёIeA:<ݐ늦ln`{Y0 >AC5"h!{3E6YҚ o;@+%5-|
?Ԋkt)D~d71SF
Mafk}YP~WּsAco^qLjB:GdH#PaNT:ɢ.1՟$PS*eYS!bW
hęf~g˪gayϤ͋|5]|l9sHNq采LksPsQ,V-03kF_H]'~4N_:&F}^D
ϓGjZ%1ߖ409EW|)3p35AaϘɗ玾_!c
JGx}n|/U;A9Xhb5FJ9ޥxP͜P7@y #kU^ qɕN_ 9{o$*,3 㪧RQu@V 3ˁ#_.QXz[VUe@5yH3m
9
=EZЋ1GKL.^8q?TYe)(@qc@@fuR/ʖpK%4e3/.9@غ<y}Hw▴Fu8X'̔-$h5%-QXu@j:U!neUuZ]J֟'auvLؙy(Fߋ]WeRTR33LMn@pOśn3A
|(U˚V*j٘ȅi0FPRyHP?l^*~
d>C `t>VX8'?lgH #
+S~!RHC+#I Uq gwPDR
f3 991t/x{qqwozՕݷ K
$^E1`w};W^^VCr|8Gq z}cq 2
}E\u@*v-?~<:m~71%|˾FIM $ȅXNpCfOճ2urҹ ]:layzp0\!9аQ^8K%y_;$˶u߽9$x!;.XG^9>oOM1fpRb^sF#w҃a++HH!u,5't^t%֓}q!qjP3:SwT+[Z\fłBAZ( @R`OH5['#N:JvZfp="BtX1ue}E/c)%Q\(HO,v>^8Q%l7 FWE'K;tu{-&2}m1џ.W`m%cIdnkf+eI'O{GH
y
?9/g!IB8Q(n1 xA\~j_iԎ(%T\
/?m[ė{,/=;SN$M(iatKb.ɔrJ4:<A2elO&y=%lQ1 i(KBi%l"C*]7'һj]npVPto6+Psa붱yx59*i(5~u.H>bG)-GH
T䵤
W[ɲ*$?vƇ!hqbwy~@0GW倜b{~T߯I;`=ұGE~#ѴNxMĉ#*qYBK+:Q CW./v6gFȢ&i{?d®%)A/gx9[RsrMδE{Omh_D(PQESrcW}0;*/"'=K$DÙ馍CL.I߾&3
+=F=g7omT2#|G$c:I"IQU֭EdU)I=Y)DW㻑)C^GxL_/@oǥ4LZ{~cqU~(R.o.˭\.s2ǵP#v%ދsq8́qV)"y6K`!jv.b5/vUL&mquOyc Om ?a"KrmG
?*4hgazS`gƅ=R3#@*yx\v]w71&pQx666y)1hTRwo7lf8w
F'FiOXw+O*?Wc#ޚU>9d/7wmf?/6FU)cqԴ'_ŕh
ʰ(1Q.Dw{{s
? 7E2>DǷQ)qvϩq_>Whjx(n|ڔ#N斸4\s
SŊ+7/ e1"Q(ջ)@I=II3LBaɼޏYy9dfo>Pm5K6w2d@c^h )UCV@r̳CL'
4侍c$nk'lE~0n!6YY a#.gνwV[&GpTAgt&qKJcuL5BS+aI,3,vT;ɒ.:$x֥&/˵\\ADq9*voW\H&P<e,>ɺD|_/"^%w[NOj:/]{)U<$^ Ute!+GP>0Y],-(!SSrO'}v9F6hR&/搠R$"d\ )Ƿ{.:xu}?ךx)RZ!F` KX|fWAGOKIն}IU%)]^.;}=TÒz>/HJ
PB(_=c𑒰Xڞ\ԍXKցe-9`XvȘFߚ,r(AaAB_92BEjRޔ*/ES.nOΨJS8¢$
CA D @
zqo1e"T$ucѴ|wԢ/U'9cRw
3Z5T'P?%snsR[JzDS{:GYk$^=le;>AhҙHG T ˗Xv8,A0@ !(Dw$Etyc ي<(S4-4$!- Қ/jC:}1#,-˜?|{B7xnI,wAݖḏ&G |