• Post Reply
  • Bookmark Topic Watch Topic
  • New Topic

JAXWS and webservices Security question

 
Isuru Samaraweera
Ranch Hand
Posts: 54
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hi All,

If B2B webservices integration has to be done asynchronously and securely Cant we only rely on JAXWS and HTTP assuming message level security is applied?

Or do we need to go for jaxWS and HTTPS to achieve both transport level and message level security?


As per my understanding you can reduce some overhead by only allowing message level security through Jaxws and Http.

Please clarify.

Thanks,
Isuru
 
Ulf Dittmer
Rancher
Posts: 42969
73
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
If B2B webservices integration has to be done asynchronously and securely Cant we only rely on JAXWS and HTTP assuming message level security is applied?

I don't understand the connection between B2B or any other kind of WS usage, asynchronicity and security. Can you elaborate how those fit together?

Or do we need to go for jaxWS and HTTPS to achieve both transport level and message level security?

What you need to do depends on your requirements. Generally I would say using both message-level security and transport-level security is not necessary; message-level security (which is preferable IMO) is sufficient.

As per my understanding you can reduce some overhead by only allowing message level security through Jaxws and Http.

Here, too, I'm not sure what you're trying to say. Can you rephrase it?
 
Isuru Samaraweera
Ranch Hand
Posts: 54
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hi Ulf,

Enabling https definitely slow down the application call.So message level security+http should provide adequate security and better performance over jaxws + https.

Thanks,
Isuru
 
Ulf Dittmer
Rancher
Posts: 42969
73
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I see no reason why one should generally be faster than the other. You would have to do timings of your particular architecture to make such a claim.
 
Isuru Samaraweera
Ranch Hand
Posts: 54
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hi Ulf,
Thanks for the reply.Lets converge to Jaxws and Http as the solution and wrap this thread.

Many thanks for the input.

Thanks,
Isuru
 
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic