Web Services Security

rameses.live.com's picture

Hi, Sorry if this post asks any simple questions, but I am very new.

I have a few web services which I would like to secure. Essentially, I want to ensure that the web service is being invoked only by a specified client. Is there a way to do this using certificates and SSL? The way I understand SSL is that SSL guarantees security at the transport level. I want to ensure that the client I am communicating with is who they say they are. In my case, the client will be a process on another known server. Currently, I am restricting access via a username and password.

Is there a way to encrypt the information sent and to send this information via SSL (i.e. the same web service must not be accessible over http)? I have not been able to find a definitive guide to doing this.

Thank you,

Rameses

nandika's picture

Re

You can use signing and encryption to achieve end to end security. Please have a look into the samples. Also search wso2.org library where you will find many articles on this. Regards Nandika
library project main code
Learn Cloud
Learn
Cloud

The WSO2 Application Server is a reliable application server that can host your enterprise web applications. The WSO2 Application Server as a Service is offered in StratosLive, the WSO2 Platform as a Service. This article explains how a simple web application can be developed and deployed from Carbon Studio to the WSO2 Application Server...

Latest Webinar
Different groups within an organization need to monitor different Key Performance Indicators (KPIs) - An operations team will be interested in the response times of business services and loads of each service,..
Thursday, February 9th 2012, 09.00 AM (PST)

Thursday, February 9th 2012, 10.00 AM (GMT)