ebxml-dev message

Subject: RE: [ebxml-dev] ebXML security

The list looks impressive. I am providing input on the possible existing standards/technologies
that could be plugged together in order to produce the necessary harmony between the various
actors for design and implementation of such an infrastructure. The current problem is the
existing standards are well defined within the domain they are used. E.g. The SAML specification
is focused on Single Sign-on and products (Oblix, Netegrity) that support them operate at the access layer
in a typical web service deployment. So when an organization wants to deploy such a security infrastructure, they
would already have these individual pieces (such as Single-Sign-On, Certificate Mgmt etc.) deployed and
the new security infrastructure should be able to leverage these.
The challenge here is to figure out which standard is offering what and can be leveraged and
then build the core layer that defines the union of these.
One thing surely lacking in the JAVA Web services pack and the kit is a good picture of how 
security is handled in JAVA for web services. Something like what the TrustBridge effort might do
for .NET.
-----Original Message-----
From: Douglas Nelson [mailto:douglas.nelson@sun.com]
Sent: Thursday, August 08, 2002 3:38 PM
To: ebxml-dev@lists.ebxml.org
Subject: [ebxml-dev] ebXML security

I would like to start a thread of security issues to discuss what features need to be included, interfaces, we would like to have and general discusses of each of the primary features. I am thinking the features should be available as web service and as an API possible an addition to the java core api's for web services. I would be interested in what you guys have thinking about security.  This first cut at the primary features,  you guys come up with any more, might include the following: Thanks Doug

