The WSIT Tutorial

Summary of Service-Side Configuration Requirements

Table 7–1 summarizes the options that need to be configured for each of the security mechanisms. Each of the columns is briefly discussed after the table.

Table 7–1 Summary of Service-Side Configuration Requirements

Mechanism 

Keystore 

Truststore 

STS 

SSL 

User in GlassFish 

Username Authentication with Symmetric Keys 

X 

     

X 

Mutual Certificates 

X 

X (no alias) 

     

Transport Security 

     

X 

X 

Message Authentication over SSL - Username Token 

     

X 

X 

Message Authentication over SSL - X.509 Token 

 

X (no alias) 

 

X 

 

SAML Authorization over SSL 

X 

X (no alias) 

 

X 

 

Endorsing Certificate 

X 

X 

     

SAML Sender Vouches with Certificate 

X 

X (no alias) 

     

SAML Holder of Key 

X 

X (no alias) 

     

STS Issued Token 

X 

X 

X 

   

STS Issued Token with Service Cert. 

X 

X 

X 

   

STS Issued Endorsing Token 

X 

X 

X