How to go about web service security in Java

Does anyone have a recommendation about web service security architecture in Java (preferably under JBoss)? Any recommended reading?

I want to expose a fairly rich web service to the world but the data are sensitive and it requires authentication from the current client (Flex), accessed via RPC. I definitely do not want any server-side session state.

What's the best way to go about implementing security through web services in Java/JBoss and where can I read about it?

Asked by: Adrian992 | Posted: 21-01-2022

Answer 1

You could try:

SOA Security

Answered by: Brianna162 | Posted: 22-02-2022

Answer 2

For web services security in JBoss, I would start by reading 8.4 WS-Security of the JBossWS User Guide.

Answered by: Oliver793 | Posted: 22-02-2022

Answer 3

WSSE is simple and works well.

Answered by: Justin576 | Posted: 22-02-2022

