ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Web services need trust as well as standards

Vivienne Fisher, ZDNet Australia ZDNet Australia

Published: 05 Jul 2002 09:04 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Proposed Web services security specifications are to be submitted to an international standards body by some of the industry's major vendors. But is it enough to protect businesses against the threats?

The latest version of the Web Services Security (WS-Security) specification is being submitted to international standards body Organization for the Advancement of Structured Information Standards (OASIS) for it to oversee the development.

Late last month IBM, Microsoft and VeriSign announced they would submit the latest version of the WS-Security specification to OASIS for development, according to a briefing paper by analyst Gartner.

WS-Security allows systems to interoperate on a platform and language neutral manner, said Gartner.

Analysts are touting it as a good step towards standards, but warn that challenges remain.

"Web services have important security issues that remain unresolved," Ray Wagner, a research director at Gartner Research said in a First Take on the move. "Proposed Web services security mechanisms highly depend on the distribution of digital certificates, and the underlying trust that supports their use."

Wagner warns that lack of any guaranteed level of trust between enterprise Web service deployments represented a major stumbling block to widespread deployment beyond the enterprise. "This issue has slowed the acceptance of public key infrastructure for years and must be resolved for Web services to become ubiquitous beyond enterprise boundaries."

John Brand, senior programme director of electronic business strategies at industry analyst META Group, sees the WS-Security specifications as a good example of standards evolving over time.

However, Brand believes it may take longer than people are anticipating. He said the vendors are recognising that they have to be seen to be working together on specifications. "The whole principle of Web services is interoperability," he said. "Web Services Security is an interim step -- what we're ultimately going to see is a more secure network-based computing platform."

Brand doesn't think, at this stage, there is any reason for people not to use Web services based on lack of an integrated Web services security model. "Use existing tools, techniques, (and) methodologies and see how they can be applied to the benefits that Web services can provide."

Greta James, research director of application integration at Gartner Australasia, argues that one of the things which has really been holding Web services back is lack of security standards.

"To have IBM and Microsoft agree on (the WS-Security) standard and put it forward to OASIS is a huge step," James said.

Other vendors, among which are Baltimore Technologies, BEA Systems, Cisco Systems, Intel, Novell, RSA Security, and Sun Microsystems have said they would participate in OASIS development effort, according to Gartner.


More enterprise IT news in ZDNet UK's Tech Update Channel.

For a weekly round-up of the enterprise IT news, sign up for the Tech Update newsletter.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
59 out of 110 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

SAP Project Director

To be successful within the SAP Project Director role you will require the following key competencies; - Proven experience of winning and managing ...

Procurement Manager, Cost Control, Bid Management, Telecoms, London

You will report to the Director of Supplier Management & he must be able to trust to you, as he will delegate some of his work to you e.g.meeting new ...

NHS Programme Manager PCT Experience Required

To set and manage financial and delivery expectations with end users and other senior officers within each customer trust. To deputise for the ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling