Home > SOA Tips > XML Developer > XML and security
SOA Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

XML DEVELOPER

XML and security


Ed Tittel
08.14.2002
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


There's a growing body of XML-related security work underway, pieces and parts of which I've covered in previous tips in this series. Wishing for a single, coherent narrative that describes all of them in one place, I optimistically typed "XML Security tutorial" into my favorite search engine to see what popped up. The lone result (though there are plenty of other good resources on this subject) is the topic of this week's tip.

Vordel is a Web and XML services security company based in Ireland, with a strong UK and US presence. Its tutorial on XML security is a pretty useful document, and a worthy starting point for anyone interested in exploring this fascinating subject. You'll find the following subjects covered in this document:

  • XML Signatures
  • XML Encryption
  • XML Key Management Specification (XKMS)
  • XML Key Information Service Specification (X-KISS)
  • XML Key Registration Service Specification (X-KRSS)
  • Security Assertion Markup Language (SAML)
  • Extensible Access Control Markup Language (XACML)

The explanations are simple, direct, and easy to follow, which is great for getting somebody started down the road toward understanding important work underway on XML security topics.

That said, it's equally important to ask "What's missing from this document?" I could go on at length about this, but without dinging its useful content in any way, the short answer is "Context and pointers." Acronyms are used without expansion or explanation, and nowhere will you find links to related specifications, articles, and so forth. Fortunately, Robin Cover's wonderful "Cover Pages" Web site can remedy these lacks in a heartbeat (for those not already in the know, this site is one of the great resource treasure troves in the XML world, and should be included in any serious markup professional's favorites or bookmark lists). I found the combination of the Vordel piece, and the search function on Cover's site was able to produce immediate acronym expansions and pointers to relevant standards, specficiations, working papers, and so forth just by cutting from the Vordel piece and pasting into the search window in the Cover site. Talk about "the whole is greater than the sum of its parts!"

For those interested in learning more on this topic, or in getting others started down that road, this combination is nearly unbeatable, and downright informative. Enjoy!


Ed Tittel is a principal at LANWrights, Inc., a wholly owned subsidiary of LeapIt.com. LANWrights offers training, writing, and consulting services on Internet, networking, and Web topics (including XML and XHTML), plus various IT certifications (Microsoft, Sun/Java, and Prosoft/CIW).


Rate this Tip
To rate tips, you must be a member of SearchSOA.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
XML
National Weather Service policy supports XML
XML and democracy at work: The Election Markup Language (EML)
For interesting interface access, check out Xamlon
Royalty-free, revolutionary UBL
Altova strikes again with MapForce 2005
Beating the RSS crunch with aggregation/bloglines
Voice, speech, SIP, and XML: ECMA-269
Microsoft Baseline Security Analyzer and XML
An open source, native XML database: dbXML 2.0
Second-generation XML security preview: SAML

XML Developer
WSDL 2.0, new messaging for Web services
Using RELAX NG For data integration
Efficient XML Interchange tackles data verbosity
XML to DDL imports, synchronizes database schemata
The basics of MathML 3.0
Migrating to XSLT 2.0
What's up with XML 2.0?
Say hello to XPath 2.0
Podcasting software covers many bases
The XML behind podcasting

XML and XML schema
What's new at the W3C
Lock-in, security loom as dark side of Compute Cloud
Ganymede: Modeling tools target SOA, UML
Data services mashups emerge for SOA
Making sense of data services mashups
XML turns 10
SOA helps save 100-year-old business
Oracle maps heterogeneous data services strategy for SOA
Handling XML with Ajax
Efficient XML draft published

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
class diagram  (SearchSOA.com)
Fast Infoset (FI)  (SearchSOA.com)
GeoRSS  (SearchSOA.com)
Keyhole Markup Language  (SearchSOA.com)
RELAX NG  (SearchSOA.com)
state diagram  (SearchSOA.com)
Universal Business Language  (SearchSOA.com)
Vector Markup Language  (SearchSOA.com)
XML infoset  (SearchSOA.com)
XML pipeline  (SearchSOA.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



SOA Trends and Strategy - SOA Education, SOA Development, SOA Implementations
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2001 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts