Web Services Security Confusion

Julia Lerman reminds me of trying to explain XML encryption and digital signatures through a translator to a Japanese audience last year. I got mixed up at some point and was having a tough time getting back on track, with the added worry of how it was all coming across in translation.

The sad part is that the general audience for WSE and Web Services development has to know about these details right now. My opinion is that the WS-* specifications should be just as hidden as the TCP/IP stack to most developers. If you need to know, you can get at the details, but most just need to be building business services - not worrying about how a public/private key encryption scheme work. Hopefully, we'll soon have a toolkit where developers can worry about business value and not plumbing.

In the meantime, we have courageous speakers like Julia and Michele to explain it to the masses. There's also John Bristowe's WSE FAQ.

 

Print | posted on Friday, November 12, 2004 3:52 PM

Feedback

# re: Web Services Security Confusion

left by Julie Lerman at 11/12/2004 4:46 PM Gravatar
Although I agree with you on some level, I think that many people will feel more empowered by understanding some of what's going on beneath the covers.

# re: Web Services Security Confusion

left by Julie at 11/12/2004 5:50 PM Gravatar
oh - and actually with the part of the settings tool to that does policies, the plumbing is 99% hidden. But there are two caveats with it. 1) if something goes awry, people who don't know anything more than how to click the check boxes will be in deep doo doo and 2) it exposes only a few (though the most important) features of ws-policy.

# re: Web Services Security Confusion

left by Drew Robbins at 11/12/2004 8:29 PM Gravatar
Agreed. Early adopters feel empowered by whats going on beneath the covers. But I think the majority later in the adoption lifecycle are terrified by whats beneath the covers. They just want to know it works and that it solves a challenge/problem they have.

Successfully deploying a service using WSE today means a highly-skilled resource is going to be involved and have control over most of the deployment factors. In other words, they will be installing or configuring the software and the infrastructure or have a lot of influence over it.

# re: Web Services Security Confusion

left by Julie at 11/12/2004 8:53 PM Gravatar
*that* is a great way to look at it, Drew. Oh, are you going to be a fantastic RD!! :-)
Title  
Name
Email (never displayed)
Url
Comments   
Please add 7 and 2 and type the answer here: