Managed Methods
Sign In
 SOA Security Enforcement 
     
SOA Security Enforcement


\
JaxView in Action
\

Download Literature

ZapThink on JaxView

Customer Case Studies

   

JaxView:  Centralize SOA Security Enforcement

Security remains an ongoing concern in SOA deployments:

  • Do your Web services apply security policies consistently?
  • Can changes to security policies be easily implemented across all services?
  • Do your developers lose productivity implementing security functions for individual services?

JaxView centralizes security management for Web services to save time and ensure consistent security implementation. JaxView removes the development overhead and reduces risk of error inherent in implementing and managing security functions on individual service interfaces. 

Single Point of Security Enforcement

Save implementation time and ease security management by using JaxView as a service proxy to check and enforce policies on XML message content. With JaxView, you can:
  • Authenticate and validate users and services requests
  • Enforce security policies for service access and usage
  • Automatically enforce security policy changes
  • Use JaxView XML gateway on the consumer side as a VPN and on the provider side as a XML firewall (below diagram)

  • JaxView delivers security for the first middle and last mile

    Extend Security to the First and Last Mile

    A frequently overlooked security risk is in the "last mile" - the application server itself. When deployed on the application server, JaxView is able to extend its security enforcement functionality to include the security policies on the application server - all the way to the last mile.

    Similarly, a service is not secure unless requests from the consumer are validated in the "first mile", before they interact with critical systems. JaxView is able to secure the initial consumer request, ensuring that only authentic requests reach your critical systems. 

    JaxView Features for SOA Security  

    When deployed as a service proxy, JaxView can be used as a policy enforcement point for centralized runtime governance of service-oriented environments. JaxView can also deploy small agents on the application server to enforce policies. Both deployment options include the following capabilities:

    Security Proxy and XML Firewall Functions

    Use JaxView as a service proxy or network intermediary component to enable centralized security for Web services and save implementation time and ease security management. This mode allows you to use JaxView to:
    • Authenticate users against LDAP and Identity Management Services
    • Map tokens using Secure Token Service (STS)
    • Authenticate and authorize consumers using Secure Token Service (STS)
    • Handle incoming and outgoing SSL/TLS handshakes
    • Block access to individual service operations based on consumer ip address
    • Support connections using X.509 certificates or Kerberos
    • Encrypt or decrypt XML message content for both request and response
    • Insert Digital signatures in the request or response xml payload.
    • Validate XML digital signatures and WS-Security headers
    • Block non-compliant service requests based on message content
    • Validation and insertion of SAML asserstions
    • Support for Windows Integrated Security in kerberos or NTLM
    • Allowing consumer access to the service based on ip address of the consumer
    • Integration with Identity providers such as CA SiteMinder, RSA ClearTrust, Oracle Access Manager, and Tivoli Access Manager using SAML assertions or Kerberos for Single Sign On Functionality

    Single Sign On

    Use the JaxView service proxy deployment option to integrate with both a variety of Identity providers or Service provider to generate tokens such as SAML tokens for session caching and Single Sign on functionality. JaxView can embed the token into the payload and also send the token back to the client application and manage sessions caching with expiration.

    Runtime Policy Enforcement Functions

    Use the JaxView service proxy deployment option to combine enforcement of automated policies on service access and usage with visibility into policy compliance. JaxView enables you to:

    • Block access to individual service operations based on time of day or date
    • Create and manage WS-Policy assertions using JaxView's internal repository and WS-Policy tools
    • Automatically update service and policy information from a UDDI-compliant registry
    • Monitor for policy compliance and compliance failures
    • Set daily or hourly limits on the number of service requests that are forwarded
    • Block service messages that exceed a certain size
    • Throttle messages
    • Apply protocol conversion (i.e.: JMS -> HTTP or vice versa) with an open API for all protocol customization

    Closed-loop Service and Policy Management Functions

    Increase your efficiency in managing services and runtime policies by integrating JaxView with a UDDI service registry. Use JaxView's bi-directional registry synchronization capability to:

    • Automatically query the service registry and update service information
    • Automatically configure new service monitoring configurations in JaxView by querying a service registry
    • Automatically query the service registry and update JaxView policy implementations
    • Create, update and manage policies through the JaxView interface
    • Export JaxView policy implementations as WS-Policy-complaint assertions to a UDDI registry
    • Automatically update the service registry with service information and policy changes made using the JaxView interface

    Web Service Policy Profiles

    JaxView enables you to create a set of policy profiles and assign them to a group of services as they are discovered. You can:

    • Create policy profiles once and assign them to a group of Web Services
    • Assign multiple policy profiles to a Web Service. As an example you can have one set of policies for internal consumers of the service and another set for external consumers of the service.

     

       

     

     

     


     




    JaxView Product Screen Shots

    Click on any of the images below to view a full-size screen shot.

    Main Console

     

    Message Summary Table

     

    Monitor Types

     

    Transactions

     

    Report Example

     

    Transaction Report

     

    NOC Console View

         
    Copyright © 2007-2008 Managed Methods
    JaxView: cost-effective Web Services and SOA runtime management solutions.