WS-Security Version 1.1 an OASIS Standard
Members Approve WS-Security v1.1 as OASIS Standard
Actional, Adobe, AmberPoint, BEA Systems, BMC Software, Computer Associates, EMC, Forum Systems, Fujitsu, Hewlett-Packard, Hitachi, IBM, Intel, Microsoft, Neustar, Nokia, Oracle, Reactivity, RSA Security, SAP, Sun Microsystems, Tibco, VeriSign, and Others Collaborate to Advance Foundational Standard for Web Services Security
Boston, MA, USA. February 15, 2006.
OASIS, the international e-business standards consortium, today announced that its members have approved WS-Security version 1.1 as an OASIS Standard, a status that signifies the highest level of ratification. Developed through an open process by the OASIS Web Services Security (WSS) Technical Committee, WS-Security delivers a technical foundation for implementing security functions such as integrity and confidentiality in messages implementing higher-level Web services applications.
Gartner analyst, Ray Wagner, advised, "Enterprises should adopt WS-Security formatting for all across-the-firewall Web service deployments, even in cases where no security needs have been identified. Gartner believes that WS-Security will be the standard for the majority of Web services, and committing to it now will allow enterprises to easily modify the security profile of deployed Web services in the future."
WS-Security builds on existing security technologies to deliver an industry standard way of securing Web services message exchanges. Providing a framework within which authentication and authorization take place, WS-Security lets users apply existing security technology and infrastructure in a Web services environment.
"We have made significant, but complementary, additions to WS-Security-many of which are the direct result of user feedback," said Kelvin Lawrence of IBM, co-chair of the OASIS WSS Technical Committee. "WS-Security v1.1 enhancements include extra profiles for Kerberos, the Security Assertion Markup Language (SAML) OASIS Standard, SOAP with Attachments and Rights Expression Language (REL)."
"The new release also enables secure, message-based Web services scenarios incorporating existing security technologies," added Chris Kaler of Microsoft, co-chair of the OASIS WSS Technical Committee. "Applications can share information on network access regardless of the underlying platform."
Patrick Gannon, president and CEO of OASIS, stated, "The OASIS WSS Technical Committee is a fine example of the open standards process, where the needs and interests of a broad base of constituents-large and small companies, vendors and users, private enterprises, multi-national corporations, and government agencies-are addressed to the benefit of all. We look forward to seeing adoption of this new level of WS-Security in the same way that the 1.0 standard was embraced."
The OASIS WSS Technical Committee remains open to new participation and particularly seeks input from those in the international community to advance WS-Security. All interested parties are encouraged to exchange information on implementing WS-Security via the wss-dev mailing list (subscribe: http://www.oasis-open.org/mlmanage/). As with all Consortium projects, archives of the OASIS WSS Technical Committee's work are accessible to both members and non-members, and OASIS hosts an open mail list for public comment on the standard.
Support for WS-Security
Forum Systems
"This is a significant step for the industry, since advanced Web services are not possible without capabilities such as the Kerberos Token Profile and SOAP with Attachments. Not unlike Secure Sockets Layer (SSL) for network communication, WS-Security will be the defacto standard for secure Application-Oriented networking," said Walid Negm, Vice President of Marketing, Forum Systems.
Fujitsu
"Fujitsu is pleased to see the new version of WS-Security become an OASIS Standard. We have been committed to the standardization of Web services technologies. With the addition of attachments support and other enhancements, the new standard will enable us to provide a wider range of solutions. This will help our customers realize secure systems based on Web services technologies," said Yasushi Ishida, Executive Architect, Software Unit, Fujitsu Limited.
Hitachi
"Hitachi is very pleased to see WS-Security v1.1 approved as an OASIS Standard. Initial reactions from the press and users when Web services was in its infancy was that the security issues would be so great to make practical deployment an impossibility. With the publication of WS-Security v1.1 as an OASIS Standard, the community at-large may be assured that the underlying tools necessary to secure Web services deployments are at hand and are practical. Usage of these standards and their composition with higher level protocols will form the basis of practical secure deployments. This inhibitor to deployment is now removed," said Takao Nakamura, Executive General Manager, Software Division, Hitachi, Ltd.
Microsoft
"Microsoft is excited to have collaborated with the co-authors of the WS-Security 1.1 specification. Its ratification as a standard is a significant milestone for Web services and the industry overall incorporating feedback from products deployed using the WS-Security 1.0 industry standard," said Chris Kaler, Security Architect at Microsoft Corp and co-chair of the OASIS Web Services Security Technical Committee. "WS-Security is a core component of the WS-* Web services architecture for secure, reliable and transacted Web services and is supported broadly across the industry. We look forward to continued adoption of the Web services standards, with the end goal of a common architecture for software interoperability."
Nokia
"Nokia is pleased to see the completion of WS-Security v1.1 as an OASIS Standard. Nokia has been an active contributor in creating this standard and believes it will benefit mobile Web services," said Frederick Hirsch, Senior Architect at Nokia. "WS-Security v1.1 is a major step forward in open standardization of the Web services stack, given the importance of interoperable security for Web services."
Oracle
"WS-Security v1.1 answers the need for secure authentication of Web services," said Prateek Mishra, director, Security Standards, Oracle. "Our work in the OASIS WSS Technical Committee demonstrates Oracle's commitment to bringing security standards to the market, incorporating them into our products, and passing along the benefits to our customers. We were pleased to work alongside other technology vendors to develop WS-Security v1.1, and look forward to helping to accelerate its adoption."
Reactivity
"The approval of WS-Security v1.1 as an OASIS Standard is critical to the future growth of Web services and service oriented architectures (SOA) that our enterprise customers are implementing," according to Andrew Nash, chief technology officer at Reactivity. "WS-Security standards enable our customers to do what matters most---building and deploying successful Web services and SOA projects that scale with the company as they add new partners, customers and services to their network."
Sun Microsystems
"Sun is pleased to participate in the evolution of WS-Security and to see it reach this important milestone. Through the OASIS process, other organizations, like the Liberty Alliance and WS-I, can reference this specification with confidence," said Bill Smith, director of business alliances at Sun Microsystems. "As part of Sun's objective to provide developers with the out-of-the-box tools they need to easily create identity-based security for their Web services applications, we look forward to broadening our support for WS-Security across the Solaris Enterprise System in products like Sun Java System Access Manager, Sun Java System Federation Manager and Sun Java System Application Server."
VeriSign
"WS-Security is already the industry foundation for adding security to Web services. The new WS-Security v1.1 standard is an important milestone that includes significant enhancements to the original specification. It also profiles and adds support for several new security token types, such as SAML, Kerberos, X.509 certificates, and others," said Siddharth Bajaj, director, Advanced Products and Research, VeriSign.
About OASIS
OASIS (Organization for the Advancement of Structured Information Standards) is a not-for-profit, international consortium that drives the development, convergence, and adoption of e-business standards. Members themselves set the OASIS technical agenda, using a lightweight, open process expressly designed to promote industry consensus and unite disparate efforts. The consortium produces open standards for Web services, security, e-business, and standardization efforts in the public sector and for application-specific markets. Founded in 1993, OASIS has more than 5,000 participants representing over 600 organizations and individual members in 100 countries. Approved OASIS Standards include AVDL, CAP, DITA, DocBook, DSML, ebXML CPPA, ebXML Messaging, ebXML Registry, EML, OpenDocument, SAML, SPML, UBL, UDDI, WSDM, WS-Reliability, WSRP, WS-Security, XACML, XCBF, and XML Catalogs.
Additional Information
OASIS WSS Technical Committee
http://www.oasis-open.org/committees/wss/
Cover Pages Technology Report: WS-Security
http://xml.coverpages.org/ws-security.html
Press Contact
Carol Geyer
Director of Communications
OASIS
Email: carol.geyer@oasis-open.org
Voice: +1.978.667.5115 x209
Additional References
- Approval of WSS v1.1 as OASIS Standard
- WSS v1.1 Submitted for OASIS Standard. "The specifications describe a mechanism for securing web services message exchanges using a variety of existing security technologies and methodolgies. The document set is the 1.1 revision of the original WS-Security 2004 OASIS standard. Several token profiles have been added. The 1.0 Errata has been factored in. Feedback from the public has been included and steps have been taken to enhance the readability and usability of the specification. An additional 1.1 Schema has been produced and a few XML Elements have been added to the language."
- "Web Services Security Specification (WSS, WS-Security, WS-Security 2004)."
Prepared by Robin Cover for The XML Cover Pages archive.