Contactdetails

NLJUG
Postbus 3389
2001 DJ Haarlem

Telefoon
023 543 00 93

Fax
023 535 96 27

Email
Algemeen: info@nljug.org
Leden: members@nljug.org

BTW: NL85241364B01
KVK: 57039615

Bank
Rabo: 3123.20.973
BIC: RABONL2U
IBAN: NL47RABO0312320973
NLJUG te Son
Algemene voorwaarden 

Membership

Membership provides members free access to the NLJUG workshops and events on a variety of Java topics, held across the country on a regular basis. Plus on a quarterly basis the Java Magazine published by Array Systems. The NLJUG is a member of a worldwide network of Java User Groups.

Fill in the form to sign up.

NLJUG

Founded in 1998, the Dutch Java Users Group consists of business partners, software developers, application architects, technical managers, students, and new media developers that have a common interest in all aspects of Java Technology.




NLJUG partners

Centric

WS-Security: is it really that simple?

The specifications for Web Services Security (WS-Security) has been around for years, but until recently it isn’t widely used. Web Services are still often secured at the transport level, i.e. securing the communication channel between the web service and it’s client. While this can provide confidentiality, integrity and authentication at some level, it does have some serious shortcomings. Especially when a message travels through intermediate nodes before reaching it’s intended receiver. Authenticating the initial sender of the message instead of the server that hosts the final web service client, can’t be done easily. Although recently WS-Security is used more and more, projects still often prefer the “simpler” solution, because WS-Security message-level security is “too complicated”.

This session will show that the complexity of WS-Security is more in the theory and the specification than in the practical application of this standard. After quickly explaining the theory, it will provide an overview of the available frameworks that make WS-Security life easier. This is demonstrated by a real life example, which will also dive into the code level. Finally the maturity of the frameworks and some best-practices and lessons learned will be discussed to get you right up to speed.


 Download de presentatie (605 Kb)

 


Eelco Klaver 
E.Consulting
Eelco Klaver is sinds 2006 werkzaam als senior consultant bij E.Consulting, wat zich specialiseert in Enterprise Java consultancy en training. Hij houdt zich hier bezig met Enterprise Java architectuur, security workshops, software reviews en security audits. Eelco heeft ruim 11 jaar hands-on ervaring met het ontwikkelen van enterprise applicaties in Java en J2EE bij verschillende werkgevers en voor diverse grote opdrachtgevers. De laatste jaren heeft hij zich gespecialiseerd in de beveiligingsaspecten van op J2EE gebaseerde enterprise applicaties.