Posted: Wed Dec 16, 2009 6:52 am Post subject: WebSphere Message Broker Security
Apprentice
Joined: 14 Oct 2009 Posts: 30
Hi everyone,
currently I am working on a security concept for our message broker shared platform. We will have clients communicate via MQ and HTTP. I will be able to control access to execution groups/message flows from MQ clients by MQ security exits (like blockIP2) without having to change code in clients.
The question is how do you control access for HTTP clients? I don't want everybody in my company to be able to call all services. In that case everyone would be able to for example get customer data.
What is the state of the art way of restricting access for web services? SSL? Or the new broker security manager? Any case studies or articles for this? _________________ Volvic
I amat a client that has mandated all WS access is to come through Datapower. They will use DP for the security access. I am not familur with the internals of Datapower but this is not the first client that is doing this and I have been made aware in the past that DP has some significant securityfeatures.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum