Web Services Security: SOAP Message Security 1.0
Total Page:16
File Type:pdf, Size:1020Kb
1 2 Web Services Security: 3 SOAP Message Security 1.0 4 (WS-Security 2004) 5 OASIS Standard 200401, March 2004 6 Document identifier: 7 {WSS: SOAP Message Security }-{1.0} (Word) (PDF) 8 Document Location: 9 http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0 10 Errata Location: 11 http://www.oasis-open.org/committees/wss 12 Editors: Anthony Nadalin IBM Chris Kaler Microsoft Phillip Hallam-Baker VeriSign Ronald Monzillo Sun 13 Contributors: Gene Thurston AmberPoint Frank Siebenlist Argonne National Lab Merlin Hughes Baltimore Technologies Irving Reid Baltimore Technologies Peter Dapkus BEA Hal Lockhart BEA Symon Chang CommerceOne Srinivas Davanum Computer Associates Thomas DeMartini ContentGuard Guillermo Lao ContentGuard TJ Pannu ContentGuard Shawn Sharp Cyclone Commerce Ganesh Vaideeswaran Documentum Sam Wei Documentum John Hughes Entegrity Tim Moses Entrust Toshihiro Nishimura Fujitsu Tom Rutt Fujitsu Yutaka Kudo Hitachi Jason Rouault HP Paula Austel IBM Bob Blakley IBM WSS: SOAP Message Security (WS-Security 2004) 15 March 2004 Copyright © OASIS Open 2002-2004. All Rights Reserved. Page 1 of 56 Joel Farrell IBM Satoshi Hada IBM Maryann Hondo IBM Michael McIntosh IBM Hiroshi Maruyama IBM David Melgar IBM Anthony Nadalin IBM Nataraj Nagaratnam IBM Wayne Vicknair IBM Kelvin Lawrence IBM (co-Chair) Don Flinn Individual Bob Morgan Individual Bob Atkinson Microsoft Keith Ballinger Microsoft Allen Brown Microsoft Paul Cotton Microsoft Giovanni Della-Libera Microsoft Vijay Gajjala Microsoft Johannes Klein Microsoft Scott Konersmann Microsoft Chris Kurt Microsoft Brian LaMacchia Microsoft Paul Leach Microsoft John Manferdelli Microsoft John Shewchuk Microsoft Dan Simon Microsoft Hervey Wilson Microsoft Chris Kaler Microsoft (co-Chair) Prateek Mishra Netegrity Frederick Hirsch Nokia Senthil Sengodan Nokia Lloyd Burch Novell Ed Reed Novell Charles Knouse Oblix Steve Anderson OpenNetwork (Sec) Vipin Samar Oracle Jerry Schwarz Oracle Eric Gravengaard Reactivity Stuart King Reed Elsevier Andrew Nash RSA Security Rob Philpott RSA Security Peter Rostin RSA Security Martijn de Boer SAP Blake Dournaee Sarvega Pete Wenzel SeeBeyond Jonathan Tourzan Sony Yassir Elley Sun Microsystems Jeff Hodges Sun Microsystems Ronald Monzillo Sun Microsystems Jan Alexander Systinet Michael Nguyen The IDA of Singapore Don Adams TIBCO WSS: SOAP Message Security (WS-Security 2004) 15 March 2004 Copyright © OASIS Open 2002-2004. All Rights Reserved. Page 2 of 56 John Weiland US Navy Phillip Hallam-Baker VeriSign Mark Hays Verisign Hemma Prafullchandra VeriSign 14 15 Abstract: 16 This specification describes enhancements to SOAP messaging to provide message 17 integrity and confidentiality. The specified mechanisms can be used to accommodate a 18 wide variety of security models and encryption technologies. 19 This specification also provides a general-purpose mechanism for associating security 20 tokens with message content. No specific type of security token is required, the 21 specification is designed to be extensible (i.e.. support multiple security token formats). 22 For example, a client might provide one format for proof of identity and provide another 23 format for proof that they have a particular business certification. 24 Additionally, this specification describes how to encode binary security tokens, a 25 framework for XML-based tokens, and how to include opaque encrypted keys. It also 26 includes extensibility mechanisms that can be used to further describe the characteristics 27 of the tokens that are included with a message. 28 Status: 29 This is a technical committee document submitted for consideration by the OASIS Web 30 Services Security (WSS) technical committee. Please send comments to the editors. If 31 you are on the [email protected] list for committee members, send comments 32 there. If you are not on that list, subscribe to the [email protected] list 33 and send comments there. To subscribe, send an email message to wss-comment- 34 [email protected] with the word "subscribe" as the body of the message. For 35 patent disclosure information that may be essential to the implementation of this 36 specification, and any offers of licensing terms, refer to the Intellectual Property Rights 37 section of the OASIS Web Services Security Technical Committee (WSS TC) web page 38 at http://www.oasis-open.org/committees/wss/ipr.php. General OASIS IPR information 39 can be found at http://www.oasis-open.org/who/intellectualproperty.shtml. WSS: SOAP Message Security (WS-Security 2004) 15 March 2004 Copyright © OASIS Open 2002-2004. All Rights Reserved. Page 3 of 56 40 Table of Contents 41 1 Introduction ............................................................................................................................. 6 42 1.1 Goals and Requirements ......................................................................................................6 43 1.1.1 Requirements................................................................................................................. 6 44 1.1.2 Non-Goals...................................................................................................................... 6 45 2 Notations and Terminology..................................................................................................... 8 46 2.1 Notational Conventions ......................................................................................................... 8 47 2.2 Namespaces ......................................................................................................................... 8 48 2.3 Acronyms and Abbreviations ................................................................................................ 9 49 2.4 Terminology........................................................................................................................... 9 50 3 Message Protection Mechanisms......................................................................................... 11 51 3.1 Message Security Model..................................................................................................... 11 52 3.2 Message Protection............................................................................................................. 11 53 3.3 Invalid or Missing Claims .................................................................................................... 11 54 3.4 Example .............................................................................................................................. 12 55 4 ID References ....................................................................................................................... 14 56 4.1 Id Attribute ........................................................................................................................... 14 57 4.2 Id Schema ........................................................................................................................... 14 58 5 Security Header .................................................................................................................... 16 59 6 Security Tokens .................................................................................................................... 18 60 6.1 Attaching Security Tokens .................................................................................................. 18 61 6.1.1 Processing Rules......................................................................................................... 18 62 6.1.2 Subject Confirmation.................................................................................................... 18 63 6.2 User Name Token ............................................................................................................... 18 64 6.2.1 Usernames................................................................................................................... 18 65 6.3 Binary Security Tokens ....................................................................................................... 19 66 6.3.1 Attaching Security Tokens ........................................................................................... 19 67 6.3.2 Encoding Binary Security Tokens................................................................................ 19 68 6.4 XML Tokens ........................................................................................................................ 20 69 6.4.1 Identifying and Referencing Security Tokens .............................................................. 20 70 7 Token References................................................................................................................. 21 71 7.1 SecurityTokenReference Element ...................................................................................... 21 72 7.2 Direct References................................................................................................................ 22 73 7.3 Key Identifiers...................................................................................................................... 23 74 7.4 Embedded References ....................................................................................................... 23 75 7.5 ds:KeyInfo ........................................................................................................................... 24 76 7.6 Key Names.........................................................................................................................