Skip to Content
J2EE™ Security for Servlets, EJBs and Web Services: Applying Theory and Standards to Practice
book

J2EE™ Security for Servlets, EJBs and Web Services: Applying Theory and Standards to Practice

by Pankaj Kumar
September 2003
Intermediate to advanced
464 pages
12h 22m
English
Pearson

Overview

J2EE developers have an extraordinary array of powerful options for securing their Web services, Web applications, EJB components and RMI objects. Now, expert Java architect Pankaj Kumar helps developers make sense of Java's increasingly rich security APIs, tools, patterns, and best practices-showing how to use each of them in the right place, at the right time, and in the right way.

Kumar covers every significant J2SE and J2EE security mechanism, presenting practical implementation techniques for the entire J2EE project lifecycle: analysis, design, development, deployment and operations. The book's example-rich coverage includes:

  • Implementing cryptography with the JCA (Java Cryptography Architecture) and JCE (Java Cryptography Extension) security APIs

  • Building PKI systems with Java: implementing X.509 certificates, Certification Authorities, Certificate Revocation Lists, and repositories

  • Java security managers, policy files, and JAAS: implementing access control based on code origin, code signer and user credentials

  • Securing the wire: Using SSL and the JSSE API to secure data exchange over unprotected networks

  • Ensuring XML message integrity, authentication, and confidentiality with the standards: XML Signature & XML Encryption using the VeriSign TSIK, and Infomosaic SecureXML libraries

  • Addressing security issues in RMI-based distributed applications

  • Developing and deploying servlets and EJBs for authenticated and secure access

  • Securing Web services with transport- and message-based security: SSL for transport-based and WS Security for message-based security

  • Covering security aspects of best-of-breed products: Apache Tomcat, Apache Axis, and BEA WebLogic Server.

  • Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
    and much more.

    Read now

    Unlock full access

    More than 5,000 organizations count on O’Reilly

    AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

    QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
    Julian F.
    Head of Cybersecurity
    QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
    Addison B.
    Field Engineer
    QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
    Amir M.
    Data Platform Tech Lead
    QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
    Mark W.
    Embedded Software Engineer

    You might also like

    J2EE™ Platform Web Services

    J2EE™ Platform Web Services

    Ray Lai
    J2EE™ Applications and BEA™ WebLogic Server™

    J2EE™ Applications and BEA™ WebLogic Server™

    Michael Girdley, Rob Woollen, Sandra L. Emerson

    Publisher Resources

    ISBN: 0131402641Purchase book