Chapter 15. Security 481
<wsse:Security> header, as defined by the Web Services Security, SOAP Message Security
specification. The SAML Token Profile has been fully supported since WebSphere Application
Server V7.0.0.9.
An XML signature can be used to bind the subjects and statements in the SAML assertion to
the SOAP message. Subject confirmation methods define the mechanism by which an entity
provides evidence (proof) of the relationship between the subject and the claims of the SAML
assertions. The Web Services Security, SAML Token Profile, describes the use of the
following subject confirmation methods:
Bearer
Because no key material is associated with a
bearer token, protect the SOAP message by
using a transport-level mechanism. Also