Technology Stack

Like most technologies, the security technology can be viewed as a stack of technology layers where a higher-level layer depends on or makes use of lower-level layers. Let us begin our recap at the bottom of this stack.

Part 2 of the book explored the Java support for basic cryptographic services framework, service-specific API classes, PKI entities and the associated APIs, tools to handle these entities, access control mechanisms, and transport-layer security with SSL and XML standards for signature and encryption. These abstractions and APIs form the building blocks of the Java platform security and are used in higher-level services.

Cryptographic services fall under two categories: services that represent cryptographic operations ...

Get J2EE™ Security for Servlets, EJBs and Web Services: Applying Theory and Standards to Practice now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.