Security References

Finally, here is a number of white papers and other references that are of general interest:

http://java.sun.com/security/

This is the main index site for all security-related features of Java. In particular, this page has links to security white papers, API and tool documentation, security specifications, and more. This site also has links to many of the other sites we’ve listed here.

http://java.sun.com/sfaq/

This is the Frequently Asked Questions page for Java security. This page primarily addresses what applets can and cannot do.

http://java.sun.com/j2se/1.3/docs/guide/security/spec/security-spec.doc.html

This document is the specification for the Java 2 security architecture; it provided invaluable background for this book. When you download the Java 2 documentation, this document can be found at $JAVAHOME/docs/guide/security/spec/security-spec.html.

http://www.users.zetnet.co.uk/hopwood/papers/compsec97.html

This document gives an interesting perspective on the topic of authentication and in particular whether Java’s techniques for authentication are secure.

http://www.doc.gov/

The Department of Commerce of the U.S. government governs and publishes the export restrictions of encryption and can grant exceptions for exporting encryption technology.

http://www.crypto.com/

The Export Policy Resource page contains a number of links and other references to sites concerned with the U.S. government encryption policies.

Bruce Schneier. Applied Cryptography ...

Get Java Security, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.