15.1. Application security

For the purposes of the discussion in this section, the term application means a collection of Web resources (HTML, images, JSPs, servlets, EJBs, etc.) that provides some function for a client request. Application security refers to the policies that support access to those resources by potential users. Application security does not include such topics as network security (firewalls), intrusion detection and computer viruses; hence those topics will not be addressed in this document.

15.1.1. Authentication

Authentication is a component of an application security policy. It is the process of determining that a user (or process) really is who they say they are. This is usually done with some sort of user ID/password ...

Get WebSphere V3.5 Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.