NonStop SOAP 4.1 User's Manual

Figure 21
Alice’s Public Key
I will pay $500
Sign
(Encrypt)
DFCD3454
BBEA788A
I will pay $500
Verify
(Decrypt)
Bob
Alice
Alice’s Private Key
Supported WS–Security Features
The Rampart module, when engaged with NonStop SOAP 4, provides the following security
features:
1. SOAP message encryption
Any part of the SOAP message can be encrypted. NonStop SOAP 4 supports the following
levels of message encryption:
Derived key support for additional security
Symmetric and Asymmetric modes of operation
Support for Advanced Encryption Standard (AES) and Triple Data Encryption Standard
(DES)
Signature encryption
Keys encryption
2. SOAP message signature
Any part of the SOAP message can be signed using a private key to maintain the integrity of
the SOAP message.
NonStop SOAP 4 supports the following levels of message signature:
XML signature with RSA-SHA1 algorithm
Message authentication with HMAC-SHA1 algorithm
Signature confirmation support
SOAP Header signing
3. Support for Key Store
X.509 certificates and private keys are supported. The keys are stored in the Privacy Enhanced
Mail (PEM) files.
Supported WS–Security Features 273