dc.contributor.editor | Matheus, Andreas | |
dc.date.accessioned | 2019-07-19T15:20:49Z | |
dc.date.available | 2019-07-19T15:20:49Z | |
dc.date.issued | 2019 | |
dc.identifier.citation | Matheus, A. (ed.) (2019) OGC Web Services Security, Version, 1.0. Wayland, MA, Open Geospatial Consortium, 96pp. (OGC 17-007r1). DOI: http://dx.doi.org/10.25607/OBP-516 | en_US |
dc.identifier.uri | http://hdl.handle.net/11329/986 | |
dc.identifier.uri | http://dx.doi.org/10.25607/OBP-516 | |
dc.description.abstract | Information Assurance (IA)[1] Controls for OGC Web Services (OWS) have been implemented for years. However, these implementations break interoperability, as they are not standardized by OGC Web Service standards. Interoperability between secured OGC Web Services and clients is limited to systems custom built to work with an IA implementation.
The goal of the OWS Common Security Standard is to allow the implementation of IA controls and to advertise their existence in an interoperable way with minimal impact to existing implementations using a backwards-compatible approach. That goal is being pursued in two ways:
Identify and document IA Controls for supporting authentication in a register maintained through the OGC.
Specify how a service can advertise their IA controls through the Service Capabilities Document.
This OGC standard applies to OWS deployed on HTTPS. It specifies how conformant OWS Services shall advertise their IA Controls and additional security features. The advertisement uses XML elements that are already part of the Capabilities document structure. This ensures that existing client implementations will not break.
The standard also describes the governance process for the IA Control registers, examples of register contents, and descriptions on how this information should be used.
Next, this standard defines conformance classes and requirements classes to be used for reaching compliance and their validation via conformance tests.
Finally, this standard defines client behavior to ensure interoperable processing of advertised security controls. | en_US |
dc.language.iso | en | en_US |
dc.publisher | Open Geospatial Consortium | en_US |
dc.relation.ispartofseries | OGC;17-007r1 | |
dc.title | OGC Web Services Security. | en_US |
dc.type | Report | en_US |
dc.description.status | Published | en_US |
dc.format.pages | 96pp | en_US |
dc.description.refereed | Refereed | en_US |
dc.publisher.place | Wayland, MA | en_US |
dc.subject.parameterDiscipline | Parameter Discipline::Cross-discipline | en_US |
dc.description.currentstatus | Current | en_US |
dc.description.maturitylevel | Mature: Methodologies are well demonstrated for a given objective, documented and peer reviewed; methods are commonly used by more than one organization (TRL 7-9) | en_US |
dc.description.bptype | Standard | en_US |
obps.contact.contactemail | standards@opengeospatial.org | |
obps.resourceurl.publisher | http://www.opengeospatial.org/docs/is | en_US |