6. Restartthe Enterprise Server.
Message Security Setup
Mostof the steps for setting up the Enterprise Server for using message security can be
accomplishedusing the Admin Console, the asadmin command-line tool, or by manually
editingsystem les. In general, editing system les is discouraged due to the possibility of
makingunintended changes that prevent the Enterprise Server from running properly,
therefore,where possible, steps for conguring the Enterprise Server using the Admin Console
areshown rst, with the asadmin tool command shown after. Steps for manually editing system
lesare shown only when there is no Admin Console or asadmin equivalent.
Supportfor message layer security is integrated into the Enterprise Server and its client
containersin the form of (pluggable) authentication modules. By default, message layer security
isdisabled on the Enterprise Server. The following sections provide the details for enabling,
creating,editing, and deleting message security congurations and providers.
“EnablingProviders for Message Security” on page 137
“Conguringthe Message Security Provider” on page 138
“Creatinga Message Security Provider” on page 139
“EnablingMessage Security for Application Clients” on page 139
“Settingthe Request and Response Policy for the Application Client Conguration” on
page139
“FurtherInformation” on page 140
Inmost cases, it will be necessary to restart the Enterprise Server after performing the
administrativeoperations listed above. This is especially the case if you want the eects of the
administrativechange to be applied to applications that were already deployed on the
EnterpriseServer at the time the operation was performed.

Enabling Providersfor Message Security

Toenable message security for web services endpoints deployed in the Enterprise Server, you
mustspecify a provider to be used by default on the server side. If you enable a default provider
formessage security, you also need to enable providers to be used by clients of the web services
deployedin the Enterprise Server. Information for enabling the providers used by clients is
discussedin “Enabling Message Security for Application Clients” on page 139.
Toenable message security for web service invocations originating from deployed endpoints,
youmust specify a default client provider. If you enabled a default client provider for the
EnterpriseServer, you must ensure that any services invoked from endpoints deployed in the
EnterpriseServer are compatibly congured for message layer security.
Usethe command-line utility:
MessageSecurity Setup
Chapter10 •Conguring Message Security 137