WS-Security in the Enterprise, Part 1: Problem Introduction
Subject:   You should aqcuaint yourself with what's out there
Date:   2005-02-14 08:23:59
From:   OConnor
Response to: Why not use the standards?

There are indeed many products that do this type of policy enforcement in the infrastrcture, and they are growing if not exploding. The value proposition for doing this in infrastrcture is overwhelming. Most app dev projects I have ever been on allocated zero time to developing security code, with app security being an afterthought. Now it can be an afterthought...
    Since I've been working on development of one of the pioneering products in this area, I'm quite familiar with the landscape, as well as with the present problems out there.
    Should this functionality be eventually moved into the infrastructure layer? Definitely. Are we technologically at this point yet? By no means.
    This unfortunate fact, combined with the desire to provide some education value, was the main motivation for starting this work.
      you are proposing gap technology and working to educate folks...that makes sense.