Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Scott Oaks

Rating No ratings yet

One of Java's most striking claims is that it provides a secure programming environment. Yet despite endless discussion, few people understand precisely what Java's claims mean and how it backs up those claims. If you're a developer, network administrator or anyone else who must understand or work with Java's security mechanisms, Java Security is the in-depth exploration you need. The new second edition focuses on the basic platform features of Java that provide security--the class loader, the bytecode verifier, and the security manager--and recent additions to Java that enhance this security model: digital signatures, security providers, and the access controller. The book covers the security model of Java 2, Version 1.3, which is significantly different from that of Java 1.1. It has extensive coverage of the two new security APIs: JAAS (Java Authentication and Authorization Service) and JSSE (Java Secure Sockets Extension). Java Security, 2nd Edition, will give you a clear understanding of the architecture of Java's security model and how to use that model in both programming and administration.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, in-depth guide to Java 2 (1.3) security architecture—covering the class loader, bytecode verifier, security manager, and cryptographic APIs—for developers and administrators who need to secure Java applications or understand how Java's security model works. 【Book Arc】 - **Opening (~0%–9%)**: Introduces the book's scope—Java security from a programmer's perspective, not network security—and outlines the core platform features: class loader, bytecode verifier, and security manager. Sets up the Java 2 security model as distinct from Java 1.1. - **Early (~9%–25%)**: Dives into the security manager and access controller, explaining permissions, policy files, protection domains, and guarded objects. Then moves to class loaders and cryptographic foundations—keys, certificates, key management, and message digests—with practical API usage. - **Middle (~25%–38%)**: Covers advanced security APIs: SSL and HTTPS via JSSE, and authentication/authorization via JAAS. Includes both programming and administrative aspects, with examples for client/server sockets and login modules. - **Late (~38%–53%)**: Provides reference material—the java.security file, security resources, identity-based key management (javakey), and a secure Java container—plus extensive API documentation in appendices. The preface clarifies target audience (Java programmers) and version specifics (Java 2 1.3, JCE 1.2.1, JSSE 1.0.2, JAAS 1.0). - **Ending (~53%+)**: Concludes with practical guidance on configuring the default sandbox and administrative changes, plus summaries comparing with previous releases. The book emphasizes using APIs over cryptographic theory, with code examples available online. 【Key Takeaways】 - **Java security is about the platform, not the network** (Opening): The book focuses on how Java programs enforce security—class loading, bytecode verification, and permission checks—rather than firewalls or VPNs. This clarifies the book's scope for readers expecting network security. - **The Java 2 security model is a radical shift from Java 1.1** (Early): The access controller and policy-based permissions replaced the old sandbox approach, making security more flexible and administratively configurable. Understanding this change is key to using Java 2 security effectively. - **Permissions and policy files are the heart of authorization** (Early): The access controller checks permissions against protection domains, and policy files define what code sources can do. This is essential for both programmers writing secure code and administrators configuring systems. - **Cryptographic APIs are practical, not theoretical** (Early): The book explains digital signatures, keys, certificates, and message digests at a rudimentary level, focusing on how to use the APIs (e.g., keytool, MessageDigest class) rather than the underlying mathematics. This makes it accessible to developers without deep crypto knowledge. - **JSSE provides SSL/TLS support for Java applications** (Middle): SSL client and server sockets, sessions, contexts, and key managers are covered, along with the HTTPS protocol handler. This enables secure network communication directly from Java code. - **JAAS adds authentication and authorization to Java** (Middle): The Java Authentication and Authorization Service allows login modules and subject-based access control, extending the security model beyond code-based permissions to user-based ones. This is crucial for applications requiring user identity. - **Administration is a first-class concern** (Late): The book includes instructions for configuring the sandbox, managing keys with keytool, and setting up policy files—useful for end users and administrators, not just developers. This dual focus is a strength of the book. 【Reading Tips】 - **Skim the appendices**: The API reference (Appendix F) and security resources (Appendix B) are for lookup, not sequential reading. Use them when you need specific class or method details. - **Deep-read Chapters 4–5**: The security manager and access controller are the core of Java's security model. Spend time here to understand permissions, policy files, and protection domains—they underpin everything else. - **Focus on examples for JSSE and JAAS**: Chapters 14–15 have practical code for SSL sockets and login modules. Read these carefully if your application needs network security or user authentication. - **Skip cryptographic theory**: If you're a developer using the APIs, you can skim the rudimentary explanations of digital signatures and digests. The book itself says it leaves the math to other texts. - **Note the version differences**: The book targets Java 2 1.3, but most content applies to 1.2. If you're on a newer Java version, be aware that some APIs (e.g., security manager) have evolved or been deprecated. 【Coverage Limits】 This guide covers the book's structure and key themes based on excerpts, but does not include detailed code examples, specific API signatures, or the full content of appendices. The excerpts do not cover the complete text of later chapters (e.g., class loaders in depth, or the secure Java container appendix).
Page 1
s New in This Edition.....................................................................................................................5 How to Contact Us...
View in text
Page 2
.............................................172 Chapter 10. Key Management.....................................................................................
View in text
Page 3
............................................................353 D.1 The 1.1−Based Class Loader..................................................................
View in text
Page 6
eb site located at http://www.oreilly.com/catalog/javasec2/. Conventions Used in This Book Constant width font is used for: Code examples• Class, variable, a...
View in text
Page 9
u can write an application that uses the 1.1 security model. Although most of the techniques in this appendix have been superseded in Java 2, there are excep...
View in text
Page 12
problems that plagued other models of software distribution. Hence, the early work on Java focused on just that issue: Java programs are considered safe beca...
View in text
Page 14
t you've set up the extensions as installed extensions. 1.2.2 The Java Cryptography Extension JCE leverages the Java 2 core platform's security architecture...
View in text
Page 17
JDBC driver, you can buy third−party implementations of JCE. However, many of the popular algorithms that are used by the extensions are patented algorithms,...
View in text
Tags
AI categories
Programming LanguageJavaCybersecurity
ISBN: 0596001576
Publisher: O'Reilly Media
Publish Year: 2001
Language: English
Pages: 486
File Format: PDF
File Size: 1.4 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…