Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{3} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Message Integrity}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{This is for data at rest. Integrity of data in transit can easily be provided by TLS. \newline % Row Count 2 (+ 2) When using public key cryptography, encryption does guarantee confidentiality but it does not guarantee integrity since the receiver's public key is public. For the same reason, encryption does not ensure the identity of the sender. \newline % Row Count 7 (+ 5) Rule: For XML data, use XML digital signatures to provide message integrity using the sender's private key. This signature can be validated by the recipient using the sender's digital certificate (public key).% Row Count 12 (+ 5) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Server Authentication}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{Rule: TLS must be used to authenticate the service provider to the service consumer. The service consumer should verify the server certificate is issued by a trusted provider, is not expired, is not revoked, matches the domain name of the service, and that the server has proven that it has the private key associated with the public key certificate (by properly signing something or successfully decrypting something encrypted with the associated public key).% Row Count 10 (+ 10) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Transport Confidentiality}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{Transport confidentiality protects against eavesdropping and man-in-the-middle attacks against web service communications to/from the server. \newline % Row Count 3 (+ 3) Rule: All communication with and between web services containing sensitive features, an authenticated session, or transfer of sensitive data must be encrypted using well configured \{\{link="https://en.wikipedia.org/wiki/Transport\_Layer\_Security"\}\}TLS\{\{/link\}\}. Rule: All communication with and between web services containing sensitive features, an authenticated session, or transfer of sensitive data must be encrypted using well configured TLS. This is recommended even if the messages themselves are encrypted because TLS provides numerous benefits beyond traffic confidentiality including integrity protection, replay defenses, and server authentication. For more information on how to do this properly see the Transport Layer Protection Cheat Sheet.  SOAP structure Such authentication is usually a function of the container of the web service. \newline % Row Count 4 (+ 4) Rule: If used, Basic Authentication must be conducted over TLS, but Basic Authentication is not recommended. \newline % Row Count 7 (+ 3) Rule: Client Certificate Authentication using TLS is a strong form of authentication that is recommended.% Row Count 10 (+ 3) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Transport Encoding}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{\{\{link="https://en.wikipedia.org/wiki/SOAP"\}\}SOAP\{\{/link\}\} encoding styles are meant to move data between software objects into XML format and back again. \newline % Row Count 4 (+ 4) Rule: Enforce the same encoding style between the client and the server.% Row Count 6 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Source}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{\{\{link="https://owasp.org/www-project-cheat-sheets/cheatsheets/Web\_Service\_Security\_Cheat\_Sheet.html"\}\}https://owasp.org/www-project-cheat-sheets/cheatsheets/Web\_Service\_Security\_Cheat\_Sheet.html\{\{/link\}\}% Row Count 5 (+ 5) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}