Web Services Security - What to expect

I am reviewing a vendor抯 product that will run on a J2EE platform. One of the features of this product is a web services framework for developing web services. What I want to assess is how well they support web services security. They may say they rely on the underlying application server to 揹o the security stuff?is this enough?

A further question is: what should I expect from different J2EE application server vendors in the area of security. Is there reasonable compliance between them or is there still an amount of proprietary implementation, that will ultimately result in application server lock-in, should I need a particular security feature?

[667 byte] By [paularmstronga] at [2007-10-1 0:28:49]
# 1

I may have posted this to the wrong area so I have also now posted it to the web servicestechnology forum (although the layout of the forums made this area look as though it was a sub set of web services). So excuse the duae posting, although arguably it is a portability issue standalone also.

paularmstronga at 2007-7-7 16:15:55 > top of Java-index,Enterprise & Remote Computing,AVK Portability...