WEBVTT

0:00:03.560000 --> 0:00:06.320000
 Hello everyone and welcome to the video.

0:00:06.320000 --> 0:00:11.460000
 In this video, we're going to be covering
 one final topic that needs to

0:00:11.460000 --> 0:00:16.520000
 be understood, at least in this context,
 in the case of soap-based web

0:00:16.520000 --> 0:00:22.520000
 services. And that is the WSDL, specifically
 its language syntax.

0:00:22.520000 --> 0:00:23.960000
 So again, you might be
 a little bit confused.

0:00:23.960000 --> 0:00:28.520000
 I mentioned this in the previous video,
 but I'm now going to be extrapolating

0:00:28.520000 --> 0:00:32.740000
 a little bit more on that, because if you
 understand this, you know, performing

0:00:32.740000 --> 0:00:37.940000
 a security test on a soap-based
 web service becomes much easier.

0:00:37.940000 --> 0:00:43.300000
 And you'll be able to much more effectively
 analyze, you know, the methods

0:00:43.300000 --> 0:00:48.100000
 supported or allowed by a web service,
 and also try and play around or

0:00:48.100000 --> 0:00:50.120000
 invoke hidden methods.

0:00:50.120000 --> 0:00:54.100000
 And that's something we'll actually be
 exploring when we go into the next

0:00:54.100000 --> 0:00:58.520000
 section of the course, where we'll actually
 be taking a look at lab examples,

0:00:58.520000 --> 0:01:03.100000
 and, you know, essentially going through
 the process, the web security,

0:01:03.100000 --> 0:01:05.460000
 the web service security
 testing methodology.

0:01:05.460000 --> 0:01:11.900000
 So to begin with, before I even get
 to the WSDL, we need to understand

0:01:11.900000 --> 0:01:13.900000
 a couple of things.

0:01:13.900000 --> 0:01:17.540000
 So a web service is characterized
 by the following.

0:01:17.540000 --> 0:01:19.880000
 Number one, one or more methods.

0:01:19.880000 --> 0:01:21.820000
 All right, what is a method?

0:01:21.820000 --> 0:01:22.580000
 We'll get to that.

0:01:22.580000 --> 0:01:27.260000
 But each of these methods reflects
 a service provided by the server or

0:01:27.260000 --> 0:01:32.160000
 application. So a method essentially,
 you can think of it as a particular

0:01:32.160000 --> 0:01:34.500000
 type of functionality, right?

0:01:34.500000 --> 0:01:38.200000
 That again, can be configured when
 developing the web service.

0:01:38.200000 --> 0:01:43.880000
 So let's say, you want your web service
 to essentially be able to facilitate

0:01:43.880000 --> 0:01:49.800000
 or allow the listing of the web service.

0:01:49.800000 --> 0:01:53.660000
 And in that case, we can then abuse
 that method to enumerate users.

0:01:53.660000 --> 0:01:57.620000
 Again, very, very simple example
 of why someone would create it.

0:01:57.620000 --> 0:02:02.960000
 Well, not really why, but an example of
 a method within a soap web service.

0:02:02.960000 --> 0:02:05.860000
 And now an attacker could
 use it to their advantage.

0:02:05.860000 --> 0:02:11.080000
 A protocol, on the other hand, defines
 the structure of each message used

0:02:11.080000 --> 0:02:12.880000
 to request a service.

0:02:12.880000 --> 0:02:15.080000
 So the protocol defines the structure.

0:02:15.080000 --> 0:02:21.840000
 So the structure behind the, behind the
 request that contains the method.

0:02:21.840000 --> 0:02:25.780000
 Okay. So the structure of a message sent
 by the web service in the response.

0:02:25.780000 --> 0:02:27.720000
 That's the second thing it defines.

0:02:27.720000 --> 0:02:32.440000
 And lastly, the protocol defines the
 transport method used to transmit

0:02:32.440000 --> 0:02:37.020000
 the messages. So what I'm essentially
 doing here with this diagram is

0:02:37.020000 --> 0:02:42.440000
 putting together all the pieces, more
 specifically, the important pieces.

0:02:42.440000 --> 0:02:45.900000
 So when I say method, just think
 of it as functionality.

0:02:45.900000 --> 0:02:48.740000
 A web service can have whatever
 functionality you want.

0:02:48.740000 --> 0:02:53.140000
 If you want a, if you're developing a
 web service, you can create a method

0:02:53.140000 --> 0:02:58.100000
 to display the system time or to get
 the system time, I should say, where

0:02:58.100000 --> 0:03:01.380000
 you make the request specify the method.

0:03:01.380000 --> 0:03:04.980000
 And then within the response, the
 system time will be sent back.

0:03:04.980000 --> 0:03:09.440000
 And you can now start to understand
 the advantage of using web services.

0:03:09.440000 --> 0:03:14.800000
 And why, you know, communication between
 two or more systems computers

0:03:14.800000 --> 0:03:17.880000
 in this case is much
 more straightforward.

0:03:17.880000 --> 0:03:20.340000
 I really like how they
 communicate a protocol.

0:03:20.340000 --> 0:03:24.500000
 On the other hand, defines the structure
 of each message used to request

0:03:24.500000 --> 0:03:35.060000
 a service. The structure of a message
 on submit the messages.

0:03:35.060000 --> 0:03:39.120000
 So method is essentially what you want
 to do or a piece of functionality.

0:03:39.120000 --> 0:03:45.080000
 The protocol defines how this is structured
 or formatted, how it is transmitted,

0:03:45.080000 --> 0:03:50.200000
 and ensures that both of these systems
 are essentially communicating or

0:03:50.200000 --> 0:03:53.000000
 are on the same page in
 terms of communication.

0:03:53.000000 --> 0:03:55.960000
 And it does that through the formatting.

0:03:55.960000 --> 0:03:58.020000
 And of course, the transport method.

0:03:58.020000 --> 0:04:02.080000
 So that brings us to the WSDL.

0:04:02.080000 --> 0:04:06.980000
 The WSDL, which stands for Web Services
 Description Language, is an XML

0:04:06.980000 --> 0:04:11.500000
 based language that is used to describe
 the functionality and interface

0:04:11.500000 --> 0:04:13.440000
 of a web service.

0:04:13.440000 --> 0:04:19.680000
 WSDL documents serve as contracts between
 service providers and consumers,

0:04:19.680000 --> 0:04:23.260000
 specifying how a web service can be used.


0:04:23.260000 --> 0:04:29.280000
 So as I said, generally speaking, when
 you develop a web service, let's

0:04:29.280000 --> 0:04:33.780000
 say in isolation, you know, you can
 go ahead and implement it and not

0:04:33.780000 --> 0:04:40.720000
 provide a WSDL. The problem with that
 is that one day, some days, another

0:04:40.720000 --> 0:04:44.780000
 developer may be required to improve
 that a web service or to test it.

0:04:44.780000 --> 0:04:49.600000
 If they don't understand what methods
 you created or what methods are

0:04:49.600000 --> 0:04:54.040000
 supported, they cannot interact
 with that web service.

0:04:54.040000 --> 0:05:00.480000
 So web service or the WSDL document is essentially
 just that it is documentation

0:05:00.480000 --> 0:05:06.960000
 on the web service that tells, that'll
 tell you how this works.

0:05:06.960000 --> 0:05:19.580000
 Okay. And remember, based on who is
 consuming the WSDL or whether or not

0:05:19.580000 --> 0:05:21.700000
 it is that could be potentially
 dangerous.

0:05:21.700000 --> 0:05:25.160000
 And that's where we get into the testing
 process that involves trying

0:05:25.160000 --> 0:05:29.840000
 to identify or invoke hidden methods
 that will allow us to do something

0:05:29.840000 --> 0:05:35.340000
 different. So the point here is that
 WSDLs are an industry standard that

0:05:35.340000 --> 0:05:39.820000
 you need to provide or that are typically
 provided, because again, on

0:05:39.820000 --> 0:05:42.820000
 a machine to machine basis,
 the communication is fine.

0:05:42.820000 --> 0:05:46.840000
 But if you want to understand how it works,
 what are the supported methods,

0:05:46.840000 --> 0:05:48.740000
 you need to have documentation.

0:05:48.740000 --> 0:05:54.220000
 So WSDL is commonly used in conjunction
 with SOAP to define and document

0:05:54.220000 --> 0:05:56.420000
 SOAP based web services.

0:05:56.420000 --> 0:06:01.320000
 And this is also the case with APIs,
 specifically RESTful APIs, where

0:06:01.320000 --> 0:06:08.000000
 in certain cases, the docs or the doc,
 the documentation will be exposed

0:06:08.000000 --> 0:06:12.260000
 in the form of the doc endpoint, where
 you can learn about how this API

0:06:12.260000 --> 0:06:19.740000
 works, so that you can either interact
 with your own web application.

0:06:19.740000 --> 0:06:24.040000
 Now, one other thing that you need to be
 aware of, and this is very important,

0:06:24.040000 --> 0:06:27.360000
 and that is that WSDL has
 different versions.

0:06:27.360000 --> 0:06:32.340000
 So as of the time me writing this slide,
 WSDL can be distinguished into

0:06:32.340000 --> 0:06:33.520000
 two main versions.

0:06:33.520000 --> 0:06:36.020000
 We have 1.1 and 2.0.

0:06:36.020000 --> 0:06:41.160000
 Although 2.0 is the current version
 and the most widely adopted version,

0:06:41.160000 --> 0:06:46.040000
 many older web services, especially in
 the financial sector, still utilize

0:06:46.040000 --> 0:06:51.220000
 WSDL 1.1. It doesn't mean that one is
 superior over the other, it's just

0:06:51.220000 --> 0:06:53.580000
 language changes.

0:06:53.580000 --> 0:06:57.340000
 Therefore, that means in the next slides,
 we'll actually see the differences

0:06:57.340000 --> 0:07:00.640000
 between the two so that this
 becomes clearer to you.

0:07:00.640000 --> 0:07:05.660000
 Now, before we even take a look at the
 differences between the two versions,

0:07:05.660000 --> 0:07:11.100000
 first of all, it is important to know
 that WSDL documents have abstract

0:07:11.100000 --> 0:07:13.180000
 and concrete definitions.

0:07:13.180000 --> 0:07:17.980000
 In the case of abstract, they described
 what the service does, such as

0:07:17.980000 --> 0:07:22.780000
 the operation provided, the input,
 the output, and the fault messages

0:07:22.780000 --> 0:07:24.620000
 used by each operation.

0:07:24.620000 --> 0:07:29.900000
 So this is now how WSDLs
 are defined, all right?

0:07:29.900000 --> 0:07:35.000000
 And you then have the concrete definitions,
 which add information, additional

0:07:35.000000 --> 0:07:39.420000
 information about how the web service communicates,
 and where the functionality

0:07:39.420000 --> 0:07:46.280000
 is offered. And you usually see these
 two forms of exposure in terms of

0:07:46.280000 --> 0:07:49.220000
 you being able to find the WSDL.

0:07:49.220000 --> 0:07:53.440000
 In the case of the abstract definition,
 it's exactly that.

0:07:53.440000 --> 0:08:00.340000
 It's very abstract regarding functionality
 offered, but more so, just

0:08:00.340000 --> 0:08:05.180000
 highlights what the web service
 does at a high level.

0:08:05.180000 --> 0:08:10.980000
 In this case, an example is the operation
 provided, the input, the output,

0:08:10.980000 --> 0:08:12.500000
 and the fault messages.

0:08:12.500000 --> 0:08:17.940000
 Whereas with concrete WSDL documents,
 this adds additional information

0:08:17.940000 --> 0:08:23.220000
 about the web, about how the web service
 communicates and where functionality

0:08:23.220000 --> 0:08:29.280000
 is offered. And it'll also go deeper
 into supported, supported methods,

0:08:29.280000 --> 0:08:30.300000
 so on and so forth.

0:08:30.300000 --> 0:08:35.200000
 So this will all make sense when we
 actually get our hands wet, which

0:08:35.200000 --> 0:08:40.000000
 we are soon. So the following image
 shows the main differences between

0:08:40.000000 --> 0:08:45.640000
 WSDL 1.1 and WSDL 2.0 definitions.

0:08:45.640000 --> 0:08:49.740000
 We will inspect the most important
 elements in the future.

0:08:49.740000 --> 0:08:54.960000
 So WSDL 1.1, you can see here
 in terms of how it works.

0:08:54.960000 --> 0:08:57.980000
 And then of course, you have the abstract
 description and the concrete

0:08:57.980000 --> 0:09:03.280000
 description. So WSDL definition
 is right over here.

0:09:03.280000 --> 0:09:06.760000
 So this is what an abstract description
 would look like, where you have

0:09:06.760000 --> 0:09:08.940000
 the types, the message,
 and then the port type.

0:09:08.940000 --> 0:09:11.320000
 I'll explain what each of these means.

0:09:11.320000 --> 0:09:15.560000
 And then the concrete description, you
 have the binding and then the service.

0:09:15.560000 --> 0:09:21.640000
 And then for WSDL 2.0, for the abstract
 description, you'll have types.

0:09:21.640000 --> 0:09:25.060000
 And then the interface for concrete,
 you'll have the binding and then

0:09:25.060000 --> 0:09:28.200000
 the service and then the end point, which
 again, you don't need to understand

0:09:28.200000 --> 0:09:31.260000
 in terms of the differences, what you
 need to understand are these tags

0:09:31.260000 --> 0:09:35.660000
 here. And I'll explain what they mean
 in the context of XML, but also

0:09:35.660000 --> 0:09:43.000000
 literally. So moving or exploring a little
 bit more about WSDL documents,

0:09:43.000000 --> 0:09:47.680000
 a WSDL document is typically created
 to describe a soap based web service.

0:09:47.680000 --> 0:09:51.740000
 And it defines the services operations,
 their input and output message

0:09:51.740000 --> 0:09:56.380000
 structures, and how they are
 bound to the soap protocol.

0:09:56.380000 --> 0:10:00.840000
 The WSDL document effectively documents
 the web service or API provided

0:10:00.840000 --> 0:10:03.200000
 by the actual service.

0:10:03.200000 --> 0:10:07.420000
 And the WSDL document serves as a contract
 between the service provider,

0:10:07.420000 --> 0:10:09.640000
 which I already stated and the consumers.


0:10:09.640000 --> 0:10:13.760000
 And it specifies how clients should
 construct soap requests to interact

0:10:13.760000 --> 0:10:15.060000
 with the service.

0:10:15.060000 --> 0:10:18.860000
 This contract defines the operations,
 the input parameters, and expected

0:10:18.860000 --> 0:10:25.560000
 responses. So this contract essentially
 defines the operations, their

0:10:25.560000 --> 0:10:29.620000
 input parameters, and the
 expected responses.

0:10:29.620000 --> 0:10:35.280000
 So in terms of the interaction between
 the client and the web service,

0:10:35.280000 --> 0:10:37.620000
 and again, a client can
 be another system.

0:10:37.620000 --> 0:10:40.800000
 In this case, I'm just putting a human
 being there just so that it makes

0:10:40.800000 --> 0:10:45.280000
 much more sense in terms of where you
 as the attacker come into play.

0:10:45.280000 --> 0:10:50.140000
 You can see that the web service comprises
 of the web service itself.

0:10:50.140000 --> 0:10:53.560000
 So think of the, you know, the
 actual code, the logic, etc.

0:10:53.560000 --> 0:10:58.560000
 The WSDL description is a separate
 document or resource that tells you

0:10:58.560000 --> 0:11:03.880000
 how this works. So the bottom line
 is before you even begin testing a

0:11:03.880000 --> 0:11:08.040000
 web service or even an API, you should
 always try and see whether the

0:11:08.040000 --> 0:11:10.420000
 WSDL file is exposed.

0:11:10.420000 --> 0:11:15.620000
 Okay, if it is, it'll tell you a lot
 about or I should say it will tell

0:11:15.620000 --> 0:11:20.380000
 you it'll essentially tell you more
 the more about how the web service

0:11:20.380000 --> 0:11:24.880000
 works and how to interact with it,
 then you would have then you would

0:11:24.880000 --> 0:11:30.140000
 have found out how had you tried to
 enumerate functionality manually.

0:11:30.140000 --> 0:11:34.760000
 So you make a request for the WSDL
 file, you then get it, you analyze

0:11:34.760000 --> 0:11:38.860000
 it, you now know, or you now understand
 how this works, what requests

0:11:38.860000 --> 0:11:42.880000
 can be made, what can't be done, and
 then you then make your request to

0:11:42.880000 --> 0:11:44.620000
 the actual web service.

0:11:44.620000 --> 0:11:48.580000
 If it is legitimate, you get a response
 and this is where you then perform

0:11:48.580000 --> 0:11:52.400000
 the testing based on what you learned
 from the WSDL document.

0:11:52.400000 --> 0:11:57.820000
 So it's very, very simple now using this
 diagram to understand what exactly

0:11:57.820000 --> 0:12:04.540000
 the flow is from the perspective of firstly
 a client, but also a web application

0:12:04.540000 --> 0:12:09.740000
 penetration tester that's testing a web
 service that's performing a security

0:12:09.740000 --> 0:12:15.100000
 test on a web service or a, I can call
 it a web app pen test, but a web

0:12:15.100000 --> 0:12:16.700000
 service pen test.

0:12:16.700000 --> 0:12:20.920000
 I think it's much better to call it an
 API pen test, but there I go again,

0:12:20.920000 --> 0:12:25.700000
 interchanging the terms or using them
 interchangeably and I won't do that

0:12:25.700000 --> 0:12:27.120000
 again, I promise.

0:12:27.120000 --> 0:12:33.840000
 So in terms of the components that
 make up, you know, the actual WSDL,

0:12:33.840000 --> 0:12:36.500000
 we have types, all right,
 which you saw earlier on.

0:12:36.500000 --> 0:12:41.420000
 So the type section defines the data
 types used in the web service.

0:12:41.420000 --> 0:12:45.700000
 It typically includes XML schema definitions
 that specify the structure

0:12:45.700000 --> 0:12:49.400000
 and the constraints of the
 input and output data.

0:12:49.400000 --> 0:12:52.260000
 You then have the message, this
 is sent in the message element.

0:12:52.260000 --> 0:12:56.560000
 The message element defines the data structures
 used in the messages exchanged

0:12:56.560000 --> 0:12:58.940000
 between the client and the service.

0:12:58.940000 --> 0:13:02.920000
 Messages can have multiple parts, each
 with a name and type definition

0:13:02.920000 --> 0:13:07.160000
 referencing the types defined
 in the types section.

0:13:07.160000 --> 0:13:11.400000
 The port type, the port type element
 describes the operations that the

0:13:11.400000 --> 0:13:13.460000
 web service supports.

0:13:13.460000 --> 0:13:18.060000
 Okay, so keep that in mind, each operation
 corresponds to a method or

0:13:18.060000 --> 0:13:20.460000
 function that a client can invoke.

0:13:20.460000 --> 0:13:24.640000
 It specifies the input and output
 messages for each operation.

0:13:24.640000 --> 0:13:29.920000
 So the each operation being performed
 corresponds to a method.

0:13:29.920000 --> 0:13:31.520000
 Okay, so keep that in mind.

0:13:31.520000 --> 0:13:35.380000
 Sorry, corresponds to a method or function
 that the client can invoke.

0:13:35.380000 --> 0:13:40.920000
 So this is very important because the
 port types will define within the

0:13:40.920000 --> 0:13:50.480000
 WSDL document will define what operations
 are supported, facilitated by

0:13:50.480000 --> 0:13:53.560000
 a method. So it's just an
 additional abstraction.

0:13:53.560000 --> 0:13:59.320000
 In essence, port type just means method
 or just means what you can do

0:13:59.320000 --> 0:14:03.520000
 or what type of request you can invoke.

0:14:03.520000 --> 0:14:06.140000
 Okay, so it's very, very simple.

0:14:06.140000 --> 0:14:07.360000
 You then have the binding.

0:14:07.360000 --> 0:14:11.360000
 All right, so the binding element specifies
 how the service operations

0:14:11.360000 --> 0:14:16.080000
 are bound to a particular protocol
 such as soap over HTTP.

0:14:16.080000 --> 0:14:21.620000
 It defines details like the protocol, message
 encoding and endpoint addresses.

0:14:21.620000 --> 0:14:23.480000
 You then have the service element.

0:14:23.480000 --> 0:14:27.040000
 The service element provides information
 about the service itself.

0:14:27.040000 --> 0:14:32.420000
 It includes the services name and its
 endpoint addresses, which is, which

0:14:32.420000 --> 0:14:35.780000
 is the URL where the clients
 can access the service.

0:14:35.780000 --> 0:14:40.000000
 Okay, so whenever I've said endpoint,
 I'm, I'm primarily telling you that

0:14:40.000000 --> 0:14:42.880000
 this is where you can interact
 with the web service.

0:14:42.880000 --> 0:14:46.340000
 Speaking from the perspective of a web
 app, pen test or someone testing

0:14:46.340000 --> 0:14:48.660000
 the web service.

0:14:48.660000 --> 0:14:50.560000
 So those are the components.

0:14:50.560000 --> 0:14:53.080000
 Now let's take a closer look
 at them with examples.

0:14:53.080000 --> 0:14:56.620000
 So in the case of the binding element,
 I'll just go over the definition

0:14:56.620000 --> 0:15:01.040000
 one more time. The binding element specifies
 how the service operations

0:15:01.040000 --> 0:15:05.000000
 are bound to a particular protocol
 such as soap over HTTP.

0:15:05.000000 --> 0:15:10.000000
 It defines details like the protocol, message
 encoding and endpoint addresses.

0:15:10.000000 --> 0:15:15.280000
 So if you take a look at what is highlighted
 in bold here, you can see

0:15:15.280000 --> 0:15:20.340000
 firstly, we have WSTL binding and then
 the name is set to Hello service

0:15:20.340000 --> 0:15:22.200000
 soap 11 binding.

0:15:22.200000 --> 0:15:25.720000
 In terms of the type, the type is
 set to Hello service port type.

0:15:25.720000 --> 0:15:31.020000
 And then in here, we have the,
 we have the service operation.

0:15:31.020000 --> 0:15:37.380000
 So you can see soap binding transport
 is equal to HTTP schemas dot XML.

0:15:37.380000 --> 0:15:41.340000
 So essentially saying using, I would,
 you know, soap is going over HTTP

0:15:41.340000 --> 0:15:43.580000
 for in this particular case.

0:15:43.580000 --> 0:15:47.680000
 And then you can see soap dot org soap
 HTTP style is equal to document

0:15:47.680000 --> 0:15:53.040000
 is essentially the binding element is very
 important because it's essentially

0:15:53.040000 --> 0:15:55.500000
 structuring the actual request.

0:15:55.500000 --> 0:15:58.700000
 So how the requests are to be structured,
 what protocol they're supposed

0:15:58.700000 --> 0:16:01.600000
 to be operating over in terms of soap.

0:16:01.600000 --> 0:16:06.020000
 And based on this, again, this, there's
 nothing too complicated in here

0:16:06.020000 --> 0:16:10.920000
 that you need to, that you need to
 be worried of, just understand what

0:16:10.920000 --> 0:16:13.140000
 each of these elements do.

0:16:13.140000 --> 0:16:15.000000
 That's the important thing.

0:16:15.000000 --> 0:16:17.840000
 We then have the port type.

0:16:17.840000 --> 0:16:21.800000
 So the port type element describes
 the operations that the web service

0:16:21.800000 --> 0:16:25.860000
 supports each operation corresponds to
 a method or function that a client

0:16:25.860000 --> 0:16:30.460000
 can invoke. It specifies the input and
 output messages for each operation.

0:16:30.460000 --> 0:16:34.500000
 So again, when specifying the port
 type or the port type element, you

0:16:34.500000 --> 0:16:37.820000
 can see that in this case, the name
 is set to Hello service port type.

0:16:37.820000 --> 0:16:39.320000
 This is an example.

0:16:39.320000 --> 0:16:42.020000
 And then you define the operation name.

0:16:42.020000 --> 0:16:45.940000
 So you, you would, again, remember methods
 are just operations, they're

0:16:45.940000 --> 0:16:49.260000
 just additional layers of
 abstraction moving up.

0:16:49.260000 --> 0:16:53.060000
 So in this case, we are defining an
 operation, the name of the operation

0:16:53.060000 --> 0:17:00.820000
 is say hello. And then the input parameters,
 the input parameter for this

0:17:00.820000 --> 0:17:06.320000
 particular operation is right over here,
 WSDL input message is equal to

0:17:06.320000 --> 0:17:10.940000
 say hello request, or the output message
 equals say hello response.

0:17:10.940000 --> 0:17:12.620000
 So just defining that.

0:17:12.620000 --> 0:17:16.860000
 And then of course, you close
 the elements or the tags here.

0:17:16.860000 --> 0:17:19.380000
 We then have operations
 themselves, right?

0:17:19.380000 --> 0:17:23.140000
 So the operation object defined within
 a port type represents a specific

0:17:23.140000 --> 0:17:25.800000
 action that a service can perform.

0:17:25.800000 --> 0:17:29.680000
 It specifies the name of the operation,
 the input message structure, the

0:17:29.680000 --> 0:17:34.620000
 output message structure and optionally
 faulty or fault messages that

0:17:34.620000 --> 0:17:36.200000
 can occur during the operation.

0:17:36.200000 --> 0:17:40.980000
 So you can see this is we have the operation
 object here, which is being

0:17:40.980000 --> 0:17:42.640000
 defined. The name is just say hello.

0:17:42.640000 --> 0:17:46.780000
 And then the soap operation, soap action
 is say hello style is equal to

0:17:46.780000 --> 0:17:55.540000
 document. WSDL input, soap body use
 literal for input, sorry for output,

0:17:55.540000 --> 0:17:57.080000
 we have soap body use literal.

0:17:57.080000 --> 0:18:00.960000
 So again, this really will not make
 much sense to you right now, because

0:18:00.960000 --> 0:18:06.700000
 again, these are just examples, code
 snippets that logically speaking

0:18:06.700000 --> 0:18:08.380000
 don't make sense.

0:18:08.380000 --> 0:18:12.480000
 But once we're able to look at a couple
 of real world examples, they will

0:18:12.480000 --> 0:18:17.140000
 you can trust me or take my
 word for that or on that.

0:18:17.140000 --> 0:18:19.000000
 We then have the interfaces, right?

0:18:19.000000 --> 0:18:22.540000
 So instead of port type, and now this
 is where the distinction between

0:18:22.540000 --> 0:18:25.840000
 WSDL 1.1 and 2 comes into play.

0:18:25.840000 --> 0:18:31.700000
 So instead of port type WSDL version
 2 utilizes interface elements, which

0:18:31.700000 --> 0:18:35.620000
 define a set of operations representing
 an interaction between the client

0:18:35.620000 --> 0:18:37.260000
 and the service.

0:18:37.260000 --> 0:18:41.060000
 Each operation specifies the types of
 messages that the service can send

0:18:41.060000 --> 0:18:48.980000
 or receive. So in WSDL v 2.0, instead
 of port type being used, we now

0:18:48.980000 --> 0:18:50.780000
 have the interface element, right?

0:18:50.780000 --> 0:18:55.740000
 So the unlike the old port type interface
 elements do not point to messages

0:18:55.740000 --> 0:18:59.160000
 anymore. It does not
 exist in version 2.0.

0:18:59.160000 --> 0:19:03.840000
 Instead, they point to schema elements
 contained within the types element.

0:19:03.840000 --> 0:19:06.820000
 So so with that being said, that's
 going to be it for this video.

0:19:06.820000 --> 0:19:08.960000
 And I will be seeing you
 in the next video.

