Re: Web Service Security
- From: "Bob" <bob@xxxxxxxxxxx>
- Date: Tue, 23 Jan 2007 07:38:13 +1300
Hi Joe,
Just realised my terminology is wrong. When I say the WSDL doc is displayed
I am meaning that the ASMX file is accessed and it is displaying its list of
methods.
regards
Bob
"Joe Kaplan" <joseph.e.kaplan@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eMq7Nb9OHHA.140@xxxxxxxxxxxxxxxxxxxxxxx
It is realistic to do this. However, you need to make sure you areProgramming"
installing the client certificate properly. You can't just install a
certificate, you must install the certificate with a private key (usually
packaged as a pfx or p12 file in Windows). Have you done this?
It is probably easier to test this using a browser and navigating to the
asmx resource (use the ?wsdl to pull up the wsdl).
You also should be able to apply the "requires client cert" setting at the
directory level and have that apply to all resources in the directory. It
should not be necessary to apply it to individual resources.
Joe K.
--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services
http://www.directoryprogramming.netof
--
"Bob" <bob@xxxxxxxxxxx> wrote in message
news:erd3Jg3OHHA.1276@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
I have read the other posts here on this subject but I am still unsure
certificatethe best way to approach my situation.
I am new to web security and web programming in general.
I have a web service and a thick client and a Standalone Root
theserver.
The thick client will be installed on our client's machine and access
certificate'web service (https) over the internet.
The scenario I want is to turn up at the clients site, install the thick
client. and install a certificate generated by the Certificate server.
I want to end up where the web service will not accept access unless the
client certificate is supplied.
i.e. Won't supply WSDL, nothing, immediate 403 access forbidden
I think I am fairly well along the path but I have a problem.
At site level I can set directory security to 'require client
certificate'but if I set the asmx file level security to 'require client
I
get 403 access forbidden. Maybe I don't know how to push the certificate
with the original request?
If I relax the asmx to 'accept client certificate' I get access but so
does
any test pc with out a certificate.
Is my scenario realistic?
Why doesn't just setting the site directory security to 'client
certificate required' do the job?
Thanks
Bob
.
- References:
- Web Service Security
- From: Bob
- Re: Web Service Security
- From: Joe Kaplan
- Web Service Security
- Prev by Date: Re: Web Service Security
- Next by Date: RE: 2 servers, 1 website, security issue
- Previous by thread: Re: Web Service Security
- Next by thread: RE: Encrypt string using SHA1withDSA and X509 certificate
- Index(es):
Relevant Pages
|