Re: Enforce specific client certificate on WCF service



Thanks Dominick, I was going to write you privately since I knew you
had an idea about the answer. It's just too bad that this
functionality is not implemented automatically, it doesn't look like a
lot of work though.

On 26 Lis, 11:15, Dominick Baier
<dbaier@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Have a look here:

http://www.leastprivilege.com/CertificateBasedAuthenticationAndWCFMes...

-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

This is driving me nuts.

I would like to secure my WCF service using certificates but I would
like to define which certificates have access, preferably configurably
since each of my deployment environments have different certificates.

In WSE 2.0 this was done using the wssp:Integrity element in the
policy file.

Is this even possible with WCF?

.



Relevant Pages

  • Re: security header is not present in the incoming message
    ... I manage to give ASPNET access to privet key file ... Is there any more stuff I can do to make completely on IIS? ... > Dominick Baier - DevelopMentor ... I did import all certificates ...
    (microsoft.public.dotnet.security)
  • Re: Using Custom Membership/Role Providers?
    ... Thanks Dominick - indeed it looks like that thread shares a similar problem ... Does the built in "provider" get upset if you ... > Hello Bill, ... >> roles functionality as well as the profile functionality. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Roles.IsUserInRole != Context.User.IsInRole
    ... Dominick Baier, DevelopMentor ... This is a web page where there is no impersonation - ... This is part of a solution intended to handle windows/domain users, ...
    (microsoft.public.dotnet.framework.aspnet.security)