【问题标题】:WCF security authenticationWCF 安全认证
【发布时间】:2011-04-06 23:03:43
【问题描述】:

我有一个简单的服务,我尝试设置身份验证。在客户端上,我希望用户输入他们的 Windows 用户帐户。 WCF 将使用客户端提供的用户名/密码并针对 Windows 身份验证对其进行身份验证。

这是我的服务器 app.config

 <system.serviceModel>
    <services>
      <service name="WcfService.Service1" behaviorConfiguration="WcfService.Service1Behavior">
        <host>
          <baseAddresses>
            <add baseAddress = "http://localhost:8731/Design_Time_Addresses/WcfService/Service1/" />
          </baseAddresses>
        </host>
        <endpoint address ="" binding="wsHttpBinding" contract="WcfService.IService1">
          <identity>
            <dns value="localhost"/>
          </identity>
        </endpoint>
        <endpoint address="mex" binding="mexHttpBinding" contract="IMetadataExchange"/>
      </service>
    </services>
    <behaviors>
      <serviceBehaviors>
        <behavior name="WcfService.Service1Behavior">
          <serviceMetadata httpGetEnabled="True"/>
          <serviceDebug includeExceptionDetailInFaults="True" />

          <serviceCredentials>
            <userNameAuthentication userNamePasswordValidationMode = "Windows"/>
          </serviceCredentials>

        </behavior>
      </serviceBehaviors>
    </behaviors>
  </system.serviceModel>

这是我的客户端 app.config

<system.serviceModel>
    <bindings>
        <wsHttpBinding>
          <binding name="WSHttpBinding_IService1">

              <security mode = "Message">
                <message  clientCredentialType = "UserName"/>
              </security>

            </binding>
        </wsHttpBinding>
    </bindings>
    <client>
        <endpoint address="http://localhost:8731/Design_Time_Addresses/WcfService/Service1/"
            binding="wsHttpBinding" bindingConfiguration="WSHttpBinding_IService1"
            contract="ServiceReference1.IService1" name="WSHttpBinding_IService1">
            <identity>
                <dns value="localhost" />
            </identity>
        </endpoint>
    </client>
</system.serviceModel>

这是我在客户端上的代码

ServiceReference1.Service1Client client = new WcfAuthentication.ServiceReference1.Service1Client();

client.ClientCredentials.UserName.UserName = "mywindowsusername";
client.ClientCredentials.UserName.Password = "mywindowsuserpassword";
Console.WriteLine(client.GetData(5));

但我总是遇到这个异常:

{"无法打开安全通道,因为与远程端点的安全协商失败。这可能是由于用于创建通道的 EndpointAddress 中缺少或错误指定 EndpointIdentity。请正确验证 EndpointAddress 指定或暗示的 EndpointIdentity标识远程端点。"} {“安全令牌请求包含无效或格式错误的元素。”}

【问题讨论】:

    标签: c# .net wcf-security


    【解决方案1】:

    看起来您分别(手动)生成了服务和客户端配置。使用svcutil 或Visual Studio 的“添加服务引用”从服务生成客户端配置通常是一个好主意。这样你就知道你得到了对应于服务配置的客户端配置。

    您想要的都是可能的,但是 WCF 不允许您在使用 wsHttpBinding 时以纯文本形式传输您的用户名/密码令牌。这意味着您必须使用 https 托管您的服务或使用服务证书。 Here 的帖子包含更多详细信息。

    但我也想知道为什么你会想要这样的东西。使用集成的 Windows 身份验证可能是一个更好的主意。这甚至是wsHttpBinding 的默认设置。这样您就不需要您的客户输入他们的 Windows 用户名/密码。

    【讨论】:

    • 很有趣,它必须使用安全连接是完全合理的。这只是一个了解 wcf 提供的不同身份验证可能性的练习。在现实世界。它适用于我的移动应用程序,用户需要在其移动设备上提供 Windows 帐户凭据。所以它使用 basichttpbinding 来保护我将使用 SSL (https) 的通信。因此,例如上面使用 nettcpbinding 应该是正确的,因为我认为默认情况下它使用应该已经用 tcp 加密的传输安全性。
    【解决方案2】:

    我认为带有 WsHttpBinding 的 Windows 身份验证仅适用于 https。

    看到这个:http://msdn.microsoft.com/en-us/library/ff650619.aspx

    【讨论】:

      【解决方案3】:
      binding.Security = new WSHttpSecurity{Mode = SecurityMode.None};
      

      【讨论】:

        猜你喜欢
        • 2013-09-06
        • 1970-01-01
        • 2019-12-20
        • 2010-10-21
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 2012-01-02
        相关资源
        最近更新 更多