【问题标题】:Is my WCF security working?我的 WCF 安全性是否有效?
【发布时间】:2013-12-03 00:26:19
【问题描述】:

我在我的 wcf 服务中使用 Message Security。

<wsHttpBinding>
    <binding name="GenericWsBinding" closeTimeout="00:45:00" openTimeout="00:45:00"
      receiveTimeout="00:45:00" sendTimeout="00:45:00" bypassProxyOnLocal="true"
      maxBufferPoolSize="2147483647" maxReceivedMessageSize="2147483647"
      messageEncoding="Mtom">
      <readerQuotas maxDepth="64" maxStringContentLength="2147483647"
        maxArrayLength="2147483647" maxBytesPerRead="4096" maxNameTableCharCount="16384" />
      <security mode="Message">
        <transport clientCredentialType="Windows" proxyCredentialType="None" />
      </security>
    </binding>
  </wsHttpBinding>

我的疑问是,我的服务是否仅通过以下三行来保护:

<security mode="Message">
    <transport clientCredentialType="Windows" proxyCredentialType="None" />
  </security>

或者我错过了什么? Obs:我在我的类型中使用 datacontract 和 datamember,因为 messagecontract 需要排他性

提前致谢。

【问题讨论】:

    标签: c# wcf web-services visual-studio security


    【解决方案1】:

    如果您选择“消息”安全模式,您应该在“消息”元素中定义参数。您的“传输”元素可能会被忽略,并且您的服务将采用默认参数来丢失“消息”。

    或者,您可以决定使用传输或混合安全性

    http://msdn.microsoft.com/pl-pl/library/ms731884%28v=vs.110%29.aspx

    【讨论】:

    • 我有点困惑。我了解 xml 元素不正确,并更改为正确的元素(消息)。但是,我怎样才能确定安全工作正常?
    • 通过在 web.config 中设置安全模式,您可以强制消息加密或整个 SSL 传输。您可以使用例如检查您的数据是如何传输的。 Wireshark 工具。
    • 对于传输模式,您还应该配置您的 IIS 网站:SSL 设置 -> 要求
    • 谢谢你,真的帮到我了 = ]
    猜你喜欢
    • 2011-02-10
    • 2011-08-26
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-10-10
    • 2010-11-13
    • 1970-01-01
    相关资源
    最近更新 更多