【发布时间】:2015-10-07 12:12:31
【问题描述】:
我几乎没有尝试为我的 WCF 设置 BasicAuthentification(在 IIS 8.5 上发布)。但我总是得到以下错误之一:
http 请求被客户端身份验证方案“基本”禁止。从服务器获得以下 authentificationheader "Digest qop="auth",algorithm=MD5-sess,nonce="someMD5stuff",charset=utf-8,realm="Digest",Negotiate,NTLM,Basic realm="localhost""。
或
客户端身份验证方案“基本”禁止 HTTP 请求。从服务器获得 authentificationheader "Basic realm="localhost""。
我的 web.config 服务器端(在 WCF 中):
<system.serviceModel>
<services>
<service name="WCF_for_APP.Service1">
<endpoint
address=""
binding="basicHttpBinding"
contract="WCF_for_APP.Service"/>
</service>
</services>
<bindings>
<basicHttpBinding>
<binding name="BasicHttpBinding_IPersonService" />
<binding>
<security mode="TransportCredentialOnly">
<transport clientCredentialType="Basic" proxyCredentialType="None" realm=""/>
</security>
</binding>
</basicHttpBinding>
</bindings>
<client>
<endpoint address="http://somewhere/customerService"
binding="basicHttpBinding" bindingConfiguration="BasicHttpBinding_IPersonService"
contract="PersonService.IPersonService" name="BasicHttpBinding_IPersonStateService" />
</client>
<behaviors>
<serviceBehaviors>
<behavior>
<serviceMetadata httpGetEnabled="true" httpsGetEnabled="false"/>
<serviceAuthenticationManager authenticationSchemes="Basic"></serviceAuthenticationManager>
<serviceCredentials>
<userNameAuthentication userNamePasswordValidationMode="Custom"
customUserNamePasswordValidatorType="CustomerValidator.SecureBindingUsernamePasswordValidator, CustomerValidator" />
</serviceCredentials>
</behavior>
</serviceBehaviors>
</behaviors>
</system.servicemodel>
我已经尝试为 bindingConfiguration 等设置名称,但它没有改变任何事情。
我尝试在 ASP 应用程序中通过 Channelfactory 客户端访问我的 WCF:
EndpointAddress endpointAddress = new EndpointAddress(endpointadress);
BasicHttpBinding basicHttpBinding = new BasicHttpBinding();
basicHttpBinding.ReaderQuotas.MaxBytesPerRead = Int16.MaxValue;
basicHttpBinding.MaxReceivedMessageSize = int.MaxValue;
basicHttpBinding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Basic;
basicHttpBinding.Security.Mode = BasicHttpSecurityMode.TransportCredentialOnly;
ChannelFactory<Service> channelFactory = null;
Service client = null;
channelFactory = new ChannelFactory<Service>(basicHttpBinding, endpointAddress);
channelFactory.Credentials.UserName.UserName = ConfigurationManager.AppSettings["wcfUser"].ToString();
channelFactory.Credentials.UserName.Password = ConfigurationManager.AppSettings["wcfPW"].ToString();
try
{
client = channelFactory.CreateChannel();
string a = client.SendMail();
}
catch(Exception e)
{
Response.Write(e.Message);
}
IIS 上的基本身份验证已激活。我真的不想切换到 HTTPS 和证书,因为我只需要这个 basicauthent 来保证内部安全。我什至无法使用 Visual Studio wcf testclient 启动 WCF,但没有身份验证设置一切正常。 WCF 和 ASP 都在我的本地 IIS 上发布。
有什么建议吗?我是否必须使用相同的凭据将用户添加到本地系统?
** 编辑 **
我想我知道这个问题!在我的 WCF 中,我调用了另一个 WCF(来自客户),而这个与我的安全设置相结合正在制造麻烦。那么我该如何解决呢?我的带有服务器端配置的 WCF 和带有客户端配置的客户 WCF 在一个 web.config 中? (客户 WCF 也通过 ChannelFactory 调用)因为如果我命名 bindingconfigs 它不会改变任何东西(参见上面的代码)。
通过 ChannelFactory 调用客户 WCF 的代码类似于上面的代码。 这可能是问题吗? 2 WCF - 一个服务器端和一个调用?!
【问题讨论】:
-
不要在没有 https 的情况下使用 BASIC。用嗅探器从电线上提取密码是微不足道的。不要认为 internal 只意味着“安全”。
-
@Crowcoder - 我真的不在乎外部是否能看到某些东西。没有亲密的转移。如果他们错误地访问 WCF 的站点,这只是为了确保每位员工的内部安全。
-
@DaveStockinger 您是否尝试将领域添加到客户端的凭据?
-
@mkysoft 我只是尝试在 WCF 的 web.config 中添加
localhost,但它也不起作用。而且我没有找到以编程方式在客户端上添加领域的方法。 -
@DaveStockinger 您可以删除基本身份验证和自定义验证配置,然后仅在 IIS 上启用基本身份验证。在文件夹安全选项卡中将用户添加到网站文件夹。这是简单的方法。但是每个有权访问站点文件夹的用户都可以调用您的网络服务。
标签: c# asp.net wcf iis basic-authentication