【问题标题】:Configuring WCF Security (wsHttpBinding)配置 WCF 安全性 (wsHttpBinding)
【发布时间】:2010-11-29 01:21:27
【问题描述】:

我有两个网站托管在同一个 IIS 服务器上。 SiteA 包含 SiteB 需要访问的 WCF 服务,以及在域上经过身份验证的任何其他服务。

该服务配置了 wsHttpBinding,因此我相信默认情况下使用 Windows 安全性。现在,我可以从本地计算机上运行的控制台应用程序以及默认 Visual Studio Web 服务器中运行的 Web 应用程序调用服务,因此我认为身份验证正在工作。

但是,当 SiteB 尝试访问服务时,它会失败并出现以下错误: 调用者未通过服务的身份验证。

SiteB 与 SiteA 在同一台机器上运行,所以我不明白为什么它无法通过身份验证。 SiteB 使用表单身份验证,我将匿名访问映射到域用户。

这里是配置位:

站点 A(服务):

<system.serviceModel>
        <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" />
        <services>
            <service behaviorConfiguration="wcfServiceBehaviour" name="MyService">
                <endpoint address="" binding="wsHttpBinding" contract="IServiceContract" />
                <endpoint address="mex" binding="mexHttpBinding" contract="IMetadataExchange" />
            </service>
        </services>
        <behaviors>
            <serviceBehaviors>
                <behavior name="wcfServiceBehaviour">
                    <serviceMetadata httpGetEnabled="true" />
                    <serviceDebug includeExceptionDetailInFaults="true" />
                </behavior>
            </serviceBehaviors>
        </behaviors>
    </system.serviceModel>

SiteB(客户端):

<system.serviceModel>
    <client>
      <endpoint address="http://xxxxx/Services/xxService.svc"
                binding="wsHttpBinding"
                contract="IServiceContract" />
    </client>
</system.serviceModel>

【问题讨论】:

  • 嗨 Xavier,我很抱歉,我错了。我显然错过了这一点。

标签: wcf wcf-binding windows-authentication


【解决方案1】:

你是正确的 - WCF 中配置的 wsHttpBinding 默认使用 Windows 身份验证。

这里有一个建议 - WCF - changing endpoint address results in securityexception - 标识块不适用于 Windows 身份验证 - 尝试删除它。

【讨论】:

  • 感谢您的提示。我已删除身份块,但身份验证仍然无法正常工作。我编辑了我的问题以反映这些变化。
  • 您是否考虑过使用 NetNamedPipeBinding 而不是 wsHttpBinding?这种绑定是安全的,并且针对同一机器处理进行了优化,.如果您仍然需要提供外部访问,您可以保留 wsHttpBinding(假设它适用于外部用户)。您需要做的就是更改绑定名称并将 http:// 更改为 net.pipe://。
  • 没有解释为什么它不起作用,但它仍然是一个很好的建议!
【解决方案2】:

SiteB 冒充其他用户时,您的代码是否指定impersonation level?

我的猜测是您没有指定足够高的模拟级别。 (委托是最高的,允许 SiteB 将权限传递给不同的服务)。

我怀疑修复 SiteB 模拟代码足以解决问题。

如果没有,请尝试将允许的模拟级别传递给服务器:

<system.serviceModel>
    <client>
      <endpoint address="http://xxxxx/Services/xxService.svc"
                binding="wsHttpBinding"
                contract="IServiceContract"
                behaviorConfiguration = "ImpersonationBehavior" />
    </client>
      <behaviors>
          <endpointBehaviors>
               <behavior name="ImpersonationBehavior">
                   <clientCredentials>
                       <windows allowedImpersonationLevel = "Delegation" /> <!-- The highest level -->
                   </clientCredentials>
               </behavior>
          <endpointBehaviors>
       </behaviors>
</system.serviceModel>

【讨论】:

  • 感谢您的建议。该应用程序正在使用表单身份验证,因此我认为在这种情况下模拟不会有帮助。无论如何,我都尝试过,以防假冒匿名用户,但这没有帮助。我将采纳 Greg 的建议并使用 NetNamedPipeBinding,并将 wsHttpBinding 留给外部用户使用。
【解决方案3】:

如果您使用像我这样的自托管站点,避免此问题的方法(如上所述)是在主机和客户端都规定 wsHttpBinding 安全模式 = NONE。

在客户端和主机上创建绑定时,您都可以使用以下代码:

 Dim binding as System.ServiceModel.WSHttpBinding 
 binding= New System.ServiceModel.WSHttpBinding(System.ServiceModel.SecurityMode.None)

或

 System.ServiceModel.WSHttpBinding binding
 binding = new System.ServiceModel.WSHttpBinding(System.ServiceModel.SecurityMode.None);

【讨论】:

    猜你喜欢
    • 2011-09-23
    • 1970-01-01
    • 2012-08-08
    • 2013-08-09
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多