Alex Rivera | Logout

WCF Service with WS-Security requires Signed Timestamp only

Asked 2010-09-24T08:54:04.637
10

I need to provide a service to a third-party that will be sending soap messages with a signed Timestamp.

How can I configure my service to support this?

UPDATE I've managed to get close to the format of the Soap message that we're after but WCF insists on signing both the username and the timestamp tokens, Is there a way to modify the binding to only sign the timestamp?


Further Update Here are our requirements:

  • The Timestamp element MUST be signed.
  • The CN name on the certificate used for signing MUST match the Username give in the UsernameToken element.
  • The certificate used for signing MUST be sent in the BinarySecurityToken element.
  • The KeyInfo element MUST only contain a SecurityTokenReference element, which must be used to reference the BinarySecurityToken.
  • A canonicalization algorithm MUST be specified.
  • The SignatureMethod MUST be specified and MUST be the SHA-1 or SHA-2 alghorithm.
  • Detached Signatures SHOULD be used.

Any suggestions?

CURRENT CONFIG

Client Binding

<bindings>
  <wsHttpBinding>
    <binding name="WSBC">
      <security mode="TransportWithMessageCredential">
        <transport clientCredentialType="Certificate" proxyCredentialType="None"></transport>
        <message clientCredentialType="UserName" negotiateServiceCredential="false" establishSecurityContext="false" />
      </security>
    </binding>
  </wsHttpBinding>
</bindings>

Client Endpoint

<client>
  <endpoint address="https://localhost/WcfTestService/Service2.svc"
  behaviorConfiguration="CCB" binding="wsHttpBinding"
  bindingConfiguration="WSBC"
  contract="ServiceReference2.IService2"
  name="wsHttpBinding_IService2" />
</client>

Client Behavior

Edit
Report

1 Answer

0

You can do this with message contracts, see: http://msdn.microsoft.com/en-us/library/ms730255.aspx

Here is an example from the above link:

[MessageContract]
public class PatientRecord 
{
   [MessageHeader(ProtectionLevel=None)] public int recordID;
   [MessageHeader(ProtectionLevel=Sign)] public string patientName;
   [MessageHeader(ProtectionLevel=EncryptAndSign)] public string SSN;
   [MessageBodyMember(ProtectionLevel=None)] public string comments;
   [MessageBodyMember(ProtectionLevel=Sign)] public string diagnosis;
   [MessageBodyMember(ProtectionLevel=EncryptAndSign)] public string medicalHistory;
}

Note the protection levels None, Sign, EncryptAndSign

answered 2011-02-24T15:01:35.030

Your Answer