KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
My question is in regards to the best (aka "least painful") way to secure access to a WCF service that is only exposed to our company's internal users. The goal is to ensure that the service is only accessed via a single Windows forms application that each of our users has installed. When the service is called, I want the service to be able to validate that it was called from the permitted application. The service to be secured uses basicHttpBinding, which supports streaming, so I believe I am limited to Transport level security. Below are simplified versions of the <bindings> and <services> sections from my service's config file. <bindings> <basicHttpBinding> <binding name="Service1Binding" transferMode="Streamed"/> </basicHttpBinding> </bindings> <services> <service name="WCFServiceSecurity.Service1" behaviorConfiguration="WCFServiceSecurity.Service1Behavior"> <endpoint address="" binding="basicHttpBinding" contract="WCFServiceSecurity.IService1" bindingConfiguration="Service1Binding"/> <endpoint address="mex" binding="mexHttpBinding" contract="IMetadataExchange"/> </service> </services> Can anyone offer some details as to what actions I would need to take in order to implement security on this service? Note: I'm new to WCF and am not familiar with security at all, so let me know if I haven't provided enough detail. UPDATE: As suggested by marc_s , I'd like to secure the WCF service using some sort of username/password mechanism. This gives a little more direction towards an answer, but I'm still somewhat blurry on how to actually do this.
Tags (comma-separated)
Save Edits
Cancel