惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
V
V2EX
T
The Blog of Author Tim Ferriss
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tailwind CSS Blog
美团技术团队
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks

博客园 - discoverx

StackPanel在增加控件的问题 IE9.0与IE8.0Table中的区别整理 删除DataTable中重复的记录 去除HTML标签--2005SQL写法 Silverlight客户端和WCF服务器端共享类库(转) ASP.NET SQL Server 注册工具 (Aspnet_regsql.exe) (转) http://msdn.microsoft.com/zh-cn/library/cc838145(VS.95).aspx http://www.guminzhijia.com/gmxy/rsbd/6494.html UML中符号的意义(转) jatoolsPrinter 2手册 - discoverx - 博客园 Silverlight入门教程 js魔力代码 Javascript多级菜单 Silverlight 2.0中文学习资源集萃 水晶报表基础操作技巧收藏 诡异的中毒现象 注册表里相应的 .Net 中的反射(动态创建类型实例) - Part.4动态创建对象 .Net 中的反射(查看基本类型信息) - Part.2
WCF安全参数相关设置方法详解(转)
discoverx · 2010-08-12 · via 博客园 - discoverx

WCF安全参数相关设置方法详解

C#代码 复制代码

  1.   

 WCF安全参数的设置方法总共有三种,主要包括:安全方式; 消息保护;以及身份验证等方式。

WCF是.NET Framework 3.5的重要组成部分,主要作用域通信方面。我们可以通过使用它来轻松的完成一些特定功能需求。在这里我们将会针对WCF安全参数的相关设置方法,为大家详解有关内容。

WCF安全参数设置方法1. 安全方式

通过设置 Binding 的属性 Security 来实现。

C#代码 复制代码

  1. NetTcpBinding binding = new NetTcpBinding();     
  2. binding.Security.Mode = SecurityMode.Transport;     
  3. binding.Security.Transport.ProtectionLevel =    
  4. System.Net.Security.ProtectionLevel.EncryptAndSign;   

WCF安全参数设置方法2. 消息保护

通过 ServiceContractAttribute 和 OperationContractAttribute 特性的 ProtectionLevel 参数我们可以设置不同的消息保护级别。

C#代码 复制代码

  1. [ServiceContract(ProtectionLevelProtectionLevel =    
  2. ProtectionLevel.EncryptAndSign)]     
  3. interface IMyContract     
  4. {  ...  }   

WCF安全参数设置方法3. 身份验证

不同的部署环境,会采取不同的选择。在 Intranet 环境下,我们可能选择 Windows 集成验证方式,而在 Internet 环境下通常的方案是采取 X.509 数字证书,当然最最通用最最常见依然是用户名/密码。

以 Windows 集成验证为例,客户端可以通过 ClientBase.ClientCredentials 属性向服务器端发送与其相匹配的身份验证信息。缺省情况下,客户端使用当前 Windows 登录账户作为身份验证信息,我们也可以显式设置不同的身份信息。

代理方式:

C#代码 复制代码

  1. NetworkCredential credentials = new NetworkCredential( );     
  2.   
  3. credentials.Domain = "MyDomain";     
  4. credentials.UserName = "MyUsername";    
  5.  credentials.Password = "MyPassword";   
  6.   using (MyContractClient client = new MyContractClient())    
  7.  {    
  8.  client.ClientCredentials.Windows.ClientCredential = credentials;     
  9. client.MyMethod( );    
  10.  }   

工厂方式:

C#代码 复制代码

  1. ChannelFactory<IMyContract> factory = new ChannelFactory<IMyContract>("");     
  2. factory.Credentials.Windows.ClientCredential = new NetworkCredential(...);    
  3.  IMyContract client = factory.CreateChannel( );    
  4.  using(client as IDisposable)     
  5. {  client.MyMethod( );  }   

在服务中,我们可以用 ServiceSecurityContext.Current (或者 OperationContext.Current.ServiceSecurityContext) 来获取相关身份信息。

Java代码 复制代码

  1. Console.WriteLine(ServiceSecurityContext.Current.WindowsIdentity.AuthenticationType);    
  2.  Console.WriteLine(ServiceSecurityContext.Current.WindowsIdentity.Name);