Well prepared question. First of all, I probably read the same book, and I would like to clarify this statement:
This is because you should not use transport security, because it should only be used in environments where you can guarantee that there is a point-to-point between the service and the client.
Yes. HTTPS (Transport Security) offers only point-to-point protection, but IMO people do not understand this scenario correctly. Do you think that if you connect to Internet banking through an HTTP server, it will happen to be somewhere in the middle of exchanging exchanges over the Internet from HTTPS to HTTP? NO! Point-to-point connection means a secure transport channel between a client and an available gateway providing the requested URL. In your scenario, this means a secured transport channel between the client and your ISA server. Communication will not be secure between your ISA and Web server 2. If you want the end-to-end interface to provide a secure channel between the client and Web server 2 (ISA will not be able to intercept messages), you need message security.
Now to your other questions:
Can I use the same certificate for WCF service message security?
Yes you can, but you need to copy the private key to your web server 2.
Is the message protection method compatible with clients who expect ASMX Webservice?
No. ASMX Pure Client cannot use message protection unless you encode many custom headers and SOAP extensions or install WSE 3.0.
Is it possible to include the Security message with the aforementioned certificate without forcing the client to add the certificate to a trusted person manually?
Yes, but the certification authority that published the certificate must be trusted on the client machine. Same thing with HTTPS. In addition, message-protected services may expose a certificate fingerprint within the WSDL. Customers can verify the identity of the service with this fingerprint. I think that in this case, you also do not need to install the certificate on the client, but after the expiration of the certificate all clients must be updated.
Do I need to copy a web server certificate to be able to use Message Security?
Yes you should. But this can be a problem, because a security certificate can be marked as not exportable. The best solution is to request a new certificate for this purpose only.
Ladislav Mrnka Jan 13 '11 at 12:20 2011-01-13 12:20
source share