Wcf Security Templates and Recommendations

I am creating a wcf service that needs to be protected, because the information that the client interacts with the service is company sensitive. I plan to post it on iis6. What would be the best practice to make sure that no one except the client application can call the service to receive / install data?

Service calls must be made under the real user ID, since all calls must be monitored and verified. I plan to use PolicyInjection for auditing.

+3
source share
1 answer

It all depends.

But basically there are two main approaches:

  • SSL transport security with basicHttpBinding
  • SSL wsHttpBinding

, .

:

1) : , . .

2) : , / . .

3) : / . , , .

4) : , .

+4

Source: https://habr.com/ru/post/1776331/


All Articles