Is the wcf security token an integrated session token or can it be reused?

I read a little about federated security and WCF and asked about the token lifetime issued by the security token service (STS).

Is the security token for a specific session started with the server, or can be reused in multiple sessions?

My goal is to be able to revoke all security tokens issued by STS by closing all open sessions and force re-authentication. I am concerned that an attacker might just reuse an already issued token.

Any input is welcome.

+3
source share
1 answer

, STS, 1 ( ). , .

var channel = channelFactory.CreateChannelWithIssuedToken(token);

, , , . CreateChannel(), , STS .

+1

Source: https://habr.com/ru/post/1791302/


All Articles