<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Don’t Impersonate If You Don’t Have To</title><link>http://blogs.msdn.com/b/david_leblanc/archive/2007/04/07/don-t-impersonate-if-you-don-t-have-to.aspx</link><description>Previously, I claimed that impersonation wasn't dangerous - to the impersonator – this is NOT true for the one being impersonated if it's a high level account – it's actually a fairly hazardous thing to be doing, since a lot of people make mistakes doing</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Don’t Impersonate If You Don’t Have To </title><link>http://blogs.msdn.com/b/david_leblanc/archive/2007/04/07/don-t-impersonate-if-you-don-t-have-to.aspx#2054428</link><pubDate>Sun, 08 Apr 2007 20:44:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2054428</guid><dc:creator>SSQA- You &amp; SQL tools</dc:creator><description>&lt;p&gt;Well not everyone will agree with me but you have to after referring to David LeBlanc's blog . Refer&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2054428" width="1" height="1"&gt;</description></item><item><title>re: Don’t Impersonate If You Don’t Have To</title><link>http://blogs.msdn.com/b/david_leblanc/archive/2007/04/07/don-t-impersonate-if-you-don-t-have-to.aspx#2049301</link><pubDate>Sun, 08 Apr 2007 08:37:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2049301</guid><dc:creator>Kris</dc:creator><description>&lt;P&gt;I have recently implemented Constrained Delegation for Web Services. We have a bunch of ASP.NET apps calling into these web services. Some are trivial web services and others are not, so we needed to pass the client context to the web services so that we know who exactly is accessing the service for audit purposes. I don't need the Client context because I am using trusted auth scheme to the down level servers from the web services. But I do need the client identity to be passed securely. We have in the past passed the client identity as part of the web method call but we decided against this now and began to look for constrained delegation to solve this problem for us. It works but is non-trivial to set it up.&lt;/P&gt;
&lt;P&gt;Are there any alternatives to this (besides the trusted subsystem model)? Can Authz APIs help me in this scenario?&lt;/P&gt;
&lt;P&gt;[dcl] AuthZ might help, but you need to be careful how you pass the identity so it can't be tampered with.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2049301" width="1" height="1"&gt;</description></item><item><title>re: Don’t Impersonate If You Don’t Have To</title><link>http://blogs.msdn.com/b/david_leblanc/archive/2007/04/07/don-t-impersonate-if-you-don-t-have-to.aspx#2049187</link><pubDate>Sun, 08 Apr 2007 08:00:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2049187</guid><dc:creator>Alik Levin</dc:creator><description>&lt;P&gt;David!, &lt;/P&gt;
&lt;P&gt;Great post on high level merits/demerits of passing identity over physical tiers.&lt;/P&gt;
&lt;P&gt;I am posting short series on the same subject on my blog - so far covered impersonation and finished writing about Delegation and Protocol transition - will post tonight. I do not pretend to be a good book chapter but small hub for technical how-to's and further reading - it is all based on MSDN and patterns&amp;amp;practices stuff&lt;/P&gt;
&lt;P&gt;here is the link &lt;A href="http://blogs.msdn.com/alikl/archive/2007/04/06/identity-flow-through-physical-tiers-impersonation.aspx" target=_new rel=nofollow&gt;http://blogs.msdn.com/alikl/archive/2007/04/06/identity-flow-through-physical-tiers-impersonation.aspx&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2049187" width="1" height="1"&gt;</description></item></channel></rss>