<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>WS-Security UsernameToken Best Practices</title><link>http://blogs.msdn.com/b/mpowell/archive/2005/02/01/365061.aspx</link><description>We just published an article by Keith Brown on how to properly use WS-Security UsernameTokens for your Web services . Keith did a great job of talking about all the issues involved and with the help of Hervey we really hashed through all the issues that</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: WS-Security UsernameToken Best Practices</title><link>http://blogs.msdn.com/b/mpowell/archive/2005/02/01/365061.aspx#381103</link><pubDate>Sun, 27 Feb 2005 04:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:381103</guid><dc:creator>下载</dc:creator><description>Thank you  I am learning of new things all day! And it is good to know of my &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;RSS already work. I think I need add button of RSS to make this thing clear.&amp;lt;br&amp;gt; But more work to do!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=381103" width="1" height="1"&gt;</description></item><item><title>re: WS-Security UsernameToken Best Practices</title><link>http://blogs.msdn.com/b/mpowell/archive/2005/02/01/365061.aspx#370309</link><pubDate>Thu, 10 Feb 2005 07:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:370309</guid><dc:creator>William</dc:creator><description>It is a good article.  The recommendation, however, is to use UsernameTokens (UT) over SSL.  TMK, I don't see a SSL implementation in WSE or FX 1.1 (however FX 2.0 will have a SSL sockets implementation IIRC).  IMHO, SecurityContextTokens are the current best way to secure all messages between web service endpoints without needing SSL (or even certs if you pass your own SCT).&lt;br&gt;--&lt;br&gt;William Stacey {MVP}  &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=370309" width="1" height="1"&gt;</description></item><item><title>re: WS-Security UsernameToken Best Practices</title><link>http://blogs.msdn.com/b/mpowell/archive/2005/02/01/365061.aspx#370259</link><pubDate>Thu, 10 Feb 2005 04:51:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:370259</guid><dc:creator>Aruna</dc:creator><description>HI. &lt;br&gt; I just wanted to know wether retriving an attachment tru byte array or retiving using WSE ?? which one is the best as u think ?&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=370259" width="1" height="1"&gt;</description></item></channel></rss>