<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Don Smith : Web Service Security</title><link>http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx</link><description>Tags: Web Service Security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>WCF Security Guidance</title><link>http://blogs.msdn.com/donsmith/archive/2008/03/31/wcf-security-guidance.aspx</link><pubDate>Tue, 01 Apr 2008 00:39:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8346636</guid><dc:creator>donsmith</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/8346636.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=8346636</wfw:commentRss><description>&lt;P&gt;If you're looking for pragmatic guidace for securing your WCF services, look no further. The WCF Security project has been posting how-to documents and videos on its &lt;A class="" href="http://codeplex.com/wcfsecurity" mce_href="http://codeplex.com/wcfsecurity"&gt;community site&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Now is the perfect time to give the team feedback. They aren't done yet and are completely willing, able, and even looking forward to apply your feedback so this can be the best resource on the 'net for WCF security questions.&lt;/P&gt;
&lt;P&gt;If you want more details about the project, check out &lt;A class="" href="http://blogs.msdn.com/jmeier/archive/2008/03/27/patterns-and-practices-wcf-security-guidance-now-available.aspx" mce_href="http://blogs.msdn.com/jmeier/archive/2008/03/27/patterns-and-practices-wcf-security-guidance-now-available.aspx"&gt;J.D.'s post&lt;/A&gt;&amp;nbsp;before you head over to &lt;A class="" href="http://codeplex.com/wcfsecurity" mce_href="http://codeplex.com/wcfsecurity"&gt;get&amp;nbsp;the goods&lt;/A&gt;.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8346636" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category></item><item><title>The first of many ARCasts on Web Service Security</title><link>http://blogs.msdn.com/donsmith/archive/2006/01/30/519023.aspx</link><pubDate>Mon, 30 Jan 2006 08:38:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:519023</guid><dc:creator>donsmith</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/519023.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=519023</wfw:commentRss><description>&lt;p&gt;Just got the email from Ron that he's just posted an &lt;a href="http://channel9.msdn.com/ShowPost.aspx?PostID=158827"&gt;ARCast on Web 
service security&lt;/a&gt;. I'm listening&amp;nbsp;to the ARCast now ... this was created 
from a webcast &lt;a href="http://blogs.msdn.com/rjacobs/"&gt;Ron&lt;/a&gt;, &lt;a href="http://blogs.msdn.com/thehoggblog"&gt;Jason&lt;/a&gt;, and &lt;a href="http://blogs.msdn.com/fred_chong"&gt;Fred&lt;/a&gt; did in September titled &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032280306&amp;amp;Culture=en-US"&gt;Web 
Services Security Patterns (Level 300)&lt;/a&gt;. I was supposed to be on this one, 
but something came up at the last minute ... so they make fun of me of 
course.&lt;/p&gt;
&lt;p&gt;About 3 weeks or so ago, I got &lt;a href="http://www.dopplerradio.net/"&gt;doppler&lt;/a&gt; and &lt;a href="http://www.microsoft.com/windows/windowsmedia/mp10/default.aspx"&gt;Window 
Media Player&lt;/a&gt; set up with my &lt;a href="http://www.iriveramerica.com/prod/hd/h10_char.aspx"&gt;iRiver H10&lt;/a&gt; so now 
I'm automatically pulling down &lt;a href="http://channel9.msdn.com/shows/ARCast_with_Ron_Jacobs"&gt;Ron's ARCast&lt;/a&gt; 
and &lt;a href="http://dotnetrocks.com"&gt;DotNetRocks!&lt;/a&gt;&amp;nbsp;so I can tune in on 
my way to work ... and when I'm on those cool Eliptical machines in the gym. Are 
there are cool podcasts that .NET developers are listening to ... what about Web 
service or distributed application podcasts. If they're out there, please let me 
know.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=519023" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category></item><item><title>Message Protection</title><link>http://blogs.msdn.com/donsmith/archive/2006/01/27/518585.aspx</link><pubDate>Sat, 28 Jan 2006 03:13:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:518585</guid><dc:creator>donsmith</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/518585.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=518585</wfw:commentRss><description>
&lt;p&gt;I look in the window of his office and he's banging away on the keyboard. It 
doesn't look like he's on disney.com or IMing with his Aussie mates - it looks 
like real work. A few minutes later an IM window is telling me to link to a blog 
entry on message protection. Okay, so it's not typical work, but it's a good 
thing for all of us that &lt;a href="http://blogs.msdn.com/thehoggblog"&gt;Jason 
&lt;/a&gt;took the time to publish it.&lt;/p&gt;
&lt;p&gt;In his most recent article, &lt;a href="http://blogs.msdn.com/thehoggblog/articles/518574.aspx"&gt;&lt;em&gt;Web service 
security - Threats and Countermeasures - Part 4 : Message Protection – Sign and 
Encrypt and Encrypt Signature!&lt;/em&gt;&lt;/a&gt;, Jason covers the threats and 
countermeasures associated with eavesdropping confidential information. Heck, he 
even provides sample messages and links to valuable resources to get more 
information.&lt;/p&gt;
&lt;p&gt;Very good Jason, now get back to work :)&lt;/p&gt;
&lt;p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=518585" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category></item><item><title>Jason is blogging ... woohoo!</title><link>http://blogs.msdn.com/donsmith/archive/2005/11/20/495068.aspx</link><pubDate>Mon, 21 Nov 2005 01:31:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:495068</guid><dc:creator>donsmith</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/495068.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=495068</wfw:commentRss><description>
&lt;p&gt;It's about time! Jason&amp;nbsp;is the&amp;nbsp;program manager on&amp;nbsp;the 
Integration &amp;amp; Web Service program on the &lt;a href="http://msdn.microsoft.com/practices"&gt;patterns &amp;amp; practices&lt;/a&gt; team 
(the same program I'm the product manager of). Jason is a really sharp guy and 
he knows a lot about Web services. I think this is going to be a really great 
blog. Also,&amp;nbsp;now you have two places to go to find out what p&amp;amp;p is doing 
in the Web services space. We can only hope Jason will write more entries than I 
do ... hey, I'm trying to get better. So go check out the &lt;a href="http://blogs.msdn.com/thehoggblog"&gt;Hogg Blog&lt;/a&gt; (what a name ... haha) 
and read about the 3 things Jason and I (and the rest of our great 
team)&amp;nbsp;are working on.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=495068" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/WS-I+Basic+Security+Profile/default.aspx">WS-I Basic Security Profile</category></item><item><title>Prizes for best bugs</title><link>http://blogs.msdn.com/donsmith/archive/2005/10/21/483520.aspx</link><pubDate>Fri, 21 Oct 2005 21:08:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:483520</guid><dc:creator>donsmith</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/483520.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=483520</wfw:commentRss><description>
&lt;p&gt;Jason is offering prizes for the best bugs found in our &lt;a href="http://practices.gotdotnet.com/projects/sopatterns"&gt;October CTP release of 
the Web Service Security Patterns&lt;/a&gt;. Here are the details.&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;&lt;em&gt;Help us find bugs in our October CTP! Compare your security knowledge 
  with the best in the world... 
  &lt;p&gt;
  &lt;p&gt;As WSE 3.0 gets closer to RTM we are finalizing the testing of our 
  guidance, our quickstarts and wrapping up the security reviews that our 
  external security reviewers (ISecPartners, Foundstone and Infosys) are 
  performing. &lt;/p&gt;
  &lt;p&gt;For the best 3 bugs reported I will get you a free p&amp;amp;p book such as 
  Integration patterns etc. If you find a security related bug that our security 
  SME's don't find you can select two books! &lt;/p&gt;
  &lt;p&gt;Please post to our workspace... and don't be afraid to post something that 
  might be wrong.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;I'm sure we can throw in some other swag from patterns &amp;amp; practices too. 
Heck, maybe even a shirt ... I know you could use another one of those 
:)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=483520" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category></item><item><title>Web Service Security Patterns: October CTP Released</title><link>http://blogs.msdn.com/donsmith/archive/2005/10/20/483245.aspx</link><pubDate>Fri, 21 Oct 2005 02:38:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:483245</guid><dc:creator>donsmith</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/483245.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=483245</wfw:commentRss><description>
&lt;p&gt;I'm a couple days late with this entry, but I'd be remiss for not mentioning 
it at all. This release is a &lt;b&gt;substantial improvement&lt;/b&gt; over the past 
releases. We added even more patterns and updated the implementation patterns to 
take advantage of WSE 3.0. The WSE 2.0 implementation patterns have been removed 
from this release. If you want to review the WSE 2.0 implementation patterns in 
the meantime, check out the August CTP.&lt;/p&gt;
&lt;p&gt;The following patterns have been added since the August CTP release. These 
patterns have all been through the workshop process, but haven't all been 
through an initial editorial pass ... that's why it's a CTP ;)&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Security Token Service 
  &lt;li&gt;Message Replay Detection 
  &lt;li&gt;Perimeter Service Router 
  &lt;li&gt;Message Validation 
  &lt;li&gt;Exception Shielding 
  &lt;li&gt;Trusted Subsystem 
  &lt;li&gt;Protocol Adapter 
  &lt;li&gt;Delegation&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;If you're building secure Web services with WSE, you can't afford not to 
check out this content. Let me know if you have any questions or comments about 
it.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=483245" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category></item><item><title>Web Service Security Patterns: August CTP just dropped</title><link>http://blogs.msdn.com/donsmith/archive/2005/08/17/452922.aspx</link><pubDate>Thu, 18 Aug 2005 05:39:28 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:452922</guid><dc:creator>donsmith</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/donsmith/comments/452922.aspx</comments><wfw:commentRss>http://blogs.msdn.com/donsmith/commentrss.aspx?PostID=452922</wfw:commentRss><description>
&lt;p&gt;Just a quick note to let you know that we just posted the August CTP release 
of the security patterns content to&amp;nbsp;the community at &lt;a href="http://practices.gotdotnet.com/projects/sopatterns"&gt;http://practices.gotdotnet.com/projects/sopatterns&lt;/a&gt;. 
The biggest change from the last release is the inclusion of the Kerberos 
implementation pattern (that's right, how to implement the KerberosToken in WSE 
2.0) and the Kerberos primer in case you need to brush up on your Kerb 
knowledge. Available in CHM format for your single-file, navigation, 
hyperlinking pleasure ;-)&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=452922" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Services/default.aspx">Web Services</category><category domain="http://blogs.msdn.com/donsmith/archive/tags/Web+Service+Security/default.aspx">Web Service Security</category></item></channel></rss>