Welcome to MSDN Blogs Sign in | Join | Help

Service Factory: Helping you design Secure Web Services using WCF

Our May community release of the Web Service Software Factory includes some of our coolest work so far (my opinion anyway). We have taken our learning from the Web service security patterns work and worked with the guys in the WCF security team (Mark Fussell; Jan Alexander; Tomasz Janczuk; Martin Gudgin; Steve Millet) to deliver a Guidance Package that helps you secure your WCF services and clients!

One of the *coolest* features is the client proxy / policy generation logic. If for example you create and secure a service using X509 certificates and then use our Guidance Pacakge to generate your proxy - in addition to simply creating the proxy it also uses MEX to work out what requirements the client has - and will then prompt you for the client cert! It gets even better though - if you change the security policy (AuthenticationMode) for the service to MutualCertificate. Then regenerate the client code - it now prompts you for both the client cert and the server cert!!!

Another cool feature is for the architect (or lead dev) to be able to predefine settings like which tokens to use and which message protection levels to use. Then when the develoeprs start securing the service only the tokens you want to use will be available etc. We have also designed a UI that simplies trying to work out how to secure your services - essentially providing an abstraction on top of both the ProtectionOrder and ProtectionLEvel setting - so that simplfies things as well...

Anyway - if you want some fun over the long weekend take a look...

 

 

Published Friday, May 26, 2006 12:56 PM by Jason Hogg

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

# re: Service Factory: Helping you design Secure Web Services using WCF

Keep up the good work
Sunday, June 11, 2006 3:56 AM by philip james campise

# FxCop rules for securing WCF services

One of the coolest features (IMHO) that you will find in the september CTP version of the Web Service Software Factory project, in particular related to the WCF Security Guidance Package, is the new WCF Security Code Analysis feature. This new feature

Wednesday, October 04, 2006 2:15 AM by Hernan de Lahitte's blog

# X509 Certificate validation

One of the coolest features (IMHO) that you will find in the september CTP version of the Web Service

Tuesday, April 21, 2009 7:48 AM by Hernan de Lahitte's blog

Leave a Comment

(required) 
required 
(required) 

  
Enter Code Here: Required
 
Page view tracker