Showing posts with label WCF. Show all posts
Showing posts with label WCF. Show all posts

Authorization Options in WCF

WCF supports three basic authorization approaches:

Role-based: Access to WCF operations is secured based on the role membership of the caller. Roles are used to partition your application’s user base into sets of users that share
the same security privileges within the application; for example, Senior Managers,Managers, and Employees .Users are mapped to roles, and if the user is authorized to perform the requested operation, the application uses fixed identities with which to access
resources. These identities are trusted by the respective resource managers
for example Database,File system.. 
 
[PrincipalPermission(SecurityAction.Demand, Role="Admin")]
        public string GetData(int value)
        {
            return string.Format("Your Return: {0}", value);
        }

Identity-based: WCF supports an Identity Model feature, which is an extension of rolebased authorization. Identity Model enables you to manage claims and policies in order to authorize clients. With this approach, you can verify claims contained within the authenticated users’ credentials. These claims can be compared with the set of
authorization policies for the WCF service. Depending on the claims provided by the client,the service can either grant or deny access to the operation or resources. Identity Model is useful for fine-grained authorization and is most beneficial when using issue token
authentication.

 Resource-based. Individual resources are secured by using Windows access control lists (ACLs). The WCF service impersonates the caller prior to accessing resources, which allows the operating system to perform standard access checks. All resource access is performed
by using the original caller’s security context. This impersonation approach severely impacts application scalability, because it means that connection pooling cannot be used effectively within the application’s middle tier.

In enterprise-level applications where scalability is essential, a role-based or identity based approach to authorization represents the best choice. For small-scale intranet applications that serve per-user content from resources (such as files) that can be secured with Windows ACLs

NB:Example will be posted later

Bindings in WCF

The following summarizes are common bindings in WCF.

basicHttpBinding Configures and exposes endpoints that are able to
Communicate with ASP.NET Web Services (ASMX)–based Web
Services and clients and other services that conform to the
WS-I Basic Profile 1.1 specification. By default, it has security
Disabled
  <bindings>
      <basicHttpBinding>
        <binding name="BasicHttpEndpointBinding">
          <security mode="TransportCredentialOnly">
            <transport clientCredentialType="Windows" />
          </security>
        </binding>
        </basicHttpBinding>
    </bindings> 

wsHttpBinding Defines a secure, reliable, interoperable binding suitable for non-duplex service contracts. The binding implements thefollowing specifications: WS-Reliable Messaging for reliability,and WS-Security for message security and authentication. Thetransport is HTTP, and message encoding is text/XML
<bindings>
      <wsHttpBinding>
        <binding name="wsHttpEndpointBinding">
          <security  mode="Transport">
            <transport clientCredentialType="Windows" />
          </security>
        </binding>
        </wsHttpBinding>
    </bindings> 

ws2007HttpBinding Defines a secure, reliable, interoperable binding suitable for non-duplex service contracts. The binding implements the following specifications: WS-Reliable Messaging for reliability,
and WS-Security for message security and authentication. The
transport is HTTP, and message encoding is text/XML
encoding. The ws2007HttpBinding provides binding similar to
wsHttpBinding but uses the standard for OASIS (Organization
for the Advancement of Structured Information Standards).
By default, it provides message security with Windows
authentication.
<bindings>
      <ws2007HttpBinding>
        <binding name="ws2007HttpEndpointBinding">
          <security  mode="Transport">
            <transport clientCredentialType="Windows" />
          </security>
        </binding>
        </ws2007HttpBinding>
    </bindings>
netTcpBinding Specifies a secure, reliable, optimized binding suitable for ross-machine communication. By default, it generates a runtime Communication stack with transport security and
Windows authentication as default security settings. It uses
TCP protocol for message delivery, and binary message
Encoding.
<bindings>
      <netTcpBinding>
        <binding name="NetTCPEndpointBinding">
          <security  mode="Transport">
            <transport clientCredentialType="Windows" />
          </security>
        </binding>
        </netTcpBinding>
    </bindings> 

netNamedPipeBinding Defines a binding that is secure, reliable, optimized for crossprocess communication on the same machine. By default, it generates a run-time communication stack with WSReliableMessaging for reliability, transport security for
transfer security, named pipes for message delivery, and
binary message encoding. It is not secured by default.
 
<bindings>
      <netNamedPipeBinding>
        <binding name="NetnamedPipeEndpointBinding">
          <security  mode="Transport">
            <transport protectionLevel="EncryptAndSign"/>
          </security>
        </binding>
        </netNamedPipeBinding>
    </bindings>
 netMsmqBinding Defines a queued binding suitable for cross-machine communication.
<bindings>
      <netMsmqBinding>
        <binding name="NetMSMQEndpointBinding">
          <security  mode="Transport">
            <transport  msmqProtectionLevel="EncryptAndSign"/>
          </security>
        </binding>
        </netMsmqBinding>
    </bindings>
 
wsFederationHttpBinding Defines a binding that supports federated security. It helps implement federation, which is the ability to flow and share identities across multiple enterprises or trust domains for authentication and authorization. WCF implements
federation over message and mixed mode security but not
over transport security. Services configured with this binding
must use the HTTP protocol as transport.

For Fedaration : http://wcfsecurity.codeplex.com/wikipage?title=What%20is%20federated%20security%3F
<bindings>
      <wsFederationHttpBinding>
        <binding name="wsFederationEndpointBinding">
          <security  mode="Transport">
            <message negotiateServiceCredential="false"></message>
          </security>
        </binding>
        </wsFederationHttpBinding>
    </bindings>

ws2007FederationHttpBinding Defines a binding that derives from wsFederationHttpBinding and supports federated security. It helps implement federation, which is the ability to flow and share identities across multiple enterprises or trust domains for
authentication and authorization. WCF implements
federation over message and mixed mode security but not
over transport security. Services configured with this binding
must use the HTTP protocol as transport.

  <bindings>
      <ws2007FederationHttpBinding>
        <binding name="ws2007FederationEndpointBinding">
          <security  mode= "Message">
            <message negotiateServiceCredential="false"></message>
          </security>
        </binding>
        </ws2007FederationHttpBinding>
    </bindings>
wsDualHttpBinding Defines a secure, reliable, and interoperable binding that is suitable for duplex service contracts or communication through Simple Object Access Protocol (SOAP) intermediaries.

<bindings>
      <wsDualHttpBinding>
        <binding name="wsDualHttpEndpointBinding">
          <security  mode= "Message">
            <message negotiateServiceCredential="false"></message>
          </security>
        </binding>
        </wsDualHttpBinding>
    </bindings>
customBinding Allows you to create a custom binding with full control over the message stack.

  <bindings>
      <customBinding>
        <binding name="CustomHttpEndpointBinding">
          <httpsTransport allowCookies="true"></httpsTransport>
        </binding>
        </customBinding>
    </bindings>