WCF Security Resources
This is a digest of WCF Security resources I was collecting for some time. Drop me a comment in case it is useful.
Guidelines
- patterns & practices WCF 3.5 Security Guidelines Now Available
- How Tos (WCF Security)
- WCF Security Learning Guide
- declarative security framework for Windows Communication Foundation (WCF)
- How To: Create a “Hello World” WCF Service Using Visual Studio
- How To Consume WCF Using AJAX Without ASP.NET
Input/Data Validation
Authentication
- WCF - Common Security Scenarios
- Certificate based Authentication and WCF
- Certificate based Authentication and WCF (Message Security)
- Certificate based Authentication and WCF (Transport Security)
- Certificate based Authentication and WCF (Mode independent)
- WCF Authentication: Custom Username and Password Validator
- Mapping Credentials to Authentication Schemes
Authorization
- WCF - Authorization
- RolePrincipal vs. RoleProviderPrincipal
- Building Claims-Based Security Model in WCF
- Building Claims-Based Security Model in WCF - Part 2
- Custom Principals and WCF
- Using IdentityModel: Adding ASP.NET Support Part 1 (Authentication based Claims)
- Using IdentityModel: Adding ASP.NET Support Part 2 (Claims Manager)
Session Management
Deployment
- Hosting WCF Services in ASP.NET - The Survival Guide
- WCF proxies in partially trusted ASP.NET Apps
- Hosting WCF Service in IIS
- Hosting and Consuming WCF Services
- Tradeoffs of IIS Hosting
- Setting a User Principal on the Endpoint
- Bindings and Security
- Controlling HTTP Connection Limits
- Walkthrough: Setting up a self hosted WCF Service with SSL
- WCF Security In Intranet Scenario : Thoughts On Cons and Pros
- Extend Your WCF Services Beyond HTTP With WAS
Sensitive Data
Auditing and Logging
- Tracing Across Services
- Troubleshooting WCF In Production Environments
- Using Service Trace Viewer for Viewing Correlated Traces and Troubleshooting
Exception Handling
Comments
- Anonymous
April 18, 2008
Wow ... I'm doing a presentation on Intro to WCF tomorrow at a Code Camp, and was wondering where to go next for a more advanced presentation at the local UG in June. I think you just made my day. - Anonymous
April 18, 2008
Andrew - great to hear I am of help. What topic would you add to the list? - Anonymous
April 23, 2008
I had a great time visiting with a great team at Verizon this week. I was able to present on a number - Anonymous
April 23, 2008
介绍一些WCF、WF、ADO.NET SyncServices和ClickOnce的很多学习资料 - Anonymous
April 23, 2008
Yes - it's useful!You reminded me we haven't shared our WCF Security resource list yet. I'll send it your way for review. - Anonymous
April 24, 2008
Thanks alikI read most of the links and I found a lot of value.Please continue to find great resources and post themmanu - Anonymous
April 24, 2008
Manu!Thanks for checking in and happy to hear it was of help.alikl