Re: Please Help me- Creating Custom tokens

From: Softwaremaker (msdn_at_removethis.softwaremaker.net)
Date: 10/20/04


Date: Wed, 20 Oct 2004 13:44:14 +0800

Yes, you are free to do implement your own security elements in the header
if you choose to. They are not standards-based though so if you trying to
interoperate with other systems that you have no control of, you may run
into problems.

There may be a security caveat breach though, anyone can do a MITM attack
and replace your custom security token lock-stock-barrel with an
unauthorized or untrusted one if you choose not to authenticate the user at
every method invocation.

-- 
Thank you.
~Softwaremaker
==================================
"Sumaira Ahmad" <sumaira.ahmad@gmail.com> wrote in message
news:1627c5ae.0410191841.292c952c@posting.google.com...
> But i guess that deals with the client sending a custom token obtained
> from a token issuer and using that to encrypt and sign the requests..
> But the problem i want to solve is slightly different since I want to
> send an encrypted token in the header of the response message . The
> token created by the server has some  user info such as his first name
> last name , etc. Will those samples help me??
> I did have a look at it once, but was wondering if there was an easy
> way of implementing it.. Looked pretty complicated to me...
> So u think that can help my implementation??
>
> Thanks,
> Sumaira
>
> "Softwaremaker" <msdn@removethis.softwaremaker.net> wrote in message
news:<uVKjDoitEHA.3448@TK2MSFTNGP09.phx.gbl>...
> > If you are looking for some custom security token implementations, you
can
> > check out some of the excellent samples that came with the WSE2.0
download
> >
> > CustomBinarySecurityToken and the CustomXMLSecurityToken samples.
> >
> > Some of them uses an implementation of the SCT (SecureContextToken) as
> > outlined in WS-Trust.
> >
> > -- 
> > Thank you.
> >
> > Regards,
> > Softwaremaker
> > http://www.softwaremaker.net/blog
> >
> > =========================================
> >
> > "Sumaira Ahmad" <sumaira.ahmad@gmail.com> wrote in message
> > news:1627c5ae.0410191230.1e4729e8@posting.google.com...
> > > Hi,
> > >
> > > Please help me know how to do this..
> > >
> > > In ASP.NET Web Application/We Server , I want to send back an
> > > encrypted token from the server to the client. This encrypted token
> > > will contain information such as: Username, groups that he belongs to,
> > > timestamp and expiry time. The client would just store this token and
> > > send it to the server the next time when it requests a page instead of
> > > sending a Username token and getting it authenticated and authorized
> > > again.
> > > Can someone please tell me how to create an encrypted token on the
> > > server and send it back in the response Soap Header??
> > >
> > > Please.. Any help would be highly appreciated.
> > >
> > > Regards,
> > > Sumaira


Relevant Pages

  • Re: UnauthorizedAccessException when using MSDTC
    ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
    (microsoft.public.data.ado)
  • Re: Routing and Remote Access - Authentication Failure
    ... because the real client computer can tunel through it's local NAT router, ... travel the Intrenet, join the VPN and access the server, when this feature ... Their security system decided that the server was trying to steel ...
    (microsoft.public.windows.server.networking)
  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)
  • RE: Problems with security requirements in Windows WorkGroups.
    ... "A remote side security requirement was not fulfilled during authentication. ... small chat application between a client and a server ... When I try to use the TCP channel I get the error (with NO inner exception ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: VPN -- the next consumer "turnkey"?
    ... I'm not a security expert. ... "A Hamachi system is comprised of backend servers and end-node ... Server nodes track client's locations and provide ... services without providing Hamachi with a list of client IP's. ...
    (alt.internet.wireless)