Re: Testing Routine for WSE 2.0

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I would first question the use of UsernameTokens. How are you sending the
password (hash, none, clear). I would tend to favor SCTs over UT if
security is important.

--
William Stacey [MVP]

"Microsoft" <chris.arnold@xxxxxxxxxxxxxxxxxx> wrote in message
news:OXoD9DrwFHA.3312@xxxxxxxxxxxxxxxxxxxxxxx
> Hi All,
>
> I have almost completed the first stage of our security upgrades for our
> web services. So far I have implemented Authentication, Authorization,
> Signing & Encryption from client to server. The first 2 of these I can
> test very simple. However, I am uncertain how to test the latter 2
> subjects (short of becoming a fulltime hacker who can intercept the SOAP
> message and change it!).
>
> Does anyone have any proven methods for testing the integrity of the
> messages?
>
> As background, I am using UsernameToken object as my SecurityToken model;
> I have implemented my own UsernameTokenManager that assigns Roles to the
> authenticated token.
>
> Many thanks,
>
> Chris
>


.



Relevant Pages

  • Re: Testing Routine for WSE 2.0
    ... I am using UTs with passwords sent Hashed. ... >I would first question the use of UsernameTokens. ... >> I have almost completed the first stage of our security upgrades for our ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • How do I get the ws-security header block in the wsdl?
    ... I am trying to configure my web service to use userNameTokens via ws- ... I do not understand why there is no ws-security header ... I want the security header block in the WSDL so I can consume the .NET ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: Password hashes
    ... There are only LM and NTLM hashes. ... There is an NTLMv2 hash but it is not stored. ... authenticating to the network. ... Auditing and reviewing the security logs ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Password hashes
    ... NTLM hash as the key. ... There is however no locally stored NTLMV2 hash of passwords. ... Auditing and reviewing the security logs ... secure their network and data and the documentation to do such at TechNet ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Crack in Computer Security Code Raises Red Flag
    ... > Crack in Computer Security Code Raises Red Flag ... Hash functions are at work, for instance, for most of the ... the uniqueness of the hash is what makes ... > Also worrying cryptographers is a stream of recent hash compromises. ...
    (sci.crypt)