Re: Kerberos Authentication and WSE 3.0



Hi Many thanks,

I have followed the pattern article. I am testing this on a windows xp
box


1) I created a domain account with suggested privileges
2) I have changed the processmodel section to run under this account
3) I have created a arbitrary SPN in my domain controller for the
account

But the WSE 841 refuses to go away. This is a proof of concept
application and i am unable to get past this for more than 48 hours!!!

System.Web.Services.Protocols.SoapHeaderException:
System.Web.Services.Protocols.SoapHeaderException: Server unavailable,
please try later ---> System.ApplicationException: WSE841: An error
occured processing an outgoing fault response. --->
System.Web.Services.Protocols.SoapHeaderException:
Microsoft.Web.Services3.Security.SecurityFault: SecurityContextToken is
expected but not present in the security header of the incoming
message.
at
Microsoft.Web.Services3.Security.SecureConversationServiceReceiveSecurityFilter.ValidateSecureConversationMessageSecurity(SoapEnvelope
envelope, Security security, MessageProtectionRequirements request)
at
Microsoft.Web.Services3.Security.SecureConversationServiceReceiveSecurityFilter.ValidateMessageSecurity(SoapEnvelope
envelope, Security security)
at
Microsoft.Web.Services3.Security.ReceiveSecurityFilter.ProcessMessage(SoapEnvelope
envelope)
at Microsoft.Web.Services3.Pipeline.ProcessInputMessage(SoapEnvelope
envelope)
at Microsoft.Web.Services3.WseProtocol.FilterRequest(SoapEnvelope
requestEnvelope)
at Microsoft.Web.Services3.WseProtocol.RouteRequest(SoapServerMessage
message)
at System.Web.Services.Protocols.SoapServerProtocol.Initialize()
at System.Web.Services.Protocols.ServerProtocolFactory.Create(Type
type, HttpContext context, HttpRequest request, HttpResponse response,
Boolean& abortProcessing)

.



Relevant Pages

  • Re: WebControls error in an application running under an impersonate identity
    ... It's a question actually what would be worse from security point of view to have domain account and password to be listed in plain ... text file on your system or run under local system account. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Accessing AD from IIS 6 vs IIS 5
    ... It is a security issue related to the account the current thread is ... you are probably running as a domain account or local system (which will use ... You probably either need to supply a server name and credentials or ensure ...
    (microsoft.public.dotnet.framework.aspnet)
  • Local Account Vs Domain Account
    ... what are the disadvantages/risks (from security standpoint)of ... using a Domain Account instead of a Local Account and vice versa. ...
    (Focus-Microsoft)
  • Re: MBSA, Office Update, Versions, Failures
    ... I apologize for posting this to three groups (MBSA, Windows Update, ... with Domain User account. ... Microsoft Baseline Security Advisor (? ... Office 2000 Security Patches - Red X's, ...
    (microsoft.public.officeupdate)
  • Re: write with cURL
    ... you can stop making excuses. ... up an account for you, process the billing, etc. ... possible features from a web site to make up for the security issues. ... Nothing you have told me shows me you know how to lock down a server ...
    (alt.php)