Re: securing a web service: options?

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi,

Take a look to the Web Services Security Guide (Microsoft Patterns &
Practices), http://msdn2.microsoft.com/en-us/library/aa480545.aspx
It is best place to go regarding security for web services.

Regards,
Pablo Cibraro.


"KJ" <n_o_s_p_a__m@xxxxxxxx> wrote in message
news:1164904450.826128.236250@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello All,

I have to secure my first real B2B web service. Could you please
provide some guidance as to which method of security I should use. One
caveat is that we will not be using SSL on the server side as per the
networking department. Windows authentication is also probably not an
option, as this web service will be interacting between two separately
located companies. I have read a little bit about passing credentials
in SOAP headers, but the MSDN documentation seems to be sparse on this
topic. Any suggestions and/or links would be appreciated. Also, if you
could point me to the docs on web services sessions, that would be
helpful too. Thanks.

p.s. This is a Visual Studio 2005 Web Site



.



Relevant Pages

  • Microsoft .NET
    ... reading up various documents that discuss - "What is Microsoft .Net" ... I'm trying to write a paper on security and software development using ... utilize connected solutions using Web services, ... language, of course, but also: ...
    (microsoft.public.dotnet.general)
  • Re: C# Exceptions
    ... What attack scenarios could be possible on such an application? ... > Are these issues really a security threat for a desktop application? ... > this application gets from its web services. ... > Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: About Best practices...
    ... You can find the answers in the ASP.NET security best practices ... All this is in Web applications and XML Web Services ... Users will log to my web site from any platform. ...
    (microsoft.public.dotnet.security)
  • Re: WebServices Testing
    ... I am tasked with doing some security testing on a new web services ... But,,, this is why the infosec bizz has become cowboy territory rather then a serious ... maybe its time that each security certification selling company keeps a public list on ...
    (Pen-Test)
  • Announce - Wrox Press releases "Professional Web Services Security" book
    ... Today web services is attracting many businesses to incorporate the ... technology, and soon many applications are seen using it. ... The security architecture designed for the Web is ...
    (comp.security.unix)