SEARCH RESULTS
 
Showing 1-10 of 13 records
 
Expand article

WCF Security Guidance from P&P

2008-04-04 06:09:00 by Keith Brown in Security Briefs
 
...WCF Security Guidance Project is in progress on CodePlex. This is our first release of prescriptive guidance modules for WCF Security How Tos Our How Tos give you step by step instructions for performing key tasks How To - Create and Install Temporary Certificates in WCF for Message Security During Development How To - Create and Install...
 
 
 
 
 
Expand article

WCF Security Guidance from P&P

2008-04-04 12:09:00 by keith-brown in Security Briefs
 
...WCF Security Guidance Project is in progress on CodePlex. This is our first release of prescriptive guidance modules for WCF Security How Tos Our How Tos give you step by step instructions for performing key tasks How To - Create and Install Temporary Certificates in WCF for Message Security During Development How To - Create and Install...
 
 
 
 
 
Expand article

WCF Security Guidance from P&P

2008-04-04 12:09:00 by keith-brown in Security Briefs
 
...WCF Security Guidance Project is in progress on CodePlex. This is our first release of prescriptive guidance modules for WCF Security How Tos Our How Tos give you step by step instructions for performing key tasks How To - Create and Install Temporary Certificates in WCF for Message Security During Development How To - Create and Install...
 
 
 
 
 
Expand article

Laptop stolen from Workers Compensation Fund auditor

The Article has images
2008-01-03 11:25:59 by Evan Francen in The Breach Blog
...WCF The Salt Lake City-based WCF provides worker compensation insurance coverage to more than 30,000 companies, representing about 61 percent of the businesses operating in the state Contractor/Consultant/Branch None Victims Client workers and companies Number Affected 2,800 workers AND 1,400 companies Types of Data Social Security...
 
 
 
 
 
Expand article

Introducing Microsoft Code Name Zermatt

2008-07-09 20:27:00 by keith-brown in Security Briefs
 
...WCF in the System.IdentityModel assembly But today I'm happy to announce that there's a new path forward in the claims world. Zermatt is the "identity framework" that I've been itching to talk about, but until today, hasn't been announced publicly Well, Vittorio just made the announcement just a moment ago, and now you can get your hands on...
 
 
 
 
 
Expand article

Identity Framework Probable Feature List

The Article has images
2007-12-16 06:42:00 by Keith Brown in Security Briefs
...WCF Fx supplies a custom ServiceHostFactory (currently called WindowsInformationCardServiceHostFactory This allows you to create a .SVC file for a WCF endpoint to expose your STS Fx supplies an HttpModule for the traditional ASP.NET authentiation pipeline According to Vittorio, this "automates a lot of the validation work in the framework"....
 
 
 
 
 
Expand article

PrincipalPermissionAttribute and Static ctor Leads to DoS

2007-12-03 09:03:00 by Keith Brown in Security Briefs
 
...WCF. I recommended caution in my guidebook , because of the nasty type load exception that you can run into if the first request to the class is denied by the attribute Be careful about using this attribute at the class level. If the class to which you apply it happens to have a static constructor (or, even worse, if it may get one in the...
 
 
 
 
 
Expand article

Authorization vs. Business Logic

2008-01-09 05:37:00 by Keith Brown in Security Briefs
 
...WCF's ServiceAuthorizationManager is all about, for example But it's not always that easy, is it? What if you want the outcome of the method to be slightly different depending on the user's security context? Perhaps you're going to use the value of some claim to customize the output, or limit your actions somewhat depending on that context?...
 
 
 
 
 
Expand article

I'm coming to New York in February

2008-01-23 12:44:00 by Keith Brown in Security Briefs
 
...WCF, Workflow, WPF, and one of my favorite topics, the new claims-based identity model (which ADFS and CardSpace use). The course runs Tuesday through Friday If this sounds intriguing, sign up today
 
 
 
 
 
Expand article

Patterns & Practices Improving Web Services Security: Scenarios and Implementation Guidance for WCF

2008-06-08 02:11:44 by mcurphey in Mark Curphey - SecurityBuddha.com
 
My cool security friend JD has done it again (in BETA). http://www.codeplex.com/WCFSecurityGuide These things are the definitive guides to the topic. Masterpieces! Download the Improving Web Services Security Guide(BETA