choosing wcf security mode -
i going work on wcf service expose our catalog information several external organization access. authenticate/authorize them using simple table in end contains login information. (right there one, grow down line) should using wcf message transport credential scenario? thoughts/suggestions welcome. matter how access our wcf service? using vs2012.
given clients may not using wcf or windows, recommend using wshttpbinding, allows use message security , attach username , passwords request. on host can use custom password validator verify credentials against database. see http://msdn.microsoft.com/en-us/library/aa702565.aspx more information on that. ssl additional option if want transport secured.
Comments
Post a Comment