|
|
|
Double Hop Windows Authentication with IIS Hosted WCF Service |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Double Hop Windows Authentication with IIS Hosted WCF Service Par Security ToolsLe [2009-11-04] à 05:54:02
Présentation : Hello, Randy Evans here. I am a principal developer on the Information Security Tools Team. In a recent project, we had a intranet web site that called an IIS hosted WCF service. The WCF service, in turn, called a SQL Server Reporting Services SSRS web service. We wanted to utilize the authorization mechanisms of SSRS. To do this, we needed to impersonate the end user when we made the calls to SSRS. For the above scenario to work, we needed to perform an authentication double hop. Meaning, the web site needed to impersonate the user when calling the WCF service and the WCF service also needed to impersonate the user when calling SSRS. Our project was using Kerberos based authentication. By default, Windows authentication does not allow a user s impersonated credentials to be reused when attempting to authenticate to a remote resource. The SSRS web service is considered a remote resource from the WCF service. There are many blogs and listings in social networks that explain how to impersonate a user coming to an IIS hosted WCF service. However, these articles do not explain how to perform the double hop. Once the service is set up to accept impersonation, the answer was actually quite simple. Windows authentication supports 5 levels of impersonation. The forth, and default, level is Impersonate. The fifth level is Delegate. The default level does not allow the double hop authentication. To enable the double hop, the client calling the WCF service needs to set the impersonation level of the WCF service to Delegate. This is performed with the following code Service1Client service new Service1Client Sets the impersonation level to delegation. Without delegation level impersonation, the WCF service would not be able to impersonate to a remote server. service.ClientCredentials.Windows.AllowedImpersonationLevel System.Security.Principal.TokenImpersonationLevel.Delegation string retString service.GetData 1 In addition to setting the impersonation level to Delegate, there are two other places where changes need to occur. 1. Enable impersonation at the web site. Either enable ASP.NET impersonation for the entire site or temporarily impersonate the user from within the web site by using WindowsIdentity.Impersonate token . Add the following attribute to each method in the WCF service that needs impersonation. OperationBehavior Impersonation ImpersonationOption.Allowed Example OperationBehavior Impersonation ImpersonationOption.Allowed public string GetData int value This is the service call that requires the double hop. ReportingService2005 reportService new ReportingService2005 reportService.Credentials System.Net.CredentialCache.DefaultCredentials Get a listing of all items in the reporting service catalog that are in the root folder. CatalogItem catalogItems reportService.ListChildren , false StringBuilder retString new StringBuilder foreach CatalogItem catalogItem in catalogItems retString.Append catalogItem.Name retString.Append You entered value.ToString return retString.ToString NOTE ImpersonationOption.Required will work as well. 2. There are three modifications required in the web.config file of the WCF Service web application. 1. Add the following binding node under the node to enforce Windows authentication. 2. Reference this binding from the service endpoint node. Note that the binding name string must match the bindingConfiguration string. In this example the string value is winAuthBasicHttpBinding . 3. Add the following node to the service s serviceBehaviors behavior node. Example Follow the below link for more details from MSDN on using impersonation with WCF services. http msdn.microsoft.com en-us library ms730088.aspx
Les mots clés de la revue de presse pour cet article : windows authentication Les videos sur SecuObs pour les mots clés : windows authentication Les mots clés pour les articles publiés sur SecuObs : windows Les éléments de la revue Twitter pour les mots clé : windows authentication
Les derniers articles du site "Security Tools" :
- Farewell from Mark Curphey Please Help Me Fight Blood Cancer - The Web Protection Library plans and processes. - Silverlight 3.0 Datagrid - How to change a cell state - How To Use CAT.NET 2.0 Beta - How To Use CAT.NET V2.0 Beta - CAT.NET 2.0 - Beta - How To View The Header of an EXE DLL - How To Customize CUIT scripts - How To Data Drive CUIT Scripts - Delay Between Actions Feature in CUIT
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|