|
|
|
Establishing Trust with the .NET Access Control Service (Geneva Beta 2) |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Establishing Trust with the .NET Access Control Service (Geneva Beta 2) Par www.leastprivilege.comLe [2009-05-15] à 10:41:30
Présentation : In Geneva you use a IssuerNameRegistry to establish trust with token issuers. The job of the registry is to parse the issuer details and return a well-known string identifying that issuer. If the registry cannot determine that well known string, the issuer is considered non-trusted and request processing is stopped. Typically it is enough to inspect the X509 certificate that was used to issue the SAML token, but with the Access Control Service the situation is a little different. The ACS uses a multi-tenant model and signs all outgoing tokens with the same certificate. This means it is not sufficient to check the signature only to determine that the token was issued by a specific instance of the ACS. In addition you also have to check the value of the SAML issuer URI which contains the logical issuer name which in turn contains the ACS solution name. Prior to Geneva Beta 2 you had to use two different extensibility points to do both checks. I wrote about that here. Starting with Beta 2, the issuer name registry now has the capability to parse both the physical and logical issuer. Great! Find a sample implementation below: class AccessControlServiceIssuerNameRegistry : IssuerNameRegistry { string _solutionName = "leastprivilege"; string _acsThumbprint = "6de1689a739d548a5690dbc3894b953ef6123d93"; string _samlIssuer; public AccessControlServiceIssuerNameRegistry() { _samlIssuer = String.Format("http://{0}.accesscontrol.windows.net/", _solutionName); } public override string GetIssuerName(SecurityToken securityToken) { // should never get called throw new NotImplementedException(); } public override string GetIssuerName(SecurityToken securityToken, string requestedIssuerName) { var issuerToken = securityToken as X509SecurityToken; if (issuerToken == null) { throw new ArgumentException("securityToken"); } if (string.IsNullOrEmpty(requestedIssuerName)) { throw new ArgumentNullException("requestedIssuerName"); } if (!string.Equals(_acsThumbprint, issuerToken.Certificate.Thumbprint, StringComparison.OrdinalIgnoreCase)) { throw new SecurityTokenException( "Token not issued by the Access Control Service"); } if (!string.Equals(_samlIssuer, requestedIssuerName, StringComparison.OrdinalIgnoreCase)) { throw new SecurityTokenException( "Token not issued by the requested instance of the Access Control Service"); } return _samlIssuer; } } []
Les mots clés de la revue de presse pour cet article : trust
Les derniers articles du site "www.leastprivilege.com" :
- Moving to a new Blog - API for the X509 Certificate Store - Thinktecture.IdentityModel.Http and the ASP.NET Web API CodePlex bits - Identity in .NET 4.5Part 4 Claims over Kerberos - Thinktecture IdentityServer and Contrib Project now on GitHub - Identity in .NET 4.5Part 3 Breaking changes - Identity in .NET 4.5Part 2 Claims Transformation in ASP.NET Beta 1 - Identity in .NET 4.5Part 1 Status Quo Beta 1 - ASP.NET WebAPI Security 5 JavaScript Clients - ASP.NET WebAPI Security 4 Examples for various Authentication Scenarios
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|