WCF, Security and Certificates

后端 未结 3 471
小鲜肉
小鲜肉 2021-02-03 14:33

I have a client/server WCF application that needs some sort of user authentication against a database. The application (both client and server together) is being developed to b

3条回答
  •  自闭症患者
    2021-02-03 15:29

    If your going to be crossing firewall boundaries then certificates are going to be your best solution. I don't know much about the specifics about applications for certificates or your application. Unfortunately, as far as i know, i think you will have to help them apply for certificates or they will have to do it their self unless they want to undertake in the process of installing their own certificate server. If the app will be internal then windows authentication will work and is VERY easy but if you think your going to have clients that user your application across firewall boundaries then you might as well invest the time in using certificates because certificates will work everywhere. Now there is something called federated security where you delegate the permission of authentication to another entity. I think this is used if say you have to domains and you want to delegate permission say of someone on another domain that is not on your domain to their domain but its pretty complex and my understanding of its very limited but by the sound of your requirements certificates is the way to go.

    Security is not supposed to be easy :)

提交回复
热议问题