<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Architecture</title><link>http://forums.asp.net/16.aspx</link><description>Discuss and debate ASP.NET application designs. &lt;a href="http://aspadvice.com/SignUp/list.aspx?l=8&amp;c=17" target="_blank"&gt;Email List&lt;/a&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: SOA and authentication / authorization</title><link>http://forums.asp.net/thread/3385692.aspx</link><pubDate>Thu, 03 Sep 2009 14:31:01 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3385692</guid><dc:creator>atconway</dc:creator><author>atconway</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3385692.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=16&amp;PostID=3385692</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;One other note to add here- you didn&amp;#39;t really elude to the type of service you were planning on creating. IMO there is no question to use WCF if you are starting from scratch.&amp;nbsp; Here is a good magazine article on WCF Authorization:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Authorization In WCF-Based Services:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msdn.microsoft.com/en-us/magazine/cc948343.aspx"&gt;http://msdn.microsoft.com/en-us/magazine/cc948343.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I have used both .asmx web services with WSE 3.0 and WCF, and I need to point out that using WSE 3.0 is &lt;strong&gt;&lt;em&gt;not &lt;/em&gt;&lt;/strong&gt;the way to go if starting new.&amp;nbsp; The reason is that WSE will not be further enhanced by Microsoft and is viewed as becoming obsolete in route to the more robust WCF services and&amp;nbsp;the associated&amp;nbsp;securtiy model.&lt;/p&gt;
&lt;p&gt;In fact, if you are using VS.NET 2008, WSE 3.0 does not even directly integrate.&amp;nbsp; There are work arounds I have used to get it integrated but they are incosistient in success of working in my experience.&amp;nbsp; So the best advice, move to WCF if possible.&lt;/p&gt;</description></item><item><title>Re: SOA and authentication / authorization</title><link>http://forums.asp.net/thread/3285259.aspx</link><pubDate>Fri, 10 Jul 2009 06:06:23 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3285259</guid><dc:creator>longhorn2005</dc:creator><author>longhorn2005</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3285259.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=16&amp;PostID=3285259</wfw:commentRss><description>&lt;p&gt;Hi there,&lt;/p&gt;&lt;p&gt;There&amp;#39;s already quiet a few information on MSDN about it also vivek has already posted very useful information to get you started. &lt;/p&gt;&lt;p&gt;I will also recommend you to have a quick look through the security best practices by patterns and practices group &lt;a href="http://msdn.microsoft.com/en-us/library/aa302428.aspx"&gt;http://msdn.microsoft.com/en-us/library/aa302428.aspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;If you are planning to head down WCF path (which i strongly recommend you should consider) then you can have a look at WCF specific information &lt;a href="http://msdn.microsoft.com/en-us/library/ms732362.aspx"&gt;http://msdn.microsoft.com/en-us/library/ms732362.aspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Hope this helps&lt;/p&gt;&lt;p&gt;Sunny&lt;/p&gt;</description></item><item><title>Re: SOA and authentication / authorization</title><link>http://forums.asp.net/thread/3270874.aspx</link><pubDate>Thu, 02 Jul 2009 09:23:48 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3270874</guid><dc:creator>vivek_iit</dc:creator><author>vivek_iit</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3270874.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=16&amp;PostID=3270874</wfw:commentRss><description>&lt;p&gt;For ASMX webservices, you can use WSE, here are some links:&lt;/p&gt;&lt;p&gt;http://www.codeproject.com/KB/webservices/KerberosAuthenticationPOC.aspx&lt;/p&gt;&lt;p&gt;http://www.codeproject.com/KB/cpp/authforwebservices.aspx&lt;/p&gt;&lt;p&gt;For WCF based services (recommended), here are some links:&lt;/p&gt;&lt;p&gt;http://nayyeri.net/blog/custom-username-and-password-authentication-in-wcf-3-5/&lt;/p&gt;&lt;p&gt;http://msdn.microsoft.com/en-us/security/aa570351.aspx (Geneva framework)&lt;br /&gt;&lt;/p&gt;&lt;p&gt;HTH,&lt;/p&gt;&lt;p&gt;Vivek&lt;br /&gt;&lt;/p&gt;</description></item><item><title>SOA and authentication / authorization</title><link>http://forums.asp.net/thread/3253497.aspx</link><pubDate>Tue, 23 Jun 2009 16:50:50 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3253497</guid><dc:creator>JeffreyABecker</dc:creator><author>JeffreyABecker</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3253497.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=16&amp;PostID=3253497</wfw:commentRss><description>&lt;p&gt;I&amp;#39;m examining moving our app to a more formally SOA architecture.&amp;nbsp; Right now authentication / Authorization is done in a mish-mash of ways all of which revolve around picking up the login cookie.&amp;nbsp; Does anyone have advice on how to structure our services with security in mind?&amp;nbsp; How do I get credential information into the service etc?&lt;br /&gt;&lt;/p&gt;</description></item></channel></rss>