Browse by Tags

All Tags » WCF
  • Security Implications Of Services Impersonating Callers

    In my last post (Caller Impersonation for WCF Services Hosted Under IIS Appears Broken), I laid out my rationale for why I felt that the security of services impersonating a caller when hosted under IIS was broken. To be responsible, I feel it necessary to follow-up my previous assertion by noting that such a configuration is not a best-practice, ...
    Posted to Paul Mehner's Blog (Weblog) by pmehner on December 23, 2007
  • Caller Impersonation for WCF Services Hosted Under IIS Appears Broken

    There is a security feature of WCF services hosted under IIS that I find poorly implemented. In all honesty, it appears to be broken and non-compliant with its intended purpose. If you’re developing services for use in the intranet environment, then it’s quite reasonable for you to expect that a service can impersonate your Windows identity ...
    Posted to Paul Mehner's Blog (Weblog) by pmehner on December 16, 2007
Powered by Community Server (Commercial Edition), by Telligent Systems