为 Windows 身份验证配置 XML Web 服务

为 Windows 身份验证配置 XML Web 服务  

代码示例

按照下列步骤使用 Windows 身份验证的所有窗体(“客户端凭据”除外)配置客户端凭据并将其传递给 Web 服务。对于“客户端凭据”,请按照“客户端证书身份验证”一节中的步骤操作。

为 Windows 身份验证配置 Web 服务

  1. 使用 IIS 配置 Web 服务,以使用 Windows 身份验证。

    IIS 允许您在目录或文件级别指定安全性。如果要逐个文件指定 Web 服务的安全性,请在 IIS 中的 .asmx 文件上为该 Web 服务设置权限。.asmx 文件是访问 Web 服务的入口点。有关详细信息,请参见 IIS 文档。

  2. 修改配置文件以指定 Windows 身份验证。

    在配置文件中,将 authentication XML 元素的 mode 属性设置为“Windows”。有关如何配置配置文件的详细信息,请参见 ASP.NET Configuration。以下代码示例修改配置文件以使用 Windows 身份验证。

    // Fragment of a Web.config file.
        <authentication mode= "Windows">
        </authentication> 

使用 Windows 身份验证将客户端凭据传递给 Web 服务

  1. 创建 Web 服务的代理类的新实例。如果尚未生成代理类,请参见创建 XML Web 服务代理以了解详细信息。

  2. 创建 NetworkCredential 类的新示例,设置 UserName、Password 和 Domain 属性。

  3. 创建 CredentialCache 的新实例。

  4. 使用 CredentialCache 的 Add 方法将 NetworkCredential 添加到 CredentialCache。

  5. 将 CredentialCache 的实例分配给代理类的 Credentials 属性。

    如果使用“集成 Windows”身份验证,那么必须将 Credentials 属性设置为 System.Net.CredentialCache.DefaultCredentials。

    当 Credentials 属性设置为 DefaultCredentials 时,客户端与服务器进行协商,以便根据服务器的配置执行 Kerberos 和/或 NTLM 身份验证。

  6. 下面的代码示例设置使用 Windows 身份验证传递给 Web 服务方法的客户端凭据。

客户端证书身份验证

按照下列步骤使用 Windows 身份验证的“客户端凭据”窗体配置客户端凭据并将其传递给 Web 服务。

为客户端证书身份验证配置 Web 服务

  1. 安装 SSL。

  2. 配置 Web 应用程序以接受客户端证书。

  3. 修改配置文件,为 Web 服务指定 Windows 身份验证。

    在配置文件中,将 authentication XML 元素的 mode 属性设置为“Windows”。有关如何配置配置文件的详细信息,请参见 ASP.NET Configuration。以下代码示例修改配置文件以使用 Windows 身份验证。

    // Fragment of a Web.config file.
        <authentication mode= "Windows">
        </authentication>

使用客户端证书身份验证将客户端凭据传递给 Web 服务

  1. 创建 Web 服务的代理类的新实例。如果尚未生成代理类,请参见创建 XML Web 服务代理以了解详细信息。

  2. 创建 X509Certificate 的新实例。

  3. 调用 CreateFromCertFile 方法,从文件加载客户端证书。

    客户端可以从受信任的证书颁发机构获取客户端证书文件。有关详细信息,请参见 IIS 文档。

  4. 将 X509Certificate 添加到代理类的 ClientCertificates ClientCertificates 集合。

    下面的代码示例演示 Web 服务客户端如何使用客户端证书传递其凭据。使用 CreateFromCertFile 方法从文件加载 Web 服务器颁发的客户端证书,然后将其添加到代理类的 ClientCertificates 属性。

    ' Instantiate proxy class to a Bank Web service.
        Dim bank As BankSession = new BankSession()
        ' Load the client certificate from a file.
        Dim x509 As X509Certificate = X509Certificate.CreateFromCertFile("c:\user.cer")
        ' Add the client certificate to the ClientCertificates property
        ' of the proxy class.
        bank.ClientCertificates.Add(x509)
        ' Call the method on the proxy class, which requires authentication
        ' using client certificates.
        bank.Deposit(500)
        

     

    // Instantiate proxy class to a Bank Web service.
        BankSession bank = new BankSession();
        // Load the client certificate from a file.
        X509Certificate x509 = X509Certificate.CreateFromCertFile(@"c:\user.cer");
        // Add the client certificate to the ClientCertificates property
        // of the proxy class.
        bank.ClientCertificates.Add(x509);
        // Call the method on the proxy class, which requires
        // authentication using client certificates.
        bank.Deposit(500);
        

示例

当 Credentials 属性设置为 System.Net.CredentialCache.DefaultCredentials 时,客户端与服务器进行协商,以便根据服务器的配置执行 Kerberos 和/或 NTLM 身份验证。

下面的代码示例设置使用 Windows 身份验证传递给 Web 服务方法的客户端凭据。

Imports System
Imports System.Web.Services.Protocols
Imports System.Net
Imports MyMath
Public Class Calculator
Public Shared Sub Main()
' Create a new instance of the proxy class to an
' Web service method. 
Dim mathproxy As MyMath.Math = New MyMath.Math()
' Create a new instance of CredentialCache.
Dim mycredentialCache As CredentialCache = New CredentialCache()
' Create a new instance of NetworkCredential using the client
' credentials.
Dim credentials As NetworkCredential = New _
NetworkCredential(UserName,SecurelyStoredPasword,Domain)
' Add the NetworkCredential to the CredentialCache.
mycredentialCache.Add(New Uri(mathproxy.Url), "Basic", _
credentials)
' Add the CredentialCache to the proxy class credentials.
mathproxy.Credentials = mycredentialCache
' Call the method on the proxy class.
Dim result As Integer
result = mathproxy.Add(3,5)
End Sub
End Class
using System;
using System.Web.Services.Protocols;
using System.Net;
using MyMath;
public class Calculator
{
public static void Main()
{
// Create a new instance of the proxy class to an XML
// Web service method. 
MyMath.Math math = new MyMath.Math();
// Create a new instance of CredentialCache.
CredentialCache credentialCache = new CredentialCache();
// Create a new instance of NetworkCredential using the client
// credentials.
NetworkCredential credentials = new
NetworkCredential(UserName,SecurelyStroredPassword,Domain);
// Add the NetworkCredential to the CredentialCache.
credentialCache.Add(new Uri(math.Url),
"Basic", credentials);
// Add the CredentialCache to the proxy class credentials.
math.Credentials = credentialCache;
// Call the method on the proxy class.
int result = math.Add(3,5);
}
}

请参见

posted @ 2006-04-17 14:46  萧萧  阅读(425)  评论(0)    收藏  举报