为 Windows 身份验证配置 XML Web 服务
按照下列步骤使用 Windows 身份验证的所有窗体(“客户端凭据”除外)配置客户端凭据并将其传递给 Web 服务。对于“客户端凭据”,请按照“客户端证书身份验证”一节中的步骤操作。
为 Windows 身份验证配置 Web 服务
-
使用 IIS 配置 Web 服务,以使用 Windows 身份验证。
IIS 允许您在目录或文件级别指定安全性。如果要逐个文件指定 Web 服务的安全性,请在 IIS 中的 .asmx 文件上为该 Web 服务设置权限。.asmx 文件是访问 Web 服务的入口点。有关详细信息,请参见 IIS 文档。
-
修改配置文件以指定 Windows 身份验证。
在配置文件中,将 authentication XML 元素的 mode 属性设置为“Windows”。有关如何配置配置文件的详细信息,请参见 ASP.NET Configuration。以下代码示例修改配置文件以使用 Windows 身份验证。
// Fragment of a Web.config file. <authentication mode= "Windows"> </authentication>
使用 Windows 身份验证将客户端凭据传递给 Web 服务
-
创建 Web 服务的代理类的新实例。如果尚未生成代理类,请参见创建 XML Web 服务代理以了解详细信息。
-
创建 NetworkCredential 类的新示例,设置 UserName、Password 和 Domain 属性。
-
创建 CredentialCache 的新实例。
-
使用 CredentialCache 的 Add 方法将 NetworkCredential 添加到 CredentialCache。
-
将 CredentialCache 的实例分配给代理类的 Credentials 属性。
如果使用“集成 Windows”身份验证,那么必须将 Credentials 属性设置为 System.Net.CredentialCache.DefaultCredentials。
当 Credentials 属性设置为 DefaultCredentials 时,客户端与服务器进行协商,以便根据服务器的配置执行 Kerberos 和/或 NTLM 身份验证。
-
下面的代码示例设置使用 Windows 身份验证传递给 Web 服务方法的客户端凭据。
客户端证书身份验证
按照下列步骤使用 Windows 身份验证的“客户端凭据”窗体配置客户端凭据并将其传递给 Web 服务。
为客户端证书身份验证配置 Web 服务
-
安装 SSL。
-
配置 Web 应用程序以接受客户端证书。
-
修改配置文件,为 Web 服务指定 Windows 身份验证。
在配置文件中,将 authentication XML 元素的 mode 属性设置为“Windows”。有关如何配置配置文件的详细信息,请参见 ASP.NET Configuration。以下代码示例修改配置文件以使用 Windows 身份验证。
// Fragment of a Web.config file. <authentication mode= "Windows"> </authentication>
使用客户端证书身份验证将客户端凭据传递给 Web 服务
-
创建 Web 服务的代理类的新实例。如果尚未生成代理类,请参见创建 XML Web 服务代理以了解详细信息。
-
创建 X509Certificate 的新实例。
-
调用 CreateFromCertFile 方法,从文件加载客户端证书。
客户端可以从受信任的证书颁发机构获取客户端证书文件。有关详细信息,请参见 IIS 文档。
-
将 X509Certificate 添加到代理类的 ClientCertificates ClientCertificates 集合。
下面的代码示例演示 Web 服务客户端如何使用客户端证书传递其凭据。使用 CreateFromCertFile 方法从文件加载 Web 服务器颁发的客户端证书,然后将其添加到代理类的 ClientCertificates 属性。
Visual Basic
复制到剪贴板' Instantiate proxy class to a Bank Web service. Dim bank As BankSession = new BankSession() ' Load the client certificate from a file. Dim x509 As X509Certificate = X509Certificate.CreateFromCertFile("c:\user.cer") ' Add the client certificate to the ClientCertificates property ' of the proxy class. bank.ClientCertificates.Add(x509) ' Call the method on the proxy class, which requires authentication ' using client certificates. bank.Deposit(500)
C#
复制到剪贴板// Instantiate proxy class to a Bank Web service. BankSession bank = new BankSession(); // Load the client certificate from a file. X509Certificate x509 = X509Certificate.CreateFromCertFile(@"c:\user.cer"); // Add the client certificate to the ClientCertificates property // of the proxy class. bank.ClientCertificates.Add(x509); // Call the method on the proxy class, which requires // authentication using client certificates. bank.Deposit(500);
示例
当 Credentials 属性设置为 System.Net.CredentialCache.DefaultCredentials 时,客户端与服务器进行协商,以便根据服务器的配置执行 Kerberos 和/或 NTLM 身份验证。
下面的代码示例设置使用 Windows 身份验证传递给 Web 服务方法的客户端凭据。
Imports System Imports System.Web.Services.Protocols Imports System.Net Imports MyMath Public Class Calculator Public Shared Sub Main() ' Create a new instance of the proxy class to an ' Web service method. Dim mathproxy As MyMath.Math = New MyMath.Math() ' Create a new instance of CredentialCache. Dim mycredentialCache As CredentialCache = New CredentialCache() ' Create a new instance of NetworkCredential using the client ' credentials. Dim credentials As NetworkCredential = New _ NetworkCredential(UserName,SecurelyStoredPasword,Domain) ' Add the NetworkCredential to the CredentialCache. mycredentialCache.Add(New Uri(mathproxy.Url), "Basic", _ credentials) ' Add the CredentialCache to the proxy class credentials. mathproxy.Credentials = mycredentialCache ' Call the method on the proxy class. Dim result As Integer result = mathproxy.Add(3,5) End Sub End Class
using System; using System.Web.Services.Protocols; using System.Net; using MyMath; public class Calculator { public static void Main() { // Create a new instance of the proxy class to an XML // Web service method. MyMath.Math math = new MyMath.Math(); // Create a new instance of CredentialCache. CredentialCache credentialCache = new CredentialCache(); // Create a new instance of NetworkCredential using the client // credentials. NetworkCredential credentials = new NetworkCredential(UserName,SecurelyStroredPassword,Domain); // Add the NetworkCredential to the CredentialCache. credentialCache.Add(new Uri(math.Url), "Basic", credentials); // Add the CredentialCache to the proxy class credentials. math.Credentials = credentialCache; // Call the method on the proxy class. int result = math.Add(3,5); } }

浙公网安备 33010602011771号