Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsFree MagazinesWhite PapersSubmit Content
Discussion GroupsASP.NETWindows FormsLanguages.NET FrameworkVisual Studio.NET
Articles.NET FrameworkASP.NETToolsWindows Forms
.NET DirectoryOpen Source ProjectsUser GroupsWeb Resources
Related Topics
Visual Basic 6SQL ServerMS AccessOther DB ProductsMS Server ProductsMore Topics ...

.NET Forum / ASP.NET / Web Services / August 2005

Tip: Looking for answers? Try searching our database.

Policy Assertion question

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Greg M - 09 Aug 2005 22:12 GMT
I have a policy assertion file that requires requests to be signed and
optionally encrypted.  When a request is not encrypted all works well.  When
a request is encrypted WSE does not verify that the request is encrypted with
the specified security token.  It appears that as long as it is encrypted and
the message can be decrypted (public key exists in KeyStore) the assertion is
satisfied.

Does anyone know how to make encryption optional but enforce a specific
certificate

<wssp:Confidentiality wsp:Usage="wsp:Optional">
 <wssp:KeyInfo>
   <wssp:SecurityToken>
     
<wssp:TokenType>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X
509v3</wssp:TokenType
>
     <wssp:TokenIssuer>O="RSA Security, Inc.", OU=WS-I Sample Applications
CA</wssp:TokenIssuer>
     <wssp:Claims>
       <wssp:SubjectName MatchType="wssp:Exact">O=WS-I, OU=WS-I Sample
Applications, CN=Retailer</wssp:SubjectName>
                <wssp:X509Extension OID="2.5.29.14"
MatchType="wssp:Exact">lE5aEvMfb4RWrmrUeVgXkq8V62s=</wssp:X509Extension>
            </wssp:Claims>
        </wssp:SecurityToken>
 </wssp:KeyInfo>
 <wssp:MessageParts
Dialect="http://schemas.xmlsoap.org/2002/12/wsse#part">wsp:Body()</wssp:MessageParts>
</wssp:Confidentiality>

Thanks for any feedback!
Greg M - 09 Aug 2005 22:58 GMT
Ah, WSE 2.0 only supports the wsp:Required value for the wsp:Usage attribute.

Rate this thread:







Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.