Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsFree MagazinesWhite PapersSubmit Content
Discussion GroupsASP.NETWindows FormsLanguages.NET FrameworkVisual Studio.NET
Articles.NET FrameworkASP.NETToolsWindows Forms
.NET DirectoryOpen Source ProjectsUser GroupsWeb Resources
Related Topics
Visual Basic 6SQL ServerMS AccessOther DB ProductsMS Server ProductsMore Topics ...

.NET Forum / ASP.NET / Web Services / April 2007

Tip: Looking for answers? Try searching our database.

Selecting the correct X509 certificate

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Alec MacLean - 03 Apr 2007 14:57 GMT
Hi,

I'm trying to get up to speed with WSE 3 as I have a project that secured
web services would help a great deal with, but have reached a frustrating
point in the configuration.  I might be asking what appears to be a dumb set
of questions.  Apologies in advance!

I'm looking to use usernameForCertificateAssertion, which I understand
should allow me to use a server certificate to secure the messages, while
using a simple login process so far as the user is concerned (I already have
a SQL DB of user accounts that I want to continue using).

I have a server certificate on our web server that is used for SSL.

What I have not yet found out (or correctly understood) is:-

Can I use the same existing server certificate (currently just enabling SSL)
to also enable the WSE certificate security?

If I can use that same certificate in this way, how do I get my development
PC to use that certificate?

Do I need a different type of certificate?  If so, what type should I be
looking at?

Documentation on this aspect seems a bit sparse, and the WSE wizard only
allows access to local machine certificate store - there's no browse, etc
for specifying the actual server/certificate it will be using in production.

Can anyone point me in the direction of a web site/how-to/_decent_ book that
describes in sufficient step-by-step detail the actual steps required to use
this approach (so my noddy-level brain can keep up!).

I have the PDF and printed version of the P&P WSE 3.0 scenarios and
implementation guidance - but it doesn't seem to say anything more than "it
can do it".  No detail on HOW to do it (assumptions made by the writers that
a given environment already exists, perhaps?).  The PDF and book are just
the MSDN articles stuck together in one document.

Thanks muchly for any decent advice.

Al
beowlf - 12 Apr 2007 11:57 GMT
> Can I use the same existing server certificate (currently just enabling SSL)
> to also enable the WSE certificate security?

You could use it if but it's not the correct way. The best choice
could be using one certificate for SSL and other for SOAP Signatures.

> If I can use that same certificate in this way, how do I get my development
> PC to use that certificate?

If you use wse3 policies just install the certificate in LocalMachine
Personal store and the MutualCertificate10Assertion,
MutualCertificate11Assertion will find it and use it for signing

> Do I need a different type of certificate?  If so, what type should I be
> looking at?

Certificate for signing purposes only.

> Documentation on this aspect seems a bit sparse, and the WSE wizard only
> allows access to local machine certificate store - there's no browse, etc
[quoted text clipped - 3 lines]
> describes in sufficient step-by-step detail the actual steps required to use
> this approach (so my noddy-level brain can keep up!).

Take a look at
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/wse3.0/html/9da
920b9-f024-4819-adb2-c83e52a4f31b.asp

Maybe too general but for taking some other concepts could be
helpfull.

> I have the PDF and printed version of the P&P WSE 3.0 scenarios and
> implementation guidance - but it doesn't seem to say anything more than "it
> can do it".  No detail on HOW to do it (assumptions made by the writers that
> a given environment already exists, perhaps?).  The PDF and book are just
> the MSDN articles stuck together in one document.

Hope help you.
Laurentzi Nuño

Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.