Solved

Password protect WCF Service hosted on IIS7 public internet

Posted on 2011-03-25
4
617 Views
Last Modified: 2012-05-11
I have a simple WCF service that I want to publish to the public internet via IIS 7. My original plan was to publish the service to iis and turn on WIndows Authentication.

But I was reading some articles on the internet about doing such a thing and it was not advised. Instead some were suggesting that you use a x509 certificate. This did not look too appealing because the amount of configuration that was needed. And does this mean that the persons consuming the service will need a certificate as well?

I just want to simply give out the url of the service along with a username and password for each user and that be that.

What is the easiest (but secure) way to accomplish this task?
0
Comment
Question by:dpbouchard
  • 3
4 Comments
 
LVL 7

Expert Comment

by:nbove
ID: 35216795
You can do one of two methods.  You can either have all of your methods also take username and password parameters.  Or you can set up an authentication service that takes a user name and password and issues an authentication token back.  Then your methods just have to take the authentication token as a parameter.
0
 
LVL 1

Author Comment

by:dpbouchard
ID: 35217172
Not exactly what I was looking for. I am looking for some way to just put authentication on the website or the folder itself to that IIS will issue a 401 requesting authentication.

I am pretty sure I can enable Windows Authentication and make this work. I am just told that it is not very secure.

Any ideas?
0
 
LVL 1

Accepted Solution

by:
dpbouchard earned 0 total points
ID: 35233100
I resolved this issue by using a local user account to the server itself in addition to adding a ssl certificate. Thanks for the help!
0
 
LVL 1

Author Closing Comment

by:dpbouchard
ID: 35304264
Resolved issue
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
File Upload Control on a ASP.NET Overlay Page 1 43
Re-position the objects 7 99
exchange 2010, exchange 2013 1 40
Displaying a web form as a modal popup dialog box. 4 25
The Confluence of Individual Knowledge and the Collective Intelligence At this writing (summer 2013) the term API (http://dictionary.reference.com/browse/API?s=t) has made its way into the popular lexicon of the English language.  A few years ago, …
In order to have all security and back ups taken care of, WordPress users can sign up for services with WP Engine.
The purpose of this video is to demonstrate how to set up the WordPress backend so that each page automatically generates a Mailchimp signup form in the sidebar. This will be demonstrated using a Windows 8 PC. Tools Used are Photoshop, Awesome…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now