How to secure a webservice - could some expert advise?

Discussion in 'ASP .Net Web Services' started by thomas, Oct 13, 2006.

  1. thomas

    thomas Guest

    Hi everybody,

    Here is the scenario: webservice running on IIS with .Net Framework 2.0 and
    a windows client application.

    Requirements:
    1. Only authenticated and authorized users shall be able to call web
    methods.
    2. User names or passwords shall never be sent over http.

    Constraints:
    3. Webservice cannot use Windows or LDAP authentication - users and their
    passwords are stored in a SQL database.
    4. The use of x.509 certificates is not an option - too expensive,
    distribution impractical. Does this eliminate WSE? Perhaps, but this level
    of security is NOT necessary.

    Note: although that would be nice, communication does NOT have to be
    encrypted. When really need, meaning when I have to start transmitting
    credit card numbers etc, this perhaps could be accomplished using https.

    Again, the solution does NOT have to be absolutely secure.

    I, of course, have some solutions in mind, but I would appreciate if someone
    who has REAL experience in implementing similar solutions could provide some
    advice or share some thoughts.

    Thank you,

    Tomasz

    p.s. I apologize for the crossposting, but realized that this might be a
    better place to post this question
     
    thomas, Oct 13, 2006
    #1
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Andrew S.

    Need some advise

    Andrew S., Sep 4, 2003, in forum: HTML
    Replies:
    3
    Views:
    394
    Chris Morris
    Sep 4, 2003
  2. ThLog
    Replies:
    6
    Views:
    376
    Travis Newbury
    Mar 2, 2006
  3. G.
    Replies:
    1
    Views:
    378
    Ian Kelly
    Sep 12, 2011
  4. Jack
    Replies:
    2
    Views:
    144
  5. Ruby Maniac
    Replies:
    57
    Views:
    633
    Chad Perrin
    Sep 27, 2007
Loading...

Share This Page