Discussion in 'ASP .Net Security' started by Stormbringer, Feb 26, 2007.

    I have a .NET 2.0 web app that uses forms authentication to get around an
    issue with FireFox. FireFox will allow you to save the username/pass and this
    is a SOX no no.

    The objects in the web application call a Windows Authenticated web service.
    I do have the username and password so I can create a WindowsIdentity object.
    Question is, how do I get that to the web serivce?

    Or is there a better way to do this? I tried WSE 3.0 but the logic in the
    business logic gets very messy.

    Stormbringer, Feb 26, 2007
    Joe Kaplan Guest

    Set the Credentials property on the web service proxy client object to a
    NetworkCredential object that contains the username and password you
    collected. You may also need the domain name.

    Joe K.
    Joe Kaplan, Feb 28, 2007
    anders.rask Guest

    If user is already logged in you can use the session cookie as
    authentication to your web service using the

    see more here

    anders.rask, Apr 13, 2007
