Skip to Content
Learning WCF
book

Learning WCF

by Michele Leroux Bustamante
May 2007
Intermediate to advanced
610 pages
20h 14m
English
O'Reilly Media, Inc.
Content preview from Learning WCF

Building a Claims-Based Security Model

The identity model in WCF supports a rich, claims-based approach to authorization, but so far in this chapter, you haven’t seen it in action. That’s because discussions so far have centered on Windows, UserName, and Certificate credentials—each of which rely on authentication and authorization features that have nothing to do with claims. As I mentioned earlier, all credentials are ultimately mapped to a set of claims when they are authenticated at the service. In this section, I’ll elaborate on this and other important concepts related to building a claims-based security model, including:

  • Security tokens and claims

  • Working with custom claims

  • Custom authorization policies

  • Claims-based authorization and related utilities

Security Tokens and Claims

Security tokens are abstractions of credentials that are passed in the security headers of a message and validated against the security policy. When security tokens are validated and processed at the service, claims representative of the token are placed into the security context for the operation being executed. Consider the following examples:

  • Windows credential (Windows token) claims include the Windows identity and the groups to which it belongs.

  • UserName credential (UserName token) claims include the username.

  • Certificate credential (X.509 token) claims include the subject key, thumbprint, public key blob, and other certificate properties.

Each claim describes an individual right or action applicable to ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Pro WCF: Practical Microsoft SOA Implementation

Pro WCF: Practical Microsoft SOA Implementation

Chris Peiris, Dennis Mulder, Shawn Cicoria, Amit Bahree, Nishith Pathak
Professional WCF 4: Windows Communication Foundation with .NET 4

Professional WCF 4: Windows Communication Foundation with .NET 4

Pablo Cibraro, Kurt Claeys, Fabio Cozzolino, Johann Grabner
How to Cheat at IIS 7 Server Administration

How to Cheat at IIS 7 Server Administration

Chris Adams, Brian Frederick, Pattrick Santry

Publisher Resources

ISBN: 9780596101626Errata Page