Showing posts with label services. Show all posts
Showing posts with label services. Show all posts

Thursday, May 17, 2012

Secure your ASMX WebServices with SWT and Claims

I was recently involved into interesting project, that was using the plain old ASMX web services. We wanted to migrate it to the Windows Azure Access Control Service and make use of Claims.

The way we achieved that is to add additional Soap Header to the client requests that includes Simple Web Token (SWT). On the server side, we make a check for this specific header existence, then extract the token, perform some validation checks and inject a fresh new Claims Identity into the Service instance. One thing to look out for is that you have to think of a workaround, if your ASMX WebService is a Singleton object. My implementation works with non-singleton implementations. And I currently get my Simple Web Tokens from Windows Azure Access Control Service’s WRAP endpoint. I have configured a “Password” service identities and I play with the RuleGroups to add additional claims, based on identity used. It is pretty flexible!

The result is on … GitHub. I initially wanted to be on CodePlex, because I have other projects there and am more used to TFS style of working. But CodePlex’s TFS is down for quite some time, which was a good excuse to use GitHub. There is some explanations in the Readme.txt file, as well as comments in the code. So feel free to get the code, play around with it, ping me if it is not working for some reason, and so on!

The project makes extensive use of SWT Implementation, done by the Two10Degrees’ team. But I added a compiled assembly reference for convenience.

Monday, February 5, 2007

Command-line tips & tricks

Ever wander how to automate specific services starting and stopping ?
Well, at first the easiest part:
How to start or stop windows service from command-line ?use the tool "net" provided by windows:
net start [name of the service]
for example:
net start "SQL Server (MSSQLSERVER)"
We can also, stop the service with this tool:
net stop "SQL Server (MSSQLSERVER)"

Now the tricky part - how to START / STOP IIS site using command-line?
(Tested against IIS 6.0)
Microsoft provides some useful scripts that automate this work, and we can use them with the command-line tool cscript.exe. Let's assume we have the "Default Web Site" configure on the IIS and we want to start / stop it. Then open a command prompt and write down:

cscript /nologo %SystemRoot%\System32\IIsWeb.vbs /start "Default Web Site"
to start the site
or
cscript /nologo %SystemRoot%\System32\IIsWeb.vbs /stop "Default Web Site"
to stop the site.

You will find a number of other useful scripts and manual here.

All this helped me to make a batch files (.bat), which I use to start / stop services on my machine (I do not always need the services running and consuming memory and resources).