Ask a questionAsk a question
 

AnswerWCF webhttp binding and security

  • Saturday, July 04, 2009 1:32 AMdsoffer Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Hello,

    I currently host a WCF service with webhttp binding so i can use it to construct an application that needs the services. Sometimes I am transfering sensative information that I would want to protect from a middleman (packet sniffer or whatnot) from being able to retreive and actually read the message content that was sent back or to the service. What is the best way/security options that I can use to achieve this?

    Thanks

Answers

  • Monday, July 06, 2009 5:59 PMAmit Sharma RMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer

    you cannot use wsHttpBinding like webHttpBinding.  Message level security involves SOAP headers which are not available on WebHttpBinding (MessageVersion.None).

    I believe that webHttpBinding with Transport level security should be enough for you, with what you are trying to achieve.


    Amit Sharma

All Replies