none
Use of Security Mode as Transport RRS feed

  • Question

  • Hi All,

       I am new to WCF. I have done the following configuration for testing WCF service.

     <bindings>
          <basicHttpBinding>
            <binding name="BasicHttpBindingConfig">
              <security mode="Transport">
                <transport clientCredentialType="None"/>
              </security>
            </binding>
          </basicHttpBinding>
        </bindings>

    Things are working fine... I have following questions

    1) Even if I have set security mode as Transport, I am able to see the passing parameter value as plain text in fiddler, then what is use of it?

    2) Can I set same security mode values irrespective to BasicHttpBinding and WsHttpBinding? 

    Regards,

    Ketan Mehta

    Tuesday, July 2, 2013 12:45 PM

Answers

  • Hi,

    >>1) Even if I have set security mode as Transport, I am able to see the passing parameter value as plain text in fiddler, then what is use of it?

    Becasue using the transport security is not secure the message. It is a secure transport, you can try to see the picture below which can help you understand better.

    Transport Security:

    Message Security:

    >>2) Can I set same security mode values irrespective to BasicHttpBinding and WsHttpBinding? 

    Yes, you can. But by default the security mode for the WsHttpBinding is Message mode.

    Hope it can help you.

    Best Regards.


    Amy Peng
    MSDN Community Support | Feedback to us
    Develop and promote your apps in Windows Store
    Please remember to mark the replies as answers if they help and unmark them if they provide no help.



    Thursday, July 4, 2013 8:25 AM
    Moderator

All replies

  • Hi,

    >>1) Even if I have set security mode as Transport, I am able to see the passing parameter value as plain text in fiddler, then what is use of it?

    Becasue using the transport security is not secure the message. It is a secure transport, you can try to see the picture below which can help you understand better.

    Transport Security:

    Message Security:

    >>2) Can I set same security mode values irrespective to BasicHttpBinding and WsHttpBinding? 

    Yes, you can. But by default the security mode for the WsHttpBinding is Message mode.

    Hope it can help you.

    Best Regards.


    Amy Peng
    MSDN Community Support | Feedback to us
    Develop and promote your apps in Windows Store
    Please remember to mark the replies as answers if they help and unmark them if they provide no help.



    Thursday, July 4, 2013 8:25 AM
    Moderator
  • Thanks Amy,

          The images more than words :)

    Wednesday, July 10, 2013 2:12 PM