473,410 Members | 1,857 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,410 software developers and data experts.

Best way for webservice security for a public application

Hi,

I hope someone can give me some advice on which form of security i can use
best in this scenario:

I have a free application that everbody on the internet can download.
It calls a webservice retrieve it's data. Currently it's not secured, so
anybody can use it.

I want to secure it, but the guy who owns the server does not want to make
use of windwos authentication, so that's not an option.

I would only like that my application can access the webservice. Which do
you think is the best way? (and perhaps i also need to use this for a
windows mobile application, is that also possible in your suggestion?)

I hope someone can give me some useful advice.

Greetings,
Jeroen
Sep 15 '06 #1
2 1281
Hi Jeroen,

I recommend you to take a look to the "Security Patterns for Web services"
guide. It was published by Microsoft, and it is available here
http://msdn.microsoft.com/library/en.../html/WSSP.asp

I think the simplest configuration for your scenario is the following:

1. Authentication :HTTP Transport authentication - Basic Authentication
2. Confidentiality: HTTPS Transport security

Regards,
Pablo Cibraro
http://weblogs.asp.net/cibrax

"news.demon.nl" <no@mailwrote in message
news:12*************@corp.supernews.com...
Hi,

I hope someone can give me some advice on which form of security i can use
best in this scenario:

I have a free application that everbody on the internet can download.
It calls a webservice retrieve it's data. Currently it's not secured, so
anybody can use it.

I want to secure it, but the guy who owns the server does not want to make
use of windwos authentication, so that's not an option.

I would only like that my application can access the webservice. Which do
you think is the best way? (and perhaps i also need to use this for a
windows mobile application, is that also possible in your suggestion?)

I hope someone can give me some useful advice.

Greetings,
Jeroen

Sep 15 '06 #2
thanks, i'll read that.

"Pablo Cibraro [MVP]" <pc******@hotmail.comschreef in bericht
news:%2******************@TK2MSFTNGP02.phx.gbl...
Hi Jeroen,

I recommend you to take a look to the "Security Patterns for Web services"
guide. It was published by Microsoft, and it is available here
http://msdn.microsoft.com/library/en.../html/WSSP.asp

I think the simplest configuration for your scenario is the following:

1. Authentication :HTTP Transport authentication - Basic Authentication
2. Confidentiality: HTTPS Transport security

Regards,
Pablo Cibraro
http://weblogs.asp.net/cibrax

"news.demon.nl" <no@mailwrote in message
news:12*************@corp.supernews.com...
>Hi,

I hope someone can give me some advice on which form of security i can
use best in this scenario:

I have a free application that everbody on the internet can download.
It calls a webservice retrieve it's data. Currently it's not secured, so
anybody can use it.

I want to secure it, but the guy who owns the server does not want to
make use of windwos authentication, so that's not an option.

I would only like that my application can access the webservice. Which do
you think is the best way? (and perhaps i also need to use this for a
windows mobile application, is that also possible in your suggestion?)

I hope someone can give me some useful advice.

Greetings,
Jeroen


Sep 15 '06 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

6
by: Davie | last post by:
I want to authorise a user of a web service by using the AuthHeaderValue for some reason I keep getting a null reference exception when I try to run the following code: It seems to work fine on a...
14
by: Bert Vandenberghe | last post by:
Hi, I was wondering if there are any best practices on the creation of webmethods? I'll try to explain this a little more: My problem is that we are changing an existing (large) DCOM application...
8
by: Topper | last post by:
Hello. I have simple web folders structure: -ROOT - BIN WebService.dll WebService.asmx I need to use my WebService.dll not in bin folder - for example, in ROOT. How do i this? How can i do...
18
by: A.M | last post by:
Hi, Is there any way to call a WSS web service method by using browser and see the XML result in browser as well? I have been told that there is query string syntax for calling...
7
by: Nalaka | last post by:
Hi, I created a sinple web service that returns a dataSet. Then I created a client program that uses this web service (that returns the Dataset). My question is, how did the client figure...
5
by: AliR | last post by:
Hi Everyone, I have a Visual C++ MFC program, and I am trying to use a webservice written in C#. When I add the webservice to my project using Add Web Reference the sproxy compiler complains...
10
by: Mike Logan | last post by:
I am using the "contract first" design methodology. Contract First is design the WSDL first then design the server and client. However I must design my XSD/XML Schema before anything. I am...
5
by: | last post by:
Hi, How long do webservice objects live for? In particular, if i have static variables filled with data from a static constructor in a webservice, how long will that data persist? thxs
2
by: KaNos | last post by:
Hello world, I've made a webservice (c# v2) to install in a server IIS 6 on a Windows 2000 last SP. We can use the webservice in local, throw the pages wich present the methods, with a windows...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new...
0
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.