SecureConversationServiceCredential.SecurityStateEncoder 屬性
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
取得或設定一個用於編碼與解碼 Cookie 序列化的客製化 SecurityStateEncoder 。
public:
property System::ServiceModel::Security::SecurityStateEncoder ^ SecurityStateEncoder { System::ServiceModel::Security::SecurityStateEncoder ^ get(); void set(System::ServiceModel::Security::SecurityStateEncoder ^ value); };
public System.ServiceModel.Security.SecurityStateEncoder SecurityStateEncoder { get; set; }
member this.SecurityStateEncoder : System.ServiceModel.Security.SecurityStateEncoder with get, set
Public Property SecurityStateEncoder As SecurityStateEncoder
屬性值
一個 SecurityStateEncoder 物件,是 的 DataProtectionSecurityStateEncoder自訂化。
範例
以下程式碼說明如何設定這個屬性。
static void Configure(ServiceHost serviceHost)
{
/*
* There are certain settings that cannot be configured via app.config.
* The security state encoder is one of them.
* Plug in a SecurityStateEncoder that uses the configured certificate
* to protect the security context token state.
*
* Note: You don't need a security state encoder for cookie mode. This was added to the
* sample to illustrate how you would plug in a custom security state encoder should
* your scenario require one.
* */
serviceHost.Credentials.SecureConversationAuthentication.SecurityStateEncoder =
new CertificateSecurityStateEncoder(serviceHost.Credentials.ServiceCertificate.Certificate);
備註
在「Cookie 模式」中,服務會以 Cookie 形式向用戶端發出安全情境令牌(SCT),使其無需維持任何安全狀態。 用戶端會將 cookie 回傳到請求訊息中,讓服務知道如何解除保護並驗證請求訊息。 由於 SCT 經常透過非安全的網路傳輸,必須受到保護。
預設情況下,Windows Communication Foundation(WCF)使用 DataProtectionSecurityStateEncoder 類別來保護 Cookie,使用資料保護 API(DPAPI)。 DPAPI 要在網路農場環境中運作,所有後端服務必須以相同的網域使用者帳號執行。 換句話說,如果服務是網頁架設的,那麼 Internet Information Services(IIS)的工作程序必須設定為以網域使用者身份執行。
這個特性讓你能使用自訂 SecurityStateEncoder 的 Cookie 來加密和解密,而不必依賴 DPAPI。