語言

如何:使用 SecurityBindingElement 建立自訂綁定

Windows 通訊基礎(WCF)包含數個系統提供的綁定,可設定,但在配置 WCF 支援的所有安全選項時,無法提供完全的彈性。 本主題將示範如何直接從個別綁定元素建立自訂綁定,並強調在建立此類綁定時可指定的一些安全設定。 欲了解更多關於建立自訂綁定的資訊,請參見 擴展綁定。

警告

SecurityBindingElement 不支援 IDuplexSessionChannel 通道形狀,而通道形狀是 TCP 傳輸 TransferMode 在設定為 Buffered時的預設通道形態。 你必須將 TransferMode 設定為 Streamed 才能在這種情況下使用 SecurityBindingElement 。

建立自訂綁定

在WCF中,所有裝訂都由 綁定元件組成。 每個綁定元素都源自該 BindingElement 類別。 對於系統提供的標準綁定,綁定元素會自動建立和設定,雖然你可以自訂部分屬性設定。

相較之下,建立自訂綁定時,會建立並設定綁定元素,並由綁定元素生成 a CustomBinding 。

為此,你將各個綁定元素加入由 BindingElementCollection 類別實例所代表的集合中,然後將 CustomBinding 物件的Elements屬性設為該物件。 您必須依序加入綁定元素:交易流程、可靠會話、安全性、複合雙工、單向、串流安全、訊息編碼與傳輸。 請注意,並非所有列出的結合元素都是每一種綁定都必須的。

SecurityBindingElement

三個綁定元素與訊息層級安全性相關,全部源自類別 SecurityBindingElement 。 這三個分別是 TransportSecurityBindingElement、 SymmetricSecurityBindingElement、 AsymmetricSecurityBindingElement和 。 使用 TransportSecurityBindingElement 來提供混合模式安全防護。 另外兩個元素用於訊息層提供安全性。

當提供運輸層安全時,會使用額外等級:

必需的綁定要素

有大量可能的結合元素可以組合成一種結合。 並非所有這些組合都成立。 本節描述安全綁定中必須具備的必要元素。

有效的安全綁定取決於多種因素,包括以下幾點:

  • 安全性模式。

  • 傳輸通訊協定。

  • 合約中規定的訊息交換模式(MEP)。

下表顯示上述各因素組合的有效結合元素堆疊配置。 請注意,這些只是最低要求。 你可以在綁定中加入額外的綁定元素,例如訊息編碼綁定元素、交易綁定元素及其他綁定元素。

安全性模式 Transport 合約訊息交換模式 合約訊息交換模式 合約訊息交換模式
Datagram Request Reply Duplex
Transport Https
單向綁定元素
HttpsTransportBindingElement HttpsTransportBindingElement
TCP
單向綁定元素
SSL 或 Windows StreamSecurityBindingElement SSL 或 Windows StreamSecurityBindingElement SSL 或 Windows 的 StreamSecurityBindingElement
TcpTransportBindingElement TcpTransportBindingElement TcpTransportBindingElement
Message Http 對稱安全綁定元素 對稱安全綁定元素 SymmetricSecurityBindingElement(認證模式 = SecureConversation)
複合雙工綁定元素
單向綁定元素 單向綁定元素
HttpTransportBindingElement HttpTransportBindingElement HttpTransportBindingElement
Tcp SecurityBindingElement SecurityBindingElement SymmetricSecurityBindingElement(認證模式 = SecureConversation)
TcpTransportBindingElement TcpTransportBindingElement TcpTransportBindingElement
混合(帶有訊息憑證的傳輸) Https TransportSecurityBindingElement TransportSecurityBindingElement
單向綁定元素
HttpsTransportBindingElement HttpsTransportBindingElement
TCP TransportSecurityBindingElement SymmetricSecurityBindingElement(認證模式 = SecureConversation) SymmetricSecurityBindingElement(認證模式 = SecureConversation)
單向綁定元素
SSL 或 Windows StreamSecurityBindingElement SSL 或 Windows StreamSecurityBindingElement SSL 或 Windows StreamSecurityBindingElement
TcpTransportBindingElement TcpTransportBindingElement TcpTransportBindingElement

請注意,SecurityBindingElements 上有許多可設定的設定。 欲了解更多資訊,請參閱 SecurityBindingElement 認證模式。

欲了解更多資訊,請參閱安全對話與安全會話。

程序

建立使用 SymmetricSecurityBindingElement 的自訂綁定

  1. 建立一個名為 BindingElementCollection的類別實例outputBec。

  2. 呼叫靜態方法 M:System.ServiceModel.Channels.SecurityBindingElement.CreateSspiNegotiationBindingElement(true),它會回傳該 SymmetricSecurityBindingElement 類別的實例。

  3. 透過呼叫 BindingElement 類的 Collection<T> 的 Add 方法,將SymmetricSecurityBindingElement 加入 outputBec 集合(BindingElement)。

  4. 建立一個 TextMessageEncodingBindingElement 類別實例並將其加入集合(outputBec)。 這會指定綁定所使用的編碼方式。

  5. 建立 HttpTransportBindingElement 並將其加入集合(outputBec)。 這表示綁定必須使用 HTTP 傳輸。

  6. 建立新的自訂綁定,方法是建立類別 CustomBinding 的實例並將集合 outputBec 傳給建構子。

  7. 所產生的客製化裝訂與標準 WSHttpBinding裝訂有許多相同的特性。 它規定了訊息層級的安全與 Windows 憑證,但會停用安全會話,要求服務憑證必須在頻外指定,且不加密簽章。 最後一個只能透過設定 MessageProtectionOrder 第 4 步所示的屬性來控制。 另外兩個則可用標準綁定設定來控制。

範例

說明

以下範例提供了一個完整的函數,用來建立使用一個 SymmetricSecurityBindingElement的自訂綁定。

Code

// Create an empty CustomBinding to populate
CustomBinding binding = new CustomBinding();
// Create a SymmetricSecurityBindingElement.
SymmetricSecurityBindingElement ssbe =
    SecurityBindingElement.CreateSspiNegotiationBindingElement(true);
// Add the SymmetricSecurityBindingElement to the BindingElementCollection.
binding.Elements.Add(ssbe);
binding.Elements.Add(new TextMessageEncodingBindingElement());
binding.Elements.Add(new HttpTransportBindingElement());
return new CustomBinding(binding);
Public Shared Function CreateCustomBinding() As Binding
    ' Create an empty Custom Binding to populate, 
    Dim binding As New CustomBinding()
    ' Create a SymmetricSecurityBindingElement.
    Dim ssbe As SymmetricSecurityBindingElement
    ssbe = SecurityBindingElement.CreateSspiNegotiationBindingElement(True)
    ' Add the SymmetricSecurityBindingElement to the BindingElementCollection.
    binding.Elements.Add(ssbe)
    binding.Elements.Add(New TextMessageEncodingBindingElement())
    binding.Elements.Add(New HttpTransportBindingElement())
    Return New CustomBinding(binding)

End Function

另請參閱