語言
Windows 通訊基礎(WCF)包含數個系統提供的綁定,可設定,但在配置 WCF 支援的所有安全選項時,無法提供完全的彈性。 本主題將示範如何直接從個別綁定元素建立自訂綁定,並強調在建立此類綁定時可指定的一些安全設定。 欲了解更多關於建立自訂綁定的資訊,請參見 擴展綁定。
警告
SecurityBindingElement 不支援 IDuplexSessionChannel 通道形狀,而通道形狀是 TCP 傳輸 TransferMode 在設定為 Buffered時的預設通道形態。 你必須將 TransferMode 設定為 Streamed 才能在這種情況下使用 SecurityBindingElement 。
建立自訂綁定
在WCF中,所有裝訂都由 綁定元件組成。 每個綁定元素都源自該 BindingElement 類別。 對於系統提供的標準綁定,綁定元素會自動建立和設定,雖然你可以自訂部分屬性設定。
相較之下,建立自訂綁定時,會建立並設定綁定元素,並由綁定元素生成 a CustomBinding 。
為此,你將各個綁定元素加入由 BindingElementCollection 類別實例所代表的集合中,然後將 CustomBinding 物件的Elements屬性設為該物件。 您必須依序加入綁定元素:交易流程、可靠會話、安全性、複合雙工、單向、串流安全、訊息編碼與傳輸。 請注意,並非所有列出的結合元素都是每一種綁定都必須的。
SecurityBindingElement
三個綁定元素與訊息層級安全性相關,全部源自類別 SecurityBindingElement 。 這三個分別是 TransportSecurityBindingElement、 SymmetricSecurityBindingElement、 AsymmetricSecurityBindingElement和 。 使用 TransportSecurityBindingElement 來提供混合模式安全防護。 另外兩個元素用於訊息層提供安全性。
當提供運輸層安全時,會使用額外等級:
必需的綁定要素
有大量可能的結合元素可以組合成一種結合。 並非所有這些組合都成立。 本節描述安全綁定中必須具備的必要元素。
有效的安全綁定取決於多種因素,包括以下幾點:
安全性模式。
傳輸通訊協定。
合約中規定的訊息交換模式(MEP)。
下表顯示上述各因素組合的有效結合元素堆疊配置。 請注意,這些只是最低要求。 你可以在綁定中加入額外的綁定元素,例如訊息編碼綁定元素、交易綁定元素及其他綁定元素。
| 安全性模式 | Transport | 合約訊息交換模式 | 合約訊息交換模式 | 合約訊息交換模式 |
|---|---|---|---|---|
Datagram |
Request Reply |
Duplex |
||
| Transport | Https | |||
| 單向綁定元素 | ||||
| HttpsTransportBindingElement | HttpsTransportBindingElement | |||
| TCP | ||||
| 單向綁定元素 | ||||
| SSL 或 Windows StreamSecurityBindingElement | SSL 或 Windows StreamSecurityBindingElement | SSL 或 Windows 的 StreamSecurityBindingElement | ||
| TcpTransportBindingElement | TcpTransportBindingElement | TcpTransportBindingElement | ||
| Message | Http | 對稱安全綁定元素 | 對稱安全綁定元素 | SymmetricSecurityBindingElement(認證模式 = SecureConversation) |
| 複合雙工綁定元素 | ||||
| 單向綁定元素 | 單向綁定元素 | |||
| HttpTransportBindingElement | HttpTransportBindingElement | HttpTransportBindingElement | ||
| Tcp | SecurityBindingElement | SecurityBindingElement | SymmetricSecurityBindingElement(認證模式 = SecureConversation) | |
| TcpTransportBindingElement | TcpTransportBindingElement | TcpTransportBindingElement | ||
| 混合(帶有訊息憑證的傳輸) | Https | TransportSecurityBindingElement | TransportSecurityBindingElement | |
| 單向綁定元素 | ||||
| HttpsTransportBindingElement | HttpsTransportBindingElement | |||
| TCP | TransportSecurityBindingElement | SymmetricSecurityBindingElement(認證模式 = SecureConversation) | SymmetricSecurityBindingElement(認證模式 = SecureConversation) | |
| 單向綁定元素 | ||||
| SSL 或 Windows StreamSecurityBindingElement | SSL 或 Windows StreamSecurityBindingElement | SSL 或 Windows StreamSecurityBindingElement | ||
| TcpTransportBindingElement | TcpTransportBindingElement | TcpTransportBindingElement |
請注意,SecurityBindingElements 上有許多可設定的設定。 欲了解更多資訊,請參閱 SecurityBindingElement 認證模式。
欲了解更多資訊,請參閱安全對話與安全會話。
程序
建立使用 SymmetricSecurityBindingElement 的自訂綁定
建立一個名為 BindingElementCollection的類別實例
outputBec。呼叫靜態方法
M:System.ServiceModel.Channels.SecurityBindingElement.CreateSspiNegotiationBindingElement(true),它會回傳該 SymmetricSecurityBindingElement 類別的實例。透過呼叫 BindingElement 類的 Collection<T> 的
Add方法,將SymmetricSecurityBindingElement 加入outputBec集合(BindingElement)。建立一個 TextMessageEncodingBindingElement 類別實例並將其加入集合(
outputBec)。 這會指定綁定所使用的編碼方式。建立 HttpTransportBindingElement 並將其加入集合(
outputBec)。 這表示綁定必須使用 HTTP 傳輸。建立新的自訂綁定,方法是建立類別 CustomBinding 的實例並將集合
outputBec傳給建構子。所產生的客製化裝訂與標準 WSHttpBinding裝訂有許多相同的特性。 它規定了訊息層級的安全與 Windows 憑證,但會停用安全會話,要求服務憑證必須在頻外指定,且不加密簽章。 最後一個只能透過設定 MessageProtectionOrder 第 4 步所示的屬性來控制。 另外兩個則可用標準綁定設定來控制。
範例
說明
以下範例提供了一個完整的函數,用來建立使用一個 SymmetricSecurityBindingElement的自訂綁定。
Code
// Create an empty CustomBinding to populate
CustomBinding binding = new CustomBinding();
// Create a SymmetricSecurityBindingElement.
SymmetricSecurityBindingElement ssbe =
SecurityBindingElement.CreateSspiNegotiationBindingElement(true);
// Add the SymmetricSecurityBindingElement to the BindingElementCollection.
binding.Elements.Add(ssbe);
binding.Elements.Add(new TextMessageEncodingBindingElement());
binding.Elements.Add(new HttpTransportBindingElement());
return new CustomBinding(binding);
Public Shared Function CreateCustomBinding() As Binding
' Create an empty Custom Binding to populate,
Dim binding As New CustomBinding()
' Create a SymmetricSecurityBindingElement.
Dim ssbe As SymmetricSecurityBindingElement
ssbe = SecurityBindingElement.CreateSspiNegotiationBindingElement(True)
' Add the SymmetricSecurityBindingElement to the BindingElementCollection.
binding.Elements.Add(ssbe)
binding.Elements.Add(New TextMessageEncodingBindingElement())
binding.Elements.Add(New HttpTransportBindingElement())
Return New CustomBinding(binding)
End Function