-
Recent Posts
Categories
- .NET Security (34)
- ASP.NET (90)
- AuthorizationServer (2)
- Azure (27)
- Conferences & Training (29)
- IdentityModel (293)
- IdentityServer (84)
- OAuth (31)
- Photography (14)
- Resources (1)
- Uncategorized (550)
- WCF (105)
- WebAPI (87)
Tweets
- RT @christianweyer: “@BASTAcon: Interessanter Titel @JoergNeumann: "Teile und herrsche! App Contracts und Extensions" http://t.co/Tl6fEoxSC… 1 day ago
- RT @zahmed: #ADRMS Federation with #Thinktecture works great. Thanks @leastprivilege 1 day ago
Feed
Archives
- June 2013
- May 2013
- April 2013
- March 2013
- February 2013
- January 2013
- December 2012
- November 2012
- October 2012
- September 2012
- August 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- January 2006
- December 2005
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
- April 2005
- March 2005
- February 2005
- January 2005
- December 2004
- November 2004
- October 2004
- September 2004
- August 2004
- July 2004
- June 2004
- May 2004
Category Archives: WebAPI
Authentication in AuthorizationServer
AS does not do its own authentication – that’s by design. When you download from the repo, AS is set up to be a WS-Federation relying party. In the configuration folder of the WebHost project you’ll find two config files: … Continue reading
Posted in AuthorizationServer, IdentityModel, IdentityServer, OAuth, WebAPI
Leave a comment
What’s in an AuthorizationServer Access Token?
The main job of AS is to produce access tokens in the JWT format. The client and the user provide the following input information for that process: Clientapplication (via the endpoint URL), client identifier, scopes Useridentity, consent to the requested … Continue reading
Posted in AuthorizationServer, IdentityModel, OAuth, WebAPI
Leave a comment
Relationship between IdentityServer and AuthorizationServer
We released a preview version of AuthorizationServer this week. AuthorizationServer is an implementation of the OAuth2 design pattern and helps making API authorization easier. IdentityServer also has OAuth2 endpoints – so you might ask yourself why we started from scratch … Continue reading
Posted in IdentityModel, IdentityServer, OAuth, WebAPI
Leave a comment
IdentityModel v3 changes
I have updated all the projects (IdentityModel, IdentityServer and AuthorizationServer) and the corresponding samples to the GA version of the Microsoft JWT handler. While doing that, I took the opportunity to clean up IdentityModel quite a bit. This resulted in … Continue reading
Posted in IdentityModel, WebAPI
1 Comment
NDC Oslo 2013 Slides
As usual this was my favourite conference of the year! I already uploaded the slides – I will keep you posted once the videos are online as well. Securing ASP.NET Web API OAuth2 – The good, the bad & the … Continue reading
Posted in IdentityModel, IdentityServer, OAuth, WebAPI
Leave a comment
Announcing Thinktecture AuthorizationServer
Today at NDC I announced Brock’s and my new open source project – Thinktecture.AuthorizationServer. AuthorizationServer (AS from now on) is an implementation of the OAuth2 patterns I described here.It has an implementation of the four OAuth2 flows and a nice … Continue reading
Posted in Conferences & Training, IdentityModel, IdentityServer, OAuth, WebAPI
5 Comments
OAuth2 done right
I think I mentioned once or twice that OAuth2 is not for authentication. It is rather a set of patterns for doing delegated authorization for HTTP/Web APIs using access tokens. But most people don’t use it like that. OAuth2 is … Continue reading
Posted in IdentityModel, IdentityServer, OAuth, WebAPI
4 Comments
Update on IdentityModel and IdentityServer
Big news: the Microsoft JWT support is now generally available!. That means that I will update IdentityServer and IdentityModel ASAP (by the end of next week, or rather – after I am done with all my talks at NDC). Speaking … Continue reading
Posted in .NET Security, ASP.NET, IdentityModel, IdentityServer, OAuth, WebAPI
Leave a comment
Two Weeks to go: NDC Identity & Access Control Workshop
…really looking forward to it! http://www.ndcoslo.com/Article/Workshops/claims Also announcing a special guest: Pedro Felix will do a introduction lecture on OpenID Connect! See you there!
Posted in .NET Security, Azure, Conferences & Training, IdentityModel, IdentityServer, OAuth, WCF, WebAPI
Leave a comment
ASP.NET Web API Authentication: Using multiple (simultaneous) Authentication Methods with Thinktecture AuthenticationHandler
Since day one it was possible to support multiple authentication methods with AuthenticationHandler (see here, here and here for some background). I simply stopped searching for other credentials once I found one of the registered ones. Since one of my … Continue reading
Posted in IdentityModel, Uncategorized, WebAPI
Leave a comment
