Category Archives: IdentityModel

Token based Authentication for WCF HTTP/REST Services: Authentication

This post shows some of the implementation techniques for adding token and claims based security to HTTP/REST services written with WCF. For the theoretical background, see my previous post. Disclaimer The framework I am using/building here is not the only … Continue reading

Posted in IdentityModel, IdentityServer | 1 Comment

Token based Authentication and Claims for Restful Services

WIF as it exists today is optimized for web applications (passive/WS-Federation) and SOAP based services (active/WS-Trust). While there is limited support for WCF WebServiceHost based services (for standard credential types like Windows and Basic), there is no ready to use … Continue reading

Posted in IdentityModel, IdentityServer | Leave a comment

Need WIF Training?

I spend numerous hours every month answering questions about WIF and identity in general. This made me realize that this is still quite a complicated topic once you go beyond the standard fedutil stuff. My good friend Brock and I … Continue reading

Posted in Conferences & Training, IdentityModel, IdentityServer | Leave a comment

Fiddling with ADFS Traffic

ADFS uses SSL extended protection which made observing traffic with Fiddler harder to impossible. Fortunately, this can be fixed – Eric Lawrence writes about it here.

Posted in IdentityModel | Leave a comment

Updated IdentityServer Sample Relying Party

I just uploaded a new version of the sample relying party. The three changes are: Added a session token diagnostics page. This allows to look at cookie sizes, details and the raw contents Sample code to switch to session mode … Continue reading

Posted in IdentityModel, IdentityServer | 3 Comments

Switching to WIF SessionMode in ASP.NET

To make it short: to switch to SessionMode (cache to server) in ASP.NET, you need to handle an event and set a property. Sounds easy – but you need to set it in the right place. The most popular blog … Continue reading

Posted in IdentityModel | 5 Comments

Guide to Claims-based Identity and Access Control (2nd Edition)

This fell through the cracks over the summer holiday time: The 2nd edition of the Patterns & Practices “claims guide” has been released. This is excellent! We added a lot of content around ADFS, Access Control Service, REST and SharePoint. … Continue reading

Posted in Conferences & Training, IdentityModel | 2 Comments

WIF in .NET 4.5–First Observations (2)

WindowsIdentity, FormsIdentity and GenericIdentity now derive from ClaimsIdentity WindowsIdentity.GetCurrent() converts Windows token details (groups for the current Windows versions) to claims. Claims for Windows identities now distinguish between user claims and device claims (Windows 8 feature) WCF now populates Thread.CurrentPrincipal … Continue reading

Posted in .NET Security, IdentityModel | Leave a comment

WIF in .NET 4.5–First Observations

System.Security.Claims has ClaimsIdentity & ClaimsPrincipal IClaimsIdentity & IClaimsPrincipal are gone. The classes implement IIdentity & IPrincipal now directly All the token handler and low level plumbing is now in System.IdentityModel

Posted in .NET Security, IdentityModel | Leave a comment

Claims-based Identity in .NET 4.5 and Windows 8

There was not a ton of new information about WIF and related technologies at Build, but Samuel Devasahayam did a great talk about claims-based access control that contained some very interesting bits of information with regards to future directions. From … Continue reading

Posted in .NET Security, IdentityModel | Leave a comment