Category Archives: Uncategorized

TechEd:Developer 2007 Security Track

TechEd:Developer in Barcelona this year will be the first TechEd ever that has a “physical” security track. That’s great. There are great speakers and interesting sessions on this track, e.g. Michael Howard (SDL, Threat Modeling), Keith Brown (identity, claims and … Continue reading

Posted in Uncategorized | Leave a comment

Details of CardSpace RP Identity Generation

Ever wondered how exactly the RP identity is “calculated” for EV and non EV certs? Get the details here. Just search for “OrgIdBytes”.  

Posted in Uncategorized | Leave a comment

CardSpace in 3.5 doesn't require SSL

Important change to CardSpace in .NET 3.5 – read the details here.  

Posted in Uncategorized | Leave a comment

Live ID and Information Cards – just good friends…

Read more here and here. finally.  

Posted in Uncategorized | Leave a comment

Certificate based Authentication and WCF

Certificate based authentication with WCF has two components – configuring credentials and determining trust. The first part is easy – you simply set the clientCredentialType in the binding’s security configuration to Certificate. This means that WCF will demand that the client … Continue reading

Posted in Uncategorized | 2 Comments

Guidance on User and Password Management

The ACE blog has a good checklist on the above topic. Something to have around when implementing the next password based system.  

Posted in Uncategorized | Leave a comment

Extend Your WCF Services Beyond HTTP With WAS

..is the title of an article by Christian, Steve and me. Online and in the September issue of MSDN Magazine. Enjoy.  

Posted in Uncategorized | Leave a comment

Custom Principals and WCF

The question how to setup a custom principal in WCF services comes up every once in a while. Since it is not obvious how this works, I knocked up a little walkthrough and a boilerplate sample. Principal Permission ModeWCF has … Continue reading

Posted in Uncategorized | 6 Comments

InfoCardSelector for ASP.NET V1.0

OK – so I settled for a final name (since the control also works for other identity selectors than CardSpace this is more appropriate) and resetted the version. There are only minor (but breaking) changes to the last version I … Continue reading

Posted in Uncategorized | Leave a comment

Excellent ASP.NET Information

Daniel currently publishes an internal Microsoft feed on his blog. Excellent information about ASP.NET internals like process models, dynamic compilation and the pipeline (more to come). Recommended!  

Posted in Uncategorized | Leave a comment