1

我有一个 WCF 服务,它以编程方式公开 WsFederationHttpBinding 端点。然后,我想使用 Visual Studio 使用服务引用对话框创建客户端端点。客户端生成正确的端点和绑定,但我必须在客户端配置中为 STS 手动创建绑定,并将其连接到联合服务绑定的发布者元素。有没有办法创建服务器端绑定,以便在客户端自动生成 STS 绑定?

这基本上是我在代码中生成绑定的方式:

public class MyServiceHost : ServiceHostFactory
{
    protected override void AddServiceEndpoint(ServiceHost host, Type contract, Uri address)
    {
        var binding = new WSFederationHttpBinding();
        // set up some binding properties here
        binding.Security = new WSFederationHttpSecurity
        {
            Mode = WSFederationHttpSecurityMode.Message,
            Message = new FederatedMessageSecurityOverHttp
            {
                AlgorithmSuite = SecurityAlgorithmSuite.Default,
                EstablishSecurityContext = true,
                IssuedTokenType = "http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV1.1",
                NegotiateServiceCredential = false,
                IssuerAddress = new EndpointAddress(
                    new Uri("http://mydomain/STSService.svc"), 
                    EndpointIdentity.CreateSpnIdentity("http/IDENTITYMASKED")),
                IssuerBinding = new WSHttpBinding
                {
                    Name = "stsBinding",
                    Security = new WSHttpSecurity
                    {
                        Mode = SecurityMode.Message,
                        Message = new NonDualMessageSecurityOverHttp
                        {
                            ClientCredentialType = MessageCredentialType.Windows,
                            NegotiateServiceCredential = true,
                            AlgorithmSuite = SecurityAlgorithmSuite.Default,
                            EstablishSecurityContext = false
                        }
                    }
                }
            }
        };
        host.AddServiceEndpoint(contract, binding, address);
    }
}

当我在 Visual Studio 中为此生成代理时,stsBinding 不在配置中或已连接,有没有办法让这种情况发生或 MEX 不允许它?

4

1 回答 1

0

不确定它是否会有所帮助,因为我自己的服务尚未运行,但我的(当前未经测试的)代码设置了 FederatedMessageSecurityOverHttp 元素的 IssuerMetadataAddress,这应该也是使客户端向导能够生成该绑定的原因。

于 2013-04-12T14:33:06.130 回答