FederatedMessageSecurityOverHttp.cs 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369
  1. //------------------------------------------------------------
  2. // Copyright (c) Microsoft Corporation. All rights reserved.
  3. //------------------------------------------------------------
  4. namespace System.ServiceModel
  5. {
  6. using System.Collections.ObjectModel;
  7. using System.IdentityModel.Tokens;
  8. using System.Runtime;
  9. using System.Runtime.CompilerServices;
  10. using System.ServiceModel.Channels;
  11. using System.ServiceModel.Security;
  12. using System.ServiceModel.Security.Tokens;
  13. using System.Xml;
  14. using System.ComponentModel;
  15. public sealed class FederatedMessageSecurityOverHttp
  16. {
  17. internal const bool DefaultNegotiateServiceCredential = true;
  18. internal const SecurityKeyType DefaultIssuedKeyType = SecurityKeyType.SymmetricKey;
  19. internal const bool DefaultEstablishSecurityContext = true;
  20. bool establishSecurityContext;
  21. bool negotiateServiceCredential;
  22. SecurityAlgorithmSuite algorithmSuite;
  23. EndpointAddress issuerAddress;
  24. EndpointAddress issuerMetadataAddress;
  25. Binding issuerBinding;
  26. Collection<ClaimTypeRequirement> claimTypeRequirements;
  27. string issuedTokenType;
  28. SecurityKeyType issuedKeyType;
  29. Collection<XmlElement> tokenRequestParameters;
  30. public FederatedMessageSecurityOverHttp()
  31. {
  32. negotiateServiceCredential = DefaultNegotiateServiceCredential;
  33. algorithmSuite = SecurityAlgorithmSuite.Default;
  34. issuedKeyType = DefaultIssuedKeyType;
  35. claimTypeRequirements = new Collection<ClaimTypeRequirement>();
  36. tokenRequestParameters = new Collection<XmlElement>();
  37. establishSecurityContext = DefaultEstablishSecurityContext;
  38. }
  39. public bool NegotiateServiceCredential
  40. {
  41. get { return this.negotiateServiceCredential; }
  42. set { this.negotiateServiceCredential = value; }
  43. }
  44. public SecurityAlgorithmSuite AlgorithmSuite
  45. {
  46. get { return this.algorithmSuite; }
  47. set
  48. {
  49. if (value == null)
  50. {
  51. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgumentNull("value");
  52. }
  53. this.algorithmSuite = value;
  54. }
  55. }
  56. public bool EstablishSecurityContext
  57. {
  58. get
  59. {
  60. return this.establishSecurityContext;
  61. }
  62. set
  63. {
  64. this.establishSecurityContext = value;
  65. }
  66. }
  67. [DefaultValue(null)]
  68. public EndpointAddress IssuerAddress
  69. {
  70. get { return this.issuerAddress; }
  71. set { this.issuerAddress = value; }
  72. }
  73. [DefaultValue(null)]
  74. public EndpointAddress IssuerMetadataAddress
  75. {
  76. get { return this.issuerMetadataAddress; }
  77. set { this.issuerMetadataAddress = value; }
  78. }
  79. [DefaultValue(null)]
  80. public Binding IssuerBinding
  81. {
  82. get
  83. {
  84. return this.issuerBinding;
  85. }
  86. set
  87. {
  88. this.issuerBinding = value;
  89. }
  90. }
  91. [DefaultValue(null)]
  92. public string IssuedTokenType
  93. {
  94. get { return this.issuedTokenType; }
  95. set { this.issuedTokenType = value; }
  96. }
  97. public SecurityKeyType IssuedKeyType
  98. {
  99. get { return this.issuedKeyType; }
  100. set
  101. {
  102. if (!SecurityKeyTypeHelper.IsDefined(value))
  103. {
  104. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new ArgumentOutOfRangeException("value"));
  105. }
  106. this.issuedKeyType = value;
  107. }
  108. }
  109. public Collection<ClaimTypeRequirement> ClaimTypeRequirements
  110. {
  111. get { return this.claimTypeRequirements; }
  112. }
  113. public Collection<XmlElement> TokenRequestParameters
  114. {
  115. get { return this.tokenRequestParameters; }
  116. }
  117. [MethodImpl(MethodImplOptions.NoInlining)]
  118. internal SecurityBindingElement CreateSecurityBindingElement(bool isSecureTransportMode,
  119. bool isReliableSession,
  120. MessageSecurityVersion version)
  121. {
  122. if ((this.IssuedKeyType == SecurityKeyType.BearerKey) &&
  123. (version.TrustVersion == TrustVersion.WSTrustFeb2005))
  124. {
  125. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new InvalidOperationException(SR.GetString(SR.BearerKeyIncompatibleWithWSFederationHttpBinding)));
  126. }
  127. if (isReliableSession && !this.EstablishSecurityContext)
  128. {
  129. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new InvalidOperationException(SR.GetString(SR.SecureConversationRequiredByReliableSession)));
  130. }
  131. SecurityBindingElement result;
  132. bool emitBspAttributes = true;
  133. IssuedSecurityTokenParameters issuedParameters = new IssuedSecurityTokenParameters(this.IssuedTokenType, this.IssuerAddress, this.IssuerBinding);
  134. issuedParameters.IssuerMetadataAddress = this.issuerMetadataAddress;
  135. issuedParameters.KeyType = this.IssuedKeyType;
  136. if (this.IssuedKeyType == SecurityKeyType.SymmetricKey)
  137. {
  138. issuedParameters.KeySize = this.AlgorithmSuite.DefaultSymmetricKeyLength;
  139. }
  140. else
  141. {
  142. issuedParameters.KeySize = 0;
  143. }
  144. foreach (ClaimTypeRequirement c in this.claimTypeRequirements)
  145. {
  146. issuedParameters.ClaimTypeRequirements.Add(c);
  147. }
  148. foreach (XmlElement p in this.TokenRequestParameters)
  149. {
  150. issuedParameters.AdditionalRequestParameters.Add(p);
  151. }
  152. WSSecurityTokenSerializer versionSpecificSerializer = new WSSecurityTokenSerializer(version.SecurityVersion,
  153. version.TrustVersion,
  154. version.SecureConversationVersion,
  155. emitBspAttributes,
  156. null, null, null);
  157. SecurityStandardsManager versionSpecificStandardsManager = new SecurityStandardsManager(version, versionSpecificSerializer);
  158. issuedParameters.AddAlgorithmParameters(this.AlgorithmSuite, versionSpecificStandardsManager, this.issuedKeyType);
  159. SecurityBindingElement issuedTokenSecurity;
  160. if (isSecureTransportMode)
  161. {
  162. issuedTokenSecurity = SecurityBindingElement.CreateIssuedTokenOverTransportBindingElement(issuedParameters);
  163. }
  164. else
  165. {
  166. if (negotiateServiceCredential)
  167. {
  168. // We should have passed 'true' as RequireCancelation to be consistent with other standard bindings.
  169. // However, to limit the change for Orcas, we scope down to just newer version of WSSecurityPolicy.
  170. issuedTokenSecurity = SecurityBindingElement.CreateIssuedTokenForSslBindingElement(issuedParameters, version.SecurityPolicyVersion != SecurityPolicyVersion.WSSecurityPolicy11);
  171. }
  172. else
  173. {
  174. issuedTokenSecurity = SecurityBindingElement.CreateIssuedTokenForCertificateBindingElement(issuedParameters);
  175. }
  176. }
  177. issuedTokenSecurity.MessageSecurityVersion = version;
  178. issuedTokenSecurity.DefaultAlgorithmSuite = this.AlgorithmSuite;
  179. if (this.EstablishSecurityContext)
  180. {
  181. result = SecurityBindingElement.CreateSecureConversationBindingElement(issuedTokenSecurity, true);
  182. }
  183. else
  184. {
  185. result = issuedTokenSecurity;
  186. }
  187. result.MessageSecurityVersion = version;
  188. result.DefaultAlgorithmSuite = this.AlgorithmSuite;
  189. result.IncludeTimestamp = true;
  190. if (!isReliableSession)
  191. {
  192. result.LocalServiceSettings.ReconnectTransportOnFailure = false;
  193. result.LocalClientSettings.ReconnectTransportOnFailure = false;
  194. }
  195. else
  196. {
  197. result.LocalServiceSettings.ReconnectTransportOnFailure = true;
  198. result.LocalClientSettings.ReconnectTransportOnFailure = true;
  199. }
  200. if (this.establishSecurityContext)
  201. {
  202. // issue the transition SCT for a short duration only
  203. issuedTokenSecurity.LocalServiceSettings.IssuedCookieLifetime = SpnegoTokenAuthenticator.defaultServerIssuedTransitionTokenLifetime;
  204. }
  205. return result;
  206. }
  207. internal static bool TryCreate(SecurityBindingElement sbe, bool isSecureTransportMode, bool isReliableSession, MessageSecurityVersion version, out FederatedMessageSecurityOverHttp messageSecurity)
  208. {
  209. Fx.Assert(null != sbe, string.Empty);
  210. messageSecurity = null;
  211. // do not check local settings: sbe.LocalServiceSettings and sbe.LocalClientSettings
  212. if (!sbe.IncludeTimestamp)
  213. return false;
  214. if (sbe.SecurityHeaderLayout != SecurityProtocolFactory.defaultSecurityHeaderLayout)
  215. return false;
  216. bool emitBspAttributes = true;
  217. // Do not check MessageSecurityVersion: it maybe changed by the wrapper element and gets checked later in the SecuritySection.AreBindingsMatching()
  218. SecurityBindingElement bootstrapSecurity;
  219. bool establishSecurityContext = SecurityBindingElement.IsSecureConversationBinding(sbe, true, out bootstrapSecurity);
  220. bootstrapSecurity = establishSecurityContext ? bootstrapSecurity : sbe;
  221. if (isSecureTransportMode && !(bootstrapSecurity is TransportSecurityBindingElement))
  222. return false;
  223. bool negotiateServiceCredential = DefaultNegotiateServiceCredential;
  224. IssuedSecurityTokenParameters issuedTokenParameters;
  225. if (isSecureTransportMode)
  226. {
  227. if (!SecurityBindingElement.IsIssuedTokenOverTransportBinding(bootstrapSecurity, out issuedTokenParameters))
  228. return false;
  229. }
  230. else
  231. {
  232. // We should have passed 'true' as RequireCancelation to be consistent with other standard bindings.
  233. // However, to limit the change for Orcas, we scope down to just newer version of WSSecurityPolicy.
  234. if (SecurityBindingElement.IsIssuedTokenForSslBinding(bootstrapSecurity, version.SecurityPolicyVersion != SecurityPolicyVersion.WSSecurityPolicy11, out issuedTokenParameters))
  235. negotiateServiceCredential = true;
  236. else if (SecurityBindingElement.IsIssuedTokenForCertificateBinding(bootstrapSecurity, out issuedTokenParameters))
  237. negotiateServiceCredential = false;
  238. else
  239. return false;
  240. }
  241. if ((issuedTokenParameters.KeyType == SecurityKeyType.BearerKey) &&
  242. (version.TrustVersion == TrustVersion.WSTrustFeb2005))
  243. {
  244. return false;
  245. }
  246. Collection<XmlElement> nonAlgorithmRequestParameters;
  247. WSSecurityTokenSerializer versionSpecificSerializer = new WSSecurityTokenSerializer(version.SecurityVersion,
  248. version.TrustVersion,
  249. version.SecureConversationVersion,
  250. emitBspAttributes,
  251. null, null, null);
  252. SecurityStandardsManager versionSpecificStandardsManager = new SecurityStandardsManager(version, versionSpecificSerializer);
  253. if (!issuedTokenParameters.DoAlgorithmsMatch(sbe.DefaultAlgorithmSuite,
  254. versionSpecificStandardsManager,
  255. out nonAlgorithmRequestParameters))
  256. {
  257. return false;
  258. }
  259. messageSecurity = new FederatedMessageSecurityOverHttp();
  260. messageSecurity.AlgorithmSuite = sbe.DefaultAlgorithmSuite;
  261. messageSecurity.NegotiateServiceCredential = negotiateServiceCredential;
  262. messageSecurity.EstablishSecurityContext = establishSecurityContext;
  263. messageSecurity.IssuedTokenType = issuedTokenParameters.TokenType;
  264. messageSecurity.IssuerAddress = issuedTokenParameters.IssuerAddress;
  265. messageSecurity.IssuerBinding = issuedTokenParameters.IssuerBinding;
  266. messageSecurity.IssuerMetadataAddress = issuedTokenParameters.IssuerMetadataAddress;
  267. messageSecurity.IssuedKeyType = issuedTokenParameters.KeyType;
  268. foreach (ClaimTypeRequirement c in issuedTokenParameters.ClaimTypeRequirements)
  269. {
  270. messageSecurity.ClaimTypeRequirements.Add(c);
  271. }
  272. foreach (XmlElement p in nonAlgorithmRequestParameters)
  273. {
  274. messageSecurity.TokenRequestParameters.Add(p);
  275. }
  276. if (issuedTokenParameters.AlternativeIssuerEndpoints != null && issuedTokenParameters.AlternativeIssuerEndpoints.Count > 0)
  277. {
  278. return false;
  279. }
  280. return true;
  281. }
  282. internal bool InternalShouldSerialize()
  283. {
  284. return (this.ShouldSerializeAlgorithmSuite()
  285. || this.ShouldSerializeClaimTypeRequirements()
  286. || this.ShouldSerializeNegotiateServiceCredential()
  287. || this.ShouldSerializeEstablishSecurityContext()
  288. || this.ShouldSerializeIssuedKeyType()
  289. || this.ShouldSerializeTokenRequestParameters());
  290. }
  291. [EditorBrowsable(EditorBrowsableState.Never)]
  292. public bool ShouldSerializeAlgorithmSuite()
  293. {
  294. return (this.AlgorithmSuite != SecurityAlgorithmSuite.Default);
  295. }
  296. [EditorBrowsable(EditorBrowsableState.Never)]
  297. public bool ShouldSerializeClaimTypeRequirements()
  298. {
  299. return (this.ClaimTypeRequirements.Count > 0);
  300. }
  301. [EditorBrowsable(EditorBrowsableState.Never)]
  302. public bool ShouldSerializeNegotiateServiceCredential()
  303. {
  304. return (this.NegotiateServiceCredential != DefaultNegotiateServiceCredential);
  305. }
  306. [EditorBrowsable(EditorBrowsableState.Never)]
  307. public bool ShouldSerializeEstablishSecurityContext()
  308. {
  309. return (this.EstablishSecurityContext != DefaultEstablishSecurityContext);
  310. }
  311. [EditorBrowsable(EditorBrowsableState.Never)]
  312. public bool ShouldSerializeIssuedKeyType()
  313. {
  314. return (this.IssuedKeyType != DefaultIssuedKeyType);
  315. }
  316. [EditorBrowsable(EditorBrowsableState.Never)]
  317. public bool ShouldSerializeTokenRequestParameters()
  318. {
  319. return (this.TokenRequestParameters.Count > 0);
  320. }
  321. }
  322. }