CodeAttest
VSTS, Oslo, INETA, ASP.NET, Debugging .NET Applications, Tips and Tricks

February 22, 2005

WSE Policy Advisor

Microsoft released WSE Policy Advisor - a tool for checking policy correctness. It is called the FxCop tool for web services.

Sample output from the report:

Alarm: Test root certificates are allowed.
Risk: Any usage of X.509 certificates for signing or encrypting is unsafe. An active attacker can generate valid test certificates, then for instance use these certificates to sign any message.
Advice: Do not use test keys in production: set the attribute allowTestRoot="false" in the element of the WSE configuration file.



# posted by Martin Kulov @ 2:17 AM




This page is powered by Blogger. Isn't yours?

 




Calendar Martin Kulov's Calendar   RSS Aggregate this blog

DevReach - The Premier Conference for Microsoft Technologies for SEE

Mobility Day 2008 Conference

DevReach - The Premier Conference for Microsoft Technologies in Bulgaria

International Association of Software Architects

SofiaDev .NET User Group

Microsoft Most Valuable Professional

View Martin Kulov's profile on LinkedIn

MSDN Event Bloggers




Recent posts




History




 
Copyright © 2004-2008 CodeAttest Ltd. All Rights Reserved.