VSTS, Oslo, INETA, ASP.NET, Debugging .NET Applications, Tips and Tricks

February 22, 2005

WSE Policy Advisor

Microsoft released WSE Policy Advisor - a tool for checking policy correctness. It is called the FxCop tool for web services.

Sample output from the report:

Alarm: Test root certificates are allowed.
Risk: Any usage of X.509 certificates for signing or encrypting is unsafe. An active attacker can generate valid test certificates, then for instance use these certificates to sign any message.
Advice: Do not use test keys in production: set the attribute allowTestRoot="false" in the element of the WSE configuration file.



# posted by Martin Kulov @ 2:17 AM

Share |







This page is powered by Blogger. Isn't yours?

 








Recent posts



Locations of visitors to this page



History




 
Copyright © 2004-2008 CodeAttest Ltd. All Rights Reserved.
<%-- Google Analytics code --%> <%-- Google Analytics code --%>