Hi,
I am looking for some guidance on designing security services that can be used on any platform. I already have services that take care of authentication and authorisation, but what I currently have maps well to ASP.net or WIndows clients, it would not neccesarily work well in another client environment. Additionally, with WSE and WCF enabling us to secure the channel between the client and the service, is 'validating' the claimed identity of the user along with their permissions (roles etc) during calls to business services overkill While I would obviously like to reuse as much of the pre-built security infrastructure as possible, having something that works in the same way as my business services is my ultimate goal.
If anybody can give me any hints, or point me in the direction of some appropriate security patterns I would appreciate it.
BTW, the services are built in C# 2.0.
Thanks, ASC.

SOA Security Patterns
Dr Zombie
Hi,
Did u check this out -> http://searchwebservices.techtarget.com/searchWebServices/downloads/SecuritySOA_(2).pdf
Cheers!
Shamrox
Web Service Security: Scenarios, Patterns, and Implementation Guidance: Home
and
http://www.owasp.org/index.jsp