{"id":1326,"date":"2014-12-09T10:11:14","date_gmt":"2014-12-09T08:11:14","guid":{"rendered":"http:\/\/hen.co.za\/blog\/?p=1326"},"modified":"2014-12-09T10:11:14","modified_gmt":"2014-12-09T08:11:14","slug":"calling-soap-web-service-from-desktop-app-with-windows-authentication","status":"publish","type":"post","link":"https:\/\/hen.co.za\/blog\/2014\/12\/calling-soap-web-service-from-desktop-app-with-windows-authentication\/","title":{"rendered":"Calling Soap web service from Desktop app with Windows Authentication"},"content":{"rendered":"<p>I recently had to create a small proof of concept app that calls a soap web service which must be a bit more secure than just allowing Anonymous access. The Web Service requires Windows Authentication to be enabled (NTLM as main provider) with Anonymous disabled.<\/p>\n<p>Calling this web service should be straight forward as you would expect a Windows (Forms) desktop application to pass any logon details when making network related calls. Unfortunately when using Web Services the call seems to be made &#8216;Anonymous&#8217; by default using the generated proxy class as created by Visual Studio. Fortunately the solution is straight forward provided you can find it on Google (or any other search engine \ud83d\ude09 )<\/p>\n<p>Without going into the real details of how and why this work here is the solution: You have to add security details to the &#8216;binding configuration&#8217; of the endpoint of the Web Reference. In short the config must look something like this:<\/p>\n<pre class=\"brush: xml; title: ; notranslate\" title=\"\">\r\n  &lt;system.serviceModel&gt;\r\n    &lt;bindings&gt;\r\n      &lt;basicHttpBinding&gt;\r\n       &lt;binding name=&quot;SomeServiceSoap&quot;&gt;\r\n                &lt;strong&gt;&lt;security mode=&quot;TransportCredentialOnly&quot;&gt;\r\n                  &lt;transport clientCredentialType=&quot;Ntlm&quot; proxyCredentialType=&quot;None&quot;\r\n                      realm=&quot;&quot; \/&gt;\r\n                  &lt;message clientCredentialType=&quot;UserName&quot; algorithmSuite=&quot;Default&quot; \/&gt;\r\n                &lt;\/security&gt;&lt;\/strong&gt;\r\n              &lt;\/binding&gt;\r\n      &lt;\/basicHttpBinding&gt;\r\n    &lt;\/bindings&gt;\r\n    &lt;client&gt;\r\n      &lt;endpoint address=&quot;http:\/\/myserver\/webservices\/SomeService\/SomeService.asmx&quot;\r\n                binding=&quot;basicHttpBinding&quot;\r\n                bindingConfiguration=&quot;SomeServiceSoap&quot;\r\n                contract=&quot;SomeServiceWS.SomeServiceSoap&quot;\r\n                name=&quot;SomeServiceSoap&quot; \/&gt;\r\n    &lt;\/client&gt;\r\n  &lt;\/system.serviceModel&gt;\r\n<\/pre>\n<p>The important part here is the &lt;security&gt; tag and its content. Like explained before on the server side Only &#8216;Windows Authentication&#8217; must be enabled with the &#8216;NTLM&#8217; provider as the first provider.<\/p>\n<p>Possibly this can also be done through code but I haven&#8217;t tried that yet.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently had to create a small proof of concept app that calls a soap web service which must be a bit more secure than just allowing Anonymous access. The Web Service requires Windows Authentication to be enabled (NTLM as &hellip;<\/p>\n<p class=\"read-more\"><a href=\"https:\/\/hen.co.za\/blog\/2014\/12\/calling-soap-web-service-from-desktop-app-with-windows-authentication\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[200,289,290],"class_list":["post-1326","post","type-post","status-publish","format-standard","hentry","category-development","tag-desktop-development","tag-web-service","tag-windows-application"],"_links":{"self":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts\/1326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/comments?post=1326"}],"version-history":[{"count":4,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts\/1326\/revisions"}],"predecessor-version":[{"id":1330,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts\/1326\/revisions\/1330"}],"wp:attachment":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/media?parent=1326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/categories?post=1326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/tags?post=1326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}