in this MSDN article on the WCF configuration scheme contains a warning:
You must protect the WCF configuration sections in the application configuration files (app.config) with the appropriate access control lists (ACLs) to prevent any potential security risks. For example, you should make sure that only the right people can access or change security settings when binding applications or the service model section of the configuration file for the service.
And this is exactly what I need for my WCF services, but I can not find much information on how to achieve this type of protection.
Can someone please give me some examples of how to protect sections of the WCF configuration file using access control lists (ACLs) or tell me more information about this topic?
Thanks in advance.
source
share