| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Security.Authentication.ExtendedProtection; |
| | | 5 | | using System.Security.Principal; |
| | | 6 | | |
| | | 7 | | namespace System.Net.Security |
| | | 8 | | { |
| | | 9 | | /// <summary> |
| | | 10 | | /// Represents a property bag for client-side of an authentication exchange. |
| | | 11 | | /// </summary> |
| | | 12 | | /// <remarks> |
| | | 13 | | /// This property bag is used as argument for <see cref="NegotiateAuthentication" /> |
| | | 14 | | /// constructor for initializing a client-side authentication. |
| | | 15 | | /// |
| | | 16 | | /// Initial values of the properties are set for an authentication using |
| | | 17 | | /// default network credentials. If you want to explicitly authenticate using a user |
| | | 18 | | /// name, password and domain combination then set the <see cref="Credential" /> |
| | | 19 | | /// property appropriately. |
| | | 20 | | /// |
| | | 21 | | /// Typical usage of the client-side authentication will also require specifying the |
| | | 22 | | /// the <see cref="TargetName" /> property. While it may be omitted in some scenarios |
| | | 23 | | /// it is usually required to be set to a valid value like <c>HOST/contoso.com</c> or |
| | | 24 | | /// <c>HTTP/www.contoso.com</c>. |
| | | 25 | | /// |
| | | 26 | | /// When the authentication is wrapped in a secure channel, like TLS, the channel |
| | | 27 | | /// binding can provide additional protection by strongly binding the authentication |
| | | 28 | | /// to a given transport channel. This is handled by setting the <see cref="Binding" /> |
| | | 29 | | /// property. For <see cref="SslStream" /> the channel binding could be obtained |
| | | 30 | | /// through the <see cref="SslStream.TransportContext" /> property and calling the |
| | | 31 | | /// <see cref="TransportContext.GetChannelBinding" /> method. |
| | | 32 | | /// </remarks> |
| | | 33 | | public class NegotiateAuthenticationClientOptions |
| | | 34 | | { |
| | | 35 | | /// <summary> |
| | | 36 | | /// Initializes a new instance of the <see cref="NegotiateAuthenticationClientOptions" /> class. |
| | | 37 | | /// </summary> |
| | 0 | 38 | | public NegotiateAuthenticationClientOptions() |
| | 0 | 39 | | { |
| | 0 | 40 | | } |
| | | 41 | | |
| | | 42 | | /// <summary> |
| | | 43 | | /// Specifies the GSSAPI authentication package used for the authentication. |
| | | 44 | | /// Common values are Negotiate, NTLM or Kerberos. Default value is Negotiate. |
| | | 45 | | /// </summary> |
| | 0 | 46 | | public string Package { get; set; } = NegotiationInfoClass.Negotiate; |
| | | 47 | | |
| | | 48 | | /// <summary> |
| | | 49 | | /// The NetworkCredential that is used to establish the identity of the client. |
| | | 50 | | /// Default value is <see cref="CredentialCache.DefaultNetworkCredentials" />. |
| | | 51 | | /// </summary> |
| | 0 | 52 | | public NetworkCredential Credential { get; set; } = CredentialCache.DefaultNetworkCredentials; |
| | | 53 | | |
| | | 54 | | /// <summary> |
| | | 55 | | /// The Service Principal Name (SPN) that uniquely identifies the server to authenticate. |
| | | 56 | | /// </summary> |
| | 0 | 57 | | public string? TargetName { get; set; } |
| | | 58 | | |
| | | 59 | | /// <summary> |
| | | 60 | | /// Channel binding that is used for extended protection. |
| | | 61 | | /// </summary> |
| | 0 | 62 | | public ChannelBinding? Binding { get; set; } |
| | | 63 | | |
| | | 64 | | /// <summary> |
| | | 65 | | /// Indicates the required level of protection of the authentication exchange |
| | | 66 | | /// and any further data exchange. Default value is None. |
| | | 67 | | /// </summary> |
| | 0 | 68 | | public ProtectionLevel RequiredProtectionLevel { get; set; } = ProtectionLevel.None; |
| | | 69 | | |
| | | 70 | | /// <summary> |
| | | 71 | | /// Indicates that mutual authentication is required between the client and server. |
| | | 72 | | /// </summary> |
| | 0 | 73 | | public bool RequireMutualAuthentication { get; set; } |
| | | 74 | | |
| | | 75 | | /// <summary> |
| | | 76 | | /// One of the <see cref="TokenImpersonationLevel" /> values, indicating how the server |
| | | 77 | | /// can use the client's credentials to access resources. |
| | | 78 | | /// </summary> |
| | 0 | 79 | | public TokenImpersonationLevel AllowedImpersonationLevel { get; set; } = TokenImpersonationLevel.None; |
| | | 80 | | } |
| | | 81 | | } |
| | | 82 | | |