Edit

Transaction Protocols

Windows Communication Foundation (WCF) implements WS-Atomic Transaction and WS-Coordination protocols.

Specification/Document Version Link
WS-Coordination 1.0

1.1
https://schemas.xmlsoap.org/ws/2004/10/wscoor/

https://docs.oasis-open.org/ws-tx/wscoor/2006/06
WS-AtomicTransaction 1.0

1.1
https://schemas.xmlsoap.org/ws/2004/10/wsat/

https://docs.oasis-open.org/ws-tx/wsat/2006/06

Interoperability on these protocol specifications is required at two levels: between applications and between transaction managers (see the following figure). Specifications describe in great detail the message formats and message exchange for both interoperability levels. Certain security, reliability, and encodings for application-to-application exchange apply as they do for regular application exchange. However, successful interoperability between transaction managers requires agreement on the particular binding, because it is usually not configured by the user.

This article describes a composition of the WS-Atomic Transaction (WS-AT) specification with security and describes the secure binding used for communication between transaction managers. The approach described in this article has been successfully tested with other implementations of WS-AT and WS-Coordination including IBM, IONA, Sun Microsystems, and others.

The following figure depicts the interoperability between two transaction managers, Transaction Manager 1 and Transaction Manager 2, and two applications, Application 1 and Application 2:

Screenshot that shows interaction between transaction managers.

Consider a typical WS-Coordination/WS-Atomic Transaction scenario with one Initiator (I) and one Participant (P). Both Initiator and Participant have Transaction Managers (ITM and PTM, respectively). Two-phase commit is referred to as 2PC in this article.

  1. CreateCoordinationContext
  2. CreateCoordinationContextResponse
  3. Register (Completion)
  4. RegisterResponse
  5. Application Message
  6. CreateCoordinationContext with Context
  7. Register (Durable)
  8. RegisterResponse
  9. CreateCoordinationContextResponse
  10. Register (Durable)
  11. RegisterResponse
  12. Application Message Response
  13. Commit (Completion)
  14. Prepare (2PC)
  15. Prepare (2PC)
  16. Prepared (2PC)
  17. Prepared (2PC)
  18. Committed (Completion)
  19. Commit (2PC)
  20. Commit (2PC)
  21. Committed (2PC)
  22. Committed (2PC)

The figure and table illustrate four classes of messages from the viewpoint of security:

  • Activation messages (CreateCoordinationContext and CreateCoordinationContextResponse).

  • Registration messages (Register and RegisterResponse)

  • Protocol messages (Prepare, Rollback, Commit, Aborted, and so on).

  • Application messages.

The first three message classes are considered Transaction Manager messages and their binding configuration is described in the "Application Message Exchange" later in this topic. The fourth class of message is application to application messages and is described in the "Message Examples" section later in this topic. This section describes the protocol bindings used for each of these classes by WCF.

The following XML Namespaces and associated prefixes are used throughout this document.

Prefix Version Namespace URI
s11 https://schemas.xmlsoap.org/soap/envelope/
wsa Pre-1.0

1.0
https://www.w3.org/2004/08/addressing

https://www.w3.org/2005/08/addressing/
wscoor 1.0

1.1
https://schemas.xmlsoap.org/ws/2004/10/wscoor/

https://docs.oasis-open.org/ws-tx/wscoor/2006/06
wsat 1.0

1.1
https://schemas.xmlsoap.org/ws/2004/10/wsat/

https://docs.oasis-open.org/ws-tx/wsat/2006/06
t Pre-1.3

1.3
https://schemas.xmlsoap.org/ws/2005/02/trust/

https://docs.oasis-open.org/ws-sx/ws-trust/200512
o https://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd
xsd https://www.w3.org/2001/XMLSchema

Transaction Manager Bindings

R1001: Transaction Managers participating in a WS-AT 1.0 transaction must use SOAP 1.1 and WS-Addressing 2004/08 for WS-Atomic Transaction and WS-Coordination message exchanges.

R1002: Transaction Managers participating in a WS-AT 1.1 transaction must use SOAP 1.1 and WS-Addressing 2005/08 for WS-Atomic Transaction and WS-Coordination message exchanges.

Application messages are not constrained to these bindings and are described later.

Transaction Manager HTTPS Binding

The transaction manager HTTPS binding relies solely on transport security to achieve security and establish trust between each sender-receiver pair in the transaction tree.

HTTPS Transport Configuration

X.509 certificates are used to establish Transaction Manager Identity. Client/server authentication is required, and client/server authorization is left as an implementation detail:

  • R1111: X.509 certificates presented over the wire must have a subject name that matches the fully qualified domain name (FQDN) of the originating machine.

  • B1112: DNS must be functional between each sender-receiver pair in the system for X.509 subject name checks to succeed.

Activation and Registration Binding Configuration

WCF requires request/reply duplex binding with correlation over HTTPS. (For more information about correlation and descriptions of the request/reply message exchange patterns, see WS-Atomic Transaction, Section 8.)

2PC Protocol Binding Configuration

WCF supports one-way (datagram) messages over HTTPS. Correlation among the messages is left as an implementation detail.

B1131: Implementations must support wsa:ReferenceParameters as described in WS-Addressing to achieve correlation of WCF’s 2PC messages.

Transaction Manager Mixed Security Binding

This is an alternate (mixed mode) binding that uses transport security combined with the WS-Coordination Issued Token model for identity establishment purposes. Activation and Registration are the only elements that differ between the two bindings.

HTTPS Transport Configuration

X.509 certificates are used to establish Transaction Manager Identity. Client/Server authentication is required, and client/server authorization is left as an implementation detail.

Activation Message Binding Configuration

Activation Messages usually do not participate in interoperability because they typically occur between an application and its local Transaction Manager.

B1221: WCF uses duplex HTTPS binding (described in Messaging Protocols) for Activation messages. Request and Reply messages are correlated using WS-Addressing 2004/08 for WS-AT 1.0 and WS-Addressing 2005/08 for WS-AT 1.1.

WS-Atomic Transaction specification, Section 8, describes further details about correlation and the message exchange patterns.

  • R1222: Upon receiving a CreateCoordinationContext, the Coordinator must issue a SecurityContextToken with associated secret STx. This token is returned inside a t:IssuedTokens header following WS-Trust specification.

  • R1223: If Activation occurs within an existing Coordination Context, the t:IssuedTokens header with the SecurityContextToken associated with existing Context must flow on the CreateCoordinationContext message.

A new t:IssuedTokens header should be generated for attaching to the outgoing wscoor:CreateCoordinationContextResponse message.

Registration Message Binding Configuration

B1231: WCF uses duplex HTTPS binding (described in Messaging Protocols). Request and Reply messages are correlated using WS-Addressing 2004/08 for WS-AT 1.0 and WS-Addressing 2005/08 for WS-AT 1.1.

WS-AtomicTransaction, Section 8, describes further details about correlation and descriptions of the message exchange patterns.

R1232: Outgoing wscoor:Register messages must use the IssuedTokenOverTransport authentication mode described in Security Protocols.

The wsse:Timestamp element must be signed using the SecurityContextToken STx issued. This signature is a proof of possession of the token associated with particular transaction and is used to authenticate a participant enlisting in the transaction. The RegistrationResponse message is sent back over HTTPS.

2PC Protocol Binding Configuration

WCF supports one-way (datagram) messages over HTTPS. Correlation among the messages is left as an implementation detail.

B1241: Implementations must support wsa:ReferenceParameters as described in WS-Addressing to achieve correlation of WCF’s 2PC messages.

Application Message Exchange

Applications are free to use any particular binding for application-to-application messages, as long as the binding meets the following security requirements:

  • R2001: Application-to-application messages must flow the t:IssuedTokens header along with the CoordinationContext in the header of the message.

  • R2002: Integrity and confidentiality of t:IssuedToken must be provided.

The CoordinationContext header contains wscoor:Identifier. While the definition of xsd:AnyURI allows the use of both absolute and relative URIs, WCF supports only wscoor:Identifiers, which are absolute URIs.

B2003: If the wscoor:Identifier of the wscoor:CoordinationContext is a relative URI, faults will be returned from transactional WCF services.

Message Examples

CreateCoordinationContext Request/Response Messages

The following messages follow a request/response pattern.

CreateCoordinationContext with WSCoor 1.0

  
    
    http://.../ws/2004/10/wscoor/CreateCoordinationContext  
    urn:uuid:069f5104-fd88-4264-9f99-60032a82854e  
      
      
https://... https://... 2005-12-15T23:36:09.921Z 2005-12-15T23:41:09.921Z ...

CreateCoordinationContext with WSCoor 1.1


    
    http://docs.oasis-open.org/ws-tx/wscoor/2006/06/CreateCoordinationContext
      
    urn:uuid:069f5104-fd88-4264-9f99-60032a82854e  
    
      
https://... https://... 2005-12-15T23:36:09.921Z 2005-12-15T23:41:09.921Z ...

CreateCoordinationContextResponse with Trust Pre-1.3 and WSCoor 1.0

  
    
    
    ./ws/2004/10/wscoor/CreateCoordinationContextResponse   
    urn:uuid:069f5104-fd88-4264-9f99-60032a82854e  
    https://...   
      
   
    http://schemas.xmlsoap.org/ws/2005/02/sc/sct  
      
        
          
          http://fabrikam123.com/SCTi  
          
      
      
      
        http://fabrikam123.com/CCi  
    
      
        
          
        
      
      
        
          
        
      
      
        
          
        
      
      
      2005-10-24T20:19:26.526Z  
      2005-10-25T06:24:26.526Z  
      
    256  
  
      
      
        
        2005-12-15T23:36:12.015Z  
        2005-12-15T23:41:12.015Z  
        
      
    
    
      
        
          
     http://fabrikam123.com/CCi  
        
        ...  
        ...  
          
          https://...  
            
             ...  
            
          
        
      
    
  

CreateCoordinationContextResponse with Trust 1.3 and WSCoor 1.1

  


http://docs.oasis-open.org/ws-tx/wscoor/2006/06/CreateCoordinationContextResponse   
urn:uuid:069f5104-fd88-4264-9f99-60032a82854e  
https://... 

  
http://schemas.xmlsoap.org/ws/2005/02/sc/sct  


 http://fabrikam123.com/SCTi  



 http://fabrikam123.com/CCi   


  




  



  
  



2005-10-24T20:19:26.526Z  
2005-10-25T06:24:26.526Z  

256




2005-12-15T23:36:12.015Z
2005-12-15T23:41:12.015Z






 http://fabrikam123.com/CCi  

...  
...  

https://...  
 ...  
  




  

Registration Messages

The following messages are registration messages.

Register with WSCoor 1.0

  
    
    http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register  
    urn:uuid:ed418b86-a75e-4aea-9d4e-a5d0cb5c088e  
      
      https://...
      
    https://...  
      
        
        2005-12-15T23:36:13.827Z  
        2005-12-15T23:41:13.827Z  
        
        
        
          http://fabrikam123.com/SCTi  
        
        
        
        
          
            
            
            
              
                
              
              
              
              alRzyhjLgoUOYoh8cx4n75eTcUk=  
              
            
          
        YZYjnVvSOVasAQqQxaaviTSWtqI=  
          
            
              
            
          
        
      
    
    
      
      ...  
        
        https://...   
        
      
    
  

Register with WSCoor 1.1

  

http://docs.oasis-open.org/ws-tx/wscoor/2006/06/Register
urn:uuid:ed418b86-a75e-4aea-9d4e-a5d0cb5c088e  

https://...
  
https://...
  

2005-12-15T23:36:13.827Z  
2005-12-15T23:41:13.827Z  


 http://fabrikam123.com/SCTi  


  
  








 alRzyhjLgoUOYoh8cx4n75eTcUk=  


  
YZYjnVvSOVasAQqQxaaviTSWtqI=  
  

  
    







...  

https://...   



  

Register Response with WSCoor 1.0

  
    
      
      http://schemas.xmlsoap.org/ws/2004/10/wscoor/RegisterResponse  
      
    urn:uuid:ed418b86-a75e-4aea-9d4e-a5d0cb5c088d  
      
      urn:uuid:ed418b86-a75e-4aea-9d4e-a5d0cb5c088e
      
    https://...  
      
        
        2005-12-15T23:36:13.827Z  
        2005-12-15T23:41:13.827Z  
        
      
    
    
      
        
        https://...  
          
          ...  
          
        
      
    
  

Register Response with WSCoor 1.1

  

 http://docs.oasis-open.org/ws-tx/wscoor/2006/06/RegisterResponse  

urn:uuid:ed418b86-a75e-4aea-9d4e-a5d0cb5c088d  
 urn:uuid:ed418b86-a75e-4aea-9d4e-a5d0cb5c088e   
https://...


2005-12-15T23:36:13.827Z  
2005-12-15T23:41:13.827Z  





  
https://...  
 ...   



  

Two Phase Commit Protocol Messages

The following message relates to the two-phase commit (2PC) protocol.

Commit with WSAT 1.0

  
    
    http://.../ws/2004/10/wsat/Commit  
    https://...  
      
        
        2005-12-15T23:36:13.827Z  
        2005-12-15T23:41:13.827Z  
        
     
    
    
      
    
  

Commit with WSAT 1.1

  

http://docs.oasis-open.org/ws-tx/wsat/2006/06  
https://...


2005-12-15T23:36:13.827Z  
2005-12-15T23:41:13.827Z  






  

Application Messages

The following messages are application messages.

Application message-Request

  
    
  
      
      
        2005-10-25T06:29:18.703Z  
        2005-10-25T06:34:18.703Z  
        
        
          
        
        
            
          
            
            
            
          
        
        
          
        
      
      
       
      
    
        
        
      
    
    
    
      
...