System.Security.Policy Namespace

The System.Security.Policy namespace contains code groups, membership conditions, and evidence. These three types of classes are used to create the rules applied by the common language runtime security policy system. Evidence classes are the input to security policy and membership conditions are the switches; together these create policy statements and determine the granted permission set. Policy levels and code groups are the structure of the policy hierarchy. Code groups are the encapsulation of a rule and are arranged hierarchically in a policy level.

  Class Description
Public class AllMembershipCondition Represents a membership condition that matches all code. This class cannot be inherited.
Public class ApplicationDirectory Provides the application directory as evidence for policy evaluation. This class cannot be inherited.
Public class ApplicationDirectoryMembershipCondition Determines whether an assembly belongs to a code group by testing its application directory. This class cannot be inherited.
Public class ApplicationSecurityInfo Holds the security evidence for an application. This class cannot be inherited.
Public class ApplicationSecurityManager Manages trust decisions for manifest-activated applications.
Public class ApplicationTrust Encapsulates security decisions about an application. This class cannot be inherited.
Public class ApplicationTrustCollection Represents a collection of ApplicationTrust objects. This class cannot be inherited.
Public class ApplicationTrustEnumerator Represents the enumerator for ApplicationTrust objects in the ApplicationTrustCollection collection.
Public class CodeConnectAccess Specifies the network resource access that is granted to code.
Public class CodeGroup Represents the abstract base class from which all implementations of code groups must derive.
Public class Evidence Defines the set of information that constitutes input to security policy decisions. This class cannot be inherited.
Public class EvidenceBase Provides a base class from which all objects to be used as evidence must derive.
Public class FileCodeGroup Grants permission to manipulate files located in the code assemblies to code assemblies that match the membership condition. This class cannot be inherited.
Public class FirstMatchCodeGroup Obsolete. Allows security policy to be defined by the union of the policy statement of a code group and that of the first child code group that matches. This class cannot be inherited.
Public class GacInstalled Confirms that a code assembly originates in the global assembly cache (GAC) as evidence for policy evaluation. This class cannot be inherited.
Public class GacMembershipCondition Determines whether an assembly belongs to a code group by testing its global assembly cache membership. This class cannot be inherited.
Public class Hash Provides evidence about the hash value for an assembly. This class cannot be inherited.
Public class HashMembershipCondition Determines whether an assembly belongs to a code group by testing its hash value. This class cannot be inherited.
Public class NetCodeGroup Grants Web permission to the site from which the assembly was downloaded. This class cannot be inherited.
Public class PermissionRequestEvidence Obsolete. Defines evidence that represents permission requests. This class cannot be inherited.
Public class PolicyException The exception that is thrown when policy forbids code to run.
Public class PolicyLevel Represents the security policy levels for the common language runtime. This class cannot be inherited.
Public class PolicyStatement Represents the statement of a CodeGroup describing the permissions and other information that apply to code with a particular set of evidence. This class cannot be inherited.
Public class Publisher Provides the Authenticode X.509v3 digital signature of a code assembly as evidence for policy evaluation. This class cannot be inherited.
Public class PublisherMembershipCondition Determines whether an assembly belongs to a code group by testing its software publisher's Authenticode X.509v3 certificate. This class cannot be inherited.
Public class Site Provides the Web site from which a code assembly originates as evidence for policy evaluation. This class cannot be inherited.
Public class SiteMembershipCondition Determines whether an assembly belongs to a code group by testing the site from which it originated. This class cannot be inherited.
Public class StrongName Provides the strong name of a code assembly as evidence for policy evaluation. This class cannot be inherited.
Public class StrongNameMembershipCondition Determines whether an assembly belongs to a code group by testing its strong name. This class cannot be inherited.
Public class TrustManagerContext Represents the context for the trust manager to consider when making the decision to run an application, and when setting up the security on a new AppDomain in which to run an application.
Public class UnionCodeGroup Obsolete. Represents a code group whose policy statement is the union of the current code group's policy statement and the policy statement of all its matching child code groups. This class cannot be inherited.
Public class Url Provides the URL from which a code assembly originates as evidence for policy evaluation. This class cannot be inherited.
Public class UrlMembershipCondition Determines whether an assembly belongs to a code group by testing its URL. This class cannot be inherited.
Public class Zone Provides the security zone of a code assembly as evidence for policy evaluation. This class cannot be inherited.
Public class ZoneMembershipCondition Determines whether an assembly belongs to a code group by testing its zone of origin. This class cannot be inherited.

  Interface Description
Public interface IApplicationTrustManager Determines whether an application should be executed and which set of permissions should be granted to it.
Public interface IIdentityPermissionFactory Defines the method that creates a new identity permission.
Public interface IMembershipCondition Defines the test to determine whether a code assembly is a member of a code group.

  Enumeration Description
Public enumeration ApplicationVersionMatch Specifies how to match versions when locating application trusts in a collection.
Public enumeration PolicyStatementAttribute Defines special attribute flags for security policy on code groups.
Public enumeration TrustManagerUIContext Specifies the type of user interface (UI) the trust manager should use for trust decisions.
Was this page helpful?
(1500 characters remaining)
Thank you for your feedback
Show:
© 2014 Microsoft