You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux容器中ASP.NET Core 8调用SSRS GetItemParametersAsync遇SSL/TLS信任错误

问题:Linux容器中ASP.NET Core 8调用SSRS SOAP接口的SSL信任错误

在Linux容器中运行ASP.NET Core 8 Web API时,调用SSRS的GetItemParametersAsync方法抛出错误:
One or more errors occurred (Could not establish trust relationship for the SSL/TLS secure channel with authority)
本地运行正常,容器环境报错,且已确认凭据和SSL证书有效。

触发错误的SOAP调用代码

var binding = new BasicHttpBinding(BasicHttpSecurityMode.Transport);
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Ntlm;
rsReporting = new ReportingService2010SoapClient(binding, new EndpointAddress(SSRSServerUrl));
var clientCredentials = new NetworkCredential(User, Password, Domain);
rsReporting.ClientCredentials.Windows.AllowedImpersonationLevel = System.Security.Principal.TokenImpersonationLevel.Impersonation;
rsReporting.ClientCredentials.Windows.ClientCredential = clientCredentials;
rsReporting.Endpoint.Address = new EndpointAddress(SSRSReport2010);
var parameters = rsReporting.GetItemParametersAsync(trustedUserHeader, reportPath, historyId, forRendering, values, credentials);
foreach (ItemParameter param in parameters.Result.Parameters)
{
   ReportParams.Add(param.Name, param.DefaultValues[0]);
}

可正常运行的REST API调用代码

string requestUrl = $"reports/api/v2.0/CatalogItems";
HttpResponseMessage response = await client.GetAsync(requestUrl);
string responseContent = await response.Content.ReadAsStringAsync();

问题原因分析

两种调用方式的SSL证书信任机制存在差异:

  • REST API使用的HttpClient默认继承容器系统的证书信任配置,若容器已信任SSRS证书或HttpClient被配置过忽略验证,就能正常访问。
  • SOAP客户端基于WCF框架,在Linux环境下的证书信任逻辑和Windows本地不一致,默认不会自动信任系统存储外的证书,而Linux容器的默认信任根证书列表里没有SSRS的证书,导致SSL握手失败。

解决方案

1. 将SSRS证书导入容器信任存储(生产环境推荐)

这是最安全的方式,让容器系统信任SSRS的SSL证书:

  • 先导出SSRS服务器的证书:执行openssl s_client -connect <ssrs-server-domain>:443 </dev/null | openssl x509 -outform PEM > ssrs-cert.crt生成证书文件。
  • 在Dockerfile中添加以下步骤,将证书导入容器信任目录(以Debian/Ubuntu为例):
COPY ./ssrs-cert.crt /usr/local/share/ca-certificates/ssrs-cert.crt
RUN update-ca-certificates

2. 临时绕过证书验证(仅测试环境使用)

如果是测试环境,可临时关闭SOAP客户端的证书验证(生产环境禁止,存在安全风险):
在初始化SOAP客户端前添加以下代码:

// 全局禁用证书验证,仅测试用
System.Net.ServicePointManager.ServerCertificateValidationCallback += (sender, cert, chain, sslPolicyErrors) => true;

3. 为SOAP客户端配置自定义证书验证

通过自定义验证逻辑,只信任指定的SSRS证书:

var binding = new BasicHttpBinding(BasicHttpSecurityMode.Transport);
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Ntlm;
var endpoint = new EndpointAddress(SSRSServerUrl);
rsReporting = new ReportingService2010SoapClient(binding, endpoint);

// 配置自定义证书验证
rsReporting.ClientCredentials.ServiceCertificate.Authentication.CertificateValidationMode = 
    System.ServiceModel.Security.X509CertificateValidationMode.Custom;
rsReporting.ClientCredentials.ServiceCertificate.Authentication.CustomCertificateValidator = 
    new SSRSCertificateValidator();

// 原有凭据配置代码
var clientCredentials = new NetworkCredential(User, Password, Domain);
rsReporting.ClientCredentials.Windows.AllowedImpersonationLevel = System.Security.Principal.TokenImpersonationLevel.Impersonation;
rsReporting.ClientCredentials.Windows.ClientCredential = clientCredentials;
rsReporting.Endpoint.Address = new EndpointAddress(SSRSReport2010);

// 调用接口
var parameters = await rsReporting.GetItemParametersAsync(trustedUserHeader, reportPath, historyId, forRendering, values, credentials);
foreach (ItemParameter param in parameters.Parameters)
{
   ReportParams.Add(param.Name, param.DefaultValues[0]);
}

实现自定义验证器:

public class SSRSCertificateValidator : System.IdentityModel.Selectors.X509CertificateValidator
{
    // 替换为你的SSRS证书指纹
    private const string TrustedThumbprint = "ABC123DEF456GHI789JKL012MNO345PQR678STU901";

    public override void Validate(X509Certificate2 certificate)
    {
        if (certificate.Thumbprint != TrustedThumbprint)
        {
            throw new System.IdentityModel.Tokens.SecurityTokenValidationException("未信任的SSRS证书");
        }
    }
}

4. 配置容器环境变量指定证书文件

ASP.NET Core在Linux下会读取SSL_CERT_FILE环境变量指向的证书文件,可将SSRS证书合并到系统证书文件后设置该变量:

ENV SSL_CERT_FILE=/app/combined-certs.pem

内容的提问来源于stack exchange,提问作者Shankar Naru

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 11:11:18