You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加URL Rewrite配置后IIS Express在Chrome中出现SSL协议错误求助

解决Chrome环境下IIS Express的ERR_SSL_PROTOCOL_ERROR异常

问题背景

合并基于VS2013、.NET 4.5.2的MVC Web应用时,添加了以下URL Rewrite配置:

<system.webServer>
  <caching enabled ="false" />
  <rewrite>
    <rules>
      <rule name="HTTP to HTTPS Redirect" stopProcessing="true">
        <match url="(.*)" />
        <conditions>
          <add input="{HTTPS}" pattern="^OFF$" />
        </conditions>
        <action type="Redirect" url="https://{HTTP_HOST}{REQUEST_URI}" appendQueryString="false" />
      </rule>
    </rules>
  </rewrite>
  <modules>

运行IIS Express后触发ERR_SSL_PROTOCOL_ERROR错误。尝试注释配置、更换应用、安装URL Rewrite 2.1、重启机器均无效,但切换到IIS可正常运行。添加<validation validateIntegratedModeConfiguration="false" />等配置后Firefox恢复正常,但Chrome仍存在异常。

解决方案

1. 清除Chrome的站点缓存与SSL数据

  • 打开Chrome,输入chrome://settings/siteData,搜索应用的本地域名(如localhost),删除对应条目
  • 进入chrome://settings/clearBrowserData,选择「所有时间」,勾选「缓存的图片和文件」「Cookie和其他网站数据」,执行清除操作
  • 完全关闭Chrome后重新启动,再运行IIS Express访问应用

2. 验证并重置IIS Express的SSL证书

  • 找到项目根目录下的隐藏文件夹.vs\config\applicationhost.config,查找对应站点的<bindings>节点,确认HTTPS绑定的配置:
    <binding protocol="https" bindingInformation="*:44300:localhost" sslFlags="0" />
    
  • 若证书异常,以管理员身份打开命令提示符,执行以下命令重新生成自签名证书(替换端口为你的应用HTTPS端口):
    "%ProgramFiles(x86)%\IIS Express\IisExpressAdminCmd.exe" setupSslUrl -url:https://localhost:44300/ -UseSelfSigned
    
  • 重启VS和IIS Express后测试

3. 调整Web.config的HTTPS重写规则适配IIS Express

IIS Express的{HTTPS}变量判断逻辑与IIS存在差异,改用{SERVER_PORT_SECURE}变量更可靠:

<system.webServer>
  <validation validateIntegratedModeConfiguration="false" />
  <caching enabled ="false" />
  <rewrite>
    <rules>
      <rule name="HTTP to HTTPS Redirect" stopProcessing="true">
        <match url="(.*)" />
        <conditions>
          <add input="{SERVER_PORT_SECURE}" pattern="^0$" />
        </conditions>
        <action type="Redirect" url="https://{HTTP_HOST}{REQUEST_URI}" appendQueryString="false" redirectType="Permanent" />
      </rule>
    </rules>
  </rewrite>
</system.webServer>

该规则通过判断SERVER_PORT_SECURE是否为0(HTTP状态)来触发重定向,适配IIS Express的环境变量逻辑。

4. 临时绕过Chrome的SSL验证(不建议长期使用)

  • 关闭所有Chrome窗口,右键快捷方式选择「属性」
  • 在「目标」栏末尾添加参数: --ignore-certificate-errors
  • 启动Chrome后访问应用,验证是否解决问题(仅用于排查,生产环境禁用)

内容的提问来源于stack exchange,提问作者Eric Brown - Cal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 10:25:12