.NET 6调用.NET Framework WCF服务如何忽略证书验证错误?
解决.NET 6调用WCF自签名证书信任问题
问题根源
.NET Framework里的ServicePointManager.ServerCertificateValidationCallback在.NET 6及后续版本的WCF客户端中不再生效——因为.NET Core/.NET 5+的WCF实现基于HttpClient,不再依赖ServicePointManager的证书验证逻辑。
正确解决方案
1. 安装必要的NuGet包
.NET 6中WCF客户端功能通过NuGet包提供,先确保项目已安装System.ServiceModel.Http包:
Install-Package System.ServiceModel.Http # 或使用.NET CLI命令 dotnet add package System.ServiceModel.Http
2. 配置WCF客户端的证书验证
安装包后,直接通过客户端的ClientCredentials配置证书验证规则,无需手动复制System.IdentityModel.dll:
var binding = new BasicHttpBinding() { SendTimeout = TimeSpan.FromMinutes(10), MaxReceivedMessageSize = Int32.MaxValue, }; binding.Security.Mode = BasicHttpSecurityMode.Transport; using (var client = new SampleService(binding, new EndpointAddress("https://localhost/SampleService/Service.svc"))) { // 仅开发环境使用:关闭证书验证 client.ClientCredentials.ServiceCertificate.SslCertificateAuthentication = new X509ServiceCertificateAuthentication { CertificateValidationMode = X509CertificateValidationMode.None, RevocationMode = X509RevocationMode.NoCheck }; var response = client.GetConfiguration(); }
更安全的替代方案(非开发环境推荐)
忽略证书验证仅适合开发场景,生产/测试环境建议将自签名证书导入本地计算机的受信任根证书颁发机构存储:
- 打开MMC控制台,添加「证书」管理单元
- 定位到「受信任的根证书颁发机构」→「证书」
- 右键导入自签名证书,完成后即可正常建立信任关系,无需修改代码
内容的提问来源于stack exchange,提问作者dafie
相关产品推荐
相关产品推荐

