You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WCF基于TLS 1.2通信时配置maxClockSkew引发算法不兼容问题求助

WCF基于TLS 1.2通信时配置maxClockSkew引发算法不兼容问题求助

各位大佬好,我最近在WCF基于TLS 1.2通信的场景下遇到了一个棘手问题,想请大家帮忙分析解决:

  • 客户端机器已经禁用了TLS 1.0和1.1,只启用了TLS 1.2
  • 客户端最初基于.NET 4.5开发,后来我把它升级到了.NET 4.8,服务器本身就是.NET 4.8,但升级后问题依旧存在
  • 客户端代码里已经明确设置了:System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12;

问题详情

当我给WCF配置了带<security>标签的自定义绑定时,通信完全失败,报错信息是:
"The client and server cannot communicate, because they do not possess a common algorithm"

客户端的配置如下:

<customBinding>
  <binding name="wsBinding">
    <transactionFlow />
    <security authenticationMode="SecureConversation" messageSecurityVersion="WSSecurity11WSTrustFebruary2005WSSecureConversationFebruary2005WSSecurityPolicy11BasicSecurityProfile10">
      <localClientSettings maxClockSkew="00:30:00" />
      <localServiceSettings maxClockSkew="00:30:00" />
      <secureConversationBootstrap authenticationMode="UserNameForSslNegotiated" messageSecurityVersion="WSSecurity11WSTrustFebruary2005WSSecureConversationFebruary2005WSSecurityPolicy11BasicSecurityProfile10">
        <localClientSettings maxClockSkew="00:30:00" />
        <localServiceSettings maxClockSkew="00:30:00" />
      </secureConversationBootstrap>
    </security>
    <textMessageEncoding>
      <readerQuotas maxDepth="32" maxStringContentLength="104857600" maxArrayLength="104857600" maxBytesPerRead="4096" maxNameTableCharCount="16384" />
    </textMessageEncoding>
    <httpsTransport maxBufferPoolSize="104857600" maxBufferSize="104857600" maxReceivedMessageSize="104857600" />
  </binding>
</customBinding>

但如果我把服务器端的<security>标签移除,同时更新客户端的配置(去掉security相关节点),通信就能正常工作,客户端配置如下:

<customBinding>
  <binding name="wsBinding" openTimeout="00:05:00" closeTimeout="00:05:00" sendTimeout="00:05:00" receiveTimeout="00:05:00">
    <transactionFlow />
    <textMessageEncoding>
      <readerQuotas maxDepth="32" maxStringContentLength="104857600" maxArrayLength="104857600" maxBytesPerRead="4096" maxNameTableCharCount="16384" />
    </textMessageEncoding>
    <httpsTransport maxBufferPoolSize="104857600" maxBufferSize="104857600" maxReceivedMessageSize="104857600" />
  </binding>
</customBinding>

可问题在于,我们的场景必须要使用maxClockSkew来处理客户端和服务器之间的时钟偏差,不能去掉安全配置。现在看起来只要一加<security>标签,WCF就会强制使用TLS 1.0,导致和客户端的TLS 1.2不兼容。

有没有大佬知道这背后的原因是什么?有没有办法既能配置maxClockSkew,又能让WCF使用TLS 1.2通信呢?

备注:内容来源于stack exchange,提问作者Frederico Almeida

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 13:52:42