Asp.Net MVC 4.5发送静默推送更新Apple Wallet Pass失效求助
Apple Wallet静默推送无法更新Pass问题排查与解决
问题描述
项目基于Asp.Net MVC 4.5,发送静默推送(Blank Push Notification)无法更新用户Apple Wallet中的Pass。日志无报错,调试时功能正常,但仅手动强制刷新Pass时才能完成更新。该功能此前正常运行,近期突然失效。
现有推送代码
public void BlankPushNotificationAPNS(string deviceID, string org_key) { int port = 2195; String hostname = "gateway.push.apple.com"; DataObject.Configuration config = ConfigurationRepository.Instance.getCofigurationByOrgKey(org_key); String certificatePath = HttpContext.Current.Server.MapPath("~/Certificates/") + config.wallet_cert_name; //Utility.Logger.LogMsg("Certificate Path : " + certificatePath); byte[] certificateBytes = File.ReadAllBytes(certificatePath); //using (var webClient = new WebClient()) //{ // certificateBytes = webClient.DownloadData(certificatePath); //} //Utility.Logger.LogMsg("Certificate Bytes : " + System.Text.Encoding.UTF8.GetString(certificateBytes)); X509Certificate2 clientCertificate = new X509Certificate2(certificateBytes, config.wallet_cert_password); X509Certificate2Collection certificatesCollection = new X509Certificate2Collection(clientCertificate); //X509Certificate cert = GetAppleServerCert(thumbprint); //Utility.Logger.LogMsg("certificate read"); TcpClient client = new TcpClient(hostname, port); SslStream sslStream = new SslStream(client.GetStream(), false, new RemoteCertificateValidationCallback(ValidateServerCertificate), null); //Utility.Logger.LogMsg("certificate read ssl"); try { //ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls11 | SecurityProtocolType.Ssl3 | SecurityProtocolType.Tls; sslStream.AuthenticateAsClient(hostname, certificatesCollection, SslProtocols.Tls, false); MemoryStream memoryStream = new MemoryStream(); BinaryWriter writer = new BinaryWriter(memoryStream); writer.Write((byte)0); writer.Write((byte)0); writer.Write((byte)32); writer.Write(StringToByteArray(deviceID.ToUpper())); String payload = "{\"aps\":\"\"}"; writer.Write((byte)0); writer.Write((byte)payload.Length); byte[] b1 = System.Text.Encoding.UTF8.GetBytes(payload); writer.Write(b1); writer.Flush(); byte[] array = memoryStream.ToArray(); sslStream.Write(array); sslStream.Flush(); client.Close(); } catch (System.Security.Authentication.AuthenticationException ex) { Utility.Logger.BlankPushLogger("Method:BlankPushNotificationAPNS,AuthenticationException", ex.Message + ", deviceID_" + deviceID + ", org name " + config.org_name_without_spaces); client.Close(); } catch (Exception e) { Utility.Logger.BlankPushLogger("Method:BlankPushNotificationAPNS,Exception", e.Message + ", deviceID_" + deviceID + ", org name " + config.org_name_without_spaces); client.Close(); } }
排查与解决建议
1. 强制启用TLS 1.2+协议
Apple已停止对TLS 1.0/1.1的支持,你的代码中注释了SecurityProtocol设置,Asp.Net 4.5默认不会自动启用TLS 1.2,需显式开启:
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls13;
同时确保服务器操作系统已安装对应TLS版本的支持补丁。
2. 检查证书有效性
- 登录Apple Developer后台确认推送证书是否过期,若过期需重新生成并替换服务器上的证书;
- 确认证书为Pass Type ID对应的推送证书,而非普通APNs证书;
- 检查证书导出格式:必须是包含私钥的.p12格式,且导出密码与代码中
config.wallet_cert_password一致。
3. 修正静默推送Payload格式
部分iOS版本对空字符串格式的aps字段兼容性差,建议改为空对象格式:
String payload = "{\"aps\":{}}";
4. 迁移到HTTP/2版本APNs接口
传统TCP端口(2195)的APNs接口已逐步被HTTP/2接口替代,新接口提供明确的推送结果反馈,便于排查问题。端点为https://api.push.apple.com/3/device/{deviceId},使用证书认证发送POST请求。
5. 检查服务器网络连通性
确认服务器能正常访问Apple的APNs服务端口(2195、443),可通过以下命令测试:
telnet gateway.push.apple.com 2195
若无法连通,需排查防火墙或代理是否拦截了流量。
6. 启用APNs反馈服务
调用APNs反馈服务(feedback.push.apple.com:2196)获取已失效的设备令牌,避免向无效设备推送,同时验证证书是否正常工作。
内容的提问来源于stack exchange,提问作者Sahil_DotNet_Dev
相关产品推荐
相关产品推荐

