ASP.NET中WCF服务HTTPS调用超时及绑定异常问题求助
问题描述
在ASP.NET Web Forms应用中调用HTTPS配置的WCF服务时,基础配置完成后无法正常运行。仅在SoapUI中设置WSS TimeToLive大于1000时可成功调用服务,但在应用中收到如下错误:
An error occurred while making the HTTP request to https://webservice.address. This could be due to the fact that the server certificate is not configured properly with HTTP.SYS in the HTTPS case. This could also be caused by a mismatch of the security binding between the client and the server.
已按服务提供方规范设置安全模式为Transport并启用用户名密码验证,SoapUI中配置了相同的用户名密码并设置了WSS TimeToLive。尝试过将WCF客户端的Close、Open、Receive、Send超时都设为10分钟,也试过改用wsHttpBinding并添加<reliableSession inactivityTimeout="00:10:00"/>配置,但问题仍未解决。
当前绑定代码如下:
var binding = new BasicHttpsBinding() { Security = new BasicHttpsSecurity() { Mode = BasicHttpsSecurityMode.Transport, Transport = new HttpTransportSecurity { ClientCredentialType = HttpClientCredentialType.None }, Message = new BasicHttpMessageSecurity { ClientCredentialType = BasicHttpMessageCredentialType.UserName, }, }, CloseTimeout = new TimeSpan(0, 10, 0), OpenTimeout = new TimeSpan(0, 10, 0), ReceiveTimeout = new TimeSpan(0, 10, 0), SendTimeout = new TimeSpan(0, 10, 0) }; var client = new SISF_to_SIAPortTypeClient(binding, new EndpointAddress("webservice.address")); client.ClientCredentials.UserName.UserName = ConfigurationManager.AppSettings["WebServiceUsername"]; client.ClientCredentials.UserName.Password = ConfigurationManager.AppSettings["WebServicePassword"]; return client;
解决建议
- 修正安全模式配置冲突:当前设置
BasicHttpsSecurityMode.Transport的同时配置了Message级别的用户名密码验证,这会导致绑定逻辑冲突。如果服务要求的是WSS(消息级别)的用户名密码验证,需将安全模式改为TransportWithMessageCredential,实现HTTPS传输+消息级身份验证的组合,同时显式配置WSS生命周期:Security = new BasicHttpsSecurity() { Mode = BasicHttpsSecurityMode.TransportWithMessageCredential, Transport = new HttpTransportSecurity { ClientCredentialType = HttpClientCredentialType.None }, Message = new BasicHttpMessageSecurity { ClientCredentialType = BasicHttpMessageCredentialType.UserName, UsernameOverTransport = new UsernamePasswordOverTransportSecurity { // 对应SoapUI的WSS TimeToLive,设置消息有效时长为10分钟 Lifetime = new Lifetime(new TimeSpan(0, 10, 0)) } }, } - 处理证书信任问题:错误提示提到证书配置问题,需确保客户端机器信任服务端的HTTPS证书。可将服务端证书导入客户端受信任根证书存储,测试环境下也可临时添加证书验证回调(生产环境不建议):
ServicePointManager.ServerCertificateValidationCallback += (sender, cert, chain, sslPolicyErrors) => true; - 启用WCF跟踪日志:开启客户端跟踪日志获取详细错误信息,定位绑定或通信问题。在web.config中添加配置:
<system.diagnostics> <sources> <source name="System.ServiceModel" switchValue="Information, ActivityTracing" propagateActivity="true"> <listeners> <add name="traceListener" type="System.Diagnostics.XmlWriterTraceListener" initializeData="c:\logs\WcfTrace.svclog" /> </listeners> </source> </sources> </system.diagnostics> - 匹配服务端绑定类型:确认服务端实际使用的绑定类型,如果服务端用wsHttpBinding,客户端需同步使用该绑定,并对应配置安全模式与消息生命周期,而非BasicHttpsBinding。
内容的提问来源于stack exchange,提问作者JustT4ser
相关产品推荐
相关产品推荐

