You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在FluentFTP中选择指定SSL证书及证书链位置?

在FluentFTP中指定证书链有效证书位置的解决方案

你的问题出在服务器返回的证书链里包含过期证书(位置0),但同时存在有效证书(位置1),FluentFTP默认会验证整个证书链导致连接失败。要实现类似FileZilla手动选择证书链中特定位置证书的效果,需要自定义证书验证逻辑,而非全盘接受所有证书(原代码里的AcceptAllCertifications属于不安全操作)。

修改后的VB代码示例

ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 Or SecurityProtocolType.Tls11 Or SecurityProtocolType.Tls
Using conn = New FtpClient("secure11.host", "user", "pwd")
    conn.EnableSsl = True
    conn.SslProtocols = SecurityProtocolType.Tls12 Or SecurityProtocolType.Tls11 Or SecurityProtocolType.Tls
    ' 绑定FluentFTP自带的证书验证事件,替代全局回调
    AddHandler conn.ValidateCertificate, AddressOf ValidateSpecificCertificateInChain
    conn.AutoConnect()
    ' do something
End Using

' 自定义证书验证方法
Private Sub ValidateSpecificCertificateInChain(sender As Object, e As FtpSslValidationEventArgs)
    ' 如果证书链本身无错误,直接接受
    If e.PolicyErrors = SslPolicyErrors.None Then
        e.Accept = True
        Return
    End If

    ' 检查证书链是否包含至少2个证书(确保位置1存在)
    If e.CertificateChain IsNot Nothing AndAlso e.CertificateChain.ChainElements.Count > 1 Then
        ' 获取证书链中位置1的证书
        Dim targetCert = e.CertificateChain.ChainElements(1).Certificate
        ' 验证该证书是否未过期
        Dim currentTime = DateTime.Now
        If targetCert.NotBefore <= currentTime AndAlso currentTime <= targetCert.NotAfter Then
            ' 可根据需求添加更多验证逻辑,比如检查颁发者、域名匹配等
            e.Accept = True
            Return
        End If
    End If

    ' 所有验证不通过则拒绝连接
    e.Accept = False
End Sub

关键说明

  • 优先使用FluentFTP自带的ValidateCertificate事件,而非全局的ServicePointManager.ServerCertificateValidationCallback,安全性和针对性更强
  • 通过e.CertificateChain.ChainElements索引直接访问证书链中的目标证书(这里是索引1)
  • 必须对目标证书做有效性校验(比如过期时间),避免盲目信任未知证书
  • 指定多版本TLS协议,提升与服务器的兼容性

内容的提问来源于stack exchange,提问作者ilens

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 06:20:05