You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AppService强制TLS 1.2出站请求问题求助

Azure AppService强制启用TLS 1.2出站协议的解决方案

1. 配置Web.Config实现全局TLS指定

无需修改代码,通过配置文件直接生效,适合仅拥有门户权限的场景:

  • 在<appSettings>节点添加:
    <add key="System.Net.ServicePointManager.SecurityProtocol" value="Tls12" />
    
  • 确保<system.web>下的<httpRuntime>配置正确匹配目标框架:
    <httpRuntime targetFramework="4.7.2" />
    
  • 添加或修改<system.net>节点:
    <system.net>
      <settings>
        <servicePointManager securityProtocol="Tls12" />
      </settings>
    </system.net>
    

你可以通过Azure门户的「配置」→「应用程序设置」添加上述appSettings,或者通过「高级工具」→「Kudu」→「Debug console」→「site/wwwroot」找到Web.Config直接编辑。

2. 修正代码中的TLS设置(避免失效)

如果保留代码中的TLS配置,需确保设置在请求发起前执行,且避免被覆盖:
将原有代码替换为直接指定TLS 1.2:

System.Net.ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;

建议放在Global.asax的Application_Start方法中,保证全局生效。

3. 通过Azure门户调整服务端TLS配置

  • 进入AppService资源的「TLS/SSL设置」→「协议设置」
  • 将「最小TLS版本」设为1.2,同时确认「出站TLS版本」配置为1.2(部分环境通过最小版本控制出站规则)
  • 保存设置后重启AppService,确保配置生效

额外检查项

  • 确认AppService的运行时版本:在「配置」→「常规设置」中,确保.NET Framework版本选择v4.7及以上,与Web.Config的targetFramework匹配
  • 清除应用缓存:通过Kudu删除临时文件或直接重启AppService,避免旧配置缓存影响

内容的提问来源于stack exchange,提问作者Alejandro Robles

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 12:05:16