WCF证书双向认证配置异常:仅单向认证生效问题排查
WCF双向认证配置问题及概念澄清
问题现象
- 为验证是否启用双向认证,将服务器证书从客户端的“受信任的人”存储中删除,通信仍正常,说明当前仅单向认证生效
- 通过Fiddler验证,服务器确实会向客户端传递自身证书
环境与证书配置
- 服务器证书通过IIS绑定到对应地址和端口,未在代码中显式配置;服务器部署在本地机器,客户端运行在虚拟机
- 证书用Keystore Explorer生成:
- CA证书已放入双方的“受信任的根证书颁发机构”
- 服务器侧:服务器证书(.pfx)存于“个人”存储,客户端证书(.cer)存于“受信任的人”存储
- 客户端侧:配置与服务器相反
服务器端代码
string address = "https://192.168.0.30:8003/Service/"; Uri uri = new Uri(address); IService service = new MessageService(); ServiceHost host = new ServiceHost(service, uri); host.Credentials.ClientCertificate.Authentication.CertificateValidationMode = X509CertificateValidationMode.PeerTrust; BasicHttpBinding binding = new BasicHttpBinding(); binding.Security.Mode = BasicHttpSecurityMode.TransportWithMessageCredential; binding.Security.Message.ClientCredentialType = BasicHttpMessageCredentialType.Certificate; binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate; host.AddServiceEndpoint(typeof(IService), binding, address); host.Open();
客户端代码
var address = new EndpointAddress(new Uri("https://192.168.0.30:8003/Service/")); BasicHttpBinding binding = new BasicHttpBinding(); binding.Security.Mode = BasicHttpSecurityMode.TransportWithMessageCredential; binding.Security.Message.ClientCredentialType = BasicHttpMessageCredentialType.Certificate; binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate; var channel = new ChannelFactory<IService>(binding, address); channel.Credentials.ServiceCertificate.Authentication.CertificateValidationMode = X509CertificateValidationMode.PeerTrust; channel.Credentials.ClientCertificate.SetCertificate(StoreLocation.CurrentUser, StoreName.My, X509FindType.FindBySubjectName, "192.168.0.39"); var proxy = channel.CreateChannel();
概念困惑与求助
查阅资料时发现大量矛盾内容:理论上单向/双向认证概念清晰,但实际配置时存在混淆。曾根据微软官方文档认为消息安全模式对应双向认证,传输安全模式对应单向认证,但实际存在用传输安全模式实现双向认证的案例,特此寻求解答。
内容的提问来源于stack exchange,提问作者bogdan.vilimonovic
相关产品推荐
相关产品推荐

