You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WCF证书双向认证配置异常:仅单向认证生效问题排查

WCF双向认证配置问题及概念澄清

问题现象

  • 为验证是否启用双向认证,将服务器证书从客户端的“受信任的人”存储中删除,通信仍正常,说明当前仅单向认证生效
  • 通过Fiddler验证,服务器确实会向客户端传递自身证书

环境与证书配置

  • 服务器证书通过IIS绑定到对应地址和端口,未在代码中显式配置;服务器部署在本地机器,客户端运行在虚拟机
  • 证书用Keystore Explorer生成:
    • CA证书已放入双方的“受信任的根证书颁发机构”
    • 服务器侧:服务器证书(.pfx)存于“个人”存储,客户端证书(.cer)存于“受信任的人”存储
    • 客户端侧:配置与服务器相反

服务器端代码

string address = "https://192.168.0.30:8003/Service/";
Uri uri = new Uri(address);
IService service = new MessageService();

ServiceHost host = new ServiceHost(service, uri);
host.Credentials.ClientCertificate.Authentication.CertificateValidationMode = X509CertificateValidationMode.PeerTrust;

BasicHttpBinding binding = new BasicHttpBinding();

binding.Security.Mode = BasicHttpSecurityMode.TransportWithMessageCredential;
binding.Security.Message.ClientCredentialType = BasicHttpMessageCredentialType.Certificate;
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate;

host.AddServiceEndpoint(typeof(IService), binding, address);
host.Open();

客户端代码

var address = new EndpointAddress(new Uri("https://192.168.0.30:8003/Service/"));

BasicHttpBinding binding = new BasicHttpBinding();
binding.Security.Mode = BasicHttpSecurityMode.TransportWithMessageCredential;
binding.Security.Message.ClientCredentialType = BasicHttpMessageCredentialType.Certificate;
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate;

var channel = new ChannelFactory<IService>(binding, address);

channel.Credentials.ServiceCertificate.Authentication.CertificateValidationMode = X509CertificateValidationMode.PeerTrust;

channel.Credentials.ClientCertificate.SetCertificate(StoreLocation.CurrentUser,
                                                     StoreName.My,
                                                     X509FindType.FindBySubjectName,
                                                     "192.168.0.39");
var proxy = channel.CreateChannel();

概念困惑与求助

查阅资料时发现大量矛盾内容:理论上单向/双向认证概念清晰,但实际配置时存在混淆。曾根据微软官方文档认为消息安全模式对应双向认证,传输安全模式对应单向认证,但实际存在用传输安全模式实现双向认证的案例,特此寻求解答。


内容的提问来源于stack exchange,提问作者bogdan.vilimonovic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 04:32:10