You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

海康威视摄像头ONVIF GetProfiles请求授权失败问题咨询

海康威视ONVIF GetProfiles认证失败排查方案

针对你遇到的GetServices请求正常,但相同认证逻辑下GetProfiles请求返回Action requested requires authorization but the sender is not authorized错误的问题,结合海康摄像头的ONVIF实现特性,可从以下几个方向排查:

  • 时间戳有效性校验
    你的两个请求中<Created>字段均为1970年的起始偏移时间,海康部分设备对不同ONVIF接口的时间戳校验严格程度不同:GetServices作为基础设备查询接口校验宽松,但Media服务的GetProfiles接口会拒绝超出合理UTC时间范围的请求。请将<Created>字段改为当前正确的UTC时间(格式示例:2024-05-20T14:30:00.000Z),同时确保设备本地时间与UTC时间同步。

  • 密码摘要生成逻辑核查
    虽使用同一SHA256函数,但需确认密码摘要生成完全符合ONVIF规范:
    正确公式:PasswordDigest = Base64(SHA256(Nonce原始字节 + Created字符串字节 + 密码原始字节))
    需注意:

    • Nonce需用Base64解码后的原始随机字节参与计算
    • Created字符串需与请求中完全一致(包括时区标识Z、毫秒数)
    • 密码需用原始明文的字节参与计算
  • Media服务地址正确性
    GetProfiles属于ONVIF Media服务接口,不能直接使用Device服务的地址发起请求。需先通过GetServices接口获取Media服务的具体Endpoint地址,再向该地址发送GetProfiles请求。

  • 命名空间兼容性
    你使用的Media服务命名空间为http://www.onvif.org/ver20/media/wsdl,部分海康老款设备可能仅支持http://www.onvif.org/ver10/media/wsdl,可尝试修改命名空间后重新测试。


成功的GetServices请求示例

<s:Envelope
    xmlns:s="http://www.w3.org/2003/05/soap-envelope"
    xmlns:a="http://www.w3.org/2005/08/addressing">
    <s:Header>
        <Security s:mustUnderstand="1"
            xmlns="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
            <UsernameToken>
                <Username>admin</Username>
                <Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">ttToXMBbkvcTwrNmFXi98IkJjI+ZcnCgTDvqd52CKtE=</Password>
                <Nonce EncodingType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary">uN08HgV/71BD39TvmdM0cw==</Nonce>
                <Created
                    xmlns="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">1970-01-01T00:46:39.000Z
                </Created>
            </UsernameToken>
        </Security>
    </s:Header>
    <s:Body
        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
        xmlns:xsd="http://www.w3.org/2001/XMLSchema">
        <GetServices
            xmlns="http://www.onvif.org/ver10/device/wsdl">
            <IncludeCapability>true</IncludeCapability>
        </GetServices>
    </s:Body>
</s:Envelope>

失败的GetProfiles请求示例

<s:Envelope
    xmlns:s="http://www.w3.org/2003/05/soap-envelope"
    xmlns:a="http://www.w3.org/2005/08/addressing">
    <s:Header>
        <Security s:mustUnderstand="1"
            xmlns="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
            <UsernameToken>
                <Username>admin</Username>
                <Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CRzaA1hDfuG031Lztc7ZsYEtiGo1O/7wFSlaCf3rBwk=</Password>
                <Nonce EncodingType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary">jwP2WzyxdbXkMX8fD8QDrQ==</Nonce>
                <Created
                    xmlns="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">1970-01-01T00:46:39.021Z
                </Created>
            </UsernameToken>
        </Security>
    </s:Header>
    <s:Body
        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
        xmlns:xsd="http://www.w3.org/2001/XMLSchema">
        <GetProfiles
            xmlns="http://www.onvif.org/ver20/media/wsdl">
            <Type>All</Type>
        </GetProfiles>
    </s:Body>
</s:Envelope>

内容的提问来源于stack exchange,提问作者Sunny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 17:17:02