You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 6调用AWS GetObjectAsync遇RemoteCertificateNameMismatch错误求助

Solutions for RemoteCertificateNameMismatch Error in S3 GetObjectAsync

1. Configure S3 Client to Bypass Certificate Validation Directly

The AWS SDK for .NET uses its own HTTP client setup, so global settings like ServicePointManager or generic HttpClient handlers won't apply. Instead, set the validation callback directly in the AmazonS3Config:

var s3Config = new AmazonS3Config
{
    // Bypass cert validation (only for testing, NOT production)
    ServerCertificateCustomValidationCallback = (sender, certificate, chain, sslPolicyErrors) => true,
    RegionEndpoint = RegionEndpoint.YourRegion // Replace with your bucket's actual region
};

using var s3Client = new AmazonS3Client(s3Config);
var response = await s3Client.GetObjectAsync("your-bucket-name", "your-file-key");

2. Enable Path-Style Access for Buckets with Dots in the Name

Bucket names containing dots often trigger certificate mismatches because virtual-hosted style URLs (e.g., bucket.name.s3.amazonaws.com) don't match the wildcard SSL certificate for *.s3.amazonaws.com. Enabling path-style access uses URLs like s3.amazonaws.com/bucket.name, which works with the default certificate:

var s3Config = new AmazonS3Config
{
    ForcePathStyle = true,
    RegionEndpoint = RegionEndpoint.YourRegion
};

using var s3Client = new AmazonS3Client(s3Config);

3. Verify and Use the Correct Region Endpoint

A mismatched region leads to connecting to the wrong S3 endpoint, causing a certificate name mismatch. Always explicitly set the RegionEndpoint to match your bucket's actual region:

// Example for us-west-2 region
var s3Config = new AmazonS3Config
{
    RegionEndpoint = RegionEndpoint.USWest2
};

4. For Custom S3-Compatible Services (e.g., MinIO)

If using a self-hosted or third-party S3 service:

  • Ensure the ServiceURL in AmazonS3Config points to your service's correct endpoint.
  • If using a self-signed certificate, either import it into your system's trusted root store, or use the validation callback to accept it (testing only).
var s3Config = new AmazonS3Config
{
    ServiceURL = "https://your-custom-s3-endpoint.com",
    ServerCertificateCustomValidationCallback = (sender, cert, chain, errors) => true, // Test only
    ForcePathStyle = true // Often required for custom services
};

Important Note

Bypassing certificate validation should only be used in testing environments. For production, resolve the root cause:

  • Use bucket names without dots (or enable path-style access if needed).
  • Ensure your S3 client uses the correct region endpoint.
  • For custom services, use a valid SSL certificate signed by a trusted CA.

内容的提问来源于stack exchange,提问作者TheProgrammer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 01:50:19