You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 3.1调用WCF服务时SSL/TLS安全通道信任关系建立失败求助

解决无法与授权方建立SSL/TLS安全通道信任关系的问题

问题原因

该错误源于客户端不信任服务端的SSL证书,常见场景包括服务端使用自签名证书、证书过期或未被添加到客户端系统的信任根证书库中。

解决方案

方案1:开发环境临时跳过证书验证(仅用于测试,禁止生产环境使用)

在创建客户端实例后,添加证书验证回调,强制信任所有证书:

Service_MDMSSoapClient sv1 = new Service_MDMSSoapClient(0);
// 添加证书验证回调
System.Net.ServicePointManager.ServerCertificateValidationCallback += 
    (sender, cert, chain, sslPolicyErrors) => true;

ArrayOfXElement a = sv1.GET_READ_IX(tungay, denngay, username, pass);

方案2:将服务端证书导入客户端信任根证书库

  1. 获取服务端SSL证书:通过浏览器访问https://10.137.4.121:8086,导出证书为.cer格式文件。
  2. 导入证书到客户端受信任的根证书颁发机构:
    • 双击证书文件,点击「安装证书」
    • 选择「本地计算机」,点击「下一步」
    • 选择「将所有证书放入下列存储」,点击「浏览」后选择「受信任的根证书颁发机构」
    • 完成导入流程,重启应用程序。

方案3:修改WCF绑定配置,指定信任特定证书

若不想导入到系统根证书库,可在代码中针对性信任目标证书:

  1. 将服务端.cer证书文件添加到项目,设置「复制到输出目录」为「如果较新则复制」。
  2. 修改GetBindingForEndpoint方法,添加证书验证逻辑:
private static System.ServiceModel.Channels.Binding GetBindingForEndpoint(EndpointConfiguration endpointConfiguration)
{
    if ((endpointConfiguration == EndpointConfiguration.Service_MDMSSoap))
    {
        System.ServiceModel.BasicHttpBinding result = new System.ServiceModel.BasicHttpBinding();
        result.MaxBufferSize = int.MaxValue;
        result.ReaderQuotas = System.Xml.XmlDictionaryReaderQuotas.Max;
        result.MaxReceivedMessageSize = int.MaxValue;
        result.AllowCookies = true;
        result.Security.Mode = System.ServiceModel.BasicHttpSecurityMode.Transport;
        
        // 配置证书验证相关参数
        result.Security.Transport.ClientCredentialType = System.ServiceModel.HttpClientCredentialType.None;
        result.Security.Transport.RequireSsl = true;

        return result;
    }

    if ((endpointConfiguration == EndpointConfiguration.Service_MDMSSoap12))
    {
        System.ServiceModel.Channels.CustomBinding result = new System.ServiceModel.Channels.CustomBinding();
        System.ServiceModel.Channels.TextMessageEncodingBindingElement textBindingElement = new System.ServiceModel.Channels.TextMessageEncodingBindingElement();
        textBindingElement.MessageVersion = System.ServiceModel.Channels.MessageVersion.CreateVersion(System.ServiceModel.EnvelopeVersion.Soap12, System.ServiceModel.Channels.AddressingVersion.None);
        result.Elements.Add(textBindingElement);
        System.ServiceModel.Channels.HttpsTransportBindingElement httpsBindingElement = new System.ServiceModel.Channels.HttpsTransportBindingElement();
        httpsBindingElement.AllowCookies = true;
        httpsBindingElement.MaxBufferSize = int.MaxValue;
        httpsBindingElement.MaxReceivedMessageSize = int.MaxValue;
        
        // 针对当前绑定添加证书验证逻辑
        httpsBindingElement.ServerCertificateValidationCallback = 
            (sender, cert, chain, sslPolicyErrors) => 
            {
                // 可通过验证证书指纹、主题等信息精准信任,示例仅验证目标地址
                return cert.Subject.Contains("10.137.4.121") || sslPolicyErrors == System.Net.Security.SslPolicyErrors.None;
            };
        
        result.Elements.Add(httpsBindingElement);
        return result;
    }
    throw new System.InvalidOperationException(string.Format("Could not find endpoint with name '{0}'.", endpointConfiguration));
}

注意事项

  • 生产环境禁止使用方案1,会引入严重安全风险。
  • 优先采用方案2,这是符合安全规范的标准做法。
  • 使用方案3时,建议严格验证证书的指纹或主题信息,避免信任任意未知证书。

内容的提问来源于stack exchange,提问作者jack

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 04:15:40