You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2016无法创建SSL/TLS安全通道问题求助

解决Windows Server 2016上Globalsign API SSL/TLS安全通道创建失败问题

问题场景

开发对接Globalsign文档签署API,本地Windows 10环境签名功能正常,但部署到Windows Server 2016后抛出异常:无法创建SSL/TLS安全通道。

异常堆栈

Exception: mscorlib => An error occurred while sending the request.
--- StackTrace ---
   at System.Runtime.ExceptionServices.ExceptionDispatchInfo.Throw()
   at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)
   at WebAPI.Models.ApiConnect.Login(String aURL, String aKey, String aSecret) in C:\Users\mao\Documents\GitHub\stadium\WebAPI\Models\Program.cs:line 64
   at WebAPI.Models.ApiConnect.GLobalsign(String naam, String club) in C:\Users\mao\Documents\GitHub\stadium\WebAPI\Models\Program.cs:line 399
   at WebAPI.Models.SignaturePad_Document_signed.TrySave(SignaturePad_Document_signed myDocument, Computer myDevice) in C:\Users\mao\Documents\GitHub\stadium\WebAPI\Models\SignaturePad_Documents.cs:line 212
--- InnerException ---
Exception: System => The request was aborted: Could not create SSL/TLS secure channel.
--- StackTrace ---
   at System.Net.HttpWebRequest.EndGetRequestStream(IAsyncResult asyncResult, TransportContext& context)
   at System.Net.Http.HttpClientHandler.GetRequestStreamCallback(IAsyncResult ar)

相关代码

string Json;

var handler = new HttpClientHandler();
handler.ClientCertificateOptions = ClientCertificateOption.Manual;
handler.SslProtocols = SslProtocols.Tls12;
handler.ClientCertificates.Add(new X509Certificate2(GsConfig.SslCertificatePath(), GsConfig.GetKeyPassword()));
using (HttpClient httpClient = new HttpClient(handler))
{
    using (HttpRequestMessage request1 = new HttpRequestMessage(new HttpMethod("POST"), baseURL + "/login"))
    {
        string body = "{\"api_key\": \"api_key\",\"api_secret\": \"api_secret\"}";
        request1.Content = new StringContent(body, Encoding.UTF8, "application/json");

        HttpResponseMessage response1 = httpClient.SendAsync(request1).GetAwaiter().GetResult();
        Json = response1.Content.ReadAsStringAsync().GetAwaiter().GetResult();
    }
}

JObject accessCode = JObject.Parse(Json);

return accessCode;

已尝试操作

  • 使用OpenSSL 1.1.1生成的pfx证书
  • 检查Windows事件日志无相关记录
  • 设置ServicePointManager参数
  • 更换客户端和处理器
  • 调整SslProtocols为None
  • 将证书安装至受信任根证书颁发机构

排查方向与解决方案

1. 补全Windows Server 2016的TLS 1.2支持补丁

Windows Server 2016默认支持TLS 1.2,但缺失累积补丁可能导致握手逻辑异常:

  • 安装KB4019276及后续系统累积更新,确保SSL/TLS组件完整
  • 验证注册表中TLS 1.2的启用状态:
    打开regedit,定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client,确认Enabled值为1、DisabledByDefault值为0

2. 确保应用账户拥有证书私钥权限

运行API的应用池/服务账户需要读取证书私钥的权限:

  1. 打开certlm.msc,找到目标证书,右键选择「所有任务」→「管理私钥」
  2. 添加应用池账户(如IIS AppPool\你的应用池名称),授予「读取」权限
  3. 建议将证书安装到本地计算机-个人存储区,而非当前用户,避免权限隔离问题

3. 验证证书链完整性

  • 检查Windows Server 2016是否信任Globalsign的根证书:下载对应环境的根证书,安装到「本地计算机-受信任根证书颁发机构」
  • 用命令certutil -verify yourcert.pfx验证证书链,确认无断裂、过期或不匹配问题

4. 捕获SSL握手详细错误

修改代码添加证书验证回调,输出具体错误:

handler.ServerCertificateCustomValidationCallback = (sender, cert, chain, sslPolicyErrors) =>
{
    // 将以下信息写入日志文件
    if (sslPolicyErrors != SslPolicyErrors.None)
    {
        string errorLog = $"SSL错误: {sslPolicyErrors}\n证书链状态: {string.Join(",", chain.ChainStatus.Select(s => s.StatusInformation))}";
        File.WriteAllText(@"C:\temp\ssl_error.log", errorLog);
    }
    return sslPolicyErrors == SslPolicyErrors.None;
};

5. 排查防火墙与代理

  • 确认服务器防火墙允许出站HTTPS请求到Globalsign API域名
  • 若服务器使用代理,需在HttpClientHandler中配置:
    handler.Proxy = new WebProxy("http://你的代理地址:端口");
    handler.UseProxy = true;
    

内容的提问来源于stack exchange,提问作者ItsProbablySomethingStupid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 09:45:27