You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 7 Docker Compose调用HTTPS API遇SSL证书错误

问题描述

我有一个已Docker化的.NET Core 7解决方案,Docker Compose文件如下:

version: '3.4'

services:
  sqldb:
    image: mcr.microsoft.com/azure-sql-edge
    ports:
      - "1433:1433"
    environment:
      - SA_PASSWORD=PASSWORD
      - ACCEPT_EULA=Y

  product-api:
    image: ${DOCKER_REGISTRY-}productapi
    build:
      context: .
      dockerfile: src/productapi/WebApi/Dockerfile
    depends_on:
      - "sqldb"

  live-api:
    image: ${DOCKER_REGISTRY-}live
    build:
      context: .
      dockerfile: src/LiveAPI/Web/Dockerfile
    depends_on:
      - "sqldb"
      - "product-api"

对应的compose override文件如下:

version: '3.4'

services:    
  product-api:
    environment:
      - ASPNETCORE_ENVIRONMENT=Development
      - ASPNETCORE_URLS=https://+:443;http://+:80
    ports:
      - "5200:443"
      - "5201:80"
    volumes:
      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro
      - ${APPDATA}/ASP.NET/Https:/root/.aspnet/https:ro

  live-api:
    environment:
      - ASPNETCORE_ENVIRONMENT=Development
      - ASPNETCORE_URLS=https://+:443;http://+:80
    ports:
      - "5300:443"
    volumes:
      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro
      - ${APPDATA}/ASP.NET/Https:/root/.aspnet/https:ro

当从live-api服务调用product-api中的REST API时,出现以下异常:

The SSL connection could not be established, see inner exception.
-> The remote certificate is invalid according to the validation procedure: RemoteCertificateNameMismatch, RemoteCertificateChainErrors

我尝试了多种方案但均未解决问题,已尝试的操作包括:在live-api中禁用SSL验证(代码如下),以及使用https://product-api:443、https://product-api、https://host.docker.internal:5200这几种地址调用API。

ServicePointManager.ServerCertificateValidationCallback += (sender, certificate, chain, errors) =>
{
    // local dev, just approve all certs
    if (development) return true;
    return errors == SslPolicyErrors.None;
};
解决方法

1. 修正证书验证回调的适用范围

ServicePointManager.ServerCertificateValidationCallback仅对基于HttpWebRequest的请求生效,如果你用的是HttpClient,需要单独配置证书验证逻辑:

var handler = new HttpClientHandler();
handler.ServerCertificateCustomValidationCallback = (sender, cert, chain, sslPolicyErrors) =>
{
    if (development) return true;
    return sslPolicyErrors == SslPolicyErrors.None;
};
var httpClient = new HttpClient(handler);

2. 生成匹配容器域名的开发证书

默认ASP.NET Core开发证书仅绑定localhost,用容器名称product-api访问时会出现域名不匹配问题。可以生成包含product-api作为备用名称的证书:

  • 打开命令行执行以下命令生成证书:
dotnet dev-certs https -ep $env:APPDATA\ASP.NET\Https\productapi.pfx -p 自定义证书密码
dotnet dev-certs https --trust
  • 在compose.override.yml的product-api服务中添加环境变量指定证书路径和密码:
environment:
  - ASPNETCORE_Kestrel__Certificates__Default__Path=/root/.aspnet/https/productapi.pfx
  - ASPNETCORE_Kestrel__Certificates__Default__Password=自定义证书密码

3. 开发环境直接用HTTP访问

本地开发场景下,可直接调用product-api的80端口(HTTP协议),将调用地址改为http://product-api:80,彻底规避SSL证书验证问题。

4. 将开发证书导入容器信任存储

如果坚持使用HTTPS,可把本地开发证书导入live-api容器的信任根:

  • 导出本地HTTPS开发证书为CER格式:
dotnet dev-certs https --export-path $env:APPDATA\ASP.NET\Https\aspnetcore.cer --format PEM
  • 在compose.override.yml的live-api服务中添加卷挂载和启动命令:
volumes:
  - ${APPDATA}/ASP.NET/Https/aspnetcore.cer:/usr/local/share/ca-certificates/aspnetcore.cer
command: sh -c "update-ca-certificates && dotnet LiveAPI.dll"

内容的提问来源于stack exchange,提问作者Imran Sh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 10:17:22