You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

更新客户端证书后WCF服务出现身份验证错误求助

问题:更换商业CA颁发的客户端证书后WCF服务通信中断

更换商业CA颁发的客户端证书后,某WCF服务通信中断,服务器跟踪到如下错误:

System.IdentityModel.Tokens.SecurityTokenValidationException: X.509证书CN=aaa.ccc.ff, O=XXXXX, L=Brbr, C=XX的链构建失败。所使用的证书的信任链无法验证。请更换证书或修改certificateValidationMode。证书链处理正常,但其中一个CA证书不被策略提供程序信任。

但该证书在另一同配置的外部服务中可正常工作。

服务端配置

<system.serviceModel>
    <extensions>
      <behaviorExtensions>
        <add name="A2AValidation" type="xxxyyyzzz.A2AValidation+CustomBehaviorSection, xxxyyyzzz A2A, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />      
      </behaviorExtensions>
    </extensions>
    <protocolMapping>
      <add scheme="http" binding="wsHttpBinding" />
    </protocolMapping>
    <bindings>
      <wsHttpBinding>
        <binding name="WcfServiceBinding">
          <security mode="Message">
            <message clientCredentialType="Certificate" negotiateServiceCredential="true" establishSecurityContext="true" />
          </security>
        </binding>
      </wsHttpBinding>
    </bindings>
    <services>
      <service behaviorConfiguration="ClientSecBehavior" name="xxxyyyzzz.Service">
        <endpoint address="" behaviorConfiguration="A2AValidationBehavior" binding="wsHttpBinding" bindingConfiguration="WcfServiceBinding" name="A2AmessageEndpoint" contract="xxxyyyzzz.IService" />
        <endpoint address="mex" binding="mexHttpsBinding" name="A2AMessageEndpointMex" contract="IMetadataExchange" />
    <host>
       <baseAddresses>
          <add baseAddress="http://xxxyyyzzz:10002/XX/A2A/Service.svc" />
       </baseAddresses>
    </host>
      </service>
    </services>
    <behaviors>
      <endpointBehaviors>
        <behavior name="A2AValidationBehavior">
          <A2AValidation />
        </behavior>
      </endpointBehaviors>
      <serviceBehaviors>
        <behavior name="ClientSecBehavior">
          <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true" />
          <serviceDebug includeExceptionDetailInFaults="true" />
          <serviceCredentials>
            <clientCertificate>
              <authentication certificateValidationMode="PeerOrChainTrust" trustedStoreLocation="LocalMachine" revocationMode="NoCheck" mapClientCertificateToWindowsAccount="true" /> 
            </clientCertificate>
        <serviceCertificate findValue="______" storeLocation="LocalMachine" storeName="My" x509FindType="FindByThumbprint" />
          </serviceCredentials>
        </behavior>       
      </serviceBehaviors>
    </behaviors>
    <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" />
    <diagnostics wmiProviderEnabled="true">
      <messageLogging logEntireMessage="true" logKnownPii="false" logMalformedMessages="true" logMessagesAtServiceLevel="true" logMessagesAtTransportLevel="true" maxMessagesToLog="500" />
      <endToEndTracing messageFlowTracing="true" />
    </diagnostics>
  </system.serviceModel>

客户端配置(包含另一可正常工作的外部服务配置)

<system.serviceModel>
    <diagnostics>
      <messageLogging
                     logEntireMessage="true"
                     logMalformedMessages="true"
                     logMessagesAtServiceLevel="true"
                     logMessagesAtTransportLevel="true"
                     maxMessagesToLog="3000"
                     maxSizeOfMessageToLog="2000"/>
    </diagnostics>
    <bindings>
      <wsHttpBinding>
        <binding name="YYYY_A2AMessageEndpoint_BindingConfig" maxReceivedMessageSize="2147483647">
          <security>
            <message clientCredentialType="Certificate" />
          </security>
        </binding>
        <binding name="XXXYYYZZZ_A2AMessageEndpoint_BindingConfig">
          <security>
            <message clientCredentialType="Certificate" />
          </security>
        </binding>
      </wsHttpBinding>
    </bindings>
    <behaviors>
      <endpointBehaviors>
        <behavior name="YYYY_A2AMessageEndpoint_BehaviorConfig">
          <clientCredentials>
            <serviceCertificate>
              <authentication
                certificateValidationMode="PeerOrChainTrust"
                revocationMode="NoCheck"
                trustedStoreLocation="LocalMachine" />
            </serviceCertificate>
            <clientCertificate findValue="__________" x509FindType="FindByThumbprint"  storeLocation="LocalMachine" storeName="My" />
          </clientCredentials>
        </behavior>
        <behavior name="XXXYYYZZZ_A2AMessageEndpoint_BehaviorConfig">
          <clientCredentials>
            <serviceCertificate>
              <authentication
                certificateValidationMode="PeerOrChainTrust"
                revocationMode="NoCheck"
                trustedStoreLocation="LocalMachine" />
            </serviceCertificate>
            <clientCertificate findValue="__________" x509FindType="FindByThumbprint"  storeLocation="LocalMachine" storeName="My" />
          </clientCredentials>
        </behavior>
      </endpointBehaviors>
    </behaviors>
    <client>
      <endpoint
                name="YYYY_A2AMessageEndpoint"
                contract="A2AMessageService.IService"
                address="http://YYYY:10002/a2a/Service.svc"
                binding="wsHttpBinding" bindingConfiguration="YYYY_A2AMessageEndpoint_BindingConfig"
                behaviorConfiguration="YYYY_A2AMessageEndpoint_BehaviorConfig" >
        <identity>
          <certificate encodedValue="xyz=" />
        </identity>
      </endpoint>
      <endpoint
                name="XXXYYYZZZ_A2AMessageEndpoint"
                contract="A2APTAMessageService.IService"
                address="http://XXXYYYZZZ:10002/PTA/A2A/Service.svc"
                binding="wsHttpBinding" bindingConfiguration="XXXYYYZZZ_A2AMessageEndpoint_BindingConfig"
                behaviorConfiguration="XXXYYYZZZ_A2AMessageEndpoint_BehaviorConfig" >
        <identity>
          <certificate encodedValue="xyz=" />
        </identity>
      </endpoint>
    </client>
  </system.serviceModel>

证书相关信息

  • 证书已在IIS证书映射和AD证书映射中正确注册,客户端证书的完整证书链在IIS和AD中显示正常。
  • 客户端证书用途:
    • 向远程计算机证明身份
    • 验证远程计算机身份
    • 包含OID:2.23.140.1.2.2

补充情况

由于该证书在另一服务中可正常使用,暂不认为证书用途是问题所在。将另一服务迁移到新服务器后,该问题也出现在新服务器上。

疑问

该证书的高级密钥用法中除“客户端身份验证”外还包含“服务器身份验证”,是否会影响AD安全提供商验证证书有效性?服务器的NTAuth存储中无相关证书。

内容的提问来源于stack exchange,提问作者zdenok

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 01:35:21