更新客户端证书后WCF服务出现身份验证错误求助
问题:更换商业CA颁发的客户端证书后WCF服务通信中断
更换商业CA颁发的客户端证书后,某WCF服务通信中断,服务器跟踪到如下错误:
System.IdentityModel.Tokens.SecurityTokenValidationException: X.509证书CN=aaa.ccc.ff, O=XXXXX, L=Brbr, C=XX的链构建失败。所使用的证书的信任链无法验证。请更换证书或修改certificateValidationMode。证书链处理正常,但其中一个CA证书不被策略提供程序信任。
但该证书在另一同配置的外部服务中可正常工作。
服务端配置
<system.serviceModel> <extensions> <behaviorExtensions> <add name="A2AValidation" type="xxxyyyzzz.A2AValidation+CustomBehaviorSection, xxxyyyzzz A2A, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> </behaviorExtensions> </extensions> <protocolMapping> <add scheme="http" binding="wsHttpBinding" /> </protocolMapping> <bindings> <wsHttpBinding> <binding name="WcfServiceBinding"> <security mode="Message"> <message clientCredentialType="Certificate" negotiateServiceCredential="true" establishSecurityContext="true" /> </security> </binding> </wsHttpBinding> </bindings> <services> <service behaviorConfiguration="ClientSecBehavior" name="xxxyyyzzz.Service"> <endpoint address="" behaviorConfiguration="A2AValidationBehavior" binding="wsHttpBinding" bindingConfiguration="WcfServiceBinding" name="A2AmessageEndpoint" contract="xxxyyyzzz.IService" /> <endpoint address="mex" binding="mexHttpsBinding" name="A2AMessageEndpointMex" contract="IMetadataExchange" /> <host> <baseAddresses> <add baseAddress="http://xxxyyyzzz:10002/XX/A2A/Service.svc" /> </baseAddresses> </host> </service> </services> <behaviors> <endpointBehaviors> <behavior name="A2AValidationBehavior"> <A2AValidation /> </behavior> </endpointBehaviors> <serviceBehaviors> <behavior name="ClientSecBehavior"> <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true" /> <serviceDebug includeExceptionDetailInFaults="true" /> <serviceCredentials> <clientCertificate> <authentication certificateValidationMode="PeerOrChainTrust" trustedStoreLocation="LocalMachine" revocationMode="NoCheck" mapClientCertificateToWindowsAccount="true" /> </clientCertificate> <serviceCertificate findValue="______" storeLocation="LocalMachine" storeName="My" x509FindType="FindByThumbprint" /> </serviceCredentials> </behavior> </serviceBehaviors> </behaviors> <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" /> <diagnostics wmiProviderEnabled="true"> <messageLogging logEntireMessage="true" logKnownPii="false" logMalformedMessages="true" logMessagesAtServiceLevel="true" logMessagesAtTransportLevel="true" maxMessagesToLog="500" /> <endToEndTracing messageFlowTracing="true" /> </diagnostics> </system.serviceModel>
客户端配置(包含另一可正常工作的外部服务配置)
<system.serviceModel> <diagnostics> <messageLogging logEntireMessage="true" logMalformedMessages="true" logMessagesAtServiceLevel="true" logMessagesAtTransportLevel="true" maxMessagesToLog="3000" maxSizeOfMessageToLog="2000"/> </diagnostics> <bindings> <wsHttpBinding> <binding name="YYYY_A2AMessageEndpoint_BindingConfig" maxReceivedMessageSize="2147483647"> <security> <message clientCredentialType="Certificate" /> </security> </binding> <binding name="XXXYYYZZZ_A2AMessageEndpoint_BindingConfig"> <security> <message clientCredentialType="Certificate" /> </security> </binding> </wsHttpBinding> </bindings> <behaviors> <endpointBehaviors> <behavior name="YYYY_A2AMessageEndpoint_BehaviorConfig"> <clientCredentials> <serviceCertificate> <authentication certificateValidationMode="PeerOrChainTrust" revocationMode="NoCheck" trustedStoreLocation="LocalMachine" /> </serviceCertificate> <clientCertificate findValue="__________" x509FindType="FindByThumbprint" storeLocation="LocalMachine" storeName="My" /> </clientCredentials> </behavior> <behavior name="XXXYYYZZZ_A2AMessageEndpoint_BehaviorConfig"> <clientCredentials> <serviceCertificate> <authentication certificateValidationMode="PeerOrChainTrust" revocationMode="NoCheck" trustedStoreLocation="LocalMachine" /> </serviceCertificate> <clientCertificate findValue="__________" x509FindType="FindByThumbprint" storeLocation="LocalMachine" storeName="My" /> </clientCredentials> </behavior> </endpointBehaviors> </behaviors> <client> <endpoint name="YYYY_A2AMessageEndpoint" contract="A2AMessageService.IService" address="http://YYYY:10002/a2a/Service.svc" binding="wsHttpBinding" bindingConfiguration="YYYY_A2AMessageEndpoint_BindingConfig" behaviorConfiguration="YYYY_A2AMessageEndpoint_BehaviorConfig" > <identity> <certificate encodedValue="xyz=" /> </identity> </endpoint> <endpoint name="XXXYYYZZZ_A2AMessageEndpoint" contract="A2APTAMessageService.IService" address="http://XXXYYYZZZ:10002/PTA/A2A/Service.svc" binding="wsHttpBinding" bindingConfiguration="XXXYYYZZZ_A2AMessageEndpoint_BindingConfig" behaviorConfiguration="XXXYYYZZZ_A2AMessageEndpoint_BehaviorConfig" > <identity> <certificate encodedValue="xyz=" /> </identity> </endpoint> </client> </system.serviceModel>
证书相关信息
- 证书已在IIS证书映射和AD证书映射中正确注册,客户端证书的完整证书链在IIS和AD中显示正常。
- 客户端证书用途:
- 向远程计算机证明身份
- 验证远程计算机身份
- 包含OID:2.23.140.1.2.2
补充情况
由于该证书在另一服务中可正常使用,暂不认为证书用途是问题所在。将另一服务迁移到新服务器后,该问题也出现在新服务器上。
疑问
该证书的高级密钥用法中除“客户端身份验证”外还包含“服务器身份验证”,是否会影响AD安全提供商验证证书有效性?服务器的NTAuth存储中无相关证书。
内容的提问来源于stack exchange,提问作者zdenok
相关产品推荐
相关产品推荐

