You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft.Identity.Client登录Office365突然失败,需启用TLS 1.2

问题描述

我有一款连接Office365管理日历条目的桌面应用,一年前更新为使用Microsoft Identity Client后运行正常。如今应用突然无法工作,推测是Azure AD逐步停用TLS 1.0和1.1所致。

相关代码如下:

var pca = PublicClientApplicationBuilder
                        .Create(ConfigurationManager.AppSettings["appId"])
                        .WithTenantId(ConfigurationManager.AppSettings["tenantId"])
                        .Build();
        
            var ewsScopes = new string[] { "EWS.AccessAsUser.All" };
             
            // Make the interactive token request - this will display the Office 365 login dialog
            var authResult = await pca.AcquireTokenInteractive(ewsScopes).ExecuteAsync();

执行最后一行代码时,Office365登录弹窗正常显示,但点击确认账号后返回错误:

You are using TLS version 1.0, 1.1 and/or 3DES cipher which are deprecated to improve the security posture of Azure AD.

我已更新Microsoft.Identity.Client至4.48.1.0、.NET Framework至4.7.2、Windows 10至64位22H2版本,却仍出现相同错误,请问遗漏了什么?

解决方案
  • 显式启用TLS 1.2
    .NET Framework 4.7+虽默认继承系统TLS设置,但部分场景下仍需强制指定。在应用启动入口(如Main方法开头)添加代码:

    System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12;
    

    注意:仅保留Tls12,不要同时包含旧版本协议。

  • 添加应用配置文件的TLS强制设置
    在app.config或web.config中插入以下配置,确保应用优先使用TLS 1.2:

    <system.net>
      <settings>
        <servicePointManager securityProtocol="Tls12" />
      </settings>
    </system.net>
    
  • 修改.NET Framework注册表项
    手动添加注册表键强制.NET应用使用强加密:

    1. 打开注册表编辑器(regedit)
    2. 定位到HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319,新建DWORD值SchUseStrongCrypto,设置为1
    3. 若为32位应用,同步修改HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319下的同名键值
  • 配置MSAL的HTTP客户端
    高版本MSAL默认使用TLS 1.2,但如果自定义了HTTP客户端,需明确指定SSL协议:

    var handler = new HttpClientHandler
    {
        SslProtocols = System.Security.Authentication.SslProtocols.Tls12
    };
    var httpClient = new HttpClient(handler);
    
    var pca = PublicClientApplicationBuilder
        .Create(ConfigurationManager.AppSettings["appId"])
        .WithTenantId(ConfigurationManager.AppSettings["tenantId"])
        .WithHttpClientFactory(new DefaultHttpClientFactory(httpClient))
        .Build();
    
  • 检查系统密码套件
    通过本地组策略编辑器(gpedit.msc)进入计算机配置>管理模板>网络>SSL配置设置,启用"SSL密码套件顺序",只保留TLS 1.2支持的强套件,禁用3DES等弱加密套件。

内容的提问来源于stack exchange,提问作者Mike VE

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 11:45:26