使用Microsoft.Identity.Client登录Office365突然失败,需启用TLS 1.2
我有一款连接Office365管理日历条目的桌面应用,一年前更新为使用Microsoft Identity Client后运行正常。如今应用突然无法工作,推测是Azure AD逐步停用TLS 1.0和1.1所致。
相关代码如下:
var pca = PublicClientApplicationBuilder .Create(ConfigurationManager.AppSettings["appId"]) .WithTenantId(ConfigurationManager.AppSettings["tenantId"]) .Build(); var ewsScopes = new string[] { "EWS.AccessAsUser.All" }; // Make the interactive token request - this will display the Office 365 login dialog var authResult = await pca.AcquireTokenInteractive(ewsScopes).ExecuteAsync();
执行最后一行代码时,Office365登录弹窗正常显示,但点击确认账号后返回错误:
You are using TLS version 1.0, 1.1 and/or 3DES cipher which are deprecated to improve the security posture of Azure AD.
我已更新Microsoft.Identity.Client至4.48.1.0、.NET Framework至4.7.2、Windows 10至64位22H2版本,却仍出现相同错误,请问遗漏了什么?
显式启用TLS 1.2
.NET Framework 4.7+虽默认继承系统TLS设置,但部分场景下仍需强制指定。在应用启动入口(如Main方法开头)添加代码:System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12;注意:仅保留
Tls12,不要同时包含旧版本协议。添加应用配置文件的TLS强制设置
在app.config或web.config中插入以下配置,确保应用优先使用TLS 1.2:<system.net> <settings> <servicePointManager securityProtocol="Tls12" /> </settings> </system.net>修改.NET Framework注册表项
手动添加注册表键强制.NET应用使用强加密:- 打开注册表编辑器(
regedit) - 定位到
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319,新建DWORD值SchUseStrongCrypto,设置为1 - 若为32位应用,同步修改
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319下的同名键值
- 打开注册表编辑器(
配置MSAL的HTTP客户端
高版本MSAL默认使用TLS 1.2,但如果自定义了HTTP客户端,需明确指定SSL协议:var handler = new HttpClientHandler { SslProtocols = System.Security.Authentication.SslProtocols.Tls12 }; var httpClient = new HttpClient(handler); var pca = PublicClientApplicationBuilder .Create(ConfigurationManager.AppSettings["appId"]) .WithTenantId(ConfigurationManager.AppSettings["tenantId"]) .WithHttpClientFactory(new DefaultHttpClientFactory(httpClient)) .Build();检查系统密码套件
通过本地组策略编辑器(gpedit.msc)进入计算机配置>管理模板>网络>SSL配置设置,启用"SSL密码套件顺序",只保留TLS 1.2支持的强套件,禁用3DES等弱加密套件。
内容的提问来源于stack exchange,提问作者Mike VE

