You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core基于IP地址的自签名证书SSL验证仍显示不安全问题排查

问题描述

我尝试通过IP地址而非localhost以HTTPS方式运行应用,例如https://192.168.2.1:5001/index.html。已执行以下操作:

  • 使用PowerShell创建自签名证书:
New-SelfSignedCertificate -CertStoreLocation "cert:\LocalMachine\My"  -dnsname "192.168.2.1" -NotAfter (Get-Date).AddYears(10) -FriendlyName "SS_192_168_2_1" -KeyUsageProperty All -KeyUsage CertSign, CRLSign, DigitalSignature

Thumbprint                                Subject
----------                                -------
ABE394F15852C9389655F3EBC111FCE624D43479  CN=192.168.2.1

$mypwd = ConvertTo-SecureString -String "SS123" -Force -AsPlainText
Get-ChildItem -Path cert:\localMachine\my\ABE394F15852C9389655F3EBC111FCE624D43479 | Export-PfxCertificate -FilePath "D:\Certificates\SS_192_168_2_1.pfx" -Password $mypwd
  • 将SS_192_168_2_1.pfx导入到当前用户的Trusted Root Certificate Authority证书存储中,导入时设置了新密码并确认保存。
  • 配置.NET Core Web API应用使用该证书,代码如下:
public class Program
{
    public static void Main(string[] args)
    {
        CreateHostBuilder(args).Build().Run();
    }

    public static IHostBuilder CreateHostBuilder(string[] args) =>
    Host.CreateDefaultBuilder(args)
        .ConfigureWebHostDefaults(webBuilder =>
        {
            webBuilder.UseStartup<Startup>();
            webBuilder.ConfigureKestrel(options =>
            {
                options.ConfigureEndpointDefaults(listenOptions =>
                {
                    // Loads the certificate (a must-have)
                    listenOptions.UseHttps(@"D:\Certificates\SS_192_168_2_1.pfx", "SS123");
                });

                options.ConfigureHttpsDefaults(o =>
                {
                    o.ClientCertificateMode = ClientCertificateMode.NoCertificate;
                });
            });
        });
}

浏览器仍显示Not Secure,Postman提示Self signed certificate,但localhost访问显示安全,请问遗漏了什么操作?


解决方案

核心问题分析

localhost能正常显示安全是因为浏览器对localhost的自签名证书有特殊信任豁免,但IP地址无此待遇,你的操作存在以下关键遗漏:

1. 证书导入位置错误

你将证书导入到当前用户的Trusted Root Certificate Authority,但主流浏览器(如Chrome、Edge)优先读取本地计算机级别的根证书存储,而非当前用户目录。需将证书导入到Local Machine的Trusted Root Certificate Authorities中:

  • 打开mmc.exe,添加「证书」管理单元,选择「计算机账户」→「本地计算机」
  • 找到「受信任的根证书颁发机构」→「证书」,右键选择「所有任务」→「导入」
  • 选择SS_192_168_2_1.pfx文件,按向导完成导入,确认存储位置正确

2. 证书SAN字段可能缺失

部分浏览器会强制验证证书的**Subject Alternative Name(SAN)**字段,而非仅依赖Subject中的CN。虽然新版PowerShell的-dnsname参数会自动添加SAN,但仍需确认:

  • 打开证书属性,切换到「详细信息」标签,查找「主题备用名称」,确认包含IP Address=192.168.2.1
  • 若缺失,重新创建证书并显式指定SAN:
New-SelfSignedCertificate -CertStoreLocation "cert:\LocalMachine\My" `
  -Subject "CN=192.168.2.1" `
  -NotAfter (Get-Date).AddYears(10) `
  -FriendlyName "SS_192_168_2_1" `
  -KeyUsageProperty All `
  -KeyUsage CertSign, CRLSign, DigitalSignature `
  -SubjectAlternativeName @{IPAddress="192.168.2.1"}

3. 浏览器缓存刷新

浏览器可能缓存了旧的不安全状态,需清除SSL相关缓存:

  • Chrome/Edge:打开chrome://settings/clearBrowserData,勾选「缓存的图片和文件」「Cookie及其他网站数据」,执行清除后重启浏览器

4. Postman证书信任配置

Postman默认不信任自签名证书,需手动设置:

  • 打开Postman设置→「General」,关闭「SSL certificate verification」选项;或在「Certificates」标签中导入你的根证书

内容的提问来源于stack exchange,提问作者Nithin B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 09:10:37