使用自定义管道的BizTalk+ESB获取trust#RequestSecurityToken报错如何解决?
问题背景
使用BizTalk 2020和ESB,通过行程实现WCF Web服务的请求/响应操作:先转换消息,路由至服务,服务返回后再二次转换。接收位置抛出trust#RequestSecurityToken错误,该行程无需加密证书,目标网站采用匿名认证。已将Web服务从Windows认证改为无认证,但问题未解决。
使用的接收管道为PTwoRecMapPipeline.Part2RecPipeline,包含组件:ESBItinerarySelector、XMLDisassembler、ESB Dispatcher(Resolve Party),且ItinerarySelect绑定数据库。
错误信息如下:
Error: System.ServiceModel.FaultException: 执行接收管道失败: "PTwoRecMapPipeline.Part2RecPipeline, PTwoRecMapPipeline, Version=1.0.1.3, Culture=neutral, PublicKeyToken=ed4d3b3678f2ac22" 来源: "XML disassembler" 接收端口: "WcfReceivePort_WCFInitiator/Service1" URI: "/WCFInitiator/Service1.svc" 原因: 无法通过消息类型 "http://schemas.xmlsoap.org/ws/2005/02/trust#RequestSecurityToken" 找到文档规范。请验证架构是否正确部署。
Server stack trace:
at System.ServiceModel.Security.IssuanceTokenProviderBase`1.DoNegotiation(TimeSpan timeout)
at System.ServiceModel.Security.SspiNegotiationTokenProvider.OnOpen(TimeSpan timeout)
at System.ServiceModel.Security.WrapperSecurityCommunicationObject.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.Security.CommunicationObjectSecurityTokenProvider.Open(TimeSpan timeout)
at System.ServiceModel.Security.Sym...
解决方案
- 检查WCF接收端口安全配置:打开BizTalk管理控制台,找到对应接收端口,进入安全选项卡,设置安全模式为
None,客户端凭据类型为None,取消所有安全令牌相关勾选选项。 - 调整XMLDisassembler配置:编辑接收管道,取消XMLDisassembler的**“强制文档验证”**选项,避免其尝试解析WS-Trust系统消息;若不需要处理这类消息,无需部署对应架构。
- 验证行程与ESB路由逻辑:确认行程未将安全协商消息纳入业务路由,检查ESB Dispatcher(Resolve Party)配置,过滤掉WS-Trust相关系统消息。
- 检查WCF服务绑定配置:修改目标服务web.config,确保绑定完全禁用安全,示例配置如下:
<bindings> <basicHttpBinding> <binding name="AnonymousBinding"> <security mode="None" /> </binding> </basicHttpBinding> </bindings>
- 重启BizTalk主机实例:修改所有配置后,重启对应主机实例确保配置生效。
内容的提问来源于stack exchange,提问作者James366

