You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows11 22H2更新后无法连接Server2003 Web服务求助

问题分析与排查方向

核心问题概述

Windows 11 22H2(22621.819)更新后,原本可正常连接Windows Server 2003 SP2 Web服务的功能出现故障,同款应用在Windows 10 21H2(19044.2251)上运行正常。客户端报错信息如下:

The underlying connection was closed: An unexpected error occurred on a send.

System.IO.IOException: Authentication failed because the remote party has closed the transport stream.
at System.Net.Security.SslState.StartReadFrame(Byte[] buffer, Int32 readBytes, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartReceiveBlob(Byte[] buffer, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.CheckCompletionBeforeNextReceive(ProtocolToken message, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartSendBlob(Byte[] incoming, Int32 count, AsyncProtocolRequest asyncRequest, Boolean renegotiation)
at System.Net.Security.SslState.ForceAuthentication(Boolean receiveFirst, Byte[] buffer, AsyncProtocolRequest asyncRequest, Boolean renegotiation)
at System.Net.Security.SslState.ProcessAuthentication(LazyAsyncResult lazyResult)
at System.Net.TlsStream.CallProcessAuthentication(Object state)
at System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
at System.Net.TlsStream.ProcessAuthentication(LazyAsyncResult result)
at System.Net.TlsStream.Write(Byte[] buffer, Int32 offset, Int32 size)
at System.Net.PooledStream.Write(Byte[] buffer, Int32 offset, Int32 size)
at System.Net.ConnectStream.WriteHeaders(Boolean async)| at System.Web.Services.Protocols.WebClientProtocol.GetWebResponse(WebRequest request)
at System.Web.Services.Protocols.HttpWebClientProtocol.GetWebResponse(WebRequest request)
at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)

客户端事件查看器日志显示:A fatal error occurred while creating a TLS client credential. The internal error state is 10013. The SSPI client process is,涉及WWAHOST、backgroundTaskHost、msteamsupdate、HxTsr等进程。已尝试微软论坛提供的解决方案但无效,以下是进一步排查方向:

进一步排查方向

1. 强制启用旧版TLS协议支持

Windows 11 22H2可能默认禁用了Server 2003 SP2依赖的TLS 1.0/1.1,需通过注册表手动开启:

  • 打开注册表编辑器(regedit)
  • 定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols
  • 分别创建TLS 1.0、TLS 1.1项下的Client子项,添加DWORD值Enabled(值为1)和DisabledByDefault(值为0)
  • 重启系统后测试连接

2. 配置.NET Framework兼容安全协议

若应用基于.NET Framework开发,Windows 11的.NET环境可能默认使用更严格的安全协议:

  • 在应用配置文件(app.config或web.config)中添加代码强制指定TLS版本:
    ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls | SecurityProtocolType.Tls11 | SecurityProtocolType.Tls12;
    
  • 若无法修改代码,可通过注册表设置.NET Framework默认启用旧版TLS:定位到HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319,添加DWORD值SchUseStrongCrypto(值为0);同时检查Wow6432Node下的同路径设置

3. 调整系统加密套件顺序

Server 2003 SP2支持的加密套件可能被Windows 11 22H2默认排除,需添加兼容套件:

  • 打开本地组策略编辑器(gpedit.msc)
  • 导航到计算机配置 > 管理模板 > 网络 > SSL配置设置
  • 启用SSL密码套件顺序,添加Server 2003支持的套件(如TLS_RSA_WITH_3DES_EDE_CBC_SHA、TLS_RSA_WITH_AES_128_CBC_SHA等),确保顺序优先于现代套件
  • 执行gpupdate /force更新组策略后测试

4. 排查安全软件拦截

部分安全软件可能在TLS握手阶段拦截旧版协议连接:

  • 临时禁用Windows Defender实时保护及第三方杀毒软件,测试连接是否恢复
  • 若恢复,添加应用或Server 2003 IP地址到安全软件信任列表

5. 捕获TLS握手数据包分析

使用Wireshark捕获客户端与Server 2003之间的TLS握手流量:

  • 设置过滤条件tls,查看握手过程中是否有Alert包(如Handshake Failure)
  • 根据错误码定位具体不兼容环节(如协议版本不匹配、加密套件协商失败)

6. 回滚Windows更新补丁

若问题由特定累积更新导致,可尝试回滚22H2的22621.819补丁:

  • 打开设置 > Windows更新 > 更新历史记录 > 卸载更新
  • 找到对应KB补丁卸载,重启系统后测试

内容的提问来源于stack exchange,提问作者Pat Sinclair

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 08:10:28