Windows11 22H2更新后无法连接Server2003 Web服务求助
核心问题概述
Windows 11 22H2(22621.819)更新后,原本可正常连接Windows Server 2003 SP2 Web服务的功能出现故障,同款应用在Windows 10 21H2(19044.2251)上运行正常。客户端报错信息如下:
The underlying connection was closed: An unexpected error occurred on a send.
System.IO.IOException: Authentication failed because the remote party has closed the transport stream.
at System.Net.Security.SslState.StartReadFrame(Byte[] buffer, Int32 readBytes, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartReceiveBlob(Byte[] buffer, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.CheckCompletionBeforeNextReceive(ProtocolToken message, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartSendBlob(Byte[] incoming, Int32 count, AsyncProtocolRequest asyncRequest, Boolean renegotiation)
at System.Net.Security.SslState.ForceAuthentication(Boolean receiveFirst, Byte[] buffer, AsyncProtocolRequest asyncRequest, Boolean renegotiation)
at System.Net.Security.SslState.ProcessAuthentication(LazyAsyncResult lazyResult)
at System.Net.TlsStream.CallProcessAuthentication(Object state)
at System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
at System.Net.TlsStream.ProcessAuthentication(LazyAsyncResult result)
at System.Net.TlsStream.Write(Byte[] buffer, Int32 offset, Int32 size)
at System.Net.PooledStream.Write(Byte[] buffer, Int32 offset, Int32 size)
at System.Net.ConnectStream.WriteHeaders(Boolean async)| at System.Web.Services.Protocols.WebClientProtocol.GetWebResponse(WebRequest request)
at System.Web.Services.Protocols.HttpWebClientProtocol.GetWebResponse(WebRequest request)
at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters)
客户端事件查看器日志显示:A fatal error occurred while creating a TLS client credential. The internal error state is 10013. The SSPI client process is,涉及WWAHOST、backgroundTaskHost、msteamsupdate、HxTsr等进程。已尝试微软论坛提供的解决方案但无效,以下是进一步排查方向:
进一步排查方向
1. 强制启用旧版TLS协议支持
Windows 11 22H2可能默认禁用了Server 2003 SP2依赖的TLS 1.0/1.1,需通过注册表手动开启:
- 打开注册表编辑器(
regedit) - 定位到
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols - 分别创建
TLS 1.0、TLS 1.1项下的Client子项,添加DWORD值Enabled(值为1)和DisabledByDefault(值为0) - 重启系统后测试连接
2. 配置.NET Framework兼容安全协议
若应用基于.NET Framework开发,Windows 11的.NET环境可能默认使用更严格的安全协议:
- 在应用配置文件(
app.config或web.config)中添加代码强制指定TLS版本:ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls | SecurityProtocolType.Tls11 | SecurityProtocolType.Tls12; - 若无法修改代码,可通过注册表设置.NET Framework默认启用旧版TLS:定位到
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319,添加DWORD值SchUseStrongCrypto(值为0);同时检查Wow6432Node下的同路径设置
3. 调整系统加密套件顺序
Server 2003 SP2支持的加密套件可能被Windows 11 22H2默认排除,需添加兼容套件:
- 打开本地组策略编辑器(
gpedit.msc) - 导航到
计算机配置 > 管理模板 > 网络 > SSL配置设置 - 启用
SSL密码套件顺序,添加Server 2003支持的套件(如TLS_RSA_WITH_3DES_EDE_CBC_SHA、TLS_RSA_WITH_AES_128_CBC_SHA等),确保顺序优先于现代套件 - 执行
gpupdate /force更新组策略后测试
4. 排查安全软件拦截
部分安全软件可能在TLS握手阶段拦截旧版协议连接:
- 临时禁用Windows Defender实时保护及第三方杀毒软件,测试连接是否恢复
- 若恢复,添加应用或Server 2003 IP地址到安全软件信任列表
5. 捕获TLS握手数据包分析
使用Wireshark捕获客户端与Server 2003之间的TLS握手流量:
- 设置过滤条件
tls,查看握手过程中是否有Alert包(如Handshake Failure) - 根据错误码定位具体不兼容环节(如协议版本不匹配、加密套件协商失败)
6. 回滚Windows更新补丁
若问题由特定累积更新导致,可尝试回滚22H2的22621.819补丁:
- 打开
设置 > Windows更新 > 更新历史记录 > 卸载更新 - 找到对应KB补丁卸载,重启系统后测试
内容的提问来源于stack exchange,提问作者Pat Sinclair

