You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

wsHttpBinding在HTTPS传输安全下不支持可靠会话,绑定验证失败求助

问题解决:WSHttpBinding在HTTPS下的可靠会话绑定验证失败

错误原因

WSHttpBinding的可靠会话(ReliableSession)与Transport安全模式存在兼容性冲突——当使用HTTPS的Transport安全时,WCF不允许启用可靠会话,这是因为可靠会话的实现依赖于消息层的协议交互,而Transport安全是在HTTP传输层进行加密,两者机制无法兼容。

解决方案

根据业务需求选择以下两种方案之一:

方案1:关闭可靠会话(业务无依赖时优先选择)

同时修改服务端和客户端配置,禁用reliableSession:

服务端web.config修改

  1. 调整绑定配置,禁用可靠会话并切换安全模式为Transport:
<wsHttpBinding>
  <binding name="wshttpbinding" bypassProxyOnLocal="true" receiveTimeout="00:10:00">
    <!-- 禁用可靠会话 -->
    <reliableSession inactivityTimeout="23:00:00" enabled="false"/>
    <security mode="Transport">
      <transport clientCredentialType="None" />
      <message clientCredentialType="None" establishSecurityContext="false" />
    </security>
  </binding>
</wsHttpBinding>
  1. 更新服务基础地址为HTTPS,同时修改元数据端点为HTTPS类型:
<services>
  <service behaviorConfiguration="Services.ServiceBehavior" name="CJDWebServices.Service">
    <endpoint address="" binding="wsHttpBinding" bindingConfiguration="wshttpbinding"
      contract="CJDWebServices.IService">
      <identity>
        <dns value="dummy1" /> <!-- 改为SSL证书对应的DNS名称 -->
      </identity>
    </endpoint>
    <endpoint address="mex" binding="mexHttpsBinding" contract="IMetadataExchange" />
    <host>
      <baseAddresses>
        <add baseAddress="https://localhost/TxService/" /> <!-- 切换为HTTPS地址 -->
      </baseAddresses>
    </host>
  </service>
</services>
  1. 开启服务行为的HTTPS元数据访问:
<behavior name="Services.ServiceBehavior">
  <serviceMetadata httpGetEnabled="False" httpsGetEnabled="True"/>
  <serviceDebug includeExceptionDetailInFaults="False" />
</behavior>

客户端app.config修改

调整对应绑定配置,禁用可靠会话并统一安全参数:

<binding name="WSHttpBinding_IService" closeTimeout="00:01:00"
  openTimeout="00:01:00" receiveTimeout="00:25:00" sendTimeout="00:25:00"
  bypassProxyOnLocal="false" transactionFlow="false" hostNameComparisonMode="StrongWildcard"
  maxBufferPoolSize="2147483647" maxReceivedMessageSize="2147483647"
  messageEncoding="Text" textEncoding="utf-8" useDefaultWebProxy="true"
  allowCookies="false">
  <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="16384"
      maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
  <!-- 禁用可靠会话 -->
  <reliableSession ordered="true" inactivityTimeout="23:59:00" enabled="False" />
  <security mode="Transport">
    <transport clientCredentialType="None" proxyCredentialType="None" realm="" />
    <message clientCredentialType="None" negotiateServiceCredential="false" establishSecurityContext="false" />
  </security>
</binding>

方案2:改用Message安全模式(需保留可靠会话时选择)

如果业务必须使用可靠会话,将安全模式改为Message,让安全验证在消息层完成,兼容可靠会话机制:

服务端web.config修改

<wsHttpBinding>
  <binding name="wshttpbinding" bypassProxyOnLocal="true" receiveTimeout="00:10:00">
    <!-- 保留可靠会话 -->
    <reliableSession inactivityTimeout="23:00:00" enabled="true"/>
    <security mode="Message">
      <message clientCredentialType="None" establishSecurityContext="false" />
    </security>
  </binding>
</wsHttpBinding>

客户端app.config修改

<binding name="WSHttpBinding_IService" ...>
  <reliableSession ordered="true" inactivityTimeout="23:59:00" enabled="True" />
  <security mode="Message">
    <message clientCredentialType="None" negotiateServiceCredential="false" establishSecurityContext="false" />
  </security>
</binding>

验证步骤

  1. 重启IIS服务确保配置生效
  2. 客户端重新同步服务引用(或手动确认配置完全匹配)
  3. 测试客户端与服务的连接

内容的提问来源于stack exchange,提问作者Faizan Nasir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 10:25:24