wsHttpBinding在HTTPS传输安全下不支持可靠会话,绑定验证失败求助
问题解决:WSHttpBinding在HTTPS下的可靠会话绑定验证失败
错误原因
WSHttpBinding的可靠会话(ReliableSession)与Transport安全模式存在兼容性冲突——当使用HTTPS的Transport安全时,WCF不允许启用可靠会话,这是因为可靠会话的实现依赖于消息层的协议交互,而Transport安全是在HTTP传输层进行加密,两者机制无法兼容。
解决方案
根据业务需求选择以下两种方案之一:
方案1:关闭可靠会话(业务无依赖时优先选择)
同时修改服务端和客户端配置,禁用reliableSession:
服务端web.config修改
- 调整绑定配置,禁用可靠会话并切换安全模式为Transport:
<wsHttpBinding> <binding name="wshttpbinding" bypassProxyOnLocal="true" receiveTimeout="00:10:00"> <!-- 禁用可靠会话 --> <reliableSession inactivityTimeout="23:00:00" enabled="false"/> <security mode="Transport"> <transport clientCredentialType="None" /> <message clientCredentialType="None" establishSecurityContext="false" /> </security> </binding> </wsHttpBinding>
- 更新服务基础地址为HTTPS,同时修改元数据端点为HTTPS类型:
<services> <service behaviorConfiguration="Services.ServiceBehavior" name="CJDWebServices.Service"> <endpoint address="" binding="wsHttpBinding" bindingConfiguration="wshttpbinding" contract="CJDWebServices.IService"> <identity> <dns value="dummy1" /> <!-- 改为SSL证书对应的DNS名称 --> </identity> </endpoint> <endpoint address="mex" binding="mexHttpsBinding" contract="IMetadataExchange" /> <host> <baseAddresses> <add baseAddress="https://localhost/TxService/" /> <!-- 切换为HTTPS地址 --> </baseAddresses> </host> </service> </services>
- 开启服务行为的HTTPS元数据访问:
<behavior name="Services.ServiceBehavior"> <serviceMetadata httpGetEnabled="False" httpsGetEnabled="True"/> <serviceDebug includeExceptionDetailInFaults="False" /> </behavior>
客户端app.config修改
调整对应绑定配置,禁用可靠会话并统一安全参数:
<binding name="WSHttpBinding_IService" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:25:00" sendTimeout="00:25:00" bypassProxyOnLocal="false" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="2147483647" maxReceivedMessageSize="2147483647" messageEncoding="Text" textEncoding="utf-8" useDefaultWebProxy="true" allowCookies="false"> <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="16384" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" /> <!-- 禁用可靠会话 --> <reliableSession ordered="true" inactivityTimeout="23:59:00" enabled="False" /> <security mode="Transport"> <transport clientCredentialType="None" proxyCredentialType="None" realm="" /> <message clientCredentialType="None" negotiateServiceCredential="false" establishSecurityContext="false" /> </security> </binding>
方案2:改用Message安全模式(需保留可靠会话时选择)
如果业务必须使用可靠会话,将安全模式改为Message,让安全验证在消息层完成,兼容可靠会话机制:
服务端web.config修改
<wsHttpBinding> <binding name="wshttpbinding" bypassProxyOnLocal="true" receiveTimeout="00:10:00"> <!-- 保留可靠会话 --> <reliableSession inactivityTimeout="23:00:00" enabled="true"/> <security mode="Message"> <message clientCredentialType="None" establishSecurityContext="false" /> </security> </binding> </wsHttpBinding>
客户端app.config修改
<binding name="WSHttpBinding_IService" ...> <reliableSession ordered="true" inactivityTimeout="23:59:00" enabled="True" /> <security mode="Message"> <message clientCredentialType="None" negotiateServiceCredential="false" establishSecurityContext="false" /> </security> </binding>
验证步骤
- 重启IIS服务确保配置生效
- 客户端重新同步服务引用(或手动确认配置完全匹配)
- 测试客户端与服务的连接
内容的提问来源于stack exchange,提问作者Faizan Nasir
相关产品推荐
相关产品推荐

