.NET Core 6/7调用TLS 1.3企业REST服务握手失败求助
调用TLS 1.3的REST服务时出现TLS握手失败问题
环境与问题背景
- 目标服务:企业内部外包系统REST服务,无法修改,固定使用TLS 1.3
- 证书信息:颁发者为
RapidSSL Global TLS RSA4096 SHA256 2022 CA1,签名算法为SHA256withRSA
尝试过的方案与错误现象
已测试RestSharp、Flurl、HttpClient等多个HTTP库,指定Tls13协议,甚至在.NET Core 7预览版(宣称TLS支持更完善)中验证,均出现相同错误:
认证失败,因为远程方发送了TLS警报:'HandshakeFailure'。
收到的消息意外或格式错误。
Fiddler捕获的详细错误:
HTTPS handshake to yyy.com (for #7) failed.
System.Security.Authentication.AuthenticationException A call to SSPI failed, see inner exception. < The message received was unexpected or badly formatted
Win32 (SChannel) Native Error Code: 0x80090326
测试代码示例
RestSharp实现
var options = new RestClientOptions("https://xx.xxx.com/auth/login") { ThrowOnAnyError = true, Timeout = 1000, Expect100Continue = true, }; var client = new RestClient(options); ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls13; ServicePointManager.ServerCertificateValidationCallback += (sender, cert, chain, sslPolicyErrors) => true; var response = client.Post(new RestRequest().AddJsonBody(new { user = "xxx@xxx.com", password = "123456" }));
HttpClient实现
var tokenrequest = new TokenRequest() { User = "xxx", Password = "123" }; HttpClient _httpClient; var httpClientHandler = new HttpClientHandler(); httpClientHandler.ServerCertificateCustomValidationCallback = (message, cert, chain, errors) => true; _httpClient = new HttpClient(httpClientHandler); ServicePointManager.SecurityProtocol |= SecurityProtocolType.Tls13; var response = await _httpClient.PostAsync("https://yyy.com", CreateHttpContent<TokenRequest>(tokenrequest)); response.EnsureSuccessStatusCode(); var data = await response.Content.ReadAsStringAsync(); Console.WriteLine(data);
内容的提问来源于stack exchange,提问作者alekoo73
相关产品推荐
相关产品推荐

