You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VB.NET中无法建立SSL/TLS安全通道信任关系问题求助

无法与授权方'dev1sintiaweb01'建立SSL/TLS安全通道信任关系的排查与解决

问题描述

在VB.NET环境中调用WCF服务时,持续触发以下错误:

无法与授权方'dev1sintiaweb01'建立SSL/TLS安全通道信任关系。

已确认服务端部署了签署证书,但错误仍存在,以下是相关配置及错误堆栈信息:

服务端WebConfig配置

<?xml version="1.0" encoding="UTF-8"?>

<configuration>
  <configSections>
    <sectionGroup name="applicationSettings" type="System.Configuration.ApplicationSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">
      <section name="SpasiWebService.My.MySettings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" requirePermission="false" />
    </sectionGroup>
  </configSections>
  <appSettings />
  
  <system.web>
    <compilation debug="true" strict="false" explicit="true" targetFramework="4.6.1">
            
        </compilation>
    <httpRuntime />
    <pages controlRenderingCompatibilityVersion="4.0" />
  </system.web>
  <system.serviceModel>
    <services>  
        <service name="SpasiService.IService1">  
        <endpoint address="basic" binding="basicHttpsBinding" contract="SpasiService.IService1" />    
        </service>  
    </services> 
    <bindings>
            <basicHttpsBinding>
                <binding maxBufferPoolSize="2147483647" maxBufferSize="2147483647" maxReceivedMessageSize="2147483647" transferMode="Streamed" >
                    <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
                </binding>
            </basicHttpsBinding>
        </bindings>

    <behaviors>
      <serviceBehaviors>
        <behavior>
         <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true"/>
         <serviceDebug includeExceptionDetailInFaults="false"/>
        </behavior>
      </serviceBehaviors>
    </behaviors>
    <protocolMapping>
      <add binding="basicHttpsBinding" scheme="https" />
    </protocolMapping>
    <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" />
  </system.serviceModel>
  <system.webServer>
    <modules runAllManagedModulesForAllRequests="true" />
   
    <directoryBrowse enabled="true" />
  </system.webServer>
  
</configuration>

客户端AppConfig配置

<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <configSections>
    <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">
      <section name="DosirAsli.My.MySettings"
        type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"
        allowExeDefinition="MachineToLocalUser" requirePermission="false"/>
    </sectionGroup>
  <!-- For more information on Entity Framework configuration, visit http://go.microsoft.com/fwlink/?LinkID=237468 -->
  <section name="entityFramework"
      type="System.Data.Entity.Internal.ConfigFile.EntityFrameworkSection, EntityFramework, Version=6.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"
      requirePermission="false"/>
  </configSections>
  <startup>
    <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.6"/>
  </startup>
  <userSettings>
    <DosirAsli.My.MySettings>
      <setting name="strLinkMyBCA" serializeAs="String">
        <value>https://mybcaportal/sites/ai/Aplikasi Pengawasan Internal/</value>
      </setting>
    </DosirAsli.My.MySettings>
  </userSettings>
  <entityFramework>
    <providers>
      <provider invariantName="System.Data.SqlClient" type="System.Data.Entity.SqlServer.SqlProviderServices, EntityFramework.SqlServer"/>
      <provider invariantName="System.Data.SQLite.EF6" type="System.Data.SQLite.EF6.SQLiteProviderServices, System.Data.SQLite.EF6"/>
    </providers>
  </entityFramework>

  <system.net>
    <settings>
      <servicePointManager checkCertificateName="false" checkCertificateRevocationList="false" />
    </settings>
  </system.net>
  
  <system.serviceModel>
    <bindings>
      <basicHttpsBinding>
        <binding name="BasicHttpsBinding_IService1" maxBufferPoolSize="2147483647" maxBufferSize="2147483647" maxReceivedMessageSize="2147483647" >
          <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
          <security mode="Transport">
            <transport clientCredentialType="Ntlm" />
          </security>

        </binding>
      </basicHttpsBinding>
     
    </bindings>
    
    <!--<client>
      
    </client>-->

    <client>
  
      <endpoint address="https://dev1sintiaweb01/WebServiceSpasi/Service1.svc"
        binding="basicHttpsBinding" bindingConfiguration="BasicHttpsBinding_IService1"
        contract="SpasiWebService.IService1" name="BasicHttpsBinding_IService" />
    </client>

  </system.serviceModel>


</configuration>

错误堆栈信息

Server stack trace:     at
System.ServiceModel.Channels.HttpChannelUtilities.ProcessGetResponseWebException(WebException
webException, HttpWebRequest request, HttpAbortReason abortReason)   
at
System.ServiceModel.Channels.HttpChannelFactory`1.HttpRequestChannel.HttpChannelRequest.WaitForReply(TimeSpan
timeout)    at
System.ServiceModel.Channels.RequestChannel.Request(Message message,
TimeSpan timeout)    at
System.ServiceModel.Dispatcher.RequestChannelBinder.Request(Message
message, TimeSpan timeout)    at
System.ServiceModel.Channels.ServiceChannel.Call(String action,
Boolean oneway, ProxyOperationRuntime operation, Object[] ins,
Object[] outs, TimeSpan timeout)    at
System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage
methodCall, ProxyOperationRuntime operation)    at
System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message)

Exception rethrown at [0]:     at
System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg)    at
System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type)    at
DosirAsli.SpasiWebService.IService1.CekDomainTersedia(String
strDomain)    at
DosirAsli.SpasiWebService.Service1Client.CekDomainTersedia(String
strDomain) in E:\Project CAAT\Web
PI\Web_PI\WebPI-DevBranch\DosirAsli\Connected
Services\SpasiWebService\Reference.vb:line 96    at
DosirAsli.Login.btnLogin_Click(Object sender, EventArgs e) in
E:\Project CAAT\Web PI\Web_PI\WebPI-DevBranch\DosirAsli\Login.vb:line
43

排查与解决方法

1. 证书信任链缺失

即使证书已签署,客户端若未信任证书的签发机构,仍会触发信任错误。

  • 操作步骤:
    1. 用浏览器打开服务端WCF地址https://dev1sintiaweb01/WebServiceSpasi/Service1.svc
    2. 点击地址栏锁图标,查看证书详情
    3. 选择"安装证书",按向导将证书导入本地计算机的受信任根证书颁发机构存储区

2. 证书域名不匹配

检查证书的通用名称(CN)或主题备用名称是否包含dev1sintiaweb01,若证书为其他域名签发,即使信任也会报错。

  • 若使用自签名证书,生成时需将CN设置为dev1sintiaweb01,或添加该域名到主题备用名称中。

3. TLS协议版本不兼容

客户端使用.NET Framework 4.6,默认支持TLS 1.0/1.1/1.2,但服务端可能禁用了旧协议,导致协商失败。

  • 在客户端调用服务前添加代码,强制指定TLS版本:
    System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12
    

4. NTLM认证配置冲突

客户端绑定设置了clientCredentialType="Ntlm",但服务端可能未开启对应认证,或NTLM协商出现问题。

  • 排查IIS站点身份验证设置,确保启用Windows身份验证;若无需客户端认证,可修改客户端绑定:
    <security mode="Transport">
      <transport clientCredentialType="None" />
    </security>
    

5. 证书吊销检查未生效

虽然客户端配置了checkCertificateRevocationList="false",但可能存在配置未生效的情况。

  • 确认服务端证书未被吊销,测试环境可在本地组策略中临时禁用证书吊销检查。

内容的提问来源于stack exchange,提问作者Nicky Apriliani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 09:30:46