VB.NET中无法建立SSL/TLS安全通道信任关系问题求助
无法与授权方'dev1sintiaweb01'建立SSL/TLS安全通道信任关系的排查与解决
问题描述
在VB.NET环境中调用WCF服务时,持续触发以下错误:
无法与授权方'dev1sintiaweb01'建立SSL/TLS安全通道信任关系。
已确认服务端部署了签署证书,但错误仍存在,以下是相关配置及错误堆栈信息:
服务端WebConfig配置
<?xml version="1.0" encoding="UTF-8"?> <configuration> <configSections> <sectionGroup name="applicationSettings" type="System.Configuration.ApplicationSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"> <section name="SpasiWebService.My.MySettings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" requirePermission="false" /> </sectionGroup> </configSections> <appSettings /> <system.web> <compilation debug="true" strict="false" explicit="true" targetFramework="4.6.1"> </compilation> <httpRuntime /> <pages controlRenderingCompatibilityVersion="4.0" /> </system.web> <system.serviceModel> <services> <service name="SpasiService.IService1"> <endpoint address="basic" binding="basicHttpsBinding" contract="SpasiService.IService1" /> </service> </services> <bindings> <basicHttpsBinding> <binding maxBufferPoolSize="2147483647" maxBufferSize="2147483647" maxReceivedMessageSize="2147483647" transferMode="Streamed" > <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" /> </binding> </basicHttpsBinding> </bindings> <behaviors> <serviceBehaviors> <behavior> <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true"/> <serviceDebug includeExceptionDetailInFaults="false"/> </behavior> </serviceBehaviors> </behaviors> <protocolMapping> <add binding="basicHttpsBinding" scheme="https" /> </protocolMapping> <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" /> </system.serviceModel> <system.webServer> <modules runAllManagedModulesForAllRequests="true" /> <directoryBrowse enabled="true" /> </system.webServer> </configuration>
客户端AppConfig配置
<?xml version="1.0" encoding="utf-8"?> <configuration> <configSections> <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"> <section name="DosirAsli.My.MySettings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/> </sectionGroup> <!-- For more information on Entity Framework configuration, visit http://go.microsoft.com/fwlink/?LinkID=237468 --> <section name="entityFramework" type="System.Data.Entity.Internal.ConfigFile.EntityFrameworkSection, EntityFramework, Version=6.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" requirePermission="false"/> </configSections> <startup> <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.6"/> </startup> <userSettings> <DosirAsli.My.MySettings> <setting name="strLinkMyBCA" serializeAs="String"> <value>https://mybcaportal/sites/ai/Aplikasi Pengawasan Internal/</value> </setting> </DosirAsli.My.MySettings> </userSettings> <entityFramework> <providers> <provider invariantName="System.Data.SqlClient" type="System.Data.Entity.SqlServer.SqlProviderServices, EntityFramework.SqlServer"/> <provider invariantName="System.Data.SQLite.EF6" type="System.Data.SQLite.EF6.SQLiteProviderServices, System.Data.SQLite.EF6"/> </providers> </entityFramework> <system.net> <settings> <servicePointManager checkCertificateName="false" checkCertificateRevocationList="false" /> </settings> </system.net> <system.serviceModel> <bindings> <basicHttpsBinding> <binding name="BasicHttpsBinding_IService1" maxBufferPoolSize="2147483647" maxBufferSize="2147483647" maxReceivedMessageSize="2147483647" > <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" /> <security mode="Transport"> <transport clientCredentialType="Ntlm" /> </security> </binding> </basicHttpsBinding> </bindings> <!--<client> </client>--> <client> <endpoint address="https://dev1sintiaweb01/WebServiceSpasi/Service1.svc" binding="basicHttpsBinding" bindingConfiguration="BasicHttpsBinding_IService1" contract="SpasiWebService.IService1" name="BasicHttpsBinding_IService" /> </client> </system.serviceModel> </configuration>
错误堆栈信息
Server stack trace: at System.ServiceModel.Channels.HttpChannelUtilities.ProcessGetResponseWebException(WebException webException, HttpWebRequest request, HttpAbortReason abortReason) at System.ServiceModel.Channels.HttpChannelFactory`1.HttpRequestChannel.HttpChannelRequest.WaitForReply(TimeSpan timeout) at System.ServiceModel.Channels.RequestChannel.Request(Message message, TimeSpan timeout) at System.ServiceModel.Dispatcher.RequestChannelBinder.Request(Message message, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[] outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type) at DosirAsli.SpasiWebService.IService1.CekDomainTersedia(String strDomain) at DosirAsli.SpasiWebService.Service1Client.CekDomainTersedia(String strDomain) in E:\Project CAAT\Web PI\Web_PI\WebPI-DevBranch\DosirAsli\Connected Services\SpasiWebService\Reference.vb:line 96 at DosirAsli.Login.btnLogin_Click(Object sender, EventArgs e) in E:\Project CAAT\Web PI\Web_PI\WebPI-DevBranch\DosirAsli\Login.vb:line 43
排查与解决方法
1. 证书信任链缺失
即使证书已签署,客户端若未信任证书的签发机构,仍会触发信任错误。
- 操作步骤:
- 用浏览器打开服务端WCF地址
https://dev1sintiaweb01/WebServiceSpasi/Service1.svc - 点击地址栏锁图标,查看证书详情
- 选择"安装证书",按向导将证书导入本地计算机的受信任根证书颁发机构存储区
- 用浏览器打开服务端WCF地址
2. 证书域名不匹配
检查证书的通用名称(CN)或主题备用名称是否包含dev1sintiaweb01,若证书为其他域名签发,即使信任也会报错。
- 若使用自签名证书,生成时需将
CN设置为dev1sintiaweb01,或添加该域名到主题备用名称中。
3. TLS协议版本不兼容
客户端使用.NET Framework 4.6,默认支持TLS 1.0/1.1/1.2,但服务端可能禁用了旧协议,导致协商失败。
- 在客户端调用服务前添加代码,强制指定TLS版本:
System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12
4. NTLM认证配置冲突
客户端绑定设置了clientCredentialType="Ntlm",但服务端可能未开启对应认证,或NTLM协商出现问题。
- 排查IIS站点身份验证设置,确保启用Windows身份验证;若无需客户端认证,可修改客户端绑定:
<security mode="Transport"> <transport clientCredentialType="None" /> </security>
5. 证书吊销检查未生效
虽然客户端配置了checkCertificateRevocationList="false",但可能存在配置未生效的情况。
- 确认服务端证书未被吊销,测试环境可在本地组策略中临时禁用证书吊销检查。
内容的提问来源于stack exchange,提问作者Nicky Apriliani
相关产品推荐
相关产品推荐

