You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows8.1下模板创建的ASP.NET Core应用运行提示无法访问求助

Fixing ERR_HTTP2_INADEQUATE_TRANSPORT_SECURITY for ASP.NET Core 3.1 on Windows 8.1

Hey there, let's work through this issue together since you're new to ASP.NET Core and hitting that tricky error on Windows 8.1. Based on what you've tried already (cleaning certificates, updating .NET, adjusting TLS settings), the root cause is indeed the compatibility between ASP.NET Core's default HTTP/2 configuration and Windows 8.1's limited TLS 1.2 cipher suite support. Here's how to fix it:

1. Quick Fix: Disable HTTP/2 (If You Don't Need It)

Since you noticed Firefox works when HTTP/2 is disabled, let's just turn off HTTP/2 support in your ASP.NET Core app. This is the fastest way to get things working:

Open your Program.cs file, and update the CreateHostBuilder method to configure Kestrel to only use HTTP/1.1 for your HTTPS endpoint:

public static IHostBuilder CreateHostBuilder(string[] args) =>
    Host.CreateDefaultBuilder(args)
        .ConfigureWebHostDefaults(webBuilder =>
        {
            webBuilder.UseStartup<Startup>();
            webBuilder.UseKestrel(options =>
            {
                // Listen on port 5001 with HTTPS, using only HTTP/1.1
                options.ListenAnyIP(5001, listenOptions =>
                {
                    listenOptions.UseHttps();
                    listenOptions.Protocols = HttpProtocols.Http1AndHttp11;
                });
            });
        });

Save the file, restart your app with dotnet watch run, and try accessing the site again in Chrome—it should load without the error.

2. Keep HTTP/2: Configure Compatible Cipher Suites

If you want to keep using HTTP/2, you need to tell Kestrel to only use cipher suites that Windows 8.1 supports. Windows 8.1's TLS 1.2 implementation doesn't support some of the newer suites that ASP.NET Core uses by default.

Update your Kestrel configuration in Program.cs to specify allowed cipher suites and enforce TLS 1.2:

// Don't forget to add this using statement at the top of the file
using System.Net.Security;

public static IHostBuilder CreateHostBuilder(string[] args) =>
    Host.CreateDefaultBuilder(args)
        .ConfigureWebHostDefaults(webBuilder =>
        {
            webBuilder.UseStartup<Startup>();
            webBuilder.UseKestrel(options =>
            {
                options.ListenAnyIP(5001, listenOptions =>
                {
                    listenOptions.UseHttps(httpsOptions =>
                    {
                        // Enforce TLS 1.2 (the only version Windows 8.1 handles well for HTTP/2)
                        httpsOptions.SslProtocols = SslProtocols.Tls12;
                        // Specify cipher suites compatible with Windows 8.1
                        httpsOptions.CipherSuitesPolicy = new CipherSuitesPolicy(new List<TlsCipherSuite>
                        {
                            TlsCipherSuite.Tls_ECDHE_RSA_WITH_AES_256_CBC_SHA384,
                            TlsCipherSuite.Tls_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
                            TlsCipherSuite.Tls_RSA_WITH_AES_256_CBC_SHA256,
                            TlsCipherSuite.Tls_RSA_WITH_AES_128_CBC_SHA256
                        });
                    });
                    // Allow both HTTP/1.1 and HTTP/2
                    listenOptions.Protocols = HttpProtocols.Http1AndHttp2;
                });
            });
        });

After making this change, clean and re-trust your certificates again:

dotnet dev-certs https --clean
dotnet dev-certs https --trust

Restart your app and test again—Chrome should now connect over HTTP/2 without issues.

3. Clarification on Microsoft.Hosting.Lifetime

Quick note: Microsoft.Hosting.Lifetime is mainly for managing your app's lifecycle (like startup/shutdown behavior, environment settings, etc.)—it doesn't handle TLS or HTTP protocol configuration directly. All the settings you need are handled by the Kestrel web server (which is what ASP.NET Core uses under the hood), either via code like above or through your appsettings.json file.

If you prefer using config files instead of code, you can add this to your appsettings.json:

"Kestrel": {
  "Endpoints": {
    "Https": {
      "Url": "https://localhost:5001",
      "Protocols": "Http1AndHttp2",
      "SslProtocols": "Tls12",
      "CipherSuites": [
        "Tls_ECDHE_RSA_WITH_AES_256_CBC_SHA384",
        "Tls_ECDHE_RSA_WITH_AES_128_CBC_SHA256"
      ]
    }
  }
}

This achieves the same result as the code-based configuration.

Final Check

After applying either fix, make sure to:

  • Restart your app completely (stop dotnet watch run and start it again)
  • Clear Chrome's cache or open an incognito window to avoid cached connection issues
  • Verify the certificate is still trusted in Windows' Certificate Manager

内容的提问来源于stack exchange,提问作者brrrrth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 07:07:58