Windows8.1下模板创建的ASP.NET Core应用运行提示无法访问求助
Hey there, let's work through this issue together since you're new to ASP.NET Core and hitting that tricky error on Windows 8.1. Based on what you've tried already (cleaning certificates, updating .NET, adjusting TLS settings), the root cause is indeed the compatibility between ASP.NET Core's default HTTP/2 configuration and Windows 8.1's limited TLS 1.2 cipher suite support. Here's how to fix it:
1. Quick Fix: Disable HTTP/2 (If You Don't Need It)
Since you noticed Firefox works when HTTP/2 is disabled, let's just turn off HTTP/2 support in your ASP.NET Core app. This is the fastest way to get things working:
Open your Program.cs file, and update the CreateHostBuilder method to configure Kestrel to only use HTTP/1.1 for your HTTPS endpoint:
public static IHostBuilder CreateHostBuilder(string[] args) => Host.CreateDefaultBuilder(args) .ConfigureWebHostDefaults(webBuilder => { webBuilder.UseStartup<Startup>(); webBuilder.UseKestrel(options => { // Listen on port 5001 with HTTPS, using only HTTP/1.1 options.ListenAnyIP(5001, listenOptions => { listenOptions.UseHttps(); listenOptions.Protocols = HttpProtocols.Http1AndHttp11; }); }); });
Save the file, restart your app with dotnet watch run, and try accessing the site again in Chrome—it should load without the error.
2. Keep HTTP/2: Configure Compatible Cipher Suites
If you want to keep using HTTP/2, you need to tell Kestrel to only use cipher suites that Windows 8.1 supports. Windows 8.1's TLS 1.2 implementation doesn't support some of the newer suites that ASP.NET Core uses by default.
Update your Kestrel configuration in Program.cs to specify allowed cipher suites and enforce TLS 1.2:
// Don't forget to add this using statement at the top of the file using System.Net.Security; public static IHostBuilder CreateHostBuilder(string[] args) => Host.CreateDefaultBuilder(args) .ConfigureWebHostDefaults(webBuilder => { webBuilder.UseStartup<Startup>(); webBuilder.UseKestrel(options => { options.ListenAnyIP(5001, listenOptions => { listenOptions.UseHttps(httpsOptions => { // Enforce TLS 1.2 (the only version Windows 8.1 handles well for HTTP/2) httpsOptions.SslProtocols = SslProtocols.Tls12; // Specify cipher suites compatible with Windows 8.1 httpsOptions.CipherSuitesPolicy = new CipherSuitesPolicy(new List<TlsCipherSuite> { TlsCipherSuite.Tls_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TlsCipherSuite.Tls_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TlsCipherSuite.Tls_RSA_WITH_AES_256_CBC_SHA256, TlsCipherSuite.Tls_RSA_WITH_AES_128_CBC_SHA256 }); }); // Allow both HTTP/1.1 and HTTP/2 listenOptions.Protocols = HttpProtocols.Http1AndHttp2; }); }); });
After making this change, clean and re-trust your certificates again:
dotnet dev-certs https --clean dotnet dev-certs https --trust
Restart your app and test again—Chrome should now connect over HTTP/2 without issues.
3. Clarification on Microsoft.Hosting.Lifetime
Quick note: Microsoft.Hosting.Lifetime is mainly for managing your app's lifecycle (like startup/shutdown behavior, environment settings, etc.)—it doesn't handle TLS or HTTP protocol configuration directly. All the settings you need are handled by the Kestrel web server (which is what ASP.NET Core uses under the hood), either via code like above or through your appsettings.json file.
If you prefer using config files instead of code, you can add this to your appsettings.json:
"Kestrel": { "Endpoints": { "Https": { "Url": "https://localhost:5001", "Protocols": "Http1AndHttp2", "SslProtocols": "Tls12", "CipherSuites": [ "Tls_ECDHE_RSA_WITH_AES_256_CBC_SHA384", "Tls_ECDHE_RSA_WITH_AES_128_CBC_SHA256" ] } } }
This achieves the same result as the code-based configuration.
Final Check
After applying either fix, make sure to:
- Restart your app completely (stop
dotnet watch runand start it again) - Clear Chrome's cache or open an incognito window to avoid cached connection issues
- Verify the certificate is still trusted in Windows' Certificate Manager
内容的提问来源于stack exchange,提问作者brrrrth

