You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Framework WCF项目迁移至.NET6:自定义绑定配置问题

.NET6下CoreWCF客户端配置指南(对应原WCF自定义绑定)

核心思路

原app.config使用**自定义绑定(customBinding)**而非基础绑定,因此不能直接用BasicHttpsBinding,需要手动构建CustomBinding并匹配原配置的所有参数,同时通过CoreWCF的ChannelFactory配置证书凭据。

完整实现代码

using CoreWCF;
using CoreWCF.Channels;
using CoreWCF.Security;
using System.Security.Cryptography.X509Certificates;

public class EGClient
{
    private readonly egw _client;

    public EGClient(IConfiguration configuration)
    {
        // 读取配置中的服务地址
        var serviceUri = new Uri(configuration.GetValue<string>("ServiceEndpoint"));
        
        // 构建自定义绑定,对应原app.config的<customBinding>
        var binding = CreateCustomBinding();
        
        // 创建端点地址(添加DNS身份验证)
        var endpointAddress = new EndpointAddress(serviceUri, new DnsEndpointIdentity("xx.xx.com"));
        
        // 配置ChannelFactory并设置证书凭据
        var channelFactory = new ChannelFactory<egw>(binding, endpointAddress);
        
        // 配置客户端证书(对应原<clientCertificate>)
        channelFactory.Credentials.ClientCertificate.SetCertificate(
            StoreLocation.LocalMachine,
            StoreName.TrustedPeople,
            X509FindType.FindBySubjectDistinguishedName,
            "CN=XXX, OU=XXX, O=XXX, L=XXX, S=XX, C=XX");
        
        // 配置服务端证书验证规则(对应原<serviceCertificate>下的<authentication>)
        channelFactory.Credentials.ServiceCertificate.Authentication.CertificateValidationMode = X509CertificateValidationMode.PeerOrChainTrust;
        channelFactory.Credentials.ServiceCertificate.Authentication.RevocationMode = X509RevocationMode.NoCheck;
        
        // 配置SSL证书验证(对应原<sslCertificateAuthentication>)
        channelFactory.Credentials.ServiceCertificate.SslCertificateAuthentication.CertificateValidationMode = X509CertificateValidationMode.None;
        
        // 禁用NTLM(对应原<windows allowNtlm="false">)
        channelFactory.Credentials.Windows.AllowNtlm = false;
        
        // 创建客户端代理
        _client = channelFactory.CreateChannel();
    }

    // 服务调用示例方法
    public void ExecuteServiceOperation(object data)
    {
        var response = _client.ExternalServiceOperation(data);
        // 处理业务响应
    }

    // 构建匹配原配置的自定义绑定
    private CustomBinding CreateCustomBinding()
    {
        // 事务流绑定元素(对应原<transactionFlow />)
        var transactionFlow = new TransactionFlowBindingElement();
        
        // 安全绑定元素(对应原<security>节点所有配置)
        var security = SecurityBindingElement.CreateMutualCertificateDuplexBindingElement();
        security.DefaultAlgorithmSuite = SecurityAlgorithmSuite.Default;
        security.AllowSerializedSigningTokenOnReply = true;
        security.EnableUnsecuredResponse = true;
        security.RequireDerivedKeys = false;
        security.MessageProtectionOrder = MessageProtectionOrder.SignBeforeEncrypt;
        security.MessageSecurityVersion = MessageSecurityVersion.WSSecurity11WSTrustFebruary2005WSSecureConversationFebruary2005WSSecurityPolicy11BasicSecurityProfile10;
        security.RequireSignatureConfirmation = false;
        
        // 文本消息编码(对应原<textMessageEncoding messageVersion="Soap11" />)
        var textEncoding = new TextMessageEncodingBindingElement(MessageVersion.Soap11, System.Text.Encoding.UTF8);
        
        // HTTPS传输绑定(对应原<httpsTransport maxReceivedMessageSize="2147483647" />)
        var httpsTransport = new HttpsTransportBindingElement();
        httpsTransport.MaxReceivedMessageSize = int.MaxValue;
        
        // 组装自定义绑定,元素顺序必须与原配置一致
        var binding = new CustomBinding();
        binding.Elements.Add(transactionFlow);
        binding.Elements.Add(security);
        binding.Elements.Add(textEncoding);
        binding.Elements.Add(httpsTransport);
        
        // 设置发送超时(对应原binding的sendTimeout="00:06:00")
        binding.SendTimeout = TimeSpan.FromMinutes(6);
        
        return binding;
    }
}

关键配置说明

  • 绑定元素顺序:严格按照原app.config中<customBinding>的元素顺序添加(事务流→安全→编码→传输),WCF绑定元素顺序直接影响通信逻辑。
  • 安全模式匹配:使用CreateMutualCertificateDuplexBindingElement()精准对应原配置的authenticationMode="MutualCertificateDuplex",其余安全参数逐一映射原配置项。
  • 证书权限:确保运行程序的账户拥有访问LocalMachine\TrustedPeople证书存储的权限,否则会出现证书查找失败异常。

内容的提问来源于stack exchange,提问作者David.Warwick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 03:45:37