Blue Prism 6.9客户端连接服务端失败求助:握手格式异常
Hey there, let’s break down this issue step by step—your errors (connection mode mismatch + TLS handshake "unexpected packet format") are almost always rooted in misaligned configurations between your client and server VMs, or gaps in how TLS/certificates are set up. Here’s what to check:
1. Confirm Connection Mode is 100% Aligned
That first error message about matching connection modes isn’t a red herring—it’s often the simplest fix:
- On the Application Server: Open the Blue Prism Server Configuration tool, head to the Connection tab. Make sure the Connection Mode is set to
HTTPS(not HTTP), port is8199, and the certificate thumbprint matches the SSL cert you installed. - On the Interactive Client: Open the Blue Prism Client Configuration tool, go to the Connection tab. Set Connection Mode to
HTTPS, input the server’s IP/hostname and port8199. It’s easy to accidentally leave this on HTTP—double-check!
2. Lock Down TLS 1.2 Configuration (No Fallbacks)
You enabled TLS 1.2 in the registry, but let’s ensure it’s configured consistently on both VMs and that older TLS versions are disabled to prevent handshake fallback issues:
- On both server and client, verify these registry keys (for .NET Framework, which Blue Prism uses):
- 32-bit path:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319 - 64-bit path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 - Ensure DWORD values
SchUseStrongCryptoandSystemDefaultTlsVersionsare set to1.
- 32-bit path:
- Next, check Windows’ native TLS settings at
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2:- Under both
ClientandServersubkeys, setEnabledto1andDisabledByDefaultto0.
- Under both
- Reboot both VMs after any registry changes—these settings won’t take effect until you do.
3. Fix HTTP.Sys Certificate Binding Issues
The "unexpected packet format" handshake error usually points to a misconfigured certificate binding on the server:
- On the app server, run this command in an elevated command prompt to check existing bindings:
Confirm the entry fornetsh http show sslcert0.0.0.0:8199(or your server’s specific IP) has:- A thumbprint matching the cert in Blue Prism Server Configuration
- The correct Blue Prism application ID:
{7564EAB7-4493-4099-9B0A-0447F4261FC2}
- If the binding is missing or wrong, re-add it with this command (replace
YOUR_CERT_THUMBPRINTwith your actual thumbprint):netsh http add sslcert ipport=0.0.0.0:8199 certhash=YOUR_CERT_THUMBPRINT appid={7564EAB7-4493-4099-9B0A-0447F4261FC2} - Also, ensure the server’s certificate is installed in the Local Machine > Personal > Certificates store, and the Blue Prism service account has read permissions to the certificate’s private key (right-click the cert > All Tasks > Manage Private Keys to set this).
- On the client VM, install the server’s certificate (or its root CA cert) in the Local Machine > Trusted Root Certification Authorities store—this stops the client from rejecting the server’s cert as untrusted.
4. Test Connectivity Outside Blue Prism
Rule out network/OS-level issues before blaming Blue Prism:
- On the client, run this PowerShell command to test HTTPS connectivity to the server:
If this fails with a similar handshake error, the problem is outside Blue Prism (check firewalls, TLS settings, or cert trust). If it succeeds, the issue is specific to the Blue Prism client config.Invoke-WebRequest -Uri https://SERVER_IP:8199 -UseBasicParsing - Verify firewalls: Ensure inbound TCP port 8199 is allowed on the server, and outbound port 8199 is allowed on the client.
- Temporarily disable antivirus/endpoint protection (just for testing) to rule out interference with TLS handshakes—some tools block certain TLS packet formats.
5. Confirm Exact Version Match
Even though both are 6.9, double-check that client and server are running the exact same build number (e.g., 6.9.0.1234). Minor build mismatches can sometimes cause HTTPS communication glitches in Blue Prism.
内容的提问来源于stack exchange,提问作者user2517610

