You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用MimeKit.Cryptography.MultipartSigned.Verify时如何禁用CRL检查?

关于禁用MimeKit签名验证时CRL检查的解决方案

问题说明

使用MimeKit.Cryptography.MultipartSigned.Verify方法时,由于通信方证书吊销列表(CRL)分发点配置错误,触发吊销检查失败异常,报错信息如下:

System.Security.Cryptography.CryptographicException: The revocation function was unable to check revocation because the revocation server was offline.
at System.Security.Cryptography.Pkcs.SignerInfo.Verify(X509Certificate2CollectionextraStore,X509Certificate2 certificate, Boolean verifySignatureOnly)
   at System.Security.Cryptography.Pkcs.SignerInfo.CheckSignature(X509Certificate2Collection extraStore, Boolean verifySignatureOnly)
   at MimeKit.Cryptography.WindowsSecureMimeDigitalSignature.Verify(Boolean verifySignatureOnly)
   --- End of inner exception stack trace ---
   at MimeKit.Cryptography.WindowsSecureMimeDigitalSignature.Verify(Boolean verifySignatureOnly)

解决方案

可以直接禁用CRL检查,操作方式如下:
调用Verify方法时传入verifySignatureOnly: true参数即可。该参数设置为true后,方法仅验证签名本身是否未被篡改,不会执行证书吊销列表检查、证书链信任校验等额外证书有效性验证步骤,可直接绕过当前报错。

代码示例

// 示例代码需结合实际业务逻辑调整
var signatures = multipartSigned.Verify();
foreach (var signature in signatures)
{
    // 传入true跳过CRL等证书有效性校验,仅验证签名完整性
    bool isSignatureValid = signature.Verify(true);
    if (isSignatureValid)
    {
        // 签名验证通过后的业务逻辑
    }
}

注意事项

该配置会跳过证书吊销、信任链等安全校验,仅适用于已确认通信方身份可信、仅CRL配置异常的场景,非特殊情况不建议在生产环境长期使用。


内容的提问来源于stack exchange,提问作者The Great Howdo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 20:36:07