.NET4.7 IIS部署WCF服务配置WS-Security PasswordDigest报错求助
你遇到的InvalidSecurity错误核心有3个问题:
- WCF默认
wsHttpBinding的UserName消息认证仅支持明文密码,你用PasswordDigest时默认校验逻辑不匹配 - 绑定配置中
transport clientCredentialType="Basic"和你要实现的消息层用户名认证冲突,传输层仅需HTTPS不需要额外Basic认证 - 服务证书查找规则及权限配置可能存在问题,导致签名校验失败
最简可行配置方案
第一步:实现自定义用户名密码验证器
先新增验证器类,用于自定义校验逻辑,同时兼容PasswordDigest模式:
using System.IdentityModel.Selectors; using System.ServiceModel; public class CustomUserNameValidator : UserNamePasswordValidator { public override void Validate(string userName, string password) { // 此处替换为你自己的用户名密码校验逻辑 if (userName != "测试用户名" || password != "测试密码") { throw new FaultException("用户名或密码错误"); } } }
第二步:修改Web.config配置
替换你现有system.serviceModel节点为以下配置,替换对应占位符即可:
<system.serviceModel> <services> <service name="SoapService" behaviorConfiguration="SoapServiceConf"> <endpoint address="" binding="wsHttpBinding" contract="Interfaces.ISoap" bindingConfiguration="wsHttpBind"/> <endpoint contract="IMetadataExchange" binding="mexHttpsBinding" address="mex" /> </service> </services> <bindings> <wsHttpBinding> <binding maxReceivedMessageSize="10485760" name="wsHttpBind"> <security mode="TransportWithMessageCredential"> <!-- 传输层仅用HTTPS,不需要额外Basic认证 --> <transport clientCredentialType="None"/> <message clientCredentialType="UserName" algorithmSuite="Default" establishSecurityContext="false" /> </security> <reliableSession enabled="false" /> <readerQuotas maxArrayLength="10485760" maxDepth="1024" maxStringContentLength="10485760" /> </binding> </wsHttpBinding> </bindings> <behaviors> <serviceBehaviors> <behavior name="SoapServiceConf"> <serviceCredentials> <!-- 修正证书查找规则,建议改用主题名查找,替换为你自己的证书主题名 --> <serviceCertificate findValue="soapservice" storeName="My" storeLocation="LocalMachine" x509FindType="FindBySubjectName" /> <!-- 配置自定义用户名验证器,替换为你自己的验证器类全名和程序集名 --> <userNameAuthentication userNamePasswordValidationMode="Custom" customUserNamePasswordValidatorType="你的命名空间.CustomUserNameValidator, 你的程序集名称" mapToWindowsAccount="False" /> </serviceCredentials> <serviceMetadata httpGetEnabled="false" httpsGetEnabled="true" /> <serviceDebug includeExceptionDetailInFaults="True" /> </behavior> </serviceBehaviors> </behaviors> <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" /> </system.serviceModel>
第三步:配置IIS证书权限
打开本地计算机证书存储,找到你用的soapservice证书,右键选择所有任务-管理私钥,添加你的IIS站点对应的应用程序池用户,给与读取权限。
第四步:SoapUI配置核对
- 确保WS-A版本为
WS-Addressing 1.0且已开启 - WSS密码类型确认选
PasswordDigest,同时开启Add Created Timestamp和Add Nonce选项 - 不需要在SoapUI的基础认证里填用户名密码,所有认证信息都在WSS配置里填写
内容的提问来源于stack exchange,提问作者YorbGG
相关产品推荐
相关产品推荐

