You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET4.7 IIS部署WCF服务配置WS-Security PasswordDigest报错求助

你遇到的InvalidSecurity错误核心有3个问题:

  1. WCF默认wsHttpBinding的UserName消息认证仅支持明文密码,你用PasswordDigest时默认校验逻辑不匹配
  2. 绑定配置中transport clientCredentialType="Basic"和你要实现的消息层用户名认证冲突,传输层仅需HTTPS不需要额外Basic认证
  3. 服务证书查找规则及权限配置可能存在问题,导致签名校验失败

最简可行配置方案

第一步:实现自定义用户名密码验证器

先新增验证器类,用于自定义校验逻辑,同时兼容PasswordDigest模式:

using System.IdentityModel.Selectors;
using System.ServiceModel;

public class CustomUserNameValidator : UserNamePasswordValidator
{
    public override void Validate(string userName, string password)
    {
        // 此处替换为你自己的用户名密码校验逻辑
        if (userName != "测试用户名" || password != "测试密码")
        {
            throw new FaultException("用户名或密码错误");
        }
    }
}

第二步:修改Web.config配置

替换你现有system.serviceModel节点为以下配置,替换对应占位符即可:

<system.serviceModel>
    <services>
        <service name="SoapService" behaviorConfiguration="SoapServiceConf">
            <endpoint address="" binding="wsHttpBinding" contract="Interfaces.ISoap" bindingConfiguration="wsHttpBind"/>
            <endpoint contract="IMetadataExchange" binding="mexHttpsBinding" address="mex" />
        </service>
    </services>
    <bindings>
        <wsHttpBinding>
            <binding maxReceivedMessageSize="10485760" name="wsHttpBind">
                <security mode="TransportWithMessageCredential">
                    <!-- 传输层仅用HTTPS,不需要额外Basic认证 -->
                    <transport clientCredentialType="None"/>
                    <message clientCredentialType="UserName" algorithmSuite="Default" establishSecurityContext="false" />
                </security>
                <reliableSession enabled="false" />
                <readerQuotas maxArrayLength="10485760" maxDepth="1024" maxStringContentLength="10485760" />
            </binding>
        </wsHttpBinding>
    </bindings>
    <behaviors>
        <serviceBehaviors>
            <behavior name="SoapServiceConf">
                <serviceCredentials>
                    <!-- 修正证书查找规则,建议改用主题名查找,替换为你自己的证书主题名 -->
                    <serviceCertificate findValue="soapservice"
                                        storeName="My"
                                        storeLocation="LocalMachine"
                                        x509FindType="FindBySubjectName" />
                    <!-- 配置自定义用户名验证器,替换为你自己的验证器类全名和程序集名 -->
                    <userNameAuthentication 
                        userNamePasswordValidationMode="Custom"
                        customUserNamePasswordValidatorType="你的命名空间.CustomUserNameValidator, 你的程序集名称"
                        mapToWindowsAccount="False" />
                </serviceCredentials>
                <serviceMetadata httpGetEnabled="false" httpsGetEnabled="true" />
                <serviceDebug includeExceptionDetailInFaults="True" />
            </behavior>
        </serviceBehaviors>
    </behaviors>
    <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" />
</system.serviceModel>

第三步:配置IIS证书权限

打开本地计算机证书存储,找到你用的soapservice证书,右键选择所有任务-管理私钥,添加你的IIS站点对应的应用程序池用户,给与读取权限。

第四步:SoapUI配置核对

  • 确保WS-A版本为WS-Addressing 1.0且已开启
  • WSS密码类型确认选PasswordDigest,同时开启Add Created Timestamp和Add Nonce选项
  • 不需要在SoapUI的基础认证里填用户名密码,所有认证信息都在WSS配置里填写

内容的提问来源于stack exchange,提问作者YorbGG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 07:15:04