WCF自定义绑定报http URI方案无效需https的问题咨询
问题根因
当前报错由两处配置和业务场景的冲突导致:
- 使用的
CertificateOverTransport认证模式本身要求底层传输必须是HTTPS协议,证书身份校验依赖传输层安全能力 - 绑定配置中使用了
<httpsTransport>传输组件,强制要求端点地址为HTTPS协议,和业务要求的HTTP地址冲突
调整方案
需要将认证改为消息层证书认证模式,同时替换传输组件为HTTP版本,具体调整点如下:
- 将
authenticationMode从CertificateOverTransport修改为MutualCertificate(如果服务端也需要返回证书做验签)或Certificate(仅客户端提交X509证书做身份认证),两种模式都将证书信息封装在SOAP消息头中传递,不依赖传输层HTTPS - 将绑定中的
<httpsTransport>节点替换为<httpTransport>,适配HTTP协议的传输要求 - 原有
allowInsecureTransport="true"、enableUnsecuredResponse="true"配置保留,支持非加密传输场景
修改后完整配置
<system.serviceModel> <bindings> <customBinding> <binding name="serviceSoapBinding"> <security allowInsecureTransport="true" enableUnsecuredResponse="true" includeTimestamp="false" authenticationMode="MutualCertificate" defaultAlgorithmSuite="Basic256" requireDerivedKeys="true" messageSecurityVersion="WSSecurity10WSTrustFebruary2005WSSecureConversationFebruary2005WSSecurityPolicy11BasicSecurityProfile10"> </security> <textMessageEncoding messageVersion="Soap11"></textMessageEncoding> <httpTransport maxReceivedMessageSize="2000000000"/> </binding> </customBinding> </bindings> <client> <endpoint address="http://...Service" binding="customBinding" bindingConfiguration="serviceSoapBinding" contract="service.service" name="servicePort" > </endpoint> </client> </system.serviceModel>
注意事项
- 如果服务端不需要对返回消息做签名,可根据实际情况调整
requireDerivedKeys和includeTimestamp配置 - 需确保客户端配置的X509证书符合服务端的校验要求,证书公钥会自动封装到SOAP请求的WS-Security头中
内容的提问来源于stack exchange,提问作者ITMemberAHE
相关产品推荐
相关产品推荐

