You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WCF自定义绑定报http URI方案无效需https的问题咨询

问题根因

当前报错由两处配置和业务场景的冲突导致:

  • 使用的CertificateOverTransport认证模式本身要求底层传输必须是HTTPS协议,证书身份校验依赖传输层安全能力
  • 绑定配置中使用了<httpsTransport>传输组件,强制要求端点地址为HTTPS协议,和业务要求的HTTP地址冲突

调整方案

需要将认证改为消息层证书认证模式,同时替换传输组件为HTTP版本,具体调整点如下:

  1. 将authenticationMode从CertificateOverTransport修改为MutualCertificate(如果服务端也需要返回证书做验签)或Certificate(仅客户端提交X509证书做身份认证),两种模式都将证书信息封装在SOAP消息头中传递,不依赖传输层HTTPS
  2. 将绑定中的<httpsTransport>节点替换为<httpTransport>,适配HTTP协议的传输要求
  3. 原有allowInsecureTransport="true"、enableUnsecuredResponse="true"配置保留,支持非加密传输场景

修改后完整配置

<system.serviceModel>
    <bindings>
        <customBinding>
            <binding name="serviceSoapBinding">
                <security allowInsecureTransport="true" enableUnsecuredResponse="true"  includeTimestamp="false"
                          authenticationMode="MutualCertificate"
                          defaultAlgorithmSuite="Basic256"
                          requireDerivedKeys="true"
                          messageSecurityVersion="WSSecurity10WSTrustFebruary2005WSSecureConversationFebruary2005WSSecurityPolicy11BasicSecurityProfile10">
                </security>
                <textMessageEncoding messageVersion="Soap11"></textMessageEncoding>
                <httpTransport maxReceivedMessageSize="2000000000"/>
            </binding>
        </customBinding>
    </bindings>
    <client>
        <endpoint address="http://...Service"
            binding="customBinding" bindingConfiguration="serviceSoapBinding"
            contract="service.service" name="servicePort" >
        </endpoint>
    </client>
</system.serviceModel> 

注意事项

  • 如果服务端不需要对返回消息做签名,可根据实际情况调整requireDerivedKeys和includeTimestamp配置
  • 需确保客户端配置的X509证书符合服务端的校验要求,证书公钥会自动封装到SOAP请求的WS-Security头中

内容的提问来源于stack exchange,提问作者ITMemberAHE

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 15:48:03