Unity 2017中基于Mono(.NET3.5)的FTP TLS访问失败求助
It looks like the core issue here is outdated TLS support in Unity 2017's Mono runtime, which defaults to older TLS versions that your FTP server likely rejects. Let’s walk through targeted fixes to get your connection working:
1. Force TLS 1.2 (Critical for Modern Servers)
Unity 2017’s .NET 3.5 runtime doesn’t expose TLS12 as an explicit enum value, but you can enable it using its integer equivalent. Add this line early in your initialization (before creating the FTP request):
// Enable TLS 1.2 (3072 is the integer value for SecurityProtocolType.Tls12) ServicePointManager.SecurityProtocol = (SecurityProtocolType)3072;
Update your FTPManager constructor to include this:
public FTPManager(string hostIP, string userName, string password) { host = hostIP; user = userName; pass = password; // Force TLS 1.2 support ServicePointManager.SecurityProtocol = (SecurityProtocolType)3072; // Disable certificate revocation check (common in older Mono setups) ServicePointManager.CheckCertificateRevocationList = false; ServicePointManager.ServerCertificateValidationCallback += OnCertif; }
2. Validate FTPS Configuration
Your code uses EnableSsl = true (explicit FTPS, which uses port 21 with a post-connection TLS handshake). If your server uses implicit FTPS (port 990), adjust the host URL to use ftps:// instead of ftp://:
// For implicit FTPS (port 990) string ftpUrl = host.StartsWith("ftps://") ? host : $"ftps://{host}:990"; FtpWebRequest request = (FtpWebRequest)WebRequest.Create(ftpUrl);
3. Improve Certificate Validation Callback
While your current callback returns true to bypass validation, adding debug logs can help identify underlying issues. Modify it like this:
private bool OnCertif(object sender, X509Certificate certificate, X509Chain chain, SslPolicyErrors sslPolicyErrors) { if (sslPolicyErrors != SslPolicyErrors.None) { Debug.LogWarning($"SSL Validation Error: {sslPolicyErrors}"); Debug.Log($"Certificate Details: Issuer={certificate.Issuer}, Subject={certificate.Subject}"); } // Bypass validation for testing (replace with proper checks in production!) return true; }
4. Full Updated FTPManager Class
Here’s the complete adjusted code incorporating all fixes:
using System; using System.Net; using System.Net.Security; using System.Security.Cryptography.X509Certificates; using System.IO; using UnityEngine; public class FTPManager { private string host = null; private string user = null; private string pass = null; public FTPManager(string hostIP, string userName, string password) { host = hostIP; user = userName; pass = password; ServicePointManager.SecurityProtocol = (SecurityProtocolType)3072; ServicePointManager.CheckCertificateRevocationList = false; ServicePointManager.ServerCertificateValidationCallback += OnCertif; } public void Stop() { ServicePointManager.ServerCertificateValidationCallback -= OnCertif; } public void ListDirectory() { // Ensure proper FTP URL format string ftpUrl = host.StartsWith("ftp://") ? host : $"ftp://{host}"; FtpWebRequest request = (FtpWebRequest)WebRequest.Create(ftpUrl); request.Method = WebRequestMethods.Ftp.ListDirectoryDetails; request.EnableSsl = true; request.Credentials = new NetworkCredential(user, pass); try { using (FtpWebResponse response = (FtpWebResponse)request.GetResponse()) using (Stream responseStream = response.GetResponseStream()) { Debug.Log($"Directory List Complete, status {response.StatusDescription}"); // Optional: Read and log directory content using (StreamReader reader = new StreamReader(responseStream)) { Debug.Log("Directory Content:\n" + reader.ReadToEnd()); } } } catch (Exception e) { Debug.LogException(e); } } private bool OnCertif(object sender, X509Certificate certificate, X509Chain chain, SslPolicyErrors sslPolicyErrors) { if (sslPolicyErrors != SslPolicyErrors.None) { Debug.LogWarning($"SSL Validation Error: {sslPolicyErrors}"); Debug.Log($"Certificate Info: Issuer={certificate.Issuer}, Subject={certificate.Subject}"); } return true; } }
Key Notes:
- TLS Version: TLS 1.2 is the minimum standard for modern servers. If your server uses TLS 1.3, Unity 2017’s Mono runtime won’t support it—you’d need to upgrade Unity to a newer version.
- Production Security: Bypassing certificate validation (
return true) is only safe for testing. In production, validate the server’s certificate to avoid man-in-the-middle attacks. - Explicit vs Implicit FTPS: Confirm with your server admin which mode they use (explicit is more common today).
内容的提问来源于stack exchange,提问作者Cindy Vuillaume

