如何在ASP.NET Core 2.0中强制启用TLS 1.2以解决Salesforce API认证错误
解决ASP.NET Core 2.0中Salesforce REST API TLS 1.2强制认证问题
你的问题很典型——Salesforce升级到仅支持TLS 1.2后,旧的默认协议设置导致认证握手失败,才会出现retry your request和Salesforce.Common.AuthenticationClient.d__1.MoveNext()的错误栈。下面是在ASP.NET Core 2.0的Startup.cs中强制启用TLS 1.2的具体步骤:
1. 添加全局TLS协议设置
在Startup.cs的Configure方法最开头添加以下代码,确保应用启动时就强制所有HTTP请求使用TLS 1.2:
using System.Net; // 别忘了引用这个命名空间 public void Configure(IApplicationBuilder app, IHostingEnvironment env) { // 强制全局使用TLS 1.2 ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12; // 原来的Configure代码(比如app.UseMvc()等)继续保留 if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } else { app.UseHsts(); } app.UseHttpsRedirection(); app.UseMvc(); }
2. (可选)在认证方法中额外确认
如果想更保险,也可以在你的GetValidateAuthentication方法开头再重复设置一次,确保Salesforce的认证请求明确使用TLS 1.2:
private async Task<AuthenticationClient> GetValidateAuthentication() { // 再次强制TLS 1.2,针对本次认证请求 ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12; RestApiSetting data = new RestApiSetting(Configuration); var auth = new AuthenticationClient(); // 你的认证逻辑继续执行... }
为什么这能解决问题?
Salesforce现在要求所有API请求必须使用TLS 1.2,而ASP.NET Core 2.0的默认安全协议可能包含了已被Salesforce停用的TLS 1.0/1.1。通过设置ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12,我们强制应用仅使用符合要求的TLS版本,这样认证握手就能成功完成。
内容的提问来源于stack exchange,提问作者maxspan
相关产品推荐
相关产品推荐

