You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在ASP.NET Core 2.0中强制启用TLS 1.2以解决Salesforce API认证错误

解决ASP.NET Core 2.0中Salesforce REST API TLS 1.2强制认证问题

你的问题很典型——Salesforce升级到仅支持TLS 1.2后,旧的默认协议设置导致认证握手失败,才会出现retry your request和Salesforce.Common.AuthenticationClient.d__1.MoveNext()的错误栈。下面是在ASP.NET Core 2.0的Startup.cs中强制启用TLS 1.2的具体步骤:

1. 添加全局TLS协议设置

在Startup.cs的Configure方法最开头添加以下代码,确保应用启动时就强制所有HTTP请求使用TLS 1.2:

using System.Net; // 别忘了引用这个命名空间

public void Configure(IApplicationBuilder app, IHostingEnvironment env)
{
    // 强制全局使用TLS 1.2
    ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;

    // 原来的Configure代码(比如app.UseMvc()等)继续保留
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }
    else
    {
        app.UseHsts();
    }

    app.UseHttpsRedirection();
    app.UseMvc();
}

2. (可选)在认证方法中额外确认

如果想更保险,也可以在你的GetValidateAuthentication方法开头再重复设置一次,确保Salesforce的认证请求明确使用TLS 1.2:

private async Task<AuthenticationClient> GetValidateAuthentication() 
{
    // 再次强制TLS 1.2,针对本次认证请求
    ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;

    RestApiSetting data = new RestApiSetting(Configuration); 
    var auth = new AuthenticationClient();
    // 你的认证逻辑继续执行...
}

为什么这能解决问题?

Salesforce现在要求所有API请求必须使用TLS 1.2,而ASP.NET Core 2.0的默认安全协议可能包含了已被Salesforce停用的TLS 1.0/1.1。通过设置ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12,我们强制应用仅使用符合要求的TLS版本,这样认证握手就能成功完成。

内容的提问来源于stack exchange,提问作者maxspan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:30:02