You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET下C# WebRequest正常,Mono环境调用带自签名证书的Rest API失败

在C#中忽略自签名证书验证(仅开发环境使用)

刚好碰到过类似的开发场景,给你补全并优化一下代码,同时提醒关键注意事项:

当开发环境中访问使用自签名证书的REST API时,我们可以通过重写证书验证回调来跳过证书校验,但一定要记住只在开发测试时用,生产环境绝对不能这么做!

完整代码示例(使用WebClient)

using System;
using System.Net;
using System.Net.Security;
using System.Security.Cryptography.X509Certificates;

class Program {
    static void Main(string[] args) {
        // 关键:必须在发起请求前设置证书验证回调
        ServicePointManager.ServerCertificateValidationCallback = TrustCertificate;
        
        string BASE_URL = "https://your-api-endpoint/";
        string param = "api/resource?param=some-value";
        GetRequest(BASE_URL + param);
        
        Console.ReadLine();
    }

    /**
     * 接受任意证书(仅用于开发环境,生产环境绝对禁用!)
     */
    private static bool TrustCertificate(object sender, X509Certificate certificate, X509Chain chain, SslPolicyErrors sslPolicyErrors) {
        // 直接返回true表示信任所有证书,跳过校验
        return true;
    }

    private static void GetRequest(string url) {
        try {
            using (WebClient client = new WebClient()) {
                string response = client.DownloadString(url);
                Console.WriteLine("API响应内容:");
                Console.WriteLine(response);
            }
        } catch (Exception ex) {
            Console.WriteLine("请求失败:" + ex.Message);
        }
    }
}

如果你用HttpClient(推荐.NET Core/.NET 5+使用)

如果是较新的.NET版本,更推荐使用HttpClient,实现方式如下:

using System;
using System.Net.Http;
using System.Net.Security;
using System.Security.Cryptography.X509Certificates;
using System.Threading.Tasks;

class Program {
    static async Task Main(string[] args) {
        // 创建自定义Handler来忽略证书验证
        var handler = new HttpClientHandler();
        handler.ServerCertificateCustomValidationCallback = (sender, cert, chain, sslPolicyErrors) => true;
        
        using (var client = new HttpClient(handler)) {
            string BASE_URL = "https://your-api-endpoint/";
            string param = "api/resource?param=some-value";
            var response = await client.GetStringAsync(BASE_URL + param);
            
            Console.WriteLine("API响应内容:");
            Console.WriteLine(response);
        }
        
        Console.ReadLine();
    }
}

重要注意事项

  • ⚠️ 生产环境禁止使用:这种方式会信任所有证书,包括恶意伪造的证书,会造成严重的安全漏洞,生产环境必须使用由正规CA签发的有效证书。
  • 回调设置时机:一定要在发起任何HTTP请求之前设置验证回调,否则不会生效。
  • 替代方案:如果开发环境需要,也可以将自签名证书导入到本地信任根证书库,这样既不用修改代码,也能安全地通过证书验证。

内容的提问来源于stack exchange,提问作者McKay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:41:11