求助:客户端连接IdentityServer4时遇IDX10108错误
解决IDX10108: 指定的地址不符合HTTPS协议规范错误
我明白你现在被这个IDX10108错误卡得头疼,毕竟查了一圈同类方案都没解决确实闹心。咱们直接针对这个问题拆解可行的解决办法:
生产环境(必须用HTTPS)
这是IdentityServer4的安全强制要求,生产环境绝对不能使用HTTP,先确认以下核心配置:
- 确保IdentityServer4服务端部署在HTTPS地址上,比如
https://your-identity-server-domain - 客户端配置里的
Authority必须严格匹配服务端的HTTPS地址,示例代码如下:
services.AddAuthentication(options => { options.DefaultScheme = "Cookies"; options.DefaultChallengeScheme = "oidc"; }) .AddCookie("Cookies") .AddOpenIdConnect("oidc", options => { options.Authority = "https://your-identity-server-domain"; // 这里必须是HTTPS options.ClientId = "your-client-id"; options.SaveTokens = true; // 其他必要配置... });
测试环境(允许临时用HTTP)
如果是本地开发测试,需要绕过HTTPS强制校验,你需要手动设置HttpDocumentRetriever的RequireHttps属性为false,同时调整服务端配置:
客户端配置修改
.AddOpenIdConnect("oidc", options => { options.Authority = "http://localhost:5000"; // 测试用HTTP地址 options.ClientId = "test-client"; options.SaveTokens = true; // 关键:配置允许HTTP的文档检索器 options.ConfigurationManager = new ConfigurationManager<OpenIdConnectConfiguration>( options.MetadataAddress, new OpenIdConnectConfigurationRetriever(), new HttpDocumentRetriever { RequireHttps = false }); });
IdentityServer4服务端配置修改
确保服务端允许HTTP访问并正确设置Issuer地址:
// .NET 6+ Program.cs builder.Services.AddIdentityServer(options => { options.IssuerUri = "http://localhost:5000"; options.PublicOrigin = "http://localhost:5000"; }) .AddInMemoryClients(Config.Clients) .AddInMemoryIdentityResources(Config.IdentityResources) .AddInMemoryApiScopes(Config.ApiScopes) .AddTestUsers(TestUsers.Users); // 让Kestrel监听HTTP端口 builder.WebHost.UseUrls("http://localhost:5000");
额外注意事项
- 绝对不要在生产环境开启HTTP支持,这会严重降低系统安全性
- 检查客户端的
Authority地址是否有拼写错误,比如漏写https里的s - 如果使用反向代理部署服务端,要确保配置了
ForwardedHeaders,让IdentityServer4能正确识别外部的HTTPS地址
内容的提问来源于stack exchange,提问作者Igor Risis
相关产品推荐
相关产品推荐

