Identity Server 3禁用不安全加密套件后异常及升级IS4相关咨询
Great question! Let's start with getting Identity Server 3 (IS3) working after disabling that insecure 3DES cipher. The issue almost always boils down to missing compatible strong cipher suites in your server configuration, or outdated dependencies in IS3 itself. Here's how to fix it:
1. Configure Strong Cipher Suites for Your Host
IS3 typically runs on either IIS or an OWIN self-hosted server—here's how to update each:
- IIS Deployment:
- Open IIS Manager, navigate to your IS3 site, go to SSL Settings, and ensure "Require SSL" and "Require 128-bit SSL" are checked.
- Update your system's cipher suite configuration via Group Policy or the Windows Registry:
- Navigate to
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers - Disable 3DES by setting its
EnabledDWORD to 0, then enable modern, secure suites likeTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384andTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256by setting theirEnabledDWORD to 1.
- Navigate to
- Restart IIS to apply changes.
- OWIN Self-Hosted:
If you're self-hosting with OWIN, explicitly specify allowed cipher suites in your server setup (requires .NET Framework 4.7.2+ forCipherSuitesPolicy):var httpsOptions = new HttpsSelfHostOptions { ServerCertificate = yourCertificate, EnabledSslProtocols = SslProtocols.Tls12 | SslProtocols.Tls13, CipherSuitesPolicy = new CipherSuitesPolicy(new[] { TlsCipherSuite.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TlsCipherSuite.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, // Add other compliant suites here }) }; using (WebApp.Start<Startup>("https://localhost:44300", options => options.UseHttps(httpsOptions))) { // Run server }
2. Update IS3 Dependencies
Outdated IS3 packages might rely on older cipher defaults. Update all IdentityServer3-related NuGet packages (like IdentityServer3.Core, IdentityServer3.EntityFramework) to their latest available versions—these updates often include fixes for cipher compatibility.
3. Verify Certificate Compatibility
Double-check that your certificate uses a modern key algorithm (RSA 2048+ or ECDSA). Certificates with RSA 1024-bit keys won't work with strong cipher suites, so you'll need to replace it if that's the case.
Identity Server 4 (IS4) is built on ASP.NET Core, so its cipher support is tightly integrated with ASP.NET Core and your host OS:
- Default Behavior: IS4 inherits ASP.NET Core's secure defaults. For .NET Core 3.1+, older insecure ciphers (like 3DES, RC4) are disabled by default, and it prioritizes TLS 1.2/1.3 with AEAD suites (AES-GCM, ChaCha20-Poly1305) which offer both encryption and integrity.
- Custom Configuration: You can explicitly define allowed ciphers in your Kestrel server setup (IS4's default host):
public static IHostBuilder CreateHostBuilder(string[] args) => Host.CreateDefaultBuilder(args) .ConfigureWebHostDefaults(webBuilder => { webBuilder.ConfigureKestrel(options => { options.ConfigureHttpsDefaults(httpsOpts => { httpsOpts.SslProtocols = SslProtocols.Tls12 | SslProtocols.Tls13; httpsOpts.CipherSuitesPolicy = new CipherSuitesPolicy(new[] { TlsCipherSuite.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TlsCipherSuite.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TlsCipherSuite.TLS_CHACHA20_POLY1305_SHA256 }); }); }); webBuilder.UseStartup<Startup>(); }); - OS-Level Control: Like IS3, you can also configure cipher suites globally via Group Policy or Registry—Kestrel will respect these settings unless you override them in code.
- Best Practices: The IS4 team recommends sticking to TLS 1.2/1.3, using only AEAD cipher suites, and avoiding any legacy protocols or ciphers to maintain compliance with modern security standards.
内容的提问来源于stack exchange,提问作者Ryan Blake

