You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Identity Server 3禁用不安全加密套件后异常及升级IS4相关咨询

Fixing Identity Server 3 After Disabling TLS_RSA_WITH_3DES_EDE_CBC_SHA

Great question! Let's start with getting Identity Server 3 (IS3) working after disabling that insecure 3DES cipher. The issue almost always boils down to missing compatible strong cipher suites in your server configuration, or outdated dependencies in IS3 itself. Here's how to fix it:

1. Configure Strong Cipher Suites for Your Host

IS3 typically runs on either IIS or an OWIN self-hosted server—here's how to update each:

  • IIS Deployment:
    • Open IIS Manager, navigate to your IS3 site, go to SSL Settings, and ensure "Require SSL" and "Require 128-bit SSL" are checked.
    • Update your system's cipher suite configuration via Group Policy or the Windows Registry:
      • Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers
      • Disable 3DES by setting its Enabled DWORD to 0, then enable modern, secure suites like TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 by setting their Enabled DWORD to 1.
    • Restart IIS to apply changes.
  • OWIN Self-Hosted:
    If you're self-hosting with OWIN, explicitly specify allowed cipher suites in your server setup (requires .NET Framework 4.7.2+ for CipherSuitesPolicy):
    var httpsOptions = new HttpsSelfHostOptions
    {
        ServerCertificate = yourCertificate,
        EnabledSslProtocols = SslProtocols.Tls12 | SslProtocols.Tls13,
        CipherSuitesPolicy = new CipherSuitesPolicy(new[]
        {
            TlsCipherSuite.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
            TlsCipherSuite.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
            // Add other compliant suites here
        })
    };
    using (WebApp.Start<Startup>("https://localhost:44300", options => options.UseHttps(httpsOptions)))
    {
        // Run server
    }
    

2. Update IS3 Dependencies

Outdated IS3 packages might rely on older cipher defaults. Update all IdentityServer3-related NuGet packages (like IdentityServer3.Core, IdentityServer3.EntityFramework) to their latest available versions—these updates often include fixes for cipher compatibility.

3. Verify Certificate Compatibility

Double-check that your certificate uses a modern key algorithm (RSA 2048+ or ECDSA). Certificates with RSA 1024-bit keys won't work with strong cipher suites, so you'll need to replace it if that's the case.


Identity Server 4's Support for Secure Cipher Suites

Identity Server 4 (IS4) is built on ASP.NET Core, so its cipher support is tightly integrated with ASP.NET Core and your host OS:

  • Default Behavior: IS4 inherits ASP.NET Core's secure defaults. For .NET Core 3.1+, older insecure ciphers (like 3DES, RC4) are disabled by default, and it prioritizes TLS 1.2/1.3 with AEAD suites (AES-GCM, ChaCha20-Poly1305) which offer both encryption and integrity.
  • Custom Configuration: You can explicitly define allowed ciphers in your Kestrel server setup (IS4's default host):
    public static IHostBuilder CreateHostBuilder(string[] args) =>
        Host.CreateDefaultBuilder(args)
            .ConfigureWebHostDefaults(webBuilder =>
            {
                webBuilder.ConfigureKestrel(options =>
                {
                    options.ConfigureHttpsDefaults(httpsOpts =>
                    {
                        httpsOpts.SslProtocols = SslProtocols.Tls12 | SslProtocols.Tls13;
                        httpsOpts.CipherSuitesPolicy = new CipherSuitesPolicy(new[]
                        {
                            TlsCipherSuite.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
                            TlsCipherSuite.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
                            TlsCipherSuite.TLS_CHACHA20_POLY1305_SHA256
                        });
                    });
                });
                webBuilder.UseStartup<Startup>();
            });
    
  • OS-Level Control: Like IS3, you can also configure cipher suites globally via Group Policy or Registry—Kestrel will respect these settings unless you override them in code.
  • Best Practices: The IS4 team recommends sticking to TLS 1.2/1.3, using only AEAD cipher suites, and avoiding any legacy protocols or ciphers to maintain compliance with modern security standards.

内容的提问来源于stack exchange,提问作者Ryan Blake

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:42:33