如何通过WS-UsernameToken生成正确的Resulting Digest?
问题分析与解决
你的代码核心问题在于对Nonce的处理方式错误——指南里的Nonce是Base64编码后的字符串,你直接把它当成UTF8字符串转成字节数组了,但实际上需要先把这个Base64字符串解码成原始的二进制字节,再和created、password的字节拼接。
具体原因
指南里给出的LKqI6G/AikKCQrN0zqZFlg==是Nonce的Base64表示,它对应的是一段原始二进制数据,而不是普通的UTF8文本。你现在直接用Encoding.UTF8.GetBytes(nonce)得到的是这个Base64字符串本身的字节,而不是Nonce的原始二进制值,这就导致后续的哈希计算完全偏离了预期。
修正后的代码
private string GenerateHashedPassword(string nonceBase64, string created, string password) { // 先把Base64格式的nonce解码成原始二进制字节 byte[] nonceBytes = Convert.FromBase64String(nonceBase64); byte[] createdBytes = Encoding.UTF8.GetBytes(created); byte[] passwordBytes = Encoding.UTF8.GetBytes(password); // 拼接顺序:Nonce原始字节 + Created字节 + Password字节 byte[] combined = new byte[nonceBytes.Length + createdBytes.Length + passwordBytes.Length]; Buffer.BlockCopy(nonceBytes, 0, combined, 0, nonceBytes.Length); Buffer.BlockCopy(createdBytes, 0, combined, nonceBytes.Length, createdBytes.Length); Buffer.BlockCopy(passwordBytes, 0, combined, nonceBytes.Length + createdBytes.Length, passwordBytes.Length); return Convert.ToBase64String(SHA1.Create().ComputeHash(combined)); }
验证结果
当你用指南里的参数调用修正后的函数:
string digestPassword = GenerateHashedPassword("LKqI6G/AikKCQrN0zqZFlg==","2010-09-16T07:50:45Z","userpassword");
得到的结果会和指南里的rmF9lT+uD6gRaU0N7S7L1kjfVms=一致。
内容的提问来源于stack exchange,提问作者LoukMouk
相关产品推荐
相关产品推荐

