Poco NetSSL_Win TLS1.3获取Schannel凭据失败问题求助
使用Poco NetSSL_Win配置TLS 1.3服务器时出现Schannel算法不兼容错误
运行代码时触发如下错误:
Server error: SSL Exception: Failed to acquire Schannel credentials: The client and server cannot communicate because they do not possess a common algorithm.
相关环境与关键现象:
- 系统:Windows 11,已启用TLS 1.3
- 证书:按照NetSSL_Win文档创建自签名证书,安装在Windows的Local User证书存储中
- 异常特征:无客户端尝试连接时也会触发该错误;相同证书和代码在TLS 1.2环境下可正常运行
卡在此问题多日,求解决指导。
#include <Poco/Net/NetSSL.h> #include <Poco/Net/Context.h> #include <Poco/Net/SecureServerSocket.h> #include <Poco/Net/SecureStreamSocket.h> #include <Poco/Net/SocketAddress.h> #include <Poco/Exception.h> #include <schannel.h> #include <exception> #include <iostream> #include <string> #include <cstdlib> constexpr unsigned short kPort = 9443; const std::string kServerCertificateSubject = "insertCN"; constexpr int kServerContextOptionsMachineStore = Poco::Net::Context::OPT_TRUST_ROOTS_WIN_CERT_STORE; void runServer(Poco::Net::Context::Ptr context) { try { Poco::Net::SocketAddress address("127.0.0.1", kPort); Poco::Net::SecureServerSocket serverSocket(address, 64, context); std::cout << "TLS server listening on 127.0.0.1:" << kPort << std::endl; while (true) { Poco::Net::SecureStreamSocket client(serverSocket.acceptConnection()); char buffer[256] = {}; const int received = client.receiveBytes(buffer, sizeof(buffer)); if (received <= 0) { continue; } std::string request(buffer, received); std::cout << "Server received: " << request << std::endl; const std::string response = "Echo over TLS -> " + request; client.sendBytes(response.data(), static_cast<int>(response.size())); } } catch (const Poco::Exception& ex) { std::cerr << "Server error: " << ex.displayText() << std::endl; } catch (const std::exception& ex) { std::cerr << "Server error: " << ex.what() << std::endl; } } int main() { try { std::cout << "Starting Poco TLS server..." << std::endl; Poco::Net::initializeSSL(); Poco::Net::Context::Ptr context = new Poco::Net::Context( Poco::Net::Context::TLS_SERVER_USE, kServerCertificateSubject, Poco::Net::Context::VERIFY_NONE, kServerContextOptionsMachineStore, Poco::Net::Context::CERT_STORE_MY); context->requireMinimumProtocol(Poco::Net::Context::PROTO_TLSV1_3); runServer(context); Poco::Net::uninitializeSSL(); } catch (const Poco::Exception& ex) { std::cerr << "Fatal Poco exception: " << ex.displayText() << std::endl; } catch (const std::exception& ex) { std::cerr << "Fatal std::exception: " << ex.what() << std::endl; } catch (...) { std::cerr << "Fatal unknown exception." << std::endl; } return 0; }
内容的提问来源于stack exchange,提问作者Lander Wallis
相关产品推荐
相关产品推荐

