【问题标题】:Problem with ssl while using wsl and identity server 4使用 wsl 和身份服务器 4 时出现 ssl 问题
【发布时间】:2023-01-03 04:18:07
【问题描述】:

我已经开发了简单的身份服务器应用程序,它具有用于用户凭据的实体框架存储和具有 OpenId 身份验证的客户端应用程序 asp.net 核心 MVC。它在本地机器上正常工作,但是当我尝试在安装了 ubuntu 20 04 的 wsl 上调试它时,出现以下错误。

AuthenticationException: The remote certificate is invalid according to the validation procedure.

我只是将 wsl 用作 Visual Studio 中的调试目标。在 wsl 机器上安装 .net,生成开发人员证书,然后简单地同时运行 2 个项目。抱歉,但我不知道我应该提供什么代码来调试这里的问题是我在身份服务器端的客户端配置:

new Client
{
 ClientId = "mvc_client",
 ClientSecrets = { new Secret("mvc_client_secret".ToSha256()) },
 AllowedGrantTypes = GrantTypes.Code,
 RequireConsent = false,
 AllowedScopes =
 {
   "dummy_api",
   IdentityServerConstants.StandardScopes.OpenId,
   IdentityServerConstants.StandardScopes.Profile
 },
RedirectUris = { "https://localhost:5000/signin-oidc" }
},

以及客户端的开放 ID:

services.AddAuthentication(config =>
{
            config.DefaultScheme = "Cookie";
            config.DefaultChallengeScheme = "oidc";
        })
               .AddCookie("Cookie")
               .AddOpenIdConnect("oidc", config =>
               {
                   config.Authority = "https://localhost:5001/";
                   //config.Authority = "http://192.168.1.11:5004/";

                   //config.RequireHttpsMetadata = false;
                   config.ClientId = "mvc_client";
                   config.ClientSecret = "mvc_client_secret";
                   config.SaveTokens = true; // persist tokens in the cookie
                   config.ResponseType = "code";
});

尝试使用客户端应用程序登录时出现此错误。如果我只尝试使用身份服务器登录,一切正常。

【问题讨论】:

    标签: c# asp.net-mvc asp.net-core-mvc identityserver4 windows-subsystem-for-linux


    【解决方案1】:

    如果您可以在 Postman 或您的浏览器中访问 oidc 配置地址(在您的情况下应该是:https:/localhost:5001/.well-known/openid-configuration)并且您只是在测试,您可以将 BackchannelHttpHandler 设置为在证书验证时始终返回 true。 同时设置SslProtocols 以允许不同的版本。出于安全原因,应在生产环境中避免这些:

    .
    .
    .AddOpenIdConnect("oidc", config =>
               {
                config.BackchannelHttpHandler = new HttpClientHandler
                  {
                   SslProtocols = SslProtocols.Tls12 | SslProtocols.Tls11 | SslProtocols.Tls12 | SslProtocols.Tls13,
                   ServerCertificateCustomValidationCallback = (message, cert, chain, errors) => true
                  };
    });
    

    【讨论】:

    • 对不起,我应该在哪里添加这个?
    • 在所有客户端应用程序的 program.cs 中。换句话说,无论你有AddOpenIdConnect
    猜你喜欢
    • 2018-11-15
    • 2021-12-07
    • 2020-11-17
    • 2017-07-26
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2020-11-17
    • 1970-01-01
    相关资源
    最近更新 更多