【问题标题】:Testing a WCF Service with certificates locally在本地使用证书测试 WCF 服务
【发布时间】:2019-10-27 05:10:07
【问题描述】:

我有一个 WCF 服务,它公开了一种接收内容的方法。客户端将通过 Internet 使用此服务。客户提供以下证书并在我的本地机器上安装如下:

Comodo 中级 .cert 1) 中级认证机构 > Comodo 中级

Comodo 根 .cert 2) 受信任的根证书颁发机构 > Commodo Root

X509 客户端证书 .pem 3) Trusted People Store > 客户端证书

我想测试/模拟一个客户端调用来测试我在本地运行的 web 服务。我安装了证书并将以下绑定添加到我的 WCF 服务配置中

<protocolMapping>
      <add scheme="https" binding="wsHttpBinding"/>
    </protocolMapping>
    <bindings>
      <wsHttpBinding>
        <binding>
          <security mode="Transport">
            <transport clientCredentialType="Certificate"></transport>
          </security>
        </binding>
      </wsHttpBinding>
    </bindings>

我创建了一个测试客户端控制台应用程序并添加了以下配置

<behaviors>
      <endpointBehaviors>
        <behavior name="endpointCredentialBehavior">
          <clientCredentials>
            <clientCertificate findValue="ClientCertificate"
                               storeLocation="LocalMachine"
                               storeName="My"
                               x509FindType="FindBySubjectName" />
          </clientCredentials>
        </behavior>
      </endpointBehaviors>
    </behaviors>
    <bindings>
      <wsHttpBinding>
        <binding name="Binding1">
          <security mode="Transport">
            <transport clientCredentialType="Certificate"/>
          </security>
        </binding>
      </wsHttpBinding>
    </bindings>

我知道在测试和生产环境中,我有一个服务器证书,但是要在本地成功地测试这一切,我是否需要创建一个服务器证书以及如何创建。这可以在同一个盒子上完成,还是我必须使用 SOAP UI 或其他东西?

【问题讨论】:

    标签: wcf certificate


    【解决方案1】:

    如果您有服务证书(由一些正规机构颁发),可以在本地测试,请参考以下链接。
    https://docs.microsoft.com/en-us/dotnet/framework/wcf/feature-details/transport-security-with-certificate-authentication
    当我们使用带证书的传输安全时,我们首先要在客户端和服务器之间建立信任关系,然后如果我们想使用自签名证书,我们可以通过PowerShell来创建证书。请参考以下 Powershell 命令创建自签名证书。

    New-SelfSignedCertificate -DnsName "vabqia864VM" -CertStoreLocation "cert:\LocalMachine\My"
    

    详情
    https://docs.microsoft.com/en-us/powershell/module/pkiclient/new-selfsignedcertificate?view=win10-ps
    对于服务器端,我们应该配置一个带有 SSL 证书的端口,因为我们使用 https 协议(如果我们使用 IIS 来托管这个,网站绑定模块会这样做)。
    https://docs.microsoft.com/en-us/dotnet/framework/wcf/feature-details/how-to-configure-a-port-with-an-ssl-certificate
    对于客户端,我们应该提供一个客户端证书进行身份验证(也可以使用端点行为来完成)。

    ServiceReference1.ServiceClient client = new ServiceReference1.ServiceClient();
    client.ClientCredentials.ClientCertificate.SetCertificate(StoreLocation.LocalMachine, StoreName.My, X509FindType.FindByThumbprint, "9ee8be61d875bd6e1108c98b590386d0a489a9ca");
    

    如果有什么我可以帮忙的,请随时告诉我。

    【讨论】:

      猜你喜欢
      • 2012-08-06
      • 2014-05-11
      • 2010-10-03
      • 1970-01-01
      • 2019-05-10
      • 1970-01-01
      • 1970-01-01
      • 2012-03-24
      • 1970-01-01
      相关资源
      最近更新 更多