【问题标题】:Requirements to enforce TLS 1.2强制实施 TLS 1.2 的要求
【发布时间】:2020-06-09 21:13:41
【问题描述】:

应用程序托管在 Azure PAAS 上。以下更改已经存在

  1. Azure 应用服务 TLS 设置为 1.2,HTTPSOnly 设置为关闭
  2. 服务 web 配置 httpRuntime targetFramework 设置为 4.7.1

为了确保我的应用程序的传入和传出请求符合 TLS 1,我还需要进行哪些更改 2.

【问题讨论】:

  • 我认为它应该可以解决问题。您仍然应该使用诸如 ssllabs.com/ssltest 之类的工具来检查您的网站。
  • 据我所知,就是这样。我要补充的一件事是(尽管它可能与问题无关),永远不要在您的应用程序中指定 TLS 版本。配置您的代码,让操作系统决定 TLS 版本。
  • 现在有更新吗?如果它对你有帮助,你可以接受它作为答案。

标签: .net azure tls1.2


【解决方案1】:

从 2018 年 6 月 30 日开始,Azure 应用服务中的所有新应用都将默认使用 TLS 1.2 创建。

在网站根目录下找到global.asax文件,右击查看代码。在这个文件中,应该有一个Application_Start 方法。

在此方法中,添加这些行以强制 TLS 1.2

protected void Application_Start()
{
    //**Add these lines**
    if (ServicePointManager.SecurityProtocol.HasFlag(SecurityProtocolType.Tls12) == false)
    {
         ServicePointManager.SecurityProtocol = ServicePointManager.SecurityProtocol | SecurityProtocolType.Tls12;
    }
    //**Add these lines**

    AreaRegistration.RegisterAllAreas();
    GlobalConfiguration.Configure(WebApiConfig.Register);
    FilterConfig.RegisterGlobalFilters(GlobalFilters.Filters);
    RouteConfig.RegisterRoutes(RouteTable.Routes);
    BundleConfig.RegisterBundles(BundleTable.Bundles);
}

此外,您可以使用 Resource Manager Policies 在 Azure WebApps 上强制实施 TLS 版本。

【讨论】:

    猜你喜欢
    • 2020-04-05
    • 2023-04-07
    • 1970-01-01
    • 2023-03-29
    • 2018-12-10
    • 2018-03-13
    • 2021-12-20
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多