【问题标题】:SSL Webservice: Could not create SSL/TLS secure channelSSL Web 服务:无法创建 SSL/TLS 安全通道
【发布时间】:2012-11-04 23:29:59
【问题描述】:

我的 C# .net 应用程序正在使用 HTTPS 网络服务。由于证书现在即将到期,我正在尝试使用我已获得的新证书(我已使用 javasdks 的 keytool 转换为 .p12 的 .jks 文件)对其进行更新。我认为这很容易,因为我知道该怎么做,但它就是不合作。

到目前为止我做了什么:

  • 已将证书导入到 CURRENT_USER\Personal
  • 将证书导入到 LOCAL_MACHINE\Personal
  • 让正确的用户 (apppoolidentity) 通过 winhttpcertcfg 工具访问证书的私钥。以下是权限列表 证书。
  • 使用 findprivatekey 工具,我还找到了实际的密钥文件,并授予 apppoolidentity 对其的访问权限。 (绝望中)。

    C:\Program Files (x86)\Windows Resource Kits\Tools>winhttpcertcfg -l -c LOCAL_MACHINE\My -s "9000 - Blabla" Microsoft (R) WinHTTP 证书配置工具 版权所有 (C) Microsoft Corporation 2001。

    匹配证书: CN=9000 - 布拉布拉 C=否 L="c/o Blabla AS, Blablaaddress" 欧=957839827 OID.1.2.240.111111.1.9.8=12345678 OID.1.2.240.111111.1.9.2=Blabla 测试 O=BlaBla AS OU=多重允许

    可以访问私钥的其他帐户和组包括: 内置\管理员 NT AUTHORITY\SYSTEM IIS 应用程序\ASP.NET v4.0 内置\用户 NT AUTHORITY\网络服务 DIGITROLLDMZ\IIS_WPG

我访问的网址如下所示:

https://test.blabla.com/blabla-5.0/services/Blabla?wsdl

...如果我从服务器的网络浏览器访问它,我会选择证书,我选择新的证书,它说没关系,绿色和 SSL 按顺序排列,但我的应用程序代码看起来像这样:

public static blabla.service.NettforhandlerService getNettforhandlerService(string applicationPath) 
    {
    blabla.service.NettforhandlerService service = new blabla.service.NettforhandlerService();
    if (System.Configuration.ConfigurationManager.AppSettings["CertificateSerialNumber"] != null && System.Configuration.ConfigurationManager.AppSettings["CertificateSerialNumber"].Length > 0)
    {
        string serviceurl = service.Url;
        X509Store store = new X509Store(StoreName.Root, StoreLocation.LocalMachine);
        store.Open(OpenFlags.ReadOnly);
        X509Certificate2Collection col = store.Certificates.Find(X509FindType.FindBySerialNumber, System.Configuration.ConfigurationManager.AppSettings["CertificateSerialNumber"], true);

        ServicePointManager.Expect100Continue = true;
        ServicePointManager.SecurityProtocol = SecurityProtocolType.Ssl3;
        ServicePointManager.CertificatePolicy = new TrustHBSCertificatePolicy();

        service.ClientCertificates.Add(col[0]);

    }
    return service;
    }

只输出这个错误:

The request was aborted: Could not create SSL/TLS secure channel.

...我在 web.config 中添加了一些跟踪/调试信息,我从错误中发现是这样的:

[Public Key]
  Algorithm: RSA
  Length: 2048
  Key Blob: 30 82 01 0a 02 82 01 01 00 8e a6 72 c2 e1 67 16 e2 be be c3 30 89 8d bb 57 0b 48 f8 1d 09 b1 e3 26 42 c9 45 9e 02 b2 43 49 16 81 94 1b 18 d6 6d ef ....
System.Net Information: 0 : [15624] SecureChannel#32061089 - Certificate is of type X509Certificate2 and contains the private key.
System.Net Information: 0 : [15624] AcquireCredentialsHandle(package = Microsoft Unified Security Protocol Provider, intent  = Outbound, scc     = System.Net.SecureCredential)
System.Net Error: 0 : [15624] AcquireCredentialsHandle() failed with error 0X8009030D.
System.Net Information: 0 : [15624] AcquireCredentialsHandle(package = Microsoft Unified Security Protocol Provider, intent  = Outbound, scc     = System.Net.SecureCredential)
System.Net Error: 0 : [15624] AcquireCredentialsHandle() failed with error 0X8009030D.
System.Net.Sockets Verbose: 0 : [15624] Socket#38259205::Dispose()
System.Net Error: 0 : [15624] Exception in the HttpWebRequest#54558071:: - The request was aborted: Could not create SSL/TLS secure channel.
System.Net Error: 0 : [15624] Exception in the HttpWebRequest#54558071::GetResponse - The request was aborted: Could not create SSL/TLS secure channel.
System.Net Verbose: 0 : [15624] 

我知道这看起来像正确的用户/身份没有被授予对证书的访问权限(来自 winhttpcertcfg),但我很确定它有,这就是我在这里不知所措的原因,

希望有一些认真的 https-certificate/web-service -skills 的人可以在这里帮助我:-)

谢谢。

问候, Jørgen E.

edit1:将标题更改为更精确的名称。 编辑2:新信息:

In EventViewer/Windows Logs/Security there is an event "Audit Failure" connected to this:

Cryptographic operation.

Subject:
    Security ID:        IIS APPPOOL\ASP.NET v4.0
    Account Name:       ASP.NET v4.0
    Account Domain:     IIS APPPOOL
    Logon ID:       0x32498

Cryptographic Parameters:
    Provider Name:  Microsoft Software Key Storage Provider
    Algorithm Name: Not Available.
    Key Name:   {00E1A3F5-7400-41CA-8290-02983473AEAF}
    Key Type:   Machine key.

Cryptographic Operation:
    Operation:  Open Key.
    Return Code:    0x80090010

【问题讨论】:

    标签: c# ssl https


    【解决方案1】:

    无法从日志中提取多少,但是...

    Google-fu 产生以下结果:0x80090010 很可能是证书访问错误。

    据此,我很有可能得出结论,您需要为您的 SSL 证书私钥设置权限 - 以便 IIS 可以访问它。 看: http://www.dotnetnoob.com/2011/01/how-to-give-iis-access-to-private-keys.html

    另一个选项的类似问题:The request was aborted: Could not create SSL/TLS secure channel

    【讨论】:

    • 嗨,感谢您的回复 :-) .. 我现在在此文件夹中找到了一个文件:C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys ...文件名是 a23e3996925c33fec814f8ce35e4b1d9_57324829-0d1c- 4ae4-ae60-1e2849f7749a ...如果我将 applicationpoolidentity 的 READ 访问权限添加到此文件,那么它可以工作! .. 但我无法识别这是什么证书,因此我可以通过适当的方式添加访问权限(winhttpcertcfg):-( .. 任何人都知道如何识别这个?或者也许只是手动添加这个访问权限就足够了?
    • 您可以使用 Microsoft 提供的工具 FindPrivateKey.exe。或者只是删除您的密钥,记下存在的文件列表,然后重新导入证书/密钥(如果您有 PFX),注意创建的新文件。参考:msdn.microsoft.com/ru-ru/library/ms732026.aspx (FindPrivateKey)
    • FindPrivateKey 并且您指定的技术与我想要实现的相反:-) 我知道 machinekeys 文件的文件名,并且想知道这个文件附加到什么证书,导致它不是我正在使用的证书,我已经通过 findprivatekey 确定了我正在使用的证书。
    • 嗯..我知道我使用的是什么证书,并且可以找到相应的机器密钥文件,但是还有另一个机器密钥文件需要“IIS APPPOOL\ASP.NET v4.0”的读取权限“让它工作..(通过手动添加对所有文件的访问使其工作)..我不知道这个文件是做什么的,这就是我想知道的。无论如何,我现在可以正常工作了,所以没问题 - 感谢您的帮助:)
    • “你需要为你的 SSL 证书私钥设置权限”——这对我有帮助,现在已经回来了两次 :) 谢谢
    【解决方案2】:

    问题已解决,似乎缺少中间证书,将其导入到 MMC 的中间证书中,一切都很好:-)

    【讨论】:

      【解决方案3】:

      回复晚了,但我遇到了同样的问题,以下更改为我解决了这个问题。 换行试试 ServicePointManager.SecurityProtocol = SecurityProtocolType.Ssl3; 与下面的 - ServicePointManager.SecurityProtocol = (SecurityProtocolType)3072;

      P.S - 我在我的应用程序中使用 .Net framework 3.5。

      【讨论】:

        猜你喜欢
        • 2017-04-02
        • 2021-12-13
        • 2014-12-26
        • 2017-02-10
        • 2017-08-22
        • 2016-08-03
        • 2018-06-17
        • 1970-01-01
        • 2023-04-08
        相关资源
        最近更新 更多