【问题标题】:Force ServicePointManager.SecurityProtocol to TLS 1.2 on all connections在所有连接上强制 ServicePointManager.SecurityProtocol 为 TLS 1.2
【发布时间】:2016-08-10 13:00:41
【问题描述】:

我有一个发送传出请求的 WCF 服务。目前它正在使用SSL 3.0或TLS 1.0。

我发送请求的服务现在只接受TLS 1.2。

我可以在请求之前(以及每个请求)设置SecurityProtocolType,但我希望它对所有传出请求使用TLS 1.2,而不必为每个请求指定它。

此代码为请求正确设置:

<OperationContract(), WebGet(UriTemplate:="...")>
Public Function SomeService()

    System.Net.ServicePointManager.SecurityProtocol = (System.Net.SecurityProtocolType) 3072; // 3072 is TLS 1.2

    // Do request

End Function

但我看不到如何将 WCF 设置为对所有请求使用 TLS 1.2。我已经尝试将上述语句放入Global.asax 中的Application_Start 和Application_BeginRequest,但是在执行请求时,SecurityProtocol 又回到了SSL3/TLS1.0

【问题讨论】:

    标签: .net vb.net wcf ssl tls1.2


    【解决方案1】:

    如果您有权访问注册表,则可以应用以下键: registry key

    这在传输层的 Windows 级别强制执行 TLS 1.2,因此您无需更改任何代码。

    这些是上述文件中更改的键:

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319]
    "SchUseStrongCrypto"=dword:00000001
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319]
    "SchUseStrongCrypto"=dword:00000001
    

    【讨论】:

    • 从技术上讲,这不会强制 1.2,它只是禁用 SSL3 并允许 TLS 1.2 -- 它还允许 TLS 1.0 和 1.1跨度>
    【解决方案2】:

    在 Startup.Auth.cs 文件中添加这一行。

    ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;
    

    这对我们有用。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2015-12-04
      • 2018-08-17
      • 2017-11-28
      • 2023-03-29
      • 2020-06-09
      • 2018-12-10
      • 2021-12-20
      • 1970-01-01
      相关资源
      最近更新 更多