【问题标题】:ASP.Net Core API won't work using SSL browser throws ERR_CONNECTION_RESETASP.Net Core API 无法使用 SSL 浏览器抛出 ERR_CONNECTION_RESET
【发布时间】:2020-10-08 04:55:44
【问题描述】:

我正在使用 ASP.NET Core Web 应用程序在 Visual Studio 中构建一个 API,但是从几天前开始它就不再工作了。当我使用 IIS Express 从 Visual Studio 运行 API 时,浏览器中出现错误:“ERR_CONNECTION_RESET”。

当我禁用 SSL 时应用程序确实可以工作,但它应该(并且之前)在启用 SSL 的情况下工作。

我尝试过的事情:

  • 更改端口(在正确范围内)
  • 删除localhost证书并修复Visual Studio,提示新建SSL证书
  • 删除 .VS 文件并以管理员模式重新启动 VS
  • 删除applicationhost.config并以管理员模式重启VS
  • 使用预构建的 WeatherAPI 创建了一个新应用程序,但也存在同样的问题
  • 使用 Jexus 运行 SSL 诊断并获得以下结果
System Time: 18/06/2020 14:40:58

Processor Architecture: AMD64

OS: Microsoft Windows NT 10.0.18363.0

Server Type: IIS Express

SERVER SSL PROTOCOLS

PCT 1.0:

PCT 1.0 is not secure. OS default is used. You might explicitly disable it via registry.

SSL 2.0: 

SSL 2.0 is not secure. OS default is used. You might explicitly disable it via registry.

SSL 3.0: 

SSL 3.0 is not secure. OS default is used. You might explicitly disable it via registry.

TLS 1.0: 

TLS 1.0 is not secure. OS default is used. You might explicitly disable it via registry.

TLS 1.1: 

TLS 1.1 is not secure. OS default is used. You might explicitly disable it via registry.

TLS 1.2: 

SChannel EventLogging: 1 (hex)

To tune TLS related settings, please follow https://support.microsoft.com/en-us/kb/187498 or try out IIS Crypto from https://www.nartac.com/Products/IISCrypto/.

Microsoft documentation on cipher suites can be found at https://docs.microsoft.com/en-us/windows/desktop/secauthn/cipher-suites-in-schannel.

-----
[W3SVC/1]
ServerComment  : WebSite1
ServerAutoStart: True
ServerState    : Stopped

BINDING: http *:8080:localhost

我还通过 Regedit 检查了子键,但在 HKey_Local_Machine\System\CurrentControlSet\Control\SecurityProviders \SCHANNEL\Protocols\ 中找不到子键

我完全不知道会是什么

编辑:在另一台 PC 上尝试过,它似乎可以正常工作

【问题讨论】:

  • 你可能会尝试运行一些诊断,docs.jexusmanager.com/tutorials/ssl-diagnostics.html 可能 HTTP API 中的证书映射已被删除。
  • 您使用的是哪个浏览器和版本?
  • @LexLi 感谢您的评论,我这样做了,并将信息添加到主要问题中。老实说,我真的不知道结果到底意味着什么,所以我去了它推荐的网站并尝试通过 regedit 找到 Protocols 中的子键,但没有。
  • @Nenad 也感谢您的评论。我使用 Chrome 作为我的标准浏览器(版本 83.0.4103.106),但在 FireFox、Edge 和 Opera 中出现了同样的错误。
  • 报告显示,只有一个站点具有 HTTP 绑定。毫无疑问,HTTPS 根本不起作用。我怀疑你是否在 Visual Studio 中正确配置了项目,因为这应该会生成 HTTPS 绑定。

标签: visual-studio api asp.net-core ssl iis


【解决方案1】:

根据报告中的绑定配置,您的项目中没有https绑定。

绑定:http *:8080:localhost

请确保您在创建 AspDotNET CoreAPI 项目时选中了配置 HTTPS 绑定的选项。

这将在Startup.cs 文件中添加额外的代码 sn-ps。

//Adding middlewares for redirecting HTTP request to HTTPS
            app.UseHttpsRedirection();

以及launchSettings.json文件中的附加HTTPS绑定配置。

另外,大部分浏览器开始只支持TLS1.2,请确保没有禁用TLS1.2。
如果问题仍然存在,请随时告诉我。

【讨论】:

  • 感谢您的回复!我的项目已完全按照您的描述设置,但我还按照您的步骤创建了一个新项目,只是为了更好地衡量。可悲的是,问题仍然存在。我尝试在与我不同的计算机上运行该项目,并且我的项目似乎使用 HTTPS 正常工作,所以我猜我的 PC / VS 很可能有问题。 (我也会将它添加到问题中)
  • 您电脑中的其他网站是否可以通过 https 正常工作?另外,在IIS express中托管WebAPI项目时,launchSettings中是否有https绑定,右下角IIS Express托盘图标中有绑定配置?
猜你喜欢
  • 2021-07-22
  • 2021-10-04
  • 1970-01-01
  • 1970-01-01
  • 2018-06-29
  • 2016-11-12
  • 2017-03-22
  • 1970-01-01
  • 2017-04-29
相关资源
最近更新 更多