【问题标题】:Certificate based authentication in WCFWCF 中基于证书的身份验证
【发布时间】:2018-02-24 20:38:33
【问题描述】:

我正在尝试使用 msdn 示例 https://msdn.microsoft.com/en-us/library/ms731074(v=vs.90).aspx 了解基于证书的身份验证

这是服务器代码:

WSHttpBinding binding = new WSHttpBinding(); 
binding.Security.Mode = SecurityMode.Transport;
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate;

// Create the URI for the endpoint. 
Uri httpUri = new Uri("https://localhost/Calculator");

// Create the service and add an endpoint. 
ServiceHost myServiceHost = new ServiceHost(typeof(ServiceModel.Calculator), httpUri); 
myServiceHost.AddServiceEndpoint(typeof(ServiceModel.ICalculator), binding, "");

// Open the service. 
myServiceHost.Open();

Console.WriteLine("Listening..."); 
Console.ReadLine();

// Close the service. 
myServiceHost.Close();

这是我写的客户端代码:

ChannelFactory<ICalculator> factory = null;

WSHttpBinding binding = new WSHttpBinding();
binding.Security.Mode = SecurityMode.Transport;
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate;

EndpointAddress address = new EndpointAddress("https://localhost/Calculator");

factory = new ChannelFactory<ICalculator>(binding, address);

System.Net.ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls | SecurityProtocolType.Tls11 | SecurityProtocolType.Tls12 | SecurityProtocolType.Ssl3;

factory.Credentials.ClientCertificate.SetCertificate(StoreLocation.CurrentUser, StoreName.My, X509FindType.FindBySubjectName, "sroger");

ICalculator channel = factory.CreateChannel();

int y = channel.add(9, 8);

我收到以下异常:

在 mscorlib.dll 中发生“System.ServiceModel.CommunicationException”类型的未处理异常

附加信息:向https://localhost/Calculator 发出 HTTP 请求时出错。这可能是由于在 HTTPS 情况下未使用 HTTP.SYS 正确配置服务器证书。这也可能是由于客户端和服务器之间的安全绑定不匹配造成的。

我在同一台机器上运行客户端和服务器。而“sroger”是我当前用户\个人\证书中的证书,它对应于我的机器名.. 不知道从这里做什么..有什么想法吗? 在服务器代码中,服务器使用什么证书?

谢谢

古鲁马尔。

【问题讨论】:

    标签: wcf certificate


    【解决方案1】:

    https://msdn.microsoft.com/en-us/library/ms731074(v=vs.90).aspx 您使用的示例不完整。 使用 https wcf 服务需要有效的服务器证书才能工作,在您的情况下,客户端和服务器证书都是必需的。 这是因为客户端和服务器都需要在 HTTPS 连接中相互信任。

    要开始使用,请阅读https://docs.microsoft.com/en-us/dotnet/framework/wcf/feature-details/message-security-with-mutual-certificates,这是一个更完整的示例,其中包括指定证书来验证服务。

    要通过 https 运行托管的 WCF 库,您需要按顺序执行以下操作:

    1. 使用 X.509 证书配置端口(已 回答 webHttpBinding with certificate)
    2. 从您的服务器,为您的公用名创建证书请求 服务器完全限定域名,或至少包括您的服务器完全限定域名的 DNS subjectAltName。 (有不同的方法可以做到这一点,你可能已经知道了 不过)
    3. 颁发证书并在您的服务器上安装证书
    4. 从托管 WCF 的应用程序的程序集文件中获取应用程序 ID 库(即[装配: Guid("5870aeed-caca-4734-8b09-5c0615402bcf")]) 抢证 通过查看证书属性获得指纹。
    5. 以管理员身份打开 CMD 并运行此命令将 X.509 证书绑定到使用的端口 通过您在服务器上的应用

      netsh http 添加 sslcert ipport=0.0.0.0:443 certash= appid={} certstorename=MY

      netsh http add iplisten ipaddress=0.0.0.0:443

    将此添加到您的服务器代码中:

    myServiceHost.Credentials.ServiceCertificate.SetCertificate(StoreLocation.LocalMachine, StoreName.My, X509FindType.FindBySerialNumber, "<certificate thumbprint>");
    

    在您的客户端代码中,通过完全限定的域名引用您的服务器地址,该证书指定为证书公用名或主题替代名称

    【讨论】:

      猜你喜欢
      • 2016-10-02
      • 1970-01-01
      • 2021-06-21
      • 1970-01-01
      • 2017-01-23
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多