【发布时间】:2021-02-27 18:21:32
【问题描述】:
我使用 asp.net core 2.2 并在我们的互联网服务器上将应用程序作为控制台应用程序 (kestrel) 启动。
附加了有效的公共证书(.pfx,请参阅下面的 appsettings.json 中的配置)。
问题:
- 如果我通过互联网在内部和外部测试应用程序,我无法理解任何问题(任何事情都按预期工作)。
- 启动应用程序没有问题。
- 但偶尔(不理解,不挑衅),我在控制台中有错误消息(崩溃例外)(见下文)。
- 当崩溃发生时,它们通常会发生多次(大多数 > 10 次) - 不幸的是,我无法说出具体发生在什么时间范围内(因为没有将时间戳写入控制台)。
- 此外,我经常(奇怪)在错误消息后的控制台上有很多空行)。
Appsettings.json:
{
"Logging": {
"LogLevel": {
"Default": "Warning"
}
},
"AllowedHosts": "*"
,
"Kestrel": {
"EndPoints": {
"Http": {
"Url": "http://localhost:5001"
},
"HttpsInlineCertFile": {
"Url": "https://192.168.3.3",
"Protocols": "Http1AndHttp2",
"Certificate": {
"Path": "./certificate_2021.pfx",
"Password": "Passwort",
"AllowInvalid": "true"
}
}
}
}
}
注意:证书未导入服务器的证书存储区(我认为这不是必需的)。
我已经在互联网上搜索了几天,但没有找到任何提示,这使我朝着正确的方向前进。
感谢您的帮助。
例外:
fail: Microsoft.AspNetCore.Server.Kestrel[0]
Uncaught exception from the OnConnectionAsync method of an IConnectionAdapter.
System.Net.InternalException: Exception of type 'System.Net.InternalException' was thrown.
at System.Net.SecurityStatusAdapterPal.GetSecurityStatusPalFromInterop(SECURITY_STATUS win32SecurityStatus, Boolean attachException)
at System.Net.Security.SecureChannel.GenerateToken(Byte[] input, Int32 offset, Int32 count, Byte[]& output)
at System.Net.Security.SecureChannel.NextMessage(Byte[] incoming, Int32 offset, Int32 count)
at System.Net.Security.SslState.StartSendBlob(Byte[] incoming, Int32 count, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.ProcessReceivedBlob(Byte[] buffer, Int32 count, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartReadFrame(Byte[] buffer, Int32 readBytes, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartReceiveBlob(Byte[] buffer, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.CheckCompletionBeforeNextReceive(ProtocolToken message, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartSendBlob(Byte[] incoming, Int32 count, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.ProcessReceivedBlob(Byte[] buffer, Int32 count, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.StartReadFrame(Byte[] buffer, Int32 readBytes, AsyncProtocolRequest asyncRequest)
at System.Net.Security.SslState.PartialFrameCallback(AsyncProtocolRequest asyncRequest)
--- End of stack trace from previous location where exception was thrown ---
at System.Net.Security.SslState.ThrowIfExceptional()
at System.Net.Security.SslState.InternalEndProcessAuthentication(LazyAsyncResult lazyResult)
at System.Net.Security.SslState.EndProcessAuthentication(IAsyncResult result)
at System.Net.Security.SslStream.EndAuthenticateAsServer(IAsyncResult asyncResult)
at System.Net.Security.SslStream.<>c.<AuthenticateAsServerAsync>b__51_1(IAsyncResult iar)
at System.Threading.Tasks.TaskFactory`1.FromAsyncCoreLogic(IAsyncResult iar, Func`2 endFunction, Action`1 endAction, Task`1 promise, Boolean requiresSynchronization)
--- End of stack trace from previous location where exception was thrown ---
at Microsoft.AspNetCore.Server.Kestrel.Https.Internal.HttpsConnectionAdapter.InnerOnConnectionAsync(ConnectionAdapterContext context)
at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.HttpConnection.ApplyConnectionAdaptersAsync()
【问题讨论】:
-
.NET Core 2.2 已停产,尝试使用 2.1 或切换到 3.1。它们是 LTS 版本,定期收到不同的修复
-
您可能遇到了 TLS 问题。 Microsoft 于 6 月在服务器上禁用了 TLS 1.0/1.1。所以客户端现在必须指定 TLS 版本 1.2/1.3。我不认为 1.3 将与 Core 2.2 一起使用,但 1.2 将在控制台中运行。因此,您需要将以下内容添加到您的 c# 中:ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;
-
@jdweng:谢谢-这(TLS 1.1)可能是该行为的合乎逻辑的原因-一旦客户端使用1.1加载应用程序就会崩溃-无法理解,因为我使用1.2进行测试.. . 我现在将对此进行更详细的调查...
-
证书必须与 TLS 1.2 兼容(参见 wiki en.wikipedia.org/wiki/Transport_Layer_Security)并且操作系统必须支持 TLS 1.2。 Core 在操作系统位于 Core 下的机器上运行。 Core 就像在 Windows(和其他操作系统)下运行的 Net。因此,您可以使用 Core 2.2 运行 TLS 1.2,但操作系统必须支持 TLS 1.2
-
TLS 1.2 端到端工作没有问题 - 这不是问题。我只能为 TLS 1.1 配置 IE11(我发现的唯一浏览器)(希望能够引发崩溃)。 “不幸的是”,我无法仅使用 TLS 1.1 引发崩溃。我进一步调查......
标签: c# asp.net-core ssl kestrel