【问题标题】:WCF service and custom CAWCF 服务和自定义 CA
【发布时间】:2016-04-07 07:47:09
【问题描述】:

我已经使用 openssl 创建了我的自定义证书颁发机构 (CA)。然后我使用前一个和来自 IIS 的请求创建了证书。所以现在我有证书链。然后我将第二个绑定到我的 WCF 服务,一切都很好。然后在客户端上,我在受信任的根证书颁发机构中安装了我的 CA 证书,以使其能够识别我的自定义证书。 我的 WCF 服务当前在简单的 http 连接上运行。 服务器端:

<system.serviceModel>
    <behaviors>
        <serviceBehaviors>
            <behavior name="SyncWcfServices.MainServiceBehavior">
                <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true" />
                <serviceDebug includeExceptionDetailInFaults="true" />
            </behavior>
        </serviceBehaviors>
    </behaviors>
    <bindings>
        <wsHttpBinding>
            <binding name="ExtendedMaxSize" maxReceivedMessageSize="2147483647">
                <security mode="None">
                    <transport clientCredentialType="None"></transport>
                </security>
            </binding>
        </wsHttpBinding>
    </bindings>
    <services>
        <service name="SyncWcfServices.MainService" behaviorConfiguration="SyncWcfServices.MainServiceBehavior">
            <endpoint address="/syncService.svc" binding="wsHttpBinding" bindingConfiguration="ExtendedMaxSize" contract="SyncWcfServices.IMainService"></endpoint>
            <endpoint address="mex" binding="mexHttpBinding" contract="IMetadataExchange"></endpoint>
        </service>
    </services>
    <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" />
</system.serviceModel>

客户端:

<system.serviceModel>
    <bindings>
        <wsHttpBinding>
            <binding name="WSHttpBinding_IMainService" maxReceivedMessageSize="2147483647" sendTimeout="00:10:00">
                <security mode="None" />
            </binding>
        </wsHttpBinding>
    </bindings>
    <client>
        <endpoint address="http://localhost/SyncService/SyncService.svc"
binding="wsHttpBinding" bindingConfiguration="WSHttpBinding_IMainService"
contract="SyncServiceReference.IMainService" name="WSHttpBinding_IMainService" />
    </client>
</system.serviceModel>

所以,我需要更改此设置以支持 SSL 连接。我已经阅读了很多帖子如何做到这一点,但总是使用 2 路认证检查,这意味着服务器必须检查客户端证书,客户端必须检查服务器证书。但我只希望客户端使用我安装的 CA 检查服务器证书。服务器将像以前一样使用普通凭据(用户名、密码)进行检查。我认为我必须将双方的安全模式更改为 Transport 并将服务器 mex 端点更改为 mexHttpsBinding 但接下来我应该怎么做?请帮忙解决。 谢谢大家!

【问题讨论】:

    标签: c# wcf ssl ssl-certificate ca


    【解决方案1】:

    终于找到了正确的方法!所以服务器端:

        <system.serviceModel>
        <behaviors>
            <serviceBehaviors>
                <behavior name="SyncWcfServices.MainServiceBehavior">
                    <serviceMetadata httpGetEnabled="true" httpsGetEnabled="true" />
                    <serviceDebug includeExceptionDetailInFaults="true" />
                    <serviceCredentials>
                    <serviceCertificate
                        findValue = "*.mydomain.com"
                        storeLocation = "LocalMachine"
                        storeName = "My"
                        x509FindType = "FindBySubjectName"
                        />
                    </serviceCredentials>
                </behavior>
            </serviceBehaviors>
        </behaviors>
        <bindings>
            <wsHttpBinding>
                <binding name="ExtendedMaxSize" maxReceivedMessageSize="2147483647">
                    <security mode="Transport">
                        <transport clientCredentialType="None"></transport>
                    </security>
                </binding>
            </wsHttpBinding>
        </bindings>
        <services>
            <service name="SyncWcfServices.MainService" behaviorConfiguration="SyncWcfServices.MainServiceBehavior">
                <endpoint address="" binding="wsHttpBinding" bindingConfiguration="ExtendedMaxSize" contract="SyncWcfServices.IMainService"></endpoint>
                <endpoint address="mex" binding="mexHttpsBinding" contract="IMetadataExchange"></endpoint>
                <host>
                    <baseAddresses>
                        <add baseAddress="http://localhost:8095/Design_Time_Addresses/SyncWcfServices/MainService/" />
                    </baseAddresses>
                </host>
            </service>
        </services>
        <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" />
    </system.serviceModel>
    

    客户端:

        <system.serviceModel>
        <behaviors>
            <endpointBehaviors>
                <behavior name = "ServiceCertificate">
                    <clientCredentials>
                        <serviceCertificate>
                            <authentication certificateValidationMode = "ChainTrust"/>
                        </serviceCertificate>
                    </clientCredentials>
                </behavior>
            </endpointBehaviors>
        </behaviors>
        <bindings>
            <wsHttpBinding>
                <binding name="ExtendedMaxSize" maxReceivedMessageSize="2147483647">
                    <security mode="Transport">
                        <transport clientCredentialType="None"></transport>
                    </security>
                </binding>
            </wsHttpBinding>
        </bindings>
        <client>
            <endpoint address="https://localhost/SyncService/SyncService.svc"
             binding="wsHttpBinding" bindingConfiguration="ExtendedMaxSize"
             behaviorConfiguration = "ServiceCertificate"
             contract="SyncServiceReference.IMainService" name="WSHttpBinding_IMainService">
            </endpoint>             
        </client>
    </system.serviceModel>
    

    希望它会帮助别人! 另请参阅 Juval Lowy 和 Michael Montgomery 的“Programming WCF Services”(第 4 版)一书。这是一本好书!

    【讨论】:

      猜你喜欢
      • 2018-11-19
      • 2010-09-17
      • 2011-04-14
      • 1970-01-01
      • 1970-01-01
      • 2013-03-17
      • 1970-01-01
      • 2011-08-26
      • 1970-01-01
      相关资源
      最近更新 更多