我有一个简单的测试客户机,使用.NET Framework 4.5.2编写,我正试图连接到客户的REST web服务。
代码本身非常简单:
using (var requestHandler = new WebRequestHandler())
{
requestHandler.ClientCertificates.Add(myCertificate);
var url = new Uri(myBaseUrl);
using (var client = new HttpClient(requestHandler) {BaseAddress = url})
{
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;
var endPoint = $"api/MyController/Ticket/12345";
var response = client.GetAsync(endPoint).Result;
response.EnsureSuccessStatusCode();
var content = response.Content.ReadAsStringAsync().Result;
Console.WriteLine(JToken.Parse(content).ToString(Formatting.Indented));
}
}
为了测试这一点,我在本地计算机上运行IIS 10.0,并通过注册表配置SSL/TLS:
\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server\Enabled=1
当启用TLS 1.1且禁用TLS 1.2时,如果我将客户端设置ServicePointManager.SecurityProtocol设置为TLS 1.1,则一切正常。
MyTest: System.AggregateException: One or more errors occurred.
---> System.Net.Http.HttpRequestException: An error occurred while sending the request.
---> System.Net.WebException: The request was aborted: Could not create SSL/TLS secure channel.
at System.Net.HttpWebRequest.EndGetResponse(IAsyncResult asyncResult)
at System.Net.Http.HttpClientHandler.GetResponseCallback(IAsyncResult ar)
--- End of inner exception stack trace ---
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task`1.GetResultCore(Boolean waitCompletionNotification)
at System.Threading.Tasks.Task`1.get_Result()
---> (Inner Exception #0) System.Net.Http.HttpRequestException: An error occurred while sending the request.
---> System.Net.WebException: The request was aborted: Could not create SSL/TLS secure channel.
at System.Net.HttpWebRequest.EndGetResponse(IAsyncResult asyncResult)
at System.Net.Http.HttpClientHandler.GetResponseCallback(IAsyncResult ar)
--- End of inner exception stack trace ---<---
这正是我所期望的。
如果我编辑注册表以启用TLS 1.2并禁用1.1,请重新启动并重试,如果我运行将ServicePointManager.SecurityProtocol设置为TLS 1.2的客户端,则一切正常。
如果我运行我的客户机,将ServicePointManager.SecurityProtocol设置为TLS 1.1,就会出现异常。
所以,我把这个放到客户端的机器上,试着连接到他们的webservice。
我们在运行客户机的机器上运行了一个测试webservice,所以我们只需要处理一个系统的配置。
MyTest: System.AggregateException: One or more errors occurred.
---> System.Net.Http.HttpRequestException: An error occurred while sending the request.
---> System.Net.WebException: The request was aborted: Could not create SSL/TLS secure channel.
at System.Net.HttpWebRequest.EndGetResponse(IAsyncResult asyncResult)
at System.Net.Http.HttpClientHandler.GetResponseCallback(IAsyncResult ar)
--- End of inner exception stack trace ---
--- End of inner exception stack trace ---
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
at System.Threading.Tasks.Task`1.GetResultCore(Boolean waitCompletionNotification)
at System.Threading.Tasks.Task`1.get_Result()
---> (Inner Exception #0) System.Net.Http.HttpRequestException: An error occurred while sending the request. ---> System.Net.WebException: The request was aborted: Could not create SSL/TLS secure channel.
at System.Net.HttpWebRequest.EndGetResponse(IAsyncResult asyncResult)
at System.Net.Http.HttpClientHandler.GetResponseCallback(IAsyncResult ar)
--- End of inner exception stack trace ---<---
所以我尝试我的客户机使用SSL 3、TLS 1.0、tls1.1和tls1.2。无论我尝试哪种,我都会得到
.
记住-这是试图访问在我运行客户端的计算机上运行的webservice。
我检查了注册表,看起来他们确实启用了TLS 1.2。我知道他们已经重新启动,因为他们做了注册表更改。
从我所处的位置来看,TLS 1.2似乎没有在他们的机器上启用,尽管注册和重新启动了。
有什么想法吗?
只是让人困惑的是,当我通过Chrome访问这个网站时,它工作得很好。
查看Chrome开发工具中的安全细节,我们可以看到:
此页是安全的(有效的HTTPS)
与此站点的连接使用的是由。。。
此页上的所有资源都已安全提供。
与此站点的连接使用TLS 1.2(强协议)、RSA(过时的密钥交换)和AES_128_CBV以及HMAC-SHA1(过时的密码)。