【问题标题】:How can I debug a WCF client using username/password in the header encrypted with SSL如何使用 SSL 加密的标头中的用户名/密码调试 WCF 客户端
【发布时间】:2011-12-09 13:57:01
【问题描述】:

我仍在尝试让 WCF 与 CXF 对话。我使用了来自http://rocksolidknowledge.com/Download.mvc 的示例,在我看来代码可以正常工作,因为当我更改客户端中的用户名时,我会在服务中看到新的用户名。

我尝试在客户端 app.config 中添加日志记录以保存发送到服务的内容。

<?xml version="1.0" encoding="utf-8" ?>
<configuration>
    <system.serviceModel>
        <bindings>
            <wsHttpBinding>
              <binding name="WSHttpBinding_Av1Service" closeTimeout="00:01:00"
                  openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00"
                  bypassProxyOnLocal="false" transactionFlow="false" hostNameComparisonMode="StrongWildcard"
                  maxBufferPoolSize="524288" maxReceivedMessageSize="65536"
                  messageEncoding="Text" textEncoding="utf-8" useDefaultWebProxy="true"
                  allowCookies="false">

                <readerQuotas maxDepth="32" maxStringContentLength="8192" maxArrayLength="16384"
                      maxBytesPerRead="4096" maxNameTableCharCount="16384" />
                <reliableSession ordered="true" inactivityTimeout="00:10:00"
                    enabled="false" />

                <security mode="TransportWithMessageCredential">
                        <transport clientCredentialType="None" proxyCredentialType="None"
                            realm="" />
                        <message clientCredentialType="UserName" negotiateServiceCredential="true"
                            algorithmSuite="Default" establishSecurityContext="true" />
                    </security>

                <!--
                <security mode="None">
                  <transport clientCredentialType="None" proxyCredentialType="None"
                      realm="" />
                  <message clientCredentialType="UserName" negotiateServiceCredential="true"
                      algorithmSuite="Default" establishSecurityContext="true" />
                </security>
                -->
              </binding>
            </wsHttpBinding>
        </bindings>
      <behaviors>
        <endpointBehaviors>

          <behavior name="client">
            <clientCredentials>
              <serviceCertificate>
                <authentication certificateValidationMode="None"/>
              </serviceCertificate>
            </clientCredentials>
          </behavior>
        </endpointBehaviors>
      </behaviors>
        <client>

            <endpoint address="https://darsdevlaptop:8015/DarsWebServices/services/av1" binding="wsHttpBinding"
                bindingConfiguration="WSHttpBinding_Av1Service" contract="Av1ServiceReference.Av1Service"
                name="WSHttpBinding_Av1Service" />

          <!--
            <endpoint 
              address="http://localhost:9015/DarsWebServices/services/av1" binding="wsHttpBinding"
                bindingConfiguration="WSHttpBinding_Av1Service" contract="Av1ServiceReference.Av1Service"
                name="WSHttpBinding_Av1Service" />
          -->
        </client>
      <diagnostics>
        <messageLogging logEntireMessage="true"
                        logMalformedMessages="true"
                        logMessagesAtServiceLevel="true"
                        logMessagesAtTransportLevel="true"
                        maxMessagesToLog="3000"
                        maxSizeOfMessageToLog="2000"/>
      </diagnostics>
    </system.serviceModel>
</configuration>

此配置生成一个 client_msg.svclog 文件,我可以使用 Microsoft 服务跟踪查看器查看该文件。在这个文件里面我看到了

E2ETraceEvent xmlns="http://schemas.microsoft.com/2004/06/E2ETraceEvent">
<System xmlns="http://schemas.microsoft.com/2004/06/windows/eventlog/system">
<EventID>0</EventID>
<Type>3</Type>
<SubType Name="Information">0</SubType>
<Level>8</Level>
<TimeCreated SystemTime="2011-12-08T15:27:46.1360000Z" />
<Source Name="System.ServiceModel.MessageLogging" />
<Correlation ActivityID="{00000000-0000-0000-0000-000000000000}" />
<Execution ProcessName="Clieint.vshost" ProcessID="5660" ThreadID="10" />
<Channel />
<Computer>DARSDEVLAPTOP</Computer>
</System>
<ApplicationData>
<TraceData>
<DataItem>
<MessageLogTraceRecord Time="2011-12-08T10:27:46.1320000-05:00" Source="ServiceLevelSendRequest" Type="System.ServiceModel.Channels.BodyWriterMessage" xmlns="http://schemas.microsoft.com/2004/06/ServiceModel/Management/MessageTrace">
<HttpRequest>
<Method>POST</Method>
<QueryString></QueryString>
<WebHeaders>
<VsDebuggerCausalityData>uIDPo7bjbPmwsKdKqJIT7OFhvN8AAAAA+hhv3g5Q+UymaaUAoh1MoXMwGPaCPSlAoTQw7kFj3m8ACQAA</VsDebuggerCausalityData>
</WebHeaders>
</HttpRequest>
<s:Envelope xmlns:a="http://www.w3.org/2005/08/addressing" xmlns:s="http://www.w3.org/2003/05/soap-envelope">
<s:Header>
<a:Action s:mustUnderstand="1">http://tempuri.org/IPing/Ping</a:Action>
<a:MessageID>urn:uuid:85d46f93-9798-41c4-a8fd-e862b3858d46</a:MessageID>
<a:ReplyTo>
<a:Address>http://www.w3.org/2005/08/addressing/anonymous</a:Address>
</a:ReplyTo>
</s:Header>
<s:Body>
<Ping xmlns="http://tempuri.org/"></Ping>
</s:Body>
</s:Envelope>
</MessageLogTraceRecord>
</DataItem>
</TraceData>
</ApplicationData>

我很失望没有找到任何关于用户名或密码的参考

<s:Header>
    <a:Action s:mustUnderstand="1">http://tempuri.org/IPing/Ping</a:Action>
    <a:MessageID>urn:uuid:85d46f93-9798-41c4-a8fd-e862b3858d46</a:MessageID>
    <a:ReplyTo>
        <a:Address>http://www.w3.org/2005/08/addressing/anonymous</a:Address>
    </a:ReplyTo>
</s:Header>

我也尝试运行 fiddler2,但我也没有看到任何用户名/密码。 那么发生了什么?我错过了如何使用视图工具吗?它不是在标题中传递的吗?如果是这样,我将如何解决这个问题!

只是为了解释我为什么关心这个:

  • 我将基于示例的代码提供给我的客户与 CXF 交谈 服务和我得到的报告是用户名/密码 没有通过。
  • 我实际上无法自己调试通信,因为我似乎无法 让 WCF 从 CXF 获得测试证书。
  • WCF 到 WCF 一切正常,但客户不是这样 需要。

我感到非常难过。感谢您的帮助。

【问题讨论】:

    标签: wcf wcf-security


    【解决方案1】:

    我没有看到正在设置的诊断源。比如这个。

    <system.diagnostics>
      <sources>
          <source name="System.ServiceModel.MessageLogging">
            <listeners>
                     <add name="messages"
                     type="System.Diagnostics.XmlWriterTraceListener"
                     initializeData="c:\logs\messages.svclog" />
              </listeners>
          </source>
        </sources>
    </system.diagnostics>
    

    希望你看过这个msdn article.

    【讨论】:

    • 感谢您的帮助。现在我看到 所以我更接近了,但我仍然无法证明正在发送用户名和密码。
    • 如果您看到用户名密码在日志中传递。你的客户端很好。没有什么可以进一步证明客户端。是时候看看服务器了:)你能控制它吗?
    • 我没有看到用户名和密码,因为我得到了 。但是基于social.msdn.microsoft.com/Forums/en/wcf/thread/…,也许这是我能做的最好的了。
    猜你喜欢
    • 1970-01-01
    • 2016-07-24
    • 1970-01-01
    • 1970-01-01
    • 2011-09-25
    • 2016-02-27
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多