2011-03-29 77 views
0

我正在使用WCF通過MSMQ(net.msmq協議)發送消息。 BizTalk服務器收到消息並處理它,一切進展順利。但是,當我查看SVCLOG時,當我將MsmqProtectionLevel專門設置爲Sign時,我看到該消息已加密。指定簽名時加密WCF消息(net.msmq)

是否有其他人看到過這種行爲?是否有可能停止加密?我的一些消息超過1MB,加密使事情變得非常緩慢。

在此先感謝!

ChannelFactory<OnRampEntry> Factory 
    { 
    get 
    { 
     if (factory == null) 
     { 
      lock (this) 
      { 
       if (factory == null) 
       { 
       var uri = ResolveQueueName(new Uri(Url)); 
       var identity = EndpointIdentity.CreateDnsIdentity(BizTalkIdentity); 
       var binding = new NetMsmqBinding(NetMsmqSecurityMode.Both) 
       { 
        DeadLetterQueue = DeadLetterQueue.System, 
        ExactlyOnce = true 
       }; 
       binding.Security.Message.ClientCredentialType = MessageCredentialType.Certificate; 
       binding.Security.Transport.MsmqProtectionLevel = System.Net.Security.ProtectionLevel.Sign; 
       binding.Security.Transport.MsmqAuthenticationMode = MsmqAuthenticationMode.WindowsDomain; 
       binding.Security.Transport.MsmqSecureHashAlgorithm = MsmqSecureHashAlgorithm.Sha1; 
       factory = new ChannelFactory<OnRampEntry>(binding, new EndpointAddress(uri, identity, (AddressHeaderCollection) null)); 
       factory.Endpoint.Behaviors.Add(new LogonCertificateBehavior()); 
       factory.Credentials.ServiceCertificate.SetDefaultCertificate(StoreLocation.LocalMachine, StoreName.TrustedPeople, X509FindType.FindBySubjectName, BizTalkIdentity); 
       factory.Open(); 
       } 
      } 
     } 
     return factory; 
    } 
    } 

    /// <summary> 
    /// MSMQ does not allow a DNS alias to be used in a queue name, e.g. "net.msmq://alias/private$/queue". 
    /// <b>ResolveQueueName</b> will tranlsate an alias to its actual machine name. 
    /// </summary> 
    /// <param name="uri"></param> 
    /// <returns></returns> 
    Uri ResolveQueueName(Uri uri) 
    { 
    var hostName = uri.DnsSafeHost; 

    try 
    { 
     var hostEntry = Dns.GetHostEntry(hostName); 
     var resolved = new Uri(uri.ToString().Replace(hostName, hostEntry.HostName)); 

     if (log.IsDebugEnabled) 
      log.Debug(string.Format("Resolved '{0}' to '{1}'.", uri, resolved)); 
     return resolved; 
    } 
    catch (SocketException e) 
    { 
     if (e.SocketErrorCode == SocketError.HostNotFound) 
      return uri; 
     throw e; 
    } 
    } 

回答

1

消息被加密的原因是使用NetMsmqSecurityMode.Both - 傳輸和消息安全。

var binding = new NetMsmqBinding(NetMsmqSecurityMode.Both) 

在傳輸層,在配置上面採用

binding.Security.Transport.MsmqProtectionLevel = System.Net.Security.ProtectionLevel.Sign; 

展望WCF記錄它是不可能的,看看有什麼被設置在傳輸層,如消息級加密到位。

不幸的是,這並沒有回答如何在不使用證書來加密郵件正文的情況下籤署郵件(使用X.509證書)的問題。