HttpClient https request fails using hostname, but works using IP address

Viewed 1908

I am new to web stuff in general. Not sure what the issue is here.

I have a machine with IIS running a ASP NET Core REST API on https. I can confirm the GET is working via Google Chrome on my machine by doing either

I confirmed the POST action is working using Postman (again ignoring invalid certificate). Everything is fine till I try and write a client application.

I have the following code.

var ip = Dns.GetHostAddresses("test-machine");
// ip contains the correct IP 

using (var hc = new HttpClient())
{
    hc.GetAsync(@"https://test-machine/api/Example").Wait();
}

This code fails. I get an System.AggregateException: 'One or more errors occurred.' with 4 exceptions stacked up on top of one another.

  1. HttpRequestException: An error occurred while sending the request.
  2. WebException: The underlying connection was closed: An unexpected error occurred on a send.
  3. IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host.
  4. SocketException: An existing connection was forcibly closed by the remote host

If I change the code to use the IP instead:

using (var hc = new HttpClient())
{
    hc.GetAsync(@"https://10.0.0.21/api/Example").Wait();
}

Then the request works as expected I.e. as with Chrome, I get a certificate problem:

AuthenticationException: The remote certificate is invalid according to the validation procedure.

What am I doing wrong? The Dns is clearly able to get the correct IP, I've seen it in the IPAddress[] returned by GetHostAddresses. Why is the HttpClient not resolving the IP - or is it resolving the IP with another problem?

I have tried

ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;

and

ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls | SecurityProtocolType.Tls11 | SecurityProtocolType.Tls12;

but this makes no difference. Using the

ServicePointManager.ServerCertificateValidationCallback

Also doesn't work as it never reaches the point of calling the callback. It's failing before then.

I suspect the problem is that as I am not familiar with any of this stuff I have missed something important somewhere.

I should note also - this is a .net 4.5.2 Console app. I tried moving to 4.6.1 and this still fails.

1 Answers

I was looking completely in the wrong place. The problem lay in the IIS setup.

The site binding was for some reason explicitly set to 10.0.0.21:433. Switching this to "All Unassigned" - seems to have made this work.

I am probably out of my depth, and could be wrong, but I suspect the reason for this is that according to Wireshark, the response to the MDNS request to find the hostname IP, was returning the ipv6 address of the server machine, which of course isn't 10.0.0.21. Again, I could be wrong.

The reason I am so unsure is that chrome seems to have ploughed right through and found the correct thing when I put in https://test-machine/api/Example and I cannot explain why.

Related