Could not create SSL/TLS secure channel happens only in windows server 2012

Viewed 2271

My goal is to check the file size, I am tested this code on several windows server 2012 r2 machines The following code gives error, (in all of them):

Could not create SSL/TLS secure channel

ServicePointManager.Expect100Continue = true;
ServicePointManager.SecurityProtocol = SecurityProtocolType.Ssl3 | SecurityProtocolType.Tls12 | SecurityProtocolType.Tls11 | SecurityProtocolType.Tls;
string url = @"https://www.gov.il/BlobFolder/reports/fortimail/he/FORTIMAIL-CERT-IL-W-1068.pdf";
HttpWebRequest myHttpWebRequest = (HttpWebRequest)WebRequest.Create(url);            
using (HttpWebResponse myHttpWebResponse = (HttpWebResponse)myHttpWebRequest.GetResponse())
{
    var headers = myHttpWebResponse.Headers;
    string fileSize = "0";
    if (headers.AllKeys.Contains("Content-Length"))
        fileSize = headers.GetValues("Content-Length")[0];
    Console.WriteLine(fileSize);
}

The same code works fine on Windows servers 2016 and on windows 10, but not on windows servers 2012.

when I enter this link from chrome it works even on server 2012, also with postman it works on all machines (but doesn't work via code in windows 2012).

The error happens for then given link, but for other file urls like http://www.orimi.com/pdf-test.pdf it works fine.

I also tried to enable TLS via registry:

enter image description here

any ideas?

1 Answers

Try to correct the configuration to:

ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;

That should get it to work. The site only supports TLS1.2, which is the current widely supported TLS version.

Windows 2012 might do TLS 1.0 out-of-the-box. Suggest to apply all the windows updates and edit system settings to do TLS 1.2 only by default. You were onto the right track with these registry keys but there are more. The configuration is not greatly explained by Microsoft documentation, might be able to find a stack overflow explaining the tweaks.

Windows 2012 R2 reached end of support in 2018 and it will reach end of extended support (assuming you pay extra each year for it) in 2023. You should consider upgrading. Expect the outdated cryptography on Windows 2008 and 2012 to be a recurrent source of TLS connectivity issues.

curl "https://www.gov.il/BlobFolder/reports/fortimail/he/FORTIMAIL-CERT-IL-W-1068.pdf" --tlsv1.2
... good

curl "https://www.gov.il/BlobFolder/reports/fortimail/he/FORTIMAIL-CERT-IL-W-1068.pdf" --tlsv1.1
curl: (35) schannel: next InitializeSecurityContext failed: SEC_E_ILLEGAL_MESSAGE (0x80090326)
This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.

curl "https://www.gov.il/BlobFolder/reports/fortimail/he/FORTIMAIL-CERT-IL-W-1068.pdf" --tlsv1.0
curl: (35) schannel: next InitializeSecurityContext failed: SEC_E_ILLEGAL_MESSAGE (0x80090326)
This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.
Related