語言

ITlsConnectionFeature.TryGetChannelBindingBytes 方法

定義

嘗試從目前連線中擷取所 kind 請求的 RFC 5929 TLS 通道綁定令牌(CBT)位元組。

public virtual bool TryGetChannelBindingBytes(System.Security.Authentication.ExtendedProtection.ChannelBindingKind kind, out ReadOnlyMemory<byte> channelBindingToken);
abstract member TryGetChannelBindingBytes : System.Security.Authentication.ExtendedProtection.ChannelBindingKind * ReadOnlyMemory -> bool
override this.TryGetChannelBindingBytes : System.Security.Authentication.ExtendedProtection.ChannelBindingKind * ReadOnlyMemory -> bool
Public Overridable Function TryGetChannelBindingBytes (kind As ChannelBindingKind, ByRef channelBindingToken As ReadOnlyMemory(Of Byte)) As Boolean

參數

kind
ChannelBindingKind

那種需要取回的通道綁定。

channelBindingToken
ReadOnlyMemory<Byte>

當此方法回傳 true時,包含通道綁定的標記位元組;否則,則為空 ReadOnlyMemory<T>。

傳回

true 如果有請求的通道綁定可用; false 否則(例如:連線非 TLS、伺服器不支援請求 kind 連線,或伺服器設定中未啟用通道綁定)。

備註

通道綁定令牌允許通道內認證協定(如透過HTTPS協商的Kerberos或NTLM)以密碼學方式綁定底層TLS通道,降低認證中繼攻擊的風險。 請參閱 https://datatracker.ietf.org/doc/html/rfc5929 Windows 使用模型的規範及 Microsoft 的「認證擴展保護」文件。

適用於