【问题标题】:Multiple Azure AD tenants with shared callback path on IdentityServer4在 IdentityServer4 上具有共享回调路径的多个 Azure AD 租户
【发布时间】:2019-12-10 15:46:57
【问题描述】:

我正在实现基于 IdentityServer4 的联合网关,起初我正在努力连接到 Azure AD。单个 Azure 租户一切正常,但我只让多个租户并肩工作,为每个租户提供自己的回调路径。如果我将多个 Azure 租户添加到我的服务而不给他们单独的回调路径,则身份验证在 Azure 端成功,但在返回我的服务时,我在回调路径中收到以下错误:

CryptographicException: The payload was invalid.
Microsoft.AspNetCore.DataProtection.Cng.CbcAuthenticatedEncryptor.DecryptImpl(Byte* pbCiphertext, uint cbCiphertext, Byte* pbAdditionalAuthenticatedData, uint cbAdditionalAuthenticatedData)
Microsoft.AspNetCore.DataProtection.Cng.Internal.CngAuthenticatedEncryptorBase.Decrypt(ArraySegment<byte> ciphertext, ArraySegment<byte> additionalAuthenticatedData)
Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector.UnprotectCore(byte[] protectedData, bool allowOperationsOnRevokedKeys, out UnprotectStatus status)
Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector.DangerousUnprotect(byte[] protectedData, bool ignoreRevocationErrors, out bool requiresMigration, out bool wasRevoked)
Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector.Unprotect(byte[] protectedData)
Microsoft.AspNetCore.DataProtection.DataProtectionCommonExtensions.Unprotect(IDataProtector protector, string protectedData)
IdentityServer4.Infrastructure.DistributedCacheStateDataFormatter.Unprotect(string protectedText, string purpose) in DistributedCacheStateDataFormatter.cs
Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.ReadPropertiesAndClearState(OpenIdConnectMessage message)
Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync()

单个回调路径的问题是每个回调路径都需要单独配置到 Azure AD 中。我想支持在我的服务中添加新的 Azure 租户,而无需在 Azure 中进行额外配置。 Azure 的通用端点有效,但我还需要支持单个租户。

如何让多个租户(或一般的外部 IDP)共享相同的回调路径?我发现一个关于使用状态参数 (https://docs.microsoft.com/en-us/azure/active-directory/develop/reply-url#use-a-state-parameter) 处理此问题的提及,但我不知道如何在此处使用。

【问题讨论】:

  • 嗨,欢迎来到 SO。请至少解释一下您尝试了什么以及失败的地方。谢谢。
  • 感谢您的欢迎。我在问题中添加了更多细节。

标签: azure azure-active-directory identityserver4


【解决方案1】:

一般来说,每个 OIDC 处理程序都需要一个唯一的回调路径。你可以看看 Azure AD 多租户功能,它只需要对所有租户进行一次回调。

【讨论】:

  • 我确实启用了多租户,Azure 似乎可以将所有调用重定向到同一个 URL。问题出现在我的回调服务中。我在我的问题中添加了更多细节,也许可以澄清情况。
猜你喜欢
  • 1970-01-01
  • 2022-09-27
  • 2017-07-07
  • 1970-01-01
  • 1970-01-01
  • 2019-01-08
  • 2014-03-21
  • 1970-01-01
  • 2020-08-26
相关资源
最近更新 更多