【发布时间】:2019-12-10 15:46:57
【问题描述】:
我正在实现基于 IdentityServer4 的联合网关,起初我正在努力连接到 Azure AD。单个 Azure 租户一切正常,但我只让多个租户并肩工作,为每个租户提供自己的回调路径。如果我将多个 Azure 租户添加到我的服务而不给他们单独的回调路径,则身份验证在 Azure 端成功,但在返回我的服务时,我在回调路径中收到以下错误:
CryptographicException: The payload was invalid.
Microsoft.AspNetCore.DataProtection.Cng.CbcAuthenticatedEncryptor.DecryptImpl(Byte* pbCiphertext, uint cbCiphertext, Byte* pbAdditionalAuthenticatedData, uint cbAdditionalAuthenticatedData)
Microsoft.AspNetCore.DataProtection.Cng.Internal.CngAuthenticatedEncryptorBase.Decrypt(ArraySegment<byte> ciphertext, ArraySegment<byte> additionalAuthenticatedData)
Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector.UnprotectCore(byte[] protectedData, bool allowOperationsOnRevokedKeys, out UnprotectStatus status)
Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector.DangerousUnprotect(byte[] protectedData, bool ignoreRevocationErrors, out bool requiresMigration, out bool wasRevoked)
Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector.Unprotect(byte[] protectedData)
Microsoft.AspNetCore.DataProtection.DataProtectionCommonExtensions.Unprotect(IDataProtector protector, string protectedData)
IdentityServer4.Infrastructure.DistributedCacheStateDataFormatter.Unprotect(string protectedText, string purpose) in DistributedCacheStateDataFormatter.cs
Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.ReadPropertiesAndClearState(OpenIdConnectMessage message)
Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync()
单个回调路径的问题是每个回调路径都需要单独配置到 Azure AD 中。我想支持在我的服务中添加新的 Azure 租户,而无需在 Azure 中进行额外配置。 Azure 的通用端点有效,但我还需要支持单个租户。
如何让多个租户(或一般的外部 IDP)共享相同的回调路径?我发现一个关于使用状态参数 (https://docs.microsoft.com/en-us/azure/active-directory/develop/reply-url#use-a-state-parameter) 处理此问题的提及,但我不知道如何在此处使用。
【问题讨论】:
-
嗨,欢迎来到 SO。请至少解释一下您尝试了什么以及失败的地方。谢谢。
-
感谢您的欢迎。我在问题中添加了更多细节。
标签: azure azure-active-directory identityserver4