【问题标题】:How to connect a Xamarin android application to Azure with a self signed certificate in C#?如何使用 C# 中的自签名证书将 Xamarin android 应用程序连接到 Azure?
【发布时间】:2020-09-30 14:54:30
【问题描述】:

尊敬的 Stackoverflow 用户,

我已将 azure key vault 自签名证书链接到我的 Azure Web 应用程序,启用 minimal TLS v1.0 并将客户端证书模式设置为 Required 以强制使用 SSL/TLS。

如果我在我的 Windows 机器上安装密钥库 pfx 证书并导航到我的 url(即:https://mywebapp.azurewebsites.net),我的浏览器会提示我使用我的证书,否则我会收到 403 Frobidden 错误,这很好。

当我在我的 Xamarin android 应用程序中加载这个 pfx 时,我总是得到一个 403 Frobidden error。

这是我的代码:

    using (HttpClientHandler handler = new HttpClientHandler() {
        SslProtocols = System.Security.Authentication.SslProtocols.Tls12,
        AutomaticDecompression = DecompressionMethods.Deflate | DecompressionMethods.GZip,
        ClientCertificateOptions = ClientCertificateOption.Manual
    })
    {
        //Add SSL certificat
        X509Certificate2 _privateCert = GetPrivateAPICertificate(); //get a self-signed pfx stored localy in the android filesystem
        if (_privateCert != null)
        {
            handler.ClientCertificates.Add(_privateCert); 
            handler.CheckCertificateRevocationList = false;
            
            handler.ServerCertificateCustomValidationCallback =
                (httpRequestMessage, cert, cetChain, policyErrors) =>
                {
                    return true; // <- when debugging return 2 Microsoft Azure certificate with subject *.azurewebsites.net but not the one I've added to my WebApp "TLS/SSL settings" blade.
                };
        }
    
        using (HttpClient httpClient = new HttpClient(handler))
        {
            using (var request = new HttpRequestMessage { RequestUri = new Uri(url), Method = method })
            {
                response = await httpClient.SendAsync(request).ConfigureAwait(false);
                responseAsString = await response.Content.ReadAsStringAsync();
                response.EnsureSuccessStatusCode(); // <- Throw exception: "Response status code does not indicate success: 403 (Forbidden)."
            }
        }
    }

我做错了什么?

编辑:添加GetPrivateAPICertificate函数

    private X509Certificate2 GetPrivateAPICertificate()
    {
        var assembly = IntrospectionExtensions.GetTypeInfo(typeof(MyCoreAssembly)).Assembly;
        X509Certificate2 cert = new X509Certificate2();

        using (StreamReader sr = new StreamReader(assembly.GetManifestResourceStream("MyCoreAssembly.mycert.pfx")))
        {
            using (MemoryStream ms = new MemoryStream())
            {
                sr.BaseStream.CopyTo(ms);
                cert = new X509Certificate2(ms.ToArray());
            }
        }
        return cert;
    }

更新

我用邮递员做了一些测试,如果我在邮递员的设置中添加我的 pfx 证书,我可以访问 Azure API。这不是 Azure 中的证书配置问题。

我不明白为什么我的 HttpRequest 中没有从 Xamarin 发送证书!

更新 2

我还在 ASP.NET 控制台应用程序中放入了完全相同的代码,并且它可以工作。我想我必须在 Xamarin 中的 HTTP 调用中添加一些内容......

【问题讨论】:

  • 精度:证书是使用 Azure Key Vault 创建的。
  • 业界5年前因为安全问题决定淘汰TLS 1.0/1.1。今年 6 月,微软推出了一项安全更新,在服务器上禁用了 TLS 1.0/1.1,并要求使用 TLS 1.2/1.3。您需要升级到 TLS 1.2/1.3。
  • @jdweng 感谢您的反馈。我已将 Azure 设置为 1.0 的 minimal TLS 版本。我已经使用 TLS 1.2 进行了测试,并且得到了相同的结果:403 被禁止(我已更新代码以使用SslProtocols.Tls12)。
  • 可能需要在头部设置用户代理。某些服务器不会接受所有浏览器。请参阅:developer.mozilla.org/en-US/docs/Web/HTTP/Headers/User-Agent
  • 我在请求中添加了 UserAgent 但没有解决问题:httpClient.DefaultRequestHeaders.Add("User-Agent", "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0");。

标签: c# xamarin azure-web-app-service x509certificate


【解决方案1】:

我终于找到了实现这一目标的方法。 以下帖子有重点: Xamarin Android - Call API using HttpClient with Certificate

通过使用HttpWebRequest 而不是HttpClient,我可以发送带有证书的请求。

这是一个回归,因为 HttpWebRequest 不如新的 HttpClient 实现直观,但这是我迄今为止找到的唯一解决方案...

【讨论】:

  • 很高兴知道您自己解决了这个问题,请接受它作为答案,这将对其他有类似问题的社区有所帮助。
猜你喜欢
  • 2014-05-16
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2019-10-11
  • 1970-01-01
  • 1970-01-01
  • 2018-02-11
  • 2013-04-18
相关资源
最近更新 更多