【发布时间】:2020-09-30 14:54:30
【问题描述】:
尊敬的 Stackoverflow 用户,
我已将 azure key vault 自签名证书链接到我的 Azure Web 应用程序,启用 minimal TLS v1.0 并将客户端证书模式设置为 Required 以强制使用 SSL/TLS。
如果我在我的 Windows 机器上安装密钥库 pfx 证书并导航到我的 url(即:https://mywebapp.azurewebsites.net),我的浏览器会提示我使用我的证书,否则我会收到 403 Frobidden 错误,这很好。
当我在我的 Xamarin android 应用程序中加载这个 pfx 时,我总是得到一个 403 Frobidden error。
这是我的代码:
using (HttpClientHandler handler = new HttpClientHandler() {
SslProtocols = System.Security.Authentication.SslProtocols.Tls12,
AutomaticDecompression = DecompressionMethods.Deflate | DecompressionMethods.GZip,
ClientCertificateOptions = ClientCertificateOption.Manual
})
{
//Add SSL certificat
X509Certificate2 _privateCert = GetPrivateAPICertificate(); //get a self-signed pfx stored localy in the android filesystem
if (_privateCert != null)
{
handler.ClientCertificates.Add(_privateCert);
handler.CheckCertificateRevocationList = false;
handler.ServerCertificateCustomValidationCallback =
(httpRequestMessage, cert, cetChain, policyErrors) =>
{
return true; // <- when debugging return 2 Microsoft Azure certificate with subject *.azurewebsites.net but not the one I've added to my WebApp "TLS/SSL settings" blade.
};
}
using (HttpClient httpClient = new HttpClient(handler))
{
using (var request = new HttpRequestMessage { RequestUri = new Uri(url), Method = method })
{
response = await httpClient.SendAsync(request).ConfigureAwait(false);
responseAsString = await response.Content.ReadAsStringAsync();
response.EnsureSuccessStatusCode(); // <- Throw exception: "Response status code does not indicate success: 403 (Forbidden)."
}
}
}
我做错了什么?
编辑:添加GetPrivateAPICertificate函数
private X509Certificate2 GetPrivateAPICertificate()
{
var assembly = IntrospectionExtensions.GetTypeInfo(typeof(MyCoreAssembly)).Assembly;
X509Certificate2 cert = new X509Certificate2();
using (StreamReader sr = new StreamReader(assembly.GetManifestResourceStream("MyCoreAssembly.mycert.pfx")))
{
using (MemoryStream ms = new MemoryStream())
{
sr.BaseStream.CopyTo(ms);
cert = new X509Certificate2(ms.ToArray());
}
}
return cert;
}
更新
我用邮递员做了一些测试,如果我在邮递员的设置中添加我的 pfx 证书,我可以访问 Azure API。这不是 Azure 中的证书配置问题。
我不明白为什么我的 HttpRequest 中没有从 Xamarin 发送证书!
更新 2
我还在 ASP.NET 控制台应用程序中放入了完全相同的代码,并且它可以工作。我想我必须在 Xamarin 中的 HTTP 调用中添加一些内容......
【问题讨论】:
-
精度:证书是使用 Azure Key Vault 创建的。
-
业界5年前因为安全问题决定淘汰TLS 1.0/1.1。今年 6 月,微软推出了一项安全更新,在服务器上禁用了 TLS 1.0/1.1,并要求使用 TLS 1.2/1.3。您需要升级到 TLS 1.2/1.3。
-
@jdweng 感谢您的反馈。我已将 Azure 设置为 1.0 的 minimal TLS 版本。我已经使用 TLS 1.2 进行了测试,并且得到了相同的结果:403 被禁止(我已更新代码以使用
SslProtocols.Tls12)。 -
可能需要在头部设置用户代理。某些服务器不会接受所有浏览器。请参阅:developer.mozilla.org/en-US/docs/Web/HTTP/Headers/User-Agent
-
我在请求中添加了 UserAgent 但没有解决问题:
httpClient.DefaultRequestHeaders.Add("User-Agent", "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0");。
标签: c# xamarin azure-web-app-service x509certificate