【问题标题】:Intermittent Azure AD B2C exceptions: IDX10614: AsymmetricSecurityKey.GetSignatureFormater() throws an exception间歇性 Azure AD B2C 异常:IDX10614:AsymmetricSecurityKey.GetSignatureFormater() 引发异常
【发布时间】:2020-10-23 21:29:58
【问题描述】:

我们使用 AAD B2C 和自定义策略已经有一段时间了,一切正常,但突然之间,我们开始在登录策略上遇到异常。更糟糕的是,有时它确实有效,但 5 次中有 4 次出现异常。

我们设法通过将策略链接到 Application Insights 来挖掘错误,这就是我们得到的结果:

"Kind": "FatalException",
    "Content": {
      "Time": "9:05 PM",
      "Exception": {
        "Kind": "Handled",
        "HResult": "80131509",
        "Message": "IDX10614: AsymmetricSecurityKey.GetSignatureFormater( 'http://www.w3.org/2001/04/xmldsig-more#rsa-sha256' ) threw an exception.\nKey: 'System.IdentityModel.Tokens.X509AsymmetricSecurityKey'\nSignatureAlgorithm: 'http://www.w3.org/2001/04/xmldsig-more#rsa-sha256', check to make sure the SignatureAlgorithm is supported.\nException:'System.Security.Cryptography.CryptographicException: Invalid provider type specified.\r\n\r\n   at System.Security.Cryptography.Utils.CreateProvHandle(CspParameters parameters, Boolean randomKeyContainer)\r\n   at System.Security.Cryptography.Utils.GetKeyPairHelper(CspAlgorithmType keyType, CspParameters parameters, Boolean randomKeyContainer, Int32 dwKeySize, SafeProvHandle& safeProvHandle, SafeKeyHandle& safeKeyHandle)\r\n   at System.Security.Cryptography.RSACryptoServiceProvider.GetKeyPair()\r\n   at System.Security.Cryptography.RSACryptoServiceProvider..ctor(Int32 dwKeySize, CspParameters parameters, Boolean useDefaultKeySize)\r\n   at System.Security.Cryptography.X509Certificates.X509Certificate2.get_PrivateKey()\r\n   at System.IdentityModel.Tokens.X509AsymmetricSecurityKey.get_PrivateKey()\r\n   at System.IdentityModel.Tokens.X509AsymmetricSecurityKey.GetSignatureFormatter(String algorithm)\r\n   at System.IdentityModel.Tokens.AsymmetricSignatureProvider..ctor(AsymmetricSecurityKey key, String algorithm, Boolean willCreateSignatures)'.\nIf you only need to verify signatures the parameter 'willBeUseForSigning' should be false if the private key is not be available.",
        "Data": {},
        "Exception": {
          "Kind": "Handled",
          "HResult": "80090014",
          "Message": "Invalid provider type specified.\r\n",
          "Data": {}
        }
      }
    }

我不确定发生了什么变化,也不知道这件事发生得有多突然。我们是否使用隐身模式都没有关系。

此外,在 Microsoft 结束时没有报告中断。

任何线索将不胜感激!

【问题讨论】:

  • 不再是间歇性的,它一直在发生。

标签: azure-ad-b2c azure-ad-b2c-custom-policy


【解决方案1】:

已通过此处找到的信息解决:StackOverflow question

因为我们也使用了Invite Flow,所以我使用了那里提到的New-SelfSignedCertificate 命令。

现在我通过使用来自此 Microsoft doc 的信息并从上面的 StackOverflow 线程附加 Provider 参数重新生成了证书:

PS C:\WINDOWS\system32> New-SelfSignedCertificate `
>>     -KeyExportPolicy Exportable `
>>     -Subject "CN=***.onmicrosoft.com" `
>>     -KeyAlgorithm RSA `
>>     -KeyLength 2048 `
>>     -KeyUsage DigitalSignature `
>>     -NotAfter (Get-Date).AddMonths(24) `
>>     -CertStoreLocation "Cert:\CurrentUser\My" `
>>     -Provider "microsoft enhanced rsa and aes cryptographic provider"

虽然我不确定为什么这会突然停止工作,但我猜可能是微软更新了一些东西。

无论如何,现在看来它可以工作了,所以我们拭目以待。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2019-07-24
    • 1970-01-01
    • 2017-12-06
    • 2013-05-17
    • 1970-01-01
    • 2021-07-08
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多