Azure容器应用(ACA)无法获取客户端证书,该如何配置?
Azure容器应用(ACA)客户端证书获取异常排查
我通过Azure容器应用(ACA)暴露了一个仅开放8080端口的端点,核心需求之一是验证HTTP请求的客户端证书。
本地环境运行正常的代码如下:
// Attempt to get the certificate from the connection var clientCertificate = httpContext.Connection?.ClientCertificate; if (clientCertificate != null) return clientCertificate; // Check if the X-ARR-ClientCert header is present if (httpContext.Request.Headers.TryGetValue("X-ARR-ClientCert", out var certHeader) && !string.IsNullOrWhiteSpace(certHeader)) { try { byte[] certBytes = Convert.FromBase64String(certHeader!); clientCertificate = new X509Certificate2(certBytes); return clientCertificate; } catch (Exception ex) { logger.LogError(ex, "Unable to parse certificate from header 'X-ARR-ClientCert'."); } }
本地运行时,直接通过httpContext.Connection?.ClientCertificate就能获取证书;在App Service中,通过httpContext.Request.Headers.TryGetValue("X-ARR-ClientCert", out var certHeader)也能正常获取证书。
我已将客户端证书设置为“accept”,且ACA部署在虚拟网络(VNet)内。最初怀疑是网关组件丢弃了证书,但通过VNet内部直接访问端点时,问题依然存在。
请问这可能是什么原因?是否遗漏了某些配置?
内容的提问来源于stack exchange,提问作者FEST
相关产品推荐
相关产品推荐

