You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure容器应用(ACA)无法获取客户端证书,该如何配置?

Azure容器应用(ACA)客户端证书获取异常排查

我通过Azure容器应用(ACA)暴露了一个仅开放8080端口的端点,核心需求之一是验证HTTP请求的客户端证书。

本地环境运行正常的代码如下:

// Attempt to get the certificate from the connection
var clientCertificate = httpContext.Connection?.ClientCertificate;
if (clientCertificate != null)
    return clientCertificate;

// Check if the X-ARR-ClientCert header is present
if (httpContext.Request.Headers.TryGetValue("X-ARR-ClientCert", out var certHeader) && !string.IsNullOrWhiteSpace(certHeader))
{
    try
    {
        byte[] certBytes = Convert.FromBase64String(certHeader!);
        clientCertificate = new X509Certificate2(certBytes);

        return clientCertificate;
    }
    catch (Exception ex)
    {
        logger.LogError(ex, "Unable to parse certificate from header 'X-ARR-ClientCert'.");
    }
}

本地运行时,直接通过httpContext.Connection?.ClientCertificate就能获取证书;在App Service中,通过httpContext.Request.Headers.TryGetValue("X-ARR-ClientCert", out var certHeader)也能正常获取证书。

我已将客户端证书设置为“accept”,且ACA部署在虚拟网络(VNet)内。最初怀疑是网关组件丢弃了证书,但通过VNet内部直接访问端点时,问题依然存在。

请问这可能是什么原因?是否遗漏了某些配置?


内容的提问来源于stack exchange,提问作者FEST

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 10:59:53