ASP.NET MVC 4.8集成B2C MFA测试服务器登录失败求助
Azure B2C多因素认证集成部署超时问题排查请求
我们使用C# ASP.NET MVC 4.8框架,为现有系统集成Azure B2C作为多因素认证(MFA)方案。网站登录按钮点击后会跳转至MFA登录页,该功能在本地开发环境完全正常,但部署到测试服务器后出现连接超时问题:无法连接到远程服务器40.126.14.164:443,抛出Socket超时异常,进而导致无法获取OpenID配置文档,触发IDX20803等系列错误。以下是相关信息,请求协助排查解决。
错误详情
连接尝试失败,因为连接方在一段时间后未正确响应,或已建立的连接失败,因为连接的主机未能响应40.126.14.164:443
描述:执行当前Web请求期间发生未处理的异常。请查看堆栈跟踪以获取有关错误及其在代码中起源的更多信息。
异常详细信息:System.Net.Sockets.SocketException: 连接尝试失败,因为连接方在一段时间后未正确响应,或已建立的连接失败,因为连接的主机未能响应40.126.14.164:443
...(完整错误栈保留原文格式)
本地正常运行代码
Login动作方法
[HttpPost] [ValidateAntiForgeryToken] public async Task<ActionResult> Login(LoginBo loginBo) { Uri appToB2cUrl; string tenant = UriHelpers.GetTenantName(); string clientId = UriHelpers.GetClientId(); string policy = UriHelpers.GetPolicy(); Uri siteUri = new Uri(Request.Url.AbsoluteUri); string redirectUri = UriHelpers.GetRedirectUri(siteUri); string authority = $"https://{tenant}.b2clogin.com/{tenant}.onmicrosoft.com/oauth2/v2.0/authorize"; string scope = Constants.SCOPE; string responseType = Constants.RESPONSESTYPE; string nonce = Constants.NONCE; string prompt = Constants.PROMPT; string b2cUrl = $"{authority}?p={policy}&client_id={clientId}&nonce={nonce}&redirect_uri={HttpUtility.UrlEncode(redirectUri)}&scope={scope}&response_type={responseType}&prompt={prompt}"; appToB2cUrl = new Uri(b2cUrl); return Redirect(appToB2cUrl.OriginalString); }
AzureResponse回调方法
[Authorize] public async Task<ActionResult> AzureResponse() { if (User.Identity.IsAuthenticated) { var claimsIdentity = User.Identity as ClaimsIdentity; // 提取相关声明 string roleClaim = claimsIdentity.FindFirst("extension_UserRole")?.Value; string nameClaim = claimsIdentity.FindFirst("extension_UserName")?.Value; string newUserClaim = claimsIdentity.FindFirst("newUser")?.Value; string customerAccountNumberClaim = claimsIdentity.FindFirst("extension_CustomerAccountNumber")?.Value; string emailAddressClaim = claimsIdentity.FindFirst("extension_EmailAddress")?.Value; string authority = UriHelpers.GetAuthority(); // 检查用户名是否为空,针对已添加到Azure B2C但在CSP中无账户的用户 if (nameClaim == String.Empty || nameClaim == null || roleClaim == String.Empty || roleClaim == null) { return RedirectToAction("AzurePrompt", "Error"); } // 将用户名存储到会话 Session["User"] = nameClaim; // 判断用户是注册还是登录 bool isSignUp = newUserClaim != null && bool.Parse(newUserClaim); // 可选:处理注册专属逻辑 if (isSignUp) { UserUpdateModel userUpdateModel = new UserUpdateModel { CustomerAccountNumber = customerAccountNumberClaim, EmailAddress = emailAddressClaim, UserName = nameClaim }; bool updateSuccess = await UpdateEmailAndUserNameAsync(userUpdateModel); } // 根据用户角色路由 return ManageRoute(nameClaim, roleClaim); } // 认证失败或未认证时,重定向到登录页 return RedirectToAction("Login"); }
OpenID配置内容
{ "issuer": "https://r*******.b2clogin.com/17a5a7a2-cd33-40b6-8b74-b1d14f19a513/v2.0/", "authorization_endpoint": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/oauth2/v2.0/authorize", "token_endpoint": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/oauth2/v2.0/token", "end_session_endpoint": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/oauth2/v2.0/logout", "jwks_uri": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/discovery/v2.0/keys", "response_modes_supported": [ "query", "fragment", "form_post" ], "response_types_supported": [ "code", "code id_token", "code token", "code id_token token", "id_token", "id_token token", "token", "token id_token" ], "scopes_supported": [ "openid" ], "subject_types_supported": [ "pairwise" ], "id_token_signing_alg_values_supported": [ "RS256" ], "token_endpoint_auth_methods_supported": [ "client_secret_post", "client_secret_basic" ], "claims_supported": [ "idp", "extension_CustomerAccountNumber", "emails", "family_name", "extension_UserRole", "oid", "sub", "extension_UserName", "tfp", "isForgotPassword", "iss", "iat", "exp", "aud", "acr", "nonce", "auth_time" ] }
排查建议
- 验证网络连通性:在测试服务器上执行
Test-NetConnection 40.126.14.164 -Port 443(PowerShell)或telnet 40.126.14.164 443,确认服务器能访问该IP的443端口。若不通,联系运维检查防火墙、安全组是否放行Azure B2C服务IP段的443端口访问。 - 检查DNS解析:在测试服务器上运行
Resolve-DnsName r*******.b2clogin.com(替换为实际租户域名),确认解析结果是否包含40.126.14.164,或是否存在解析异常。 - 代理配置检查:若测试服务器需通过代理访问外网,在web.config中添加正确的代理配置:
<system.net> <defaultProxy useDefaultCredentials="true"> <proxy proxyaddress="http://你的代理服务器:端口" bypassonlocal="false" /> </defaultProxy> </system.net>
- 启用TLS 1.2+:Azure B2C要求使用TLS 1.2及以上版本,在Global.asax的
Application_Start方法中添加:
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls13;
- 验证OpenID端点可达性:在测试服务器上直接访问OpenID配置中的
authorization_endpoint和jwks_uri,确认能正常返回内容。 - 核对Authority参数:确认代码中拼接的authority与OpenID配置的authorization_endpoint匹配,检查policy参数值是否为
b2c_1_sms(与配置中的路径一致)。
内容的提问来源于stack exchange,提问作者Jong Lar
相关产品推荐
相关产品推荐

