You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET MVC 4.8集成B2C MFA测试服务器登录失败求助

Azure B2C多因素认证集成部署超时问题排查请求

我们使用C# ASP.NET MVC 4.8框架,为现有系统集成Azure B2C作为多因素认证(MFA)方案。网站登录按钮点击后会跳转至MFA登录页,该功能在本地开发环境完全正常,但部署到测试服务器后出现连接超时问题:无法连接到远程服务器40.126.14.164:443,抛出Socket超时异常,进而导致无法获取OpenID配置文档,触发IDX20803等系列错误。以下是相关信息,请求协助排查解决。

错误详情

连接尝试失败,因为连接方在一段时间后未正确响应,或已建立的连接失败,因为连接的主机未能响应40.126.14.164:443
描述:执行当前Web请求期间发生未处理的异常。请查看堆栈跟踪以获取有关错误及其在代码中起源的更多信息。
异常详细信息:System.Net.Sockets.SocketException: 连接尝试失败,因为连接方在一段时间后未正确响应,或已建立的连接失败,因为连接的主机未能响应40.126.14.164:443
...(完整错误栈保留原文格式)

本地正常运行代码

Login动作方法

[HttpPost]
[ValidateAntiForgeryToken]
public async Task<ActionResult> Login(LoginBo loginBo)
{
    Uri appToB2cUrl;

    string tenant = UriHelpers.GetTenantName();
    string clientId = UriHelpers.GetClientId();
    string policy = UriHelpers.GetPolicy();
    
    Uri siteUri = new Uri(Request.Url.AbsoluteUri);         

    string  redirectUri = UriHelpers.GetRedirectUri(siteUri);         
    string authority = $"https://{tenant}.b2clogin.com/{tenant}.onmicrosoft.com/oauth2/v2.0/authorize";
    string scope = Constants.SCOPE;
    string responseType = Constants.RESPONSESTYPE;
    string nonce = Constants.NONCE;
    string prompt = Constants.PROMPT;

    string b2cUrl = $"{authority}?p={policy}&client_id={clientId}&nonce={nonce}&redirect_uri={HttpUtility.UrlEncode(redirectUri)}&scope={scope}&response_type={responseType}&prompt={prompt}";
    appToB2cUrl = new Uri(b2cUrl);

    return Redirect(appToB2cUrl.OriginalString);
}

AzureResponse回调方法

[Authorize]
public async Task<ActionResult> AzureResponse()
{
    if (User.Identity.IsAuthenticated)
    {
        var claimsIdentity = User.Identity as ClaimsIdentity;

        // 提取相关声明
        string roleClaim = claimsIdentity.FindFirst("extension_UserRole")?.Value;
        string nameClaim = claimsIdentity.FindFirst("extension_UserName")?.Value;
        string newUserClaim = claimsIdentity.FindFirst("newUser")?.Value;
        string customerAccountNumberClaim = claimsIdentity.FindFirst("extension_CustomerAccountNumber")?.Value;
        string emailAddressClaim = claimsIdentity.FindFirst("extension_EmailAddress")?.Value;
        string authority = UriHelpers.GetAuthority();

        // 检查用户名是否为空,针对已添加到Azure B2C但在CSP中无账户的用户
        if (nameClaim == String.Empty || nameClaim == null || roleClaim == String.Empty || roleClaim == null)
        {   
            return RedirectToAction("AzurePrompt", "Error");
        }
        // 将用户名存储到会话
        Session["User"] = nameClaim;

        // 判断用户是注册还是登录
        bool isSignUp = newUserClaim != null && bool.Parse(newUserClaim);

        // 可选:处理注册专属逻辑
        if (isSignUp)
        {
            UserUpdateModel userUpdateModel = new UserUpdateModel
            {
                CustomerAccountNumber = customerAccountNumberClaim,
                EmailAddress = emailAddressClaim,
                UserName = nameClaim
            };

            bool updateSuccess = await UpdateEmailAndUserNameAsync(userUpdateModel);

        }

        // 根据用户角色路由
        return ManageRoute(nameClaim, roleClaim);
    }

    // 认证失败或未认证时,重定向到登录页
    return RedirectToAction("Login");
}

OpenID配置内容

{
    "issuer": "https://r*******.b2clogin.com/17a5a7a2-cd33-40b6-8b74-b1d14f19a513/v2.0/",
    "authorization_endpoint": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/oauth2/v2.0/authorize",
    "token_endpoint": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/oauth2/v2.0/token",
    "end_session_endpoint": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/oauth2/v2.0/logout",
    "jwks_uri": "https://r*******.b2clogin.com/r*******.onmicrosoft.com/b2c_1_sms/discovery/v2.0/keys",
    "response_modes_supported": [
        "query",
        "fragment",
        "form_post"
    ],
    "response_types_supported": [
        "code",
        "code id_token",
        "code token",
        "code id_token token",
        "id_token",
        "id_token token",
        "token",
        "token id_token"
    ],
    "scopes_supported": [
        "openid"
    ],
    "subject_types_supported": [
        "pairwise"
    ],
    "id_token_signing_alg_values_supported": [
        "RS256"
    ],
    "token_endpoint_auth_methods_supported": [
        "client_secret_post",
        "client_secret_basic"
    ],
    "claims_supported": [
        "idp",
        "extension_CustomerAccountNumber",
        "emails",
        "family_name",
        "extension_UserRole",
        "oid",
        "sub",
        "extension_UserName",
        "tfp",
        "isForgotPassword",
        "iss",
        "iat",
        "exp",
        "aud",
        "acr",
        "nonce",
        "auth_time"
    ]
}

排查建议

  • 验证网络连通性:在测试服务器上执行Test-NetConnection 40.126.14.164 -Port 443(PowerShell)或telnet 40.126.14.164 443,确认服务器能访问该IP的443端口。若不通,联系运维检查防火墙、安全组是否放行Azure B2C服务IP段的443端口访问。
  • 检查DNS解析:在测试服务器上运行Resolve-DnsName r*******.b2clogin.com(替换为实际租户域名),确认解析结果是否包含40.126.14.164,或是否存在解析异常。
  • 代理配置检查:若测试服务器需通过代理访问外网,在web.config中添加正确的代理配置:
<system.net>
  <defaultProxy useDefaultCredentials="true">
    <proxy proxyaddress="http://你的代理服务器:端口" bypassonlocal="false" />
  </defaultProxy>
</system.net>
  • 启用TLS 1.2+:Azure B2C要求使用TLS 1.2及以上版本,在Global.asax的Application_Start方法中添加:
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls13;
  • 验证OpenID端点可达性:在测试服务器上直接访问OpenID配置中的authorization_endpoint和jwks_uri,确认能正常返回内容。
  • 核对Authority参数:确认代码中拼接的authority与OpenID配置的authorization_endpoint匹配,检查policy参数值是否为b2c_1_sms(与配置中的路径一致)。

内容的提问来源于stack exchange,提问作者Jong Lar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 02:34:56