You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ECDsa在Azure Web App执行失败,本地/Mac环境正常求助

问题描述

我有两个生成Apple认证令牌的方法,在Mac和本地Windows PC上均能正常运行,但部署到**Azure Web App(Windows环境的.NET Core 8 WebApi)**时,抛出Cryptographic Exception异常,错误信息为:"The system cannot find the file specified."。已确认密钥无误,不知如何进一步排查解决。

生成令牌的代码

public string GenerateAppleSecret(string TeamId, string keyId, string serviceId, string key)
{
    var now = DateTimeOffset.Now.AddDays(-1);
    ReadOnlySpan<byte> keyAsSpan = Convert.FromBase64String(key);
    var prvKey = ECDsa.Create();
    prvKey.ImportPkcs8PrivateKey(keyAsSpan, out var read);
    return new JwtBuilder()
        .WithAlgorithm(new ES256Algorithm(ECDsa.Create(), prvKey))
        .AddHeader("kid", keyId)
        .ExpirationTime(now.AddDays(4).UtcDateTime)
        .IssuedAt(now.UtcDateTime)
        .Issuer(TeamId)
        .Audience("https://appleid.apple.com")
        .Subject(serviceId)
        .Encode();
}

private string CreateWeatherKitAuthToken(string teamId, string keyId, string serviceId, string privateKey)
{
   if (string.IsNullOrEmpty(privateKey) || privateKey.Length < 5)
   {
       throw new ArgumentNullException("Invalid Private Key");
   }

   byte[] privateKeyBytes = Convert.FromBase64String(privateKey);

   // 创建跨平台ECDsa实例并导入私钥
   ECDsa ecdsa = ECDsa.Create();  // 标记为跨平台
   ecdsa.ImportPkcs8PrivateKey(privateKeyBytes, out _); // 导入PKCS8格式密钥

   // 定义头部
   var header = new JwtHeader(new SigningCredentials(
       new ECDsaSecurityKey(ecdsa), SecurityAlgorithms.EcdsaSha256)
   );
   header["kid"] = keyId; // Apple密钥标识符(kid)

   // 定义令牌的当前时间和过期时间(纪元以来的秒数)
   var currentTime = DateTimeOffset.UtcNow.ToUnixTimeSeconds();
   var expirationTime = currentTime + 3600; // 令牌1小时后过期

   // 定义载荷
   var payload = new JwtPayload
   {
       { "iss", teamId },           // 签发者(Apple团队ID)
       { "iat", currentTime },       // 签发时间
       { "exp", expirationTime },    // 过期时间
       { "sub", serviceId }          // 主题(服务ID)
   };

   // 创建JWT令牌
   var jwtToken = new JwtSecurityToken(header, payload);

   // 返回令牌字符串
   var handler = new JwtSecurityTokenHandler();
   return handler.WriteToken(jwtToken);
}

异常堆栈跟踪

System.Security.Cryptography.CryptographicException:
   at System.Security.Cryptography.CngKey.Import (System.Security.Cryptography, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a)
   at System.Security.Cryptography.CngPkcs8.ImportPkcs8 (System.Security.Cryptography, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a)
   at System.Security.Cryptography.CngPkcs8.ImportPkcs8PrivateKey (System.Security.Cryptography, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a)
   at System.Security.Cryptography.ECDsaCng.ImportPkcs8PrivateKey (System.Security.Cryptography, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a)
   at System.Security.Cryptography.PemKeyHelpers.ImportPem (System.Security.Cryptography, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a)
   at WeatherKitApi.GetECDsaPrivateKey (CosplayCorps.Business, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null: D:\a\1\s\CosplayCorps.Business\Api\Apple\WeatherKitApi.cs:80)

排查解决方法

1. 强制使用软件加密实现

Windows Azure Web App默认会优先调用CNG硬件加密提供者,但环境可能缺少对应的硬件支持,导致找不到系统依赖文件。修改代码,显式创建基于软件的ECDsa实例:

将原代码中的ECDsa.Create()替换为指定椭圆曲线的软件实现:

// 第一个方法中的修改
var prvKey = ECDsa.Create(ECCurve.NamedCurves.nistP256);
prvKey.ImportPkcs8PrivateKey(keyAsSpan, out var read);

// 第二个方法中的修改
ECDsa ecdsa = ECDsa.Create(ECCurve.NamedCurves.nistP256);
ecdsa.ImportPkcs8PrivateKey(privateKeyBytes, out _);

2. 验证Azure运行环境配置

确认Azure Web App的运行栈为ASP.NET Core 8.0 (Windows),且.NET版本配置正确,避免因版本不匹配导致加密API兼容性问题。

3. 检查密钥格式完整性

确保传入的Base64密钥字符串无多余换行、空格或特殊字符,Apple的PKCS8格式密钥Base64编码应为连续字符串,不应包含分割线。

4. 尝试PEM格式密钥导入

若上述方法无效,将密钥转换为带-----BEGIN PRIVATE KEY-----和-----END PRIVATE KEY-----头的PEM格式,改用ImportFromPem方法导入:

// 假设privateKey为PEM格式字符串
ecdsa.ImportFromPem(privateKey.ToCharArray());

内容的提问来源于stack exchange,提问作者Mitaku

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 14:37:34