You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地IIS中Sustainsys.Saml2对接MS Entra报Cookie状态丢失错误

问题:.NET Framework 4.7.2 WebForms本地IIS环境下Sustainsys.Saml2对接MS Entra报InResponseTo错误

报错信息

Received message _a80178a3-d538-4b8e-a538-5fbbef823aca contains unexpected InResponseTo "iddbc74838186f4f58a236105450827f37". No cookie preserving state from the request was found so the message was not expected to have an InResponseTo attribute. This error typically occurs if the cookie set when doing SP-initiated sign on have been lost.

环境及已尝试操作

  • 基于.NET Framework 4.7.2的WebForms应用
  • 本地IIS运行
  • 已配置受信任SSL证书(域名local.abc.com,尝试过*.abc.com、local.abc.com及生产环境证书,均导入受信任根证书颁发机构)
  • 已添加脚本修改Cookie的SameSite值为空或"Unspecified",该方案在Azure App Service生产环境正常,但本地失效

解决方案尝试方向

1. 校准本地IIS的Cookie核心配置

  • 打开IIS管理器,进入站点的配置编辑器,定位到system.web/httpCookies:
    • 设置domain为local.abc.com,确保Cookie绑定域名和请求域名完全一致;
    • 开启requireSSL选项,保证Cookie仅通过HTTPS传输。

2. 显式配置Sustainsys.Saml2的Cookie处理器

在web.config中直接指定Sustainsys.Saml2的Cookie参数,覆盖默认行为:

<sustainsys.saml2 entityId="https://local.abc.com/Saml2" returnUrl="https://local.abc.com/">
  <identityProviders>
    <!-- 你的MS Entra身份提供商配置 -->
  </identityProviders>
  <cookieHandler requireSsl="true" domain="local.abc.com" sameSite="Unspecified" />
</sustainsys.saml2>

3. 固定本地IIS的机器密钥

本地IIS默认自动生成机器密钥,重启后会导致Cookie加密密钥变更,丢失会话状态。在web.config的system.web节点下添加固定密钥(可通过IIS管理器"机器密钥"功能生成):

<machineKey validationKey="生成的验证密钥" decryptionKey="生成的解密密钥" validation="SHA1" decryption="AES" />

4. 调整浏览器隐私设置

  • 关闭浏览器"阻止第三方Cookie"选项,避免本地域名被误判为第三方;
  • 清空浏览器缓存和Cookie,排除旧无效Cookie的干扰。

5. 验证本地主机映射

检查C:\Windows\System32\drivers\etc\hosts文件,确认已正确添加127.0.0.1 local.abc.com的映射,且无冲突记录。

内容的提问来源于stack exchange,提问作者RoLYroLLs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 14:22:38