验证id_token_hint签名时遇“元数据无密钥集”错误的排查
Azure AD B2C验证id_token_hint签名报错:Key not found in metadata 排查与解决
参考Azure AD B2C的魔法登录链接示例实现id_token_hint签名验证时,遇到如下错误:
Message:Key not found in metadata. Reason: 'No key set found in metadata'
我的技术配置如下:
<TechnicalProfile Id="IdTokenHint_ExtractClaims"> <DisplayName> My ID Token Hint TechnicalProfile</DisplayName> <Protocol Name="None" /> <Metadata> <Item Key="METADATA">https://someapp.azurewebsites.net/api/.well-known/openid-configuration</Item> </Metadata> <OutputClaims> <OutputClaim ClaimTypeReferenceId="email" /> </OutputClaims> </TechnicalProfile>
已暴露用于验证签名的公钥相关端点:
https://someapp.azurewebsites.net/api/.well-known/openid-configurationhttps://someapp.azurewebsites.net/api/.well-known/keys
(附openid-configuration、keys、id_token_hint截图)
问题原因与解决方法
报错核心原因是OpenID配置元数据的字段命名不符合Azure AD B2C的规范:B2C要求元数据JSON必须使用驼峰命名格式(例如关键字段需命名为jwks_uri),若字段格式不正确,B2C无法识别并加载对应的公钥集,进而触发"No key set found in metadata"错误。
将openid-configuration返回的JSON内容调整为驼峰命名格式后,该问题已解决。
内容的提问来源于stack exchange,提问作者Anton Putau
相关产品推荐
相关产品推荐

