通过C#编程获取Azure设备预配服务EnrollmentGroupKeys时密钥为空
解决Azure设备预配服务EnrollmentGroup密钥返回null的问题
问题原因
Azure设备预配服务出于安全设计,默认不会在返回的注册组信息中包含对称密钥明文。你调用的GetEnrollmentGroupAsync(string groupId)重载方法,服务端只会返回注册组的基础属性,不会携带敏感的PrimaryKey和SecondaryKey,因此转换后的SymmetricKeyAttestation对象中这两个属性为null。
解决方法
使用带includeKeys参数的重载方法,显式要求服务端返回密钥信息:
// 获取包含密钥的注册组详情 EnrollmentGroup group = await provisioningClient.GetEnrollmentGroupAsync(groupId, includeKeys: true); logger.LogInformation("Got Enrollment Group: {group}", JsonConvert.SerializeObject(group)); var attestation = (SymmetricKeyAttestation)group.Attestation; var primaryKey = attestation.PrimaryKey; var secondaryKey = attestation.SecondaryKey; if(string.IsNullOrEmpty(primaryKey)) logger.LogWarning("No Primary Key"); if(string.IsNullOrEmpty(secondaryKey)) logger.LogWarning("No Secondary Key"); logger.LogInformation("Got Keys {pri} and {sec}", primaryKey, secondaryKey);
额外注意
确保你的认证身份(比如服务主体)拥有EnrollmentGroup.ReadWriteAll或同等权限,否则即使设置includeKeys: true,也会因权限不足无法获取密钥。
内容的提问来源于stack exchange,提问作者MikeF
相关产品推荐
相关产品推荐

