You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python SDK在Azure Key Vault创建EC密钥时遇权限错误求助

问题描述

我正在遵循Python生成椭圆曲线密钥的Azure官方教程,执行以下代码时持续报错:

from azure.identity import DefaultAzureCredential
from azure.keyvault.keys import KeyClient

credential = DefaultAzureCredential()

key_client = KeyClient(vault_url="https://mykv.vault.azure.net/", credential=credential)

# 创建椭圆曲线密钥
ec_key = key_client.create_ec_key("test-ec-key", curve="P-256")
print(ec_key.name)
print(ec_key.key_type)

错误信息

azure.core.exceptions.HttpResponseError: (Forbidden) Caller is not authorized to perform action on resource.

If role assignments, deny assignments or role definitions were changed recently, please observe propagation time.

Caller: appid=d5f43625-e0e3-4e27-a63d-477f9e91cb5c;oid=890cda89-b200-41a9-8453-454cd42698eb;iss=https://sts.windows.net/47ed4b29-d620-4166-975b-81fdce3d3875/

Action: 'Microsoft.KeyVault/vaults/keys/create/action'

Resource: '/subscriptions/db002e19-6b8e-4b1b-a70d-a430eb7b5acf/resourcegroups/test_rg/providers/microsoft.keyvault/vaults/mykv/keys/test-ec-key'

Assignment: (not found)

DenyAssignmentId: null

DecisionReason: 'DeniedWithNoValidRBAC'

Vault: mykv;location=eastus

Inner error: {
"code": "ForbiddenByRbac"
}

问题原因与解决方案

原因

错误信息中的DeniedWithNoValidRBAC明确说明:当前调用身份(对应错误里的appid或oid标识的主体)没有被授予在目标Key Vault上执行Microsoft.KeyVault/vaults/keys/create/action操作的RBAC权限,且系统未找到对应的角色分配记录。

解决步骤

  • 确认需授权的主体:根据错误中的appid(应用程序身份)或oid(用户/服务主体对象ID),定位需要赋予权限的身份实体。
  • 分配RBAC角色:
    1. 登录Azure门户,找到目标Key Vault(mykv)。
    2. 进入访问控制(IAM)页面,点击添加 -> 添加角色分配。
    3. 在角色列表中选择包含密钥创建权限的角色,例如:
      • Key Vault Crypto Officer:支持密钥的创建、管理等操作
      • Key Vault Contributor:支持管理Key Vault及其包含的所有资源(密钥、机密等)
    4. 在成员页面,搜索并选中步骤1确认的主体。
    5. 完成角色分配,等待权限生效(通常需要1-5分钟,最长不超过30分钟)。
  • 验证修复效果:重新运行代码,确认是否成功创建椭圆曲线密钥。

内容的提问来源于stack exchange,提问作者Varshini M B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 04:43:28