基于证书的客户端凭据访问SharePoint REST API(替代已弃用的ACS)
解决AADSTS700027:客户端断言签名证书未注册问题
问题场景
尝试采用基于证书的客户端凭据流访问SharePoint REST API(替代已弃用的ACS),已完成以下操作:
- 将证书上传至Azure AD应用注册
- 配置应用角色与API权限并获取管理员同意
但在Postman中调用令牌端点时,持续返回AADSTS700027错误:
AADSTS700027: The certificate with identifier used to sign the client assertion is not registered on application. [Reason - The key was not found., Thumbprint of key used by client: 'D7A075E3A[...]F45F75F39DFAF', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id 'a4f[...]'
Postman请求与响应详情:
POST /622d2..d28d/oauth2/v2.0/token HTTP/1.1 Content-Type: application/x-www-form-urlencoded User-Agent: PostmanRuntime/7.35.0 Accept: */* Postman-Token: 6eb86bfb..b982cf90 Host: login.microsoftonline.com Accept-Encoding: gzip, deflate, br Connection: keep-alive Content-Length: 1042 Cookie: fpc=AnJUj6Foo6JHu93Jqm..DdB90OAAAA; stsservicecookie=estsfd; x-ms-gateway-slice=estsfd client_id=a4f1[...]&client_assertion=eyJhbGciOiJSUzI1NiIsInR5cCI6Ik[...]&scope=https%3A%2F%2Ft[..]n.sharepoint.com%2F.default&grant_type=client_credentials&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
HTTP/1.1 401 Unauthorized Cache-Control: no-store, no-cache Pragma: no-cache Content-Type: application/json; charset=utf-8 Expires: -1 Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff P3P: CP="DSP CUR OTPi IND OTRi ONL FIN" x-ms-request-id: fd41f6c6-e80a-465b-b6de-effd5de74a00 x-ms-ests-server: 2.1.16878.5 - WEULR1 ProdSlices X-XSS-Protection: 0 Set-Cookie: fpc=AnJUj6Foo6JHu93JqmIgZdyfiZiWAwAAAIDdB90OAAAA; expires=Tue, 09-Jan-2024 16:28:44 GMT; path=/; secure; HttpOnly; SameSite=None Set-Cookie: x-ms-gateway-slice=estsfd; path=/; secure; samesite=none; httponly Date: Sun, 10 Dec 2023 16:28:44 GMT Content-Length: 1146 {"error":"invalid_client","error_description":"AADSTS700027: The certificate with identifier used to sign the client assertion is not registered on application. [Reason - The key was not found., Thumbprint of key used by client: '0BA07DD820C5F4[..]5E3AF40105EB6', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id 'a4[...]'. Review the documentation at https://docs.microsoft.com/en-us/graph/deployments to determine the corresponding service endpoint and https://docs.microsoft.com/en-us/graph/api/application-get?view=graph-rest-1.0&tabs=http to build a query request URL, such as 'https://graph.microsoft.com/beta/appli...']. Trace ID: fd41f6c6-e80a-465.. Correlation ID: a5e2.. Timestamp: 2023-12-10 16:28:44Z","error_codes":[700027],"timestamp":"2023-12-10 16:28:44Z","trace_id":"fd41f...fd5de74a00","correlation_id":"a5e...4c7d2","error_uri":"https://login.microsoftonline.com/error?code=700027"}
排查与解决步骤
1. 定位客户端断言使用的证书
客户端断言是由私钥签名的JWT,其中x5t字段对应签名证书的SHA-1指纹:
- 解码Postman中
client_assertion的JWT内容,提取x5t字段值,与错误提示的指纹对比,确认实际使用的证书。
2. 验证Azure AD应用的证书配置
登录Azure门户,进入目标应用注册的证书和密码页面:
- 检查错误提示的指纹是否存在于已上传证书列表中:
- 若不存在:说明签名用的私钥与上传的公钥证书不匹配,需重新上传对应私钥的公钥证书(格式为.cer/.pem)
- 若存在:检查证书是否过期,或是否为X.509公钥证书(不支持私钥直接上传)
3. 确认客户端断言生成逻辑正确性
生成JWT断言时必须满足以下要求:
- 使用对应证书的私钥签名,算法为RS256
x5t字段值为证书的SHA-1指纹(注意大小写需与Azure门户中存储的一致,Azure默认存储大写格式)iss与sub字段值必须等于应用的client_idaud字段值必须为令牌端点的完整URL(如https://login.microsoftonline.com/622d2..d28d/oauth2/v2.0/token)
4. 排查Postman配置错误
- 确认
client_assertion无复制错误(如截断、多余空格或字符) - 检查请求参数:
grant_type为client_credentials,client_assertion_type为urn:ietf:params:oauth:client-assertion-type:jwt-bearer - 验证
scope格式正确,应为https://<你的租户>.sharepoint.com/.default
5. 绕过门户缓存验证证书配置
若Azure门户显示证书已存在但仍报错,可通过Graph API查询应用的证书配置(避免门户缓存影响):
GET https://graph.microsoft.com/v1.0/applications/{你的应用ID}/keyCredentials
返回结果中customKeyIdentifier为证书SHA-1指纹的Base64编码,解码后与错误提示的指纹对比,确认是否存在。
内容的提问来源于stack exchange,提问作者Carl
相关产品推荐
相关产品推荐

