You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于证书的客户端凭据访问SharePoint REST API(替代已弃用的ACS)

解决AADSTS700027:客户端断言签名证书未注册问题

问题场景

尝试采用基于证书的客户端凭据流访问SharePoint REST API(替代已弃用的ACS),已完成以下操作:

  • 将证书上传至Azure AD应用注册
  • 配置应用角色与API权限并获取管理员同意

但在Postman中调用令牌端点时,持续返回AADSTS700027错误:

AADSTS700027: The certificate with identifier used to sign the client assertion is not registered on application. [Reason - The key was not found., Thumbprint of key used by client: 'D7A075E3A[...]F45F75F39DFAF', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id 'a4f[...]'

Postman请求与响应详情:

POST /622d2..d28d/oauth2/v2.0/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: PostmanRuntime/7.35.0
Accept: */*
Postman-Token: 6eb86bfb..b982cf90
Host: login.microsoftonline.com
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Content-Length: 1042
Cookie: fpc=AnJUj6Foo6JHu93Jqm..DdB90OAAAA; stsservicecookie=estsfd; x-ms-gateway-slice=estsfd
 
client_id=a4f1[...]&client_assertion=eyJhbGciOiJSUzI1NiIsInR5cCI6Ik[...]&scope=https%3A%2F%2Ft[..]n.sharepoint.com%2F.default&grant_type=client_credentials&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer
HTTP/1.1 401 Unauthorized
Cache-Control: no-store, no-cache
Pragma: no-cache
Content-Type: application/json; charset=utf-8
Expires: -1
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
x-ms-request-id: fd41f6c6-e80a-465b-b6de-effd5de74a00
x-ms-ests-server: 2.1.16878.5 - WEULR1 ProdSlices
X-XSS-Protection: 0
Set-Cookie: fpc=AnJUj6Foo6JHu93JqmIgZdyfiZiWAwAAAIDdB90OAAAA; expires=Tue, 09-Jan-2024 16:28:44 GMT; path=/; secure; HttpOnly; SameSite=None
Set-Cookie: x-ms-gateway-slice=estsfd; path=/; secure; samesite=none; httponly
Date: Sun, 10 Dec 2023 16:28:44 GMT
Content-Length: 1146
 

{"error":"invalid_client","error_description":"AADSTS700027: The certificate with identifier used to sign the client assertion is not registered on application. [Reason - The key was not found., Thumbprint of key used by client: '0BA07DD820C5F4[..]5E3AF40105EB6', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id 'a4[...]'. Review the documentation at https://docs.microsoft.com/en-us/graph/deployments to determine the corresponding service endpoint and https://docs.microsoft.com/en-us/graph/api/application-get?view=graph-rest-1.0&tabs=http to build a query request URL, such as 'https://graph.microsoft.com/beta/appli...']. Trace ID: fd41f6c6-e80a-465.. Correlation ID: a5e2.. Timestamp: 2023-12-10 16:28:44Z","error_codes":[700027],"timestamp":"2023-12-10 16:28:44Z","trace_id":"fd41f...fd5de74a00","correlation_id":"a5e...4c7d2","error_uri":"https://login.microsoftonline.com/error?code=700027"}

排查与解决步骤

1. 定位客户端断言使用的证书

客户端断言是由私钥签名的JWT,其中x5t字段对应签名证书的SHA-1指纹:

  • 解码Postman中client_assertion的JWT内容,提取x5t字段值,与错误提示的指纹对比,确认实际使用的证书。

2. 验证Azure AD应用的证书配置

登录Azure门户,进入目标应用注册的证书和密码页面:

  • 检查错误提示的指纹是否存在于已上传证书列表中:
    • 若不存在:说明签名用的私钥与上传的公钥证书不匹配,需重新上传对应私钥的公钥证书(格式为.cer/.pem)
    • 若存在:检查证书是否过期,或是否为X.509公钥证书(不支持私钥直接上传)

3. 确认客户端断言生成逻辑正确性

生成JWT断言时必须满足以下要求:

  • 使用对应证书的私钥签名,算法为RS256
  • x5t字段值为证书的SHA-1指纹(注意大小写需与Azure门户中存储的一致,Azure默认存储大写格式)
  • iss与sub字段值必须等于应用的client_id
  • aud字段值必须为令牌端点的完整URL(如https://login.microsoftonline.com/622d2..d28d/oauth2/v2.0/token)

4. 排查Postman配置错误

  • 确认client_assertion无复制错误(如截断、多余空格或字符)
  • 检查请求参数:grant_type为client_credentials,client_assertion_type为urn:ietf:params:oauth:client-assertion-type:jwt-bearer
  • 验证scope格式正确,应为https://<你的租户>.sharepoint.com/.default

5. 绕过门户缓存验证证书配置

若Azure门户显示证书已存在但仍报错,可通过Graph API查询应用的证书配置(避免门户缓存影响):

GET https://graph.microsoft.com/v1.0/applications/{你的应用ID}/keyCredentials

返回结果中customKeyIdentifier为证书SHA-1指纹的Base64编码,解码后与错误提示的指纹对比,确认是否存在。


内容的提问来源于stack exchange,提问作者Carl

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 05:35:13