如何为Azure B2C配置通用SAML联合的PartnerEntity?
Azure B2C 通用SAML联合策略中PartnerEntity的通用配置方案
我们有一款以Azure B2C作为身份提供商(IDP)的SaaS应用,当前通过SAML联合实现企业单点登录(SSO)。目前的做法是为每个企业单独配置ClaimsProvider,每个配置里都要指定具体的PartnerEntity,示例代码如下:
<TechnicalProfile Id="Contoso-SAML2"> <DisplayName>Contoso</DisplayName> <Description>Login with your AD FS account</Description> <Protocol Name="SAML2"/> <Metadata> <Item Key="RequestsSigned">false</Item> <Item Key="ResponsesSigned">false</Item> <Item Key="WantsEncryptedAssertions">false</Item> <Item Key="PartnerEntity">https://login.microsoftonline.com/..tenantid../federationmetadata/2007-06/federationmetadata.xml?appid=..appid..</Item> </Metadata> <CryptographicKeys> <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/> </CryptographicKeys> ... </TechnicalProfile>
我们希望创建通用的联合策略,让PartnerEntity可以通用配置,不用为每个外部合作伙伴单独添加技术配置文件,当前模板中PartnerEntity的位置不知道该如何填写,模板示例如下:
<ClaimsProvider> <DisplayName>SAML</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="Contoso-SAML2"> <DisplayName>SAML</DisplayName> <Description>Login with your AD FS account</Description> <Protocol Name="SAML2"/> <Metadata> <Item Key="RequestsSigned">false</Item> <Item Key="ResponsesSigned">false</Item> <Item Key="WantsEncryptedAssertions">false</Item> <Item Key="PartnerEntity"> what to add here for generic ??? </Item> </Metadata> <CryptographicKeys> <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/> </CryptographicKeys> ... </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
通用配置方案
Azure B2C无法直接设置固定的通用PartnerEntity值,而是需要通过动态声明传递+元数据地址引用的方式实现通用SAML联合策略,具体步骤如下:
- 移除固定的PartnerEntity项,改用
MetadataAddress来动态指定IDP元数据地址 - 添加输入声明,用于接收依赖方应用发起请求时传入的目标企业SAML元数据URL
- 在Metadata中使用声明占位符,将动态传入的元数据地址绑定到配置中
修改后的通用技术配置文件示例:
<ClaimsProvider> <DisplayName>Generic SAML SSO</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="Generic-SAML2"> <DisplayName>Enterprise SAML Login</DisplayName> <Description>Login with your enterprise SAML account</Description> <Protocol Name="SAML2"/> <!-- 定义输入声明,接收外部传入的IDP元数据URL --> <InputClaims> <InputClaim ClaimTypeReferenceId="IdpMetadataUrl" Required="true"/> </InputClaims> <Metadata> <Item Key="RequestsSigned">false</Item> <Item Key="ResponsesSigned">false</Item> <Item Key="WantsEncryptedAssertions">false</Item> <!-- 通过声明占位符动态获取元数据地址,替代固定的PartnerEntity --> <Item Key="MetadataAddress">{Claim:IdpMetadataUrl}</Item> </Metadata> <CryptographicKeys> <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/> </CryptographicKeys> <IncludeInSso>true</IncludeInSso> ... </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
关键说明
MetadataAddress是Azure B2C用来指定SAML IDP元数据地址的标准配置项,支持使用声明占位符{Claim:ClaimName}动态取值- 依赖方应用在发起认证请求时,需要将对应企业的SAML元数据URL作为
IdpMetadataUrl声明传递给Azure B2C - 也可以通过传递IDP的实体ID(EntityId)结合元数据自动发现机制,但直接传递元数据URL更直接可靠
内容的提问来源于stack exchange,提问作者Rasmus Vesterskov F.
相关产品推荐
相关产品推荐

