You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PySAML2对接Microsoft Entra ID出现KEY-NOT-FOUND验证失败求助

PySAML2 验证失败:KEY-NOT-FOUND 错误排查求助

我已在Azure门户创建企业应用并完成相关配置,配置截图如下:
Azure企业应用配置截图

以下是我的Python代码:

acs_url = 'http://localhost:8000/user/login/sso/auth'

rv = requests.get("App Federation Metadata Url From Azure Dashboard")
# I have to do this because
# the "inline" metadata type isn't working in PySAML2
import tempfile
tmp = tempfile.NamedTemporaryFile()
f = open(tmp.name, 'w')
f.write(rv.text)
f.close()

settings = {
    'metadata': {
        "local": [tmp.name]
        },
    'entityid': 'http://localhost:8000/user/login/sso/auth',
    'service': {
        'sp': {
            'endpoints': {
                'assertion_consumer_service': [
                    (acs_url, BINDING_HTTP_REDIRECT),
                    (acs_url, BINDING_HTTP_POST)
                ],
            },
            # Don't verify that the incoming requests originate from us via
            # the built-in cache for authn request ids in pysaml2
            'allow_unsolicited': True,
            # Don't sign authn requests
            'authn_requests_signed': False,
            'want_assertions_signed': True,
            'want_response_signed': False,
        },
    },
    'debug': 1,
    "logging": {
        "version": 1,
        "formatters": {
            "simple": {
                "format": "[%(asctime)s] [%(levelname)s] [%(name)s.%(funcName)s] %(message)s",
            },
        },
        "handlers": {
            "stdout": {
                "class": "logging.StreamHandler",
                "stream": "ext://sys.stdout",
                "level": "DEBUG",
                "formatter": "simple",
            },
        },
        "loggers": {
            "saml2": {
                "level": "DEBUG"
            },
        },
        "root": {
            "level": "DEBUG",
            "handlers": [
                "stdout",
            ],
        },
    },
}

spConfig = Saml2Config()
spConfig.load(settings)
spConfig.allow_unknown_attributes = True
saml_client = Saml2Client(config=spConfig)
tmp.close()
authn_response = saml_client.parse_authn_request_response(
    SAMLResponse,
    entity.BINDING_HTTP_POST)
authn_response.get_identity()
user_info = authn_response.get_subject()
# username = user_info.text

print(user_info)

运行代码时出现如下错误:

error=Verification status: FAILED
Failure reason: KEY-NOT-FOUND
Error: failed to verify file "/var/folders/60/1yz0pnwd2jv15p28bffgz8p40000gn/T/tmpza0_h534.xml"

我已查阅大量文档及Stack Overflow相关解答,但均未解决问题,恳请各位提供技术帮助。


内容的提问来源于stack exchange,提问作者Mohamad Fadil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 16:48:13