You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft.SCIM.WebHostSample在Azure AD中授权失败求助

解决SCIM示例API调用时的JWT签名验证失败问题

问题核心

错误IDX10634: 无法创建SignatureProvider,算法HS256不被X509SecurityKey支持明确说明:测试应用获取的Token使用HS256对称算法签名,但SCIM服务端配置了**X509证书(非对称密钥)**进行Token验证,两者不兼容,导致签名验证失败。

解决方案

1. 对齐服务端与Token的签名算法

根据需求选择以下两种方案之一:

方案A:修改服务端以支持HS256对称算法

若想继续使用现有/scim/Token接口生成的HS256 Token,需调整SCIM服务端的JWT验证配置,改用对称密钥替代X509证书:
找到服务端Startup.cs或Program.cs中的认证配置代码,替换为如下逻辑:

services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(options =>
    {
        options.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateIssuer = true,
            ValidateAudience = true,
            ValidateLifetime = true,
            ValidateIssuerSigningKey = true,
            ValidIssuer = "与/scim/Token接口配置一致的颁发者",
            ValidAudience = "与/scim/Token接口配置一致的受众",
            // 使用对称密钥替代X509证书
            IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes("与/scim/Token接口生成Token时相同的密钥")),
            ValidAlgorithms = new[] { SecurityAlgorithms.HmacSha256 } // 指定支持HS256算法
        };
    });

方案B:生成RS256签名的Token适配服务端X509证书

若要保留服务端的X509证书验证逻辑,需修改测试应用的Token生成逻辑,用对应证书的私钥生成RS256签名的Token,替换原有的GetToken方法:

private async Task<string> GetTokenWithRS256()
{
    // 加载用于签名的X509证书(可从本地文件或Azure Key Vault获取)
    var certificate = new X509Certificate2("证书文件路径.pfx", "证书密码");
    var securityKey = new X509SecurityKey(certificate);

    var tokenHandler = new JwtSecurityTokenHandler();
    var tokenDescriptor = new SecurityTokenDescriptor
    {
        Subject = new ClaimsIdentity(new[] { new Claim(ClaimTypes.Name, "test-user") }),
        Expires = DateTime.UtcNow.AddHours(1),
        Issuer = "与SCIM服务端配置一致的颁发者",
        Audience = "与SCIM服务端配置一致的受众",
        SigningCredentials = new SigningCredentials(securityKey, SecurityAlgorithms.RsaSha256)
    };

    var token = tokenHandler.CreateToken(tokenDescriptor);
    return tokenHandler.WriteToken(token);
}

之后在Button_Click方法中调用此新方法获取Token即可。

2. 修正Azure AD环境的配置逻辑

如果是对接Azure AD的SCIM服务,不应使用自定义的/scim/Token接口,而是通过Azure AD的OAuth2客户端凭证流获取官方颁发的Token:

private async Task<string> GetAzureADToken()
{
    var client = new HttpClient();
    var request = new HttpRequestMessage(HttpMethod.Post, "https://login.microsoftonline.com/你的租户ID/oauth2/v2.0/token");
    var formData = new Dictionary<string, string>
    {
        ["client_id"] = "你的应用注册Client ID",
        ["client_secret"] = "你的应用注册Client Secret",
        ["scope"] = "https://graph.microsoft.com/.default", // 或对应SCIM服务的scope
        ["grant_type"] = "client_credentials"
    };
    request.Content = new FormUrlEncodedContent(formData);
    
    var response = await client.SendAsync(request);
    response.EnsureSuccessStatusCode();
    var tokenData = await response.Content.ReadFromJsonAsync<JObject>();
    return tokenData["access_token"].ToString();
}

内容的提问来源于stack exchange,提问作者Eric Metz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 13:17:06