使用Microsoft Graph时遇AADSTS50013签名验证错误求助
AADSTS50013签名验证失败问题排查
错误信息
"AADSTS50013: Assertion failed signature validation. [Reason - Key was found, but use of the key to verify the signature failed., Thumbprint of key used by client: 'myThumbprint', Found key 'Start=10/02/2022 18:06:49, End=10/02/2027 18:06:49', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id '00000000-0000-0000-0000-000000000000'"
相关代码
{ logger.LogInformation("Loading files from drop point. Function executed at: {Date}", DateTime.Now); string message; using var certStore = new X509Store(StoreName.My, StoreLocation.CurrentUser); certStore.Open(OpenFlags.ReadOnly); X509Certificate2Collection certCollection = certStore.Certificates.Find( X509FindType.FindByThumbprint, "myThumbprint", false); if (certCollection.Count == 0) { message = "Could not find an installed certificate " + $"with the with a matching Thumbprint to "; logger.LogError(message); } X509Certificate2 cert = certCollection[0]; logger.LogInformation(cert.FriendlyName); string tenantId = ""; string clientId = ""; string clietnIdCertificate = ""; var credential = new ClientCertificateCredential(tenantId, clientId, cert); var scopes = new[] { "https://graph.microsoft.com/.default" }; GraphServiceClient graphServiceClient = new GraphServiceClient(credential,scopes); IConfidentialClientApplication confidentialClientApplication = ConfidentialClientApplicationBuilder .Create(clietnIdCertificate) .WithTenantId(tenantId) .WithCertificate(cert) .Build(); var authResult = await confidentialClientApplication .AcquireTokenForClient(scopes) .ExecuteAsync(); string incomingToken = authResult.AccessToken.ToString(); TokenProvider provider = new TokenProvider(); var onBehalf = new OnBehalfOfCredential(tenantId,clientId,cert,incomingToken); provider.token = incomingToken; var authenticationProvider = new BaseBearerTokenAuthenticationProvider(provider); var graphServiceClient2 = new GraphServiceClient(onBehalf,scopes); var user = await graphServiceClient2.Me.GetAsync(); } public class TokenProvider : IAccessTokenProvider { public string token { get; set; } public Task<string> GetAuthorizationTokenAsync(Uri uri, Dictionary<string, object> additionalAuthenticationContext = default, CancellationToken cancellationToken = default) { return Task.FromResult(token); } public AllowedHostsValidator AllowedHostsValidator { get; } }
Azure配置截图

可能原因及解决办法
1. 证书不匹配或私钥缺失
- 核对本地证书的有效期,确保与错误信息中显示的
Start=10/02/2022 18:06:49, End=10/02/2027 18:06:49完全一致,确认是Azure应用注册中配置的同一份证书。 - 检查本地证书是否包含私钥:打开证书管理器,查看证书“常规”选项卡,确认显示“您有一个对应的私钥”。若缺失,需重新导入带私钥的.pfx格式证书。
2. 应用ID配置错误
- 修正代码中变量拼写错误:
clietnIdCertificate应为clientIdCertificate,并填入正确的Azure应用Client ID。当前该变量为空,会导致使用无效应用ID发起认证。 - 确认
clientId变量填写的是目标应用的Client ID,避免混淆多个应用的ID。
3. 认证流程逻辑错误
- 代码同时混用
ClientCertificateCredential和ConfidentialClientApplication两种认证方式,且错误将应用权限令牌(AcquireTokenForClient获取)用于代表用户的OBO流程:- 若需应用权限调用Graph(如批量读取用户),直接使用
ClientCertificateCredential创建的graphServiceClient即可,无需额外OBO流程。 - 若需代表用户调用Graph,需先获取用户授权的令牌,再使用
OnBehalfOfCredential,当前的incomingToken是应用令牌,不符合OBO流程要求。
- 若需应用权限调用Graph(如批量读取用户),直接使用
4. 证书算法不兼容
- 检查证书签名算法是否为Azure AD支持的类型(如SHA256),旧的SHA1证书可能被拒绝,需更换为符合要求的证书。
内容的提问来源于stack exchange,提问作者Dan-Robert Samoila
相关产品推荐
相关产品推荐

