You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft Graph时遇AADSTS50013签名验证错误求助

AADSTS50013签名验证失败问题排查

错误信息

"AADSTS50013: Assertion failed signature validation. [Reason - Key was found, but use of the key to verify the signature failed., Thumbprint of key used by client: 'myThumbprint', Found key 'Start=10/02/2022 18:06:49, End=10/02/2027 18:06:49', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id '00000000-0000-0000-0000-000000000000'"

相关代码

{
    logger.LogInformation("Loading files from drop point. Function executed at: {Date}", DateTime.Now);
    string message;
    using var certStore = new X509Store(StoreName.My, StoreLocation.CurrentUser);

    certStore.Open(OpenFlags.ReadOnly);
    X509Certificate2Collection certCollection = certStore.Certificates.Find(
        X509FindType.FindByThumbprint,
        "myThumbprint",
        false);

    if (certCollection.Count == 0)
    {
        message = "Could not find an installed certificate " +
                         $"with the with a matching Thumbprint to ";
        logger.LogError(message);
    }

    X509Certificate2 cert = certCollection[0];
    logger.LogInformation(cert.FriendlyName);
    string tenantId = "";
    string clientId = "";
    string clietnIdCertificate = "";

    var credential = new ClientCertificateCredential(tenantId, clientId, cert);
    var scopes = new[] { "https://graph.microsoft.com/.default" };
    GraphServiceClient graphServiceClient = new GraphServiceClient(credential,scopes);


    IConfidentialClientApplication confidentialClientApplication = ConfidentialClientApplicationBuilder
        .Create(clietnIdCertificate)
        .WithTenantId(tenantId)
        .WithCertificate(cert)
        .Build();

    var authResult = await confidentialClientApplication
                    .AcquireTokenForClient(scopes)
                    .ExecuteAsync();

    string incomingToken = authResult.AccessToken.ToString();

    TokenProvider provider = new TokenProvider();
    var onBehalf = new OnBehalfOfCredential(tenantId,clientId,cert,incomingToken);
    provider.token = incomingToken;
    var authenticationProvider = new BaseBearerTokenAuthenticationProvider(provider);
    var graphServiceClient2 = new GraphServiceClient(onBehalf,scopes);
    var user = await graphServiceClient2.Me.GetAsync();

}
public class TokenProvider : IAccessTokenProvider
{
    public string token { get; set; }
    public Task<string> GetAuthorizationTokenAsync(Uri uri, Dictionary<string, object> additionalAuthenticationContext = default,
        CancellationToken cancellationToken = default)
    {
        return Task.FromResult(token);
    }

    public AllowedHostsValidator AllowedHostsValidator { get; }
}

Azure配置截图

Azure配置截图

可能原因及解决办法

1. 证书不匹配或私钥缺失

  • 核对本地证书的有效期,确保与错误信息中显示的Start=10/02/2022 18:06:49, End=10/02/2027 18:06:49完全一致,确认是Azure应用注册中配置的同一份证书。
  • 检查本地证书是否包含私钥:打开证书管理器,查看证书“常规”选项卡,确认显示“您有一个对应的私钥”。若缺失,需重新导入带私钥的.pfx格式证书。

2. 应用ID配置错误

  • 修正代码中变量拼写错误:clietnIdCertificate应为clientIdCertificate,并填入正确的Azure应用Client ID。当前该变量为空,会导致使用无效应用ID发起认证。
  • 确认clientId变量填写的是目标应用的Client ID,避免混淆多个应用的ID。

3. 认证流程逻辑错误

  • 代码同时混用ClientCertificateCredential和ConfidentialClientApplication两种认证方式,且错误将应用权限令牌(AcquireTokenForClient获取)用于代表用户的OBO流程:
    • 若需应用权限调用Graph(如批量读取用户),直接使用ClientCertificateCredential创建的graphServiceClient即可,无需额外OBO流程。
    • 若需代表用户调用Graph,需先获取用户授权的令牌,再使用OnBehalfOfCredential,当前的incomingToken是应用令牌,不符合OBO流程要求。

4. 证书算法不兼容

  • 检查证书签名算法是否为Azure AD支持的类型(如SHA256),旧的SHA1证书可能被拒绝,需更换为符合要求的证书。

内容的提问来源于stack exchange,提问作者Dan-Robert Samoila

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 17:43:15