You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用App Registration的addKey接口时遇Authentication_MissingOrMalformed错误求助

排查401 Authentication_MissingOrMalformed错误的步骤

一、验证Proof Token有效性

  • 确认签名证书:生成proof token的证书必须是当前已上传到Azure AD应用注册的有效证书(未过期、未被删除),不能使用新证书或本地未上传的证书。
  • 修正JWT声明问题:
    • iss必须严格等于应用的Object ID(不是Client ID),检查代码中objectId变量的赋值是否正确,你的代码里string objectId = {objectId}";存在语法错误,应改为string objectId = "{objectId}";(替换为实际的应用Object ID)。
    • 用JWT解码工具验证生成的token中aud字段是否为固定值00000003-0000-0000-c000-000000000000(Microsoft Graph受众ID)。
  • 同步时间范围:确保proof token的NotBefore和Expires有效期不超过10分钟,且本地服务器时间与Azure AD服务器时间偏差不超过5分钟,否则token会被判定无效。
  • 检查签名算法:生成的token的alg字段必须为RS256(X509证书签名算法),若为其他算法会导致验证失败。

二、检查客户端认证配置

  • 确认认证证书:初始化ClientCertificateCredential时,必须使用已上传到应用注册的证书(和生成proof token的证书为同一个),确保PFX文件路径、密码无误。
  • 验证权限配置:调用application:addKey实际需要以下应用权限之一,需确认应用注册已添加并完成管理员同意:
    • Application.ReadWrite.OwnedBy(应用拥有者权限)
    • Application.ReadWrite.All(全局应用读写权限)

三、修正请求体的KeyCredential字段

  • 调整证书数据格式:改用newCert.Export(X509ContentType.Cert)获取新证书的公钥DER数据(仅需公钥),避免直接使用GetRawCertData可能带来的格式问题。
  • 补充可选字段:给KeyCredential添加DisplayName字段(如DisplayName = "New Rotated Certificate"),部分场景下缺失该字段会触发验证异常。

四、代码修正示例

修正Proof Token生成的语法错误

string pfxFilePath = "certandkey.pfx";
string password = "password";
string objectId = "{objectId}"; // 替换为实际应用Object ID

// Get signing certificate
X509Certificate2 signingCert = new X509Certificate2(pfxFilePath, password);

// audience
string aud = "00000003-0000-0000-c000-000000000000";

var claims = new Dictionary<string, object>()
{
    { "aud", aud },
    { "iss", objectId }
};

var now = DateTime.UtcNow;
var securityTokenDescriptor = new SecurityTokenDescriptor
{
    Claims = claims,
    NotBefore = now,
    Expires = now.AddMinutes(10),
    SigningCredentials = new X509SigningCredentials(signingCert)
};

var handler = new JsonWebTokenHandler();
var x = handler.CreateToken(securityTokenDescriptor);

修正KeyCredential的证书数据获取

string tenantId = "{tenantId}";
string clientId = "{clientId}";
string newCertPath = "newcert.pfx";
X509Certificate2 newCert = new X509Certificate2(newCertPath);
var credential = new ClientCertificateCredential(tenantId, clientId, signingCert);
var graphClient = new GraphServiceClient(credential);

// 获取新证书的公钥DER数据
byte[] certData = newCert.Export(X509ContentType.Cert);

var requestBody = new Microsoft.Graph.Applications.Item.AddKey.AddKeyPostRequestBody
{
    KeyCredential = new KeyCredential
    {
        Type = "AsymmetricX509Cert",
        Usage = "Verify",
        Key = certData,
        DisplayName = "New Rotation Certificate"
    },
    PasswordCredential = null,
    Proof = x,
};
var result = await graphClient.Applications[objectId].AddKey.PostAsync(requestBody);

五、额外排查步骤

  • 使用Graph Explorer手动构造请求调用POST /applications/{objectId}/addKey,排除代码层面的问题。
  • 在Azure Portal的AD日志中查找对应401请求的详细错误信息,获取更具体的失败原因(如证书无效、权限不足等)。

内容的提问来源于stack exchange,提问作者Aaron

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 02:33:11