You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET MAUI iOS端MSAL认证报错:钥匙串访问组未启用排查

.NET MAUI iOS端MSAL认证钥匙串访问组错误排查方案

针对你迁移到.NET MAUI后iOS端MSAL抛出的钥匙串访问组错误,以下是几个可能遗漏的配置或步骤:

  • 检查Entitlements.plist的路径配置
    .NET MAUI的iOS平台文件默认存放在Platforms/iOS目录下,如果你的Entitlements.plist也在该目录,需要修改项目文件中的CodesignEntitlements路径为完整相对路径:

    <PropertyGroup Condition="'$(TargetFramework)'=='net7.0-ios'">
        <CodesignEntitlements>Platforms/iOS/Entitlements.plist</CodesignEntitlements>
        <CodesignKey>Apple Development: John Smith (UYG3HQ6LCP)</CodesignKey>
        <CodesignProvision>VS: com.mycompany.MyCompany Development</CodesignProvision>
    </PropertyGroup>
    

    若路径错误,签名过程会忽略该文件,导致钥匙串权限未生效。

  • 统一钥匙串访问组的配置值
    确保WithIosKeychainSecurityGroup传入的参数与Entitlements.plist中的组名保持一致(包含AppIdentifierPrefix):

    _authenticationClient = PublicClientApplicationBuilder
        .Create(B2CConstants.ClientId)
        .WithB2CAuthority(B2CConstants.AuthoritySignInSignUp)
        .WithRedirectUri($"msal{B2CConstants.ClientId}://auth")
        .WithIosKeychainSecurityGroup($"{B2CConstants.AppIdentifierPrefix}.com.microsoft.adalcache")
        .Build();
    

    你可以在Apple开发者后台获取团队ID(即AppIdentifierPrefix),直接替换$(AppIdentifierPrefix)变量,避免MAUI构建时变量替换失败。

  • 验证配置文件(Provisioning Profile)的权限
    登录Apple开发者后台,检查你的开发配置文件是否已包含对应的钥匙串访问组:

    1. 进入"Certificates, Identifiers & Profiles",找到你的App ID
    2. 确认"Keychain Sharing"权限已启用,并添加$(AppIdentifierPrefix).com.microsoft.adalcache访问组
    3. 重新生成配置文件并在Visual Studio中更新
  • 升级MSAL NuGet包版本
    确保使用的Microsoft.Identity.Client是支持.NET MAUI的最新稳定版(建议>=4.56.0),旧版本可能存在MAUI iOS适配问题。

  • 清理缓存并重新部署

    1. 删除项目的bin和obj目录,清理构建缓存
    2. 重启Visual Studio for Mac
    3. 重新连接iPhone设备,选择正确的配置文件重新部署应用

内容的提问来源于stack exchange,提问作者David Shochet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 17:40:38