You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Google Play预启动报告中Unsafe Cipher Mode警告的MSAL配置及相关调整咨询

Fixing "Unsafe Cipher Mode" in MSAL for Google Play Pre-Launch Reports

Let’s tackle this issue head-on—you’re seeing a warning about unsafe cipher modes in MSAL’s StorageHelper->getKeyThumbPrint method, and need to switch to AES/GCM/NoPadding as Google recommends. Here’s how to address this:

Client-Side MSAL Configuration (Android)

The problem stems from MSAL’s default local cache encryption implementation. To replace it with the recommended GCM mode, you’ll need to customize MSAL’s crypto factory:

  1. Implement a custom ICryptoFactory
    Create a class that implements MSAL’s ICryptoFactory interface, where you define encryption using AES/GCM/NoPadding. This lets you override the default cipher settings used for caching tokens locally.

    Example code snippet:

    import com.microsoft.identity.common.java.crypto.ICryptoFactory;
    import com.microsoft.identity.common.java.crypto.IEncryptionManager;
    import com.microsoft.identity.common.java.crypto.EncryptionManager;
    import com.microsoft.identity.common.java.exception.ClientException;
    
    public class CustomGcmCryptoFactory implements ICryptoFactory {
        @Override
        public IEncryptionManager getEncryptionManager() throws ClientException {
            // Configure encryption to use AES/GCM/NoPadding
            return new EncryptionManager.Builder()
                    .setEncryptionAlgorithm("AES/GCM/NoPadding")
                    .build();
        }
    
        // Implement other required interface methods (e.g., getMacManager, getSignatureManager)
        // using secure, modern algorithms as needed
    }
    
  2. Pass the custom factory to MSAL initialization
    When creating your PublicClientApplication instance, inject your custom crypto factory to ensure MSAL uses it for all local cache operations:

    PublicClientApplication.create(
        context,
        R.raw.auth_config,
        new CustomGcmCryptoFactory(), // Your custom factory here
        null
    );
    

    Note: Make sure you’re using a recent version of MSAL for Android (v2.0+ recommended) to ensure full support for custom crypto factories and modern cipher modes.

Server-Side/Azure AD Adjustments: None Needed

Good news—you don’t need to make any changes to your backend services or Azure AD settings.

The cipher mode warning relates to how MSAL encrypts tokens locally on the device (in the app’s cache). This doesn’t affect the OAuth 2.0/OIDC flow with Azure AD, which already uses secure HTTPS and industry-standard encryption for all client-server communication. Your access token handling on the server side remains unchanged.


内容的提问来源于stack exchange,提问作者Roar Grønmo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 21:52:40