关于Google Play预启动报告中Unsafe Cipher Mode警告的MSAL配置及相关调整咨询
Let’s tackle this issue head-on—you’re seeing a warning about unsafe cipher modes in MSAL’s StorageHelper->getKeyThumbPrint method, and need to switch to AES/GCM/NoPadding as Google recommends. Here’s how to address this:
Client-Side MSAL Configuration (Android)
The problem stems from MSAL’s default local cache encryption implementation. To replace it with the recommended GCM mode, you’ll need to customize MSAL’s crypto factory:
Implement a custom
ICryptoFactory
Create a class that implements MSAL’sICryptoFactoryinterface, where you define encryption usingAES/GCM/NoPadding. This lets you override the default cipher settings used for caching tokens locally.Example code snippet:
import com.microsoft.identity.common.java.crypto.ICryptoFactory; import com.microsoft.identity.common.java.crypto.IEncryptionManager; import com.microsoft.identity.common.java.crypto.EncryptionManager; import com.microsoft.identity.common.java.exception.ClientException; public class CustomGcmCryptoFactory implements ICryptoFactory { @Override public IEncryptionManager getEncryptionManager() throws ClientException { // Configure encryption to use AES/GCM/NoPadding return new EncryptionManager.Builder() .setEncryptionAlgorithm("AES/GCM/NoPadding") .build(); } // Implement other required interface methods (e.g., getMacManager, getSignatureManager) // using secure, modern algorithms as needed }Pass the custom factory to MSAL initialization
When creating yourPublicClientApplicationinstance, inject your custom crypto factory to ensure MSAL uses it for all local cache operations:PublicClientApplication.create( context, R.raw.auth_config, new CustomGcmCryptoFactory(), // Your custom factory here null );Note: Make sure you’re using a recent version of MSAL for Android (v2.0+ recommended) to ensure full support for custom crypto factories and modern cipher modes.
Server-Side/Azure AD Adjustments: None Needed
Good news—you don’t need to make any changes to your backend services or Azure AD settings.
The cipher mode warning relates to how MSAL encrypts tokens locally on the device (in the app’s cache). This doesn’t affect the OAuth 2.0/OIDC flow with Azure AD, which already uses secure HTTPS and industry-standard encryption for all client-server communication. Your access token handling on the server side remains unchanged.
内容的提问来源于stack exchange,提问作者Roar Grønmo

