求助:.NET Framework4.8 WebForms集成ITFoxtec SAML与Azure AD实现SAML SSO
.NET Framework 4.8 WebForms 集成 ITFoxtec SAML2 对接 Azure AD SSO 实操指导
核心配置步骤
1. 安装依赖包
通过NuGet安装适配的ITFoxtec包,WebForms可复用其核心逻辑,执行命令:
Install-Package ITfoxtec.Identity.Saml2.Mvc
2. Web.config 关键配置
在<configuration>节点下添加SAML2专属配置节:
<configSections> <section name="saml2" type="ITfoxtec.Identity.Saml2.Configuration.Saml2ConfigurationSection, ITfoxtec.Identity.Saml2" /> </configSections> <saml2 entityId="https://你的应用域名/Saml2/Acs" wantAssertionsSigned="true"> <identityProviders> <add entityId="https://login.microsoftonline.com/你的AzureAD租户ID/v2.0" signOnUrl="https://login.microsoftonline.com/你的AzureAD租户ID/saml2" signOutUrl="https://login.microsoftonline.com/你的AzureAD租户ID/saml2" wantAuthnRequestsSigned="true"> <signingCertificates> <add storeName="AddressBook" storeLocation="CurrentUser" x509FindType="FindByThumbprint" findValue="AzureAD应用的签名证书指纹" /> </signingCertificates> </add> </identityProviders> <serviceProvider entityId="https://你的应用域名/Saml2/Acs" signingCertificateFile="~/App_Data/你的应用签名证书.pfx" signingCertificatePassword="证书密码" wantAssertionsSigned="true" /> </saml2>
同时修改<system.web>中的认证模式,避免与Forms Auth冲突:
<authentication mode="None" />
3. 实现SAML端点页面
创建两个WebForms页面:SamlLogin.aspx(发起SSO请求)和SamlAcs.aspx(处理Azure AD返回的断言)
SamlLogin.aspx.cs 核心代码
protected void Page_Load(object sender, EventArgs e) { var saml2Configuration = new Saml2Configuration(); saml2Configuration.Load(); var saml2AuthnRequest = new Saml2AuthnRequest(saml2Configuration) { Destination = saml2Configuration.IdentityProviders.Default.SignOnUrl, Subject = new Saml2NameID(""), ForceAuthn = false, IsPassive = false, }; saml2AuthnRequest.RelayState = Request.QueryString["ReturnUrl"] ?? "~/"; saml2AuthnRequest.Create(Request.Url.GetLeftPart(UriPartial.Authority) + ResolveUrl("~/Saml2/Acs")); Response.Redirect(saml2AuthnRequest.RedirectUrl); }
SamlAcs.aspx.cs 核心代码
protected void Page_Load(object sender, EventArgs e) { var saml2Configuration = new Saml2Configuration(); saml2Configuration.Load(); var saml2AuthnResponse = new Saml2AuthnResponse(saml2Configuration); saml2AuthnResponse.ReadSamlResponse(Request.Form["SAMLResponse"]); if (saml2AuthnResponse.Status != Saml2StatusCodes.Success) { throw new Exception($"SAML认证失败: {saml2AuthnResponse.StatusMessage}"); } saml2AuthnResponse.Validate(); // 提取用户核心信息 var userId = saml2AuthnResponse.NameID.Value; var userClaims = saml2AuthnResponse.ClaimsIdentity.Claims; // 替换为你的应用登录逻辑,比如生成FormsAuth票据 FormsAuthentication.SetAuthCookie(userId, false); // 跳转回原请求页面 var relayState = Request.Form["RelayState"] ?? "~/"; Response.Redirect(relayState); }
4. Azure AD 应用配置要点
- 进入Azure AD企业应用,将单一登录设置为SAML模式
标识符(实体ID)填写Web.config中serviceProvider的entityId值回复URL(断言消费者服务URL)设置为https://你的应用域名/Saml2/Acs- 确保Azure AD签名证书的指纹与Web.config中的配置完全匹配
- 配置声明映射,比如将Azure AD的
userprincipalname映射为SAML的NameID
5. 常见问题排查
- 签名验证失败:检查双方证书配置,确保Azure AD公钥已导入应用服务器证书存储,或直接在Web.config中指定证书文件路径
- RelayState丢失:确认SAML请求中RelayState参数正确传递,Azure AD会原样返回该值
- 断言过期:调整SAML配置中的超时参数,检查请求里的
NotOnOrAfter时间范围
内容的提问来源于stack exchange,提问作者Aniket Ghosh
相关产品推荐
相关产品推荐

