You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:.NET Framework4.8 WebForms集成ITFoxtec SAML与Azure AD实现SAML SSO

.NET Framework 4.8 WebForms 集成 ITFoxtec SAML2 对接 Azure AD SSO 实操指导

核心配置步骤

1. 安装依赖包

通过NuGet安装适配的ITFoxtec包,WebForms可复用其核心逻辑,执行命令:

Install-Package ITfoxtec.Identity.Saml2.Mvc

2. Web.config 关键配置

在<configuration>节点下添加SAML2专属配置节:

<configSections>
  <section name="saml2" type="ITfoxtec.Identity.Saml2.Configuration.Saml2ConfigurationSection, ITfoxtec.Identity.Saml2" />
</configSections>

<saml2 entityId="https://你的应用域名/Saml2/Acs" wantAssertionsSigned="true">
  <identityProviders>
    <add entityId="https://login.microsoftonline.com/你的AzureAD租户ID/v2.0" signOnUrl="https://login.microsoftonline.com/你的AzureAD租户ID/saml2" signOutUrl="https://login.microsoftonline.com/你的AzureAD租户ID/saml2" wantAuthnRequestsSigned="true">
      <signingCertificates>
        <add storeName="AddressBook" storeLocation="CurrentUser" x509FindType="FindByThumbprint" findValue="AzureAD应用的签名证书指纹" />
      </signingCertificates>
    </add>
  </identityProviders>
  <serviceProvider entityId="https://你的应用域名/Saml2/Acs" signingCertificateFile="~/App_Data/你的应用签名证书.pfx" signingCertificatePassword="证书密码" wantAssertionsSigned="true" />
</saml2>

同时修改<system.web>中的认证模式,避免与Forms Auth冲突:

<authentication mode="None" />

3. 实现SAML端点页面

创建两个WebForms页面:SamlLogin.aspx(发起SSO请求)和SamlAcs.aspx(处理Azure AD返回的断言)

SamlLogin.aspx.cs 核心代码

protected void Page_Load(object sender, EventArgs e)
{
    var saml2Configuration = new Saml2Configuration();
    saml2Configuration.Load();
    
    var saml2AuthnRequest = new Saml2AuthnRequest(saml2Configuration)
    {
        Destination = saml2Configuration.IdentityProviders.Default.SignOnUrl,
        Subject = new Saml2NameID(""),
        ForceAuthn = false,
        IsPassive = false,
    };

    saml2AuthnRequest.RelayState = Request.QueryString["ReturnUrl"] ?? "~/";
    saml2AuthnRequest.Create(Request.Url.GetLeftPart(UriPartial.Authority) + ResolveUrl("~/Saml2/Acs"));
    
    Response.Redirect(saml2AuthnRequest.RedirectUrl);
}

SamlAcs.aspx.cs 核心代码

protected void Page_Load(object sender, EventArgs e)
{
    var saml2Configuration = new Saml2Configuration();
    saml2Configuration.Load();

    var saml2AuthnResponse = new Saml2AuthnResponse(saml2Configuration);
    saml2AuthnResponse.ReadSamlResponse(Request.Form["SAMLResponse"]);
    
    if (saml2AuthnResponse.Status != Saml2StatusCodes.Success)
    {
        throw new Exception($"SAML认证失败: {saml2AuthnResponse.StatusMessage}");
    }
    
    saml2AuthnResponse.Validate();
    
    // 提取用户核心信息
    var userId = saml2AuthnResponse.NameID.Value;
    var userClaims = saml2AuthnResponse.ClaimsIdentity.Claims;
    
    // 替换为你的应用登录逻辑,比如生成FormsAuth票据
    FormsAuthentication.SetAuthCookie(userId, false);
    
    // 跳转回原请求页面
    var relayState = Request.Form["RelayState"] ?? "~/";
    Response.Redirect(relayState);
}

4. Azure AD 应用配置要点

  • 进入Azure AD企业应用,将单一登录设置为SAML模式
  • 标识符(实体ID)填写Web.config中serviceProvider的entityId值
  • 回复URL(断言消费者服务URL)设置为https://你的应用域名/Saml2/Acs
  • 确保Azure AD签名证书的指纹与Web.config中的配置完全匹配
  • 配置声明映射,比如将Azure AD的userprincipalname映射为SAML的NameID

5. 常见问题排查

  • 签名验证失败:检查双方证书配置,确保Azure AD公钥已导入应用服务器证书存储,或直接在Web.config中指定证书文件路径
  • RelayState丢失:确认SAML请求中RelayState参数正确传递,Azure AD会原样返回该值
  • 断言过期:调整SAML配置中的超时参数,检查请求里的NotOnOrAfter时间范围

内容的提问来源于stack exchange,提问作者Aniket Ghosh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 07:45:25