You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AD FS SAML令牌访问SharePoint 2019的更优端点咨询

问题描述

我已为本地SharePoint服务器配置AD FS信赖方信任,成功从AD FS获取到SAML Token(核心响应内容如下)。目前我通过向http://mylocalsharepoint/_trust/default.aspx提交URL编码表单,提取Set-Cookie中的FedAuth Cookie完成认证,但该端点会返回完整网页,而我仅需获取访问令牌。我希望使用XML SOAP消息或XML格式提交请求,而非URL编码表单。发现/_vti_bin/authentication.asmx仅支持用户名密码模式,请问是否存在更合适的端点?

AD FS返回的SAML Token核心内容

<trust:RequestSecurityTokenResponse>
    <trust:Lifetime>
        <wsu:Created xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">2022-10-19T16:56:36.105Z</wsu:Created>
        <wsu:Expires xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">2022-10-19T17:56:36.105Z</wsu:Expires>
    </trust:Lifetime>
    <wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy">
        <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
            <wsa:Address>urn:sharepoint:spsites</wsa:Address>
        </wsa:EndpointReference>
    </wsp:AppliesTo>
    <trust:RequestedSecurityToken>
        <saml:Assertion MajorVersion="1" MinorVersion="1" AssertionID="_3519cbe0-66fb-4bc3-9a40-91ea06cb0ad7" Issuer="http://ms-adfs.intranet/adfs/services/trust" IssueInstant="2022-10-19T16:56:36.230Z" xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion">
            <saml:Conditions NotBefore="2022-10-19T16:56:36.105Z" NotOnOrAfter="2022-10-19T17:56:36.105Z">
                <saml:AudienceRestrictionCondition>
                    <saml:Audience>urn:sharepoint:spsites</saml:Audience>
                </saml:AudienceRestrictionCondition>
            </saml:Conditions>
            <saml:AttributeStatement>
                <saml:Subject>
                    <saml:SubjectConfirmation>
                        <saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod>
                    </saml:SubjectConfirmation>
                </saml:Subject>
                <saml:Attribute AttributeName="emailaddress" AttributeNamespace="http://schemas.xmlsoap.org/ws/2005/05/identity/claims">
                    <saml:AttributeValue>billbates@microsotofu.com</saml:AttributeValue>
                </saml:Attribute>
            </saml:AttributeStatement>
            <saml:AuthenticationStatement AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:X509-PKI" AuthenticationInstant="2022-10-19T16:56:35.639Z">
                <saml:Subject>
                    <saml:SubjectConfirmation>
                        <saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod>
                    </saml:SubjectConfirmation>
                </saml:Subject>
            </saml:AuthenticationStatement>
            <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:SignedInfo>
                    <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                    <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
                    <ds:Reference URI="#_3519cbe0-66fb-4bc3-9a40-91ea06cb0ad7">
                        <ds:Transforms>
                            <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                            <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                        </ds:Transforms>
                        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
                        <ds:DigestValue>gTz6J3z40UUkqOf1DV3gAe4yel5AD0GVPCJ7xI6ac44=</ds:DigestValue>
                    </ds:Reference>
                </ds:SignedInfo>
                <ds:SignatureValue>ftyI5grqS01/g9zpfUuPn24xXMvJ...</ds:SignatureValue>
                <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
                    <X509Data>
                        <X509Certificate>MIICxDCCAaygAwIBAgIQEqN9pL4STbx...</X509Certificate>
                    </X509Data>
                </KeyInfo>
            </ds:Signature>
        </saml:Assertion>
    </trust:RequestedSecurityToken>
    <trust:TokenType>urn:oasis:names:tc:SAML:1.0:assertion</trust:TokenType>
    <trust:RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</trust:RequestType>
    <trust:KeyType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Bearer</trust:KeyType>
</trust:RequestSecurityTokenResponse>
解决方案

你可以使用SharePoint的/_vti_bin/spsecuritytokenissuer.asmx端点,该端点支持通过SOAP提交SAML Token来获取FedAuth和rtFa Cookie,且不会返回完整网页。

使用步骤

  • 构造SOAP请求:将从AD FS获取的SAML Assertion(即<saml:Assertion>...</saml:Assertion>节点内容)嵌入到SOAP消息中,示例如下:
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"
               xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
               xmlns:xsd="http://www.w3.org/2001/XMLSchema">
  <soap:Body>
    <RequestSecurityTokenResponse xmlns="http://docs.oasis-open.org/ws-sx/ws-trust/200512">
      <RequestedSecurityToken>
        <!-- 此处插入你的完整SAML Assertion内容 -->
        <saml:Assertion MajorVersion="1" MinorVersion="1" AssertionID="_3519cbe0-66fb-4bc3-9a40-91ea06cb0ad7" ...>
          <!-- 省略Assertion内部内容 -->
        </saml:Assertion>
      </RequestedSecurityToken>
      <TokenType>urn:oasis:names:tc:SAML:1.0:assertion</TokenType>
      <RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</RequestType>
    </RequestSecurityTokenResponse>
  </soap:Body>
</soap:Envelope>
  • 发送请求:

    • 请求方法:POST
    • 请求URL:http://mylocalsharepoint/_vti_bin/spsecuritytokenissuer.asmx
    • 请求头:设置Content-Type: text/xml; charset=utf-8,同时携带AD FS返回的相关会话Cookie(若存在)
  • 提取Cookie:响应的Set-Cookie头中会包含FedAuth和rtFa,这两个就是所需的访问令牌相关Cookie,无需处理返回的XML响应体。

注意事项

  • 确保SAML Assertion中的Audience值与SharePoint信赖方配置一致(即示例中的urn:sharepoint:spsites)
  • 若使用SAML 2.0 Assertion,只需调整对应命名空间和版本号,端点同样兼容
  • 该端点仅接受SOAP格式的XML请求,不支持URL编码表单

内容的提问来源于stack exchange,提问作者Pea Kay See Es

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 16:45:44