使用AD FS SAML令牌访问SharePoint 2019的更优端点咨询
问题描述
我已为本地SharePoint服务器配置AD FS信赖方信任,成功从AD FS获取到SAML Token(核心响应内容如下)。目前我通过向http://mylocalsharepoint/_trust/default.aspx提交URL编码表单,提取Set-Cookie中的FedAuth Cookie完成认证,但该端点会返回完整网页,而我仅需获取访问令牌。我希望使用XML SOAP消息或XML格式提交请求,而非URL编码表单。发现/_vti_bin/authentication.asmx仅支持用户名密码模式,请问是否存在更合适的端点?
AD FS返回的SAML Token核心内容
<trust:RequestSecurityTokenResponse> <trust:Lifetime> <wsu:Created xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">2022-10-19T16:56:36.105Z</wsu:Created> <wsu:Expires xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">2022-10-19T17:56:36.105Z</wsu:Expires> </trust:Lifetime> <wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"> <wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing"> <wsa:Address>urn:sharepoint:spsites</wsa:Address> </wsa:EndpointReference> </wsp:AppliesTo> <trust:RequestedSecurityToken> <saml:Assertion MajorVersion="1" MinorVersion="1" AssertionID="_3519cbe0-66fb-4bc3-9a40-91ea06cb0ad7" Issuer="http://ms-adfs.intranet/adfs/services/trust" IssueInstant="2022-10-19T16:56:36.230Z" xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion"> <saml:Conditions NotBefore="2022-10-19T16:56:36.105Z" NotOnOrAfter="2022-10-19T17:56:36.105Z"> <saml:AudienceRestrictionCondition> <saml:Audience>urn:sharepoint:spsites</saml:Audience> </saml:AudienceRestrictionCondition> </saml:Conditions> <saml:AttributeStatement> <saml:Subject> <saml:SubjectConfirmation> <saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod> </saml:SubjectConfirmation> </saml:Subject> <saml:Attribute AttributeName="emailaddress" AttributeNamespace="http://schemas.xmlsoap.org/ws/2005/05/identity/claims"> <saml:AttributeValue>billbates@microsotofu.com</saml:AttributeValue> </saml:Attribute> </saml:AttributeStatement> <saml:AuthenticationStatement AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:X509-PKI" AuthenticationInstant="2022-10-19T16:56:35.639Z"> <saml:Subject> <saml:SubjectConfirmation> <saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod> </saml:SubjectConfirmation> </saml:Subject> </saml:AuthenticationStatement> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:SignedInfo> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/> <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> <ds:Reference URI="#_3519cbe0-66fb-4bc3-9a40-91ea06cb0ad7"> <ds:Transforms> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/> </ds:Transforms> <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> <ds:DigestValue>gTz6J3z40UUkqOf1DV3gAe4yel5AD0GVPCJ7xI6ac44=</ds:DigestValue> </ds:Reference> </ds:SignedInfo> <ds:SignatureValue>ftyI5grqS01/g9zpfUuPn24xXMvJ...</ds:SignatureValue> <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#"> <X509Data> <X509Certificate>MIICxDCCAaygAwIBAgIQEqN9pL4STbx...</X509Certificate> </X509Data> </KeyInfo> </ds:Signature> </saml:Assertion> </trust:RequestedSecurityToken> <trust:TokenType>urn:oasis:names:tc:SAML:1.0:assertion</trust:TokenType> <trust:RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</trust:RequestType> <trust:KeyType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Bearer</trust:KeyType> </trust:RequestSecurityTokenResponse>
解决方案
你可以使用SharePoint的/_vti_bin/spsecuritytokenissuer.asmx端点,该端点支持通过SOAP提交SAML Token来获取FedAuth和rtFa Cookie,且不会返回完整网页。
使用步骤
- 构造SOAP请求:将从AD FS获取的SAML Assertion(即
<saml:Assertion>...</saml:Assertion>节点内容)嵌入到SOAP消息中,示例如下:
<?xml version="1.0" encoding="utf-8"?> <soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"> <soap:Body> <RequestSecurityTokenResponse xmlns="http://docs.oasis-open.org/ws-sx/ws-trust/200512"> <RequestedSecurityToken> <!-- 此处插入你的完整SAML Assertion内容 --> <saml:Assertion MajorVersion="1" MinorVersion="1" AssertionID="_3519cbe0-66fb-4bc3-9a40-91ea06cb0ad7" ...> <!-- 省略Assertion内部内容 --> </saml:Assertion> </RequestedSecurityToken> <TokenType>urn:oasis:names:tc:SAML:1.0:assertion</TokenType> <RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</RequestType> </RequestSecurityTokenResponse> </soap:Body> </soap:Envelope>
发送请求:
- 请求方法:POST
- 请求URL:
http://mylocalsharepoint/_vti_bin/spsecuritytokenissuer.asmx - 请求头:设置
Content-Type: text/xml; charset=utf-8,同时携带AD FS返回的相关会话Cookie(若存在)
提取Cookie:响应的Set-Cookie头中会包含
FedAuth和rtFa,这两个就是所需的访问令牌相关Cookie,无需处理返回的XML响应体。
注意事项
- 确保SAML Assertion中的
Audience值与SharePoint信赖方配置一致(即示例中的urn:sharepoint:spsites) - 若使用SAML 2.0 Assertion,只需调整对应命名空间和版本号,端点同样兼容
- 该端点仅接受SOAP格式的XML请求,不支持URL编码表单
内容的提问来源于stack exchange,提问作者Pea Kay See Es
相关产品推荐
相关产品推荐

