You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AppSettings.Json中IdentityServer的Key属性作用及生产配置方法

关于Duende Identity Server签名密钥配置的疑问解答

为什么移除IdentityServer:Key段会报错?

你混淆了ASP.NET Core DataProtection和Duende IdentityServer签名密钥两个完全独立的体系:

  • DataProtection是ASP.NET Core用来保护自身敏感数据(比如Cookie、会话信息)的机制,你配置的AddDataProtection().PersistKeysToDbContext只作用于这个体系,和IdentityServer签发JWT令牌的签名密钥无关。
  • IdentityServer要求必须明确配置签名凭证,用来签发和验证OAuth2/OIDC的令牌,所以移除Key段会触发No signing credential is configured错误。

IdentityServer:Key配置段的作用

这个配置段是IdentityServer指定签名凭证来源的唯一入口,不管是开发临时密钥、自动管理的轮换密钥,还是第三方证书,都需要通过它来定义:

  • 开发环境的Type:Development是Duende提供的快速调试模式,会自动生成内存级临时签名密钥(服务重启就丢失),不用手动准备密钥文件/证书,方便开发。
  • 所谓的“自动管理并轮换密钥”,本质是通过配置Key段的特定Type(比如FileSystem、SqlServer)并开启AutoGenerate和AutoRotate参数来实现的,不是完全不需要这个配置段。

生产环境配置方案

根据你的部署场景,推荐以下几种配置方式:

1. 文件系统存储(单服务器/共享存储多节点)

适合单服务器部署,或者多服务器共享同一文件存储(比如NAS)的场景,自动生成并轮换密钥:

"IdentityServer": {
  "Key": {
    "Type": "FileSystem",
    "FilePath": "/var/identityserver/signingkeys.json", // 替换为你的实际路径
    "AutoGenerate": true,
    "AutoRotate": true,
    "RotationInterval": "90.00:00:00", // 可选,默认90天轮换
    "RetentionDuration": "180.00:00:00" // 可选,保留旧密钥180天用于验证旧令牌
  }
}

2. 数据库存储(分布式多节点)

适合分布式部署的场景,密钥存在数据库中,所有节点共用:
首先安装Duende.IdentityServer.Storage NuGet包,然后配置:

"IdentityServer": {
  "Key": {
    "Type": "SqlServer", // 支持SqlServer、PostgreSQL等,对应不同包
    "ConnectionString": "YourProductionDbConnectionString",
    "AutoGenerate": true,
    "AutoRotate": true
  }
}

同时在服务注册时确保启用密钥存储:

builder.Services.AddIdentityServer()
    .AddSigningKeyStore() // 启用数据库存储签名密钥
    .AddOtherServices(); // 其他IdentityServer服务配置

3. 证书存储(高安全要求场景)

适合对安全性要求高的生产环境,使用本地证书或云密钥保管库的证书:

本地证书示例:

"IdentityServer": {
  "Key": {
    "Type": "Store",
    "StoreName": "My",
    "StoreLocation": "LocalMachine", // 或CurrentUser
    "Name": "CN=YourIdentityServerCertificate" // 证书的主题名称
  }
}

Azure Key Vault示例:

"IdentityServer": {
  "Key": {
    "Type": "KeyVault",
    "VaultUrl": "https://your-vault.vault.azure.net/",
    "Name": "your-signing-key"
  }
}

内容的提问来源于stack exchange,提问作者J.Kennedy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 21:20:31