Microsoft Graph NuGet包V4.19+版本导致API调用挂起超时问题排查
问题现象
使用Microsoft Graph API访问SharePoint站点时,NuGet包版本4.18及以下运行正常,但4.19及以上版本会导致API调用挂起,最终超时抛出"A task was canceled"错误。已排查代码死锁无问题,最小示例程序在执行GetSiteIdAsync获取Site Id步骤时挂起。代码如下:
internal async Task Initialize() { await GetSpAccessTokenAsync(); await GetSiteIdAsync(); } private async Task GetSpAccessTokenAsync() { try { Console.WriteLine("Get certificate."); X509Certificate2 certificate = GetCertificate(cfg.GraphCertificate, cfg.GraphPrivateKey, cfg.GraphPassphrase); if (certificate != null) { Console.WriteLine("Certificate obtained. Get access token."); AuthenticationResult authResult = await GetAccessTokenAsync(certificate); accessTokenExpiryDate = TimeZoneInfo.ConvertTimeFromUtc(authResult.ExpiresOn.UtcDateTime, TimeZoneInfo.FindSystemTimeZoneById("Central Standard Time")); Console.WriteLine($"Token expiry date: {accessTokenExpiryDate}"); client = new GraphServiceClient( new DelegateAuthenticationProvider( (reqMsg) => { // Append the access token to the request. reqMsg.Headers.Authorization = new AuthenticationHeaderValue("bearer", authResult.AccessToken); return Task.FromResult(0); })); } } catch (Exception e) { Console.WriteLine($"Error in GetSpAccessTokenAsync(). {e.Message}"); throw; } } private async Task<AuthenticationResult> GetAccessTokenAsync(X509Certificate2 certificate) { string[] scopes = new string[] { "https://graph.microsoft.com/.default" }; IConfidentialClientApplication app; app = ConfidentialClientApplicationBuilder.Create(cfg.GraphSpApplicationId) .WithAuthority(new Uri(cfg.CertificateAuthority)) .WithCertificate(certificate) .Build(); AuthenticationResult authenticationResult = await app.AcquireTokenForClient(scopes).ExecuteAsync(); return authenticationResult; } private async Task GetSiteIdAsync() { try { Console.WriteLine("Get site id."); Site site = await client.Sites .GetByPath(cfg.SharePointSiteUrl.AbsolutePath, cfg.SharePointSiteUrl.DnsSafeHost) .Request() .GetAsync(); Console.WriteLine("Site API invoked."); siteId = site.Id; Console.WriteLine($"Site id = {siteId}"); } catch (Exception e) { Console.WriteLine($"Exception in GetSiteIdAsync(). {e.Message}"); } }
补充环境信息:3台服务器中2台出现该问题,1台可正常运行,正协调部署Wireshark抓包,现寻求前置排查思路。
排查思路
- 检查.NET版本与依赖兼容性:对比故障/正常服务器的.NET运行时版本,以及
System.Net.Http、Microsoft.Identity.Client等依赖库版本,确认是否存在版本过低或冲突。 - 验证TLS配置差异:Graph SDK 4.19+可能默认启用更高版本TLS(如TLS 1.3),检查故障服务器是否启用TLS 1.2/1.3,对比注册表中
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols下的TLS配置项。 - 排查代理与网络策略:确认故障服务器的代理配置(环境变量、应用内设置)是否与正常服务器一致;检查防火墙/安全组是否拦截Graph API请求;用
curl或Invoke-WebRequest测试服务器到https://graph.microsoft.com的基础连通性。 - 证书与身份验证日志:检查故障服务器证书的存储位置、私钥读取权限;在MSAL初始化时添加日志,查看身份验证过程是否有隐藏异常:
app = ConfidentialClientApplicationBuilder.Create(cfg.GraphSpApplicationId) .WithAuthority(new Uri(cfg.CertificateAuthority)) .WithCertificate(certificate) .WithLogging((level, message, containsPii) => { Console.WriteLine($"MSAL Log: {level} - {message}"); }, LogLevel.Verbose) .Build(); - 自定义HTTP客户端配置:Graph SDK 4.19+可能修改了默认HTTP客户端设置,尝试手动创建
HttpClient并传入GraphServiceClient,覆盖超时、连接池等配置:var httpClient = new HttpClient(new HttpClientHandler()) { Timeout = TimeSpan.FromMinutes(5) }; client = new GraphServiceClient(httpClient, new DelegateAuthenticationProvider(...)); - 系统资源与事件日志:检查故障服务器的CPU、内存、带宽使用率,确认是否资源耗尽;查看系统事件日志,排查网络、进程相关异常记录。
内容的提问来源于stack exchange,提问作者gs_rider
相关产品推荐
相关产品推荐

