Sitecore CM/CD拓扑下Azure Blob上传报403认证失败求助
Azure Blob存储上传403认证失败(CM/CD拓扑环境)
问题场景
- 使用
Azure.Storage.Blob库从Sitecore网站向Azure Blob存储上传图片 - 本地环境、测试单拓扑环境均正常运行,预发布CM/CD拓扑下上传操作抛出403状态码
- 存储账户为公共账户,本地及测试环境可执行任意操作;关闭预发布环境的Azure Front Door后,问题仍存在
报错信息
Exception: Azure.RequestFailedException Message: Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature. RequestId:8e1769d5-e01e-001e-0499-ac8ce4000000 Time:2022-08-10T09:13:32.0353745Z Status: 403 (Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.) ErrorCode: AuthenticationFailed Additional Information: AuthenticationErrorDetail: The MAC signature found in the HTTP request 'cJB+JGEEjhxJiYsAlcnlZOBw09rreVlAd5eJMis7vD0=' is not the same as any computed signature. Server used following string to sign: 'PUT 887486 application/octet-stream x-ms-blob-type:BlockBlob x-ms-client-request-id:5a970fad-c322-41dd-9c79-be7b52057fdd x-ms-date:Wed, 10 Aug 2022 09:13:32 GMT x-ms-request-id:|NoBMxLCuSY4=.5431b150_8. x-ms-request-root-id:NoBMxLCuSY4= x-ms-return-client-request-id:true x-ms-version:2021-04-10 /[sa_name]/[container_name]/AdvertisementMedia/10c8df42-8803-4acb-38eb-08da7a1ea032/5viawtti.zki.png'
排查与解决方案
1. 验证存储账户密钥与配置一致性
- 核对预发布环境CM/CD节点的存储账户访问密钥,确认与测试/本地环境完全一致,排查是否存在密钥过期、复制时的字符遗漏/多空格问题
- 检查Sitecore配置文件中存储账户的连接字符串,确保CM和CD节点的配置完全相同,无节点间配置差异
2. 检查服务器时间同步
- Azure存储服务要求客户端服务器时间与UTC时间差不超过15分钟,否则会触发签名认证失败。检查预发布CM/CD节点的系统时间,确认已同步到正确的UTC时间,重点排查CD节点是否存在时间偏移
3. 排查请求头干扰
- 从报错的签名字符串可以看到,请求包含
x-ms-request-id和x-ms-request-root-id这类额外头。检查CD节点上是否有自定义中间件、代理或Sitecore模块修改了请求头,导致客户端签名计算时的请求头与服务器端验证时的签名字符串不匹配 - 对比本地/测试环境与预发布环境的请求头差异,确认是否存在额外头被插入的情况
4. 确认权限与身份配置
- 若使用托管身份而非访问密钥,检查预发布环境应用服务的托管身份是否已被授予
Storage Blob Data Contributor等必要权限,且CM/CD节点的身份配置一致 - 即使存储账户为公共,也需确认预发布环境的服务器IP是否在存储账户的防火墙白名单中(若开启了防火墙限制)
5. 核对库版本
- 确认预发布环境的
Azure.Storage.Blob库版本与本地/测试环境完全一致,不同版本的库在签名计算逻辑(尤其是请求头处理)上可能存在差异
6. 隔离测试验证
- 在预发布CD节点上运行独立的上传测试代码(使用相同连接字符串上传小文件),排除Sitecore框架的影响,确认问题根源是环境还是代码
- 使用Azure Storage Explorer在预发布服务器上连接目标存储账户,测试上传操作,验证网络与权限是否正常
内容的提问来源于stack exchange,提问作者Marius Popa
相关产品推荐
相关产品推荐

