SSL终止负载均衡器反向代理下Issuer名称不匹配问题解决
问题:Apigee代理调用.NET Core API时出现Issuer不匹配错误
我尝试通过Apigee代理部署数据API,该API基于.NET Core 3.0运行在AWS EC2实例的IIS服务器上。通过Apigee代理调用数据API时,IIS服务器抛出以下异常:
Category: IdentityServer4.AccessTokenValidation.IdentityServerAuthenticationHandler EventId: 0 RequestId: 80003dde-0002-fe00-b63f-84710c7967bb RequestPath: /v0.1/wells/dpr SpanId: |74716527-4b0a0a0f46d32af3. TraceId: 74716527-4b0a0a0f46d32af3 ParentId: Policy error while contacting the discovery endpoint https://example.com: Issuer name does not match authority: http://example.com Exception: System.InvalidOperationException: Policy error while contacting the discovery endpoint https://example.com: Issuer name does not match authority: http://example.com at IdentityModel.AspNetCore.OAuth2Introspection.PostConfigureOAuth2IntrospectionOptions.GetIntrospectionEndpointFromDiscoveryDocument(OAuth2IntrospectionOptions options) at IdentityModel.AspNetCore.OAuth2Introspection.PostConfigureOAuth2IntrospectionOptions.InitializeIntrospectionClient(OAuth2IntrospectionOptions options) at IdentityModel.AspNetCore.OAuth2Introspection.OAuth2IntrospectionHandler.LoadClaimsForToken(String token) at IdentityModel.AspNetCore.OAuth2Introspection.OAuth2IntrospectionHandler.HandleAuthenticateAsync() at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.AuthenticateAsync() at Microsoft.AspNetCore.Authentication.AuthenticationService.AuthenticateAsync(HttpContext context, String scheme) at IdentityServer4.AccessTokenValidation.IdentityServerAuthenticationHandler.HandleAuthenticateAsync()
经分析,问题源于负载均衡器执行SSL终止后,以HTTP而非HTTPS调用IIS服务器,导致出现issuer name does not match错误。
尝试的解决方案及过程
初次配置ForwardedHeaders未解决
我尝试在.NET Core API中添加UseForwardedHeaders配置:
public static IApplicationBuilder UseIdServer(this IApplicationBuilder app) { app.UseForwardedHeaders(new ForwardedHeadersOptions { ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto }); app.UseIdentityServer(); return app; }
该配置在Configure方法中调用:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } app .UseCORS() .UseCustomCookiePolicy(env) .UseIdServer() .UseRouting() .UseAuth() .UseEndpoints(endpoints => { endpoints.MapControllers(); }); }
但该配置并未解决问题。
更新1:按微软文档配置仍未成功
我还按照微软文档的建议在startup.cs中配置ForwardedHeaders,但仍未成功:
public void ConfigureServices(IServiceCollection services) { services.Configure<ForwardedHeadersOptions>(options => { options.ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto; }); ... } public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { app.UseForwardedHeaders(); ... }
更新2:强制设置HTTPS解决问题
我尝试在Startup.cs的Configure方法中强制将请求协议设置为https:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { app.Use((context, next) => { context.Request.Scheme = "https"; return next(); }); ... }
此方法解决了问题,但我想了解如何正确配置中间件中的X-Forwarded-*头。
更新3:仅启用XForwardedProto解决问题
感谢@Chen提供的资料,我在Configure方法中按如下方式配置ForwardedHeaders:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { ... app.UseForwardedHeaders(new ForwardedHeadersOptions { ForwardedHeaders = ForwardedHeaders.XForwardedProto }); ... }
之前我同时启用了ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto,但仅启用ForwardedHeaders.XForwardedProto就解决了问题。
内容的提问来源于stack exchange,提问作者Georgi Koemdzhiev
相关产品推荐
相关产品推荐

