You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SSL终止负载均衡器反向代理下Issuer名称不匹配问题解决

问题:Apigee代理调用.NET Core API时出现Issuer不匹配错误

我尝试通过Apigee代理部署数据API,该API基于.NET Core 3.0运行在AWS EC2实例的IIS服务器上。通过Apigee代理调用数据API时,IIS服务器抛出以下异常:

Category: IdentityServer4.AccessTokenValidation.IdentityServerAuthenticationHandler
EventId: 0
RequestId: 80003dde-0002-fe00-b63f-84710c7967bb
RequestPath: /v0.1/wells/dpr
SpanId: |74716527-4b0a0a0f46d32af3.
TraceId: 74716527-4b0a0a0f46d32af3
ParentId: 

Policy error while contacting the discovery endpoint https://example.com: Issuer name does not match authority: http://example.com

Exception: 
System.InvalidOperationException: Policy error while contacting the discovery endpoint https://example.com: Issuer name does not match authority: http://example.com
   at IdentityModel.AspNetCore.OAuth2Introspection.PostConfigureOAuth2IntrospectionOptions.GetIntrospectionEndpointFromDiscoveryDocument(OAuth2IntrospectionOptions options)
   at IdentityModel.AspNetCore.OAuth2Introspection.PostConfigureOAuth2IntrospectionOptions.InitializeIntrospectionClient(OAuth2IntrospectionOptions options)
   at IdentityModel.AspNetCore.OAuth2Introspection.OAuth2IntrospectionHandler.LoadClaimsForToken(String token)
   at IdentityModel.AspNetCore.OAuth2Introspection.OAuth2IntrospectionHandler.HandleAuthenticateAsync()
   at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.AuthenticateAsync()
   at Microsoft.AspNetCore.Authentication.AuthenticationService.AuthenticateAsync(HttpContext context, String scheme)
   at IdentityServer4.AccessTokenValidation.IdentityServerAuthenticationHandler.HandleAuthenticateAsync()

经分析,问题源于负载均衡器执行SSL终止后,以HTTP而非HTTPS调用IIS服务器,导致出现issuer name does not match错误。

尝试的解决方案及过程

初次配置ForwardedHeaders未解决

我尝试在.NET Core API中添加UseForwardedHeaders配置:

public static IApplicationBuilder UseIdServer(this IApplicationBuilder app)
{
        app.UseForwardedHeaders(new ForwardedHeadersOptions
        {
            ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto
        });
        app.UseIdentityServer();

        return app;
}

该配置在Configure方法中调用:

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }

    app
        .UseCORS()
        .UseCustomCookiePolicy(env)
        .UseIdServer()
        .UseRouting()
        .UseAuth()
        .UseEndpoints(endpoints =>
        {
            endpoints.MapControllers();
        });
}

但该配置并未解决问题。

更新1:按微软文档配置仍未成功

我还按照微软文档的建议在startup.cs中配置ForwardedHeaders,但仍未成功:

public void ConfigureServices(IServiceCollection services)
{
    services.Configure<ForwardedHeadersOptions>(options =>
    {
        options.ForwardedHeaders =
            ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto;
    });
...
}

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    app.UseForwardedHeaders();
    ...
}

更新2:强制设置HTTPS解决问题

我尝试在Startup.cs的Configure方法中强制将请求协议设置为https:

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    app.Use((context, next) =>
    {
        context.Request.Scheme = "https";
        return next();
    });
    ...
}

此方法解决了问题,但我想了解如何正确配置中间件中的X-Forwarded-*头。

更新3:仅启用XForwardedProto解决问题

感谢@Chen提供的资料,我在Configure方法中按如下方式配置ForwardedHeaders:

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
...
    app.UseForwardedHeaders(new ForwardedHeadersOptions
    {
        ForwardedHeaders = ForwardedHeaders.XForwardedProto
    });

...
}

之前我同时启用了ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto,但仅启用ForwardedHeaders.XForwardedProto就解决了问题。


内容的提问来源于stack exchange,提问作者Georgi Koemdzhiev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 20:03:19