You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdS4部署Linux后Web App OIDC认证报IDX20803错误求助

IdentityServer4部署Linux后OIDC客户端抛出IDX20803错误

问题详情

本地搭建的IdentityServer4(IdS4)服务与采用Authorization Code模式的OIDC交互式认证Web应用运行正常,但将IdS4部署到Linux服务器后,Web应用触发以下错误:

System.InvalidOperationException: IDX20803: Unable to obtain configuration from: 'System.String'.
   at Microsoft.IdentityModel.Protocols.ConfigurationManager`1.GetConfigurationAsync(CancellationToken cancel)
   at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsyncInternal(AuthenticationProperties properties)
   at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsync(AuthenticationProperties properties)
   at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.ChallengeAsync(AuthenticationProperties properties)
   at Microsoft.AspNetCore.Authentication.AuthenticationService.ChallengeAsync(HttpContext context, String scheme, AuthenticationProperties properties)
   at Microsoft.AspNetCore.Authorization.Policy.AuthorizationMiddlewareResultHandler.HandleAsync(RequestDelegate next, HttpContext context, AuthorizationPolicy policy, PolicyAuthorizationResult authorizeResult)
   at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
   at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
   at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddleware.Invoke(HttpContext context)

当前可确认的情况:

  • 浏览器能正常访问IdS4主页及配置端点:https://pruebasids.xxxxx.com/ 和 https://pruebasids.xxxxx.com/.well-known/openid-configuration/
  • 通过Client Credentials模式调用https://pruebasids.xxxxx.com/connect/token端点可正常获取令牌

相关配置代码

IdS4客户端配置

new Client {
    ClientId = "myWebapp",
    ClientSecrets = { new Secret("myPassword".Sha256()) },

    AllowedGrantTypes = GrantTypes.Code,

    RedirectUris = { "https://localhost:5444/signin-oidc" },
    PostLogoutRedirectUris = { "https://localhost:5444/home/index" },

    AllowOfflineAccess = true,
    AllowedScopes = { "openid", "profile", "myApi.read", "myApi.write", "role" },
    RequirePkce = true,
    RequireConsent = false,
    AllowPlainTextPkce = false
},

IdS4 Startup配置

public void ConfigureServices(IServiceCollection services) {
    services.AddDbContext<ApplicationContext>(options =>
        options.UseSqlServer(Configuration.GetConnectionString("myDB"))
    );

    services.AddIdentityServer()
        .AddDeveloperSigningCredential()
        .AddInMemoryApiResources(Config.ApiResources)
        .AddInMemoryClients(Config.Clients)
        .AddInMemoryIdentityResources(Config.IdentityResources)
        .AddInMemoryApiScopes(Config.ApiScopes)
        .AddProfileService<ProfileService>();

    services.AddControllersWithViews();
}

public void Configure(IApplicationBuilder app, IWebHostEnvironment env) {
    if (env.IsDevelopment()) {
        app.UseDeveloperExceptionPage();
    }

    app.UseHttpsRedirection();
    app.UseStaticFiles();
    app.UseRouting();

    app.UseIdentityServer();
    app.UseAuthorization();

    app.UseEndpoints(endpoints => endpoints.MapDefaultControllerRoute());
}

Web应用Startup配置

public void ConfigureServices(IServiceCollection services)
{
    services.AddControllersWithViews().AddJsonOptions(options => options.JsonSerializerOptions.PropertyNamingPolicy = null);

    services.AddHttpClient();

    services.AddAuthentication(options =>
    {
        options.DefaultScheme = "Cookie";
        options.DefaultChallengeScheme = "oidc";
    })
        .AddCookie("Cookie", options =>
        {
            options.AccessDeniedPath = "/home/accessdenied";
        })
        .AddOpenIdConnect("oidc", options =>
        {
            options.Authority = "https://pruebasids.xxxxx.com";
            options.MetadataAddress = "https://pruebasids.xxxxx.com/.well-known/openid-configuration";
            options.ClientId = "myWebapp";
            options.ClientSecret = "myPassword";
            options.AccessDeniedPath = "/home/accessdenied";
            options.SignedOutCallbackPath = "/home/index";

            options.ResponseType = OpenIdConnectResponseType.Code;
            options.UsePkce = true;
            options.ResponseMode = OpenIdConnectResponseMode.Query;
            options.SaveTokens = true;
            options.Scope.Add("myApi.read");

            options.GetClaimsFromUserInfoEndpoint = true;
            options.ClaimActions.MapUniqueJsonKey("role", "role", "role");
            options.TokenValidationParameters.NameClaimType = "name";
            options.TokenValidationParameters.RoleClaimType = "role";
        });
}

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }
    else
    {
        app.UseExceptionHandler("/Home/Error");
        app.UseHsts();
    }
    app.UseHttpsRedirection();
    app.UseStaticFiles();

    app.UseRouting();

    app.UseAuthentication();
    app.UseAuthorization();

    app.UseEndpoints(endpoints =>
    {
        endpoints.MapControllerRoute(
            name: "default",
            pattern: "{controller=Home}/{action=Index}/{id?}");
    });
}

解决方案建议

1. 修复证书信任问题

Linux服务器可能未信任IdS4的HTTPS证书(比如自签名证书),导致Web应用的HttpClient无法验证证书,从而无法获取配置。

临时测试方案(生产环境禁用)

在Web应用的OIDC配置中添加证书跳过验证:

.AddOpenIdConnect("oidc", options =>
{
    // 其他配置保持不变
    options.BackchannelHttpHandler = new HttpClientHandler
    {
        ServerCertificateCustomValidationCallback = (message, cert, chain, errors) => true
    };
});

生产环境方案

将IdS4的证书导入Web应用服务器的系统信任存储:

  • Ubuntu/Debian:将证书复制到/usr/local/share/ca-certificates/,运行sudo update-ca-certificates
  • CentOS/RHEL:将证书复制到/etc/pki/ca-trust/source/anchors/,运行sudo update-ca-trust extract

2. 统一Metadata地址格式

浏览器访问的配置端点带有末尾斜杠,而Web应用配置的地址无斜杠,可能引发301重定向导致配置获取失败。修改Web应用的MetadataAddress:

options.MetadataAddress = "https://pruebasids.xxxxx.com/.well-known/openid-configuration/";

3. 替换开发者签名凭证(生产环境必备)

当前IdS4使用AddDeveloperSigningCredential(),该凭证仅适合开发环境,重启服务器后会生成新密钥,建议替换为持久化签名凭证:

// 使用PFX证书文件示例
services.AddIdentityServer()
    .AddSigningCredential(new X509Certificate2("path/to/your-cert.pfx", "cert-password"))
    // 其余配置保持不变

4. 排查网络连通性

在Web应用服务器上执行以下命令,验证是否能正常访问IdS4配置端点:

curl -v https://pruebasids.xxxxx.com/.well-known/openid-configuration/

若返回非200状态码,需检查服务器防火墙出站规则(确保443端口开放)、DNS解析是否正常。


内容的提问来源于stack exchange,提问作者Erick González

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 20:45:55