IdS4部署Linux后Web App OIDC认证报IDX20803错误求助
IdentityServer4部署Linux后OIDC客户端抛出IDX20803错误
问题详情
本地搭建的IdentityServer4(IdS4)服务与采用Authorization Code模式的OIDC交互式认证Web应用运行正常,但将IdS4部署到Linux服务器后,Web应用触发以下错误:
System.InvalidOperationException: IDX20803: Unable to obtain configuration from: 'System.String'. at Microsoft.IdentityModel.Protocols.ConfigurationManager`1.GetConfigurationAsync(CancellationToken cancel) at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsyncInternal(AuthenticationProperties properties) at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsync(AuthenticationProperties properties) at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.ChallengeAsync(AuthenticationProperties properties) at Microsoft.AspNetCore.Authentication.AuthenticationService.ChallengeAsync(HttpContext context, String scheme, AuthenticationProperties properties) at Microsoft.AspNetCore.Authorization.Policy.AuthorizationMiddlewareResultHandler.HandleAsync(RequestDelegate next, HttpContext context, AuthorizationPolicy policy, PolicyAuthorizationResult authorizeResult) at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddleware.Invoke(HttpContext context)
当前可确认的情况:
- 浏览器能正常访问IdS4主页及配置端点:
https://pruebasids.xxxxx.com/和https://pruebasids.xxxxx.com/.well-known/openid-configuration/ - 通过Client Credentials模式调用
https://pruebasids.xxxxx.com/connect/token端点可正常获取令牌
相关配置代码
IdS4客户端配置
new Client { ClientId = "myWebapp", ClientSecrets = { new Secret("myPassword".Sha256()) }, AllowedGrantTypes = GrantTypes.Code, RedirectUris = { "https://localhost:5444/signin-oidc" }, PostLogoutRedirectUris = { "https://localhost:5444/home/index" }, AllowOfflineAccess = true, AllowedScopes = { "openid", "profile", "myApi.read", "myApi.write", "role" }, RequirePkce = true, RequireConsent = false, AllowPlainTextPkce = false },
IdS4 Startup配置
public void ConfigureServices(IServiceCollection services) { services.AddDbContext<ApplicationContext>(options => options.UseSqlServer(Configuration.GetConnectionString("myDB")) ); services.AddIdentityServer() .AddDeveloperSigningCredential() .AddInMemoryApiResources(Config.ApiResources) .AddInMemoryClients(Config.Clients) .AddInMemoryIdentityResources(Config.IdentityResources) .AddInMemoryApiScopes(Config.ApiScopes) .AddProfileService<ProfileService>(); services.AddControllersWithViews(); } public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseIdentityServer(); app.UseAuthorization(); app.UseEndpoints(endpoints => endpoints.MapDefaultControllerRoute()); }
Web应用Startup配置
public void ConfigureServices(IServiceCollection services) { services.AddControllersWithViews().AddJsonOptions(options => options.JsonSerializerOptions.PropertyNamingPolicy = null); services.AddHttpClient(); services.AddAuthentication(options => { options.DefaultScheme = "Cookie"; options.DefaultChallengeScheme = "oidc"; }) .AddCookie("Cookie", options => { options.AccessDeniedPath = "/home/accessdenied"; }) .AddOpenIdConnect("oidc", options => { options.Authority = "https://pruebasids.xxxxx.com"; options.MetadataAddress = "https://pruebasids.xxxxx.com/.well-known/openid-configuration"; options.ClientId = "myWebapp"; options.ClientSecret = "myPassword"; options.AccessDeniedPath = "/home/accessdenied"; options.SignedOutCallbackPath = "/home/index"; options.ResponseType = OpenIdConnectResponseType.Code; options.UsePkce = true; options.ResponseMode = OpenIdConnectResponseMode.Query; options.SaveTokens = true; options.Scope.Add("myApi.read"); options.GetClaimsFromUserInfoEndpoint = true; options.ClaimActions.MapUniqueJsonKey("role", "role", "role"); options.TokenValidationParameters.NameClaimType = "name"; options.TokenValidationParameters.RoleClaimType = "role"; }); } public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } else { app.UseExceptionHandler("/Home/Error"); app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); }); }
解决方案建议
1. 修复证书信任问题
Linux服务器可能未信任IdS4的HTTPS证书(比如自签名证书),导致Web应用的HttpClient无法验证证书,从而无法获取配置。
临时测试方案(生产环境禁用)
在Web应用的OIDC配置中添加证书跳过验证:
.AddOpenIdConnect("oidc", options => { // 其他配置保持不变 options.BackchannelHttpHandler = new HttpClientHandler { ServerCertificateCustomValidationCallback = (message, cert, chain, errors) => true }; });
生产环境方案
将IdS4的证书导入Web应用服务器的系统信任存储:
- Ubuntu/Debian:将证书复制到
/usr/local/share/ca-certificates/,运行sudo update-ca-certificates - CentOS/RHEL:将证书复制到
/etc/pki/ca-trust/source/anchors/,运行sudo update-ca-trust extract
2. 统一Metadata地址格式
浏览器访问的配置端点带有末尾斜杠,而Web应用配置的地址无斜杠,可能引发301重定向导致配置获取失败。修改Web应用的MetadataAddress:
options.MetadataAddress = "https://pruebasids.xxxxx.com/.well-known/openid-configuration/";
3. 替换开发者签名凭证(生产环境必备)
当前IdS4使用AddDeveloperSigningCredential(),该凭证仅适合开发环境,重启服务器后会生成新密钥,建议替换为持久化签名凭证:
// 使用PFX证书文件示例 services.AddIdentityServer() .AddSigningCredential(new X509Certificate2("path/to/your-cert.pfx", "cert-password")) // 其余配置保持不变
4. 排查网络连通性
在Web应用服务器上执行以下命令,验证是否能正常访问IdS4配置端点:
curl -v https://pruebasids.xxxxx.com/.well-known/openid-configuration/
若返回非200状态码,需检查服务器防火墙出站规则(确保443端口开放)、DNS解析是否正常。
内容的提问来源于stack exchange,提问作者Erick González
相关产品推荐
相关产品推荐

