You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ADFS对接IdentityServer4报MSIS9642无法生成ID令牌配置问题咨询

问题背景

需求为通过ADFS搭建认证体系,IdentityServer用于登录鉴权,因现有SharePoint环境且存在多个Claim Provider,需使用ADFS。
尝试搭建的架构如下:

SPA <--> ADFS <--> IdentityServer

涉及地址

SPA: https://example.com/app  
ADFS: http://fedsrv.example.com/adfs  
ID: https://idp.example.com/spa  

ADFS侧现有配置

  • ADFS中创建应用组OIDC_SPA,包含原生应用Portal和Web APIPortal
  • 原生应用客户端ID为example,重定向URI为https://example.com/app
  • Web API的依赖方标识符为example,配置了Permit everyone策略,声明转换规则PT all为x:[] => issue(claim = x);,客户端权限配置为allatclaims, opened and profile
  • 声明提供方信任配置:
    • CP联合元数据URL:https://idp.example.com/spa/wsfed/FederationMetadata/2007-06/FederationMetadata.xml
    • CP标识符为https://idp.example.com/spa
    • WS-Fed被动端点为https://idp.example.com/spa/wsfed
  • AnchorClaimType配置命令:
set-adfsclaimsprovidertrust -targetidentifier https://idp.example.com/spa -AnchorClaimType http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
  • 主领域映射配置命令:
Set-AdfsWebApiApplication -TargetName OIDC_SPA -ClaimsProviderName "<CP name>"

IdentityServer侧现有配置

  • 新增客户端,ClientID为http://fedsrv.example.com/adfs/services/trust,ProtocolTyp为wsfed
  • RelyingParties配置:
FieldValue
Realmhttp://fedsrv.example.com/adfs/services/trust
TokenTypeurn:oasis:names:tc:SAML:2.0:assertion
SignatureAlgorithmhttp://www.w3.org/2001/04/xmldsig-more#rsa-sha256
DigestAlgorithmhttp://www.w3.org/2001/04/xmlenc#sha256
SamlNameIdentifierFormaturn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
  • IdentityResources已配置opened和profile

报错信息

运行时出现MSIS9642 unable to construct an id token错误


错误原因&修复方案

MSIS9642报错核心原因是ADFS为OIDC客户端签发ID Token时,缺少必填的sub(主体)声明,或sub对应的源声明未正确传入、转换。以下是具体配置错误/遗漏项及修复方法:

  1. 拼写错误修正
    现有配置中客户端权限、IdentityResources配置的opened为拼写错误,正确值为openid,这是OIDC必填scope,优先修正该配置。
  2. ADFS侧声明映射遗漏
    ADFS生成OIDC ID Token的sub声明时,默认需要从传入的声明中提取对应值,当前配置的AnchorClaimType为name声明,但未配置将该声明映射为OIDC标准sub声明的规则,在Web APIPortal的声明转换规则中新增如下规则即可:
c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Value = c.Value, Issuer = c.Issuer);
  1. IdentityServer侧声明输出遗漏
    当前IdentityServer的RelyingParty配置未指定要输出name(即AnchorClaimType对应的声明)给ADFS,在该WS-Fed客户端配置中新增声明映射规则,确保name声明会被包含在返回给ADFS的SAML断言中。同时可将SamlNameIdentifierFormat修改为urn:oasis:names:tc:SAML:2.0:nameid-format:persistent,避免非持久化NameID导致ADFS无法稳定生成sub声明。
  2. 应用组权限校验
    确认原生应用Portal已经被授予了Web APIPortal的allatclaims、openid、profile三个权限,未授予权限的情况下ADFS无法获取足够的声明生成ID Token。
  3. 声明提供方信任规则校验
    检查IdentityServer对应的声明提供方信任配置,确认已配置规则允许name声明传入ADFS,默认情况下ADFS会过滤未明确允许的声明,可新增如下传递所有声明的规则:
c:[] => pass(claim = x);

内容的提问来源于stack exchange,提问作者domiSchenk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 08:36:03