如何在Java中获取Azure AD应用客户端密钥过期日期
我来帮你搞定这个问题!要通过Azure SDK for Java获取Azure AD应用注册的凭据过期日期,你需要用到Microsoft Graph SDK for Java——因为Azure AD的应用凭据信息是通过Graph API来管理的,而非Azure Management SDK(后者更多用于管理VM、存储这类Azure资源)。下面是完整的实现步骤:
步骤1:添加必要的依赖
首先在你的pom.xml里引入Microsoft Graph SDK和Azure身份认证相关的依赖(用最新稳定版即可):
<dependencies> <!-- Microsoft Graph SDK 核心依赖 --> <dependency> <groupId>com.microsoft.graph</groupId> <artifactId>microsoft-graph</artifactId> <version>6.7.0</version> </dependency> <!-- Azure Identity 用于获取Graph API的访问令牌 --> <dependency> <groupId>com.azure</groupId> <artifactId>azure-identity</artifactId> <version>1.12.0</version> </dependency> </dependencies>
步骤2:配置认证权限
你需要确保用于认证的主体(服务主体或你的个人账户)拥有Application.Read.All权限:
- 如果用服务主体:在Azure AD里给该服务主体添加「Microsoft Graph」的应用权限,选择
Application.Read.All,然后点击「授予管理员同意」。 - 如果用个人账户:添加「Microsoft Graph」的委派权限,同样选择
Application.Read.All,并确保账户有足够的租户权限。
步骤3:编写Java代码获取凭据过期日期
下面是完整的代码示例,这里用服务主体认证(ClientSecretCredential),适合后台服务场景;如果是桌面应用,可以换成InteractiveBrowserCredential这类交互式认证方式:
import com.azure.identity.ClientSecretCredential; import com.azure.identity.ClientSecretCredentialBuilder; import com.microsoft.graph.models.Application; import com.microsoft.graph.models.PasswordCredential; import com.microsoft.graph.requests.GraphServiceClient; import okhttp3.Request; import java.util.List; public class AppCredentialExpiryChecker { public static void main(String[] args) { // 替换成你的租户和认证信息 String tenantId = "你的Azure AD租户ID"; String authClientId = "用于认证的服务主体Client ID"; String authClientSecret = "用于认证的服务主体密钥"; String targetAppClientId = "你要查询的应用的Client ID"; // 创建服务主体认证凭据 ClientSecretCredential credential = new ClientSecretCredentialBuilder() .tenantId(tenantId) .clientId(authClientId) .clientSecret(authClientSecret) .build(); // 初始化Graph Service客户端 GraphServiceClient<Request> graphClient = GraphServiceClient .builder() .authenticationProvider(request -> { // 获取Graph API的访问令牌 String accessToken = credential.getToken("https://graph.microsoft.com/.default").block().getToken(); request.addHeader("Authorization", "Bearer " + accessToken); return request; }) .buildClient(); try { // 通过Client ID查询目标应用(Azure AD中AppID/ClientID是唯一的) Application targetApp = graphClient.applications() .filter("appId eq '" + targetAppClientId + "'") .buildRequest() .get() .getCurrentPage() .get(0); System.out.println("=== 应用【" + targetApp.displayName + "】的凭据信息 ==="); // 处理密码凭据(也就是你说的客户端密钥) List<PasswordCredential> passwordCreds = targetApp.passwordCredentials; if (passwordCreds != null && !passwordCreds.isEmpty()) { System.out.println("\n--- 密码凭据(客户端密钥)---"); for (PasswordCredential cred : passwordCreds) { System.out.println("凭据名称: " + cred.displayName); System.out.println("过期日期: " + cred.endDateTime); System.out.println("创建日期: " + cred.startDateTime); System.out.println("------------------------"); } } else { System.out.println("\n未找到密码凭据"); } // 处理证书凭据(如果你的应用用了证书认证) List<com.microsoft.graph.models.KeyCredential> keyCreds = targetApp.keyCredentials; if (keyCreds != null && !keyCreds.isEmpty()) { System.out.println("\n--- 证书凭据 ---"); for (com.microsoft.graph.models.KeyCredential cred : keyCreds) { System.out.println("凭据名称: " + cred.displayName); System.out.println("过期日期: " + cred.endDateTime); System.out.println("创建日期: " + cred.startDateTime); System.out.println("------------------------"); } } else { System.out.println("\n未找到证书凭据"); } } catch (Exception e) { e.printStackTrace(); System.err.println("获取凭据信息失败: " + e.getMessage()); } } }
关键注意事项
- Graph API的必要性:Azure Management SDK无法直接读取AD应用的凭据细节,必须通过Microsoft Graph API来获取。
- 权限验证:如果运行时报403错误,一定要检查权限是否正确配置,尤其是应用权限需要管理员手动同意。
- Client ID唯一性:Azure AD中每个应用的
appId(即Client ID)是全局唯一的,所以用filter("appId eq 'xxx'")可以精准定位目标应用。
内容的提问来源于stack exchange,提问作者rupa
相关产品推荐
相关产品推荐

