You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在B2C Policy中仅加密SAML断言的属性(而非整个断言)

好问题!在Azure AD B2C的SAML自定义策略中,要实现仅加密断言里的特定属性(而非整个断言),需要通过配置自定义策略来实现,具体步骤如下:

1. 准备并配置加密证书

首先你需要一个用于加密的X.509证书,将其上传到Azure AD B2C的密钥容器中(比如创建一个名为B2C_1A_SamlEncryptionCert的密钥引用)。然后在TrustFrameworkExtensions.xml中添加该证书的引用配置:

<ClaimsProviders>
  <ClaimsProvider>
    <DisplayName>Token Encryption Configuration</DisplayName>
    <TechnicalProfiles>
      <TechnicalProfile Id="JwtIssuer">
        <Metadata>
          <!-- 指定符合SAML Core 2.0规范的加密算法 -->
          <Item Key="KeyEncryptionAlgorithm">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</Item>
        </Metadata>
        <CryptographicKeys>
          <Key Id="Encryption" StorageReferenceId="B2C_1A_SamlEncryptionCert"/>
        </CryptographicKeys>
      </TechnicalProfile>
    </TechnicalProfiles>
  </ClaimsProvider>
</ClaimsProviders>
2. 修改SAML断言颁发的技术配置文件

找到负责生成SAML断言的TechnicalProfile(通常ID为Saml2AssertionIssuer或类似),不要开启整个断言的加密(即不要设置<Item Key="assertionsencrypted">true</Item>),而是在需要加密的输出声明上标记Encrypted="true":

<TechnicalProfile Id="Saml2AssertionIssuer">
  <DisplayName>SAML 2.0 Assertion Issuer</DisplayName>
  <Protocol Name="SAML2"/>
  <OutputTokenFormat>SAML2</OutputTokenFormat>
  <Metadata>
    <!-- 确保不要开启整个断言加密 -->
    <!-- <Item Key="assertionsencrypted">true</Item> -->
    <Item Key="AttributeNameFormat">urn:oasis:names:tc:SAML:2.0:attrname-format:basic</Item>
  </Metadata>
  <CryptographicKeys>
    <Key Id="MetadataSigning" StorageReferenceId="B2C_1A_SamlIdpCert"/>
    <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SamlIdpCert"/>
    <!-- 指定用于属性加密的密钥 -->
    <Key Id="Encryption" StorageReferenceId="B2C_1A_SamlEncryptionCert"/>
  </CryptographicKeys>
  <OutputClaims>
    <!-- 无需加密的属性,正常输出 -->
    <OutputClaim ClaimTypeReferenceId="displayName"/>
    <OutputClaim ClaimTypeReferenceId="givenName"/>
    <!-- 需要加密的属性,添加Encrypted="true"标记 -->
    <OutputClaim ClaimTypeReferenceId="email" Encrypted="true"/>
    <OutputClaim ClaimTypeReferenceId="phoneNumber" Encrypted="true"/>
    <OutputClaim ClaimTypeReferenceId="extension_privateInfo" Encrypted="true"/>
  </OutputClaims>
</TechnicalProfile>
3. 关键注意事项
  • 不要同时开启断言加密和属性加密:如果设置了assertionsencrypted=true,整个断言会被加密,里面的所有属性自然也会被加密,单独标记属性加密就没有意义了。
  • SP端需支持解密:确保服务提供商(SP)拥有对应加密证书的私钥,并且他们的SAML配置能够处理<EncryptedAttribute>元素(这是SAML Core 2.0第6节定义的标准加密属性格式)。
  • 证书有效性:加密证书必须是有效的X.509证书,建议使用2048位以上的密钥长度,并且在过期前及时更新。

这样配置后,Azure AD B2C生成的SAML断言中,只有你标记了Encrypted="true"的属性会被加密,其他属性保持明文状态,完全符合SAML Core 2.0的规范要求。

内容的提问来源于stack exchange,提问作者Sooraj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:16:21