如何在B2C Policy中仅加密SAML断言的属性(而非整个断言)
好问题!在Azure AD B2C的SAML自定义策略中,要实现仅加密断言里的特定属性(而非整个断言),需要通过配置自定义策略来实现,具体步骤如下:
1. 准备并配置加密证书
首先你需要一个用于加密的X.509证书,将其上传到Azure AD B2C的密钥容器中(比如创建一个名为B2C_1A_SamlEncryptionCert的密钥引用)。然后在TrustFrameworkExtensions.xml中添加该证书的引用配置:
<ClaimsProviders> <ClaimsProvider> <DisplayName>Token Encryption Configuration</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="JwtIssuer"> <Metadata> <!-- 指定符合SAML Core 2.0规范的加密算法 --> <Item Key="KeyEncryptionAlgorithm">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</Item> </Metadata> <CryptographicKeys> <Key Id="Encryption" StorageReferenceId="B2C_1A_SamlEncryptionCert"/> </CryptographicKeys> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider> </ClaimsProviders>
2. 修改SAML断言颁发的技术配置文件
找到负责生成SAML断言的TechnicalProfile(通常ID为Saml2AssertionIssuer或类似),不要开启整个断言的加密(即不要设置<Item Key="assertionsencrypted">true</Item>),而是在需要加密的输出声明上标记Encrypted="true":
<TechnicalProfile Id="Saml2AssertionIssuer"> <DisplayName>SAML 2.0 Assertion Issuer</DisplayName> <Protocol Name="SAML2"/> <OutputTokenFormat>SAML2</OutputTokenFormat> <Metadata> <!-- 确保不要开启整个断言加密 --> <!-- <Item Key="assertionsencrypted">true</Item> --> <Item Key="AttributeNameFormat">urn:oasis:names:tc:SAML:2.0:attrname-format:basic</Item> </Metadata> <CryptographicKeys> <Key Id="MetadataSigning" StorageReferenceId="B2C_1A_SamlIdpCert"/> <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SamlIdpCert"/> <!-- 指定用于属性加密的密钥 --> <Key Id="Encryption" StorageReferenceId="B2C_1A_SamlEncryptionCert"/> </CryptographicKeys> <OutputClaims> <!-- 无需加密的属性,正常输出 --> <OutputClaim ClaimTypeReferenceId="displayName"/> <OutputClaim ClaimTypeReferenceId="givenName"/> <!-- 需要加密的属性,添加Encrypted="true"标记 --> <OutputClaim ClaimTypeReferenceId="email" Encrypted="true"/> <OutputClaim ClaimTypeReferenceId="phoneNumber" Encrypted="true"/> <OutputClaim ClaimTypeReferenceId="extension_privateInfo" Encrypted="true"/> </OutputClaims> </TechnicalProfile>
3. 关键注意事项
- 不要同时开启断言加密和属性加密:如果设置了
assertionsencrypted=true,整个断言会被加密,里面的所有属性自然也会被加密,单独标记属性加密就没有意义了。 - SP端需支持解密:确保服务提供商(SP)拥有对应加密证书的私钥,并且他们的SAML配置能够处理
<EncryptedAttribute>元素(这是SAML Core 2.0第6节定义的标准加密属性格式)。 - 证书有效性:加密证书必须是有效的X.509证书,建议使用2048位以上的密钥长度,并且在过期前及时更新。
这样配置后,Azure AD B2C生成的SAML断言中,只有你标记了Encrypted="true"的属性会被加密,其他属性保持明文状态,完全符合SAML Core 2.0的规范要求。
内容的提问来源于stack exchange,提问作者Sooraj
相关产品推荐
相关产品推荐

