You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Function与启用Windows身份验证的App Service API证书连接咨询

实现Azure Function通过证书调用启用Windows Auth的Azure App Service REST API方案

我之前帮客户解决过一模一样的场景——Azure Function要调用启用Windows身份验证的App Service API,因为无服务器环境没法直接传递Windows凭据,用客户端证书来做身份验证是最稳妥的方案,下面是一步步的实现指南:

一、核心思路

因为Azure Function是无服务器架构,无法直接获取或传递Windows域身份凭据,所以我们用客户端证书认证替代传统Windows Auth:让App Service信任指定的客户端证书,Azure Function在调用API时携带该证书,App Service验证通过后就会允许请求访问。

二、步骤1:准备并部署证书

  • 先准备一个客户端证书:测试环境可以用自签证书(用New-SelfSignedCertificate PowerShell命令生成),生产环境建议使用CA签发的正规证书
  • 将证书(.pfx格式,带私钥)上传到Azure Function的证书库:在Azure门户进入你的Function App → TLS/SSL设置 → 私有证书(.pfx) → 上传证书并设置密码
  • 将证书的公钥(.cer格式)上传到目标App Service的证书库:进入App Service → TLS/SSL设置 → 公钥证书(.cer) → 上传公钥文件
  • 在App Service的配置里启用客户端证书认证:进入App Service → 设置 → 配置 → 常规设置 → 找到客户端证书选项,设置为「需要」(严格模式)或「可选」(兼容模式)

三、步骤2:配置App Service信任证书

  • 修改App Service的web.config(如果是.NET应用),添加客户端证书验证的配置:
<system.webServer>
  <security>
    <!-- 启用SSL和证书协商 -->
    <access sslFlags="Ssl, SslNegotiateCert" />
    <authentication>
      <windowsAuthentication enabled="true" />
      <anonymousAuthentication enabled="false" />
    </authentication>
  </security>
</system.webServer>
  • (可选)在App Service的应用设置里添加WEBSITE_CLIENT_CERTIFICATE_THUMBPRINT,值设为你的证书指纹,这样只有携带该证书的请求才能通过验证,进一步提升安全性

四、步骤3:配置Azure Function加载证书

  • 在Function App的应用设置里添加WEBSITE_LOAD_CERTIFICATES,值设为你的证书指纹(或者用*加载所有证书),这样Function代码就能访问到证书
  • 如果是.NET开发的Function,代码中可以这样获取证书:
using System.Security.Cryptography.X509Certificates;

// 打开当前用户的证书存储
var store = new X509Store(StoreName.My, StoreLocation.CurrentUser);
store.Open(OpenFlags.ReadOnly);
// 通过指纹查找证书
var certCollection = store.Certificates.Find(
    X509FindType.FindByThumbprint,
    "YOUR_CERTIFICATE_THUMBPRINT",
    validOnly: false
);
store.Close();

// 获取目标证书
var clientCert = certCollection.Count > 0 ? certCollection[0] : throw new InvalidOperationException("Certificate not found");

五、步骤4:Function代码调用API

.NET示例

用HttpClient携带证书发送请求:

using System.Net.Http;
using System.Net.Http.Headers;

var handler = new HttpClientHandler();
handler.ClientCertificates.Add(clientCert);

using var httpClient = new HttpClient(handler);
var apiUrl = "https://your-app-service-name.azurewebsites.net/api/your-endpoint";
var response = await httpClient.GetAsync(apiUrl);

// 确保请求成功
response.EnsureSuccessStatusCode();
var responseContent = await response.Content.ReadAsStringAsync();

Python示例

用requests库携带证书:

import requests

# 证书路径(如果是上传到Function的证书库,也可以用环境变量指定路径)
cert_path = "path/to/your-cert.pfx"
cert_password = "your-cert-password"

response = requests.get(
    "https://your-app-service-name.azurewebsites.net/api/your-endpoint",
    cert=(cert_path, cert_password)
)
response.raise_for_status()
print(response.text)

六、验证与排错

  • 先用Postman测试:导入客户端证书,发送请求到App Service API,确认能正常返回数据
  • 查看Function的日志(Azure门户→Function App→监控→日志),检查是否有证书加载失败、权限不足的错误
  • 如果App Service拒绝请求,检查web.config配置是否正确,证书指纹是否匹配,客户端证书是否有效

内容的提问来源于stack exchange,提问作者IamChandu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:19:04