You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure API Management中Validate-JWT禁用证书验证咨询

Solution for Disabling Certificate Validation in APIM's JWT Validation with Self-Signed OpenID Config

Hey there, I’ve tackled this exact issue with Azure API Management’s JWT validation using asymmetric signatures and self-signed certificates—let’s break down your options.

Instead of disabling certificate validation entirely (which carries security risks), the best practice is to add your self-signed certificate to APIM’s trusted root store. This tells APIM to trust SSL certificates issued by this root CA, so it won’t throw errors when calling your OpenID config URL.

Here’s how to set it up:

  • Log into the Azure Portal and navigate to your API Management instance.
  • Go to Certificates > Trusted Root Certificates in the left-hand menu.
  • Click Add and upload your self-signed certificate (supports .cer or .pfx formats).
  • Once the certificate is imported, APIM will automatically trust any SSL certificate signed by this root CA—your <validate-jwt> with <openid-config> will work without issues.

If you absolutely need to skip certificate validation (e.g., for a test environment), you can’t do this directly with the <openid-config> tag. Instead, you’ll need to manually fetch the OpenID configuration and JWKS keys using the <send-request> strategy (which supports skipping certificate checks), then pass those keys to <validate-jwt>.

Here’s a sample policy snippet:

<!-- Fetch OpenID config, ignoring certificate errors -->
<send-request mode="new" response-variable-name="openidConfig" timeout="20" ignore-certificate-errors="true">
    <set-url>https://your-self-signed-domain/.well-known/openid-configuration</set-url>
    <set-method>GET</set-method>
</send-request>

<!-- Fetch JWKS keys using the URI from the config, again ignoring cert errors -->
<send-request mode="new" response-variable-name="jwks" timeout="20" ignore-certificate-errors="true">
    <set-url>@(((JObject)context.Variables["openidConfig"]).GetValue("jwks_uri").ToString())</set-url>
    <set-method>GET</set-method>
</send-request>

<!-- Validate JWT using the fetched public keys -->
<validate-jwt header-name="Authorization" failed-validation-httpcode="401" failed-validation-error-message="Invalid token">
    <issuers>
        <issuer>https://your-issuer-identifier/</issuer>
    </issuers>
    <issuer-signing-keys>
        <!-- Extract the first public key from the JWKS response -->
        <key>@(((JObject)context.Variables["jwks"])["keys"][0]["x5c"][0].ToString())</key>
    </issuer-signing-keys>
</validate-jwt>

Important Notes:

  • Disabling certificate validation (ignore-certificate-errors="true") exposes your APIM instance to man-in-the-middle attacks—only use this in non-production environments.
  • If your JWKS has multiple keys, you’ll need to adjust the policy to loop through all keys instead of just the first one.

内容的提问来源于stack exchange,提问作者danutz_plusplus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:42:05