You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell为Azure App Service导入ADFS令牌签名证书

Alright, let's break down your problem and fix it step by step. First off, the core issue here is that Azure App Service (a PaaS offering) runs in a sandbox environment that blocks direct writes to the Local Machine certificate store—that's why your Kudu PowerShell command threw that "handle is invalid" error. You can't modify LocalMachine\TrustedPeople directly in App Service, but there are workarounds to get your ADFS token signing certificate trusted by your app.

This approach leverages App Service's native features to make the certificate accessible and trusted by your app without touching the Local Machine store:

  1. Convert your CER to PFX (if needed)
    App Service's certificate library requires PFX files. If you only have a CER (public key), use OpenSSL to wrap it into a PFX:

    openssl pkcs12 -export -nokeys -in website.cer -out website.pfx
    

    You'll be prompted to set a password—just pick any value (since there's no private key here).

  2. Upload the PFX to App Service

    • Go to your App Service in the Azure Portal
    • Left menu > Certificates > Upload Certificate
    • Select your PFX file, enter the password you set, and finish uploading. Note down the certificate's thumbprint from the details page.
  3. Configure your app to load the certificate

    • Go to Configuration > Application settings in your App Service
    • Add a new setting named WEBSITE_LOAD_CERTIFICATES with the value set to your certificate's thumbprint (or use * to load all uploaded certificates)
    • This loads the certificate into the Cert:\CurrentUser\My store. To make your app trust it, run this in Kudu's PowerShell (or implement it in your app's startup code):
      $targetThumbprint = "YOUR_CERT_THUMBPRINT"
      $cert = Get-ChildItem Cert:\CurrentUser\My | Where-Object {$_.Thumbprint -eq $targetThumbprint}
      Import-Certificate -Cert $cert -CertStoreLocation "Cert:\CurrentUser\TrustedPeople" -Verbose
      

Solution 2: Use Azure Key Vault for Certificate Management (Great for Shared Certificates)

If you need to share this certificate across multiple apps or want better security management, use Key Vault:

  1. Upload the CER to Key Vault

    • Open your Key Vault in the Azure Portal
    • Left menu > Certificates > Generate/Import
    • Select Import, upload your website.cer, set a name, and complete the import.
  2. Grant App Service access to Key Vault

    • Enable System-assigned managed identity for your App Service (left menu > Identity > toggle on)
    • Go back to Key Vault > Access policies > Add access policy
    • Select your App Service's managed identity, grant the Certificate > Get permission, and save.
  3. Load and trust the certificate in your app
    Use the Azure Key Vault SDK (in your app's code) to fetch the certificate, then import it into Cert:\CurrentUser\TrustedPeople just like in Solution 1.

Fixing the Subscription Not Found Error

Your issues with Add-AzureCertificate and AzureRM cmdlets are likely due to outdated modules or incorrect context:

  1. Upgrade to the latest Az PowerShell module
    Uninstall the old AzureRM modules and install the modern Az module:

    Uninstall-Module -Name AzureRM -AllVersions -Force
    Install-Module -Name Az -AllowClobber -Scope CurrentUser
    
  2. Re-authenticate and select the correct subscription

    Connect-AzAccount
    # List all your subscriptions to confirm the ID
    Get-AzSubscription
    # Select your target subscription
    Select-AzSubscription -SubscriptionId "YOUR_SUBSCRIPTION_ID"
    

    Now you can use cmdlets like Import-AzWebAppCertificate to manage certificates for your App Service.

Why Did the Kudu Import Fail?

The "handle is invalid" error is a side effect of App Service's sandbox restrictions. The sandbox blocks all writes to the Local Machine certificate store as a security measure—you can only modify the Current User store in this environment.

内容的提问来源于stack exchange,提问作者joym8

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:38:36