代码之家  ›  专栏  ›  技术社区  ›  Narendra Jangir

azure密钥保管库401身份验证错误

  •  1
  • Narendra Jangir  · 技术社区  · 8 年前

    我正在为我的azure无状态服务结构应用程序从密钥保管库获取机密值,并为100s密钥保管库机密中仅2个密钥保管库机密获取401依赖性错误(如果我通过连接的应用程序洞察进行检查)。 下面是通过应用程序洞察显示的一个密钥保管库机密的依赖性错误的屏幕截图。

    image

    这里的请求路径是 https://mykeyvaultname.vault.azure.net:443/secrets/PushMessagingSecretsTopicName/?api-version=7.0

    我获取金库密钥的代码如下所示-

        public async Task<string> GetSecretAsync(string secretName, string clientId, string appKey, string vaultAddress)
                {
                    string secretValue = string.Empty;
                    if (string.IsNullOrEmpty(secretName))
                        throw new ArgumentNullException(nameof(secretName));
    
                    if (string.IsNullOrEmpty(clientId))
                        throw new ArgumentNullException(nameof(clientId));
    
                    if (string.IsNullOrEmpty(appKey))
                        throw new ArgumentNullException(nameof(appKey));
    
                    if (string.IsNullOrEmpty(vaultAddress))
                        throw new ArgumentNullException(nameof(vaultAddress));
    
                    var secretIdentifier = vaultAddress + "secrets/" + secretName;
                    string cacheKey = secretIdentifier + clientId + appKey;
    
                    secretValue = await GetSecretValue(clientId, appKey, secretIdentifier, cacheKey);
    
                    return secretValue;
                }
    
    private async Task<string> GetSecretValue(string clientId, string appKey, string secretIdentifier, string cacheKey)
            {
                IAdAuthentication authToken = new AdAuthentication
                {
                    ClientId = clientId,
                    AppKey = appKey
                };
                KeyVaultClient keyVaultClient = new KeyVaultClient(authToken.GetAuthenticationTokenAsync);
    
                // Get secret from the KeyVault.
    
                SecretBundle secret = null;
    
                Task tskGetSecret = Task.Run(async () =>
                {
                            //Here I am getting exception with response
                            secret = await keyVaultClient.GetSecretAsync(secretIdentifier).ConfigureAwait(false);
                });
                await Task.WhenAny(tskGetSecret);
    
                if (tskGetSecret.IsFaulted || tskGetSecret.IsCanceled)
                {
                    secret = null;
                }
    
                string secretValue = string.Empty;
                if (secret != null && secret.Value != null)
                {
                    secretValue = secret.Value.Trim();
                }
    
                return secretValue;
            }
    

    我已经进一步调试了这个问题,下面是我的发现-

    1. 获取特定keyvaultsecret的值时发生异常。

    2. 除此之外,还成功获取了机密值。

    3. 例外情况是: Microsoft.Rest.TransientFaultHandling.HttpRequestWithStatusException: 'Response status code indicates server error: 401 (Unauthorized).'

    堆栈跟踪:

    at Microsoft.Rest.RetryDelegatingHandler.<>c__DisplayClass11_0.<<SendAsync>b__1>d.MoveNext()
    
    1 回复  |  直到 7 年前
        1
  •  0
  •   Narendra Jangir    7 年前

    我正在关闭此问题,因为通过进一步调试,我发现此问题不是间歇性的,也与特定的密钥保管库机密无关。获取应用程序的第一个密钥保管库机密值时,始终会出现此问题。我要结束这个问题,并打开一个 new issue 有适当的细节。

    推荐文章