繁体   English   中英

通过.NET库将Azure密钥保险库证书添加到Azure批处理帐户

[英]Adding Azure key vault certificate to Azure Batch account via .NET libs

我需要自动创建一个Azure Batch帐户。 其中一部分是从现有的Azure密钥保管库向帐户添加证书。 我想我已经拥有了所有需要的东西,但我无法将它们全部融合在一起。 我有一个KeyVault.Models.CertificateBundle对象和一个Management.Batch.Models.BatchAccount对象,但是我不确定如何将它们融为一体。

我的代码如下所示:

// Create Batch account
var storageAccount = new Models.AutoStorageBaseProperties(storageAccountId);
mgmtClient.BatchAccount.Create(resourceGroupName, accountName,
    new Models.BatchAccountCreateParameters()
    {
        Location = clusterZone,
        AutoStorage = storageAccount
    });

string certName;
Models.CertificateCreateOrUpdateParameters certParams;

// Add certificate
using (KeyVaultClient kvClient = new KeyVaultClient(new KeyVaultClient.AuthenticationCallback(GetKeyVaultToken)))
{
    var cert = kvClient.GetCertificateAsync(certId).GetAwaiter().GetResult();
    string thumbprint = Convert.ToBase64String(cert.X509Thumbprint);
    string cer = Convert.ToBase64String(cert.Cer);
    certParams = new Models.CertificateCreateOrUpdateParameters(Convert.ToBase64String(cert.Cer), cert.Id, thumbprint: thumbprint, format: Models.CertificateFormat.Cer, type: cert.ContentType);
    certName = $"SHA1-{thumbprint}"; // not sure about this one
}

// failing with a complaint about the cert name
mgmtClient.Certificate.Create(resourceGroupName, accountName, certName, certParams);

我收到的这段代码的确切错误是:

'certificateName' does not match expected pattern '^[\\w]+-[\\w]+$'.

certName看起来像SHA1-XXXXXXXXXXXXXXXXXXXXXX+XXXX= 指纹中有一些非字母数字字符。 我只是在猜测这是SHA1,但除此之外,这个名称对我来说似乎很合适。 我不确定我缺少什么。

我也很乐意接受某人针对此特定问题的简便解决方案。

'certificateName'与预期的模式'^ [\\ w] +-[\\ w] + $'不匹配。

您可以调试代码并从Azure keyvault检查指纹。 在您的代码中,您从代码中获得的指纹与认证指纹不同。 我得到了带有以下代码的认证指纹。

X509Certificate2 x509 = new X509Certificate2();
x509.Import(cert.Cer);
var thumbprint = x509.Thumbprint;

以下是我用来将证书添加到Azure批处理帐户的演示代码。

var credentials = SdkContext.AzureCredentialsFactory.FromFile(@"cred file path");
var resourceGroup = "resourceGroup";
var accountName = "batchAccountName";
var subscriptionId = "subscriptionName";
var certificateIdentifier = "https://keyvaultName.vault.azure.net/certificates/certName/xxxxx";
var batchManagementClient = new BatchManagementClient(credentials)
        {
            SubscriptionId = subscriptionId
        };
var azureServiceTokenProvider = new AzureServiceTokenProvider();

var keyVaultClient =
            new KeyVaultClient(
                new KeyVaultClient.AuthenticationCallback(azureServiceTokenProvider.KeyVaultTokenCallback));
var cert = keyVaultClient.GetCertificateAsync(certificateIdentifier).Result;
X509Certificate2 x509 = new X509Certificate2();
x509.Import(cert.Cer);
var thumbprint = x509.Thumbprint;
var certConent = Convert.ToBase64String(cert.Cer);
var certName = $"SHA1-{thumbprint}";
var result= batchManagementClient.Certificate.CreateAsync(resourceGroup, accountName, certName, new CertificateCreateOrUpdateParametersInner
        {
            Thumbprint = thumbprint,
            Data = certConent,
            ThumbprintAlgorithm = "SHA1",
            Format = CertificateFormat.Cer,

        }).Result;

测试结果:

在此处输入图片说明

暂无
暂无

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM