arp*_*sai 6 azure asp.net-core-mvc azure-sql-database azure-web-app-service
我们在 Azure 应用服务上部署了 Web 应用程序。我们的数据库也在 Azure 上,配置为使用 AAD 身份验证(我们已分配 AAD 管理员)。
我们在 Web 应用程序中使用以下连接字符串来使用以下连接字符串连接到此服务器和数据库。
数据源 = xxxxxxx.database.windows.net;初始目录 = xxxxxxx;持久安全信息 = False;身份验证 = Active Directory 集成
请注意:通过本地系统使用时,此连接字符串工作正常。但是,当我们在 Azure 应用服务中使用此 conn 字符串时,出现以下错误:
无法验证 Active Directory 中的用户 NT Authority\Anonymous Logon (Authentication=ActiveDirectoryIntegrated)。错误代码0x4BC;state 10 指定的域名格式无效
根据您的描述,我发现您使用了Active Directory集成身份验证。
\n\n\n\n\n要使用集成 Windows 身份验证,您的域\xe2\x80\x99s Active Directory 必须与 Azure Active Directory 联合。连接到数据库的客户端应用程序(或服务)必须在用户\xe2\x80\x99s 域凭据下的加入域的计算机上运行
\n
如果您将 Web 应用程序发布到 Azure,Azure 的 Web 应用程序服务器将不会位于您的域\xe2\x80\x99s Active Directory 中。所以SQL Server不会通过auth。
\n\n我建议您可以尝试使用Active Directory 密码身份验证而不是 Active Directory 集成身份验证。
\n\n使用 azure AD 用户名和密码替换连接字符串,如下所示。效果会很好。
\n\nServer=tcp:brandotest.database.windows.net,1433;Initial Catalog=bradnotestsql;Persist Security Info=False;User ID={your_username};Password={your_password};MultipleActiveResultSets=False;Encrypt=True;TrustServerCertificate=False;Authentication="Active Directory Password";\nRun Code Online (Sandbox Code Playgroud)\n
由于接受的答案有点过时,如果您在 2020 年或之后来到这里,设置集成身份验证的正确方法如下:
(摘自这里,asp.net标准实现)
https://learn.microsoft.com/en-us/azure/app-service/app-service-web-tutorial-connect-msi
添加 Microsoft.Azure.Services.AppAuthentication nuget 包。
通过添加以下内容来修改您的 web.config:(在 configSections 中)
<section name="SqlAuthenticationProviders" type="System.Data.SqlClient.SqlAuthenticationProviderConfigurationSection, System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" />
Run Code Online (Sandbox Code Playgroud)
(进而)
<SqlAuthenticationProviders>
<providers>
<add name="Active Directory Interactive" type="Microsoft.Azure.Services.AppAuthentication.SqlAppAuthenticationProvider, Microsoft.Azure.Services.AppAuthentication" />
</providers>
</SqlAuthenticationProviders>
Run Code Online (Sandbox Code Playgroud)
请务必注意您在那里使用的名称。然后...您的连接字符串将如下所示:
<add name="MyEntities" connectionString="metadata=res://*/Data.MyDB.csdl|res://*/Data.MyDB.ssdl|res://*/Data.MyDB.msl;provider=System.Data.SqlClient;provider connection string="server=tcp:MyDB.database.windows.net;database=MyDB;UID=AnyString;Authentication=Active Directory Interactive;"" providerName="System.Data.EntityClient" />
Run Code Online (Sandbox Code Playgroud)
重要的注意事项是,您在 SqlAuthenticationProviders 部分中指定的名称必须与您在身份验证的连接字符串中使用的名称完全相同。
另一个重要的注意事项是,根据旧的连接字符串,您必须将数据源更改为服务器,并将初始目录更改为数据库。 UID=AnyString是必要的,否则会抛出异常。
如果不严格遵循这些步骤,将会出现一个可爱的错误:
System.Data.Entity.Core.EntityException:底层提供程序在打开时失败。---> System.AggregateException:发生一个或多个错误。---> System.AggregateException:发生一个或多个错误。---> AdalException:指定域名的格式无效。\r\n at ADALNativeWrapper.ADALGetAccessToken(String username, IntPtr password, String stsURL, String servicePrincipalName, ValueType correlationId, String clientId, Boolean* fWindowsIntegrated, Int64& fileTime) \r\n 在 System.Data.SqlClient.ActiveDirectoryNativeAuthenticationProvider.<>c__DisplayClass2_0.b__0()\r\n 在 System.Threading.Tasks.Task`1.InnerInvoke()\r\n 在 System.Threading.Tasks.Task .Execute()\r\n --- 内部异常堆栈跟踪结束
起初,这个错误没有任何意义,但是一旦您看到参数从“数据源”重命名为“服务器”,它就有意义了。
| 归档时间: |
|
| 查看次数: |
20792 次 |
| 最近记录: |