【发布时间】:2015-09-26 18:16:34
【问题描述】:
我正在尝试列出我的 Windows azure 存储帐户中的容器。但我遇到了一个异常
“远程服务器返回错误:(403) 服务器无法验证请求。确保 Authorization 标头的值格式正确,包括签名..”
但是我已经按照给出的说明包含了签名,有人发现我的代码有什么错误吗?
private static String SignThis(string StringToSign,string Key,string Account)
{
String signature = string.Empty;
byte[] unicodeKey = Convert.FromBase64String(Key);
using (HMACSHA256 hmacSha256 = new HMACSHA256(unicodeKey))
{
Byte[] dataToHmac = System.Text.Encoding.UTF8.GetBytes(StringToSign);
signature = Convert.ToBase64String(hmacSha256.ComputeHash(dataToHmac));
}
String authorizationHeader = String.Format(
System.Globalization.CultureInfo.InvariantCulture,
"{0} {1}:{2}",
"SharedKey",
Account,
signature);
return authorizationHeader;
}
static void ListContainers()
{
Thread.CurrentThread.CurrentCulture = System.Globalization.CultureInfo.InvariantCulture;
string Key = @"MyStorageAccountKey";
string Account = @"MyStorageAccountName";
DateTime dt = DateTime.UtcNow;
string dataStr = dt.ToString ("R",System.Globalization.CultureInfo.InvariantCulture);
string StringToSign = String.Format("GET\n"
+ "\n" // content encoding
+ "\n" // content language
+ "\n" // content length
+ "\n" // content md5
+ "\n" // content type
+ "\n" // date
+ "\n" // if modified since
+ "\n" // if match
+ "\n" // if none match
+ "\n" // if unmodified since
+ "\n" // range
+ "x-ms-date:" + dataStr + "\nx-ms-version:2014-02-14\n" // headers
+ "/{0}\ncomp:list", Account);
string auth = SignThis(StringToSign, Key, Account);
string method = "GET";
string urlPath = string.Format ("https://{0}.blob.core.windows.net/?comp=list", Account);
Uri uri = new Uri(urlPath);
HttpWebRequest reque = (HttpWebRequest)WebRequest.Create(uri);
reque.Method = method;
reque.Headers.Add("Authorization", auth);
reque.Headers.Add("x-ms-date",dataStr);
reque.Headers.Add("x-ms-version", "2014-02-14");
using (HttpWebResponse response = (HttpWebResponse) reque.GetResponse ()) {
using (StreamReader reader = new StreamReader(response.GetResponseStream()))
{
string text = reader.ReadToEnd();
}
}
}
Edit : String i 用于生成签名
GET
x-ms-date:Tue, 14 Jul 2015 18:38:16 GMT
x-ms-version:2014-02-14
/MyStorageAccountName/
comp:list
编辑:我收到了异常响应:
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthenticationFailed</Code><Message>Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.
RequestId:2fc74ef8-0001-0083-2664-be8850000000
Time:2015-07-14T18:38:18.0831721Z</Message><AuthenticationErrorDetail>The MAC signature found in the HTTP request '5rqWNl2i8kuZF6haCRqFr1S0viOM9eLjz4L/zU6GCsg=' is not the same as any computed signature. Server used following string to sign: 'GET
x-ms-date:Tue, 14 Jul 2015 18:38:16 GMT
x-ms-version:2014-02-14
/MyStorageAccountName/
comp:list'.</AuthenticationErrorDetail></Error>
最终编辑:在进行了 gauvrav 指定的所有更改后,我发现我使用的 storagekey 错误,更换正确的后,它工作正常。
此错误可能还有其他变化:请参考link
【问题讨论】:
-
错误响应应包含用于对所使用的存储服务进行签名的字符串,因此您可以使用它来验证您的字符串签名中是否缺少某些内容。
-
谢谢,你能解释一下如何获取存储服务的“string-to-sign”的值吗?
-
@SerdarOzler-Microsoft 的意思是,如果您运行代码并让 Fiddler 运行(或通过解析您得到的 WebException 的响应来检查错误),您将在错误消息中看到使用的 StringToSign由服务器。您可以将其与您的 StringToSign 进行比较,以查看不匹配的内容。我用这个技巧在你的代码中找到了问题。
标签: c# asp.net azure azure-storage azure-blob-storage