Description
Secret set in a keyvault should succeed if the access permissions were set for the Tenant. But logs show it fails even with proper permissions set.
01:01:06.4380: [INFO] [DESCRIPTION] Create a key vault store to put the certificate secret
01:01:47.9054: [EXCEPTION] System.Management.Automation.RemoteException: ERROR: Operation returned an invalid status code 'Unauthorized'
Yugang's investigation:
This is a bug falling into either stack’s ADFS token service or key-vault service . In detail, the token service gives out a token with type as “bearer” under both original token acquisition request and the later refresh request; but, key-vault service expects: “Bearer”. So the round trip is not working. The workaround is to hard-code to “Bearer” in Key-vault data plane library, which I guess is what PS does. But CLI always uses the type returned from token response, which is the right thing.
{"access_token":"…","token_type":"bearer","expires_in":3600,"resource":"https://management.adfs.azurestack.local/6c2dc67f-8ac0-4573-b8f2-75228aff7491","refresh_token":"…","refresh_token_expires_in":28799,"scope":"openid","id_token":"…"}
Description
Secret set in a keyvault should succeed if the access permissions were set for the Tenant. But logs show it fails even with proper permissions set.
01:01:06.4380: [INFO] [DESCRIPTION] Create a key vault store to put the certificate secret
01:01:47.9054: [EXCEPTION] System.Management.Automation.RemoteException: ERROR: Operation returned an invalid status code 'Unauthorized'
Yugang's investigation:
This is a bug falling into either stack’s ADFS token service or key-vault service . In detail, the token service gives out a token with type as “bearer” under both original token acquisition request and the later refresh request; but, key-vault service expects: “Bearer”. So the round trip is not working. The workaround is to hard-code to “Bearer” in Key-vault data plane library, which I guess is what PS does. But CLI always uses the type returned from token response, which is the right thing.
{"access_token":"…","token_type":"bearer","expires_in":3600,"resource":"https://management.adfs.azurestack.local/6c2dc67f-8ac0-4573-b8f2-75228aff7491","refresh_token":"…","refresh_token_expires_in":28799,"scope":"openid","id_token":"…"}