Skip to content

Azure Stack: ADFS: Keyvault Secret cmds don't work #4448

Description

Description

Secret set in a keyvault should succeed if the access permissions were set for the Tenant. But logs show it fails even with proper permissions set.

01:01:06.4380: [INFO] [DESCRIPTION] Create a key vault store to put the certificate secret
01:01:47.9054: [EXCEPTION] System.Management.Automation.RemoteException: ERROR: Operation returned an invalid status code 'Unauthorized'

Yugang's investigation:
This is a bug falling into either stack’s ADFS token service or key-vault service . In detail, the token service gives out a token with type as “bearer” under both original token acquisition request and the later refresh request; but, key-vault service expects: “Bearer”. So the round trip is not working. The workaround is to hard-code to “Bearer” in Key-vault data plane library, which I guess is what PS does. But CLI always uses the type returned from token response, which is the right thing.

{"access_token":"…","token_type":"bearer","expires_in":3600,"resource":"https://management.adfs.azurestack.local/6c2dc67f-8ac0-4573-b8f2-75228aff7491","refresh_token":"…","refresh_token_expires_in":28799,"scope":"openid","id_token":"…"}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

KeyVaultaz keyvaultService AttentionThis issue is responsible by Azure service team.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions