在Web服务中找不到Windows Azure管理证书

时间:2013-01-04 08:52:38

标签: c# .net azure configuration certificate

我想使用Windows Azure Management API以编程方式扩展我的Web服务。首先,我尝试获得管理证书。

我使用makecert.exe创建了一个新的自签名证书。它描述了here

makecert -sky exchange -r -n "CN=<CertificateName>" -pe -a sha1 -len 2048 -ss My "<CertificateName>.cer"

然后我将我的证书上传到我的azure订阅(this way)。 我真的在新的和以前的管理门户中看到我上传的证书。

现在我将以下code添加到我的webservice

private X509Certificate2 GetX509Certificate2()
    {

        // The thumbprint value of the management certificate.
        // You must replace the string with the thumbprint of a 
        // management certificate associated with your subscription.
        string certThumbprint = "mythumprint...";

        // Create a reference to the My certificate store.
        X509Store certStore = new X509Store(StoreName.My, StoreLocation.CurrentUser);

        // Try to open the store.
        try
        {
            certStore.Open(OpenFlags.ReadOnly);
        }
        catch (Exception e)
        {
            if (e is CryptographicException)
            {
                Console.WriteLine("Error: The store is unreadable.");
                debugTable.persist("Error: The store is unreadable.");
            }
            else if (e is SecurityException)
            {
                Console.WriteLine("Error: You don't have the required permission.");
                debugTable.persist("Error: You don't have the required permission.");
            }
            else if (e is ArgumentException)
            {
                Console.WriteLine("Error: Invalid values in the store.");
                debugTable.persist("Error: Invalid values in the store.");
            }
            else
            {
                debugTable.persist("Something got wrong with certificate");
                return null;
            }
        }

        // Find the certificate that matches the thumbprint.
        X509Certificate2Collection certCollection = certStore.Certificates.Find(X509FindType.FindByThumbprint, certThumbprint, false);
        certStore.Close();

        // Check to see if our certificate was added to the collection. If no, throw an error, if yes, create a certificate using it.
        if (0 == certCollection.Count)
        {
            Console.WriteLine("Error: No certificate found containing thumbprint " + certThumbprint);
            debugTable.persist("Error: No certificate found containing thumbprint " + certThumbprint);
            return null;
        }

        debugTable.persist("found cert");
        // Create an X509Certificate2 object using our matching certificate.
        X509Certificate2 certificate = certCollection[0];
        return certificate;
    }

debugtable.persists()方法将调试消息写入表存储。 最后我只在表格中找到这些条目:

"Error: No certificate found containing thumbprint " + certThumbprint

我的代码怎么了?

1 个答案:

答案 0 :(得分:4)

所以你在门户网站上传了你的证书。这意味着证书可用于对Service Management API进行身份验证。

现在,如果您想在Web /辅助角色托管的WCF服务/ Web服务中使用此证书,您还需要在Cloud Service中上载该证书:

enter image description here

然后,您需要打开Web /辅助角色的设置,并通过指定位置,商店名称和指纹来在此处添加新证书:

enter image description here

如果您重新部署该应用程序,则证书将可用,并且您的WCF服务将能够使用它(如果该服务具有足够的权限来访问它)。