-
Notifications
You must be signed in to change notification settings - Fork 277
Add MSI mTLS PoP support: pure MI + FIC-with-MI (impl for devex #3832) #3839
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Gladwin Johnson VR (gladjohn)
merged 4 commits into
master
from
gladjohn/msi-fic-mtls-pop-fresh
Jun 10, 2026
Merged
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
966a168
Add MSI mTLS PoP support: pure MI + FIC-with-MI
8a4db7f
Address review feedback: rename effectiveToken; bump KeyAttestation t…
gladjohn bf59ec5
address pr comments
gladjohn d61c723
Merge branch 'master' into gladjohn/msi-fic-mtls-pop-fresh
gladjohn File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
4 changes: 4 additions & 0 deletions
4
src/Microsoft.Identity.Web.Certificateless/PublicAPI/PublicAPI.Unshipped.txt
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1,5 @@ | ||
| #nullable enable | ||
| override Microsoft.Identity.Web.ManagedIdentityClientAssertion.GetSignedAssertionWithBindingAsync(Microsoft.Identity.Client.AssertionRequestOptions? assertionRequestOptions, System.Threading.CancellationToken cancellationToken = default(System.Threading.CancellationToken)) -> System.Threading.Tasks.Task<Microsoft.Identity.Client.ClientSignedAssertion?>! | ||
| override Microsoft.Identity.Web.ManagedIdentityClientAssertion.SupportsTokenBinding.get -> bool | ||
| virtual Microsoft.Identity.Web.ClientAssertionProviderBase.GetSignedAssertionWithBindingAsync(Microsoft.Identity.Client.AssertionRequestOptions? assertionRequestOptions, System.Threading.CancellationToken cancellationToken = default(System.Threading.CancellationToken)) -> System.Threading.Tasks.Task<Microsoft.Identity.Client.ClientSignedAssertion?>! | ||
| virtual Microsoft.Identity.Web.ClientAssertionProviderBase.SupportsTokenBinding.get -> bool |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,40 @@ | ||
| // Copyright (c) Microsoft Corporation. All rights reserved. | ||
| // Licensed under the MIT License. | ||
|
|
||
| using Microsoft.Extensions.DependencyInjection; | ||
| using Microsoft.Extensions.Logging; | ||
| using Microsoft.Identity.Abstractions; | ||
| using Microsoft.Identity.Web; | ||
| using System.Net; | ||
|
|
||
| // Federated Identity Credentials (FIC) backed by Managed Identity, exchanged for an | ||
| // app token via mTLS Proof-of-Possession. | ||
| // | ||
| // Two-leg flow: | ||
| // Leg 1 — Managed Identity mints a binding cert + signed assertion (audience: AzureADTokenExchange). | ||
| // Leg 2 — Entra ID exchanges that assertion for a resource access token, pinning it to the same cert. | ||
| // | ||
| // Trigger: AuthorizationHeaderProviderOptions.ProtocolScheme = "MTLS_POP" (in appsettings.json | ||
| // under AcquireTokenOptions, with RequestAppToken = true) plus ClientCredentials of type | ||
| // SignedAssertionFromManagedIdentity. | ||
|
|
||
| var factory = TokenAcquirerFactory.GetDefaultInstance(); | ||
|
|
||
| factory.Services.AddLogging(b => b.AddConsole().SetMinimumLevel(LogLevel.Warning)); | ||
|
|
||
| factory.Services.AddDownstreamApi( | ||
| "AzureKeyVault", | ||
| factory.Configuration.GetSection("AzureKeyVault")); | ||
|
|
||
| IServiceProvider sp = factory.Build(); | ||
| IDownstreamApi api = sp.GetRequiredService<IDownstreamApi>(); | ||
|
|
||
| HttpResponseMessage response = await api.CallApiForAppAsync("AzureKeyVault"); | ||
|
|
||
| if (response.StatusCode != HttpStatusCode.OK) | ||
| { | ||
| Console.WriteLine($"Vault returned {(int)response.StatusCode} {response.ReasonPhrase}"); | ||
| return; | ||
| } | ||
|
|
||
| Console.WriteLine("Secret retrieved successfully via FIC + mTLS PoP."); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,35 @@ | ||
| # daemon-app-fic-mtls | ||
|
|
||
| Daemon (console) sample that calls Azure Key Vault using **Federated Identity Credentials (FIC) | ||
| backed by Managed Identity**, with the resulting app token bound to the MI's binding certificate | ||
| via **mTLS Proof-of-Possession** (PoP). | ||
|
|
||
| ## What this demonstrates | ||
|
|
||
| Two-leg flow: | ||
|
|
||
| 1. **Leg 1 — Managed Identity** (`SignedAssertionFromManagedIdentity`) | ||
| - V2 managed identity credential endpoint returns a binding certificate + a signed assertion | ||
| whose audience is `api://AzureADTokenExchange`. | ||
| 2. **Leg 2 — Confidential Client → Entra ID** | ||
| - Microsoft.Identity.Web sends that assertion to the application's tenant and asks for the | ||
| downstream resource (Key Vault) access token. | ||
| - `ProtocolScheme = "MTLS_POP"` pins the outer token to the same binding certificate, so the | ||
| downstream HTTPS call to Key Vault uses mTLS. | ||
|
|
||
| No app secret, no rotatable certificate. | ||
|
|
||
| ## Prerequisites | ||
|
|
||
| - App registration (`AzureAd:ClientId`) with a **Federated Identity Credential** that trusts the | ||
| managed identity in `AzureAd:ClientCredentials[0].ManagedIdentityClientId`. | ||
| - The app registration must be granted **Key Vault Secrets User** (or higher) on the target vault. | ||
| - Host must expose the V2 managed identity credential endpoint (Azure VM, Arc-enabled server, etc.). | ||
|
|
||
| ## Run | ||
|
|
||
| ```bash | ||
| dotnet run | ||
| ``` | ||
|
|
||
| Expected output: `Secret retrieved successfully via FIC + mTLS PoP.` |
29 changes: 29 additions & 0 deletions
29
tests/DevApps/daemon-app/daemon-app-fic-mtls/appsettings.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| { | ||
| "AzureAd": { | ||
| "Instance": "https://login.microsoftonline.com/", | ||
| "TenantId": "10c419d4-4a50-45b2-aa4e-919fb84df24f", | ||
| "ClientId": "a599ce88-0a5f-4a6e-beca-e67d3fc427f4", | ||
| "ClientCapabilities": [ "cp1" ], | ||
| "ClientCredentials": [ | ||
| { | ||
| "SourceType": "SignedAssertionFromManagedIdentity", | ||
| "ManagedIdentityClientId": "4b7a4b0b-ecb2-409e-879a-1e21a15ddaf6" | ||
| } | ||
| ] | ||
| }, | ||
|
|
||
| "AzureKeyVault": { | ||
| "BaseUrl": "https://msidlabs.vault.azure.net/", | ||
| "RelativePath": "secrets/id4slab1?api-version=7.4", | ||
| "RequestAppToken": true, | ||
| "ProtocolScheme": "MTLS_POP", | ||
| "Scopes": [ "https://vault.azure.net/.default" ] | ||
| }, | ||
|
|
||
| "Logging": { | ||
| "LogLevel": { | ||
| "Default": "Warning", | ||
| "Microsoft": "Information" | ||
| } | ||
| } | ||
| } |
24 changes: 24 additions & 0 deletions
24
tests/DevApps/daemon-app/daemon-app-fic-mtls/daemon-app-fic-mtls.csproj
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,24 @@ | ||
| <Project Sdk="Microsoft.NET.Sdk"> | ||
|
|
||
| <PropertyGroup> | ||
| <OutputType>Exe</OutputType> | ||
| <TargetFrameworks>net8.0</TargetFrameworks> | ||
| <RootNamespace>Daemon_app_fic_mtls</RootNamespace> | ||
| <ImplicitUsings>enable</ImplicitUsings> | ||
| <Nullable>enable</Nullable> | ||
| <LangVersion>13</LangVersion> | ||
| <IsPackable>false</IsPackable> | ||
| </PropertyGroup> | ||
|
|
||
| <ItemGroup> | ||
| <ProjectReference Include="..\..\..\..\src\Microsoft.Identity.Web.DownstreamApi\Microsoft.Identity.Web.DownstreamApi.csproj" /> | ||
| <ProjectReference Include="..\..\..\..\src\Microsoft.Identity.Web.TokenAcquisition\Microsoft.Identity.Web.TokenAcquisition.csproj" /> | ||
| </ItemGroup> | ||
|
|
||
| <ItemGroup> | ||
| <None Update="appsettings.json"> | ||
| <CopyToOutputDirectory>PreserveNewest</CopyToOutputDirectory> | ||
| </None> | ||
| </ItemGroup> | ||
|
|
||
| </Project> |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| // Copyright (c) Microsoft Corporation. All rights reserved. | ||
| // Licensed under the MIT License. | ||
|
|
||
| using Microsoft.Extensions.DependencyInjection; | ||
| using Microsoft.Extensions.Logging; | ||
| using Microsoft.Identity.Abstractions; | ||
| using Microsoft.Identity.Web; | ||
| using System.Net; | ||
|
|
||
| // Pure Managed Identity with mTLS Proof-of-Possession. | ||
| // Requires an Azure VM / Arc-enabled server that exposes the V2 managed identity | ||
| // credential endpoint (returns a binding certificate alongside the access token). | ||
| // | ||
| // Trigger: AuthorizationHeaderProviderOptions.ProtocolScheme = "MTLS_POP" in appsettings.json | ||
| // (under AcquireTokenOptions, with RequestAppToken = true). | ||
|
|
||
| var factory = TokenAcquirerFactory.GetDefaultInstance(); | ||
|
|
||
| factory.Services.AddLogging(b => b.AddConsole().SetMinimumLevel(LogLevel.Warning)); | ||
|
|
||
| factory.Services.AddDownstreamApi( | ||
| "AzureKeyVault", | ||
| factory.Configuration.GetSection("AzureKeyVault")); | ||
|
|
||
| IServiceProvider sp = factory.Build(); | ||
| IDownstreamApi api = sp.GetRequiredService<IDownstreamApi>(); | ||
|
|
||
| HttpResponseMessage response = await api.CallApiForAppAsync("AzureKeyVault"); | ||
|
|
||
| if (response.StatusCode != HttpStatusCode.OK) | ||
| { | ||
| Console.WriteLine($"Vault returned {(int)response.StatusCode} {response.ReasonPhrase}"); | ||
| return; | ||
| } | ||
|
|
||
| Console.WriteLine("Secret retrieved successfully via MSI mTLS PoP."); |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.