@brentschmaltz
I'm being faced with similar issue that's been reported in here. I have tried all the suggestions but I'm getting no where.
Am I missing something?
I have added a snapshot of my code
IDX10511: Signature validation failed. Keys tried: 'Microsoft.IdentityModel.Tokens.X509SecurityKey
I'm using MSAL interceptor in Angular 8 code to send access token to the server "C# .NET core 3.1".
//*********************************
public static JwtSecurityToken Validate(string token)
{
string stsDiscoveryEndpoint = "https://login.microsoftonline.com/eddf9e42-9a7f-4639-8042-***********/.well-known/openid-configuration?appid=7391aebb-1a35-4ad7-8166-xxxxxxxxxx"; // https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration";
ConfigurationManager<OpenIdConnectConfiguration> configManager = new ConfigurationManager<OpenIdConnectConfiguration>(stsDiscoveryEndpoint, new OpenIdConnectConfigurationRetriever());
OpenIdConnectConfiguration config = configManager.GetConfigurationAsync().Result;
TokenValidationParameters validationParameters = new TokenValidationParameters
{
ValidateAudience = false,
ValidIssuer = config.Issuer,
IssuerSigningKeys = config.SigningKeys,
ValidateIssuerSigningKey = false,
ValidateIssuer = true,
ValidateActor = false,
ValidateLifetime = true
};
IdentityModelEventSource.ShowPII = true;
JwtSecurityTokenHandler tokendHandler = new JwtSecurityTokenHandler();
SecurityToken jwt;
var result = tokendHandler.ValidateToken(token, validationParameters, out jwt);
return jwt as JwtSecurityToken;
}
/*
IDX10511: Signature validation failed. Keys tried: 'Microsoft.IdentityModel.Tokens.X509SecurityKey, KeyId: 'HlC0R12skxNZ1WQwmjOF_6t_tDE', InternalId: '91ea3222-c9ea-4aa4-a515-83f2b195f989'. , KeyId: HlC0R12skxNZ1WQwmjOF_6t_tDE
'.
kid: 'HlC0R12skxNZ1WQwmjOF_6t_tDE'.
Exceptions caught:
''.
token: '{"alg":"RS256","typ":"JWT","nonce":"19yszC4xPiqhnbI587HT_08QFjftE7J3qE8F9xw_sqY","x5t":"HlC0R12skxNZ1WQwmjOF_6t_tDE","kid":"HlC0R12skxNZ1WQwmjOF_6t_tDE"}.{"aud":"00000003-0000-0000-c000-000000000000","iss":"https://sts.windows.net/eddf9e42-9a7f-4639-8042-110281cf41a2/","iat":1581413726,"nbf":1581413726,"exp":1581417626,"acct":0,"acr":"1","aio":"42NgYLgWut8sY6dad5urN6/nxuP8P7Z6ZXr1Wwl355xibZu8nxMA","amr":["pwd"],"app_displayname":"SoraxWeb","appid":"7391aebb-1a35-4ad7-8166-xxxxxxxx","appidacr":"0","family_name":"kwofie","given_name":"Ernest","ipaddr":"212.161.81.38","name":"Exxxx kxxxx","oid":"9f9efce3-37e5-4018-8035-7ffc6323e827","onprem_sid":"S-1-5-21-3789744388-407605227-1228871550-7770","platf":"3","puid":"100320003319DDA9","scp":"Mail.Send openid profile User.Read User.ReadWrite email","sub":"LhkC5zL_zJm-MZBjJDYCz5Asjm7Nwg9tHUehKVSH40A","tid":"eddf9e42-9a7f-4639-8042-***","unique_name":"Exxxx.[email protected]","upn":"Exxxx.[email protected]","uti":"3RsEnJpEokmZb-Y3MwJzAA","ver":"1.0","xms_st":{"sub":"zSJz0JM6iB6SRwxi1ZZm_1F__aYqHhEDtjb5qkege_o"},"xms_tcdt":1443089411}'.
*/
Startup.cs
public void ConfigureServices(IServiceCollection services)
{
services.AddCors(options => options.AddPolicy(MyAllowSpecificOrigins, builder =>
{
builder.AllowAnyOrigin().AllowAnyMethod().AllowAnyHeader();
}));
services.AddControllers();
}
public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
if (env.IsDevelopment())
{
app.UseDeveloperExceptionPage();
}
app.UseRouting();
app.UseCors(MyAllowSpecificOrigins);
app.UseHttpsRedirection();
app.UseAuthorization();
app.UseEndpoints(endpoints =>
{
endpoints.MapControllers();
});
}
@EkwofiePrax - Why are you trying to validate an access token for Graph?
This token requires special processing in order to validate.
Please refer to: https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/issues/609#issuecomment-524434987
More on 'special processing': https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/issues/609#issuecomment-405683736
Hi @GeoK thanks for your direction, much appreciate, I guess the cue was in the "aud":"00000003-0000-0000-c000-000000000000"
https://www.shawntabrizi.com/aad/common-microsoft-resources-azure-active-directory/

Looking at protectedResourceMap below:
I was using graph.microsoft.com scope for my API as follows
: ["user.read", "mail.send"]].

This was causing the validation to fail with error: Microsoft.IdentityModel.Tokens.SecurityTokenInvalidSignatureException: 'IDX10511: Signature validation failed. Keys tried: 'Microsoft.IdentityModel.Tokens.X509SecurityKey, KeyId: 'HlC0R12skxNZ1WQwmjOF_6t_tDE', InternalId:

I had to go Azure and preform the following task: scope name : Read.All

in my Angular app, I had to update my protectedResourseMap to this:

@GeoK I hope I havent missed anything here :)
You shouldn't validate an access token for Graph. Still not sure why would you do that.
Please review the comments linked in my previous comment.
In a nutshell, the signature is over the transformed nonce, so if you try and validate it directly, the signature will fail.
Most helpful comment
Hi @GeoK thanks for your direction, much appreciate, I guess the cue was in the "aud":"00000003-0000-0000-c000-000000000000"

https://www.shawntabrizi.com/aad/common-microsoft-resources-azure-active-directory/
Looking at protectedResourceMap below:

I was using graph.microsoft.com scope for my API as follows
: ["user.read", "mail.send"]].
This was causing the validation to fail with error: Microsoft.IdentityModel.Tokens.SecurityTokenInvalidSignatureException: 'IDX10511: Signature validation failed. Keys tried: 'Microsoft.IdentityModel.Tokens.X509SecurityKey, KeyId: 'HlC0R12skxNZ1WQwmjOF_6t_tDE', InternalId:
I had to go Azure and preform the following task: scope name : Read.All
in my Angular app, I had to update my protectedResourseMap to this:

@GeoK I hope I havent missed anything here :)