PyJWT用RS256算法调用encode时报'Could not deserialize key data'错误
PyJWT使用RS256算法生成Token报错问题
此前使用PyJWT官方文档推荐的代码运行正常,但数月后无法工作。环境为Xubuntu系统,项目已Docker化。
问题代码
import jwt SEC = "SECRET" token = jwt.encode( {'name': ' ', 'admin': True}, SEC, algorithm='RS256' ) print(token)
报错信息
Traceback (most recent call last): File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/algorithms.py", line 350, in prepare_key RSAPrivateKey, load_pem_private_key(key_bytes, password=None) File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/primitives/serialization/base.py", line 25, in load_pem_private_key return ossl.load_pem_private_key( File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 747, in load_pem_private_key return self._load_key( File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 929, in _load_key self._handle_key_loading_error() File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 984, in _handle_key_loading_error raise ValueError( ValueError: ('Could not deserialize key data. The data may be in an incorrect format, it may be encrypted with an unsupported algorithm, or it may be an unsupported key type (e.g. EC curves with explicit parameters).', [<OpenSSLError(code=503841036, lib=60, reason=524556, reason_text=unsupported)>]) During handling of the above exception, another exception occurred: Traceback (most recent call last): File "/home/cc/Documents/test/j.py", line 6, in <module> token = jwt.encode( File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/api_jwt.py", line 73, in encode return api_jws.encode( File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/api_jws.py", line 160, in encode key = alg_obj.prepare_key(key) File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/algorithms.py", line 353, in prepare_key return cast(RSAPublicKey, load_pem_public_key(key_bytes)) File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/primitives/serialization/base.py", line 35, in load_pem_public_key return ossl.load_pem_public_key(data) File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 794, in load_pem_public_key self._handle_key_loading_error() File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 984, in _handle_key_loading_error raise ValueError( ValueError: ('Could not deserialize key data. The data may be in an incorrect format, it may be encrypted with an unsupported algorithm, or it may be an unsupported key type (e.g. EC curves with explicit parameters).', [<OpenSSLError(code=75497580, lib=9, reason=108, reason_text=no start line)>])
使用的库版本
cffi==1.15.1 cryptography==39.0.0 pycparser==2.21 PyJWT==2.6.0
解决方法
核心原因
RS256属于非对称加密算法,要求必须使用RSA私钥作为签名密钥,普通字符串"SECRET"不符合RSA密钥的PEM格式,导致cryptography库无法解析。旧版PyJWT可能对密钥格式校验不严格,新版本修复了这个问题,因此之前能运行现在报错。
方案1:切换为对称加密算法(HS256)
如果不需要非对称加密的特性,直接改用HS256算法,该算法支持普通字符串作为密钥:
import jwt SEC = "SECRET" token = jwt.encode( {'name': ' ', 'admin': True}, SEC, algorithm='HS256' ) print(token)
方案2:使用合法的RSA密钥对
如果必须使用RS256,需要先生成RSA私钥并在代码中使用:
- 生成RSA私钥(终端执行命令):
openssl genrsa -out private.pem 2048
- 修改代码读取私钥文件:
import jwt with open("private.pem", "r") as f: private_key = f.read() token = jwt.encode( {'name': ' ', 'admin': True}, private_key, algorithm='RS256' ) print(token)
内容的提问来源于stack exchange,提问作者CC7052
相关产品推荐
相关产品推荐

