.NET 7数据保护密钥跨机器使用时解密异常原因排查
.NET Data Protection跨机器使用DPAPI加密密钥文件报错:CryptographicException
两台开发机器运行相同的.NET 7 Web项目,均启用.NET Data Protection且配置一致。将其中一台机器的密钥文件(XML)复制到另一台后,目标机器使用该密钥文件时抛出System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation异常。
日志追踪信息如下:
trce: Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector[5] Performing unprotect operation to key {[REMOVED]} with purposes ('[REMOVED]', '[REMOVED]'). dbug: Microsoft.AspNetCore.DataProtection.TypeForwardingActivator[0] Forwarded activator type request from Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor, Microsoft.AspNetCore.DataProtection, Version=6.0.0.0, Culture=neutral, PublicKeyToken=adb9793829ddae60 to Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor, Microsoft.AspNetCore.DataProtection, Culture=neutral, PublicKeyToken=adb9793829ddae60 dbug: Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor[51] Decrypting secret element using Windows DPAPI. fail: Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor[43] An exception occurred while trying to decrypt the element. System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation. at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapiCore(Byte* pbProtectedData, UInt32 cbProtectedData, Byte* pbOptionalEntropy, UInt32 cbOptionalEntropy) at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapi(Byte[] protectedSecret) at Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor.Decrypt(XElement encryptedElement) fail: Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager[24] An exception occurred while processing the key element '<key id="[REMOVED]" version="1" />'. System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation. at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapiCore(Byte* pbProtectedData, UInt32 cbProtectedData, Byte* pbOptionalEntropy, UInt32 cbOptionalEntropy) at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapi(Byte[] protectedSecret) at Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor.Decrypt(XElement encryptedElement) at Microsoft.AspNetCore.DataProtection.XmlEncryption.XmlEncryptionExtensions.DecryptElement(XElement element, IActivator activator) at Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager.Microsoft.AspNetCore.DataProtection.KeyManagement.Internal.IInternalXmlKeyManager.DeserializeDescriptorFromKeyElement(XElement keyElement) trce: Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager[25] An exception occurred while processing the key element '<key id="[REMOVED]" version="1"> <creationDate>2022-09-15T01:32:44.1371668Z</creationDate> <activationDate>2022-09-15T01:32:44.1270795Z</activationDate> <expirationDate>2022-12-14T01:32:44.1270795Z</expirationDate> <descriptor deserializerType="Microsoft.AspNetCore.DataProtection.AuthenticatedEncryption.ConfigurationModel.AuthenticatedEncryptorDescriptorDeserializer, Microsoft.AspNetCore.DataProtection, Version=6.0.0.0, Culture=neutral, PublicKeyToken=adb9793829ddae60"> <descriptor> <encryption algorithm="AES_256_CBC" /> <validation algorithm="HMACSHA256" /> <encryptedSecret decryptorType="Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor, Microsoft.AspNetCore.DataProtection, Version=6.0.0.0, Culture=neutral, PublicKeyToken=adb9793829ddae60" xmlns="http://schemas.asp.net/2015/03/dataProtection"> <encryptedKey xmlns=""> <!-- This key is encrypted with Windows DPAPI. --> <value>[REMOVED]</value> </encryptedKey> </encryptedSecret> </descriptor> </descriptor> </key>'. System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation. at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapiCore(Byte* pbProtectedData, UInt32 cbProtectedData, Byte* pbOptionalEntropy, UInt32 cbOptionalEntropy) at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapi(Byte[] protectedSecret) at Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor.Decrypt(XElement encryptedElement) at Microsoft.AspNetCore.DataProtection.XmlEncryption.XmlEncryptionExtensions.DecryptElement(XElement element, IActivator activator) at Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager.Microsoft.AspNetCore.DataProtection.KeyManagement.Internal.IInternalXmlKeyManager.DeserializeDescriptorFromKeyElement(XElement keyElement)
经确认两台机器的密钥文件内容完全一致,导致异常的可能原因如下:
- DPAPI加密范围不匹配:默认情况下,.NET Data Protection生成密钥时使用用户范围的DPAPI加密,只有生成密钥的Windows用户账号才能解密。如果两台机器运行项目的用户账号不同(比如一台用LocalSystem,另一台用域账号,或者同域不同用户名),就会触发解密失败。
- 未配置机器范围的DPAPI加密:若要实现跨机器共享密钥,需要显式配置Data Protection使用机器范围的DPAPI加密。默认生成的用户级密钥无法跨机器用户解密。
- 域信任边界问题:如果是域环境,用户级DPAPI加密依赖域的信任关系。若两台机器不在同一个域,或者域信任失效,即使用户名相同,也无法解密对方用户加密的数据。
- 密钥文件权限不足:目标机器上的密钥文件没有被运行项目的用户授予读取权限,导致DPAPI解密时无法正确访问密钥数据,触发加密操作异常。
- 系统加密组件差异:两台机器的Windows版本、加密组件更新不一致(比如一台是Windows Server 2022,另一台是Windows 10),或者加密算法支持存在差异,也会导致解密失败。
内容的提问来源于stack exchange,提问作者MaxP
相关产品推荐
相关产品推荐

