You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署Azure后出现WindowsCryptographicException:密钥集不存在问题排查

.NET Core 3.1 Azure Web App 数据保护证书访问异常排查

环境与场景

  • Azure Web App Service,服务计划:S1:2(已扩展至2个实例)
  • .NET Core 3.1 应用,通过.NET数据保护功能从Azure Key Vault按证书指纹获取证书

数据保护配置代码

public static IServiceCollection AddCertDataProtection(this IServiceCollection services, SigningKeyCertificateOptions certOptions, ILogger log)
{
    var primaryCert = Certificates.GetCertificateByThumbprint(certOptions.PrimaryThumbprint, log);
    var secondaryCert = Certificates.GetCertificateByThumbprint(certOptions.SecondaryThumbprint, log);

    if(primaryCert == null && secondaryCert == null)
    {
        throw new Exception($"Could not load primary or secondary certs. Primary: {certOptions.PrimaryThumbprint}," +
            $" Secondary: {certOptions.SecondaryThumbprint}");
    }

    IDataProtectionBuilder dataProtectionBuilder = null;

    if (primaryCert != null) {
        dataProtectionBuilder = services.AddDataProtection()
            .SetApplicationName("AppName")
            .ProtectKeysWithCertificate(primaryCert);
    }

    if (secondaryCert != null)
    {
        dataProtectionBuilder?.UnprotectKeysWithAnyCertificate(secondaryCert);
    }

    dataProtectionBuilder.PersistKeysToDbContext<ApplicationDataProtectionContext>();

    return services;
}

异常现象

证书已成功加载,但调用PersistKeysToDbContext时出现以下异常:

异常详情1

{"Message":"An exception occurred while processing the key element '\"<key id=\\\"XXXX\\\" version=\\\"1\\\" />\"'.","Element":"<key id=\"XXXXXX\" version=\"1\" />","EventId":{"Id":24,"Name":"ExceptionOccurredWhileProcessingTheKeyElement"},"SourceContext":"Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager","Application":"XXX","ApplicationName":"XXX","HostName":"XXX","Release":"XXXX","Level":"Error","Exception":{"Type":"Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException","Message":"Keyset does not exist","StackTrace":"   at Internal.NativeCrypto.CapiHelper.CreateProvHandle(CspParameters parameters, Boolean randomKeyContainer)\r\n   at System.Security.Cryptography.RSACryptoServiceProvider.get_SafeProvHandle()\r\n   at System.Security.Cryptography.RSACryptoServiceProvider.get_SafeKeyHandle()\r\n   at System.Security.Cryptography.RSACryptoServiceProvider..ctor(Int32 keySize, CspParameters parameters, Boolean useDefaultKeySize)\r\n   at System.Security.Cryptography.RSACryptoServiceProvider..ctor(CspParameters parameters)\r\n   at Internal.Cryptography.Pal.CertificatePal.<>c.<GetRSAPrivateKey>b__66_0(CspParameters csp)\r\n   at Internal.Cryptography.Pal.CertificatePal.GetPrivateKey[T](Func`2 createCsp, Func`2 createCng)\r\n   at Internal.Cryptography.Pal.CertificatePal.GetRSAPrivateKey()\r\n   at Internal.Cryptography.Pal.CertificateExtensionsCommon.GetPrivateKey[T](X509Certificate2 certificate, Predicate`1..."}}

异常详情2

{"Message":"An exception occurred while processing the key element '\"<key id=\\\"XXX\\\" version=\\\"1\\\" />\"'.","Element":"<key id=\"XXX\" version=\"1\" />","EventId":{"Id":24,"Name":"ExceptionOccurredWhileProcessingTheKeyElement"},"SourceContext":"Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager","Application":"XXX","ApplicationName":"XXX","HostName":"XXX","Release":"XXX","Level":"Error","Exception":{"Type":"System.Security.Cryptography.CryptographicException","Message":"Unable to retrieve the decryption key.","StackTrace":"   at System.Security.Cryptography.Xml.EncryptedXml.GetDecryptionKey(EncryptedData encryptedData, String symmetricAlgorithmUri)\r\n   at System.Security.Cryptography.Xml.EncryptedXml.DecryptDocument()\r\n   at Microsoft.AspNetCore.DataProtection.XmlEncryption.EncryptedXmlDecryptor.Decrypt(XElement encryptedElement)\r\n   at Microsoft.AspNetCore.DataProtection.XmlEncryption.XmlEncryptionExtensions.DecryptElement(XElement element, IActivator activator)\r\n   at Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager.Microsoft.AspNetCore.DataProtection.KeyManagement.Internal.IInternalXmlKeyManager.DeserializeDescriptorFromKeyElement(XElement keyElement)","InnerExceptions":[]},"timestamp":"2022-11-10T08:59:48.7435261+00:00"}

已验证配置与信息

  • 异常仅偶尔出现,有时仅在单个实例上触发
  • 应用注册已加入Key Vault访问策略,拥有证书获取权限
  • 已设置应用配置WEBSITE_LOAD_USER_PROFILE为*
  • 证书已从Key Vault正确加载到应用的TLS/SSL -> 私钥管理页面
  • 证书有效期至2023年3月
  • 本地可通过移除当前用户对证书私钥的访问权限(mmc.exe -> 证书管理 -> 管理私钥)复现该问题

疑问与需求

  1. 应用服务缺少哪些必要配置?
  2. 为何异常仅偶尔发生?
  3. 请提供具体的排查建议

内容的提问来源于stack exchange,提问作者PedroZol

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 06:20:22