部署Azure后出现WindowsCryptographicException:密钥集不存在问题排查
.NET Core 3.1 Azure Web App 数据保护证书访问异常排查
环境与场景
- Azure Web App Service,服务计划:S1:2(已扩展至2个实例)
- .NET Core 3.1 应用,通过.NET数据保护功能从Azure Key Vault按证书指纹获取证书
数据保护配置代码
public static IServiceCollection AddCertDataProtection(this IServiceCollection services, SigningKeyCertificateOptions certOptions, ILogger log) { var primaryCert = Certificates.GetCertificateByThumbprint(certOptions.PrimaryThumbprint, log); var secondaryCert = Certificates.GetCertificateByThumbprint(certOptions.SecondaryThumbprint, log); if(primaryCert == null && secondaryCert == null) { throw new Exception($"Could not load primary or secondary certs. Primary: {certOptions.PrimaryThumbprint}," + $" Secondary: {certOptions.SecondaryThumbprint}"); } IDataProtectionBuilder dataProtectionBuilder = null; if (primaryCert != null) { dataProtectionBuilder = services.AddDataProtection() .SetApplicationName("AppName") .ProtectKeysWithCertificate(primaryCert); } if (secondaryCert != null) { dataProtectionBuilder?.UnprotectKeysWithAnyCertificate(secondaryCert); } dataProtectionBuilder.PersistKeysToDbContext<ApplicationDataProtectionContext>(); return services; }
异常现象
证书已成功加载,但调用PersistKeysToDbContext时出现以下异常:
异常详情1
{"Message":"An exception occurred while processing the key element '\"<key id=\\\"XXXX\\\" version=\\\"1\\\" />\"'.","Element":"<key id=\"XXXXXX\" version=\"1\" />","EventId":{"Id":24,"Name":"ExceptionOccurredWhileProcessingTheKeyElement"},"SourceContext":"Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager","Application":"XXX","ApplicationName":"XXX","HostName":"XXX","Release":"XXXX","Level":"Error","Exception":{"Type":"Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException","Message":"Keyset does not exist","StackTrace":" at Internal.NativeCrypto.CapiHelper.CreateProvHandle(CspParameters parameters, Boolean randomKeyContainer)\r\n at System.Security.Cryptography.RSACryptoServiceProvider.get_SafeProvHandle()\r\n at System.Security.Cryptography.RSACryptoServiceProvider.get_SafeKeyHandle()\r\n at System.Security.Cryptography.RSACryptoServiceProvider..ctor(Int32 keySize, CspParameters parameters, Boolean useDefaultKeySize)\r\n at System.Security.Cryptography.RSACryptoServiceProvider..ctor(CspParameters parameters)\r\n at Internal.Cryptography.Pal.CertificatePal.<>c.<GetRSAPrivateKey>b__66_0(CspParameters csp)\r\n at Internal.Cryptography.Pal.CertificatePal.GetPrivateKey[T](Func`2 createCsp, Func`2 createCng)\r\n at Internal.Cryptography.Pal.CertificatePal.GetRSAPrivateKey()\r\n at Internal.Cryptography.Pal.CertificateExtensionsCommon.GetPrivateKey[T](X509Certificate2 certificate, Predicate`1..."}}
异常详情2
{"Message":"An exception occurred while processing the key element '\"<key id=\\\"XXX\\\" version=\\\"1\\\" />\"'.","Element":"<key id=\"XXX\" version=\"1\" />","EventId":{"Id":24,"Name":"ExceptionOccurredWhileProcessingTheKeyElement"},"SourceContext":"Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager","Application":"XXX","ApplicationName":"XXX","HostName":"XXX","Release":"XXX","Level":"Error","Exception":{"Type":"System.Security.Cryptography.CryptographicException","Message":"Unable to retrieve the decryption key.","StackTrace":" at System.Security.Cryptography.Xml.EncryptedXml.GetDecryptionKey(EncryptedData encryptedData, String symmetricAlgorithmUri)\r\n at System.Security.Cryptography.Xml.EncryptedXml.DecryptDocument()\r\n at Microsoft.AspNetCore.DataProtection.XmlEncryption.EncryptedXmlDecryptor.Decrypt(XElement encryptedElement)\r\n at Microsoft.AspNetCore.DataProtection.XmlEncryption.XmlEncryptionExtensions.DecryptElement(XElement element, IActivator activator)\r\n at Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager.Microsoft.AspNetCore.DataProtection.KeyManagement.Internal.IInternalXmlKeyManager.DeserializeDescriptorFromKeyElement(XElement keyElement)","InnerExceptions":[]},"timestamp":"2022-11-10T08:59:48.7435261+00:00"}
已验证配置与信息
- 异常仅偶尔出现,有时仅在单个实例上触发
- 应用注册已加入Key Vault访问策略,拥有证书获取权限
- 已设置应用配置
WEBSITE_LOAD_USER_PROFILE为* - 证书已从Key Vault正确加载到应用的TLS/SSL -> 私钥管理页面
- 证书有效期至2023年3月
- 本地可通过移除当前用户对证书私钥的访问权限(mmc.exe -> 证书管理 -> 管理私钥)复现该问题
疑问与需求
- 应用服务缺少哪些必要配置?
- 为何异常仅偶尔发生?
- 请提供具体的排查建议
内容的提问来源于stack exchange,提问作者PedroZol
相关产品推荐
相关产品推荐

