Unable to start Kestrel. Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException: The specified network password is not correct?

Viewed 2493

I created a Blazor application and added the following json config in appsettings.json after I created C:\Users\wsn2\Test\Certificates\9Cert.pfx. (https://docs.microsoft.com/en-us/aspnet/core/fundamentals/servers/kestrel?view=aspnetcore-3.1)

{
  "Kestrel": {
    "Endpoints": {
      "Https": {
        "Url": "https://*:5005",
        "Certificates": {
          "Path": "C:\\Users\\wsn2\\Test\\Certificates\\9Cert.pfx",
          "Password": "4passWord"
        }
      }
    },
    "Certificates": {
      "Default": {
        "Path": "C:\\Users\\wsn2\\Test\\Certificates\\9Cert.pfx",
        "Password": "4passWord"
      }
    }
  }

However, running the published self-contained kestrel application got the following error:

[23:40:25 INF] User profile is available. Using 'C:\Users\wsn2\AppData\Local\ASP.NET\DataProtection-Keys' as key repository and Windows DPAPI to encrypt keys at rest.
[23:40:25 FTL] Unable to start Kestrel.
Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException: The specified network password is not correct.
   at Internal.Cryptography.Pal.CertificatePal.FilterPFXStore(Byte[] rawData, SafePasswordHandle password, PfxCertStoreFlags pfxCertStoreFlags)
   at Internal.Cryptography.Pal.CertificatePal.FromBlobOrFile(Byte[] rawData, String fileName, SafePasswordHandle password, X509KeyStorageFlags keyStorageFlags)
   at System.Security.Cryptography.X509Certificates.X509Certificate..ctor(String fileName, String password, X509KeyStorageFlags keyStorageFlags)
   at System.Security.Cryptography.X509Certificates.X509Certificate2..ctor(String fileName, String password)
   at Microsoft.AspNetCore.Server.Kestrel.KestrelConfigurationLoader.LoadCertificate(CertificateConfig certInfo, String endpointName)
   at Microsoft.AspNetCore.Server.Kestrel.KestrelConfigurationLoader.LoadDefaultCert(ConfigurationReader configReader)
   at Microsoft.AspNetCore.Server.Kestrel.KestrelConfigurationLoader.Load()
   at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.ValidateOptions()
   at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.StartAsync[TContext](IHttpApplication`1 application, CancellationToken cancellationToken)
Unhandled exception. Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException: The specified network password is not correct.
   at Internal.Cryptography.Pal.CertificatePal.FilterPFXStore(Byte[] rawData, SafePasswordHandle password, PfxCertStoreFlags pfxCertStoreFlags)
   at Internal.Cryptography.Pal.CertificatePal.FromBlobOrFile(Byte[] rawData, String fileName, SafePasswordHandle password, X509KeyStorageFlags keyStorageFlags)
   at System.Security.Cryptography.X509Certificates.X509Certificate..ctor(String fileName, String password, X509KeyStorageFlags keyStorageFlags)
   at System.Security.Cryptography.X509Certificates.X509Certificate2..ctor(String fileName, String password)
   at Microsoft.AspNetCore.Server.Kestrel.KestrelConfigurationLoader.LoadCertificate(CertificateConfig certInfo, String endpointName)
   at Microsoft.AspNetCore.Server.Kestrel.KestrelConfigurationLoader.LoadDefaultCert(ConfigurationReader configReader)
   at Microsoft.AspNetCore.Server.Kestrel.KestrelConfigurationLoader.Load()
   at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.ValidateOptions()
   at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.StartAsync[TContext](IHttpApplication`1 application, CancellationToken cancellationToken)
   at Microsoft.AspNetCore.Hosting.GenericWebHostService.StartAsync(CancellationToken cancellationToken)
   at Microsoft.Extensions.Hosting.Internal.Host.StartAsync(CancellationToken cancellationToken)
   at Microsoft.Extensions.Hosting.HostingAbstractionsHostExtensions.RunAsync(IHost host, CancellationToken token)
   at Microsoft.Extensions.Hosting.HostingAbstractionsHostExtensions.RunAsync(IHost host, CancellationToken token)
   at Microsoft.Extensions.Hosting.HostingAbstractionsHostExtensions.Run(IHost host)
2 Answers

Put your 9Cert.pfx file in the folder where you published the code

I ended up with this:

  • get openssl from here "http://slproweb.com/products/Win32OpenSSL.html"

  • generate certificate (public key) and private key like this:

    openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 -keyout web.key -nodes -out web.crt -subj "/C=US/ST=NY/L=Some City/O=MyCompany/OU=MyCompany/CN=mycompany.com" -addext "subjectAltName=DNS:mycompany.com"

  • copy resulting 'web.key' and 'web.crt' into application folder

  • add following section into 'appsettings.json'

     "Kestrel": {
       "Endpoints": {
         "Https": {
           "Url": "https://0.0.0.0:5001"
       }
     },
     "Certificates": {
       "Default": {
         "Path": "web.crt",
         "KeyPath": "web.key"
       }
     }
    

    }

That's all. Try in your browser "https://localhost:5001/" and you will be prompted about non-trusted certificate but you can still proceed.

Related