Troubleshooting: Encryption.DecryptRSAUTF8 Exception (Object Reference Not Set to an Instance of an Object)

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    The Error log shows Encryption.DecryptRSAUTF8 exception: Object reference not set to an instance of an object. This can come with a loss of functionality, or the realm can continue to work normally despite the error. A more common variant of this error, Keyset does not exist, is covered separately -- see Troubleshooting: "Keyset Does Not Exist" and Related Invalid User Errors.

     

    Cause

    The realm's License Cert (shown in the License Info section of the System Info tab) encrypts and decrypts sensitive values stored in web.config. This error occurs when:

    1. Values were encrypted into web.config using License Cert X.
    2. The License Cert was changed to License Cert Y.
    3. Most values have since been recreated and re-encrypted using License Cert Y.
    4. One or more values were never cleared or re-entered since the cert changed, so they're still encrypted with the old cert.

    That remaining, still-encrypted-with-the-old-cert value is what triggers the exception.

     

    Resolution:

    Once you've settled on the final cert, update every secure value web.config can store:

    1. The FbaUser password, on the Workflow tab.
    2. The API Key/Secret, on the API tab.
    3. Oracle and SQL connection strings, on the Data tab.
    4. The Web Service password, on the Data tab.
    5. Any other passwords (AD, AD-LDS, etc.), on the Data tab.


     

    Special Considerations

    A value that isn't currently visible on the Data tab may still have been set previously. For example, if the realm originally used an AD connection but has since switched to Web Service, the old AD password is still saved in web.config and needs to be updated or blanked out too.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.