dotnet / dotnet/AspNetCore.Docs

Certificate with Capi limitation?

Open
#24,343 0 comments 0 reactions 0 assignees View on GitHub
doc-enhancement Security-PU Source - Docs.ms
Dominant language
C#
Stars
13.1k
Forks
24.6k
Avg merge
1d 3h
Merged PRs (30d)
97

Description

Doc states:

> Due to .NET Framework limitations, only certificates with CAPI private keys are supported. See the content below for possible workarounds to these limitations.

What are the workarounds below - I can't see any, I only see alternative encryption methods using dpapi?

Also it would be very useful if a link or some guidance coukd be provided on how to create such a certificate with a CAPI key. Tools like openssl are commonly used, but I've not heard the term CAPI before so does this mean if using openssl for example you have to use different / specialised commands to produce a compatible cert?

---
#### Document Details

⚠ *Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.*

* ID: 0c24ccb9-b297-f942-ebf1-c994d672f183
* Version Independent ID: 5d6eb72e-b1b5-1507-6162-16a9a4a01aa0
* Content: [Key encryption at rest in Windows and Azure using ASP.NET Core](https://docs.microsoft.com/en-us/aspnet/core/security/data-protection/implementation/key-encryption-at-rest?view=aspnetcore-6.0)
* Content Source: [aspnetcore/security/data-protection/implementation/key-encryption-at-rest.md](https://github.com/dotnet/AspNetCore.Docs/blob/main/aspnetcore/security/data-protection/implementation/key-encryption-at-rest.md)
* Product: **aspnet-core**
* Technology: **aspnetcore-security**
* GitHub Login: @Rick-Anderson
* Microsoft Alias: **riande**

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.