Is there an existing issue for this?
What happened?
Summary:
When SMTP Server Mode is set to Portal (as opposed to Global/Host), completing the Exchange Online OAuth authorization flow saves an encrypted msauth_authentication value to PortalSettings, but does not save its corresponding msauth_authentication_algorithmName setting. When the SMTP Settings admin page later attempts to load and decrypt this value via TokenCacheHelper.GetAuthenticationData(), it fails with a CryptographicException: Padding is invalid and cannot be removed, which surfaces to the browser as a generic InvalidOperationException (WebAPI JSON serialization failure wrapping the crypto exception).
When SMTP Server Mode is set to Global, the equivalent value is saved to HostSettings, where msauth_authentication_algorithmName (value: SHA512) is correctly persisted alongside it — and the page works fine.
Steps to reproduce?
On a DNN 10.3.3 site, go to Site Settings → SMTP Settings.
Set SMTP Server Mode to Portal.
Configure Exchange Online OAuth (Tenant ID, Client ID, Client Secret) and click Authorize.
Complete the Microsoft login/consent flow and get redirected back to the SMTP Settings tab.
Observe the error (see below) — the tab fails to load, both immediately after authorizing and on any subsequent visit.
Current Behavior
Attempting to view the admin page produced the following error in the F12 Console:
{
"Message": "An error has occurred.",
"ExceptionMessage": "The 'ObjectContent`1' type failed to serialize the response body for content type 'application/json; charset=utf-8'.",
"ExceptionType": "System.InvalidOperationException",
"InnerException": {
"ExceptionMessage": "Padding is invalid and cannot be removed.",
"ExceptionType": "System.Security.Cryptography.CryptographicException",
"StackTrace": " at System.Security.Cryptography.CapiSymmetricAlgorithm.DepadBlock...
at DotNetNuke.Security.FIPSCompliant.DecryptAES(...)
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.GetAuthenticationData()
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.BeforeAccessNotification(...)
..."
}
}
Expected Behavior
No response
Relevant log output
{
"Message": "An error has occurred.",
"ExceptionMessage": "The 'ObjectContent`1' type failed to serialize the response body for content type 'application/json; charset=utf-8'.",
"ExceptionType": "System.InvalidOperationException",
"InnerException": {
"ExceptionMessage": "Padding is invalid and cannot be removed.",
"ExceptionType": "System.Security.Cryptography.CryptographicException",
"StackTrace": " at System.Security.Cryptography.CapiSymmetricAlgorithm.DepadBlock...
at DotNetNuke.Security.FIPSCompliant.DecryptAES(...)
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.GetAuthenticationData()
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.BeforeAccessNotification(...)
..."
}
}
Anything else?
manually adding msauth_authentication_algorithmName (value: SHA512) to the PortalSettings table clears the issue.
Affected Versions
10.3.3 (latest release)
What browsers are you seeing the problem on?
Chrome
Code of Conduct
Is there an existing issue for this?
What happened?
Summary:
When SMTP Server Mode is set to Portal (as opposed to Global/Host), completing the Exchange Online OAuth authorization flow saves an encrypted msauth_authentication value to PortalSettings, but does not save its corresponding msauth_authentication_algorithmName setting. When the SMTP Settings admin page later attempts to load and decrypt this value via TokenCacheHelper.GetAuthenticationData(), it fails with a CryptographicException: Padding is invalid and cannot be removed, which surfaces to the browser as a generic InvalidOperationException (WebAPI JSON serialization failure wrapping the crypto exception).
When SMTP Server Mode is set to Global, the equivalent value is saved to HostSettings, where msauth_authentication_algorithmName (value: SHA512) is correctly persisted alongside it — and the page works fine.
Steps to reproduce?
On a DNN 10.3.3 site, go to Site Settings → SMTP Settings.
Set SMTP Server Mode to Portal.
Configure Exchange Online OAuth (Tenant ID, Client ID, Client Secret) and click Authorize.
Complete the Microsoft login/consent flow and get redirected back to the SMTP Settings tab.
Observe the error (see below) — the tab fails to load, both immediately after authorizing and on any subsequent visit.
Current Behavior
Attempting to view the admin page produced the following error in the F12 Console:
{
"Message": "An error has occurred.",
"ExceptionMessage": "The 'ObjectContent`1' type failed to serialize the response body for content type 'application/json; charset=utf-8'.",
"ExceptionType": "System.InvalidOperationException",
"InnerException": {
"ExceptionMessage": "Padding is invalid and cannot be removed.",
"ExceptionType": "System.Security.Cryptography.CryptographicException",
"StackTrace": " at System.Security.Cryptography.CapiSymmetricAlgorithm.DepadBlock...
at DotNetNuke.Security.FIPSCompliant.DecryptAES(...)
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.GetAuthenticationData()
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.BeforeAccessNotification(...)
..."
}
}
Expected Behavior
No response
Relevant log output
{ "Message": "An error has occurred.", "ExceptionMessage": "The 'ObjectContent`1' type failed to serialize the response body for content type 'application/json; charset=utf-8'.", "ExceptionType": "System.InvalidOperationException", "InnerException": { "ExceptionMessage": "Padding is invalid and cannot be removed.", "ExceptionType": "System.Security.Cryptography.CryptographicException", "StackTrace": " at System.Security.Cryptography.CapiSymmetricAlgorithm.DepadBlock... at DotNetNuke.Security.FIPSCompliant.DecryptAES(...) at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.GetAuthenticationData() at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.BeforeAccessNotification(...) ..." } }Anything else?
manually adding msauth_authentication_algorithmName (value: SHA512) to the PortalSettings table clears the issue.
Affected Versions
10.3.3 (latest release)
What browsers are you seeing the problem on?
Chrome
Code of Conduct