Skip to content

[Bug]: Portal-scoped SMTP OAuth (Exchange Online) fails with "Padding is invalid" — msauth_authentication_algorithmName not persisted to PortalSettings #7483

Description

@MarkBertelsman

Is there an existing issue for this?

  • I have searched the existing issues

What happened?

Summary:
When SMTP Server Mode is set to Portal (as opposed to Global/Host), completing the Exchange Online OAuth authorization flow saves an encrypted msauth_authentication value to PortalSettings, but does not save its corresponding msauth_authentication_algorithmName setting. When the SMTP Settings admin page later attempts to load and decrypt this value via TokenCacheHelper.GetAuthenticationData(), it fails with a CryptographicException: Padding is invalid and cannot be removed, which surfaces to the browser as a generic InvalidOperationException (WebAPI JSON serialization failure wrapping the crypto exception).

When SMTP Server Mode is set to Global, the equivalent value is saved to HostSettings, where msauth_authentication_algorithmName (value: SHA512) is correctly persisted alongside it — and the page works fine.

Steps to reproduce?

On a DNN 10.3.3 site, go to Site Settings → SMTP Settings.
Set SMTP Server Mode to Portal.
Configure Exchange Online OAuth (Tenant ID, Client ID, Client Secret) and click Authorize.
Complete the Microsoft login/consent flow and get redirected back to the SMTP Settings tab.
Observe the error (see below) — the tab fails to load, both immediately after authorizing and on any subsequent visit.

Current Behavior

Attempting to view the admin page produced the following error in the F12 Console:

{
"Message": "An error has occurred.",
"ExceptionMessage": "The 'ObjectContent`1' type failed to serialize the response body for content type 'application/json; charset=utf-8'.",
"ExceptionType": "System.InvalidOperationException",
"InnerException": {
"ExceptionMessage": "Padding is invalid and cannot be removed.",
"ExceptionType": "System.Security.Cryptography.CryptographicException",
"StackTrace": " at System.Security.Cryptography.CapiSymmetricAlgorithm.DepadBlock...
at DotNetNuke.Security.FIPSCompliant.DecryptAES(...)
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.GetAuthenticationData()
at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.BeforeAccessNotification(...)
..."
}
}

Expected Behavior

No response

Relevant log output

{
  "Message": "An error has occurred.",
  "ExceptionMessage": "The 'ObjectContent`1' type failed to serialize the response body for content type 'application/json; charset=utf-8'.",
  "ExceptionType": "System.InvalidOperationException",
  "InnerException": {
    "ExceptionMessage": "Padding is invalid and cannot be removed.",
    "ExceptionType": "System.Security.Cryptography.CryptographicException",
    "StackTrace": "   at System.Security.Cryptography.CapiSymmetricAlgorithm.DepadBlock...
       at DotNetNuke.Security.FIPSCompliant.DecryptAES(...)
       at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.GetAuthenticationData()
       at Dnn.ExchangeOnlineAuthProvider.Components.TokenCacheHelper.BeforeAccessNotification(...)
       ..."
  }
}

Anything else?

manually adding msauth_authentication_algorithmName (value: SHA512) to the PortalSettings table clears the issue.

Affected Versions

10.3.3 (latest release)

What browsers are you seeing the problem on?

Chrome

Code of Conduct

  • I agree to follow this project's Code of Conduct

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions