LastPass Integration CryptographicException

LastPass Integration CryptographicException

avatar

My company had begun using the LastPass integrated authentication. It was working perfectly up until sometime today. It was working this morning but now whenever we try to use the integrated authentication, we get the following error message. We've verified the credentials used to access the LastPass DB are valid. Any help is much appreciated.

CryptographicException - Padding is invalid and cannot be removed.

at System.Security.Cryptography.RijndaelManagedTransform.DecryptData(Byte[] inputBuffer, Int32 inputOffset, Int32 inputCount, Byte[]& outputBuffer, Int32 outputOffset, PaddingMode paddingMode, Boolean fLast)
at System.Security.Cryptography.RijndaelManagedTransform.TransformFinalBlock(Byte[] inputBuffer, Int32 inputOffset, Int32 inputCount)
at System.Security.Cryptography.CryptoStream.FlushFinalBlock()
at System.Security.Cryptography.CryptoStream.Dispose(Boolean disposing)
at System.IO.Stream.Close()
at System.IO.Stream.Dispose()
at LastPassManagement.ParserHelper.DecryptAes256(Byte[] data, Byte[] encryptionKey, CipherMode mode, Byte[] iv)
at LastPassManagement.ParserHelper.DecryptAes256(Byte[] data, Byte[] encryptionKey)
at LastPassManagement.ParserHelper.<>c__DisplayClass5.<Parse_ACCT>b__1(BinaryReader reader)
at LastPassManagement.ParserHelper.WithBytes[TResult](Byte[] bytes, Func`2 action)
at LastPassManagement.ParserHelper.Parse_ACCT(Chunk chunk, Byte[] encryptionKey, SharedFolder folder)
at LastPassManagement.Vault.<>c__DisplayClass3.<.ctor>b__0(BinaryReader reader)
at LastPassManagement.ParserHelper.<>c__DisplayClass1e.<WithBytes>b__1d(BinaryReader reader)
at LastPassManagement.ParserHelper.WithBytes[TResult](Byte[] bytes, Func`2 action)
at LastPassManagement.ParserHelper.WithBytes(Byte[] bytes, Action`1 action)
at LastPassManagement.Vault..ctor(Blob blob, Byte[] encryptionKey)
at LastPassManagement.Vault.Create(String username, String password, String mobilePortalUUID, String multifactorPassword)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.ProcessWithoutTwoFactor(CredentialsConnection credentialsConnection)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.GetVault(CredentialsConnection credentialsConnection)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.Init(CredentialsConnection credentialsConnection)
at Devolutions.RemoteDesktopManager.Frames.CredentialSettings.FreCredentialResolverLastPassSettings.InitVault()
at Devolutions.RemoteDesktopManager.Frames.CredentialSettings.FreCredentialResolverLastPassSettings.butBrowse_Click(Object sender, EventArgs e)
at System.Windows.Forms.Control.OnClick(EventArgs e)
at System.Windows.Forms.Button.OnClick(EventArgs e)
at System.Windows.Forms.Button.OnMouseUp(MouseEventArgs mevent)
at System.Windows.Forms.Control.WmMouseUp(Message& m, MouseButtons button, Int32 clicks)
at System.Windows.Forms.Control.WndProc(Message& m)
at System.Windows.Forms.ButtonBase.WndProc(Message& m)
at System.Windows.Forms.Button.WndProc(Message& m)
at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)

All Comments (28)

avatar

Hello, We are working on finding the cause, I'll keep you posted

Maurice

avatar

I'm also experiencing this issue.

It *appeared* to occur when we changed an Administrator in LastPass of an unrelated account.

We got an email that said our shared folders have changed.

The problem only occurs for my account, which is 2-factor enabled, but not for my colleagues account, that doesn't have 2-factor, for the same credentials / host.

avatar

We are add diagnostics information to our next beta version so we have a better idea of what is occurring. Will you be able to test it out?

Maurice

avatar

Hello Maurice, I would be happy to help test. I appreciate you looking into the issue!

avatar

I have updated to the beta, encountered the error, and submitted a bug report.

The exception in the log is:


[6/12/2014 2:20:38 PM - 9.4.7.0]ERROR System.Security.Cryptography.CryptographicException: Padding is invalid and cannot be removed.
at System.Security.Cryptography.RijndaelManagedTransform.DecryptData(Byte[] inputBuffer, Int32 inputOffset, Int32 inputCount, Byte[]& outputBuffer, Int32 outputOffset, PaddingMode paddingMode, Boolean fLast)
at System.Security.Cryptography.RijndaelManagedTransform.TransformFinalBlock(Byte[] inputBuffer, Int32 inputOffset, Int32 inputCount)
at System.Security.Cryptography.CryptoStream.FlushFinalBlock()
at System.Security.Cryptography.CryptoStream.Dispose(Boolean disposing)
at System.IO.Stream.Close()
at System.IO.StreamReader.Dispose(Boolean disposing)
at System.IO.TextReader.Dispose()
at LastPassManagement.ParserHelper.DecryptAes256(Byte[] data, Byte[] encryptionKey, CipherMode mode, Byte[] iv)
at LastPassManagement.ParserHelper.DecryptAes256(Byte[] data, Byte[] encryptionKey)
at LastPassManagement.ParserHelper.<>c__DisplayClass19.<Parse_SHAR>b__17(BinaryReader reader)
at LastPassManagement.ParserHelper.WithBytes[TResult](Byte[] bytes, Func`2 action)
at LastPassManagement.Vault.<>c__DisplayClass3.<.ctor>b__0(BinaryReader reader)
at LastPassManagement.ParserHelper.<>c__DisplayClass1e.<WithBytes>b__1d(BinaryReader reader)
at LastPassManagement.ParserHelper.WithBytes[TResult](Byte[] bytes, Func`2 action)
at LastPassManagement.ParserHelper.WithBytes(Byte[] bytes, Action`1 action)
at LastPassManagement.Vault..ctor(Blob blob, Byte[] encryptionKey)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.GetVaultWithTwoFactorDelayedGoogle(String username, String password)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.ProcessWithTwoFactorGoogle(CredentialsConnection credentialsConnection)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.GetVault(CredentialsConnection credentialsConnection)
at Devolutions.RemoteDesktopManager.Managers.LastPassManager.Init(CredentialsConnection credentialsConnection)
at Devolutions.RemoteDesktopManager.Frames.CredentialSettings.FreCredentialResolverLastPassSettings.InitVault()
at Devolutions.RemoteDesktopManager.Frames.CredentialSettings.FreCredentialResolverLastPassSettings.butBrowse_Click(Object sender, EventArgs e)
at System.Windows.Forms.Control.OnClick(EventArgs e)
at System.Windows.Forms.Button.OnClick(EventArgs e)
at System.Windows.Forms.Button.OnMouseUp(MouseEventArgs mevent)
at System.Windows.Forms.Control.WmMouseUp(Message& m, MouseButtons button, Int32 clicks)
at System.Windows.Forms.Control.WndProc(Message& m)
at System.Windows.Forms.ButtonBase.WndProc(Message& m)
at System.Windows.Forms.Button.WndProc(Message& m)
at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)

avatar

Hello,

The beta from last night includes code to add diagnostic information when the debug mode is activated. Please set the debug level to 1 and send me that log by PM or to support@devolutions.net

Do not forget to turn off debugging after

Maurice

avatar

Any progress on this issue?

I've changed my master password as a diagnostics measure and the problem remains.
Also tried killing my authenticator app and restarting it.

avatar

you must send me the debug log that is generated when you set the debugger on. it's in the config folder of RDM.

Maurice

avatar

I already did and we already discussed it a bit via email but then you stopped replying :S

avatar

ah, it's hard to keep track with the usernames vs the emails, sorry about that.

ah mentioned in the emails, the password that is submitted has a length of 0. you have it set to "always prompt for password", which does prompt you. I need to try to reproduce because this case has been tested, I need to find out if we are meeting an edge case

I may have to add debug instructions and ask for a build

Maurice

avatar

Ok am happy to try any ideas or special builds.

I reset my password to something that contains no special characters, but the problem remains.

avatar

Now I can no longer login to RDM online...

"Login failed, the user is locked."

avatar

Please use the "forgot password" link, it unlocks as well.

Maurice

avatar

That did it, thanks.

avatar

FYI this problem is now happening to both my colleagues who do not have 2-factor auth, and have not upgraded with RDM version.

avatar

Hello,

Have you received my email with the info to book a debugging session?

Regards

Maurice

avatar

Yes I replied on Wed:

---

Hi Maurice,

I am AEST (UTC+10). I'm assuming your EST is currently UTC-4.

Going by that, I think it would work best for both of us between 8am and 12pm EST (this is between 10pm and 2am AEST, which is usually fine for me, earlier the better though).

Wed or Thur this week would work, otherwise lets leave it till early next week.

---

Given that it is already Thursday, let's leave it until next week.

avatar

any of your colleagues could do it before?

Maurice

avatar

I'm a founder so I'm happy to work so late. I may not be popular if I get my team to take a midnight Goto meeting call :)

avatar

no no, I will adapt to your schedule

Anything in green is fair game (except if I have a previous commitment), yellow we just need to confirm before



So I guess from your 8am to lunch...



http://www.timeanddate.com/worldclock/meetingtime.html?iso=20140620&p1=165&p2=240
edited by mcote on 6/19/2014
edited by mcote on 6/19/2014

Maurice

time zone coverage.png

avatar

10am Friday AEST works for me (a bit over 9 hours from now).

avatar

meeting invite sent, thanks

Maurice

avatar

Hi Maurice,

Thanks for the call.

I have figured out how to reproduce this issue reliably, it is quite simple.

Create a Shared folder with a name that exceeds 24 characters in length.

That is it!

avatar

Thank you for taking the time to show me the issue.

I have created a new shared folder, and granted a test account readonly access and also blocking "view password", but sadly I cannot reproduce the error that you experience. I get prompted twice under one circumstance, but it still works (I will fix that bug)

If you can create a new folder as you had proposed you would do, please let us know how that turns out. I will take that time to add more instrumentation code for our debug mode.

Thanks again

Maurice

avatar

Yes it appears to have nothing to do with permissions, please see my previous post about length of the shared folder name.

avatar

well, I hadn't seen your response before posting mine, sorry about that

About your discovery... wow! I'll test it out and see if we can work with our third party to circumvent the issue.

You've been a great help. Well, you found it yourself, so you get all the credit.

I will keep you posted on the resolution.

Maurice

avatar

My pleasure.

I am very happy I can again use RDM in all it's glory!

avatar

Hello,

I have committed a fix to our repository, it will be in our next build.

Thank you for all that hard work

Maurice