Fix .NET and mage compatibility in KMS CNG Provider#71
Open
hlshen wants to merge 3 commits into
Open
Conversation
tdbhacks
pushed a commit
that referenced
this pull request
Jun 17, 2026
This unblocks .NET and mage compatibility in CNG provider. Original PR: #71 Bug: b/507187574 Bug: b/522970646 Change-Id: Ia29a30525d14860a38ed0a43b688bfc354f182b7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change resolves compatibility issues between the Google Cloud KMS CNG provider and tools running on the .NET runtime (such as dotnet/sign / Sign CLI) as well as the Windows SDK tool mage.exe.
Background & Context
During the migration of our VSIX (VS Code extension) signing pipeline to the 64-bit dotnet/sign tool, we encountered blocking failures. The .NET implementation of dotnet/sign failed to interface with the KMS CNG provider (kmscng.dll).
Deep dive investigation revealed two distinct root causes in the CNG provider that blocked .NET tools:
Missing Key Length Properties: The provider did not expose the key length, which .NET strictly requires.
Strict Flag Validation: The provider rejected the NCRYPT_PERSIST_ONLY_FLAG flag, which .NET and mage commonly pass.
This PR addresses both issues with minimal, low-risk changes.
fixes #69