Exception: "Windows Data Protection API (DPAPI) is not supported on this platform." using Microsoft.Trusted.Signing.Client 1.0.76

Watts, Chris 50 Reputation points
2025-02-28T17:24:48.5066667+00:00

We've successfully been using SignTool.exe with Microsoft.Trusted.Signing.Client 1.0.60 for some time.

In upgrading to Microsoft.Trusted.Signing.Client 1.0.76 we now get the following exception being raised: Windows Data Protection API (DPAPI) is not supported on this platform.

This is happening when running the 64 bit version of SignTool.exe on both Windows 10 and Windows 11.

We have found that this is due to the exact copy of System.Security.Cryptography.ProtectedData.dll that is present in the bin\x64 folder of Microsoft.Trusted.Signing.Client

1.0.76 appears to be shipping with the version of the dll from the NuGet package: system.security.cryptography.protecteddata.4.7.0\lib\netstandard2.0

Everything starts working again if we replace with the version from:
system.security.cryptography.protecteddata.4.7.0\runtimes\win\lib\netstandard2.0

While this does allow things to work, patching the contents of a NuGet package obtained as part of a build is error prone and likely to result in errors further down the line.

Is this an error that needs correcting in Microsoft.Trusted.Signing.Client?

If this is a deliberate change, how should we be changing our Azure settings and .json configuration file to enable SignTool to authenticate correctly?

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


Answer accepted by question author
Meha-MSFT 2,460 Reputation points Microsoft Employee Moderator
2025-06-13T20:25:55.9166667+00:00

If you are still experiencing issues, please use this version: https://www.nuget.org/packages/Microsoft.Trusted.Signing.Client.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.