Repository navigation
bad signature when sharing a file via public link while using encryption #6543
Description
Activity
I cannot reproduce this locally here on a stable12 installation. Do you have some more detailed reproduction steps? Does it happen on any file?
Yes, it happens on all files, even on those which have been already shared months ago. If I'm logged in, the download works without any problems.
Yes, it happens on all files, even on those which have been already shared months ago. If I'm logged in, the download works without any problems.
So just to recap:
- You upload a zip file via web interface
- You publicly share the file via web interface
- From a not-logged-in browser you access the publicly shared file and try to download it
- This fails with said error message
Did this happen also before 12.0.3 RC1? Can you provide me with a test account on said instance? ([email protected])
I'm currently restoring a backup from the stable version. I'll give you an account as soon as the restore is done. Thanks for your help.
Beautified error message:
Exception: {"Exception":"OCP\Encryption\Exceptions\GenericEncryptionException","Message":"Bad Signature","Code":0,"Trace":"#0 \/data\/www\/rcvd.io\/nextcloud\/apps\/encryption\/lib\/Crypto\/Crypt.php(463): OCA\Encryption\Crypto\Crypt->checkSignature('GnrifLmsUaVL3bK...', '\x9D$\xAE\x9B\xF7\xE3\/l\xAEm\xDB\x1DCr?...', '6b12de7060ce774...') #1 \/data\/www\/rcvd.io\/nextcloud\/apps\/encryption\/lib\/Crypto\/Crypt.php(422): OCA\Encryption\Crypto\Crypt->symmetricDecryptFileContent('GnrifLmsUaVL3bK...', '\x9D$\xAE\x9B\xF7\xE3\/l\xAEm\xDB\x1DCr?...', 'AES-256-CTR', 0) #2 \/data\/www\/rcvd.io\/nextcloud\/apps\/encryption\/lib\/KeyManager.php(427): OCA\Encryption\Crypto\Crypt->decryptPrivateKey('GnrifLmsUaVL3bK...') #3 \/data\/www\/rcvd.io\/nextcloud\/apps\/encryption\/lib\/Crypto\/Encryption.php(490): OCA\Encryption\KeyManager->getFileKey('\/alex\/files\/Tau...', 'pubShare_40674a...') #4 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/Files\/Storage\/Wrapper\/Encryption.php(328): OCA\Encryption\Crypto\Encryption->isReadable('\/alex\/files\/Tau...', NULL) #5 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/Files\/Storage\/Wrapper\/Wrapper.php(169): OC\Files\Storage\Wrapper\Encryption->isReadable('files\/Taufe Kon...') #6 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/Files\/View.php(1136): OC\Files\Storage\Wrapper\Wrapper->isReadable('files\/Taufe Kon...') #7 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/Files\/View.php(492): OC\Files\View->basicOperation('isReadable', '\/Taufe Konrad\/f...') #8 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/Files\/Filesystem.php(686): OC\Files\View->isReadable('\/Taufe Konrad\/f...') #9 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/legacy\/files.php(264): OC\Files\Filesystem::isReadable('\/Taufe Konrad\/f...') #10 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/legacy\/files.php(120): OC_Files::getSingleFile(Object(OC\Files\View), '\/Taufe Konrad', 'fotos_konrad_ta...', Array) #11 \/data\/www\/rcvd.io\/nextcloud\/apps\/files_sharing\/lib\/Controller\/ShareController.php(535): OC_Files::get('\/Taufe Konrad', 'fotos_konrad_ta...', Array) #12 [internal function]: OCA\Files_Sharing\Controller\ShareController->downloadShare('BPpRfnEIFYlSfTU', NULL, '', '') #13 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/AppFramework\/Http\/Dispatcher.php(160): call_user_func_array(Array, Array) #14 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/AppFramework\/Http\/Dispatcher.php(90): OC\AppFramework\Http\Dispatcher->executeController(Object(OCA\Files_Sharing\Controller\ShareController), 'downloadShare') #15 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/AppFramework\/App.php(114): OC\AppFramework\Http\Dispatcher->dispatch(Object(OCA\Files_Sharing\Controller\ShareController), 'downloadShare') #16 \/data\/www\/rcvd.io\/nextcloud\/lib\/public\/AppFramework\/App.php(136): OC\AppFramework\App::main('ShareController', 'downloadShare', Object(OC\AppFramework\DependencyInjection\DIContainer)) #17 \/data\/www\/rcvd.io\/nextcloud\/core\/routes.php(129): OCP\AppFramework\App->dispatch('ShareController', 'downloadShare') #18 [internal function]: OC\Route\Router->{closure}(Array) #19 \/data\/www\/rcvd.io\/nextcloud\/lib\/private\/Route\/Router.php(299): call_user_func(Object(Closure), Array) #20 \/data\/www\/rcvd.io\/nextcloud\/lib\/base.php(1004): OC\Route\Router->match('\/s\/BPpRfnEIFYlS...') #21 \/data\/www\/rcvd.io\/nextcloud\/index.php(48): OC::handleRequest() #22 {main}","File":"\/data\/www\/rcvd.io\/nextcloud\/apps\/encryption\/lib\/Crypto\/Crypt.php","Line":483}"Just verified that
- the problem still exists after restoring the old 12.0 version
- the problem also exists with shared images (the image is shown but can not bei downloaded)
@LukasReschke I just sent the account data to you
Thanks, @rcvd.
It seems like the decryption of the public sharing key is failing here for some reason.
cc @schiessle FYI
Is there anything I can do to shed some more light onto this issue?
@rcvd is it a fresh Nextcloud 12 installation or did you upgraded from Nextcloud 11?
@schiessle It's an upgraded installation...started a while ago with owncloud.
OK, I just tried the upgrade path: Setup Nextcloud 11, enable encryption, create a public link and upgrade but the link still works here. Does it happen for all public links? only a few? What happens if you create a new public link?
It happens for all public links. For old and new ones. Even on different or newly created accounts. If I decrypt the files using occ the link starts working.
Same problem in 11.6 with pdf file.
- addedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Jun 20, 2018 We can't reproduce this anymore. Could you test please with a more recent version again? I will close this ticket for now but we can easily reopen the ticket if this is still reproducible somehow. Then please also share exact steps how to do it.
- removedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Nov 29, 2018 - added a commit that references this issue
on Nov 22, 2025
Steps to reproduce
Expected behaviour
The file should be downloadable without any further actions
Actual behaviour
Error screen "Can't read signature" "Ungültige Signatur" (Invalid Signature)
General server configuration
Operating system: Linux 4.12.13-1-ARCH #1 SMP PREEMPT Fri Sep 15 06:36:43 UTC 2017 x86_64
Web server: nginx/1.12.1 (fpm-fcgi)
Database: mysql 10.1.26
PHP version: 7.1.9
PHP-modules loaded
Nextcloud configuration
Nextcloud version: 12.0.3 RC2 - 12.0.3.1
Updated from an older Nextcloud/ownCloud or fresh install: Updated
Where did you install Nextcloud from: Official Website
Are you using external storage, if yes which one: files_external is disabled
Are you using encryption: yes
Are you using an external user-backend, if yes which one: No
Signing status
Enabled apps
Disabled apps
Content of config/config.php
Client configuration
Browser: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Safari/604.1.38
Operating system: OS X 10.13
Logs
Web server error log
Nextcloud log (data/nextcloud.log)
Browser log