{"id":"49e5ce3cf97780f3","repo":"docker/cli","slug":"could-not-decrypt-key","errorCode":null,"errorMessage":"could not decrypt key","messagePattern":"could not decrypt key","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"cmd/docker-trust/trust/key_load.go","lineNumber":113,"sourceCode":"\tif _, _, err = tufutils.ExtractPrivateKeyAttributes(privKeyBytes); err != nil {\n\t\treturn fmt.Errorf(\"provided file %s is not a supported private key - to add a signer's public key use docker trust signer add\", keyPath)\n\t}\n\tif privKeyBytes, err = decodePrivKeyIfNecessary(privKeyBytes, passRet); err != nil {\n\t\treturn fmt.Errorf(\"cannot load key from provided file %s: %w\", keyPath, err)\n\t}\n\t// Make a reader, rewind the file pointer\n\treturn trustmanager.ImportKeys(bytes.NewReader(privKeyBytes), privKeyImporters, keyName, \"\", passRet)\n}\n\nfunc decodePrivKeyIfNecessary(privPemBytes []byte, passRet notary.PassRetriever) ([]byte, error) {\n\tpemBlock, _ := pem.Decode(privPemBytes)\n\t_, containsDEKInfo := pemBlock.Headers[\"DEK-Info\"]\n\tif containsDEKInfo || pemBlock.Type == \"ENCRYPTED PRIVATE KEY\" {\n\t\t// if we do not have enough information to properly import, try to decrypt the key\n\t\tif _, ok := pemBlock.Headers[\"path\"]; !ok {\n\t\t\tprivKey, _, err := trustmanager.GetPasswdDecryptBytes(passRet, privPemBytes, \"\", \"encrypted\")\n\t\t\tif err != nil {\n\t\t\t\treturn []byte{}, errors.New(\"could not decrypt key\")\n\t\t\t}\n\t\t\tprivPemBytes = privKey.Private()\n\t\t}\n\t}\n\treturn privPemBytes, nil\n}\n","sourceCodeStart":95,"sourceCodeEnd":120,"githubUrl":"https://github.com/docker/cli/blob/e9452d6e785f6e365712b9d71bd7517591773c86/cmd/docker-trust/trust/key_load.go#L95-L120","documentation":"Error \"could not decrypt key\" thrown in docker/cli.","triggerScenarios":"Thrown at cmd/docker-trust/trust/key_load.go:113 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":[],"exampleFix":null,"handlingStrategy":null,"validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"analyzedSha":"e9452d6e785f6e365712b9d71bd7517591773c86","analyzedAt":"2026-08-01T07:09:22.474Z","schemaVersion":2}