Parent issue for making license key validation handle the key problems customers actually run into, in both AutoMapper and MediatR. Both products share the same license code, so each fix has a sub-issue per repo.
Why
Since July 2025 there have been 26 support cases about license validation, and 16 of them showed IDX10511: Signature validation failed. That message says the signature is wrong, but in most cases the key itself was fine and something else was going on:
| Cause |
Cases |
Sub-issues |
| Whitespace or newlines added to the key (PDF delivery, email wrapping, copy/paste, K8s secrets) |
3 confirmed, ~3 more likely |
Strip whitespace |
| Truncated key (last few characters lost) |
3 |
Detect truncated or malformed keys |
| Blazor WASM / client platforms: RSA not supported, but reported as a critical signature error |
7 |
Detect PlatformNotSupportedException inside the validation result |
| Other (wrong key, IdentityModel version break #4565) |
2 |
n/a |
| Unresolved |
11 |
n/a |
Every fix below should turn a misleading critical-level signature error into either a successful validation or a message that tells the user what to do.
Sub-issues
AutoMapper
MediatR
Optional hardening (not tracked as a sub-issue yet)
Give the license validation key its own static CryptoProviderFactory { CacheSignatureProviders = false } so it doesn't use the process-wide CryptoProviderFactory.Default cache. This costs about 5 µs more per validation, which happens once per configuration. It isn't linked to any confirmed failure.
🤖 Generated with Claude Code
Parent issue for making license key validation handle the key problems customers actually run into, in both AutoMapper and MediatR. Both products share the same license code, so each fix has a sub-issue per repo.
Why
Since July 2025 there have been 26 support cases about license validation, and 16 of them showed
IDX10511: Signature validation failed. That message says the signature is wrong, but in most cases the key itself was fine and something else was going on:Every fix below should turn a misleading critical-level signature error into either a successful validation or a message that tells the user what to do.
Sub-issues
AutoMapper
MediatR
Optional hardening (not tracked as a sub-issue yet)
Give the license validation key its own static
CryptoProviderFactory { CacheSignatureProviders = false }so it doesn't use the process-wideCryptoProviderFactory.Defaultcache. This costs about 5 µs more per validation, which happens once per configuration. It isn't linked to any confirmed failure.🤖 Generated with Claude Code