Solved - ConvertTo-SecureString : Key not valid for use in specified state.

Опубликовано: 28 Май 2026
на канале: Maruti AIR Tech
7,533
19

ConvertTo-SecureString : Key not valid for use in specified state.
At
$securePass = Get-Content $filename| ConvertTo-SecureString
~~~~~~~~~~~~~~~~~~~~~~
CategoryInfo : InvalidArgument: (:) [ConvertTo-SecureString], CryptographicException
FullyQualifiedErrorId : ImportSecureString_InvalidArgument_CryptographicError,Microsoft.PowerShell.Commands.ConvertToSecureStringCommand


------------------------------

The issue due to the way original credential was created before being exported to xml.

When you use the command ConvertTo-SecureString it encrypts the plaintext password with the encryption key on the local machine, under your user account.
This means that if you export it to xml, you can only use it on that same local machine.

The minute you copy the xml file to another machine and try to import the credential object,
it won't work because it will be trying to decrypt it with it's local keys which don't match.
(hence the error message).
This is an important security measure as it prevents me from copying the file and using it on another computer.



If you need to have the user account on another computer to run something, then there are Three options:

(Unsecured) Use Plain Text

(Most secure) Create the credential object on each remote computer that you need it.

(Least secure) When you create the credential with ConvertTo-SecureString you can specify the -Key or -SecureKey parameter.
This way instead of using the local encryption keys, it will use the one you specify.
Then in your script, you provide the same key to decrypt it.