profile
viewpoint

Ask questionsHMAC Mismatch occurs on computer restart, and the kbdx file cannot be opened or repaired.

Expected Behavior

The kbdx should be able to be opened without issue, or, in the worst case, repaired.

Current Behavior

Open KeepassXC after a restart, and when entering the password (unchanged from the previous sessions), the database cannot be opened due to an HMAC mismatch. It cannot be repaired due to the same error. This even occurs in the most recent backups of the kbdx file that was open at the time.

Possible Solution

Currently, the only solution is restore a previous version of the database, but, backups made within the last few hours of the computer restart also tend to be corrupted, requires a backup that is usually a day older.

Steps to Reproduce

I'm sorry, I can't reliably reproduce this. There were 2 instances of corruption that were expected - a BSOD, and a Chrome Crash while connected through the new KeepassXC Browser Integration. But in both cases, there were also multiple backups of the open database that were also corrupted, not just the version of the kbdx open in KeepassXC.

Context

I've lost passwords, been unable to access PGP credentials, cc information, external keyfiles, and other information that is stored in KeepassXC. It occurs across multiple unique databases.

The kbdx file is always saved successfully, even with the BSOD and Chrome Crash, there was no active changes in the kbdx file, and it was successfully saved and backed up, it just happened to be open at the time.

Now, this is not always an issue when I can restore it, but I there are cases where that is not possible. In some cases, credentials are lost and the account they are tied to is unrecoverable as a result. Thankfully this hasn't occurred for anything too serious and I've made a point to spread out things into multiple locations to try and mitigate that.

Debug Info

KeePassXC - Version 2.3.4 Revision: 6fe821c

Libraries:

  • Qt 5.11.1
  • libgcrypt 1.8.3

Operating system: Windows 10 (10.0) CPU architecture: x86_64 Kernel: winnt 10.0.17134

Enabled extensions:

  • Auto-Type
  • Browser Integration
  • Legacy Browser Integration (KeePassHTTP)
  • SSH Agent
  • YubiKey
keepassxreboot/keepassxc

Answer questions phoerious

Make sure you only have boxes checked for things you have in your key (so uncheck key file if you don't have one). KeePassXC 2.5 will improve the usability of the unlock dialogue in this regard.

useful!

Related questions

KeePassXC-Browser, Firefox Add-On - message "Timeout or not connected to KeePassXC" hot 1
Unable to open the database. No root group. hot 1
KeepassXC as libsecret implementation doesn't return secret when searching by some attributes hot 1
SSH Agent integration does not work with snap build hot 1
Can't open password database which looks fine in KeePass hot 1
keepassxc snap browser integration in Vivaldi gives error message hot 1
how to use keeshare hot 1
Improve support for Macbook Pro TouchID hot 1
keepassxc as pinentry for gpg hot 1
Make KPXC databases accessible via libsecret/DBus hot 1
macOS 10.15: Auto-type requires screen reader permission hot 1
Database opens in read-only mode when accessed remotely using 'dav' protocol hot 1
QObject::startTimer message when run in console hot 1
Unable to connect to KeePassXC-Browser hot 1
Github User Rank List