【问题标题】:Using ASPNet_Regiis to encrypt custom configuration section - can you do it?使用 ASPNet_Regiis 加密自定义配置部分 - 你能做到吗?
【发布时间】:2009-04-24 16:39:16
【问题描述】:

我有一个带有自定义配置部分的 Web 应用程序。该部分包含我想加密的信息(希望使用 ASPNet_RegIIS 而不是自己做)。

Web.Config:

<?xml version="1.0"?>

    <configuration xmlns="http://schemas.microsoft.com/.NetConfiguration/v2.0">
      <configSections>
          <section name="MyCustomSection" 
                   type="MyNamespace.MyCustomSectionHandler, MyAssembly"/>
    </configSections>
<configProtectedData>
    <providers>
      <clear />
      <add name="DataProtectionConfigurationProvider"
           type="System.Configuration.RsaProtectedConfigurationProvider, System.Configuration, Version=2.0.0.0,
                   Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a,
                   processorArchitecture=MSIL"
           keyContainerName="MyKeyContainer"
           useMachineContainer="true" />
    </providers>
  </configProtectedData>
    <MyCustomSection>
       <blah name="blah1">
          <blahChild name="blah1Child1" />
       </blah>
    </MyCustomSection>

配置处理程序在尝试加密之前运行良好。当我尝试使用以下方法对其进行加密时:

aspnet_regiis -pef "MyCustomSection" c:\inetpub\wwwroot\MyWebsite -prov DataProtectionConfigurationProvider

我收到一个错误:

加密配置部分...一个 创建时出错 配置节处理程序 MyCustomSection:无法加载文件 或组装“MyAssembly”或其之一 依赖关系。系统找不到 指定的文件。 (c:\inetpub\wwwroot\MyWebsite\web.config 第 5 行)

我尝试过配置/不配置提供程序。有/无部分组。有/没有事先启动网站。我已经尝试暂时将我的程序集放在 GAC 中进行注册。我还尝试了我的 log4net 部分,只是为了尝试不属于我的东西,但没有运气。我以管理员身份运行命令提示符。有任何想法吗?或者 ASPNet_RegIIS 不能用于自定义部分?

查看MSDN 后的最后一个镜头是将我的处理程序更改为从 ConfigurationSection 继承而不是实现 IConfigurationSectionHandler,因为它在 2.0 中在技术上已被弃用(希望它与 aspnet_regiis 版本有关)。那里也没有运气。

任何想法让我知道。谢谢!

【问题讨论】:

  • 我遇到了同样的问题。我不认为有一种方法可以在不将程序集放入 gac 或下面答案中的 hack 的情况下使其正常工作?
  • 我厌倦了摆弄它 - 所以我只是暂时将程序集放在 gac 中。

标签: asp.net encryption web-config aspnet-regiis.exe system.configuration


【解决方案1】:

aspnet_regiis 必须能够绑定程序集。正常的 .net 绑定规则适用。

我通过在与aspnet_regiis.exe 相同的目录中创建一个名为aspnet_regiis_bin 的目录以及一个以aspnet_regiis_bin 作为私有路径的aspnet_regiis.exe.config 文件来解决此问题,如下所示:

<configuration>
   <runtime>
      <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">
         <probing privatePath="aspnet_regiis_bin"/>
      </assemblyBinding>
   </runtime>
</configuration>

然后,我将定义自定义配置部分的程序集复制到 aspnet_regiis_bin,以便 aspnet_regiis 可以找到它们。

此过程不要求程序集是强命名的或在 GAC 中,但确实需要在框架目录中乱七八糟。

【讨论】:

  • 天才!!注意:确保将它放在 C:\Windows\Microsoft.NET\Framework\v4.0.30319\ 文件夹中,而不是 Framework64 文件夹中
  • 将近 10 年后...在 Google 上找到了这个,这正是我需要的解决方案。非常感谢!
【解决方案2】:

我正在使用一种解决方法,即我暂时注释掉 configSections 元素的内容:

<configSection>
    <!--
    <section name="CustomSection" type="" />
    -->
</configSection>

然后您可以像往常一样使用aspnet_regiis -pef 运行加密。运行后,只需取消注释该部分,您的网站就可以运行了。

【讨论】:

  • 谢谢。通过使用您的建议,我能够使该过程自动化(一些 Powershell cmets 取出部分名称,然后运行 ​​aspnet_regiis,然后通过 Powershell 再次删除 cmets)。
【解决方案3】:

这完全是 hack,但我不确定是否有另一种方法可以做到这一点,而无需强烈命名定义自定义部分的程序集并对其进行 GAC 化(尽管您提到这也不起作用,而且我我不知道为什么它不会)。由于aspnet_regiis运行在:\Windows\Microsoft.Net\Framework\文件夹(在WinXP中),你可以将定义你的配置部分的DLL复制到相关的Framework\文件夹中,然后应该可以。

【讨论】:

  • 当我将它移入 GAC 时,它使用强名称进行了签名。我还确保在我的 configuration/section.type 中包含 version/culture/public 密钥。不过,您的解决方案确实让我通过了,谢谢。如果其他人遇到这种情况,我最终会按照答案建议将 dll 移动到框架文件夹,然后以管理员身份运行 aspnet_regiis (Windows Server 2007)。
  • 经过更多的摆弄之后,我得到了它从 GAC 注册。我从来没有尝试过同时注册到 GAC 并在类型中使用长格式(尽管我在不同的时间都这样做了)。仔细考虑之后,完全有理由要求程序集在 GAC 中。再次感谢。
  • 太棒了。我也遇到了一些麻烦。
  • 正确答案。此外,如果您使用程序集的运行时限定,aspnet_regiis 将不会遵守这一点。部分声明本身必须包含程序集的完全限定名称。有关有效和无效的示例配置条目,请参阅我的单独答案。
【解决方案4】:

为了记录,我最终得到了一个小的维护页面来为我做这件事。

var currentConfig = System.Web.Configuration.WebConfigurationManager.OpenWebConfiguration("~/");
// Unprotect
ConfigurationSection section = currentConfig.GetSection("MyCustomSection");
if (section.SectionInformation.IsProtected)
{
   section.SectionInformation.UnprotectSection();
   currentConfig.Save();
}

// Protect
if (!section.SectionInformation.IsProtected)
{
     section.SectionInformation.ProtectSection("DataProtectionConfigurationProvider");
     currentConfig.Save();
}

注意事项:您的进程将需要对正在修改的配置文件的写入权限。您需要某种方式来授权谁可以运行它。保存时会generally 重启网站。

【讨论】:

    【解决方案5】:

    显示为正确的答案是正确的。我想添加评论但无法添加,因为评论太长(示例配置条目)。

    部分名称应使用程序集的全名。运行时程序集限定不适用于 aspnet_regiis.exe。

    这个作品:

    <configSections>
      <section name="securityConfiguration" type="Microsoft.Practices.EnterpriseLibrary.Security.Configuration.SecuritySettings, Microsoft.Practices.EnterpriseLibrary.Security, Version=5.0.414.0, Culture=neutral, PublicKeyToken=9c844884b2afcb9e" />
    </configSections>
    

    但这不起作用:

    <configSections>
      <section name="securityConfiguration" type="Microsoft.Practices.EnterpriseLibrary.Security.Configuration.SecuritySettings, Microsoft.Practices.EnterpriseLibrary.Security" />
    </configSections>
    
    <runtime>
      <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">
         <qualifyAssembly partialName="Microsoft.Practices.EnterpriseLibrary.Security" fullName="Microsoft.Practices.EnterpriseLibrary.Security, Version=5.0.414.0, Culture=neutral, PublicKeyToken=9c844884b2afcb9e" />
        </assemblyBinding>
    </runtime>
    

    【讨论】:

      猜你喜欢
      • 2011-09-09
      • 2011-12-24
      • 1970-01-01
      • 1970-01-01
      • 2016-02-02
      • 2012-10-01
      • 1970-01-01
      • 2010-10-25
      相关资源
      最近更新 更多