【问题标题】:How can we create an AsymmetricSecurityKey?我们如何创建 AsymmetricSecurityKey?
【发布时间】:2018-02-19 06:34:19
【问题描述】:

我们如何在 c# 中创建 AsymmetricSecurityKey。实际上,我们正在使用 AsymetricSecurityKey 创建签名凭据,这是我们的代码:

// Define const Key this should be private secret key  stored in some safe place
string key = "401b09eab3c013d4ca54922bb802bec8fd5318192b0a75f201d8b3727429090fb337591abd3e44453b954555b7a0812e1081c39b740293f765eae731f5a65ed1";

// Create Security key  using private key above:
// not that latest version of JWT using Microsoft namespace instead of System
var securityKey = new AsymmetricSecurityKey(Encoding.UTF8.GetBytes(key));

// Also note that securityKey length should be >256b
// so you have to make sure that your private key has a proper length
//
var credentials = new Microsoft.IdentityModel.Tokens.SigningCredentials
                  (securityKey, SecurityAlgorithms.HmacSha256Signature);

【问题讨论】:

  • 在非对称中我不认为可以提供私钥/公钥,它只能生成。
  • 这可能会有所帮助github.com/aspnet/Identity/blob/…
  • @FaizanRabbani,你能给我提供任何在 C# 中生成 AsymmetricSecurityKey 的示例代码吗?
  • AsymmetricSecurityKey 是抽象类,需要创建具体的实现。例如,如果您使用 RSA:var securityKey = new RsaSecurityKey(...)

标签: c#


【解决方案1】:

您可以使用以下方法生成公钥/私钥:

public void GenerateRsaCryptoServiceProviderKey()
{
        var rsaProvider = new RSACryptoServiceProvider(512);
        SecurityKey key = new RsaSecurityKey(rsaProvider);      
}

你应该在下面使用RsaSha256

var credentials = new Microsoft.IdentityModel.Tokens.SigningCredentials
                  (key, SecurityAlgorithms.RsaSha256);

【讨论】:

  • 其实我需要从 AsymmetricSecurityKey 创建 SigningCredentials 对象
  • 即 var credentials = new SigningCredentials(asymmetricSecurityKey, SecurityAlgorithms.HmacSha256Signature);
【解决方案2】:

您是否专门寻找AsymmetricSecurityKey

我注意到您引用的是 HM256 算法。这让我相信您正在寻找SymmetricSecurityKey。此外,您的方法似乎非常适用于使用 HMAC 算法。

要生成SymmetricSecurityKey,您可以尝试以下代码:

// Define const Key this should be private secret key  stored in some safe place
string key = "401b09eab3c013d4ca54922bb802bec8fd5318192b0a75f201d8b3727429090fb337591abd3e44453b954555b7a0812e1081c39b740293f765eae731f5a65ed1";

// Create Security key  using private key above:
// not that latest version of JWT using Microsoft namespace instead of System
var securityKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(key));

// Also note that securityKey length should be >256b
// so you have to make sure that your private key has a proper length
//
var credentials = new Microsoft.IdentityModel.Tokens.SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256Signature);

如果您想要使用 RS256 alg 的解决方案(它将使用 pfx 格式的证书),您可以发表评论,我也会尽力为您提供一个示例。

【讨论】:

    【解决方案3】:

    这会从 F# 中的 RSA 公钥创建安全密钥。

        let pem = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnzyis1ZjfNB0bBgKFMSvvkTtwlvBsaJq7S5wA+kzeVOVpVWwkWdVha4s38XM/pa/yr47av7+z3VTmvDRyAHcaT92whREFpLv9cj5lTeJSibyr/Mrm/YtjCZVWgaOYIhwrXwKLqPr/11inWsAkfIytvHWTxZYEcXLgAXFuUuaS3uF9gEiNQwzGTU1v0FqkqTBr4B8nW3HCN47XUu0t8Y0e+lf4s4OxQawWD79J9/5d3Ry0vbV3Am1FtGJiJvOwRsIfVChDpYStTcHTCMqtvWbV6L11BWkpzGXSW4Hv43qa+GSYOD2QU68Mb59oSk2OB+BtOLpJofmbGEGgvmwyCI9MwIDAQAB"
            
        let getPublicKey (pem: string) =
                let publicKey = ReadOnlySpan<byte>(Convert.FromBase64String(pem))
                let rsa = RSA.Create()
                let mutable read = 0
                rsa.ImportSubjectPublicKeyInfo(publicKey, &read)
                new RsaSecurityKey(rsa)
    
        getPublicKey pem
    

    【讨论】:

      猜你喜欢
      • 2011-11-05
      • 2018-10-22
      • 2019-05-06
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2022-11-16
      • 2021-05-25
      相关资源
      最近更新 更多