【发布时间】:2015-07-14 18:24:44
【问题描述】:
我的组织要求使用位于我们生产服务器上的特定 System.Configuration.RsaProtectedConfigurationProvider 对敏感连接字符串进行加密。但是,我有一个将连接字符串存储在数据库中的应用程序,我想使用相同的密钥对这些字符串执行加密。
我最初的想法是创建一个包含对加密提供程序的引用的虚拟配置文件,加载一些文本并执行加密,而无需将其写回磁盘。然后我可以将密码/明文从 xml 中提取出来:
DummyConfig.config:
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<configSections>
<section name="DummySection" type="virutalConfig.DummySect, virutalConfig, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
</configSections>
<DummySection />
<configProtectedData>
<providers>
<add name="MyProvider"
type="System.Configuration.RsaProtectedConfigurationProvider, System.Configuration, Version=2.0.0.0,
 Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a,
 processorArchitecture=MSIL"
keyContainerName="MyKeys"
useMachineContainer="true" />
</providers>
</configProtectedData>
</configuration>
程序.cs:
class Program
{
static void Main(string[] args)
{
var fileMap = new ExeConfigurationFileMap
{
ExeConfigFilename = @"c:\virtconfigtest\DummyConfig.config"
};
var config = ConfigurationManager.OpenMappedExeConfiguration(fileMap, ConfigurationUserLevel.None);
var sect = config.GetSection("DummySection") as DummySect;
sect.Inf = "this is some plaintext!";
sect.SectionInformation.ProtectSection("MyProvider");
//sect.SectionInformation.ForceSave = true;
//config.Save();
if (sect.SectionInformation.IsProtected)
{
Console.WriteLine("Section is protected. Raw XML:");
Console.WriteLine(sect.SectionInformation.GetRawXml());
}
else
{
Console.WriteLine("Section is not protected. Raw XML:");
Console.WriteLine(sect.SectionInformation.GetRawXml());
}
Console.ReadLine();
}
}
public class DummySect : ConfigurationSection
{
public DummySect() { }
[ConfigurationProperty("inf")]
public string Inf
{
get { return (string)this["inf"]; }
set { this["inf"] = value; }
}
}
不幸的是,GetRawXml() 只返回明文,即使要得到它,似乎也必须将配置文件写回磁盘。
我可以通过将磁盘上的文件作为 xml 文档读取来得到我想要的,但我宁愿不必这样做。无论如何,整个计划都是相当粗暴的,即使没有在混合中添加磁盘写入。我是否必须从提供商处检索 RSA 密钥才能执行此操作?如果有,怎么做?
【问题讨论】:
标签: c# .net encryption configuration-files