【问题标题】:How to encrypt / decrypt a configuration file section with RsaProtectedConfigurationProvider如何使用 RsaProtectedConfigurationProvider 加密/解密配置文件部分
【发布时间】:2016-05-10 14:53:53
【问题描述】:

在我的配置文件中,我有一些敏感信息我想加密以提高安全性。

这是我的代码(按预期工作):

class Program
{
    static void Main(string[] args)
    {
        System.Configuration.ExeConfigurationFileMap fileMap = new ExeConfigurationFileMap();
        fileMap.ExeConfigFilename = @"D:\Web_S\Prep\test\test.exe.config";
        System.Configuration.Configuration configuration = System.Configuration.ConfigurationManager.OpenMappedExeConfiguration(fileMap, ConfigurationUserLevel.None);
        string userNameWithoutEncryption = configuration.AppSettings.Settings["username"].Value;
        EncryptAppSettings("appSettings", configuration);
    }

    protected static void EncryptAppSettings(string section, Configuration configuration)
    {    
        AppSettingsSection objAppsettings = (AppSettingsSection)configuration.GetSection(section);
        objAppsettings.SectionInformation.ProtectSection("RsaProtectedConfigurationProvider");
        objAppsettings.SectionInformation.ForceSave = true;
        configuration.Save(ConfigurationSaveMode.Modified);

    }
}

.config:

<?xml version="1.0" encoding="utf-8" ?>
<configuration>
  <appSettings>
    <add key="username" value="a2zmenu"/>
    <add key="password" value="password"/>
  </appSettings>
</configuration>

加密后的 .config 如下所示:

<?xml version="1.0" encoding="utf-8" ?>
<configuration>
  <configSections>
    <section name="customAppSettings" type="System.Configuration.NameValueSectionHandler" />
  </configSections>
  <appSettings configProtectionProvider="RsaProtectedConfigurationProvider">
    <EncryptedData Type="http://www.w3.org/2001/04/xmlenc#Element"
      xmlns="http://www.w3.org/2001/04/xmlenc#">
      <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" />
      <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
        <EncryptedKey xmlns="http://www.w3.org/2001/04/xmlenc#">
          <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5" />
          <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
            <KeyName>Rsa Key</KeyName>
          </KeyInfo>
          <CipherData>
<CipherValue>09+Lm23xDWWnAZFOagh3NRwp5tzad+3oedvTgoeWqunQBiAfk9UGfGxriZg6snwwANUDzOANZ+wOFUb6qa0Atf
NgSd6b4FFSKTqzkfLlk+S9GtPSAVrRaLU9
/Q2Qu7oxoSbhW7NWtengJbEZrFm+GqlLlm08w8Np/y03DMExFeA=</CipherValue>
          </CipherData>
        </EncryptedKey>
      </KeyInfo>
      <CipherData>
<CipherValue>qSYRXNEKhbwNodH60c7qoWeKZ2QKVQmizPXVGCgHVZPMQ4F+XDqlZa2OyIin0kEI3j8pCjNL097RlZClgdd
gPEd61AEw6DXJc43Z98obNFHmXfK9aS67qEtO6E
T+qCWQq2ZRbfK6xZ6jlfeink35/veUmoxAmDXrkwdrbQVKv98=</CipherValue>
      </CipherData>
    </EncryptedData>
  </appSettings>
</configuration>

我有以下问题: 让

等信息安全吗
   <EncryptedKey xmlns="http://www.w3.org/2001/04/xmlenc#">
      <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5" />

在 .config 中?

难道不能用这些信息解密吗? 文件加密后,你能确认我可以评论这一行吗:

  EncryptAppSettings("appSettings", configuration);

当我尝试在使用此行加密文件后获取用户名值时:

string userNameafterEncryption = configuration.AppSettings.Settings["username"].Value;

即使我的文件现在已加密,我也会得到解密的值。我不明白为什么...

感谢您的帮助

【问题讨论】:

    标签: c# .net app-config rsaprotectedconfiguration


    【解决方案1】:

    首先,您需要了解配置加密如何以及从哪些配置中真正保护您。 RsaProtectedConfigurationProvider 可以在两个地方存储用于实际加密的私钥。第一个是

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys
    

    这是存储机器范围密钥的文件夹。默认情况下,任何用户都可以访问此文件夹,但您需要提升权限(以管理员身份运行)才能读取此文件夹中的文件(同样,默认情况下)。

    第二个可能的位置是

    C:\Documents and Settings\[user name]\Application Data\Microsoft\Crypto\RSA
    

    这是用户级别的位置 - 只有特定用户才能访问它。

    默认情况下,RsaProtectedConfigurationProvider 将使用机器级位置,这由该提供程序的UseMachineContainer 属性控制。默认配置在机器级配置文件(位于C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config)中定义,定义如下:

    <add name="RsaProtectedConfigurationProvider" type="System.Configuration.RsaProtectedConfigurationProvider,System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a" description="Uses RsaCryptoServiceProvider to encrypt and decrypt" keyContainerName="NetFrameworkConfigurationKey" cspProviderName="" useMachineContainer="true" useOAEP="false"/>
    

    如果您想使用用户级位置加密您的部分,您可以在自己的 app.config 文件中覆盖此配置(查看更多 here)。

    现在,当您了解所有这些信息后,您可以做出明智的决定,是否需要加密您的部分,如果需要 - 使用哪个位置。

    1. 如果您使用机器级位置(默认) - 您的应用程序应该在提升(在管理员下)运行以对您的部分进行加密和解密。如果有人可以访问您的配置文件 - 如果没有管理员权限,他将无法解密它。在某些环境(尤其是企业)中,运行提升可能会成为问题。

    2. 如果您使用用户级位置 - 您的应用程序不需要运行提升。只有加密部分的用户可以稍后解密它。如果有人以不同的用户(想象一些公司域)访问您的计算机并窃取文件 - 他将无法解密它。

    您可以为特定用户\机器预加密您的部分(如果需要,可以将加密部分的密钥从一台机器导出到另一台机器)或在第一次运行时要求用户输入敏感数据(数据库密码为一个例子) - 然后将该数据保存到 app.config 和加密部分。

    至于为什么您会自动获得解密值 - 那是因为如果可能的话,它是动态解密的。您似乎默认以管理员身份运行(例如禁用您的 UAC),因此您可以访问用于加密的密钥,因此可以解密。如果您在没有管理员的情况下运行 - 当您尝试访问加密值时会抛出异常。

    【讨论】:

    • 使用 ClickOnce 将应用程序发布到 LAN 服务器时会发生什么情况:...this application is available only online?
    • @Tim 我不确定,但 clickonce 文档中有一条注释,在“从 Web 或网络共享启动应用程序”部分:“技术上,应用程序已下载并安装到本地计算机上的应用程序缓存”。因此,由于它像往常一样从本地文件夹运行,我希望它的行为与答案中描述的相同。
    猜你喜欢
    • 1970-01-01
    • 2010-12-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多