【问题标题】:unable to encrypt web.config file using RSA encryption method无法使用 RSA 加密方法加密 web.config 文件
【发布时间】:2016-08-23 15:01:43
【问题描述】:

我是这个过程的新手。我的要求是使用 RSA 加密方法加密 Asp.Net webforms 应用程序的 appSettings 部分。此外,加密文件将部署到 Dev、QA 环境中,相同的密钥具有不同的 appSettings 值。所以我应该能够在本地或开发机器上加密文件一次,并且能够使用相同的方法加密 qa-web.config 和 prod-web.config 并将它们部署到各自的环境中。

我一直在关注 MSDN“https://msdn.microsoft.com/en-us/library/2w117ede.aspx”中的这篇文章,但出现以下异常 - “未找到提供程序 [providername]”。请在这方面提供帮助

更新 1:请找到 web.config 代码,其中 appSettings 需要加密:

<connectionStrings>
  <add name="DBConnectionString" connectionString="xxxxxx" providerName="System.Data.SqlClient" />   
</connectionStrings>
<appSettings>
  <add key="abc" value="val" />
  <add key="def" value="val1" />
  <add key="xde" value="val2" />
  <add key="ldf" value="val3" />
</appSettings>
<system.web>
  <authentication mode="None" />
  <compilation debug="true" targetFramework="4.5.2" />
  <httpRuntime targetFramework="4.5.2" />
</system.web>

【问题讨论】:

  • 这个RSA的应用一开始就没有意义; RSA 通常要求您使用其他 人的公钥加密,而不是您自己的密钥。您可能想在这里使用其他方案。对称密钥算法要快得多(并且可以说为此目的更安全)。另外,调试方面,您可以发布您正在使用的代码吗? (至少是产生异常的代码)。
  • 即使我得到这个错误。在文章中使用此命令“aspnet_regiis -pe "connectionStrings" -app "/MyApplication" -prov "MyProvider" 时出现错误。
  • 对不起,这里没有代码。没有人可以在没有看到产生异常的代码的情况下开始诊断异常。投票结束。
  • @lavan 这真的应该张贴在问题本身,而不是 cmets 部分,很难阅读。此外,该特定代码与帮助您调试问题并不是特别相关,因为那不是实际执行加密或引发异常的代码。除此之外,我仍然认为这种特殊方法从根本上讲是没有意义的,因此有问题的异常不值得一开始就修复。

标签: c#


【解决方案1】:

1) 以管理员身份启动 VS 的开发人员命令提示符并转到您要加密的应用程序的根目录,创建您自己的密钥集 - 例如。我的钥匙

C:\inetpub\wwwroot> aspnet_regiis -pc "My_key"  -exp
Microsoft (R) ASP.NET RegIIS version 4.0.30319.0
Administration utility to install and uninstall ASP.NET on the local machine.
Copyright (C) Microsoft Corporation.  All rights reserved.
Creating RSA Key container...
Succeeded!

2) 添加对 NT 授权服务的访问权限 - 因为 Web 服务器在此授权下运行

C:\inetpub\wwwroot>aspnet_regiis -pa "My_key" "NT AUTHORITY\NETWORK SERVICE"
Microsoft (R) ASP.NET RegIIS version 4.0.30319.0
Administration utility to install and uninstall ASP.NET on the local machine.
Copyright (C) Microsoft Corporation.  All rights reserved.
Adding ACL for access to the RSA Key container...
Succeeded!

3) 添加一个名为 e.g. “My_Provider”到 web.config,指定在步骤 1 (My_key) 中创建的密钥,在该部分下。

 <configProtectedData >
    <providers>
      <add name="My_Provider"
           type="System.Configuration.RsaProtectedConfigurationProvider, System.Configuration, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=MSIL"
           KeyContainerName="My_key"
           useMachineContainer="true" />
    </providers>
  </configProtectedData>

-->确保以完整的管理员权限启动 VS Developer 提示符,否则,您将收到错误消息。

第 4 步)现在加密连接字符串,指定名为

的提供者
 C:\inetpub\wwwroot>aspnet_regiis -pe "connectionStrings"  -prov "My_Provider"
Microsoft (R) ASP.NET RegIIS version 4.0.30319.0
Administration utility to install and uninstall ASP.NET on the local machine.
Copyright (C) Microsoft Corporation.  All rights reserved.
Encrypting configuration section...
The protection provider 'MY_Provider' was not found.
Failed!

我遇到了错误,因为我的 CMD 提示没有以完全管理员身份启动。此外,当 wwwroot 中有多个应用程序时,您必须使用 -app "/application1" 参数指定要加密的应用程序

从这里开始,只需将密钥导出到 XML 文件,然后将它们导入 DEV/UAT/PROD 服务器,然后再次删除服务器上的 XML 文件

【讨论】:

    猜你喜欢
    • 2015-02-25
    • 1970-01-01
    • 2012-05-08
    • 2019-07-22
    • 1970-01-01
    • 2013-02-09
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多