<connectionStrings configProtectionProvider="RsaProtectedConfigurationProvider">
<EncryptedData Type="http://www.w3.org/2001/04/xmlenc#Element" xmlns="http://www.w3.org/2001/04/xmlenc#">
<EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" />
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<EncryptedKey xmlns="http://www.w3.org/2001/04/xmlenc#">
<EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5" />
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<KeyName>Rsa Key</KeyName>
</KeyInfo>
<CipherData>
<CipherValue>.......</CipherValue>
</CipherData>
</EncryptedKey>
</KeyInfo>
<CipherData>
<CipherValue>.......</CipherValue>
</CipherData>
</EncryptedData>
</connectionStrings>
[xml]$x = Get-Content "$Path\Web.config"
$Prov = New-Object System.Configuration.RsaProtectedConfigurationProvider
$Prov.Decrypt($x.configuration.connectionStrings.EncryptedData)
它通过配置所在服务器上的远程Powershell执行。该帐户是管理员,因此应提供本地计算机密钥。我发现一个错误:
Value cannot be null. Parameter name: keyName
一个相同的模块提供程序名fragment适用于DPAPI加密的部分。密钥名就在该部分中。我错过了什么?
更新:当Web代码执行时,它调用
Initialize()
先在提供者上。我已经模拟了初始化调用的参数。它们来自机器。配置。
$nv = New-Object System.Collections.Specialized.NameValueCollection
$nv.Add("description", "Uses RsaCryptoServiceProvider to encrypt and decrypt")
$nv.Add("keyContainerName", "NetFrameworkConfigurationKey")
$nv.Add("cspProviderName", "")
$nv.Add("useMachineContainer", "true")
$nv.Add("useOAEP", "false")
$Prov.Initialize("RsaProtectedConfigurationProvider", $nv)
现在我得到一个不同的错误:“坏数据”。
更新2:在该文件上尝试了sicing aspnet_regis,得到了相同的“坏数据”错误。但网站本身似乎已经启动并运行,并且可以感知数据库。可能是连接字符串部分
是
毕竟是被破坏了,而且网站把它带到了别处。