代码之家  ›  专栏  ›  技术社区  ›  Seva Alekseyev

RSA解密Web.config节

  •  0
  • Seva Alekseyev  · 技术社区  · 8 年前

    <connectionStrings configProtectionProvider="RsaProtectedConfigurationProvider">
        <EncryptedData Type="http://www.w3.org/2001/04/xmlenc#Element" xmlns="http://www.w3.org/2001/04/xmlenc#">
          <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" />
          <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
            <EncryptedKey xmlns="http://www.w3.org/2001/04/xmlenc#">
              <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5" />
              <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
                <KeyName>Rsa Key</KeyName>
              </KeyInfo>
              <CipherData>
                <CipherValue>.......</CipherValue>
              </CipherData>
            </EncryptedKey>
          </KeyInfo>
          <CipherData>
            <CipherValue>.......</CipherValue>
          </CipherData>
        </EncryptedData>
    </connectionStrings>
    

    [xml]$x = Get-Content "$Path\Web.config"
    $Prov = New-Object System.Configuration.RsaProtectedConfigurationProvider
    $Prov.Decrypt($x.configuration.connectionStrings.EncryptedData)
    

    它通过配置所在服务器上的远程Powershell执行。该帐户是管理员,因此应提供本地计算机密钥。我发现一个错误:

    Value cannot be null. Parameter name: keyName
    

    一个相同的模块提供程序名fragment适用于DPAPI加密的部分。密钥名就在该部分中。我错过了什么?

    更新:当Web代码执行时,它调用 Initialize() 先在提供者上。我已经模拟了初始化调用的参数。它们来自机器。配置。

    $nv = New-Object System.Collections.Specialized.NameValueCollection
    $nv.Add("description", "Uses RsaCryptoServiceProvider to encrypt and decrypt")
    $nv.Add("keyContainerName", "NetFrameworkConfigurationKey")
    $nv.Add("cspProviderName", "")
    $nv.Add("useMachineContainer", "true")
    $nv.Add("useOAEP", "false")
    $Prov.Initialize("RsaProtectedConfigurationProvider", $nv)
    

    现在我得到一个不同的错误:“坏数据”。

    更新2:在该文件上尝试了sicing aspnet_regis,得到了相同的“坏数据”错误。但网站本身似乎已经启动并运行,并且可以感知数据库。可能是连接字符串部分 是 毕竟是被破坏了,而且网站把它带到了别处。

    1 回复  |  直到 8 年前
        1
  •  0
  •   wazz    8 年前

    我不确定是否要通过Powershell来完成,但下面是我通过网页上的代码隐藏手动完成的操作。这里可能有线索。如果没有帮助,我可以删除这个答案。

    protected void btnEncryptConnStrings_Click(object sender, EventArgs e)
    {
        // Open web.config file as a configuration object to get information.
        Configuration objConfigFile = WebConfigurationManager.OpenWebConfiguration(Request.ApplicationPath);
    
        // Work with the <connectionStrings> section.
        ConfigurationSection connectionStrings = objConfigFile.GetSection("connectionStrings");
    
        if(connectionStrings != null)
        {
            // Only encrypt the section if it is not already protected.
            if(!connectionStrings.SectionInformation.IsProtected)
            {
                // Encrypt the <connectionStrings> section using the
                // DataProtectionConfigurationProvider provider (see notes at top of file).
                connectionStrings.SectionInformation.ProtectSection("RsaProtectedConfigurationProvider"); // alt: DataProtectionConfigurationProvider
    
                objConfigFile.Save();
    
                // other stuff.
            }
        }
    }
    
    推荐文章