Velocity Reviews

Velocity Reviews (http://www.velocityreviews.com/forums/index.php)
-   ASP .Net Security (http://www.velocityreviews.com/forums/f62-asp-net-security.html)
-   -   Encrypting .config files (http://www.velocityreviews.com/forums/t770122-encrypting-config-files.html)

MCM 09-16-2009 07:54 PM

Encrypting .config files
 
This article explains how to encrypt sections of web.config:

http://msdn.microsoft.com/en-us/library/zhhddkxy.aspx

In my application I have this line in web.config:

<appSettings configSource="Config\AppSettings.config" />

My question is, how do I encrypt the entire AppSettings.config file?


Jesse Houwing 09-16-2009 08:26 PM

Re: Encrypting .config files
 
* MCM wrote, On 16-9-2009 21:54:
> This article explains how to encrypt sections of web.config:
>
> http://msdn.microsoft.com/en-us/library/zhhddkxy.aspx
>
> In my application I have this line in web.config:
>
> <appSettings configSource="Config\AppSettings.config" />
>
> My question is, how do I encrypt the entire AppSettings.config file?
>


The not so nice answer is, put it in a web.config, encrypt the section
you want, extract it back into the AppSettings.config.

And you might be able to encrypt it through the programming API directly
from your application on first load.

--
Jesse Houwing
jesse.houwing at sogeti.nl

Allen Chen [MSFT] 09-17-2009 02:16 AM

RE: Encrypting .config files
 
Hi,

>My question is, how do I encrypt the entire AppSettings.config file?


Unfortunately it's not supported out of box. Even if you use built-in API
to encrypt it, the value will be extracted from the custom file and added
to web.config.

A straightforward workaround is to encrypt the value data of an appSettings
on your own. Then decrypt it in your code to get the correct value. You can
do this programatically:

http://msdn.microsoft.com/en-us/libr...graphy.rsacryp
toserviceprovider.aspx

Please let me know if it can solve this issue and feel free to ask if you
have additional questions.

Regards,
Allen Chen
Microsoft Online Support

Delighting our customers is our #1 priority. We welcome your comments and
suggestions about how we can improve the support we provide to you. Please
feel free to let my manager know what you think of the level of service
provided. You can send feedback directly to my manager at:
msdnmg@microsoft.com.

==================================================
Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/en-us/subs...#notifications.

Note: MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 2 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions. Issues of this
nature are best handled working with a dedicated Microsoft Support Engineer
by contacting Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/en-us/subs.../aa948874.aspx
==================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


MCM 09-17-2009 05:37 AM

RE: Encrypting .config files
 
That's not the answer I was hoping for, but it is an answer.

My choices seem to be:

1. encrpyt/decrypt data myself

2. get rid of the external files and put it in web.config and use regiis to
encode the sections via the article I posted.

Neither is ideal, but what can ya do? Thanks for the help.


"Allen Chen [MSFT]" wrote:

> Hi,
>
> >My question is, how do I encrypt the entire AppSettings.config file?

>
> Unfortunately it's not supported out of box. Even if you use built-in API
> to encrypt it, the value will be extracted from the custom file and added
> to web.config.
>
> A straightforward workaround is to encrypt the value data of an appSettings
> on your own. Then decrypt it in your code to get the correct value. You can
> do this programatically:
>
> http://msdn.microsoft.com/en-us/libr...graphy.rsacryp
> toserviceprovider.aspx
>
> Please let me know if it can solve this issue and feel free to ask if you
> have additional questions.
>
> Regards,
> Allen Chen
> Microsoft Online Support
>
> Delighting our customers is our #1 priority. We welcome your comments and
> suggestions about how we can improve the support we provide to you. Please
> feel free to let my manager know what you think of the level of service
> provided. You can send feedback directly to my manager at:
> msdnmg@microsoft.com.
>
> ==================================================
> Get notification to my posts through email? Please refer to
> http://msdn.microsoft.com/en-us/subs...#notifications.
>
> Note: MSDN Managed Newsgroup support offering is for non-urgent issues
> where an initial response from the community or a Microsoft Support
> Engineer within 2 business day is acceptable. Please note that each follow
> up response may take approximately 2 business days as the support
> professional working with you may need further investigation to reach the
> most efficient resolution. The offering is not appropriate for situations
> that require urgent, real-time or phone-based interactions. Issues of this
> nature are best handled working with a dedicated Microsoft Support Engineer
> by contacting Microsoft Customer Support Services (CSS) at
> http://msdn.microsoft.com/en-us/subs.../aa948874.aspx
> ==================================================
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
>


Allen Chen [MSFT] 09-17-2009 07:54 AM

RE: Encrypting .config files
 
Hi,

>That's not the answer I was hoping for, but it is an answer.


>My choices seem to be:


>1. encrpyt/decrypt data myself


>2. get rid of the external files and put it in web.config and use regiis

to
>encode the sections via the article I posted.


>Neither is ideal, but what can ya do? Thanks for the help.


Thanks for your reply. Yes I believe they are the only options. This is not
a supported function. If we want to do that we probably have to
encrpt/decrypt ourselves.

Regards,
Allen Chen
Microsoft Online Support

Delighting our customers is our #1 priority. We welcome your comments and
suggestions about how we can improve the support we provide to you. Please
feel free to let my manager know what you think of the level of service
provided. You can send feedback directly to my manager at:
msdnmg@microsoft.com.


Allen Chen [MSFT] 09-21-2009 02:01 AM

RE: Encrypting .config files
 
Hi,

>That's not the answer I was hoping for, but it is an answer.


>My choices seem to be:


>1. encrpyt/decrypt data myself


>2. get rid of the external files and put it in web.config and use regiis

to
>encode the sections via the article I posted.


>Neither is ideal, but what can ya do? Thanks for the help.



Do you have additional questions? If you have, please feel free to ask.


Regards,
Allen Chen
Microsoft Online Support

Delighting our customers is our #1 priority. We welcome your comments and
suggestions about how we can improve the support we provide to you. Please
feel free to let my manager know what you think of the level of service
provided. You can send feedback directly to my manager at:
msdnmg@microsoft.com.


MCM 09-21-2009 02:51 PM

RE: Encrypting .config files
 
Nope. All good here. Thanks.

"Allen Chen [MSFT]" wrote:

> Hi,
>
> >That's not the answer I was hoping for, but it is an answer.

>
> >My choices seem to be:

>
> >1. encrpyt/decrypt data myself

>
> >2. get rid of the external files and put it in web.config and use regiis

> to
> >encode the sections via the article I posted.

>
> >Neither is ideal, but what can ya do? Thanks for the help.

>
>
> Do you have additional questions? If you have, please feel free to ask.
>
>
> Regards,
> Allen Chen
> Microsoft Online Support
>
> Delighting our customers is our #1 priority. We welcome your comments and
> suggestions about how we can improve the support we provide to you. Please
> feel free to let my manager know what you think of the level of service
> provided. You can send feedback directly to my manager at:
> msdnmg@microsoft.com.
>
>



All times are GMT. The time now is 09:32 AM.

Powered by vBulletin®. Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO ©2010, Crawlability, Inc.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57