详解C#App.config和Web.config加密

2019-12-30 19:45:55刘景俊

打开cmd,进入vs安装目录C:WindowsMicrosoft.NETFramework64v4.0.30319


cd C:WindowsMicrosoft.NETFramework64v4.0.30319

如果是Web.config就直接加密,是App.config就先改为Web.config才可以进行加密


aspnet_regiis -pef "节点" "项目路径"

例如:

需要加密的App.config数据库连接字符串为


<connectionStrings>
 <add name="connStr" connectionString="Data Source=.;Initial Catalog=testDB;User ID=sa;Password=123456" />
 </connectionStrings>

加密命令为


aspnet_regiis -pef "connectionStrings" "Web.config所在目录"

如加密失败

解决方案:

创建一个可导出的rsa密钥容器,命名为Key


aspnet_regiis -pc "Key" -exp 

将Web.cofig/App.config的configuration增加属性值xmlns,即改为


<configuration xmlns="http://www.easck.com/.NetConfiguration/v2.0">

将数据库连接字符串改为以下:


 <configProtectedData> 
  <providers> 
   <clear /> 
   <add name="KeyProvider" type="System.Configuration.RsaProtectedConfigurationProvider, System.Configuration, Version=2.0.0.0,Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=MSIL" keyContainerName="Key" useMachineContainer="true"/> 
  </providers> 
</configProtectedData> 
<connectionStrings> 
  <add name="connStr" connectionString="Data Source=.;Initial Catalog=testDB;User ID=sa;Password=123456;" providerName="System.Data.SqlClient" /> 
</connectionStrings>

开始对配置文件进行加密


aspnet_regiis -pef "connectionStrings" "Web.config所在目录" -prov "KeyProvider"

注意:vs会提示是否修改,选择全是

解密配置文件


aspnet_regiis -pdf "connectionStrings" "Web.config所在目录" 

如果是App.config改成的Web.config,加密成功之后再改为App.config,并删除configuration的属性xmlns值

未加密的Web.config/App.config文件内容:


<?xml version="1.0" encoding="utf-8" ?>
<configuration>
  <startup> 
    <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2" />
  </startup>
 <connectionStrings>
  <add name="connStr" connectionString="Data Source=.;Initial Catalog=testDB;User ID=sa;Password=123456" />
 </connectionStrings>
</configuration>