Solved

External app config and encryption of settings

Posted on 2016-09-30
1
78 Views
Last Modified: 2016-10-17
We have a number of applications and services that need to share an external app config file. The external file contains a configSection with information that we which to encrypt.
Each service and application resides in its own application folder, and that is where the problems begin to escalate.
In the App.config, external files can be referenced with either ‘configSource’ or ‘file’ attribute. ‘configSource’ cannot be used because the external config file does not reside in the app folder or in app sub folders. Threrefore we have to use the ‘file’ attribute.
<customSettings file=”path to setting”/>
The ‘customSettings’ configSection has been defined as followed:
<configSections>
    <section name="customSettings" type="System.Configuration.NameValueFileSectionHandler, System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"/>
  </configSections>
I’m then trying to encrypt the configSection using code like this:
Configuration config = ConfigurationManager.OpenExeConfiguration(ConfigurationUserLevel.None);
ConfigurationSection section = config.GetSection("customSettings");

if (!section.SectionInformation.IsProtected)
{
  section.SectionInformation.ProtectSection("DataProtectionConfigurationProvider");
  config.Save();
}
Because I’m using the file attribute (I suspect). The config section is encrypted in App.config and the external file is not. What gets encrypted in App.config is just <customSettings file=”path to setting”/>. Which is pretty useless.

This means that the Individual applications and services cannot encrypt the external config file.
I then had the idea that I would place a small application residing in the same directory as the external config file. The purpose of this application was to encrypt the external config file by using ‘configSource’ attribute instead. This approach does not work at all. Nothing happens, and nothing is encrypted.

To investigate a little further I placed the ‘customSettings’ in the App.config and encrypted the section successfully. I then copied the encrypted data to the external file to test if encryption could work in the external config file. This works fine with the ‘configSource’ but throws an exception when using the ‘file’ attribute. Exception thrown: Unrecognized attribute 'configProtectionProvider'
Since we must use the ‘file’ attribute in the app.config I now have 2 problems.
1)      Cannot encrypt external file.
2)      If the external file is manually encrypted, I cannot read it using the ‘file’ attribute.
0
Comment
Question by:Thomas Koehrsen
1 Comment
 
LVL 20

Accepted Solution

by:
Daniel Van Der Werken earned 500 total points
ID: 41823596
Sorry. I'm not completely following. It appears you're attempting to store sensitive data in a file and read it programmatically, and you want to use the data within the app.

And the app.config is giving you troubles with this.

And you have multiple applications using the same app.config.

If it were me, I'd jump ship on the app.config usage idea and roll my own process.

1. Create a common file available in a location all applications have access. You can use the appSettings section of the app.config to point to the location of this file.

2. Encrypt the file with a common key stored in the app.config, or use the machine key for that system, or some other means.

3. Use standard C# encryption and decryption methods to encrypt/decrypt the information in the file using standard System.IO and System.Cryptography means.

4. Store the data in some pre-defined format. You can use XML or JSON or even just some format of your own like each line with bars (|) delimiting the info:

server|username|password

Then you can use the string.Split() method to read the expected data and parse it once the data has been decrypted using standard means.

Otherwise, I'm sorry, I don't have the experience or knowledge about the app.config usage to assist. I'm wondering if it might behoove you to move past that attempt as it seems you've run into a number of possible limitations already.
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us here at EE write code. Many of us write exceptional code; just as many of us write exception-prone code. As we all should know, exceptions are a mechanism for handling errors which are typically out of our control. From database errors, t…
Entity Framework is a powerful tool to help you interact with the DataBase but still doesn't help much when we have a Stored Procedure that returns more than one resultset. The solution takes some of out-of-the-box thinking; read on!
In a recent question (https://www.experts-exchange.com/questions/28997919/Pagination-in-Adobe-Acrobat.html) here at Experts Exchange, a member asked how to add page numbers to a PDF file using Adobe Acrobat XI Pro. This short video Micro Tutorial sh…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question