External app config and encryption of settings

Posted on 2016-09-30
Last Modified: 2016-10-17
We have a number of applications and services that need to share an external app config file. The external file contains a configSection with information that we which to encrypt.
Each service and application resides in its own application folder, and that is where the problems begin to escalate.
In the App.config, external files can be referenced with either ‘configSource’ or ‘file’ attribute. ‘configSource’ cannot be used because the external config file does not reside in the app folder or in app sub folders. Threrefore we have to use the ‘file’ attribute.
<customSettings file=”path to setting”/>
The ‘customSettings’ configSection has been defined as followed:
    <section name="customSettings" type="System.Configuration.NameValueFileSectionHandler, System, Version=, Culture=neutral, PublicKeyToken=b77a5c561934e089"/>
I’m then trying to encrypt the configSection using code like this:
Configuration config = ConfigurationManager.OpenExeConfiguration(ConfigurationUserLevel.None);
ConfigurationSection section = config.GetSection("customSettings");

if (!section.SectionInformation.IsProtected)
Because I’m using the file attribute (I suspect). The config section is encrypted in App.config and the external file is not. What gets encrypted in App.config is just <customSettings file=”path to setting”/>. Which is pretty useless.

This means that the Individual applications and services cannot encrypt the external config file.
I then had the idea that I would place a small application residing in the same directory as the external config file. The purpose of this application was to encrypt the external config file by using ‘configSource’ attribute instead. This approach does not work at all. Nothing happens, and nothing is encrypted.

To investigate a little further I placed the ‘customSettings’ in the App.config and encrypted the section successfully. I then copied the encrypted data to the external file to test if encryption could work in the external config file. This works fine with the ‘configSource’ but throws an exception when using the ‘file’ attribute. Exception thrown: Unrecognized attribute 'configProtectionProvider'
Since we must use the ‘file’ attribute in the app.config I now have 2 problems.
1)      Cannot encrypt external file.
2)      If the external file is manually encrypted, I cannot read it using the ‘file’ attribute.
Question by:Thomas Koehrsen
1 Comment
LVL 20

Accepted Solution

Daniel Van Der Werken earned 500 total points
ID: 41823596
Sorry. I'm not completely following. It appears you're attempting to store sensitive data in a file and read it programmatically, and you want to use the data within the app.

And the app.config is giving you troubles with this.

And you have multiple applications using the same app.config.

If it were me, I'd jump ship on the app.config usage idea and roll my own process.

1. Create a common file available in a location all applications have access. You can use the appSettings section of the app.config to point to the location of this file.

2. Encrypt the file with a common key stored in the app.config, or use the machine key for that system, or some other means.

3. Use standard C# encryption and decryption methods to encrypt/decrypt the information in the file using standard System.IO and System.Cryptography means.

4. Store the data in some pre-defined format. You can use XML or JSON or even just some format of your own like each line with bars (|) delimiting the info:


Then you can use the string.Split() method to read the expected data and parse it once the data has been decrypted using standard means.

Otherwise, I'm sorry, I don't have the experience or knowledge about the app.config usage to assist. I'm wondering if it might behoove you to move past that attempt as it seems you've run into a number of possible limitations already.

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Calculating holidays and working days is a function that is often needed yet it is not one found within the Framework. This article presents one approach to building a working-day calculator for use in .NET.
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question