Ask a Question related to ASP.NET Security, Design and Development.
-
Dan Amiga #1
DPAPI and config files
Hello. This is about DPAPI and configuration files.
Basically, what I understand is when loading the exe assembly the framework
takes parameters from the config file and loads them.
I want to store THE ENTIRE web.config ( or any other config file ) using
DPAPI.
That is - I want to develop a component which intercept the frameworks
request to the web.config, decrypt the config file stored in the DPAPI
protected storage and give it to the framework for regular execution.
The thing is - I want it to be transparent. I don't want other development
teams to be concered and implement this logic in their applications.
Any idea's ?
Dan Amiga,
Israel.
Dan Amiga Guest
-
Protect Files in Web.Config?
I have a web.config section that only allows certain groups into a subdirectory. Is it possible to specify that only some types of files (example... -
Where are the Xorg config files ?
Hi all, I installed FreeBSD 5.3 along with Xorg 6.7.0-9 and KDE 3.3.0-4. I started KDE by creating an .xinitrc file in my home directory containing... -
The same web.config and global.asax files
Hello, I have to project: one ASN.NET project and another - Web Service in the same solution. I want to use the same web.config and... -
Config files
Hi Group, I have following options for working with the configuration files with the relatively large web application. 1. Configuration... -
What are all those *.config.old files?
Hello, I am not totally positive if you can delete them. You might try to delete them by sending them to the Recycle Bin folder. Try it out the... -
Paul Glavich [MVP - ASP.NET] #2
Re: DPAPI and config files
The configuration application block offers similar functionality but
relegates most of the config info to another file (not the web.config) and
encrypts that.
[url]http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnbda/html/cmab.asp[/url]
--
- Paul Glavich
Microsoft MVP - ASP.NET
"Dan Amiga" <dan.amiga@ness.com> wrote in message
news:eQem$NoiEHA.2448@TK2MSFTNGP12.phx.gbl...framework> Hello. This is about DPAPI and configuration files.
> Basically, what I understand is when loading the exe assembly the> takes parameters from the config file and loads them.
> I want to store THE ENTIRE web.config ( or any other config file ) using
> DPAPI.
>
> That is - I want to develop a component which intercept the frameworks
> request to the web.config, decrypt the config file stored in the DPAPI
> protected storage and give it to the framework for regular execution.
>
> The thing is - I want it to be transparent. I don't want other development
> teams to be concered and implement this logic in their applications.
>
> Any idea's ?
>
> Dan Amiga,
> Israel.
>
>
>
>
>
>
Paul Glavich [MVP - ASP.NET] Guest
-
Dan Amiga #3
Re: DPAPI and config files
I am talking about Framework config files, not only Web.Config, also
Machine.config, etc.
How does this application block handels options that must exists before the
assembly loads such as processmodel / impersonation ?
"Paul Glavich [MVP - ASP.NET]" <glav@aspalliance.com-NOSPAM> wrote in
message news:eNMsN92iEHA.340@TK2MSFTNGP10.phx.gbl...[url]http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnbda/html/[/url]> The configuration application block offers similar functionality but
> relegates most of the config info to another file (not the web.config) and
> encrypts that.
>
>
cmab.aspdevelopment>
> --
> - Paul Glavich
> Microsoft MVP - ASP.NET
>
>
> "Dan Amiga" <dan.amiga@ness.com> wrote in message
> news:eQem$NoiEHA.2448@TK2MSFTNGP12.phx.gbl...> framework> > Hello. This is about DPAPI and configuration files.
> > Basically, what I understand is when loading the exe assembly the> > takes parameters from the config file and loads them.
> > I want to store THE ENTIRE web.config ( or any other config file ) using
> > DPAPI.
> >
> > That is - I want to develop a component which intercept the frameworks
> > request to the web.config, decrypt the config file stored in the DPAPI
> > protected storage and give it to the framework for regular execution.
> >
> > The thing is - I want it to be transparent. I don't want other>> > teams to be concered and implement this logic in their applications.
> >
> > Any idea's ?
> >
> > Dan Amiga,
> > Israel.
> >
> >
> >
> >
> >
> >
>
Dan Amiga Guest
-
Joe Kaplan \(MVP - ADSI\) #4
Re: DPAPI and config files
I don't believe you can do what you want to do as there are no hooks into
the configuration file APIs at the level you need. The best you could do
would be to encrypt specific data or use something like the configuration
application block as previously mentioned.
Joe K.
"Dan Amiga" <dan.amiga@ness.com> wrote in message
news:eg3mdI3iEHA.356@tk2msftngp13.phx.gbl...the> I am talking about Framework config files, not only Web.Config, also
> Machine.config, etc.
> How does this application block handels options that must exists beforeand> assembly loads such as processmodel / impersonation ?
>
>
>
>
> "Paul Glavich [MVP - ASP.NET]" <glav@aspalliance.com-NOSPAM> wrote in
> message news:eNMsN92iEHA.340@TK2MSFTNGP10.phx.gbl...> > The configuration application block offers similar functionality but
> > relegates most of the config info to another file (not the web.config)[url]http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnbda/html/[/url]>> > encrypts that.
> >
> >using> cmab.asp> >
> > --
> > - Paul Glavich
> > Microsoft MVP - ASP.NET
> >
> >
> > "Dan Amiga" <dan.amiga@ness.com> wrote in message
> > news:eQem$NoiEHA.2448@TK2MSFTNGP12.phx.gbl...> > framework> > > Hello. This is about DPAPI and configuration files.
> > > Basically, what I understand is when loading the exe assembly the> > > takes parameters from the config file and loads them.
> > > I want to store THE ENTIRE web.config ( or any other config file )> development> > > DPAPI.
> > >
> > > That is - I want to develop a component which intercept the frameworks
> > > request to the web.config, decrypt the config file stored in the DPAPI
> > > protected storage and give it to the framework for regular execution.
> > >
> > > The thing is - I want it to be transparent. I don't want other>> >> > > teams to be concered and implement this logic in their applications.
> > >
> > > Any idea's ?
> > >
> > > Dan Amiga,
> > > Israel.
> > >
> > >
> > >
> > >
> > >
> > >
> >
>
Joe Kaplan \(MVP - ADSI\) Guest
-
Dan Amiga #5
Re: DPAPI and config files
Thanks,
It's already a progress if you understood what I wanted :)
How can I be sure there are no Hooks into it ?
Where else can I post for info ?
"Joe Kaplan (MVP - ADSI)" <joseph.e.kaplan@removethis.accenture.com> wrote
in message news:eOZ8ot3iEHA.3016@tk2msftngp13.phx.gbl...[url]http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnbda/html/[/url]> I don't believe you can do what you want to do as there are no hooks into
> the configuration file APIs at the level you need. The best you could do
> would be to encrypt specific data or use something like the configuration
> application block as previously mentioned.
>
> Joe K.
>
> "Dan Amiga" <dan.amiga@ness.com> wrote in message
> news:eg3mdI3iEHA.356@tk2msftngp13.phx.gbl...> the> > I am talking about Framework config files, not only Web.Config, also
> > Machine.config, etc.
> > How does this application block handels options that must exists before> and> > assembly loads such as processmodel / impersonation ?
> >
> >
> >
> >
> > "Paul Glavich [MVP - ASP.NET]" <glav@aspalliance.com-NOSPAM> wrote in
> > message news:eNMsN92iEHA.340@TK2MSFTNGP10.phx.gbl...> > > The configuration application block offers similar functionality but
> > > relegates most of the config info to another file (not the web.config)>> >> > > encrypts that.
> > >
> > >frameworks> using> > cmab.asp> > >
> > > --
> > > - Paul Glavich
> > > Microsoft MVP - ASP.NET
> > >
> > >
> > > "Dan Amiga" <dan.amiga@ness.com> wrote in message
> > > news:eQem$NoiEHA.2448@TK2MSFTNGP12.phx.gbl...
> > > > Hello. This is about DPAPI and configuration files.
> > > > Basically, what I understand is when loading the exe assembly the
> > > framework
> > > > takes parameters from the config file and loads them.
> > > > I want to store THE ENTIRE web.config ( or any other config file )> > > > DPAPI.
> > > >
> > > > That is - I want to develop a component which intercept theDPAPI> > > > request to the web.config, decrypt the config file stored in theexecution.> > > > protected storage and give it to the framework for regularapplications.> > development> > > >
> > > > The thing is - I want it to be transparent. I don't want other> > > > teams to be concered and implement this logic in their>> >> > > >
> > > > Any idea's ?
> > > >
> > > > Dan Amiga,
> > > > Israel.
> > > >
> > > >
> > > >
> > > >
> > > >
> > > >
> > >
> > >
> >
>
Dan Amiga Guest



Reply With Quote

