.NET8解密RsaProtectedConfigurationProvider遇平台不支持错误的解决
.NET 8迁移中解密RSA加密的连接字符串配置文件
我将应用的连接字符串定义在单独的配置文件中,迁移至.NET 8时,尝试解密该配置文件出现「平台不支持」错误,请问能否通过C#实现解密?以下是我的配置文件:
<?xml version="1.0" encoding="utf-8"?> <connectionStrings configProtectionProvider="RsaProtectedConfigurationProvider"> <EncryptedData Type="http://www.w3.org/2001/04/xmlenc#Element" xmlns="http://www.w3.org/2001/04/xmlenc#"> <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" /> <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#"> <EncryptedKey xmlns="http://www.w3.org/2001/04/xmlenc#"> <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" /> <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#"> <KeyName>Rsa Key</KeyName> </KeyInfo> <CipherData> <CipherValue>lT+4rnY5uXs2FXfNh4PSZOzbihEyLNOHH2+aQB2mAuElk6NBLFtEKKGr+V0nUDE74w4N1zX00nWUqM2A3u5RiPc3NSxY3qF/Ff5CxMdmTIpmPpyJ1aIfPF4ldCAePQksikahbsMXk5+MREBZ+kzsEsCvoQa/JrjO/1oz/tG9vZZCG3GD/Rsp1PbVX1IKdy2WrEO1cp4YQVLdPmXJM7TkvXabz3mIptLfb2qI/csZ8ZvHHPFDXtd4aM6BBibO5MINAR0eeFPZU1gtkXxv+h+i5szht0O/FlP4nrLfBM/6Wz7Y4QEZJRBKaIicbzizqqjzIG6B4n2Ho6+3ImAf3XLTDw==</CipherValue> </CipherData> </EncryptedKey> </KeyInfo> <CipherData> <CipherValue>ekEvjGOU3CKUhcqn178SRAn6mcL5Z3OJQqFEbSH4qjvZqDMZmGyS1TiDqCf38aJMxo1gFM3o9N18awCMXmoij/xBVJTvoC6wuLLTK+dGNrj9KUlVpPdErOq+3ZBj80ewYa6ZNp2Z7H7i7ttNt2SJNSA7OoOK8heYURuMHW5yUlfnHwmnZPgxptofLsWyFtdNKwzy/W2+rNMPQ7i4V8oosjw4hvgfzxBK00Eip424RqFxNVo4kV1rNMTEaoLnn0LIhk4G4ZrpdnKdQ2K2bKI99ODRAEpA02oc66sO7wGR+ZfmCEewt8dUoCX8L55GZGISrW2xhZE8WqT7YjWs6g5DiHiZRNR2kh8Mjp+y9AOLuJ1ilLHGpp55R2PxqczMQXxdtvRoeAGC9CqaZex2KsBYGBhTK1tx7DchLrCLeiZZbxtdvL3/NMsYTuM8HP/ZXzKLmk3bp5v1RU6hELyl8uQOsuDZBcMndnwYphOAGpmI6TL/ZoNsMUtGV7RhfUn/7Z/8Ktgc1r8rvOqhC0wdVCzOVclEyhlmjg2yBXefO9lcC9UzKjw5C5Yv6OozT1p9vpI8YaMLfK1aR3U24CjQONgjD+c7gXRRK2mDw+ILeEXkJdQ=</CipherValue> </CipherData> </EncryptedData> </connectionStrings>
可以通过C#手动实现解密流程
.NET 8中RsaProtectedConfigurationProvider的跨平台支持有限,导致直接解密报错,你可以手动解析XML加密结构,结合RSA和AES算法完成解密,步骤如下:
前提条件
你需要拥有加密该配置文件时使用的RSA私钥(可以从原机器的证书存储导出,或者从保存的密钥文件加载)。
实现代码
using System; using System.Security.Cryptography; using System.Security.Cryptography.Xml; using System.Xml; using System.Linq; public class ConfigDecryptor { public static string DecryptConnectionStrings(string encryptedConfigPath, RSA rsaPrivateKey) { // 加载加密的配置XML XmlDocument xmlDoc = new XmlDocument(); xmlDoc.PreserveWhitespace = true; xmlDoc.Load(encryptedConfigPath); // 初始化EncryptedData和EncryptedKey对象 EncryptedData encryptedData = new EncryptedData(); encryptedData.LoadXml((XmlElement)xmlDoc.GetElementsByTagName("EncryptedData")[0]); EncryptedKey encryptedKey = new EncryptedKey(); encryptedKey.LoadXml((XmlElement)xmlDoc.GetElementsByTagName("EncryptedKey")[0]); // 用RSA私钥解密得到AES密钥 encryptedKey.DecryptKey(rsaPrivateKey, false); byte[] aesKey = encryptedKey.CipherValue; // 解析AES密文和IV(IV附加在密文头部) byte[] fullCipherBytes = Convert.FromBase64String(encryptedData.CipherData.CipherValue); byte[] aesIv = fullCipherBytes.Take(16).ToArray(); byte[] actualCipherBytes = fullCipherBytes.Skip(16).ToArray(); // 执行AES解密 using Aes aesAlg = Aes.Create(); aesAlg.Key = aesKey; aesAlg.IV = aesIv; ICryptoTransform decryptor = aesAlg.CreateDecryptor(aesAlg.Key, aesAlg.IV); using var msDecrypt = new System.IO.MemoryStream(actualCipherBytes); using var csDecrypt = new CryptoStream(msDecrypt, decryptor, CryptoStreamMode.Read); using var srDecrypt = new System.IO.StreamReader(csDecrypt); return srDecrypt.ReadToEnd(); } // 从PEM文件加载RSA私钥 public static RSA LoadRsaPrivateKeyFromPem(string pemPath) { string pemContent = System.IO.File.ReadAllText(pemPath); pemContent = pemContent.Replace("-----BEGIN RSA PRIVATE KEY-----", "") .Replace("-----END RSA PRIVATE KEY-----", "") .Replace("\r", "") .Replace("\n", ""); byte[] privateKeyBytes = Convert.FromBase64String(pemContent); RSA rsa = RSA.Create(); rsa.ImportPkcs8PrivateKey(privateKeyBytes, out _); return rsa; } // 使用示例 public static void Main() { string configFile = "your-encrypted-config.xml"; string privateKeyFile = "your-rsa-private-key.pem"; using RSA rsa = LoadRsaPrivateKeyFromPem(privateKeyFile); string decryptedConfig = DecryptConnectionStrings(configFile, rsa); Console.WriteLine(decryptedConfig); } }
关键说明
- RSA密钥加载:如果私钥存储在Windows证书管理器中,可以改用
X509Certificate2加载,替换LoadRsaPrivateKeyFromPem方法。 - IV分离:
RsaProtectedConfigurationProvider加密时会将AES的IV附加在密文头部(前16字节),解密前需要先分离。 - 算法匹配:代码中使用的
RSA-OAEP-MGF1P和AES-256-CBC与配置文件中的加密算法完全对应,确保解密成功。
内容的提问来源于stack exchange,提问作者Jithin Paulson
相关产品推荐
相关产品推荐

