You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET8解密RsaProtectedConfigurationProvider遇平台不支持错误的解决

.NET 8迁移中解密RSA加密的连接字符串配置文件

我将应用的连接字符串定义在单独的配置文件中,迁移至.NET 8时,尝试解密该配置文件出现「平台不支持」错误,请问能否通过C#实现解密?以下是我的配置文件:

<?xml version="1.0" encoding="utf-8"?>
<connectionStrings configProtectionProvider="RsaProtectedConfigurationProvider">
    <EncryptedData Type="http://www.w3.org/2001/04/xmlenc#Element"
        xmlns="http://www.w3.org/2001/04/xmlenc#">
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" />
        <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
            <EncryptedKey xmlns="http://www.w3.org/2001/04/xmlenc#">
                <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" />
                <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
                    <KeyName>Rsa Key</KeyName>
                </KeyInfo>
                <CipherData>
                    <CipherValue>lT+4rnY5uXs2FXfNh4PSZOzbihEyLNOHH2+aQB2mAuElk6NBLFtEKKGr+V0nUDE74w4N1zX00nWUqM2A3u5RiPc3NSxY3qF/Ff5CxMdmTIpmPpyJ1aIfPF4ldCAePQksikahbsMXk5+MREBZ+kzsEsCvoQa/JrjO/1oz/tG9vZZCG3GD/Rsp1PbVX1IKdy2WrEO1cp4YQVLdPmXJM7TkvXabz3mIptLfb2qI/csZ8ZvHHPFDXtd4aM6BBibO5MINAR0eeFPZU1gtkXxv+h+i5szht0O/FlP4nrLfBM/6Wz7Y4QEZJRBKaIicbzizqqjzIG6B4n2Ho6+3ImAf3XLTDw==</CipherValue>
                </CipherData>
            </EncryptedKey>
        </KeyInfo>
        <CipherData>
            <CipherValue>ekEvjGOU3CKUhcqn178SRAn6mcL5Z3OJQqFEbSH4qjvZqDMZmGyS1TiDqCf38aJMxo1gFM3o9N18awCMXmoij/xBVJTvoC6wuLLTK+dGNrj9KUlVpPdErOq+3ZBj80ewYa6ZNp2Z7H7i7ttNt2SJNSA7OoOK8heYURuMHW5yUlfnHwmnZPgxptofLsWyFtdNKwzy/W2+rNMPQ7i4V8oosjw4hvgfzxBK00Eip424RqFxNVo4kV1rNMTEaoLnn0LIhk4G4ZrpdnKdQ2K2bKI99ODRAEpA02oc66sO7wGR+ZfmCEewt8dUoCX8L55GZGISrW2xhZE8WqT7YjWs6g5DiHiZRNR2kh8Mjp+y9AOLuJ1ilLHGpp55R2PxqczMQXxdtvRoeAGC9CqaZex2KsBYGBhTK1tx7DchLrCLeiZZbxtdvL3/NMsYTuM8HP/ZXzKLmk3bp5v1RU6hELyl8uQOsuDZBcMndnwYphOAGpmI6TL/ZoNsMUtGV7RhfUn/7Z/8Ktgc1r8rvOqhC0wdVCzOVclEyhlmjg2yBXefO9lcC9UzKjw5C5Yv6OozT1p9vpI8YaMLfK1aR3U24CjQONgjD+c7gXRRK2mDw+ILeEXkJdQ=</CipherValue>
        </CipherData>
    </EncryptedData>
</connectionStrings>

可以通过C#手动实现解密流程

.NET 8中RsaProtectedConfigurationProvider的跨平台支持有限,导致直接解密报错,你可以手动解析XML加密结构,结合RSA和AES算法完成解密,步骤如下:

前提条件

你需要拥有加密该配置文件时使用的RSA私钥(可以从原机器的证书存储导出,或者从保存的密钥文件加载)。

实现代码

using System;
using System.Security.Cryptography;
using System.Security.Cryptography.Xml;
using System.Xml;
using System.Linq;

public class ConfigDecryptor
{
    public static string DecryptConnectionStrings(string encryptedConfigPath, RSA rsaPrivateKey)
    {
        // 加载加密的配置XML
        XmlDocument xmlDoc = new XmlDocument();
        xmlDoc.PreserveWhitespace = true;
        xmlDoc.Load(encryptedConfigPath);

        // 初始化EncryptedData和EncryptedKey对象
        EncryptedData encryptedData = new EncryptedData();
        encryptedData.LoadXml((XmlElement)xmlDoc.GetElementsByTagName("EncryptedData")[0]);

        EncryptedKey encryptedKey = new EncryptedKey();
        encryptedKey.LoadXml((XmlElement)xmlDoc.GetElementsByTagName("EncryptedKey")[0]);

        // 用RSA私钥解密得到AES密钥
        encryptedKey.DecryptKey(rsaPrivateKey, false);
        byte[] aesKey = encryptedKey.CipherValue;

        // 解析AES密文和IV(IV附加在密文头部)
        byte[] fullCipherBytes = Convert.FromBase64String(encryptedData.CipherData.CipherValue);
        byte[] aesIv = fullCipherBytes.Take(16).ToArray();
        byte[] actualCipherBytes = fullCipherBytes.Skip(16).ToArray();

        // 执行AES解密
        using Aes aesAlg = Aes.Create();
        aesAlg.Key = aesKey;
        aesAlg.IV = aesIv;
        ICryptoTransform decryptor = aesAlg.CreateDecryptor(aesAlg.Key, aesAlg.IV);

        using var msDecrypt = new System.IO.MemoryStream(actualCipherBytes);
        using var csDecrypt = new CryptoStream(msDecrypt, decryptor, CryptoStreamMode.Read);
        using var srDecrypt = new System.IO.StreamReader(csDecrypt);
        
        return srDecrypt.ReadToEnd();
    }

    // 从PEM文件加载RSA私钥
    public static RSA LoadRsaPrivateKeyFromPem(string pemPath)
    {
        string pemContent = System.IO.File.ReadAllText(pemPath);
        pemContent = pemContent.Replace("-----BEGIN RSA PRIVATE KEY-----", "")
                               .Replace("-----END RSA PRIVATE KEY-----", "")
                               .Replace("\r", "")
                               .Replace("\n", "");
        byte[] privateKeyBytes = Convert.FromBase64String(pemContent);
        
        RSA rsa = RSA.Create();
        rsa.ImportPkcs8PrivateKey(privateKeyBytes, out _);
        return rsa;
    }

    // 使用示例
    public static void Main()
    {
        string configFile = "your-encrypted-config.xml";
        string privateKeyFile = "your-rsa-private-key.pem";
        
        using RSA rsa = LoadRsaPrivateKeyFromPem(privateKeyFile);
        string decryptedConfig = DecryptConnectionStrings(configFile, rsa);
        Console.WriteLine(decryptedConfig);
    }
}

关键说明

  1. RSA密钥加载:如果私钥存储在Windows证书管理器中,可以改用X509Certificate2加载,替换LoadRsaPrivateKeyFromPem方法。
  2. IV分离:RsaProtectedConfigurationProvider加密时会将AES的IV附加在密文头部(前16字节),解密前需要先分离。
  3. 算法匹配:代码中使用的RSA-OAEP-MGF1P和AES-256-CBC与配置文件中的加密算法完全对应,确保解密成功。

内容的提问来源于stack exchange,提问作者Jithin Paulson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 17:42:34