基于Puppet管理多服务器IIS:非共享配置下各类密钥作用咨询
Great question—managing IIS keys across a server farm without relying on IIS Shared Configuration is totally feasible with Puppet, and understanding exactly what each key does is key to keeping user auth consistent when they hop between servers. Let’s break down each key category, their core roles, and how you can sync them reliably with Puppet.
These are the most critical keys for cross-server user authentication consistency. Machine Keys handle three main tasks:
- Encrypting and decrypting Forms Authentication tickets (so a user’s auth cookie works seamlessly across all servers)
- Validating ASP.NET view state to prevent tampering and ensure integrity
- Encrypting sensitive cookie data that’s passed between the client and server
If these keys don’t match across your servers, users will hit "invalid ticket" errors or get logged out abruptly when switching between web servers—exactly the issue you’re trying to avoid.
In Puppet, you can manage these via the registry_value resource. They’re stored in the registry under HKLM\SOFTWARE\Microsoft\ASP.NET\<version>\MachineKey (replace <version> with your ASP.NET runtime version, like v4.0.30319 for .NET 4.x). You’ll need to set both validationKey and decryptionKey to identical hexadecimal strings on all servers.
WAS is the backend service that manages application pools and process lifecycle for IIS. Its keys are used to encrypt sensitive configuration data like:
- Application pool service account passwords
- Encrypted settings in
applicationHost.configrelated to process management and resource allocation
If WAS Keys differ across servers, any synced application pool configurations with encrypted passwords will fail to decrypt, leading to application pool startup errors and broken apps.
These keys live in HKLM\SYSTEM\CurrentControlSet\Services\WAS\Parameters\Keys as binary values (WASKey and WASIV). In Puppet, you’ll use the binary type for these registry values to ensure the raw byte data is synced correctly across all servers.
These keys are used by IIS itself to encrypt sensitive data stored in its core configuration files (like applicationHost.config and web.config), such as:
- Encrypted database connection strings
- Sensitive IIS module settings that shouldn’t be stored in plaintext
Mismatched keys here mean encrypted config values from one server won’t be readable on another, breaking applications that rely on those settings.
You’ll find these in HKLM\SOFTWARE\Microsoft\InetStp\Configuration\Keys as binary values (EncryptionKey and EncryptionIV). Again, use Puppet’s registry_value resource with the binary type to sync these across your farm.
Puppet Implementation Example
Here’s a practical snippet to show how you’d define these resources in Puppet:
# Sync ASP.NET Machine Keys (adjust version to match your runtime) registry_value { 'HKLM\SOFTWARE\Microsoft\ASP.NET\v4.0.30319\MachineKey\validationKey': ensure => present, type => string, data => 'F9C5D8A7B6E4C3B2A1F0E9D8C7B6A5F4E3D2C1B0A9F8E7D6C5B4A3F2E1D0C9B8', } registry_value { 'HKLM\SOFTWARE\Microsoft\ASP.NET\v4.0.30319\MachineKey\decryptionKey': ensure => present, type => string, data => 'A1B2C3D4E5F6A7B8C9D0E1F2A3B4C5D6', } # Sync WAS Keys (binary values) registry_value { 'HKLM\SYSTEM\CurrentControlSet\Services\WAS\Parameters\Keys\WASKey': ensure => present, type => binary, data => binary('0x123456789ABCDEF0123456789ABCDEF0'), } registry_value { 'HKLM\SYSTEM\CurrentControlSet\Services\WAS\Parameters\Keys\WASIV': ensure => present, type => binary, data => binary('0xABCDEF1234567890'), } # Sync IIS Configuration Keys registry_value { 'HKLM\SOFTWARE\Microsoft\InetStp\Configuration\Keys\EncryptionKey': ensure => present, type => binary, data => binary('0x9876543210FEDCBA9876543210FEDCBA'), } registry_value { 'HKLM\SOFTWARE\Microsoft\InetStp\Configuration\Keys\EncryptionIV': ensure => present, type => binary, data => binary('0xDCBAFEDC12345678'), } # Restart IIS/WAS when keys change to apply updates exec { 'restart-iis-was': command => 'iisreset /restart', path => ['C:\Windows\System32'], refreshonly => true, subscribe => [ Registry_value['HKLM\SOFTWARE\Microsoft\ASP.NET\v4.0.30319\MachineKey\validationKey'], Registry_value['HKLM\SYSTEM\CurrentControlSet\Services\WAS\Parameters\Keys\WASKey'] ], }
Quick Tips
- Generate secure keys using official tools: Use
aspnet_regiis -gkto create Machine Keys, and export the binary WAS/IIS keys from a trusted baseline server to use in Puppet. - Ensure your Puppet agent runs with admin privileges to modify these restricted registry paths.
- Always test key syncs in a staging environment first to avoid unexpected production outages.
内容的提问来源于stack exchange,提问作者Kyle Brandt

