Ang*_*ker 5 .net c# .net-core asp.net-core
我有点不清楚数据保护密钥在网络场环境中如何工作。我没有所有服务器都可以使用的通用位置(并且不想处理权限)。因此我想生成一个密钥并将其与网络应用程序一起分发。
我正在执行以下操作,但不确定这是否正确。因此,我在我的开发电脑上本地生成一个密钥文件:
var specialFolder = Environment.SpecialFolder.CommonApplicationData;
var appDataPath = Path.Combine(
Environment.GetFolderPath(specialFolder),
"company",
"product"
);
services.AddDataProtection().PersistKeysToFileSystem(new DirectoryInfo(appDataPath));
Run Code Online (Sandbox Code Playgroud)
这将创建一个key-some-guid.xml文件。然后我使用我的 Web 应用程序分发此文件。
现在,当我运行 Web 应用程序时,在 Startup.Configure 服务中,将此文件复制到位置appDataPath(上面定义的)并调用services.AddDataProtection().PersistKeysToFileSystem(new DirectoryInfo(appDataPath));.
那行得通吗?或者我从根本上错过了一些东西?
回答我自己的问题。以下内容似乎适用于整个网络场。从 Startup.ConfigureServices 调用以下方法。它假设密钥(在开发计算机上生成)位于项目根目录下的 Keys 文件夹中。
public Startup(IHostingEnvironment env)
{
/* skipping boilerplate setup code */
Environment = env;
}
private IHostingEnvironment Environment { get; set; }
private void ConfigureDataProtection(IServiceCollection services) {
// get the file from the Keys directory
string keysFile = string.Empty;
string keysPath = Path.Combine(Environment.ContentRootPath, "Keys");
if (!Directory.Exists(keysPath)) {
Log.Add($"Keys directory {keysPath} doesn't exist");
return;
}
string[] files = Directory.GetFiles(keysPath);
if (files.Length == 0) {
LLog.Add($"No keys found in directory {keysPath}");
return;
} else {
keysFile = files[0];
if (files.Length >= 2) {
LLog.Add($"Warning: More than 1 key found in directory {keysPath}. Using first one.");
}
}
// find and optionally create the path for the key storage
var appDataPath = Path.Combine(
System.Environment.GetFolderPath(System.Environment.SpecialFolder.CommonApplicationData),
"companyName",
"productName"
);
if (!Directory.Exists(appDataPath)) {
try {
Directory.CreateDirectory(appDataPath);
} catch (Exception ex) {
Log.Add($"Error creating key storage folder at {appDataPath}. Error: {ex.Message}");
return;
}
}
// delete any keys from the storage directory
try {
foreach (var file in new DirectoryInfo(appDataPath).GetFiles()) file.Delete();
} catch (Exception ex) {
Log.Add($"Error deleting keys from {appDataPath}. Error: {ex.Message}");
return;
}
try {
string targetPath = Path.Combine(appDataPath, new FileInfo(keysFile).Name);
File.Copy(keysFile, targetPath, true);
} catch (Exception ex) {
Log.Add($"Error copying key file {keysFile} to {appDataPath}. Error: {ex.Message}");
return;
}
// everything is in place
services.AddDataProtection()
.PersistKeysToFileSystem(new DirectoryInfo(appDataPath))
.DisableAutomaticKeyGeneration();
}
Run Code Online (Sandbox Code Playgroud)
| 归档时间: |
|
| 查看次数: |
1594 次 |
| 最近记录: |