nocscienceat.EncryptedConfigurationProvider
2.1.1
dotnet add package nocscienceat.EncryptedConfigurationProvider --version 2.1.1
NuGet\Install-Package nocscienceat.EncryptedConfigurationProvider -Version 2.1.1
<PackageReference Include="nocscienceat.EncryptedConfigurationProvider" Version="2.1.1" />
<PackageVersion Include="nocscienceat.EncryptedConfigurationProvider" Version="2.1.1" />
<PackageReference Include="nocscienceat.EncryptedConfigurationProvider" />
paket add nocscienceat.EncryptedConfigurationProvider --version 2.1.1
#r "nuget: nocscienceat.EncryptedConfigurationProvider, 2.1.1"
#:package nocscienceat.EncryptedConfigurationProvider@2.1.1
#addin nuget:?package=nocscienceat.EncryptedConfigurationProvider&version=2.1.1
#tool nuget:?package=nocscienceat.EncryptedConfigurationProvider&version=2.1.1
nocscienceat.EncryptedConfigurationProvider
A .NET configuration provider that loads encrypted configuration data from files using AES-256-GCM encryption with RSA key wrapping via X.509 certificates.
Overview
This library extends Microsoft.Extensions.Configuration to support encrypted configuration files (.encVault).
Configuration values are encrypted using AES-256-GCM and the encryption key is protected using RSA with an X.509 certificate from the Windows Certificate Store (LocalMachine or CurrentUser.)
For this purpose, it utilizes the nocscienceat.Aes256GcmRsaCryptoService library for encryption and decryption operations, but with the same Certificate for Encryption and Signing (AES Key, nonce and tag are signed during Encryption and verified during Decryption)
Features
- Secure Configuration Storage: Encrypts sensitive configuration data at rest
- Certificate-Based Encryption: Uses X.509 certificates for RSA key wrapping
- Seamless Integration: Works with standard .NET configuration system
- Certificate Location: Supports both CurrentUser and LocalMachine certificate stores, Certificate is referenced by its thumbprint
Installation
Add the package to your project: nocscienceat.EncryptedConfigurationProvider
Usage
Create an encrypted configuration file
Update: You can use the https://github.com/klemensurban/nocscienceat.JsonEncryptor Command Line Utility to create encrypted configuration files
Code snippet to create an encrypted configuration file: Use the
nocscienceat.Aes256GcmRsaCryptoServiceNuGet package to encrypt your JSON configuration - see library description for usage details - and encode it with base64.
The encrypted file must be named<certificateThumbprint>.encVaultand placed in a base directory defined in e.g. appsettings.json or other methods of configuration. The ServiceAccount running the application must have access to the certificate and its private key in the specified certificate store.
using nocscienceat.Aes256GcmRsaCryptoService;
....
....
byte[] plainText = Encoding.UTF8.GetBytes(jsonString);
ReadOnlySpan<byte> plainTextSpan = plainText.AsSpan();
if (string.IsNullOrWhiteSpace(certificateThumbprint) ||
certificateThumbprint.Length is not (40 or 64) ||
!certificateThumbprint.All(Uri.IsHexDigit))
{
throw new ArgumentException("Certificate thumbprint must be a 40 or 64 character hexadecimal string.");
}
byte[] cipherText = CryptoService.Encrypt(plainTextSpan, certificateThumbprint, certificateThumbprint, true); // true .. LocalMachine Certificate Store
string base64CipherText = Convert.ToBase64String(cipherText, Base64FormattingOptions.InsertLineBreaks);
// Output the Base64-encoded ciphertext to a file with name <CertificateThumbprint>.encVault in the current directory
string outputFileName = $"{certificateThumbprint}.encVault";
File.WriteAllText(outputFileName, base64CipherText);
Configure your host to use the provider
Add the NuGet package
nocscienceat.EncryptedConfigurationProviderto your projectAdd in the using block of program.cs:
using nocscienceat.EncryptedConfigurationProvider;Add the provider in your application's configuration setup ..
IConfigurationBuilder.AddEncryptedConfigurationProvider(optional: false);e.g. in a .NET 6+ WebApplication:
WebApplicationBuilder builder = WebApplication.CreateBuilder(args);
builder.Configuration.AddEncryptedConfigurationProvider(optional: false);
ConfigurationManager configuration = builder.Configuration;
- Add the following section to your
appsettings.json:
"nocscienceat.EncryptedConfigurationProvider": {
"BaseDirectory": "Directory where to find <certificateThumbprint>.encVault",
"CertificateThumbprint": "<certificateThumbprint>",
"LocalMachine": true/false
}
- Access the configuration values as usual e.g
public class Worker
{
private readonly IConfiguration _configuration;
public Worker(IConfiguration configuration, ILogger<Worker> logger)
{
_configuration = configuration;
}
public async returntype SomeWork(parameters)
{
AccountInfo? accountinfo = _configuration.GetSection("LdapAccountInfo").Get<AccountInfo>(); // Access decrypted configuration values as encrypted in <certificateThumbprint>.encVault
// do some work
}
}
Notes
- The certificate must be available in the specified certificate store. The ServiceAccount running the application must have access to the certificate and its private key in the specified certificate store.
- The provider will throw if the encrypted file is missing and
optionalis set tofalse.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Extensions.Configuration.Binder (>= 10.0.0 && < 11.0.0)
- Microsoft.Extensions.Configuration.Json (>= 10.0.0 && < 11.0.0)
- nocscienceat.Aes256GcmRsaCryptoService (>= 2.1.0)
-
net8.0
- Microsoft.Extensions.Configuration.Binder (>= 8.0.2 && < 9.0.0)
- Microsoft.Extensions.Configuration.Json (>= 8.0.1 && < 9.0.0)
- nocscienceat.Aes256GcmRsaCryptoService (>= 2.1.0)
-
net9.0
- Microsoft.Extensions.Configuration.Binder (>= 9.0.11 && < 10.0.0)
- Microsoft.Extensions.Configuration.Json (>= 9.0.11 && < 10.0.0)
- nocscienceat.Aes256GcmRsaCryptoService (>= 2.1.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.1.1 | 701 | 12/3/2025 |