How to secure ConnectionString and/or AppSettings in asp.net core (on-prem)

Viewed 3945

First off, I know we dont have ConnectionStrings and AppSettings per se in .Net core, but in my case I want to encrypt a ConnectionString and maybe some other application configurations stored in my appsettings.json (or other settings file).

I know this has been discussed alot all over the internet, but no one seems to have a legit answer.. So suggestions that has beeen thrown out there are:

  • Using EnvironmentConfigurationBuilder, however... that doesnt really solve the issue, since we just moved our plain text configurations from appsettings.json to the Env-variables)
  • Create a custom ConfigurationProvider that encrypts and decrypts the appsettings.json (or selective parts of it), however.. that doesnt solve the issue either, since we need to store our key(s) for the decryption somewhere accessible by our application, and even if we did store the key as a "hard-coded" string in our application, a "hacker" could simply just de-compile it.

Someone also mentioned that even if you do encrypt the appsettings.json, a "hacker" could always just do a memory dump and find the decrypted version of the data.. Im no expert on that field, so Im not sure how likely or how complicated such as thing would be.

Azure Key Vault has also been mentioned a few times, however.. in my case and in alot of cases when working with authorities, this is not an option since cloud-services are not allowed.

I might be overthinking this, since if an attacker/hacker actually has managed to get into our server, then we might have bigger issues.. but what would be the way to deal with this issue? Do you simply dont care and leave it all as "plain text"? Or should you take some sort if action and encrypt or obscure the secrets?

1 Answers

You don't need to encrypt connection strings from your config file because the best way is still to NOT store this information in your config files but as environment variables on your server.

In your appsettings.json file just store your local development connection string. For other environments, on the server it is deployed set an environment variable with __ (double underscore) for each child node in you config file.

You can read how this works on this page

If you have a config file as follow

{ 
   "ConnectionStrings": { 
     "default": "Server=192.168.5.1; Database=DbContextFactorySample3; user id=database-user; password=Pa$$word;" 
   } 
}

On a Windows server you would set the value like this

set "ConnectionStrings__default=Server=the-production-database-server; Database=DbContextFactorySample2; Trusted_Connection=True;"

I don't know how is your deployment flow and tools you're using but it's worth digging into it and find how you can use of this feature.

For example if you're deploying on Kubernetes you could use Helm to set your secret values.

At my company on TFS we create a Release pipeline and make use of the variables section to set the secret values. These values will then be used when the code is deployed on Kubernetes. Variables in Release pipelines in TFS can be hidden like passwords and no developer can see the production values. Only administrators can

Related