AmCreations.Configuration.EncryptedJson 1.0.2

dotnet add package AmCreations.Configuration.EncryptedJson --version 1.0.2
NuGet\Install-Package AmCreations.Configuration.EncryptedJson -Version 1.0.2
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="AmCreations.Configuration.EncryptedJson" Version="1.0.2" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
paket add AmCreations.Configuration.EncryptedJson --version 1.0.2
#r "nuget: AmCreations.Configuration.EncryptedJson, 1.0.2"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
// Install AmCreations.Configuration.EncryptedJson as a Cake Addin
#addin nuget:?package=AmCreations.Configuration.EncryptedJson&version=1.0.2

// Install AmCreations.Configuration.EncryptedJson as a Cake Tool
#tool nuget:?package=AmCreations.Configuration.EncryptedJson&version=1.0.2

AM-Créations configuration encrypter NuGet downloads

What is AM-Créations configuration encrypter

This tool makes it easy to encrypt and decrypt JSON configuation files. It consists of two parts :

  • A command line utility that lets you encrypt values in your JSON configuration files
  • A library that decrypts them on the fly in your .NET Standard applications

Motivation

Projects often contains sensitive information like database connection strings, API keys or usernames and passwords for external services. This information should never be committed to source control and should be handled in a secure way. Key vaults like those provided by Azure and AWS aren't always available for projects that can't be connected to the internet.

Advantages

  • Lets you encrypt only certain values in your configuation, so the rest of the config is still readable.
  • Access the encrypted values the same way you are used to in your .NET Core applications.
  • Lets you share config files or even check them in in your VCS without the need to remove sensitive information.
  • The configuration file is not fully encrypted, only its string values, so you are aware of which values are overriden and you don't need to have the full unencrypted file to add or change a key.

Installation

You can install the package via the NuGet Package Manager by searching for AmCreations.Configuration.EncryptedJson.

You can also install the package via PowerShell using the following command:

Install-Package AmCreations.Configuration.EncryptedJson

or via the dotnet CLI:

dotnet add package AmCreations.Configuration.EncryptedJson

Getting started

  • To decrypt values for the configuration file you will need a certificate (private and public key), or at least its private key.
  • To encrypt values for the configuration file you will need a certificate (private and public key), or at least its public key.

Certificates can be generated by using openssl. An example certificate is already in the project and the encrypted string in the example appsettings.Encrypted.json file has been encrypted with it.

To generate a certificate you could use the following commands:

openssl genrsa 2048 > private.key
openssl req -new -x509 -nodes -sha1 -days 365 -key private.key > public.cer
openssl pkcs12 -export -in public.cer -inkey private.key -out cert.pfx -passout pass:

Loading the encrypted JSON configuration

To make an encrypted configuration file, just create a JSON file, like any appsettings file, containing only the values you need to encrypt, for example :

{
  "ConnectionStrings": {
    "Main": ""
  }
}

Now you need to encrypt the value used in "ConnectionStrings:Main", you'll need to install locally or globally the conf-encrypt CLI tool, available on NuGet.

To install it globally :

dotnet tool install -g conf-encrypt

And then run it : this will output the encrypted value of "Content To Encode"

conf-encrypt encrypt "/path/to/the/public-key-or-certificate" "Content To Encode"

Then paste the encrypted value in the appsettings file (here next to "Main").

Add the following to your Program.cs file:

using AmCreations.Configuration.EncryptedJson;

The encrypted JSON configuration can be loaded from a file in your Program.cs like this:

Host.CreateDefaultBuilder(args)
    .ConfigureAppConfiguration((hostingContext, config) =>
    {
        config.AddEncryptedJsonFile("appsettings.Encrypted.json", new FilesystemCertificateLoader("/etc/ssl/private/my-app-cert.pfx"));
    })

AddEncryptedJsonFile() also supports the optional and reloadOnChange parameters (like the classical AddJsonFile method).

You can now access your application's settings by injecting IConfiguration or IOptions in your classes, as usual.

Other commands

To decrypt a specific value: this will output the decrypted value of "Content To Decode"

conf-encrypt decrypt "/path/to/the/private-key-or-certificate" "Content To Decode"

Credits

This library is based on the libraries :

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last updated
1.0.2 9,377 11/22/2022
1.0.1 1,753 4/7/2022
1.0.0 400 3/25/2022
1.0.0-alpha3 137 3/25/2022
1.0.0-alpha2 362 1/7/2022
1.0.0-alpha 171 11/19/2021