Wednesday, April 4, 2012

Use RSA in C#

RSA is one of the asymmetric encryption algorithm. There are two keys, public and private, in this algorithm. Detail is reference to RSA. In general, the public key is saved as a .crt file and the private key is saved as a .pfx file with password.

To use these two keys, you need to load them by an X509Certificate2 object.

using System.Security.Cryptography.X509Certificates;

RSACryptoServiceProvider LoadPublicKeyFromFile(
string publicKeyFile)
{
///load public key from .crt
X509Certificate2 pubKey =
new X509Certificate2(publicKeyFile);

return (RSACryptoServiceProvider)pubKey.PublicKey.Key;
}

RSACryptoServiceProvider LoadPrivateKeyFromFile(
string privateKeyFile, string password)
{
///load private key from .pfx with password
X509Certificate2 priKey =
new X509Certificate2(privateKeyFile, password);

return (RSACryptoServiceProvider)priKey.PrivateKey;
}

Sometimes, you might need to save the keys into a database. RSACryptoServiceProvider provide simple functions to let you convert it to/from an xml string.

string ToXmlString(RSACryptoServiceProvider key)
{
/// true for private key, false for public key
return key.ToXmlString(true);
}

RSACryptoServiceProvider FromXmlString(string xmlString)
{
RSACryptoServiceProvider key =
new RSACryptoServiceProvider();
key.FromXmlString(xmlString);

return key;
}

Remember, you can get a RSACryptoServiceProvider object whenever you load a public or a private key. Sometimes you might need to use the private key to encrypt a message as a signature and others can use the public key to decrypt and verify if the signature is right from you. And sometimes you might need to use the public key to encrypt a message so that only the private key owner can decrypt it. The usages for both these keys are the same.

byte[] Encrypt(byte[] rawData, RSACryptoServiceProvider key)
{
/// encrypt without OAEP, but PKCS#1 v1.5 padding
return key.Encrypt(rawData, false);
}

byte[] Decrypt(byte[] encData, RSACryptoServiceProvider key)
{
/// decrypt without OAEP, but PKCS#1 v1.5 padding
return key.Decrypt(rawData, false);
}

You can use either padding algorithm, but remember to use the same algorithm in both encryption and decryption. Besides, since the sources for both encryption and decryption are byte arrays. You might need to use Convert.FromBase64String and Encoding.UTF8.GetString to convert strings to/from byte arrays.

--
Reference
RSACryptoServiceProvider Class
Optimal asymmetric encryption padding

Thursday, March 1, 2012

High Availability(HA) of Sql Server Reporting Service(SSRS)

MS SQL Server provide Reporting Service (SSRS) which help customers easily generate database status report like login user list or frequency of some event. As long as there are corresponding records in database, customers can schedule report processing or do it on demand by querying.

But when providing such service, providers need to cover this part when planning high availability (HA) on their system. HA of SSRS can be broken down to three parts: service, RS database (RSDB), and main database.

For the service part, you only need to deploy more servers. For the main database, as all database HA, you can apply cluster or mirroring on it. Since you can set failover partner in the connection string of RS datasource, RS will connect to the backup database server when failover without downtime.

The most difficult part is the HA of RS database. Since you can only set one database in RS server, at least not support until 2008, as reference in ReportServer (TempDB) Mirror capability, the setting won't switch to backup database server when failover.

In such situation, you can separate RS databases which means each RS has its own RSDB. When any one of the RS+RSDB failover, others will still work fine. But since there is no sync in the RSDBs, so you need to import the templates and datasource to each RSDB. At the same time, you will hardly query the report history since they will be recorded in different RSDBs.

The second choose is pure mirroring, set all RS to the same RSDB, as reference to How to: Configure a Report Server Scale-Out Deployment (Reporting Services Configuration). By this way, you need to manually set all RS to the backup RSDB when failover. Still, you can use rsconfig.exe to set RSDB by SQL server agent service, as reference to Reporting Services Disaster Recovery, but you may need to save your credential in the script which might not be accessible in most company policies.

The third way, which is also the suggestion in MS official site, is using cluster in RSDB. But you can't install RS on database cluster, so you need more servers to provide HA. Detail can be reference to Planning a Deployment Topology.

--
Reference
SQL Server Reporting Services Disaster Recovery Case Study
How to: Configure SharePoint Integration on Multiple Servers

Tuesday, January 31, 2012

Expand Disk in Virtaul Machine

One of the greatest advantage to use virtual machine is the flexibility of hardware. Under physical hardware constrain, expanding hardware in a virtual machine is quite simple. For CPU and memory, the setting is automatically complete by Windows. So all we need to do is turn off virtual machine, setting, and turn on it.

To expand volume size, we need to expand disk in virtual machine settings.

And use embedded program "diskpart" to extend it.

C:\Documents and Settings\Administrator>diskpart

Microsoft DiskPart version 5.2.3790.3959
Copyright (C) 1999-2001 Microsoft Corporation.
On computer: WIN2K3X86

DISKPART> list volume

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
Volume 0 C NTFS Partition 15 GB Healthy System
Volume 1 D CD-ROM 0 B Healthy
Volume 2 E New Volume NTFS Partition 20 GB Healthy

DISKPART> select volume 2

Volume 2 is the selected volume.

DISKPART> extend

DiskPart successfully extended the volume.

DISKPART> list volume

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
Volume 0 C NTFS Partition 15 GB Healthy System
Volume 1 D CD-ROM 0 B Healthy
* Volume 2 E New Volume NTFS Partition 21 GB Healthy

DISKPART>


Besides, due to the system disk protection, the function is blocked on system disk in windows 2003. After expand disk in virtual machine settings, we need to mount the disk file in another machine, extend this disk as a normal volume, and turn on the original virtual machine. The system disk is expanded to desired size.

--
Reference
How to Extend Windows Boot Volumes in VMware