Skip to content

Find all literal machineKey decryptionKey and decryptionKey topics and replace key with [your key here] #34365

@Rick-Anderson

Description

@Rick-Anderson

This is about configuring the machine keys in the web.config for web-farm like scenarios. The problem is that the configuration snip from the articles list a configuration sample containing machine key values. It seems that we have quite a few customers that have been copying and pasting this directly into their production configurations without any afterthoughts – and some of them have been compromised by **ViewState injection attacks*- [ ]

In PR


Associated WorkItem - 354961

Metadata

Metadata

Assignees

Labels

seQUESTeredIdentifies that an issue has been imported into Quest.sfi-adminSFI-Admin

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions