As a developer in Niloosoft HunterHRMS, I needed to register our domain with Google in order to start integrating with Google Docs. As part of the registration process, I had to submit a certificate file. Creating the file has been an unpleasant process, as even Google's instructions are very insuffcient. Therefore, for myself and others, I hereby summarize the exact step-by-step instructions on how to create this precious file.
Google currently requires a pem cert file.
1. Download open ssl to the computer
2. Create 2 environment variables on the computer:
A. Name: RANDFILE Value: .rnd
B. Name: OPENSSL_CONF Value: The full file name of the openssl.cnf file. For example: D:\Program Files\openssl-0.9.8k_X64\openssl.cnf (To reach Envrironment Variables editing window: computer -> properties -> Advanced system settings -> Advanced tab -> Environment Variables button.)
3. Run openssl.exe (only after the environment variables have been created!)
4. Create private key file + certificate file:
(Note: you will be prompted to enter the certificate information. When you are asked for the Common Name, enter the domain - such as www.hrms.me)
OpenSSL> req -x509 -nodes -days 365 -newkey rsa:1024 -sha1 -keyout myrsakey.pem -out myrsacert.pem
5. Create a pfx certificate (used by .Net) based on the pem private key + certificate:
(Note: you will be prompted for a password. It may be left empty)
OpenSSL> pkcs12 -export -in myrsacert.pem -inkey myrsakey.pem -out CertForGoogle.pfx -name "Cert for Google".
Adam Porat is a senior .Net programmer Specializing in C#, WCF, ASP.NET, Elasticsearch, SQL Server.
Tuesday, August 28, 2012
Sunday, August 26, 2012
Why WCF always gives CommunicationObjectFaultedException?
I have been frustrated regarding WCF - it always seemed to give the same obscure exception:
CommunicationObjectFaultedException - The communication object cannot be used because it is in the Faulted state
Finally I found out why.
Actually WCF usually throws clear exceptions. You just have to use it right.
I have been using WCF proxys with a C# using statement. And here the trouble lies.
What the C# using statement does is this: it wraps up the using block in a try clause, and in the finally clause it disposes the object given in the using clause. In other words, it ensures the object gets disposed even if an exception occured inside the block.
This is very good for working with files, etc. But with WCF it is a problem. Why? because the WCF proxy's Dispose method actually calls the proxy's Close method. But this Close method has a catch: if the proxy is in a Faulted state, Close() throws the infamous exception CommunicationObjectFaultedException.
So what happens is this: you call a method on a service and get an exception. This puts the proxy in a faulted state. Then the using block calls Dispose on the proxy, and the CommunicationObjectFaultedException is thrown.
A WCF proxy in a faulted state still holds some resources. And to dispose of them, you need to call the proxy's Abort method. This method does not throw an exception if the proxy is in a faulted state.
So the recommended pattern to use a WCF proxy is this:
// Create the proxy object here
try
{
proxy.MyMethod();
}
finally
{
if (proxy != null)
{
if (proxy.State == System.ServiceModel.CommunicationState.Faulted)
{
proxy.Abort();
}
else
{
proxy.Close();
}
}
}
{
if (proxy != null)
{
if (proxy.State == System.ServiceModel.CommunicationState.Faulted)
{
proxy.Abort();
}
else
{
proxy.Close();
}
}
}
The writer is a .Net team leader at Niloosoft Hunter HRMS
Thursday, February 2, 2012
SQL Server Compact Edition vs. SQL Express Edition
I've tried using SQL Server Compact Edition 4.0 for a certain Hunter HRMS application. The result was slow and I was getting "timed out waiting for a lock" exceptions. I did a lot to try to prevent any locks - close any open connections/DataReaders etc., even use NOLOCK hints, but still these timeouts would appear.
I then changed to SQL Express edition with minimal code changes to accommodate the change. All the problems disappeared - response time was excellent, with no timeouts.
Thought I should share this with the world.
I then changed to SQL Express edition with minimal code changes to accommodate the change. All the problems disappeared - response time was excellent, with no timeouts.
Thought I should share this with the world.
Thursday, January 12, 2012
Table and Table-Cell Style Properties
There is some confusion regarding the different styling possibilities of a table, and which properties should be set on a table element and which on a cell (td) element. So let's clear this up.
The confusion is partly caused due to 2 deprecated html table attributes: cellspacing and cellpadding.
Let's look at the relevant ways to affect a table, and the ways to accomplish them (recommended and deprecated).
1. Control the padding inside each cell
The deprecated way has been to set the cellpadding attribute on the table.
The recommended way is to set the CSS padding property on the cell elements (td or th).
2. Control the space between the cell borders
The deprecated way has been to set the cellspacing attribute on the table.
The recommended way it to set the CSS property border-spacing on the table element.
3. Collapse the cell borders into a single border
This is done using the CSS property border-collapse on the table element.
Note: if you collapse the border, any border-spacing value will be ignored.
4. Set the style of the border of the cells
Style the border using CSS on the cells (td / th).
Addition note: you cannot set the margin on a table cell. It will be ignored. Use border-spacing on the table element instead.
Adam Porat is a team leader at Niloosoft on Hunter HRMS product.
The confusion is partly caused due to 2 deprecated html table attributes: cellspacing and cellpadding.
Let's look at the relevant ways to affect a table, and the ways to accomplish them (recommended and deprecated).
1. Control the padding inside each cell
The deprecated way has been to set the cellpadding attribute on the table.
The recommended way is to set the CSS padding property on the cell elements (td or th).
2. Control the space between the cell borders
The deprecated way has been to set the cellspacing attribute on the table.
The recommended way it to set the CSS property border-spacing on the table element.
3. Collapse the cell borders into a single border
This is done using the CSS property border-collapse on the table element.
Note: if you collapse the border, any border-spacing value will be ignored.
4. Set the style of the border of the cells
Style the border using CSS on the cells (td / th).
Addition note: you cannot set the margin on a table cell. It will be ignored. Use border-spacing on the table element instead.
Adam Porat is a team leader at Niloosoft on Hunter HRMS product.
Wednesday, May 18, 2011
How to overcome ValidateRequest problems
As part of a project to secure Hunter HRMS application by Niloosoft I encountered a problem with ASP.NET's ValidateRequest feature. It seems to cause validation errors not only on characters such as < >, but also on special text characters from different languages. I didn't want to disable ValidateRequest (not for the entire application in web.config, and not even for the specific page), because it is a valuable security feature. So I found the following solution, to get around ValidateRequest for a specific text box:
On the client, I catch the submit button onclick event. I then put in the TextBox using Javascript the url-encoded values of the textbox. This would look something like this:
document.getElementById("txtName").value = encodeURIComponent(document.getElementById("txtName").value);
Note that encodeURIComponent() is a built-in javascript function. You can Google it for more information, but basically it does exactly what it says - applies url encoding to its input. It also encodes url-characters such as / & ?, because it is designed to encode a portion of a url string, thus these values are encoded.
Now, on the server side, all you need to do is decode the text using Server.UrlDecode().
Incidently, this may cause 2 problems: (1) While the page posts back, the user would see the value in the text-box changes to the encoded value (2) In case there is an error in the postback, the encoded value would remain in the text-box instead of the real value. To overcome these problems, what I did was this: (a) I put the encoded value in a hidden field instead of the original text-box. (b) I set the text-box to disabled to prevent its value from posting back to the server and causing an error (make sure the form's "SubmitDisabledControls" property is set to false) (c) On the page's OnPreLoad event I decoded the value in the hidden field, and put it back in the text-box. These handlings worked perfectly.
This is a great way to get around ValidateRequest for a specific text box. But note this: make sure to html-encode the value when you display it in labels - because it might include malicious script (as it bypassed the ValidateRequest check !) ! But this is another subject (you can look up anti-xss).
If this post helped you, please let me know by posting a comment !
On the client, I catch the submit button onclick event. I then put in the TextBox using Javascript the url-encoded values of the textbox. This would look something like this:
document.getElementById("txtName").value = encodeURIComponent(document.getElementById("txtName").value);
Note that encodeURIComponent() is a built-in javascript function. You can Google it for more information, but basically it does exactly what it says - applies url encoding to its input. It also encodes url-characters such as / & ?, because it is designed to encode a portion of a url string, thus these values are encoded.
Now, on the server side, all you need to do is decode the text using Server.UrlDecode().
Incidently, this may cause 2 problems: (1) While the page posts back, the user would see the value in the text-box changes to the encoded value (2) In case there is an error in the postback, the encoded value would remain in the text-box instead of the real value. To overcome these problems, what I did was this: (a) I put the encoded value in a hidden field instead of the original text-box. (b) I set the text-box to disabled to prevent its value from posting back to the server and causing an error (make sure the form's "SubmitDisabledControls" property is set to false) (c) On the page's OnPreLoad event I decoded the value in the hidden field, and put it back in the text-box. These handlings worked perfectly.
This is a great way to get around ValidateRequest for a specific text box. But note this: make sure to html-encode the value when you display it in labels - because it might include malicious script (as it bypassed the ValidateRequest check !) ! But this is another subject (you can look up anti-xss).
If this post helped you, please let me know by posting a comment !
Sunday, May 1, 2011
How to get rid of padded zeroes after decryption
This is how I got rid of padded zeroes after using RijndaelManaged encryption:
// Find the index of the last one appended zero
int i = plainbytes.Length - 1;
for (; i > 0; i--)
{
if (plainbytes[i] != 0)
{
i++;
break;
}
}
// Here i means the number of bytes to take from the array.
return plainbytes.Take(i).ToArray();
// Find the index of the last one appended zero
int i = plainbytes.Length - 1;
for (; i > 0; i--)
{
if (plainbytes[i] != 0)
{
i++;
break;
}
}
// Here i means the number of bytes to take from the array.
return plainbytes.Take(i).ToArray();
If you turn the byte[] first to string, then you can clean out the string as follows:
// Find the index of the last one appended zero
int i = decryptedString.Length - 1;
for (; i > 0; i--)
{
if (decryptedString[i] != '\0')
{
i++;
break;
}
}
// Here i means the number of bytes to take from the array.
decryptedString = decryptedString.Substring(0, i);
Wednesday, March 16, 2011
How to deal with ASP.NET Event Validation
I have encountered problems with the Event Validation mechanism in ASP.NET when I add values to a dropdown list using javascript - in this case I sometimes get an exception. How to deal with it? I found several solutions on the web, but none were very good. While this mechanism can be disabled, it is not good to do so for application secruity reasons. I found another solution which worked great for me:
First you must understand why the exception occured: It is because the value selected by the user did not exist in the original values in the drop-down list as originally created by the server. So what I did was to create a hidden field, and send the value to the server in the hidden field (put the selected value in a hidden field on the client using javascript). And, right before the postback (on the client using javacript), disable the drop-down element. Disabling this element prevents its value from being sent to the server, thus preventing the Event Validation exception.
Example how to disable:
var ddlProfField = document.getElementById("ddlProfessionalField");
ddlProfField.disabled = "disabled";
Another option, instead of disabling the element, is to clear its values like this:
ddlProfField.options.length = 0;
If this post helped you, please let me know by posting a comment !
For other solutions see this link: http://odetocode.com/blogs/scott/archive/2006/03/21/asp-net-event-validation-and-invalid-callback-or-postback-argument-again.aspx
First you must understand why the exception occured: It is because the value selected by the user did not exist in the original values in the drop-down list as originally created by the server. So what I did was to create a hidden field, and send the value to the server in the hidden field (put the selected value in a hidden field on the client using javascript). And, right before the postback (on the client using javacript), disable the drop-down element. Disabling this element prevents its value from being sent to the server, thus preventing the Event Validation exception.
Example how to disable:
var ddlProfField = document.getElementById("ddlProfessionalField");
ddlProfField.disabled = "disabled";
Another option, instead of disabling the element, is to clear its values like this:
ddlProfField.options.length = 0;
If this post helped you, please let me know by posting a comment !
For other solutions see this link: http://odetocode.com/blogs/scott/archive/2006/03/21/asp-net-event-validation-and-invalid-callback-or-postback-argument-again.aspx
Subscribe to:
Posts (Atom)