Create and use strong-named assemblies - .NET (2024)

  • Article

A strong name consists of the assembly's identity—its simple text name, version number, and culture information (if provided)—plus a public key and a digital signature. It is generated from an assembly file using the corresponding private key. (The assembly file contains the assembly manifest, which contains the names and hashes of all the files that make up the assembly.)

Warning

Do not rely on strong names for security. They provide a unique identity only.

A strong-named assembly can only use types from other strong-named assemblies. Otherwise, the integrity of the strong-named assembly would be compromised.

Note

Although .NET Core supports strong-named assemblies, and all assemblies in the .NET Core library are signed, the majority of third-party assemblies do not need strong names. For more information, see Strong Name Signing on GitHub.

Strong name scenario

The following scenario outlines the process of signing an assembly with a strong name and later referencing it by that name.

  1. Assembly A is created with a strong name using one of the following methods:

    • Using a development environment that supports creating strong names, such as Visual Studio.

    • Creating a cryptographic key pair using the Strong Name tool (Sn.exe) and assigning that key pair to the assembly using either a command-line compiler or the Assembly Linker (Al.exe). The Windows SDK provides both Sn.exe and Al.exe.

  2. The development environment or tool signs the hash of the file containing the assembly's manifest with the developer's private key. This digital signature is stored in the portable executable (PE) file that contains Assembly A's manifest.

  3. Assembly B is a consumer of Assembly A. The reference section of Assembly B's manifest includes a token that represents Assembly A's public key. A token is a portion of the full public key and is used rather than the key itself to save space.

  4. The common language runtime verifies the strong name signature when the assembly is placed in the global assembly cache. When binding by strong name at run time, the common language runtime compares the key stored in Assembly B's manifest with the key used to generate the strong name for Assembly A. If the .NET security checks pass and the bind succeeds, Assembly B has a guarantee that Assembly A's bits have not been tampered with and that these bits actually come from the developers of Assembly A.

Note

This scenario doesn't address trust issues. Assemblies can carry full Microsoft Authenticode signatures in addition to a strong name. Authenticode signatures include a certificate that establishes trust. It's important to note that strong names don't require code to be signed in this way. Strong names only provide a unique identity.

Bypass signature verification of trusted assemblies

Starting with the .NET Framework 3.5 Service Pack 1, strong-name signatures are not validated when an assembly is loaded into a full-trust application domain, such as the default application domain for the MyComputer zone. This is referred to as the strong-name bypass feature. In a full-trust environment, demands for StrongNameIdentityPermission always succeed for signed, full-trust assemblies, regardless of their signature. The strong-name bypass feature avoids the unnecessary overhead of strong-name signature verification of full-trust assemblies in this situation, allowing the assemblies to load faster.

The bypass feature applies to any assembly that is signed with a strong name and that has the following characteristics:

  • Fully trusted without StrongName evidence (for example, has MyComputer zone evidence).

  • Loaded into a fully trusted AppDomain.

  • Loaded from a location under the ApplicationBase property of that AppDomain.

  • Not delay-signed.

This feature can be disabled for individual applications or for a computer. See How to: Disable the strong-name bypass feature.

TitleDescription
How to: Create a public-private key pairDescribes how to create a cryptographic key pair for signing an assembly.
How to: Sign an assembly with a strong nameDescribes how to create a strong-named assembly.
Enhanced strong namingDescribes enhancements to strong-names in the .NET Framework 4.5.
How to: Reference a strong-named assemblyDescribes how to reference types or resources in a strong-named assembly at compile time or run time.
How to: Disable the strong-name bypass featureDescribes how to disable the feature that bypasses the validation of strong-name signatures. This feature can be disabled for all or for specific applications.
Create assembliesProvides an overview of single-file and multifile assemblies.
How to delay sign an assembly in Visual StudioExplains how to sign an assembly with a strong name after the assembly has been created.
Sn.exe (Strong Name tool)Describes the tool included in the .NET Framework that helps create assemblies with strong names. This tool provides options for key management, signature generation, and signature verification.
Al.exe (Assembly linker)Describes the tool included in the .NET Framework that generates a file that has an assembly manifest from modules or resource files.
Create and use strong-named assemblies - .NET (2024)
Top Articles
How Long Does a Foreclosure Stay on Your Credit? - NerdWallet
Citi Secure Email Center Notice
NYT Mini Crossword today: puzzle answers for Tuesday, September 17 | Digital Trends
Gomoviesmalayalam
Best Team In 2K23 Myteam
Occupational therapist
craigslist: kenosha-racine jobs, apartments, for sale, services, community, and events
Cad Calls Meriden Ct
Sissy Transformation Guide | Venus Sissy Training
7543460065
Palace Pizza Joplin
Heska Ulite
Bernie Platt, former Cherry Hill mayor and funeral home magnate, has died at 90
Florida (FL) Powerball - Winning Numbers & Results
Tripadvisor Near Me
Helloid Worthington Login
Lonadine
FAQ: Pressure-Treated Wood
Los Angeles Craigs List
The most iconic acting lineages in cinema history
Summer Rae Boyfriend Love Island – Just Speak News
104 Whiley Road Lancaster Ohio
Katherine Croan Ewald
Classic | Cyclone RakeAmerica's #1 Lawn and Leaf Vacuum
Daylight Matt And Kim Lyrics
Geometry Review Quiz 5 Answer Key
Melissababy
The BEST Soft and Chewy Sugar Cookie Recipe
Air Traffic Control Coolmathgames
8005607994
Gas Buddy Prices Near Me Zip Code
Reser Funeral Home Obituaries
Drift Hunters - Play Unblocked Game Online
Cornedbeefapproved
Infinite Campus Asd20
UAE 2023 F&B Data Insights: Restaurant Population and Traffic Data
A Plus Nails Stewartville Mn
Quality Tire Denver City Texas
Old Peterbilt For Sale Craigslist
How to Watch the X Trilogy Starring Mia Goth in Chronological Order
The Banshees Of Inisherin Showtimes Near Reading Cinemas Town Square
How to Get a Better Signal on Your iPhone or Android Smartphone
Unblocked Games Gun Games
3 Zodiac Signs Whose Wishes Come True After The Pisces Moon On September 16
Vérificateur De Billet Loto-Québec
Bradshaw And Range Obituaries
Unpleasant Realities Nyt
Unit 4 + 2 - Concrete and Clay: The Complete Recordings 1964-1969 - Album Review
2121 Gateway Point
Bloons Tower Defense 1 Unblocked
Generator für Fantasie-Ortsnamen: Finden Sie den perfekten Namen
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5309

Rating: 4.1 / 5 (42 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.