Perhaps a silly question but...
Why the concern for security on a configuration file that is only readable on a web server? By default, IIS will not serve a .config file and presumably if you can get onto the web server itself to read the "physical" file, then you have a larger security concern.
-Peter
compiledthoughts.com