RE: Encrypting MS SQL databases



Hi !

Yep, I've been thinking yet about your idea, but there are 2 problems on this:
1. The guy would need to decrypt manually the file where are stored the database files before launching MS SQL Server, what will not be acceptable by the clients :)
2. An auto-synchronization has to be performed by the laptops (between the local database and the central one) when they are connected to one of our LANs. I doubt this can be perform automatically if the databases are encrypted :)

Bénoni.

-----Message d'origine-----
De : Lars Solberg [mailto:sunberg@xxxxxxxxx]
Envoyé : vendredi 11 août 2006 15:27
À : MARTIN Benoni
Cc : security-basics@xxxxxxxxxxxxxxxxx
Objet : Re: Encrypting MS SQL databases

Hi

What about an encrypted volume on every laptop? You can use example TrueCrypt to mount the volume. TrueCrypt supports password and using an file as an password.

--
Lars

On 8/11/06, MARTIN Benoni <benoni.martin@xxxxxxxxxxx> wrote:
Hi list !

I'm currently working on a solution needing to perform replications
between MS SQL Server databases: there will be a central database and
several laptops connecting to it. The replications will occur on the
laptops, so they will have all the data on them, including sensitive
data.

So I will need to encrypt the data in their databases, and AFAIK, MS
SQL server 2K does not have encryption tools included.

So I will be looking for a tool that:
- will not be a millstone around people's neck :) (having 5 more
logins/passwords to know just because of the encryption)
- will be strong enough to not panic if a laptop is stolen :)

Any clue will be appreciated !

----------------------------------------------------------------------
----- This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has
designated Norwich University a center of Academic Excellence in
Information Security. Our program offers unparalleled Infosec
management education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed
degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
----------------------------------------------------------------------
-----



---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: The ugly side of using disk encryption
    ... That is good info about DriveCrypt. ... because compusec only supports 128 bit AES encryption. ... My forensic laptops are all DriveCrypted, I have let at least 50 different ... > EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ...
    (Security-Basics)
  • Re: Encrypting MS SQL databases
    ... There are many approaches to encryption available these days. ... only the appropriate credentials could gain access to the replicated databases. ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence ...
    (Security-Basics)
  • Re: General Sanity Check on Programmatic Resetting of Links
    ... desktop PCs, but some of the managers may be on laptops. ... Lots of databases do this sort of thing. ... workgroup server at our main location. ...
    (microsoft.public.access.modulesdaovba)
  • RE: Whole disk encryption
    ... We use SafeBoot on all our laptops and even on a bunch of dekstops. ... For specific data you can also use the content encryption future to ... WHY would you choose to NOT do full disk? ...
    (Focus-Microsoft)
  • Re: EFS | Encryption | import private key
    ... the certificate of 1 DRA on all the laptops" It's not 100% true. ... same DRA certificat on all laptops when we will "deploy" the EFS encryption. ...
    (microsoft.public.security)