RE: Better security
- From: stcheng@xxxxxxxxxxxxxxxxxxxx (Steven Cheng[MSFT])
- Date: Fri, 19 Jan 2007 10:14:44 GMT
Hi Dave,
Yes, use aspnet_regiis is one way to encrypt the content so that only
ASP.NET runtime can decrypt it. However, for your scenario, you only want
A,B to know the key and be able to encrypt and decrypt the
connectionstring, this violate the usage of ASP.NET/.NET 2.0's
configuration protection/encryption. So I think you can review your current
security design here to see whether any other approach should be better?
Sincerely,
Steven Cheng
Microsoft MSDN Online Support Lead
This posting is provided "AS IS" with no warranties, and confers no rights.
.
- References:
- Better security
- From: David Thielen
- RE: Better security
- From: Steven Cheng[MSFT]
- RE: Better security
- From: Dominick Baier
- RE: Better security
- From: David Thielen
- RE: Better security
- From: Steven Cheng[MSFT]
- Better security
- Prev by Date: Re: RedirectFromLoginPage wont redirect
- Next by Date: Re: Web Service Security
- Previous by thread: RE: Better security
- Next by thread: RE: Better security
- Index(es):
Relevant Pages
|