Re: Patterns for security

From: carion1 (ddavis76_at_gmail.com)
Date: 09/16/05

  • Next message: William Stacey [MVP]: "Re: Importance of salt"
    Date: Thu, 15 Sep 2005 19:11:05 -0500
    
    

    If the back end is SQL Server just use SSL. I am sure BizTalk would support
    an SSL connection. Got me on the main frames.

    -- 
    Derek Davis
    ddavis76@gmail.com
    "STom" <stombiztalker@hotmail.com> wrote in message 
    news:%23PN7k6asFHA.2072@TK2MSFTNGP14.phx.gbl...
    > Yes, this is a web app that will pass the request through the DMZ, through 
    > a firewall to the app server. I believe at this point we may be using 
    > BizTalk, which really doesn't have much to do with it I guess.
    >
    > The problem still remains, keeping the CC info encrypted all the way 
    > through.
    >
    > You say there are standard practices for doing this. Thats what I'm 
    > looking for. Any links you could provide?
    >
    > Thanks.
    >
    > STom
    > <rounner@yahoo.com> wrote in message 
    > news:1125875972.665194.5200@g47g2000cwa.googlegroups.com...
    >> You're writing a web app that needs credit card info?
    >> There are standard practices for handling this, and the security
    >> considerations are known and discussed and you can risk mitigate. For
    >> example you may arrange to have SSL certificates sent to your clients
    >> to secure the transaction (look up mutual SSL authentication and check
    >> phishing/ pharming too). If you have millions of clients then this may
    >> be deemed too logistically difficult.
    >> When you say a clients confidential data will not be stored securely on
    >> the mainframe... you might want to reconsider.
    >>
    >
    > 
    

  • Next message: William Stacey [MVP]: "Re: Importance of salt"

    Relevant Pages

    • RE: How to enable 2-way SSL encryption
      ... This digital signature takes the form of a certificate ... SQL server 2000 implements SSL. ... Enable SSL Encryption for SQL Server 2000 with Certificate Server ...
      (microsoft.public.sqlserver.server)
    • Re: JDBC - MSQL 2K5/MS SQL 2005 SSL ISSUE
      ... however I am trying to configure SSL on SQL Server ... Encrypted Connection" option in SQL Server 2000 network utility is enabled, ... Java Program if it is running in SSL mode or not? ...
      (microsoft.public.sqlserver.security)
    • How to install SQL server securing it with SSL communications. For Server 2000 or Server 2003. Issue
      ... segment as the webserver or SQL server with windows patches. ... Most early invented NIDS do NOT understand SSL or IPv6 traffic because they ... administrators group during the installation or after. ... Use the HTML web page on the certificate server. ...
      (microsoft.public.sqlserver.security)
    • Re: User ASPNET in SQL Server 2000
      ... Without SSL this implementation would be a security nightmare, with SSL it would be dragging feet. ... > Make sure that the connection properties for your SQL connection (e.g., ... >> I think that if you need to use integrated autentication on the SQL server ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: DIFFICULT PROBLEM! SSL for SQL 2000 Server. MS Fix bulletin does not help at all.
      ... > My goal is to be able to use SSL when connecting to SQL Server via Query ... I also want to keep the SQL Server installation under a "Domain ... > Srv, Win 2000 Srv. ...
      (microsoft.public.sqlserver.datamining)