RE: Encryption of Connection String
From: Gang Guo [MSFT] (gangguo@online.microsoft.com)
Date: 12/30/02
- Next message: Ghulam Farid: "Disabling or renaming the sa account"
- Previous message: Richard Waymire [MS]: "Re: Transferring logins form 6.5 to 2000, anyone?!"
- In reply to: paul reed: "Encryption of Connection String"
- Next in thread: Jasper Smith: "Re: Encryption of Connection String"
- Reply: Jasper Smith: "Re: Encryption of Connection String"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: gangguo@online.microsoft.com (Gang Guo [MSFT]) Date: Mon, 30 Dec 2002 06:18:08 GMT
If the connection string is for the session state server, please check the
following article.
Q329290 HOW TO: Use the ASP.NET Utility to Encrypt Credentials and Session
State
http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q329290
If it is for your application, my advice is to use Windows authentication
to connect to your SQL server, thus you will not need store the user name
and password in any form.
If you need use the standard authentication (that means the UID and PWD are
needed for the connection string), as long as you keep your web server
safe, it doesn't make big difference how you encrypt your connection
string. If you just don't want to store the connection string as clear text
in the config file, you can use some class under
System.Security.Cryptography to encrypt/decrypt it, and store the key in
your code/or some registry.
Remember one thing, no matter how your application encryption/store the
connection string, you must decrypt and restore the UID/PWD to clear text
before you make the connection. If your web server is not physical secured,
someone who are really want to get your connection string just need crack
the uid/pwd at that time and that will defeat all your effort for
protection.
Regards,
Gang Guo
This posting is provided "AS IS" with no warranties, and confers no rights.
Got .Net? http://www.gotdotnet.com
- Next message: Ghulam Farid: "Disabling or renaming the sa account"
- Previous message: Richard Waymire [MS]: "Re: Transferring logins form 6.5 to 2000, anyone?!"
- In reply to: paul reed: "Encryption of Connection String"
- Next in thread: Jasper Smith: "Re: Encryption of Connection String"
- Reply: Jasper Smith: "Re: Encryption of Connection String"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|