Re: Encrypting data in SQL 2005



I agree. And we have a security group that would be in charge of the
password or key or whatever. My point is, I am looking for a system
that would work for what I have described.

What I would like to do is to have a cert of some type installed on the
web server that no one but the machine admin and the security group
would have access to. This cert would then be used by the web
application to access the key and decrypt the data. If a lead
developer or architect would need that access, then they would request
it through the proper channels with the security admin group and have
it installed on their machine in the same way.

I am not to concerned about the DBA or Admin hacking the box. This is
mostly to comply with a client security request. Only X people have
access to the sensitive data on the database.

Jim

.



Relevant Pages

  • Re: Local Admin on workstation
    ... reset the local admin password, ... I would go on every station to install myself or remotely through remote ... >I was thinking more along the lines of creating a security group, ... >>>> except making them local admin through restricted group in GPO, ...
    (microsoft.public.windows.server.active_directory)
  • Re: delegating administrative access
    ... I guess then I need to create a security group called Jr Admin or something ... The question is, what permissions are ... > needed to rename a computer object in AD? ...
    (microsoft.public.win2000.active_directory)
  • Active Directory Admin Model
    ... The company I work for wants a distributed Administration model. ... No one except for the Enterprise admin team is to have the domain admin passwords. ... * The Current NT4 domains have been collapsed into Regional OUs and authority delegated at this level to a security group above the delegation point. ... * The Terminal server configuration has been altered to allow them to login to the DC's in admin mode ...
    (microsoft.public.win2000.active_directory)
  • Repost to MS - permissions problem as Administrator
    ... I usually read the backup report from the previous evening this way ... You must be a member of the Domain Admins security group." ... as Enterprise Admin, Builtin Admin, etc. ...
    (microsoft.public.windows.server.sbs)