Re: Encrypt/Decrypt SQL Server 2005 data files



Thank you very much for the reply. EFS is what we tried. There are two
unfortunate limitations. First, according to Microsoft, you cannot use SQL
if the log file is encrypted. Second, decrypt takes many minutes and the
long required time makes the technology impractical to use.
I agree that there is no absolute way to prevent access to data once an
expert has physical possession of a computer or a hard drive.
SecuriKey does work as advertised. There are ways to circumvent the
technology, but it provides some protection.

Maybe you can encrypt just the snsitive part of the data? Try to look at the
EncryptByKey and other encryption functions in BOL. Together with carefully
set NTFS permissions and encrypted backup you might get what you need.

--
Dejan Sarka
http://www.solidqualitylearning.com/blogs/


.



Relevant Pages

  • Re: How to create password protected files thru C#
    ... Users and groups have rights which are used to resolve access to the ... Now, you can encrypt the file, and then make it so only your app has ... I want to create a log file from my C# code. ... should not be able to open this file from Windows Explorer. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Encrypt/Decrypt SQL Server 2005 data files
    ... First, according to Microsoft, you cannot use SQL if the log file is encrypted. ... decrypt takes many minutes and the long required time makes the technology impractical to use. ... Maybe you can encrypt just the snsitive part of the data? ...
    (microsoft.public.sqlserver.security)
  • RE: NTE_BAD_DATA
    ... They are NOT used DIRECTLY to encrypt / decrypt data; ... you should generate a RANDOM SESSION KEY and select a SYMMETRIC ENCRYPTION ... // imported from a BLOB read in from the source file or having ...
    (microsoft.public.platformsdk.security)
  • Re: Back Doors
    ... >> Design into the system a master key. ... Encrypt that with public key. ... Decrypt random symmetric key with private key. ...
    (sci.crypt)
  • Re: CAPI and RC4: can not decrypt when Final parameter is set to F
    ... to store ASYMMETRIC key pairs - never symmetric keys like RC4, ... Now when you need to encrypt at one place and decrypt at the other normally ... Get a HCRYPTPROV handle to a key container with CryptAcquireContext ...
    (microsoft.public.platformsdk.security)