Microsoft SQL Server
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsDatabaseMicrosoft SQL Server

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old August 3rd, 2004, 09:14 PM
mroskothen mroskothen is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 1 mroskothen User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
how to log into sql securely

Hi, my asp.net application is accessing a mssql on another server. This works fine when I use this in my web.config file:

<addkey="dbkey"value="server=192.12.12.1;database=mydb;user=dbuser;passw ord=mypassword"/>

However I don't like to store my password in plain text.

I played around with aspnet_setreg.exe and I followed those instructions:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q329290

However my application says 'Could not create Windows user token from the credentials specified in the config file'

when I use it in the recommended way:

<identityimpersonate="true"
userName="registry:HKLM\SOFTWARE\MYDB\identity\ASPNET_SETREG ,userName"
password="registry:HKLM\SOFTWARE\MYDB\identity\ASPNET_SETREG ,password"
/>


I don't really need the asp.net worker process to run impersonate. All I need is to store and transmit the password encrypted.

Does anyone have a suggestion?

Thanks, Markus

Reply With Quote
  #2  
Old August 14th, 2004, 04:56 PM
Kris_Vanherck's Avatar
Kris_Vanherck Kris_Vanherck is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Location: Belgium, Antwerp
Posts: 177 Kris_Vanherck User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 24 sec
Reputation Power: 5
if you don't want to send passwords in plain text you only have 2 options (both windows integrated security)
1) add every user to the db and let asp.net impersonate
2) put a domain user on the worker process

number 1 is easy and dirty, it also makes it possible for users to use sql tools to bypass your app en access the db directly (perfect for abuse)
number 2 is not so easy as it sounds (if you're unlucky u will have to change the application pools too)

i can tell you now, this stuff has given me and my co-workers headaces for weeks, epecialy is you're having multiple OS in your users pool

Reply With Quote
Reply

Viewing: ASP Free ForumsDatabaseMicrosoft SQL Server > how to log into sql securely


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway