Encrypt connection channel

Ask a Question related to ASP.NET Security, Design and Development.

  1. #1

    Default Encrypt connection channel

    (Been reading other messages on this subject but could not find an answer,
    that is why I'm posting this. Please note, although I have posted to several
    groups, I've set follow-to microsoft.public.sqlserver.security in case I
    posted to where I shouldn't have, sorry if I have).

    Using
    + ASP.Net
    + SQL Server 2000
    + Windows 2K Adv. Server.

    It is possible to encryp data that is exchanged between ASP.Net server in
    DMZ and SQL Server in secured zone? By that I mean securing all that data
    that passes though the firewall on port 1433 between ASP.Net and SQL Server.
    I guess there are two aspects to this question:

    1 Encrypt the connection string that is used to make a connection, ie pass
    and ancrypted connection string from ASP.Net to SQL Server to make a
    connection. Does ADO.Net and SQL Server support this feature?

    2 Encryption of sensitive sensitive query data that is exchanged between
    ASP.Net and SQL Server. By this I mean storing the data in cleartext, then
    have it ecrypted while it is in transition from the DB server to ASP.Net
    then have in decrypted back into cleartext in ASP.Net application. Is that
    possible?

    I suppse if either of the above is not possible then I will have to store
    the sensitive data into the DB encrypted and have it decrypted after
    reading. The problem with this method is that session keys cannot be used:
    the key used for encryption / decryption needs to be fixed for all time.

    Please help.


    Tushar Karsan Guest

  2. Similar Questions and Discussions

    1. Encrypt key
      Hello, I want to use the encrypt and decrypt function for my passwords. Can someone give me an example what key shoul I be using. My password...
    2. When to encrypt
      On 12/6/2004 6:10 PM, Greg Stark wrote: I was wondering where he keeps his servers. Are they kept under a little rain shelter on the parking lot,...
    3. The underlying connection as closed: Could not establish secure channel for SSL/TLS
      Ok, I try to communicate with a web service who receive xml message under a https using SSL. I have a directory with 240 XML files on my desktop....
    4. encrypt
      I can encrypt the contents of a memory stream with no problems, however when decrypting( I'm using the same key an IV ) I get an exception stating...
    5. Encrypt in Perl, De-encrypt in Javascript
      I got a javascript off the net which encrypt and de-encrypt HTML code so that nobody can read the public html file. here is the code of...
  3. #2

    Default Encrypt connection channel

    (Been reading other messages on this subject but could not find an answer,
    that is why I'm posting this. Please note, although I have posted to several
    groups, I've set follow-to microsoft.public.sqlserver.security in case I
    posted to where I shouldn't have, sorry if I have).

    Using
    + ASP.Net
    + SQL Server 2000
    + Windows 2K Adv. Server.

    It is possible to encryp data that is exchanged between ASP.Net server in
    DMZ and SQL Server in secured zone? By that I mean securing all that data
    that passes though the firewall on port 1433 between ASP.Net and SQL Server.
    I guess there are two aspects to this question:

    1 Encrypt the connection string that is used to make a connection, ie pass
    and ancrypted connection string from ASP.Net to SQL Server to make a
    connection. Does ADO.Net and SQL Server support this feature?

    2 Encryption of sensitive sensitive query data that is exchanged between
    ASP.Net and SQL Server. By this I mean storing the data in cleartext, then
    have it ecrypted while it is in transition from the DB server to ASP.Net
    then have in decrypted back into cleartext in ASP.Net application. Is that
    possible?

    I suppse if either of the above is not possible then I will have to store
    the sensitive data into the DB encrypted and have it decrypted after
    reading. The problem with this method is that session keys cannot be used:
    the key used for encryption / decryption needs to be fixed for all time.

    Please help.


    Tushar Karsan Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139