Showing posts with label application. Show all posts
Showing posts with label application. Show all posts

Thursday, March 29, 2012

End User Report Designer

Hi,
I am looking into a suitable report tool I can use in an application.
I want to be able to give the end user the ability to create there own
reports, and then have the application access them just like any other
report I ship with the application.
Does SQL Reporting 2005 have a report design tool that can be used by end
users ? If not are there any third party ones ?
ThanksYou can use the Report Builder, which comes with SQL Reporting Services
2005.
You can create new reports from a set of templates. If you make the
templates general enough, your users should be able to report on everything
they need to report on.
More about the Report Builder at
http://msdn2.microsoft.com/en-us/library/ms155933.aspx
Kaisa M. Lindahl Lervik
"Aussie Rules" <AussieRules@.nospam.nospam> wrote in message
news:%23wGa6WP8GHA.608@.TK2MSFTNGP03.phx.gbl...
> Hi,
> I am looking into a suitable report tool I can use in an application.
> I want to be able to give the end user the ability to create there own
> reports, and then have the application access them just like any other
> report I ship with the application.
> Does SQL Reporting 2005 have a report design tool that can be used by end
> users ? If not are there any third party ones ?
> Thanks
>|||Hi,
Thanks for the reply.
Is the license on this report builder only available to be run on the
server.
Ideally it would be good if any number of end users could create a report at
there own workstations, and save them centrally...
THanks
"Kaisa M. Lindahl Lervik" <kaisaml@.hotmail.com> wrote in message
news:e4jLJqP8GHA.4996@.TK2MSFTNGP03.phx.gbl...
> You can use the Report Builder, which comes with SQL Reporting Services
> 2005.
> You can create new reports from a set of templates. If you make the
> templates general enough, your users should be able to report on
> everything they need to report on.
> More about the Report Builder at
> http://msdn2.microsoft.com/en-us/library/ms155933.aspx
> Kaisa M. Lindahl Lervik
>
> "Aussie Rules" <AussieRules@.nospam.nospam> wrote in message
> news:%23wGa6WP8GHA.608@.TK2MSFTNGP03.phx.gbl...
>> Hi,
>> I am looking into a suitable report tool I can use in an application.
>> I want to be able to give the end user the ability to create there own
>> reports, and then have the application access them just like any other
>> report I ship with the application.
>> Does SQL Reporting 2005 have a report design tool that can be used by end
>> users ? If not are there any third party ones ?
>> Thanks
>|||Hello Aussie,
You do not need to purchase any additional license for the report builder.
For more information about license issue, You can call 1-800-426-9400,
Monday through Friday, 6:00 A.M. to 6:00 P.M. (Pacific time) to speak
directly to a Microsoft licensing specialist, and you can get more detailed
information from there. Worldwide customers can use the Guide to Worldwide
Microsoft Licensing Sites to find contact information in their locations.
For detailed information on contacting Microsoft Customer Service, please
reference the following Microsoft Knowledge Base article.
Q295539 How and When to Contact Microsoft Customer Service
http://support.microsoft.com/?id=295539
Sincerely,
Wei Lu
Microsoft Online Community Support
==================================================
Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscriptions/support/default.aspx.
==================================================(This posting is provided "AS IS", with no warranties, and confers no
rights.)|||Hi Wei,
Thanks for you reply.
Is there a standalone installation for the report builder tool, or must the
SQL tools be installed and this option selected?
Thanks
"Wei Lu [MSFT]" <weilu@.online.microsoft.com> wrote in message
news:YbcGiPQ8GHA.1860@.TK2MSFTNGXA01.phx.gbl...
> Hello Aussie,
> You do not need to purchase any additional license for the report builder.
> For more information about license issue, You can call 1-800-426-9400,
> Monday through Friday, 6:00 A.M. to 6:00 P.M. (Pacific time) to speak
> directly to a Microsoft licensing specialist, and you can get more
> detailed
> information from there. Worldwide customers can use the Guide to Worldwide
> Microsoft Licensing Sites to find contact information in their locations.
> For detailed information on contacting Microsoft Customer Service, please
> reference the following Microsoft Knowledge Base article.
> Q295539 How and When to Contact Microsoft Customer Service
> http://support.microsoft.com/?id=295539
> Sincerely,
> Wei Lu
> Microsoft Online Community Support
> ==================================================> Get notification to my posts through email? Please refer to
> http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
> ications.
> Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
> where an initial response from the community or a Microsoft Support
> Engineer within 1 business day is acceptable. Please note that each follow
> up response may take approximately 2 business days as the support
> professional working with you may need further investigation to reach the
> most efficient resolution. The offering is not appropriate for situations
> that require urgent, real-time or phone-based interactions or complex
> project analysis and dump analysis issues. Issues of this nature are best
> handled working with a dedicated Microsoft Support Engineer by contacting
> Microsoft Customer Support Services (CSS) at
> http://msdn.microsoft.com/subscriptions/support/default.aspx.
> ==================================================> (This posting is provided "AS IS", with no warranties, and confers no
> rights.)
>|||Hello Aussie,
If you installed the SQL Reporting Services 2005, this tool will installed
in the server side and end user could access it from the Report Manager web
site.
The report builder is a ClickOnce application that end user could download
from the web site and then installed on the client.
Once you installed the SQL Reporting Services 2005, you could use the
Report Builder.
For more information about Report Builder, please refer the following
article:
Report Builder
http://msdn2.microsoft.com/en-us/library/ms155933.aspx
How to: Start Report Builder
http://msdn2.microsoft.com/en-us/library/ms159221.aspx
Hope this will be helpful.
Sincerely,
Wei Lu
Microsoft Online Community Support
==================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
==================================================This posting is provided "AS IS" with no warranties, and confers no rights.|||Hi,
From what i have read this is a web based tool, is there a desktop tool. My
application is a VB.net desktop client accessing a sqlserver server
"Wei Lu [MSFT]" <weilu@.online.microsoft.com> wrote in message
news:9UvHYro8GHA.1860@.TK2MSFTNGXA01.phx.gbl...
> Hello Aussie,
> If you installed the SQL Reporting Services 2005, this tool will installed
> in the server side and end user could access it from the Report Manager
> web
> site.
> The report builder is a ClickOnce application that end user could download
> from the web site and then installed on the client.
> Once you installed the SQL Reporting Services 2005, you could use the
> Report Builder.
> For more information about Report Builder, please refer the following
> article:
> Report Builder
> http://msdn2.microsoft.com/en-us/library/ms155933.aspx
> How to: Start Report Builder
> http://msdn2.microsoft.com/en-us/library/ms159221.aspx
> Hope this will be helpful.
> Sincerely,
> Wei Lu
> Microsoft Online Community Support
> ==================================================> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> ==================================================> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>|||Hello Aussie,
In the VB.NET winform application, you could use the Report Viewer control
and creat a Client Report Definition (.rdlc) File to retrieve the data.
You could convert the rdl file to rdlc file. The rdlc file will render in
your winform application and does not need the report server.
For more information, please refer the following article:
Creating Client Report Definition (.rdlc) Files
http://msdn2.microsoft.com/en-us/library/ms252067.aspx
Sincerely,
Wei Lu
Microsoft Online Community Support
==================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
==================================================This posting is provided "AS IS" with no warranties, and confers no rights.|||Note: Report Builder is a winforms application. It is accessible via URL but
is downloaded to the user's desktop and store in the Click Once cache for
use.
--
Regards,
Carolyn Chau
This posting is provided "AS IS" with no warranties, and confers no rights.
"Wei Lu [MSFT]" wrote:
> Hello Aussie,
> In the VB.NET winform application, you could use the Report Viewer control
> and creat a Client Report Definition (.rdlc) File to retrieve the data.
> You could convert the rdl file to rdlc file. The rdlc file will render in
> your winform application and does not need the report server.
> For more information, please refer the following article:
> Creating Client Report Definition (.rdlc) Files
> http://msdn2.microsoft.com/en-us/library/ms252067.aspx
> Sincerely,
> Wei Lu
> Microsoft Online Community Support
> ==================================================> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> ==================================================> This posting is provided "AS IS" with no warranties, and confers no rights.
>|||you need to look at 90 Degree Software - they do just that
"Aussie Rules" wrote:
> Hi,
> I am looking into a suitable report tool I can use in an application.
> I want to be able to give the end user the ability to create there own
> reports, and then have the application access them just like any other
> report I ship with the application.
> Does SQL Reporting 2005 have a report design tool that can be used by end
> users ? If not are there any third party ones ?
> Thanks
>
>

Tuesday, March 27, 2012

Encryption using MS SQL 2005

Hello,

I have a application server with about 500,000 users. We are trying to tacle the issue of encryption. We are using MS SQL 2005 and I am sure that symmetric encryption would be the best, due to speed. But heres the kicker.....We want the whole database encrypted at rest, and when clients log onto our ASP to gain access to their programms the data must be in plain text. Any sugesstions?

Thanks,

Corliss

You have to choose: either the database is encrypted, or it is not.

If it is encrypted, then each query will have to decrypt the data upon access.

OR, you may choose to use SSL or IPSEC to control and encrypt the data at the transport layer. (But that does not encrypt the database 'at rest'.)

I suggest that you look in Books Online for the topics: Encryption, Encrypted data. Here are some resources about encryption:

Encrypting Connections to SQL Server
http://msdn2.microsoft.com/en-us/library/ms189067.aspx

Encryption -Column-level using the CryptoAPI
http://www.sqlservercentral.com/columnists/mcoles/sql2000dbatoolkitpart1.asp

Encryption -Example
http://blogs.msdn.com/lcris/archive/2005/12/16/504692.aspx

Encryption/Decryption
http://www.sqlservercentral.com/columnists/mcoles/sql2000dbatoolkitpart1.asp
http://blogs.msdn.com/lcris/archive/category/10357.aspx
http://blogs.msdn.com/sqlblog/archive/2006/11/02/part-i-data-security-enhancements-in-sql-server-2005.aspx

|||

Corliss, do you also expect that data is accessible only if clients connect via your ASP application?

Right now, there isn't any such capability, but we're always welcoming suggestions for new features, so we're interested in finding more about what type of encryption feature you would find helpful.

Thanks
Laurentiu

|||

Cristofor,

That woulbe be Ideal, but I also know that it isn't possible. I want to encrypt the entire database and only allow data to be accessible through the applications that we have on the server. this is troulesome for sure because the SQL server works best when authenitcation of users/ groups takes place.

|||Look into using IPSEC. It is not a 'complete' solution for your problem, but perhaps it can narrow down the attack vectors and reduce the risk.|||

Using IPSEC?

In terms of network traffic I don't really need to. All traffic is encrypted due to citrix and a VPN. "At Rest" is the issue:)

Is there a way to decrypt when the data needs to be accessed...like when an odbc connection is made.

|||

At this moment, there isn't any feature that would answer your requirements. The SQL Server 2005 encryption is meant for selective encryption of data - encrypting the entire database would require a different solution.

For the access restricted to applications, this is again not something that can be guaranteed - users can always bypass applications and connect directly by figuring out how the application connects in the first place. Encryption wouldn't address this scenario.

Thanks
Laurentiu

|||

You might find this thread 'insightful'. Similar issue.

http://forums.microsoft.com/MSDN/showpost.aspx?postid=1354173&siteid=1

|||

Corliss,

We have plans to release a feature that may solve your exact requirements in the next version of SQL Server. However, this may be limited to only certain SKUs. What SKU does your organization currently have license to? Would you be interested in participating with us in a public CTP program to try it out?

Thanks

Andy

|||

please forward me more details Smile

corliss

Encryption using MS SQL 2005

Hello,

I have a application server with about 500,000 users. We are trying to tacle the issue of encryption. We are using MS SQL 2005 and I am sure that symmetric encryption would be the best, due to speed. But heres the kicker.....We want the whole database encrypted at rest, and when clients log onto our ASP to gain access to their programms the data must be in plain text. Any sugesstions?

Thanks,

Corliss

You have to choose: either the database is encrypted, or it is not.

If it is encrypted, then each query will have to decrypt the data upon access.

OR, you may choose to use SSL or IPSEC to control and encrypt the data at the transport layer. (But that does not encrypt the database 'at rest'.)

I suggest that you look in Books Online for the topics: Encryption, Encrypted data. Here are some resources about encryption:

Encrypting Connections to SQL Server
http://msdn2.microsoft.com/en-us/library/ms189067.aspx

Encryption -Column-level using the CryptoAPI
http://www.sqlservercentral.com/columnists/mcoles/sql2000dbatoolkitpart1.asp

Encryption -Example
http://blogs.msdn.com/lcris/archive/2005/12/16/504692.aspx

Encryption/Decryption
http://www.sqlservercentral.com/columnists/mcoles/sql2000dbatoolkitpart1.asp
http://blogs.msdn.com/lcris/archive/category/10357.aspx
http://blogs.msdn.com/sqlblog/archive/2006/11/02/part-i-data-security-enhancements-in-sql-server-2005.aspx

|||

Corliss, do you also expect that data is accessible only if clients connect via your ASP application?

Right now, there isn't any such capability, but we're always welcoming suggestions for new features, so we're interested in finding more about what type of encryption feature you would find helpful.

Thanks
Laurentiu

|||

Cristofor,

That woulbe be Ideal, but I also know that it isn't possible. I want to encrypt the entire database and only allow data to be accessible through the applications that we have on the server. this is troulesome for sure because the SQL server works best when authenitcation of users/ groups takes place.

|||Look into using IPSEC. It is not a 'complete' solution for your problem, but perhaps it can narrow down the attack vectors and reduce the risk.|||

Using IPSEC?

In terms of network traffic I don't really need to. All traffic is encrypted due to citrix and a VPN. "At Rest" is the issue:)

Is there a way to decrypt when the data needs to be accessed...like when an odbc connection is made.

|||

At this moment, there isn't any feature that would answer your requirements. The SQL Server 2005 encryption is meant for selective encryption of data - encrypting the entire database would require a different solution.

For the access restricted to applications, this is again not something that can be guaranteed - users can always bypass applications and connect directly by figuring out how the application connects in the first place. Encryption wouldn't address this scenario.

Thanks
Laurentiu

|||

You might find this thread 'insightful'. Similar issue.

http://forums.microsoft.com/MSDN/showpost.aspx?postid=1354173&siteid=1

|||

Corliss,

We have plans to release a feature that may solve your exact requirements in the next version of SQL Server. However, this may be limited to only certain SKUs. What SKU does your organization currently have license to? Would you be interested in participating with us in a public CTP program to try it out?

Thanks

Andy

|||

please forward me more details Smile

corliss

sql

encryption optimization

Hi,
I have an application that requires the storing of personal data, name,
address, ssn with a requirement that key fields, first name, last name,
address1, city, zip, ssn be encrypted. Currently, there are over 100,000
records, and growing fast. Searches need to be done based on these key
fields (lastname like 'A%' for instance). I am loading the return set into
SqlDataSource and GridView using .net version 2.0.
I'm using a stored procedure to return the data.
When the page first loads (which filters on lastname = 'A%', it loads
slowly, about 20 seconds), if I change the filter (lastname = 'Q%') it times
out.
Is there a best practice to follow in a case like this that would result in
the best performance possible. I realize with all the encryption that it is
very processing intensive, but with a first load at least usable, but the
second load timing out, there may be some things I should do (clear buffers
or something) that I do not know about doing.
Can you help on this?
Thanks.The bottom line is that you can't efficiently search (use indexes) on these
encrypted key columns because you are searching using the decrypted value
and this value is not stored in the database. During the search, not only
must each value be decrypted, a scan of all table rows is required. This is
a very expensive operation.
For an equality search, you can store a hash in clear text, index the hash
value and add the hash search criteria to your search. This will greatly
reduce the number of qualifying rows and usually result in acceptable
performance. See Laurentiu Cristofor's blog
(http://blogs.msdn.com/lcris/archive.../22/506931.aspx) for a more
complete discussion.
Unfortunately, there is no way to perform efficient wildcard/range searches
on encrypted data. If you must have this functionality, you'll need to take
a different approach like encrypting at the file level (EFS) rather than
column level. I don't know if that's an option in your environment.
Hope this helps.
Dan Guzman
SQL Server MVP
"Gerhard" <acsla@.community.nospam> wrote in message
news:CA33D347-57EC-451F-A3BB-A3931D8CFF65@.microsoft.com...
> Hi,
> I have an application that requires the storing of personal data, name,
> address, ssn with a requirement that key fields, first name, last name,
> address1, city, zip, ssn be encrypted. Currently, there are over 100,000
> records, and growing fast. Searches need to be done based on these key
> fields (lastname like 'A%' for instance). I am loading the return set
> into
> SqlDataSource and GridView using .net version 2.0.
> I'm using a stored procedure to return the data.
> When the page first loads (which filters on lastname = 'A%', it loads
> slowly, about 20 seconds), if I change the filter (lastname = 'Q%') it
> times
> out.
> Is there a best practice to follow in a case like this that would result
> in
> the best performance possible. I realize with all the encryption that it
> is
> very processing intensive, but with a first load at least usable, but the
> second load timing out, there may be some things I should do (clear
> buffers
> or something) that I do not know about doing.
> Can you help on this?
> Thanks.|||Hi Acsla,
I am interested in this issue. Would you mind letting me know the result of
the suggestions?
I noticed that you bind the query result to a Gridview, so I guess that the
loading time (20s and time out) refers to the whole loading process when
all data has been displayed in your GridView. Does the Gridview have a
paging function? According to my experience, if the query result is also
huge, the render time of the control may also spend a long time.
Basically I agree with Dan's suggestions on SQL. Additionally, I would like
your checking how long it will spend if you separately run the SQL
statement in Query Analyzer.
If you need further assistance, feel free to let me know. I will be more
than happy to be of assistance.
Have a great day!
Charles Wang
Microsoft Online Community Support
========================================
==============
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
========================================
==============
This posting is provided "AS IS" with no warranties, and confers no rights.
========================================
==============sql

Encryption of Data in SQL05

My current experience is with access and sql2000. In my current application, I compress/encrypt my data prior to storing in my database. Does the new verion of sql support compression/encryption and if so can you please point me to any links which discuss.

thanks,

Fred Herring

Encryption is supported in SQL Server 2005, see for example:

http://msdn2.microsoft.com/en-us/library/ms345262(en-US,SQL.90).aspx

I also have a number of postings with examples on my blog:

http://blogs.msdn.com/lcris/archive/category/10357.aspx

If you want to evaluate the encryption features of SQL Server 2005, they're also available in the Express edition, which you can get from here:

http://msdn.microsoft.com/sql/express/

If you need more specific information, this is the right place to post questions.

Thanks
Laurentiu

|||

I have read that encryption is available for SQL 05. I have also attempted encryption on a column.

What are some good examples and practices when using encryption in SQL 05? How and where is the key stored?

How does the key work per column, or one per database?

How do you manage encryption keys?

Where are encryption keys stored and where is a safe place to store them? I don't have a full understanding of how encryption works in SQL 05, so any help would be great- I've read syntax and how to create and use them- but only in an example- I have not used them in practice- I don't understand how to use them in a real world example, or at least for our business.

Any help?

|||

You can find detailed answers to these questions by following these links:

Encryption Hierarchy article in Books Online:
http://msdn2.microsoft.com/en-us/library/ms189586.aspx

My blog with various examples and discussions of encryption functionality:
http://blogs.msdn.com/lcris/archive/category/10357.aspx

If after reading those articles, you still have questions that are unanswered, let us know.

Thanks
Laurentiu

|||Great! Thanks for the blog and the links! I look forward to diving into these!

Monday, March 26, 2012

Encryption in SQL Server2000/VB

Hi,

I have an application in SQL Server 2000 and VB as the front end. We want to encrypt the password for connecting to the database so that even the programmers will not be able to see it. Only administrator should know the password. A common db account will be used for connecting to the database. This password needs to be encrypted.
Encryption either in VB or SQL server 2000 is fine.

Is there a way? Thanks in advance.

RajI'm asuming u meant the password written in your codes.

err I'm guessing...compile your connection parameter coding into a object file and call it in your vb?

I know a way to encrypt ASP,vbscript thought, using Windows Script Encoder. You can find it in unser MSDN search.

It not fool proof, but then again, I think it only encrypts script files.|||use VB to encypt...and have a dll to do this encryption and decryption...and embed this logic of encryption and put the password as well into this dll. Actually what i have done is, i have a file name config.txt which this dll accesses and retrives the password..and this config.txt is encrypted. And when user/developer put his password in the login dialog or any connection string...it will be first sent to that dll and it encrypts that password and compares against the encrypted password in the file.|||I have an easier solution. I developed an encryption function, and put them into an DLL. There is an "admin" executable, which shows the result of encryption, and I used the result as the real DB password.

This DLL isn't availabe to the developer directly, but is used in the middle tier, which receives the original password from the developer, and connects to the DB with the encrypted one.

Encryption in MDF file possible?

I am working on a distributed application that will use a SQL Express 2005 MDF file for the primary application data storage. The program will be storing sensitive data and I would like to encrypt the data in it.

I have searched through the forums and cannot find any reference to how to enable encryption for an MDF file.

I thought about writing my own encrypt / decrypt functions, however, I'm using databound controls and do not have a home-grown data access layer that I can tap into to implement the encryption.

When I originally added the MDF file to my application, under the "Advanced" settings, I saw that I could switch an "Encryption" property to "True"... figuring that would do the trick. However, when the MDF file is created I get an error stating, "The instance of SQL Server you attempted to connect to does not support encryption".

What is the trick for encrypting data in an MDF file that is being used with databound controls? Remember that this will be a distributed app - so if there are any customizations that are required on the SQL Express side to support this - I will need to find some way to configure SQL Express on the target machines during my bootstrap install of it.

Any help would be greatly appreciated! Thanks!

I think you actually want to encrypt the data and not the file. Here is a link to a starting point:

http://msdn2.microsoft.com/en-us/library/ms190357.aspx

|||

Yes - that is what I meant... encrypting *data* in the MDF file.

As I wrote in my original post, I'm using data-bound controls, so I do not have a data layer that have created to pass data through - it is all being handled by the magic of Microsoft. That being said, I'm not sure how to implement the information contained in the link you provided. That seemed in line with me writing my own encryption functions and passing the data through them during read / writing to the database - which isn't an option for me using databound controls. Or is it?

|||

I've never tried using the the SQL Server 2005 encryption with databound controls but it should work as long as you can edit the query. You basically extend the query to include encryption and decryption information.

The pointer I sent you is just one of several BTW

Thursday, March 22, 2012

Encryption at the database field level

Hello Everyone

I need a solution for the following problem ASAP

Configuration
SQL 2000 ENT Edition
Client - Server Application Designed in VB

I have one filed in one of my tables in a database E.g Credit Card Number. I need this fields to be Encrypted so that no body can see and mis use that information. One option is to change the application and incorporate the encryption logic into the application. Does SQL 2000 Provides some kind of Encryption at a field level? or can i manage this thing at the database level? I desperatelly want to do it at the database level.Refer to this MSDN link (http://msdn.microsoft.com/library/en-us/dnnetsec/html/SecNetHT19.asp) about using SSL communication.

Also on SQL Server level you can use MULTI-PROTOCOL netlib with ENCRYPTION option for the security, refer to books online for more information.

Encryption and Decryption by Key

I am trying to use the encryptionbykey and decryptionbykey from the database to return a key that is used in a web application as a querystring. I can encrpyt fine. But when the value is passed back to a function as as varchar and convert it to a varbinary it does not decrypt. Below is an example:

CREATE SYMMETRIC KEY DummyKey

WITH ALGORITHM = DESX

ENCRYPTION BY PASSWORD = N'd7mmy';

GO

DECLARE @.UnsubscribeURL varchar(300)

DECLARE @.OriginalUserKey varchar(250)

DECLARE @.EncryptedUserKey varchar(250)

-- Get Unsubscribe URL

SELECT @.UnsubscribeURL = 'http://hrowdn01.paychex.com/secure/hronlineApplication/unsubscribe.aspx?UserKey='

-- Create the user key (Company_Id + '_' + Employee_Id)

SELECT @.OriginalUserKey = CONVERT(varchar, 161) + '_' + CONVERT(varchar, 3381)

-- Open Encryption key

OPEN SYMMETRIC KEY DummyKey

DECRYPTION BY PASSWORD = N'd7mmy'

-- Encrypt the user key

SELECT @.EncryptedUserKey = master.dbo.fn_varbintohexstr(EncryptByKey(Key_GUID('DummyKey'),@.OriginalUserKey))

--EXEC master..xp_blowfishencrypt @.OriginalUserKey, @.key, @.EncryptedUserKey OUTPUT

CLOSE SYMMETRIC KEY DummyKey

-- Finish creating the unsubscribe URL

SET @.UnsubscribeURL = @.UnsubscribeURL + @.EncryptedUserKey

SELECT @.UnsubscribeURL

--New function would be here

DECLARE @.decrypted_str VARBINARY(MAX)

DECLARE @.DecryptedUserKey varchar(MAX)

OPEN SYMMETRIC KEY DummyKey

DECRYPTION BY PASSWORD = N'd7mmy'

SET @.decrypted_str = CONVERT(varbinary(max),'0x002da862c3f37f449936e9a3eabc83340100000007f5728f4a1ff60d6a08a3ee30dd7d8626551f0da25d14719f4e81a00147a2d9')

SET @.DecryptedUserKey = DecryptByKey(@.decrypted_str)

-- display decrypted text

SELECT @.DecryptedUserKey AS PlainText;

-- close and drop the key

CLOSE SYMMETRIC KEY DummyKey

DROP SYMMETRIC KEY DummyKey

Thanks,

J

Jason,

I've been playing around with this a little bit.

I don't have an answer.

But from what i can tell, you're going to need a function that reverses the process of

master.dbo.fn_varbintohexstr().

It appears that just recasting that output to varbinary isn't doing what you need.

sql

Encryption and "WHERE encrypted_column LIKE"

I am starting an encryption project for my database and I'm performing
some tests on decryption speed. A lot of my application queries use a
LIKE parameter in the WHERE clause. To keep from changing my
application I am performing all the work on the back-end; creating
views, triggers and UDFs to encrypt/decrypt the data. A problem has
arisen around the LIKE parameter, though.

Currently:
SELECT SSN, FNAME, LNAME FROM USERS WHERE LNAME LIKE 'BON%'

will become:
SET @.NEWVALUE = dbo.decrypt_hash('BON%')
SELECT SSN, FNAME, LNAME FROM USERS_VIEW WHERE LNAME_HASH LIKE
@.NEWVALUE

This will not work. A hash can only compare a string value to a string
value. Has anyone else worked with this type of encryption and how did
you get around using LIKE?

Thanks,
JoshUsing TSQL to encrypt in a UDF is a non-starter. It's always going to
destroy performance because any non-trivial encryption algorithm is likely
to be unfeasibly slow implemented in TSQL.

Firstly, what is the goal of encrypting the data? Understand that encryption
is not a good way to control access to a database. There are legitimate uses
of encryption in a database but encrypting user's names seems a little
unusual. Since your example code doesn't even seem to include a key for the
decryption function I don't quite understand what you are trying to
implement here.

If you really need encryption then Google for some of the third-party
solutions available. You'll also find previous posts on this topic in the
microsoft.public.sqlserver.* hierarchy.

--
David Portas
SQL Server MVP
--|||David Portas (REMOVE_BEFORE_REPLYING_dportas@.acm.org) writes:
> Using TSQL to encrypt in a UDF is a non-starter. It's always going to
> destroy performance because any non-trivial encryption algorithm is likely
> to be unfeasibly slow implemented in TSQL.

You could call an extended stored procedure from the UDF to perform
the actual encryption. Of course, it will still be slow since the UDF
and XP calls are expensive in themselves. Then again, Encryption
and high performance do not really go well together.

As for the problem posted, I would suggest that what is needed is:

SELECT SSN, FNAME, LNAME FROM USERS_VIEW
WHERE dbo.decrypt(LNAME_HASH) LIKE 'BON%'

Which is not going to perform well at all.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se

Books Online for SQL Server SP3 at
http://www.microsoft.com/sql/techin.../2000/books.asp|||"joshsackett" <joshsackett@.gmail.com> wrote in message
news:1117212160.020006.275040@.z14g2000cwz.googlegr oups.com...
> I am starting an encryption project for my database and I'm performing
> some tests on decryption speed. A lot of my application queries use a
> LIKE parameter in the WHERE clause. To keep from changing my
> application I am performing all the work on the back-end; creating
> views, triggers and UDFs to encrypt/decrypt the data. A problem has
> arisen around the LIKE parameter, though.

I was just reading an article on this I think in this month's SQL Server
magazine.

I'll agree that encrypting last name is a bit "different".

One thing they suggested for things like credit card numbers is a) being
able to index on a column OTHER than the ccn so you can get the row(s) in
question and only decrypt that absolute minimum needed and if you DO need to
use the ccn, b) store the last 4 digits unencrypted to use that to help
narrow your search.

> Currently:
> SELECT SSN, FNAME, LNAME FROM USERS WHERE LNAME LIKE 'BON%'
> will become:
> SET @.NEWVALUE = dbo.decrypt_hash('BON%')
> SELECT SSN, FNAME, LNAME FROM USERS_VIEW WHERE LNAME_HASH LIKE
> @.NEWVALUE
> This will not work. A hash can only compare a string value to a string
> value. Has anyone else worked with this type of encryption and how did
> you get around using LIKE?
> Thanks,
> Josh|||Josh,

Hashing is not encryption, and hashing something like a last name
is useless, except for obfuscation. Only the 1,000,000 most common
last names in the world (if not 10,000) account for virtually everyone,
so if someone has a hash (say SHA1) of a last name, they basically
have the last name and can look up the hash in a small dictionary of
hashed last names. When hashing is appropriate, such as for creating
a message digest, it is not reversible. The sum of this is that
something based on the idea of "decrypting a hash" is flawed.

That said, the more you want to do efficiently with the encrypted
value, the less useful the encryption. If you can use LIKE or
other comparisons efficiently in predicates with the encrypted value,
you're letting your users play "Twenty Questions" with your data:

1. Does Secret start with the letter 'L' (LIKE 'L%')?
2. It does? Good. Does it satisfy WHERE Secret >= 'LN'?
3. No? Ok, does it satisfy WHERE Secret > 'LG'?
...

If you're just obfuscating the data with a reversible obfuscator,
you might just as well do this when someone needs a LIKE result:

select ...
from users_view
where dbo.deobfuscate(LNAME) like ' BON%'

If that's too slow, maybe you can manage to add dbo.deobfuscate(LNAME)
to the underlying table and index that computed column, hoping the
index will be used by the query. I'm not sure whether you can make
this work, but as Erland said, encryption and performance don't
go well together. Security and availability are Heisenbergian: you
can't have both, and the more of one you have, the less you have of
the other. This is as unavoidable as any law of physics.

Steve Kass
Drew University

joshsackett wrote:

> I am starting an encryption project for my database and I'm performing
> some tests on decryption speed. A lot of my application queries use a
> LIKE parameter in the WHERE clause. To keep from changing my
> application I am performing all the work on the back-end; creating
> views, triggers and UDFs to encrypt/decrypt the data. A problem has
> arisen around the LIKE parameter, though.
> Currently:
> SELECT SSN, FNAME, LNAME FROM USERS WHERE LNAME LIKE 'BON%'
> will become:
> SET @.NEWVALUE = dbo.decrypt_hash('BON%')
> SELECT SSN, FNAME, LNAME FROM USERS_VIEW WHERE LNAME_HASH LIKE
> @.NEWVALUE
> This will not work. A hash can only compare a string value to a string
> value. Has anyone else worked with this type of encryption and how did
> you get around using LIKE?
> Thanks,
> Josh|||First off, thanks to everyone who has provided their input. Secondly,
let me continue down the path I started:

My client performs searches on SSN, FNAME & LNAME. Any of these columns
can currently be included in a "LIKE" search. I am researching
encryption methods for the database that have minimal impact on the
application. The only way to accomplish this is to change the table
names, encrypt the data and create views to access the tables. The
problem (as you know) is that in order to perform a comparison on an
encrypted column is to completely decrypt the column and then compare.
This is not acceptable performance wise.

The next option is to not change the DB but the application. So to have
the application perform a search against an indexed, encrypted column I
would write (in essence)
SELECT dbo.decrypt(ENC_SSN), dbo.decrypt(ENC_FNAME),
dbo.decrypt(ENC_LNAME), ADDRESS FROM UserTable WHERE ENC_LNAME =
dbo.encrypt(SMITH) .

This is MUCH faster. The problem now is how to perform a LIKE search?
dbo.encrypt(SMITH) will look nothing like dbo.encrypt(SMI). The only
thing I can think of is to create another column containing the first 2
(or so) characters of the last name and perform a straight comparison
on that column using a SUBSTRING of the original LastNameString and
then decrypt all the matching columns and perform a like search on
those. Example:

@.LastNameString = 'WILLI%'
@.ShortLNS = SUBSTRING(@.LastNameString,1,2)

SELECT dbo.decrypt(ENC_SSN), dbo.decrypt(ENC_FNAME),
dbo.decrypt(ENC_LNAME), ADDRESS
FROM UserTable
WHERE dbo.decrypt(ENC_LNAME) LIKE @.LastNameString
AND
-- This next section limits the search result but only by
26^ShortColumnLength.
-- So in this case 26^2 = 676 unique rows (max.. assuming someone's
last name starts with "ZZ" :)
dbo.decrypt(ENC_LNAME) IN
(
SELECT dbo.decrypt(ENC_LNAME) from UserTable
WHERE SHORT_LNAME = @.ShortLNS
)|||I got it! This can be performed for every searchable column. Wrap the
entire thing in a stored procedure (expand as needed) and viola!

@.LastNameString = 'WILLI%'
@.ShortLNS = SUBSTRING(@.LastNameString,1,2)

DECLARE @.tbl_enc_lname TABLE
(enc_lname varchar(30))
INSERT INTO @.tbl_enc_lname
SELECT enc_lname FROM users WHERE short_lname = @.ShortLNS

SELECT
dbo.decrypt(enc_ssn),dbo.decrypt(enc_fname),dbo.de crypt(enc_lname),
address from users
WHERE
dbo.decrypt(enc_lname) LIKE @.LastNameString
AND
enc_lname IN
(
SELECT enc_lname from @.enc_lname_holder
)

SQL Statistics:
44 unique last names out of 100,000 rows
2,301 rows returned

SQL Server Execution Times:
CPU time = 5428 ms, elapsed time = 7118 ms.

SQL Server IOSTATS:
Table '#21D600EE'. Scan count 0, logical reads 4494, physical reads 0,
read-ahead reads 0.
Table 'users'. Scan count 2, logical reads 497, physical reads 0,
read-ahead reads 0.
Table 'users'. Scan count 2, logical reads 7234, physical reads 0,
read-ahead reads 0.
Table '#21D600EE'. Scan count 1, logical reads 22, physical reads 0,
read-ahead reads 0.

Hardware:
Single Pentium 4 - 1.7GHz
384MB RAM
Dell Inspiron 8200 Notebook
SQL Server Desktop Edition|||SELECT enc_lname from @.enc_lname_holder
should read
SELECT enc_lname from @.tbl_enc_lname|||> The only way to accomplish this is to change the table
> names, encrypt the data and create views to access the tables.

This makes no sense at all. You would be better off creating SPs to access
the data unencrypted and then denying all permissions on the base tables. As
I said before, encryption is not the way to control access to data.

--
David Portas
SQL Server MVP
--|||I agree.. what good does it do to encrypt the DB data when the method
for decrypting it exists in the database? If anyone gets the database
(which is I assume what you are worried about) they can simply use the
routine that already exists in the DB to get the data. I assume this is
some sort of privacy feature...

I will say though, that we had a product where people kept asking us if
the usernames and passwords were encrypted in the database. We got sick
of repeatedly explaining why not, so we did a simple encryption on them
so that we could say, "yes, they are" and move on to the next topic.|||David: If someone steals my physical database files or the backups then
they have access to the data, so it must be encrypted. I am not merely
trying to keep people out, I am trying ot make sure that if someone
gets the data they cannot read it.

pb: The routine to decrypt the data exists in the database but you must
run a stored procedure with the routine alias and password before your
run a query if you wish to pull unencrypted data. Check out the program
XP_CRYPT (search Google) and you'll see where I am going with this.

encryption ?

Hello,
My application will have more than 100 stored procedures and I want to use the "WITH ENCRYPTION" clause so that they are not visible to the my application's customer using EM. I will be writing the stored procedures in VS.Net server explorer to write the
se stored procedures. The problem is that if I add "WITH ENCRYP.." right there while coding the stored procedures then after saving the sto. proc. even I cannot access it, as it is encrypted. I will be using the "Create Script" utility of SQL Server to
create scripts for tables, stored procedures etc and then will execute this script on client's machines. Is there any way I can continue seeing the stored procedure but not the client.
Thanks
On Thu, 20 May 2004 12:56:03 -0700, dev wrote:

>Hello,
>My application will have more than 100 stored procedures and I want to use the "WITH ENCRYPTION" clause so that they are not visible to the my application's customer using EM. I will be writing the stored procedures in VS.Net server explorer to write th
ese stored procedures. The problem is that if I add "WITH ENCRYP.." right there while coding the stored procedures then after saving the sto. proc. even I cannot access it, as it is encrypted. I will be using the "Create Script" utility of SQL Server to
create scripts for tables, stored procedures etc and then will execute this script on client's machines. Is there any way I can continue seeing the stored procedure but not the client.
>Thanks
Hi Dev,
Two options:
1) Store your stored procedures as text files on your computers. Copy and
paste the code into and out of your development tool, unless it provides
load and save facilities (like Query Analyzer does).
2) Don't use encryption on your development database. Reexecute all
procedures with encryption on a seperate database, then ship that database
to your customers.
Best, Hugo
(Remove _NO_ and _SPAM_ to get my e-mail address)
|||Thanks Hugo,
In the 1st idea, do you mean save in separate .sql files ? The 2nd idea wont work for me I think because I won't be shipping the database, instead I will include the .sql files generated after using "Create Scripts".
dev

Wednesday, March 21, 2012

Encrypting the actual MDF file - not the data column

Hi there,
We have a website application that we needed to replicae in various laptops
for our team that does not have internet access to our production site
constantly. We wrote the application that keeps in sync the website, the
database and the relevant data between the laptop and our production server.
In order to do that, we had to replicate the production database and
production "compiled" website on the local laptop, and have the applicaion
downloading and uploading the relevant data in order to keep the whole thing
in sync. Success !!!
Now comes the problem:
At this point we have a laptop that holds a production compiled dotfuscated
website (we are ok with that) and the production database with a minimum
subset of data. This means that the Database schema and the data is open to
anybody that has access to that laptop. So what happen if the laptop gets
stolen ?
The only way we can allow that is if we find a way to encrypt somehow the
MDF file.
Constraint:
We cannot change the production website and SP code to ENCRYPT - DECRYPT
certain data columns.
So my question is ..can I secure the DB file in case the laptop get stolen?
Thanks,
FPConsider using Encrypting File System (EFS).
Tom
----
Thomas A. Moreau, BSc, PhD, MCSE, MCDBA
SQL Server MVP
Toronto, ON Canada
"Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
news:%23QK1780ZHHA.5020@.TK2MSFTNGP05.phx.gbl...
Hi there,
We have a website application that we needed to replicae in various laptops
for our team that does not have internet access to our production site
constantly. We wrote the application that keeps in sync the website, the
database and the relevant data between the laptop and our production server.
In order to do that, we had to replicate the production database and
production "compiled" website on the local laptop, and have the applicaion
downloading and uploading the relevant data in order to keep the whole thing
in sync. Success !!!
Now comes the problem:
At this point we have a laptop that holds a production compiled dotfuscated
website (we are ok with that) and the production database with a minimum
subset of data. This means that the Database schema and the data is open to
anybody that has access to that laptop. So what happen if the laptop gets
stolen ?
The only way we can allow that is if we find a way to encrypt somehow the
MDF file.
Constraint:
We cannot change the production website and SP code to ENCRYPT - DECRYPT
certain data columns.
So my question is ..can I secure the DB file in case the laptop get stolen?
Thanks,
FP|||Tom,
With EFS, would my local application be able to connect and run queries
normally?
"Tom Moreau" <tom@.dont.spam.me.cips.ca> wrote in message
news:eYxH5O1ZHHA.4000@.TK2MSFTNGP02.phx.gbl...
> Consider using Encrypting File System (EFS).
> --
> Tom
> ----
> Thomas A. Moreau, BSc, PhD, MCSE, MCDBA
> SQL Server MVP
> Toronto, ON Canada
> "Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
> news:%23QK1780ZHHA.5020@.TK2MSFTNGP05.phx.gbl...
> Hi there,
> We have a website application that we needed to replicae in various
> laptops
> for our team that does not have internet access to our production site
> constantly. We wrote the application that keeps in sync the website, the
> database and the relevant data between the laptop and our production
> server.
> In order to do that, we had to replicate the production database and
> production "compiled" website on the local laptop, and have the applicaion
> downloading and uploading the relevant data in order to keep the whole
> thing
> in sync. Success !!!
> Now comes the problem:
> At this point we have a laptop that holds a production compiled
> dotfuscated
> website (we are ok with that) and the production database with a minimum
> subset of data. This means that the Database schema and the data is open
> to
> anybody that has access to that laptop. So what happen if the laptop gets
> stolen ?
> The only way we can allow that is if we find a way to encrypt somehow the
> MDF file.
> Constraint:
> We cannot change the production website and SP code to ENCRYPT - DECRYPT
> certain data columns.
> So my question is ..can I secure the DB file in case the laptop get
> stolen?
> Thanks,
> FP
>
>|||Also,
Since I do need to keep in sync the local DB and sometimes I need to "drop"
it and then recreate an empty one, would I be able to programmatically
encrypt the file using EFS?
If so, do you have a code sample (possibly in C#)?
Thanks again,
Filippo
"Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
news:uar7Yq1ZHHA.4872@.TK2MSFTNGP03.phx.gbl...
> Tom,
> With EFS, would my local application be able to connect and run queries
> normally?
>
> "Tom Moreau" <tom@.dont.spam.me.cips.ca> wrote in message
> news:eYxH5O1ZHHA.4000@.TK2MSFTNGP02.phx.gbl...
>|||You'd have SQL running under a domain account and that account would then be
writing files (data and log) on the disk. If you copy files to be attached
or restores, be sure to use that same domain account.
How you connect to SQL Server doesn't matter. The login that you use to
talk to SQL Server isn't the account that writes to those files. The SQL
Server service account is.
Tom
----
Thomas A. Moreau, BSc, PhD, MCSE, MCDBA, MCITP, MCTS
SQL Server MVP
Toronto, ON Canada
.
"Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
news:uar7Yq1ZHHA.4872@.TK2MSFTNGP03.phx.gbl...
Tom,
With EFS, would my local application be able to connect and run queries
normally?
"Tom Moreau" <tom@.dont.spam.me.cips.ca> wrote in message
news:eYxH5O1ZHHA.4000@.TK2MSFTNGP02.phx.gbl...
> Consider using Encrypting File System (EFS).
> --
> Tom
> ----
> Thomas A. Moreau, BSc, PhD, MCSE, MCDBA
> SQL Server MVP
> Toronto, ON Canada
> "Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
> news:%23QK1780ZHHA.5020@.TK2MSFTNGP05.phx.gbl...
> Hi there,
> We have a website application that we needed to replicae in various
> laptops
> for our team that does not have internet access to our production site
> constantly. We wrote the application that keeps in sync the website, the
> database and the relevant data between the laptop and our production
> server.
> In order to do that, we had to replicate the production database and
> production "compiled" website on the local laptop, and have the applicaion
> downloading and uploading the relevant data in order to keep the whole
> thing
> in sync. Success !!!
> Now comes the problem:
> At this point we have a laptop that holds a production compiled
> dotfuscated
> website (we are ok with that) and the production database with a minimum
> subset of data. This means that the Database schema and the data is open
> to
> anybody that has access to that laptop. So what happen if the laptop gets
> stolen ?
> The only way we can allow that is if we find a way to encrypt somehow the
> MDF file.
> Constraint:
> We cannot change the production website and SP code to ENCRYPT - DECRYPT
> certain data columns.
> So my question is ..can I secure the DB file in case the laptop get
> stolen?
> Thanks,
> FP
>
>|||You wouldn't encrypt it programmatically. It's done automatically.
Tom
----
Thomas A. Moreau, BSc, PhD, MCSE, MCDBA, MCITP, MCTS
SQL Server MVP
Toronto, ON Canada
.
"Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
news:O5Il8p%23ZHHA.1300@.TK2MSFTNGP02.phx.gbl...
Also,
Since I do need to keep in sync the local DB and sometimes I need to "drop"
it and then recreate an empty one, would I be able to programmatically
encrypt the file using EFS?
If so, do you have a code sample (possibly in C#)?
Thanks again,
Filippo
"Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
news:uar7Yq1ZHHA.4872@.TK2MSFTNGP03.phx.gbl...
> Tom,
> With EFS, would my local application be able to connect and run queries
> normally?
>
> "Tom Moreau" <tom@.dont.spam.me.cips.ca> wrote in message
> news:eYxH5O1ZHHA.4000@.TK2MSFTNGP02.phx.gbl...
>|||Also have a look at:
http://technet.microsoft.com/en-us/.../aa906017.aspx, for a new
technology that would be helpful in this scenario.
Thanks
Laurentiu Cristofor [MSFT]
Software Development Engineer
SQL Server Engine
http://blogs.msdn.com/lcris/
This posting is provided "AS IS" with no warranties, and confers no rights.
"Tom Moreau" <tom@.dont.spam.me.cips.ca> wrote in message
news:%23DmRu$MaHHA.4552@.TK2MSFTNGP05.phx.gbl...
> You'd have SQL running under a domain account and that account would then
> be
> writing files (data and log) on the disk. If you copy files to be
> attached
> or restores, be sure to use that same domain account.
> How you connect to SQL Server doesn't matter. The login that you use to
> talk to SQL Server isn't the account that writes to those files. The SQL
> Server service account is.
> --
> Tom
> ----
> Thomas A. Moreau, BSc, PhD, MCSE, MCDBA, MCITP, MCTS
> SQL Server MVP
> Toronto, ON Canada
> .
> "Hey it's Filippo" <pandiani69@.hotmail.com> wrote in message
> news:uar7Yq1ZHHA.4872@.TK2MSFTNGP03.phx.gbl...
> Tom,
> With EFS, would my local application be able to connect and run queries
> normally?
>
> "Tom Moreau" <tom@.dont.spam.me.cips.ca> wrote in message
> news:eYxH5O1ZHHA.4000@.TK2MSFTNGP02.phx.gbl...
>

Encrypting Field in Database

I have existing application that we need to encrypt the field that stores
the user password. This is a SQL Server 2000 database that has a table
that stores userid and passwords.
Please let me know the procedures that I need to implement to encrypt the
password field.
Thanks,Refer to the Encryption section in the following FAQ:
http://www.sqlsecurity.com/DesktopDefault.aspx?tabid=22
-Sue
On Thu, 27 Oct 2005 09:32:13 -0700, Joe K. <Joe
K.@.discussions.microsoft.com> wrote:

>I have existing application that we need to encrypt the field that stores
>the user password. This is a SQL Server 2000 database that has a table
>that stores userid and passwords.
>Please let me know the procedures that I need to implement to encrypt the
>password field.
>Thanks,|||Hi,
refer and visit my site www.activecrypt.com .
Regards
--
Andy Davis
Activecrypt Team
---
SQL Server Encryption Software
http://www.activecrypt.com
"Sue Hoegemeier" wrote:

> Refer to the Encryption section in the following FAQ:
> http://www.sqlsecurity.com/DesktopDefault.aspx?tabid=22
> -Sue
> On Thu, 27 Oct 2005 09:32:13 -0700, Joe K. <Joe
> K.@.discussions.microsoft.com> wrote:
>
>

Encrypting Data

I have an application that has stores sensitive data in an SQL server and I am currently handling this through my ASP.NET application using the encryption classes in C#.

One of the things we would eventually like to be able to do is use other programs (like Microsoft Access) to run advanced Querys on the tables and retrive the data. With the encyption being done in C#/ASP all that would be returned would be the encrypted data.

I wondering if there is a way to build a layer to encrypt/decrypt data at the database level, my searches haven't yeiled to much info (As well as a trip to Borders) as I haven't seen any books that even touch on this.

I don't know a lot about SQL right now (Mainly only MySQL so Stored Procs and all that stuff are really new to me) so I don't know if I would go about it this way or not? (Using a stored procedure)

Can anyone reccommened where I should start to learn about accomplishing this? Books are usually the best help but I'll take any kind of information that can be thrown my way :-)

Thanks!ummm... what are you encrypting? and does it NEED to be encrypted up the wazoo?|||Yes, It needs to be encrypted. No matter what it is there should be a way to encrypt it correct?|||Sorry, To add to that what are my other options? I know there are user access controls (although never have worked with them) and that type of stuff but one thing that worried me would be using access control, right now as it is I can remote desktop to the SQL machine open enterprise manager and browse the tables. (No password needed) I'm all for doing it the correct way. But part of the thing to is even though I'm writing the program because it's encrypted I never have to see the data.

encrypting connections to sql server 2005

can you please tell me how can i encrypt data sent between client application and sql server 2005.Hi,

thats quite easy, you can do this on the protocol layer:

http://support.microsoft.com/kb/316898/en-us

HTH, Jens K. Suessmeyer.

http://www.sqlserver2005.de|||can i not enable encryption without installing any certificate?|||

No, a certificate is needed in order to use SSL. I am including additional links that may be useful.

· Encrypting Connections to SQL Server http://msdn2.microsoft.com/en-us/library/ms189067.aspx

· SSL Certificates http://msdn2.microsoft.com/en-gb/library/aa364691.aspx (This one makes reference to SSL for HTTP connections, but the main explanation and description of how SSL uses certificates are common)

· Configuring Certificate for Use by SSL http://msdn2.microsoft.com/en-us/library/ms186362.aspx

I hope this information will be useful.

-Raul Garcia

SDE/T

SQL Server Engine

|||

Hi,

there is no must to buy a public trusted certificate if you don′t need it somewhere outside your company and that fits your secuirty needs, you can also create a certificate on your own.

HTH, Jens K. Suessmeyer.

http://www.sqlserver2005.de

sql

Monday, March 19, 2012

encrypting a database ?

Hi,
does it possible to encrypt an entire database?
I know when can encrypt SP
we have to deploy a home made application based on SQL 2000 but we want to
hide the structure of the database to the users AND the administrators
They can just access the table (for reporting access), but not seeing the
relations, indexes and specific configuration tables.
does it possible?
Thanks.
Jerome.
You can use some 3rd party products. Check, for example, those sites:
http://www.netlib.com/sql-server-encryption.shtml
http://www.ecatenate.com/dblockdown_product_info.html
Dejan Sarka, SQL Server MVP
Associate Mentor
Solid Quality Learning
More than just Training
www.SolidQualityLearning.com
"Jj" <willgart@.BBBhotmailAAA.com> wrote in message
news:uFC1PjAhEHA.632@.tk2msftngp13.phx.gbl...
> Hi,
> does it possible to encrypt an entire database?
> I know when can encrypt SP
> we have to deploy a home made application based on SQL 2000 but we want to
> hide the structure of the database to the users AND the administrators
> They can just access the table (for reporting access), but not seeing the
> relations, indexes and specific configuration tables.
> does it possible?
> Thanks.
> Jerome.
>

encrypting a database ?

Hi,
does it possible to encrypt an entire database?
I know when can encrypt SP
we have to deploy a home made application based on SQL 2000 but we want to
hide the structure of the database to the users AND the administrators
They can just access the table (for reporting access), but not seeing the
relations, indexes and specific configuration tables.
does it possible?
Thanks.
Jerome.You can use some 3rd party products. Check, for example, those sites:
http://www.netlib.com/sql-server-encryption.shtml
http://www.ecatenate.com/dblockdown_product_info.html
Dejan Sarka, SQL Server MVP
Associate Mentor
Solid Quality Learning
More than just Training
www.SolidQualityLearning.com
"Jj" <willgart@.BBBhotmailAAA.com> wrote in message
news:uFC1PjAhEHA.632@.tk2msftngp13.phx.gbl...
> Hi,
> does it possible to encrypt an entire database?
> I know when can encrypt SP
> we have to deploy a home made application based on SQL 2000 but we want to
> hide the structure of the database to the users AND the administrators
> They can just access the table (for reporting access), but not seeing the
> relations, indexes and specific configuration tables.
> does it possible?
> Thanks.
> Jerome.
>

encrypting a database ?

Hi,
does it possible to encrypt an entire database?
I know when can encrypt SP
we have to deploy a home made application based on SQL 2000 but we want to
hide the structure of the database to the users AND the administrators
They can just access the table (for reporting access), but not seeing the
relations, indexes and specific configuration tables.
does it possible?
Thanks.
Jerome.You can use some 3rd party products. Check, for example, those sites:
http://www.netlib.com/sql-server-encryption.shtml
http://www.ecatenate.com/dblockdown_product_info.html
--
Dejan Sarka, SQL Server MVP
Associate Mentor
Solid Quality Learning
More than just Training
www.SolidQualityLearning.com
"Jéjé" <willgart@.BBBhotmailAAA.com> wrote in message
news:uFC1PjAhEHA.632@.tk2msftngp13.phx.gbl...
> Hi,
> does it possible to encrypt an entire database?
> I know when can encrypt SP
> we have to deploy a home made application based on SQL 2000 but we want to
> hide the structure of the database to the users AND the administrators
> They can just access the table (for reporting access), but not seeing the
> relations, indexes and specific configuration tables.
> does it possible?
> Thanks.
> Jerome.
>

Sunday, March 11, 2012

Encrypted Connection

Hi all,
If this is not the correct groups to post this, please redirect me.
I have a .NET application and SQL Server 2005 Express running on a Windows
Server 2003 Web Edition. Both connect to a remote SQL Server 2000 database
running on Windows 2000.
SQL Server Express 2005 has the 2000 server set up as a linked server.
What are my options for encrypting the connections to the SQL Server 2000?
For the .NET app, I assume that I can use multiprotocol. Correct? Other
suggestions?
What about the SQL Server 2005 linked server to 2000?
TIA
AG
Email: discuss at adhdata dot com
SQL Server supports SSL encryption for connections. See the following
articles:
http://support.microsoft.com/kb/276553
http://msdn2.microsoft.com/en-us/library/ms189067.aspx
http://msdn2.microsoft.com/en-us/library/ms191192.aspx
Regards,
Plamen Ratchev
http://www.SQLStudio.com
"AG" <NOSPAMa-giam@.newsgroups.nospam> wrote in message
news:%23JeihNoKHHA.960@.TK2MSFTNGP04.phx.gbl...
> Hi all,
> If this is not the correct groups to post this, please redirect me.
> I have a .NET application and SQL Server 2005 Express running on a Windows
> Server 2003 Web Edition. Both connect to a remote SQL Server 2000 database
> running on Windows 2000.
> SQL Server Express 2005 has the 2000 server set up as a linked server.
> What are my options for encrypting the connections to the SQL Server 2000?
> For the .NET app, I assume that I can use multiprotocol. Correct? Other
> suggestions?
> What about the SQL Server 2005 linked server to 2000?
> TIA
> --
> AG
> Email: discuss at adhdata dot com
>
>
|||Thanks for the quick response Plamen,
That all requires a SSL cert, which the 2000 server does not have.
Is there some way to use multiprotocol with the linked server?
The current setup is using a VPN, but we are moving to a new server and
there may be a problem setting up a VPN.
AG
Email: discuss at adhdata dot com
"Plamen Ratchev" <Plamen@.SQLStudio.com> wrote in message
news:Oyn6mApKHHA.4992@.TK2MSFTNGP04.phx.gbl...
> SQL Server supports SSL encryption for connections. See the following
> articles:
> http://support.microsoft.com/kb/276553
> http://msdn2.microsoft.com/en-us/library/ms189067.aspx
> http://msdn2.microsoft.com/en-us/library/ms191192.aspx
> Regards,
> Plamen Ratchev
> http://www.SQLStudio.com
>
> "AG" <NOSPAMa-giam@.newsgroups.nospam> wrote in message
> news:%23JeihNoKHHA.960@.TK2MSFTNGP04.phx.gbl...
>
|||The multiprotocol has been depreciated in SQL Server 2005. See this post for
details (look under the Changes section):
http://blogs.msdn.com/sql_protocols/archive/2005/09/22/473111.aspx
If you do not have a local Certificate Server you can always purchase a
third-party certificate.
Regards,
Plamen Ratchev
http://www.SQLStudio.com
"AG" <NOSPAMa-giam@.newsgroups.nospam> wrote in message
news:%23kAVctpKHHA.4384@.TK2MSFTNGP03.phx.gbl...
> Thanks for the quick response Plamen,
> That all requires a SSL cert, which the 2000 server does not have.
> Is there some way to use multiprotocol with the linked server?
> The current setup is using a VPN, but we are moving to a new server and
> there may be a problem setting up a VPN.
> --
> AG
> Email: discuss at adhdata dot com
>
> "Plamen Ratchev" <Plamen@.SQLStudio.com> wrote in message
> news:Oyn6mApKHHA.4992@.TK2MSFTNGP04.phx.gbl...
>
|||Hello AG,
I agree with Plamen that you could use a third party certificate if
necessary.
Also, you may consider configure IPsec between the servers so that all IP
traffic is protected between them. Pleas esee the following articles for
more details:
TechNet Support WebCast: How to use IPSec to help secure network traffic
http://support.microsoft.com/default.aspx?kbid=888266
IPsec
http://www.microsoft.com/technet/network/ipsec/default.mspx
If you have further comments or feedback, please feel free to let's know.
Thank you.
Best Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Community Support
==================================================
Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications
<http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx>.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
<http://msdn.microsoft.com/subscriptions/support/default.aspx>.
==================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
|||Thanks Peter,
Sorry, I did not get back to you sooner. I wanted to get the client's
networking person involved and that will happen today.
IPsec looks like it might do the job.
AG
Email: discuss at adhdata dot com
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:Jj1YdPvKHHA.2304@.TK2MSFTNGHUB02.phx.gbl...
> Hello AG,
> I agree with Plamen that you could use a third party certificate if
> necessary.
> Also, you may consider configure IPsec between the servers so that all IP
> traffic is protected between them. Pleas esee the following articles for
> more details:
> TechNet Support WebCast: How to use IPSec to help secure network traffic
> http://support.microsoft.com/default.aspx?kbid=888266
> IPsec
> http://www.microsoft.com/technet/network/ipsec/default.mspx
> If you have further comments or feedback, please feel free to let's know.
> Thank you.
> Best Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Community Support
> ==================================================
> Get notification to my posts through email? Please refer to
> http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
> ications
> <http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx>.
> Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
> where an initial response from the community or a Microsoft Support
> Engineer within 1 business day is acceptable. Please note that each follow
> up response may take approximately 2 business days as the support
> professional working with you may need further investigation to reach the
> most efficient resolution. The offering is not appropriate for situations
> that require urgent, real-time or phone-based interactions or complex
> project analysis and dump analysis issues. Issues of this nature are best
> handled working with a dedicated Microsoft Support Engineer by contacting
> Microsoft Customer Support Services (CSS) at
> <http://msdn.microsoft.com/subscriptions/support/default.aspx>.
> ==================================================
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>

Encrypted Connection

Hi all,
If this is not the correct groups to post this, please redirect me.
I have a .NET application and SQL Server 2005 Express running on a Windows
Server 2003 Web Edition. Both connect to a remote SQL Server 2000 database
running on Windows 2000.
SQL Server Express 2005 has the 2000 server set up as a linked server.
What are my options for encrypting the connections to the SQL Server 2000?
For the .NET app, I assume that I can use multiprotocol. Correct? Other
suggestions?
What about the SQL Server 2005 linked server to 2000?
TIA
AG
Email: discuss at adhdata dot comSQL Server supports SSL encryption for connections. See the following
articles:
http://support.microsoft.com/kb/276553
http://msdn2.microsoft.com/en-us/library/ms189067.aspx
http://msdn2.microsoft.com/en-us/library/ms191192.aspx
Regards,
Plamen Ratchev
http://www.SQLStudio.com
"AG" <NOSPAMa-giam@.newsgroups.nospam> wrote in message
news:%23JeihNoKHHA.960@.TK2MSFTNGP04.phx.gbl...
> Hi all,
> If this is not the correct groups to post this, please redirect me.
> I have a .NET application and SQL Server 2005 Express running on a Windows
> Server 2003 Web Edition. Both connect to a remote SQL Server 2000 database
> running on Windows 2000.
> SQL Server Express 2005 has the 2000 server set up as a linked server.
> What are my options for encrypting the connections to the SQL Server 2000?
> For the .NET app, I assume that I can use multiprotocol. Correct? Other
> suggestions?
> What about the SQL Server 2005 linked server to 2000?
> TIA
> --
> AG
> Email: discuss at adhdata dot com
>
>|||Thanks for the quick response Plamen,
That all requires a SSL cert, which the 2000 server does not have.
Is there some way to use multiprotocol with the linked server?
The current setup is using a VPN, but we are moving to a new server and
there may be a problem setting up a VPN.
AG
Email: discuss at adhdata dot com
"Plamen Ratchev" <Plamen@.SQLStudio.com> wrote in message
news:Oyn6mApKHHA.4992@.TK2MSFTNGP04.phx.gbl...
> SQL Server supports SSL encryption for connections. See the following
> articles:
> http://support.microsoft.com/kb/276553
> http://msdn2.microsoft.com/en-us/library/ms189067.aspx
> http://msdn2.microsoft.com/en-us/library/ms191192.aspx
> Regards,
> Plamen Ratchev
> http://www.SQLStudio.com
>
> "AG" <NOSPAMa-giam@.newsgroups.nospam> wrote in message
> news:%23JeihNoKHHA.960@.TK2MSFTNGP04.phx.gbl...
>|||The multiprotocol has been depreciated in SQL Server 2005. See this post for
details (look under the Changes section):
http://blogs.msdn.com/sql_protocols.../22/473111.aspx
If you do not have a local Certificate Server you can always purchase a
third-party certificate.
Regards,
Plamen Ratchev
http://www.SQLStudio.com
"AG" <NOSPAMa-giam@.newsgroups.nospam> wrote in message
news:%23kAVctpKHHA.4384@.TK2MSFTNGP03.phx.gbl...
> Thanks for the quick response Plamen,
> That all requires a SSL cert, which the 2000 server does not have.
> Is there some way to use multiprotocol with the linked server?
> The current setup is using a VPN, but we are moving to a new server and
> there may be a problem setting up a VPN.
> --
> AG
> Email: discuss at adhdata dot com
>
> "Plamen Ratchev" <Plamen@.SQLStudio.com> wrote in message
> news:Oyn6mApKHHA.4992@.TK2MSFTNGP04.phx.gbl...
>|||Hello AG,
I agree with Plamen that you could use a third party certificate if
necessary.
Also, you may consider configure IPsec between the servers so that all IP
traffic is protected between them. Pleas esee the following articles for
more details:
TechNet Support WebCast: How to use IPSec to help secure network traffic
http://support.microsoft.com/default.aspx?kbid=888266
IPsec
http://www.microsoft.com/technet/ne...ec/default.mspx
If you have further comments or feedback, please feel free to let's know.
Thank you.
Best Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Community Support
========================================
==========
Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/subscript...ault.aspx#notif
ications
<http://msdn.microsoft.com/subscript...ps/default.aspx>.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
<http://msdn.microsoft.com/subscript...rt/default.aspx>.
========================================
==========
This posting is provided "AS IS" with no warranties, and confers no rights.|||Thanks Peter,
Sorry, I did not get back to you sooner. I wanted to get the client's
networking person involved and that will happen today.
IPsec looks like it might do the job.
AG
Email: discuss at adhdata dot com
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:Jj1YdPvKHHA.2304@.TK2MSFTNGHUB02.phx.gbl...
> Hello AG,
> I agree with Plamen that you could use a third party certificate if
> necessary.
> Also, you may consider configure IPsec between the servers so that all IP
> traffic is protected between them. Pleas esee the following articles for
> more details:
> technet Support WebCast: How to use IPSec to help secure network traffic
> http://support.microsoft.com/default.aspx?kbid=888266
> IPsec
> http://www.microsoft.com/technet/ne...ec/default.mspx
> If you have further comments or feedback, please feel free to let's know.
> Thank you.
> Best Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Community Support
> ========================================
==========
> Get notification to my posts through email? Please refer to
> l]
> ications
> <[url]http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx" target="_blank">http://msdn.microsoft.com/subscript...ps/default.aspx>.
> Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
> where an initial response from the community or a Microsoft Support
> Engineer within 1 business day is acceptable. Please note that each follow
> up response may take approximately 2 business days as the support
> professional working with you may need further investigation to reach the
> most efficient resolution. The offering is not appropriate for situations
> that require urgent, real-time or phone-based interactions or complex
> project analysis and dump analysis issues. Issues of this nature are best
> handled working with a dedicated Microsoft Support Engineer by contacting
> Microsoft Customer Support Services (CSS) at
> <http://msdn.microsoft.com/subscript...rt/default.aspx>.
> ========================================
==========
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>