Solved

## Encrypting information being sent to MS SQL database over the internet.

Posted on 2004-03-21
5
222 Views
Last Modified: 2010-04-15
Hello,

I have a software application written in c# that accesses a database over the internet.  I need a way of encrypting the information being sent back and forth between the application and the database.  We also have a web application running off of the same database, and for this we are using an SSL certificate.  Is there anyway to incorporate this certificate into the application?  I would prefer not to encrypt the information in the database, just the transmission.

Thanks for your help.
0
Comment
Question by:FTIISD
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 12

Expert Comment

by:esteban_felipe
ID: 10647008
Hi FTIISD,

How is the information being sent/recieve?. Remoting? proxy objects?.. or are you opening a db connection to a server over the internet?

Esteban Felipe
www.estebanf.com
0
 
LVL 20

Accepted Solution

by:
TheAvenger earned 500 total points
ID: 10647523
Check this out: using SSL to secure communication with SQL Server 2000:

http://msdn.microsoft.com/library/en-us/dnnetsec/html/SecNetHT19.asp
0
 
LVL 7

Expert Comment

by:jj819430
ID: 10650676
If the server is certified and running your app then yes you can run off of its certification. But it depends on the certificate as to how you go about this. Another option is to put another application on the SQL server that acts as an intermediary with your application, and then you can simply throw a plugin that uses Public or Private key encryption (whatever you want) on to it. Just make sure you don't use anything labeled as "Proprietary" just stick to what is tried and true, for example RSA.
0
 

Author Comment

by:FTIISD
ID: 10680025
Hi,

Thanks for all your help.  The information is currently being stored at a hosting company.  They will not enable the encryption for me.  We are in the process of removing it from them, and placing it on a local server.  When this is done, (within the next couple of days) I will be able to attempt these methods.

Thanks
0
 
LVL 2

Expert Comment

by:eric_duncan
ID: 10691584
If you are putting the database on a local server, you might not want to encrypt the transmissions at all if you KNOW that your firewall settings are strong and your network is secure. Encryption on a database connection will affect performance considerably, so I wouldn't do it unless I had to.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Extention Methods in C# 3.0 by Ivo Stoykov C# 3.0 offers extension methods. They allow extending existing classes without changing the class's source code or relying on inheritance. These are static methods invoked as instance method. This…
This article describes a simple method to resize a control at runtime.  It includes ready-to-use source code and a complete sample demonstration application.  We'll also talk about C# Extension Methods. Introduction In one of my applications…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question