Solved

How to save database parameters for ASP.NET application

Posted on 2011-03-14
5
503 Views
Last Modified: 2012-05-11
Hi,

we have a ASP.NET application (developped in VB 2008) that needs to connect to a remote SQL Server 2008 Express database. Application will be deploy on a Windows 7 Pro and a Windows 2008 64-bits server. What is the best way to save the database connection parameters? Those parameters cannot be hardcoded and neither kept into the registry.

thanks for your time and help
0
Comment
Question by:Dominic34
5 Comments
 
LVL 23

Assisted Solution

by:Saqib Khan
Saqib Khan earned 250 total points
ID: 35131674
I would encrypt the parameter information and then would save them into web.config file

web.config cannot be accessed by web users, and if someone has access to server they can not read anythign as long as parameter info is encrypted.
http://www.google.com/url?sa=t&source=web&cd=1&ved=0CB8QFjAA&url=http%3A%2F%2Fwww.codeproject.com%2FKB%2Fsecurity%2FSimpleEncryption.aspx&rct=j&q=asp.net%20encryption&ei=rmd-TcfKMOe70QGxqtTbAw&usg=AFQjCNF0WU4IWqUtlcElDzpRRdFD0gJMiQ&cad=rjt
0
 
LVL 1

Accepted Solution

by:
pjbaratelli earned 250 total points
ID: 35131699
Read this article for storing information in webconfigs.

http://peterkellner.net/2008/02/23/webconfigbestpractice/

Encrypting the information is a very good idea.

Almost all my site settings are stored in the Registry.  This was done to avoid the security team from hacking into the web.config file years ago (At the beginning, Framework 1.0).   To date, no one has penetrated this (we have had several penetration tests).  Here is the sample code.  

The one Administrative benefit for this method is management of settings is easier for a network administrator as well as moving the sites from one server to another (or so I have been told ).

Below is some sample code to store information in the registry.  You will need to give read permissions to some account (ask the system administrator, but  I think it is network services)

Imports System.Runtime.InteropServices
Imports System.Net
Imports System.IO
Imports System.Security.Permissions
Imports Microsoft.Win32
Imports System.Data

<Assembly: RegistryPermissionAttribute(SecurityAction.RequestMinimum, ViewAndModify:="HKEY_LOCAL_MACHINE")> 

Public Class RcisWebConfig
    ' Standard private variables
    Private p_RegistryPath As String = "SOFTWARE\[CompanyName]\[AppName]"
    Private p_RegistryKey As RegistryKey

    ' Custom private variables
    Private p_DBConnectionString As String


#Region "Properties"

    Public ReadOnly Property DBConnectionString() As String

        Get
            Return Me.p_DBConnectionString
        End Get

    End Property

#End Region

#Region "Constructors"

    Public Sub New()

        Me.p_DBConnectionString = "Initialized"
        Me.LoadSettings()

    End Sub

#End Region

    Private Sub LoadSettings()

        p_RegistryKey = Registry.LocalMachine.OpenSubKey(p_RegistryPath)
        Me.p_DBConnectionString = Me.p_RegistryKey.GetValue("DBConnectionString").ToString()

    End Sub

End Class

Open in new window

0
 
LVL 12

Expert Comment

by:mwochnick
ID: 35132654
0
 
LVL 12

Expert Comment

by:mwochnick
ID: 35132706
0
 

Author Closing Comment

by:Dominic34
ID: 35137211
thanks for the replies. We will use the web.config and we will also look for encrypted registry. thanks for the links mwochnick, it could certainly be really usefull.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article discusses the ASP.NET AJAX ModalPopupExtender control. In this article we will show how to use the ModalPopupExtender control, how to display/show/call the ASP.NET AJAX ModalPopupExtender control from javascript, how to show/display/cal…
In this Article, I will provide a few tips in problem and solution manner. Opening an ASPX page in Visual studio 2003 is very slow. To make it fast, please do follow below steps:   Open the Solution/Project. Right click the ASPX file to b…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question