Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

How to save database parameters for ASP.NET application

Posted on 2011-03-14
5
Medium Priority
?
511 Views
Last Modified: 2012-05-11
Hi,

we have a ASP.NET application (developped in VB 2008) that needs to connect to a remote SQL Server 2008 Express database. Application will be deploy on a Windows 7 Pro and a Windows 2008 64-bits server. What is the best way to save the database connection parameters? Those parameters cannot be hardcoded and neither kept into the registry.

thanks for your time and help
0
Comment
Question by:Dominic34
5 Comments
 
LVL 23

Assisted Solution

by:Saqib Khan
Saqib Khan earned 1000 total points
ID: 35131674
I would encrypt the parameter information and then would save them into web.config file

web.config cannot be accessed by web users, and if someone has access to server they can not read anythign as long as parameter info is encrypted.
http://www.google.com/url?sa=t&source=web&cd=1&ved=0CB8QFjAA&url=http%3A%2F%2Fwww.codeproject.com%2FKB%2Fsecurity%2FSimpleEncryption.aspx&rct=j&q=asp.net%20encryption&ei=rmd-TcfKMOe70QGxqtTbAw&usg=AFQjCNF0WU4IWqUtlcElDzpRRdFD0gJMiQ&cad=rjt
0
 
LVL 1

Accepted Solution

by:
pjbaratelli earned 1000 total points
ID: 35131699
Read this article for storing information in webconfigs.

http://peterkellner.net/2008/02/23/webconfigbestpractice/

Encrypting the information is a very good idea.

Almost all my site settings are stored in the Registry.  This was done to avoid the security team from hacking into the web.config file years ago (At the beginning, Framework 1.0).   To date, no one has penetrated this (we have had several penetration tests).  Here is the sample code.  

The one Administrative benefit for this method is management of settings is easier for a network administrator as well as moving the sites from one server to another (or so I have been told ).

Below is some sample code to store information in the registry.  You will need to give read permissions to some account (ask the system administrator, but  I think it is network services)

Imports System.Runtime.InteropServices
Imports System.Net
Imports System.IO
Imports System.Security.Permissions
Imports Microsoft.Win32
Imports System.Data

<Assembly: RegistryPermissionAttribute(SecurityAction.RequestMinimum, ViewAndModify:="HKEY_LOCAL_MACHINE")> 

Public Class RcisWebConfig
    ' Standard private variables
    Private p_RegistryPath As String = "SOFTWARE\[CompanyName]\[AppName]"
    Private p_RegistryKey As RegistryKey

    ' Custom private variables
    Private p_DBConnectionString As String


#Region "Properties"

    Public ReadOnly Property DBConnectionString() As String

        Get
            Return Me.p_DBConnectionString
        End Get

    End Property

#End Region

#Region "Constructors"

    Public Sub New()

        Me.p_DBConnectionString = "Initialized"
        Me.LoadSettings()

    End Sub

#End Region

    Private Sub LoadSettings()

        p_RegistryKey = Registry.LocalMachine.OpenSubKey(p_RegistryPath)
        Me.p_DBConnectionString = Me.p_RegistryKey.GetValue("DBConnectionString").ToString()

    End Sub

End Class

Open in new window

0
 
LVL 12

Expert Comment

by:mwochnick
ID: 35132706
0
 

Author Closing Comment

by:Dominic34
ID: 35137211
thanks for the replies. We will use the web.config and we will also look for encrypted registry. thanks for the links mwochnick, it could certainly be really usefull.
0

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick way to get a menu to work on our website, is using the Menu control and assign it to a web.sitemap using SiteMapDataSource. Example of web.sitemap file: (CODE) Sample code to add to the page menu: (CODE) Running the application, we wi…
User art_snob (http://www.experts-exchange.com/M_6114203.html) encountered strange behavior of Android Web browser on his Mobile Web site. It took a while to find the true cause. It happens so, that the Android Web browser (at least up to OS ver. 2.…
this video summaries big data hadoop online training demo (http://onlineitguru.com/big-data-hadoop-online-training-placement.html) , and covers basics in big data hadoop .
Loops Section Overview
Suggested Courses

963 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question