Solved

How to save database parameters for ASP.NET application

Posted on 2011-03-14
5
504 Views
Last Modified: 2012-05-11
Hi,

we have a ASP.NET application (developped in VB 2008) that needs to connect to a remote SQL Server 2008 Express database. Application will be deploy on a Windows 7 Pro and a Windows 2008 64-bits server. What is the best way to save the database connection parameters? Those parameters cannot be hardcoded and neither kept into the registry.

thanks for your time and help
0
Comment
Question by:Dominic34
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 23

Assisted Solution

by:Saqib Khan
Saqib Khan earned 250 total points
ID: 35131674
I would encrypt the parameter information and then would save them into web.config file

web.config cannot be accessed by web users, and if someone has access to server they can not read anythign as long as parameter info is encrypted.
http://www.google.com/url?sa=t&source=web&cd=1&ved=0CB8QFjAA&url=http%3A%2F%2Fwww.codeproject.com%2FKB%2Fsecurity%2FSimpleEncryption.aspx&rct=j&q=asp.net%20encryption&ei=rmd-TcfKMOe70QGxqtTbAw&usg=AFQjCNF0WU4IWqUtlcElDzpRRdFD0gJMiQ&cad=rjt
0
 
LVL 1

Accepted Solution

by:
pjbaratelli earned 250 total points
ID: 35131699
Read this article for storing information in webconfigs.

http://peterkellner.net/2008/02/23/webconfigbestpractice/

Encrypting the information is a very good idea.

Almost all my site settings are stored in the Registry.  This was done to avoid the security team from hacking into the web.config file years ago (At the beginning, Framework 1.0).   To date, no one has penetrated this (we have had several penetration tests).  Here is the sample code.  

The one Administrative benefit for this method is management of settings is easier for a network administrator as well as moving the sites from one server to another (or so I have been told ).

Below is some sample code to store information in the registry.  You will need to give read permissions to some account (ask the system administrator, but  I think it is network services)

Imports System.Runtime.InteropServices
Imports System.Net
Imports System.IO
Imports System.Security.Permissions
Imports Microsoft.Win32
Imports System.Data

<Assembly: RegistryPermissionAttribute(SecurityAction.RequestMinimum, ViewAndModify:="HKEY_LOCAL_MACHINE")> 

Public Class RcisWebConfig
    ' Standard private variables
    Private p_RegistryPath As String = "SOFTWARE\[CompanyName]\[AppName]"
    Private p_RegistryKey As RegistryKey

    ' Custom private variables
    Private p_DBConnectionString As String


#Region "Properties"

    Public ReadOnly Property DBConnectionString() As String

        Get
            Return Me.p_DBConnectionString
        End Get

    End Property

#End Region

#Region "Constructors"

    Public Sub New()

        Me.p_DBConnectionString = "Initialized"
        Me.LoadSettings()

    End Sub

#End Region

    Private Sub LoadSettings()

        p_RegistryKey = Registry.LocalMachine.OpenSubKey(p_RegistryPath)
        Me.p_DBConnectionString = Me.p_RegistryKey.GetValue("DBConnectionString").ToString()

    End Sub

End Class

Open in new window

0
 
LVL 12

Expert Comment

by:mwochnick
ID: 35132654
0
 
LVL 12

Expert Comment

by:mwochnick
ID: 35132706
0
 

Author Closing Comment

by:Dominic34
ID: 35137211
thanks for the replies. We will use the web.config and we will also look for encrypted registry. thanks for the links mwochnick, it could certainly be really usefull.
0

Featured Post

Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Technology Resume 7 88
ASP.NET Content Page 3 64
How to use NFS (Network File System) in Asp.net mvc 5? 4 72
How to fix 'event logs could not be searched' error asp.net? 3 26
In .NET 2.0, Microsoft introduced the Web Site.  This was the default way to create a web Project in Visual Studio 2005.  In Visual Studio 2008, the Web Application has been restored as the default web Project in Visual Studio/.NET 3.x The Web Si…
It was really hard time for me to get the understanding of Delegates in C#. I went through many websites and articles but I found them very clumsy. After going through those sites, I noted down the points in a easy way so here I am sharing that unde…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
Suggested Courses

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question