Link to home
Start Free TrialLog in
Avatar of atljarman
atljarman

asked on

SQL Server Express Triggers to Compare hashed passwords before updating user passwords

I recently asked a question where i need to develop a way to compare the last 5 passwords for a user before they update their password in a SQL database prior to the password being changed.  I asked this using the .Net engine https://www.experts-exchange.com/questions/28553621/net-4-0-password-history-example-sql-server.html and seem to not be making it very far.

It made me think that this has to be a common issue that maybe i'm not looking at it the right way.  Is there a way to use SQL Server Triggers or procedures to compare the hashed passwords.   For example, I have a PasswordHistory table in the database that stores the history of the hashed password which are copies of the hashed password in the aspnet_Membership table for the users.  I imagine that you could create a temporary table that the password that is suggested is first inserted and then if it is a comparison reject the update of the membership table.  

I have no real idea how to write SQL Triggers or Procedures so I am reaching out to you all to see if there is an answer.  I've been working on this issue for 6 months and intensely the last three weeks.  Thank you in advance.
ASKER CERTIFIED SOLUTION
Avatar of Vitor Montalvão
Vitor Montalvão
Flag of Switzerland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of atljarman
atljarman

ASKER

Ok.  So the user names and passwords are stored in tables that are accessed and updated by .net.  I think that is different than sql server logon user and passwords.  I think your recpmmendation is kob th latter, correct?  Thank you for trying to help.
Aren't SQL Server logins?
These are ASP .Net Membership SQL Server database passwords - This was solved on another question but will award points even though it was answering a different question.   I don't think I was asking the right question.