Showing posts with label protected. Show all posts
Showing posts with label protected. Show all posts

Monday, March 12, 2012

Pasword Data Type

Hello ...

I want to ask about the best data type protected for pasword colomn in SQL Server .. to make my DB more secure ...

thanks ...

That depends on the version you are using on the effort you want to put in your front end application. There are two ways. Server encrypted data (which is accessible in SQL Server 2005) or client encrypted data (or the combination of both). In SQL Server 2000 I always used a client library to encrypt / decrypt the data that was passed to the server. In SQL Server 2005 there is a server based functionalty for encrypting data.

HTH, Jens SUessmeyer.

http://www.sqlserver2005.de
|||

The following two threads may also be helpful:

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=258837&SiteID=1
http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=263309&SiteID=1

Thanks
Laurentiu

Pasword Data Type

Hello ...

I want to ask about the best data type protected for pasword colomn in SQL Server .. to make my DB more secure ...

thanks ...

That depends on the version you are using on the effort you want to put in your front end application. There are two ways. Server encrypted data (which is accessible in SQL Server 2005) or client encrypted data (or the combination of both). In SQL Server 2000 I always used a client library to encrypt / decrypt the data that was passed to the server. In SQL Server 2005 there is a server based functionalty for encrypting data.

HTH, Jens SUessmeyer.

http://www.sqlserver2005.de
|||

The following two threads may also be helpful:

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=258837&SiteID=1
http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=263309&SiteID=1

Thanks
Laurentiu

Friday, March 9, 2012

PASSWORD PROTECTED TABLE

Hello:
I would like to know if there is a way to get a password protected table in
sqlserver 2000, developer EDITION
The database administrator can open any table including a user table and he
can know the password of any user just by opening the table, that's why is
better to have a table with password protected or any encryption type in the
password field associated to the login, so only the IT manager can open this
table and not any programmer that has access to SQLserver.
ThanksThere are third party products that offer encryption
functionality. You can find them listed in this FAQ site in
the encryption section:
http://www.sqlsecurity.com/DesktopDefault.aspx?tabid=22
-Sue
On Fri, 14 Oct 2005 15:44:03 -0400, "Gina Hernandez"
<pdwhitt@.nospam.wdsinc.com> wrote:

>Hello:
>I would like to know if there is a way to get a password protected table in
>sqlserver 2000, developer EDITION
>The database administrator can open any table including a user table and h
e
>can know the password of any user just by opening the table, that's why i
s
>better to have a table with password protected or any encryption type in th
e
>password field associated to the login, so only the IT manager can open thi
s
>table and not any programmer that has access to SQLserver.
>
>Thanks
>

Password protected stored procedure question

I have a password protected stored procedure that I have created.
If the user issues just the name of the stored procedure he gets a
message telling him that he needs to input the password.
If the user inputs the wrong password he gets a "syntax error" message
back in the query browser.
Now, here is the question:
How can I set it up so that the password shows up as asterisk in the
query browser?
Example - Sp_test password
Shows up as Sp_test ******** in the query browser."Varied_Interest" <Varied_Interest@.mail.com> wrote in message
news:1173373412.914934.102930@.p10g2000cwp.googlegroups.com...
>I have a password protected stored procedure that I have created.
> If the user issues just the name of the stored procedure he gets a
> message telling him that he needs to input the password.
> If the user inputs the wrong password he gets a "syntax error" message
> back in the query browser.
> Now, here is the question:
> How can I set it up so that the password shows up as asterisk in the
> query browser?
> Example - Sp_test password
> Shows up as Sp_test ******** in the query browser.
>
Make the password ********
Seriously, you can't do this in query analyzer.
And not really sure the point, there's better ways to enforce security than
this.
(and if the user has the ability to run sp_helptext sp_test you have zero
security anyway.)
Also, you generally do NOT want to name a stored proc sp_ unless you intend
to put it in the master database and make it available to all databases.
sp_ stands for system procedure, NOT stored procedure and the sp_ forces the
optmizer to handle things a bit differently.
Greg Moore
SQL Server DBA Consulting
sql (at) greenms.com http://www.greenms.com|||Hi,
Regarding "name a stored proc sp_ unless you intend to put it in the master
database and make it available to all databases"
This is a "non-supported" activity, and it does not work in SQL 2005! I
made the mistake, and we have a lot of work to do to move our stuff from
2000 to 2005.
--
Thank you,
Daniel Jameson
SQL Server DBA
Children's Oncology Group
www.childrensoncologygroup.org
"Greg D. Moore (Strider)" <mooregr_deleteth1s@.greenms.com> wrote in message
news:O7fZCVaYHHA.208@.TK2MSFTNGP05.phx.gbl...
> "Varied_Interest" <Varied_Interest@.mail.com> wrote in message
> news:1173373412.914934.102930@.p10g2000cwp.googlegroups.com...
>>I have a password protected stored procedure that I have created.
>> If the user issues just the name of the stored procedure he gets a
>> message telling him that he needs to input the password.
>> If the user inputs the wrong password he gets a "syntax error" message
>> back in the query browser.
>> Now, here is the question:
>> How can I set it up so that the password shows up as asterisk in the
>> query browser?
>> Example - Sp_test password
>> Shows up as Sp_test ******** in the query browser.
>
> Make the password ********
> Seriously, you can't do this in query analyzer.
> And not really sure the point, there's better ways to enforce security
> than this.
> (and if the user has the ability to run sp_helptext sp_test you have zero
> security anyway.)
> Also, you generally do NOT want to name a stored proc sp_ unless you
> intend to put it in the master database and make it available to all
> databases. sp_ stands for system procedure, NOT stored procedure and the
> sp_ forces the optmizer to handle things a bit differently.
>
> --
> Greg Moore
> SQL Server DBA Consulting
> sql (at) greenms.com http://www.greenms.com
>|||"Daniel Jameson" <djameson@.childrensoncologygroup.org> wrote in message
news:Ogum6JdYHHA.4772@.TK2MSFTNGP05.phx.gbl...
> Hi,
> Regarding "name a stored proc sp_ unless you intend to put it in the
> master database and make it available to all databases"
> This is a "non-supported" activity, and it does not work in SQL 2005! I
> made the mistake, and we have a lot of work to do to move our stuff from
> 2000 to 2005.
Hmm, wasn't sure if 2005 still allowed that or not.
Probably better that they don't.
> --
> Thank you,
> Daniel Jameson
> SQL Server DBA
> Children's Oncology Group
> www.childrensoncologygroup.org
>
Greg Moore
SQL Server DBA Consulting
sql (at) greenms.com http://www.greenms.com

Password protected stored procedure question

I have a password protected stored procedure that I have created.
If the user issues just the name of the stored procedure he gets a
message telling him that he needs to input the password.
If the user inputs the wrong password he gets a "syntax error" message
back in the query browser.
Now, here is the question:
How can I set it up so that the password shows up as asterisk in the
query browser?
Example - Sp_test password
Shows up as Sp_test ******** in the query browser.
"Varied_Interest" <Varied_Interest@.mail.com> wrote in message
news:1173373412.914934.102930@.p10g2000cwp.googlegr oups.com...
>I have a password protected stored procedure that I have created.
> If the user issues just the name of the stored procedure he gets a
> message telling him that he needs to input the password.
> If the user inputs the wrong password he gets a "syntax error" message
> back in the query browser.
> Now, here is the question:
> How can I set it up so that the password shows up as asterisk in the
> query browser?
> Example - Sp_test password
> Shows up as Sp_test ******** in the query browser.
>
Make the password ********
Seriously, you can't do this in query analyzer.
And not really sure the point, there's better ways to enforce security than
this.
(and if the user has the ability to run sp_helptext sp_test you have zero
security anyway.)
Also, you generally do NOT want to name a stored proc sp_ unless you intend
to put it in the master database and make it available to all databases.
sp_ stands for system procedure, NOT stored procedure and the sp_ forces the
optmizer to handle things a bit differently.
Greg Moore
SQL Server DBA Consulting
sql (at) greenms.com http://www.greenms.com
|||Hi,
Regarding "name a stored proc sp_ unless you intend to put it in the master
database and make it available to all databases"
This is a "non-supported" activity, and it does not work in SQL 2005! I
made the mistake, and we have a lot of work to do to move our stuff from
2000 to 2005.
Thank you,
Daniel Jameson
SQL Server DBA
Children's Oncology Group
www.childrensoncologygroup.org
"Greg D. Moore (Strider)" <mooregr_deleteth1s@.greenms.com> wrote in message
news:O7fZCVaYHHA.208@.TK2MSFTNGP05.phx.gbl...
> "Varied_Interest" <Varied_Interest@.mail.com> wrote in message
> news:1173373412.914934.102930@.p10g2000cwp.googlegr oups.com...
>
> Make the password ********
> Seriously, you can't do this in query analyzer.
> And not really sure the point, there's better ways to enforce security
> than this.
> (and if the user has the ability to run sp_helptext sp_test you have zero
> security anyway.)
> Also, you generally do NOT want to name a stored proc sp_ unless you
> intend to put it in the master database and make it available to all
> databases. sp_ stands for system procedure, NOT stored procedure and the
> sp_ forces the optmizer to handle things a bit differently.
>
> --
> Greg Moore
> SQL Server DBA Consulting
> sql (at) greenms.com http://www.greenms.com
>
|||"Daniel Jameson" <djameson@.childrensoncologygroup.org> wrote in message
news:Ogum6JdYHHA.4772@.TK2MSFTNGP05.phx.gbl...
> Hi,
> Regarding "name a stored proc sp_ unless you intend to put it in the
> master database and make it available to all databases"
> This is a "non-supported" activity, and it does not work in SQL 2005! I
> made the mistake, and we have a lot of work to do to move our stuff from
> 2000 to 2005.
Hmm, wasn't sure if 2005 still allowed that or not.
Probably better that they don't.

> --
> Thank you,
> Daniel Jameson
> SQL Server DBA
> Children's Oncology Group
> www.childrensoncologygroup.org
>
Greg Moore
SQL Server DBA Consulting
sql (at) greenms.com http://www.greenms.com

Password protected stored procedure question

I have a password protected stored procedure that I have created.
If the user issues just the name of the stored procedure he gets a
message telling him that he needs to input the password.
If the user inputs the wrong password he gets a "syntax error" message
back in the query browser.
Now, here is the question:
How can I set it up so that the password shows up as asterisk in the
query browser?
Example - Sp_test password
Shows up as Sp_test ******** in the query browser."Varied_Interest" <Varied_Interest@.mail.com> wrote in message
news:1173373412.914934.102930@.p10g2000cwp.googlegroups.com...
>I have a password protected stored procedure that I have created.
> If the user issues just the name of the stored procedure he gets a
> message telling him that he needs to input the password.
> If the user inputs the wrong password he gets a "syntax error" message
> back in the query browser.
> Now, here is the question:
> How can I set it up so that the password shows up as asterisk in the
> query browser?
> Example - Sp_test password
> Shows up as Sp_test ******** in the query browser.
>
Make the password ********
Seriously, you can't do this in query analyzer.
And not really sure the point, there's better ways to enforce security than
this.
(and if the user has the ability to run sp_helptext sp_test you have zero
security anyway.)
Also, you generally do NOT want to name a stored proc sp_ unless you intend
to put it in the master database and make it available to all databases.
sp_ stands for system procedure, NOT stored procedure and the sp_ forces the
optmizer to handle things a bit differently.
Greg Moore
SQL Server DBA Consulting
sql (at) greenms.com http://www.greenms.com|||Hi,
Regarding "name a stored proc sp_ unless you intend to put it in the master
database and make it available to all databases"
This is a "non-supported" activity, and it does not work in SQL 2005! I
made the mistake, and we have a lot of work to do to move our stuff from
2000 to 2005.
Thank you,
Daniel Jameson
SQL Server DBA
Children's Oncology Group
www.childrensoncologygroup.org
"Greg D. Moore (Strider)" <mooregr_deleteth1s@.greenms.com> wrote in message
news:O7fZCVaYHHA.208@.TK2MSFTNGP05.phx.gbl...
> "Varied_Interest" <Varied_Interest@.mail.com> wrote in message
> news:1173373412.914934.102930@.p10g2000cwp.googlegroups.com...
>
> Make the password ********
> Seriously, you can't do this in query analyzer.
> And not really sure the point, there's better ways to enforce security
> than this.
> (and if the user has the ability to run sp_helptext sp_test you have zero
> security anyway.)
> Also, you generally do NOT want to name a stored proc sp_ unless you
> intend to put it in the master database and make it available to all
> databases. sp_ stands for system procedure, NOT stored procedure and the
> sp_ forces the optmizer to handle things a bit differently.
>
> --
> Greg Moore
> SQL Server DBA Consulting
> sql (at) greenms.com http://www.greenms.com
>|||"Daniel Jameson" <djameson@.childrensoncologygroup.org> wrote in message
news:Ogum6JdYHHA.4772@.TK2MSFTNGP05.phx.gbl...
> Hi,
> Regarding "name a stored proc sp_ unless you intend to put it in the
> master database and make it available to all databases"
> This is a "non-supported" activity, and it does not work in SQL 2005! I
> made the mistake, and we have a lot of work to do to move our stuff from
> 2000 to 2005.
Hmm, wasn't sure if 2005 still allowed that or not.
Probably better that they don't.

> --
> Thank you,
> Daniel Jameson
> SQL Server DBA
> Children's Oncology Group
> www.childrensoncologygroup.org
>
Greg Moore
SQL Server DBA Consulting
sql (at) greenms.com http://www.greenms.com

Password Protected Excel File

Hi

I'm in need of a bit of assitance here. Basically I am currently creating a SSIS package which works in principle with the exception of my data flow.

On my data flow I am reading an excel file using the excel source, this works fine for a number of my examples but one of the excel files is password protected. This is throwing an error when I try to run the package.

Does anyone know how to read a password protected excel file?

Thanks
Kismet123You cannot access a password-protected Excel file using the Jet OLE DB Provider, period.

I probably shouldn't mention this, but as an interesting tidbit of useless knowledge, the Provider can access the file if it is open at the same time in the Excel application...and without even providing the password. But doing so causes a huge memory leak in the Excel process that's going to bring things down sooner or later.
Q319998 BUG: Memory Leak When You Query Open Excel Worksheet with ADO
http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q319998

-Doug
|||Thanks for that information Doug. Could you possibly tell me what the Password property is referring to when you create an Excel Connection Manager. I thought it would have something to do with if the connection you are making is password protected.

Kismet

Password protected BAK Files

Hello All,
Can anyone help me? I would like to put a password on BAK files everytime my
backup jobs run. So that when I restore a db from one of these BAK files, I
need to provide the password.
Thanks in Advance,
Tuoc"Tuoc" <anonymous@.discussions.microsoft.com> wrote in message
news:D9549303-3521-4C75-ABFB-685820FC140D@.microsoft.com...
quote:

> Can anyone help me? I would like to put a password on BAK files everytime

my backup jobs run. So that when I restore a db from one of these BAK files,
I need to provide the password.
quote:

>

If you are looking to secure your BAK files, consider using EFS (Encrypted
File System) for the folder that you dump your BAK files. Even if you could
make this work, file level passwords would not be of any value.
Steve|||SQL2000 only
BACKUP DATABASE pubs to DISK = 'c:\pubs.bak'
WITH PASSWORD = 'test'
If you try and restore this without a password, you get
RESTORE DATABASE pubs FROM DISK = 'c:\pubs.bak'
WITH REPLACE
Server: Msg 3279, Level 16, State 2, Line 1
Access is denied due to a password failure
Server: Msg 3013, Level 16, State 1, Line 1
RESTORE DATABASE is terminating abnormally.
To restore, you need the password e.g.
RESTORE DATABASE pubs FROM DISK = 'c:\pubs.bak'
WITH REPLACE,PASSWORD = 'test'
However, I've never really seen anyone use this. There's also the issue of
managing/generating/storing the passwords so they're not just hardcoded into
the jobs but using something like NEWID would probably do it but you would
have to store it with the backup filename somewhere so you could restore it
e.g.
declare @.p varchar(36) ; set @.p = NEWID()
declare @.file varchar(200) ; set @.file = '<generate filename>'
-- store password away somewhere secure with filename
BACKUP DATABASE pubs to DISK = @.file
WITH PASSWORD = @.p
HTH
Jasper Smith (SQL Server MVP)
I support PASS - the definitive, global
community for SQL Server professionals -
http://www.sqlpass.org
"Tuoc" <anonymous@.discussions.microsoft.com> wrote in message
news:D9549303-3521-4C75-ABFB-685820FC140D@.microsoft.com...
quote:

> Hello All,
> Can anyone help me? I would like to put a password on BAK files everytime

my backup jobs run. So that when I restore a db from one of these BAK files,
I need to provide the password.
quote:

> Thanks in Advance,
> Tuoc
|||Tuoc
You also posted this on .server where there are quite a few reponses. Please
do not post the same questions on multiple newsgroups independently, so you
will not have to follow multiple threads of response, and so other people
won't waste time answering a question that has already been answered.
Thanks!
HTH
--
Kalen Delaney
SQL Server MVP
www.SolidQualityLearning.com
"Tuoc" <anonymous@.discussions.microsoft.com> wrote in message
news:D9549303-3521-4C75-ABFB-685820FC140D@.microsoft.com...
quote:

> Hello All,
> Can anyone help me? I would like to put a password on BAK files everytime

my backup jobs run. So that when I restore a db from one of these BAK files,
I need to provide the password.
quote:

> Thanks in Advance,
> Tuoc
|||Kalen,
I'm sorry about that.
Tuoc

Password protected Access 2000 DB

Hi everyone,

I'm having a problem connecting to my Access 2000 DB from VB.net 2003. The DB has an password protection, but no username/password protection. So, no .mdw files are used, only the DB own Jet password. At desing-mode, when connecting to DB first time, I'm asked the username (blanc) password (blanc) and the Jet database password ('myPass'). Everything works just fine until when I try to debug the program. Database login dialogbox appears and asks for username and password, but no Jet database password... So, I'm unable to connect. PLEASE help me on this one, because I starting to lose my mind while trying to find the answer. Thx in advance.

Jari@.FinlandPlease help. I'm desperate.|||I'm STILL strugging with this problem. Somebody, please help me. I've tried every solution presented on this forum (and every other that I was able to find) but the problem still exists. I managed to change the db path, userID and password at runtime, but can't find a way to enter the DB password... If I remove the password from DB everything works just fine. Even with normal logon information (userID & password). The TableLogOnInfo class doesn't give the option for DB password, only the UserID and password. The ConnectionInfo class has a password-option but I'm not sure is this for the DB password or what? And how should I use this class? I'll paste some code for you to see.

Dim oCRTab As New CrystalDecisions.Shared.TableLogOnInfo
Dim oCRConn As New CrystalDecisions.Shared.ConnectionInfo

Dim tab As Table
Dim report As New MyReport
tab = report .Database.Tables("MyTable")
oCRConn.Password = "TheDBPass"

oCRTab.ConnectionInfo = oCRConn
oCRTab.ConnectionInfo.ServerName = "c:\dbTest\db1.mdb"
oCRTab.TableName = "MyTable"

tab.ApplyLogOnInfo(oCRTab)

And later I bind the report to the CRViewer and it still asks for the login information...|||Yep, talking to myself again. Found out the solution to the problem: there isn't any... I received a post from businessobjects and found out this:

====================
NOTE:

You cannot set a database level password when
using Crystal Reports for Visual Studio .NET 2002 or
2003.
====================

So back to square one. I quess I'll have to find some other way to do my reports.

antijape .......boycottin CR since 2005.......

Password Proctected Excel Subscription

I need to send protected information via a reporting services subscripiton. Unfortunately the receiver can not access our reporting services web page so I have to send it as an excel attachment with email. Is there a way I can protect the spreadsheet automatically before it is sent via the subscription.

Thanks

Reporting Services doesn't currently have a DRM/IRM or Excel password feature, so you would have to post-process the Excel files that RS generates.|||Thanks but I'm still not sure how I'd do that without programming.|||You will have to do some programming, or open the Excel files in Excel and modify them.