Re: Hiding the database password
Posted in 2000
Topics: Security, Permissions & Auditing
Not really, not that I can think of, anyway. One option is to keep the password in that configuration file, but encrypt it. What are your clients running on? I know it's a web app, but where are those config files kept and how to they get accessed? In article <8p5np0$mit$1@nnrp1.deja.com>, rich@whilewereyoung.com wrote: > I'm dealing with a problem and I wanted to get a few opinions on how to > approach it. > > Basically we have a web app that uses many database calls to do its' > work. Over time our we've setup many configuration type files that > have the database user password in it. The end result is to take the > database password out of all the configuration files so users that user > who have access to those config files can use them but not be able to > connect to the database. > > Is there anyway of getting the password out of these files but still > enable the web app to get the password from some protected area and use > it for its needs? > > Rich > > Sent via Deja.com http://www.deja.com/ > Before you buy. > -- # unrm / ksh: unrm: not found # man cpio Sent via Deja.com http://www.deja.com/ Before you buy.
I actually thought of encrypting it but I'm not sure if that will help unless I used PGP or something. UNIX password encryption won't work because it is one way encryption meaning the password will still have to exist somewhere to be read from. We are using the Netscape Iplanet server. There are actual situations where the webserver needs to execute a process that logs into the database. In article <8p5udn$v7k$1@nnrp1.deja.com>, mars1972@my-deja.com wrote: > Not really, not that I can think of, anyway. One option is to keep the > password in that configuration file, but encrypt it. What are your > clients running on? I know it's a web app, but where are those config > files kept and how to they get accessed? > > In article <8p5np0$mit$1@nnrp1.deja.com>, > rich@whilewereyoung.com wrote: > > I'm dealing with a problem and I wanted to get a few opinions on how > to > > approach it. > > > > Basically we have a web app that uses many database calls to do its' > > work. Over time our we've setup many configuration type files that > > have the database user password in it. The end result is to take the > > database password out of all the configuration files so users that > user > > who have access to those config files can use them but not be able to > > connect to the database. > > > > Is there anyway of getting the password out of these files but still > > enable the web app to get the password from some protected area and > use > > it for its needs? > > > > Rich > > > > Sent via Deja.com http://www.deja.com/ > > Before you buy. > > > > -- > # unrm / > ksh: unrm: not found > # man cpio > > Sent via Deja.com http://www.deja.com/ > Before you buy. > Sent via Deja.com http://www.deja.com/ Before you buy.