Re: Hiding the database password
Posted in 2000
Rich We have a similar situation. However, the database user(s) are guarded by Unix username/password, and has mode 600, so other users cant see the contents of these files. Most of the users come in through the web anyway, and the few (maintainence pesonnel) users who can telnet into the machine(s) cant see the contents. You could encrypt the config files with some public key/private key algorithm, and have the program decrypt it on the fly, but that will create problems for you when you want to change the Unix password for some reason. HTH Sujit rich@whilewereyoung.com on 09/06/2000 08:27:57 AM Please respond to rich@whilewereyoung.com To: informix-list@iiug.org cc: Subject: Hiding the database password I'm dealing with a problem and I wanted to get a few opinions on how to approach it. Basically we have a web app that uses many database calls to do its' work. Over time our we've setup many configuration type files that have the database user password in it. The end result is to take the database password out of all the configuration files so users that user who have access to those config files can use them but not be able to connect to the database. Is there anyway of getting the password out of these files but still enable the web app to get the password from some protected area and use it for its needs? Rich Sent via Deja.com http://www.deja.com/ Before you buy.