Password Encryption in RMS Store Opertions database

May 12, 2005 4 Replies

Cashier Passwords should be encrypted in the Store Operations database. This could be a security risk and should be looked at quickly.


---------------- This post is a suggestion for Microsoft, and Microsoft responds to the suggestions with the most votes. To vote for this suggestion, click the "I Agree" button in the message pane. If you do not see the button, follow this link to open the suggestion in the Microsoft Web-based Newsreader and then click "I Agree" in the message pane.



formatting link


This issue was addressed 11/2/04 with the release of Service Pack 2.

formatting link
"After you install RMS SP2, all server names, database names, user names, and passwords that are stored in the registry are encrypted to help prevent unauthorized access or exploitation of this information. These enhancements help protect your information in RMS. These enhancements are part of our Trustworthy Computing initiative." Update your Store Operations and you will be fine.

Rob

formatting link

Hi Rob,

SP2 only encrypted the registry entries - I think Jeff is looking to encrypt the data in the database - am I correct Jeff?

Kind Regards,

Jason.

formatting link

>

He means encrypting the Password column in the Cashier table.

I don't see much advantage to this though. If somone already has access to your database, encrypting the cashier passwords isn't going to prevent anything.

Yes Jason you are correct the database table should be encrytped to secure access to the database

Jeff

"Jas> Hi Rob,

formatting link
>

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required