<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Dynamic SQL and digital signatures in SQL Server 2005</title><link>http://blogs.msdn.com/raulga/archive/2007/05/09/dynamic-sql-and-digital-signatures-in-sql-server-2005.aspx</link><description>As I already mentioned, dynamic SQL is a quite powerful, but also quite dangerous. In SQL Server 2005 we introduced a new feature that is also quite powerful and when used properly can be quite useful; but it is important to learn and understand any such</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Dynamic SQL and digital signatures in SQL Server 2005</title><link>http://blogs.msdn.com/raulga/archive/2007/05/09/dynamic-sql-and-digital-signatures-in-sql-server-2005.aspx#2525744</link><pubDate>Thu, 10 May 2007 19:29:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2525744</guid><dc:creator>Adam Machanic</dc:creator><description>&lt;P&gt;Great timing on this post -- I'm doing a webcast on this topic tomorrow for MSDN:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032334738" target=_new rel=nofollow&gt;http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032334738&lt;/A&gt;&lt;/P&gt;</description></item><item><title>Pythian Group Blog    &amp;raquo; Log Buffer #44: a Carnival of the Vanities for DBAs</title><link>http://blogs.msdn.com/raulga/archive/2007/05/09/dynamic-sql-and-digital-signatures-in-sql-server-2005.aspx#2549660</link><pubDate>Fri, 11 May 2007 19:52:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2549660</guid><dc:creator>Pythian Group Blog    » Log Buffer #44: a Carnival of the Vanities for DBAs</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.pythian.com/blogs/477/log-buffer-44-a-carnival-of-the-vanities-for-dbas"&gt;http://www.pythian.com/blogs/477/log-buffer-44-a-carnival-of-the-vanities-for-dbas&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Dynamic SQL and digital signatures in SQL Server 2005</title><link>http://blogs.msdn.com/raulga/archive/2007/05/09/dynamic-sql-and-digital-signatures-in-sql-server-2005.aspx#2698935</link><pubDate>Thu, 17 May 2007 20:18:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2698935</guid><dc:creator>creif</dc:creator><description>&lt;P&gt;Using your excellent samples I have pretty much worked out everything that I need to encrypt one column, including maintaining both the &lt;/P&gt;
&lt;P&gt;encrpyted data and a one way hash for searches. &amp;nbsp;I have a view which decrypts the data properly when the symmetric key has been opened (and obviously returns null when the key is not open).&lt;/P&gt;
&lt;P&gt;I want the view to return the decrypted data only when the user is accessing the database from a single application. &amp;nbsp;This application maintains a single database connection per session. &amp;nbsp;My thought was to open the key when the database connection is established by the application and close it when the application exits, thereby granting access only through the application. &amp;nbsp;Is that an acceptable practice?&lt;/P&gt;
&lt;P&gt;If I do that, should I protect the key with a password that is then compiled in the application so that I can open the key? &amp;nbsp;This means that every installation will have a key protected by the same password. &amp;nbsp;Or is there a better way to do that? &amp;nbsp;Does this post on digital signing have any relevance to my situation?&lt;/P&gt;</description></item><item><title>re: Dynamic SQL and digital signatures in SQL Server 2005</title><link>http://blogs.msdn.com/raulga/archive/2007/05/09/dynamic-sql-and-digital-signatures-in-sql-server-2005.aspx#2705695</link><pubDate>Fri, 18 May 2007 07:48:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2705695</guid><dc:creator>raulga</dc:creator><description>&lt;p&gt; &amp;nbsp; Thanks a lot for your comments. I am glad I am able to help.&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;We have discussed this particular topic (security based on application identity) in great detail in the forum. Below is a link to that particular thread. &lt;a rel="nofollow" target="_new" href="http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=793129&amp;amp;SiteID=1"&gt;http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=793129&amp;amp;SiteID=1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; I invite you to continue the discussion in the forum so more people have a chance to read and benefit from it.&lt;/p&gt;
&lt;p&gt; &amp;nbsp;Thanks a lot,&lt;/p&gt;
&lt;p&gt;-Raul&lt;/p&gt;</description></item><item><title>web</title><link>http://blogs.msdn.com/raulga/archive/2007/05/09/dynamic-sql-and-digital-signatures-in-sql-server-2005.aspx#7293197</link><pubDate>Tue, 29 Jan 2008 01:06:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7293197</guid><dc:creator>web</dc:creator><description>&lt;p&gt;web website domain website &lt;a rel="nofollow" target="_new" href="http://manieboddy.oceansfree.com/"&gt;http://manieboddy.oceansfree.com/&lt;/a&gt; web&lt;/p&gt;
</description></item></channel></rss>