How do I secure connection strings in VS?
I see some others have posted this question, however, none of the solutions I've tried have fixed yet. I have XP 32-bit with VS 2008 and I am trying to encrypt my connection string in the web.config file.
But I get the error: The configuration section "..." was not found. Error!
The command I give her is: C: \ Program Files \ Microsoft Visual Studio 9.0 \ VC> Aspnet_regiis.exe -pe "system.we b / AdventureWorksConnectionString2" -app "/ Documents and Settings / Admin / My Docume nts / Visual Studio 2008 / Projects / AddFileToSQL2 "
Also, how does -app map the virtual directory? In other words, the path above is the directory below c :. Is this the right way? And AddFileToSQL2 is the name of my project, although it is part of the AddFileToSQL solution.
I have a shared folder with all permissions.
And the relevant part of my web.config file:
<add name="AdventureWorksConnectionString2" connectionString="Data Source=SIDEKICK;Initial Catalog=AdventureWorks;Persist Security Info=true; User ID=AdventureWorks;Password=sqlMagic"
providerName="System.Data.SqlClient" />
a source to share
With DPAPI, you can only encrypt entire partitions as far as I know. Thus, you cannot encrypt just one connection string, but the entire connectionStrings section. Second, it -app
refers to the virtual path to the application on your IIS server where it should find this section and configuration file. Thus, if your site looks like this:
root
/appFoo
And you want to encrypt connection strings in / appFoo which you would do
aspnet_regiis -pe "connectionStrings" -app "/appFoo"
How To: Encrypt Configuration Sections in ASP.NET 2.0 Using DPAPI
a source to share