Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
protect DBI config info
System
On this project DBI is used to connect to Oracle. Originally the DB configuration info were kept in the Perl modules that connect to the DB, then they were moved to a config file. The client now doesn't want passwords stored in plain text anywhere. Just wondering if anyone has a good solution for this.
It seems to me that if you can access the module then a script can get a database connection without a password or see the encryption/decription logic, so whether the password is in plain text or encrypted, if you have access to the system and/or the module code there is a security issue. Does anyone know of a good way to make a module ensure only authorized scripts can get a handle to the database, or otherwise protect the code? I don't think file permissions on the module can handle it because processes accessing the module could be running as any user (under impersonation)?
Thanks in advance,
-John
Find more posts tagged with
Comments
Migrateduser
If they don't want it stored as plain text, you could store it as a dbm file. Not exactly secure, but not plain text either. If you've never worked with dbm files before, they're like hashes but they're stored on the disk.
- Jason