Click here to monitor SSC
SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 

Rotating Keys

By Steve Jones, 2010/01/29

Total article views: 97 | Views in the last 30 days: 3

http://www.mooncostumes.com/image/7768I've been thinking about security lately quite a bit, having finished tech editing a book on encryption and reading another one. I've had a few polls on various security items and this Friday I thought about another one.

How often do you rotate encryption keys or passwords?

Good practices dictate that you periodically rotate those keys and re-encrypt data to ensure that if a malicious user were to acquire an older copy of the database, and somehow brute force the keys, they wouldn't be able to actually use those keys or passwords against your current database server.

Passwords seem to rotate on all types of intervals, depending on how paranoid the Windows system administrator is. I've had them rotate as often as every 30 days and as long as a year. I guess I've had places where passwords never expired, but I wouldn't count that as any type of "rotation."

I'm really looking for an idea of what people think is a good interval. My guess is that for heavily encrypted data, rotating keys and dealing with the hassles of decryption/re-encryption, once a year is probably a good interval, but let me know if you think differently. Or if any of you are actually using SQL Server encryption keys, how often do you rotate keys.

Or do you not bother to rotate them at all?

Steve Jones


The Voice of the DBA Podcasts

Everyday Jones

The podcast feeds are available at sqlservercentral.mevio.com. You can also follow Steve Jones on Twitter:

Overall RSS Feed: or now on iTunes!

Today's podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

I really appreciate and value feedback on the podcasts. Let us know what you like, don't like, or even send in ideas for the show. If you'd like to comment, post something here. The boss will be sure to read it.

By Steve Jones, 2010/01/29

Total article views: 97 | Views in the last 30 days: 3
Your response
 
 
Related Articles
FORUM

Password Encryption in SQl SERVER 2005

Password Encryption in SQl SERVER 2005

ARTICLE

Podcast Announcements

Podcast Feeds

FORUM

DTS to SSIS 2005 migration - password encryption - DTEXEC

DTS to SSIS 2005 migration - password encryption - DTEXEC

FORUM

SQL Encryption:hiding the Password

here I am asking for help on how to hide the password tha tI use for encrypting data

FORUM

Automated SQL Installer - encrypt password in template ini file

Automated SQL Installer - encrypt password in template ini file

Tags
editorial    
 
Contribute

Join the most active online SQL Server Community

SQL knowledge, delivered daily, free:

Email address:  

You make SSC a better place

As a member of SQLServerCentral, you get free access to loads of fresh content: thousands of articles and SQL scripts, a library of free eBooks, a weekly database news roundup, a great Q & A platform… And it’s our huge, buzzing community of SQL Server Professionals that makes it such a success.

Join us!

Steve Jones
Editor, SQLServerCentral.com

Already a member? Jump in:

Email address:   Password:   Remember me: Forgotten your password?
Steve Jones