Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Force Protocol Encryption - Please help!

0 views
Skip to first unread message

canuck

unread,
Sep 28, 2004, 10:51:29 AM9/28/04
to
Hi, I just recently set up a SQL 2000 server and have a question about
the "Force Protocol Encryption" setting... can someone please help me!

I installed my SQL server on a standalone W2K server which is NOT a
member of a domain. I want to ensure that all connections to the SQL
server are encrypted, so I enabled the Force Protocol Encryption
setting. In order to make it work, I installed Certification Autority
services on the same server, generated my SQL service account a
certificate & installed the cert on the server.

After installing the cert, I was once again able to start my SQL
server and it appears that all is well, however I am concerned about
whether or not the connections are actually being encrypted. Do my
clients need to trust the Certificate Authority that the cert was
generated on for the encryption to work? I read some Microsoft
support articles about this issue and they don't seem that clear on
this issue.

Is there anything special that needs to be done on the clients & does
anyone know of a way to verify that the connection is encrypted?

Thanks for any help you guys can provide!!!


Kevin McDonnell [MSFT]

unread,
Sep 28, 2004, 3:10:44 PM9/28/04
to
Prev Post:

After installing the cert, I was once again able to start my SQL
server and it appears that all is well, however I am concerned about
whether or not the connections are actually being encrypted. Do my
clients need to trust the Certificate Authority that the cert was
generated on for the encryption to work? I read some Microsoft
support articles about this issue and they don't seem that clear on
this issue.

Is there anything special that needs to be done on the clients & does
anyone know of a way to verify that the connection is encrypted?


Reply:
The only way to verify that the connection is encrypted is to make a
network trace and review it.
If you enable encryption on the serverside, the clients are not required to
trust the same root authority .


Thanks,

Kevin McDonnell
Microsoft Corporation

This posting is provided AS IS with no warranties, and confers no rights.

0 new messages