Dear Suriana, Dzofeer and Syed Amir
During the regular certificate upgrade checks on TDPS, we have found out that the SQL protocol encryption is disabled on TDPS hence the SQL communication is plain which is vulnerable to attacks. Also found out following;
1. Central database is now clustered and upgraded to Windows Server 2003.
2. All client PCs has formatted and upgraded hardware.
3. Client ODBC is not capable of encrypting SQL communication (version is older).
We would like to know whether you have disabled it because of a architectural reason on TDPS or not.
If the answer is Yes, kindly suggest us a way of encrypting SQL communication as per the present architecture.
If the answer is No, we need to bring up SQL communication encryption ASAP and meets to the security standards. For enable this, we would like to know following from you;
1. Recommended ODBC version to install which supports SQL encryption.
2. Present TDPS architecture diagram including Live, backup, DR etc.
Thank you & Best Regards,
Roshan Chandrasiri.,
Epic Lanka Technologies (Pvt) Ltd.
Wehhhhh, dh pkul brapa nehhh????? cmni kalu, bila masa aku nk bleh g man badminton n balik rehat ????wawawawawawa..dah laaa main ngn security..huhuhu....anway, c u on monday yaaa mr roshan
Wehhhhh, dh pkul brapa nehhh????? cmni kalu, bila masa aku nk bleh g man badminton n balik rehat ????wawawawawawa..dah laaa main ngn security..huhuhu....anway, c u on monday yaaa mr roshan
No comments:
Post a Comment