Hi Alex,

> > And if so, does that also means that metadata is encrypted as well
> 
> yes

Great, so then we go from "Unknown" to "True" protection.
I like the 1 byte Boolean to ;-)

> > so that
> > we don't have to set rdb$xxx_source to null anymore?
> >
> >
> 
> that's not 1to1 related
> 
> If in case when firebird DB engine has a key to decrypt database there
can't
> be additional sessions with generic SQL access (i.e. only your task can
work
> with database) - yes, there is no need to kill sources. If additional
sessions
> are possible - sources can be accessed. I.e. it depends upon what crypt
(and
> key store plugins) are used.
> 

I see. 
If the key is provided only through the attachment then the metadata is
secured, dependent of the client of course. 
But as soon as the key is provided to the engine all attachments can see it
just like now.
Clear.

If you don't mind I'm curious, is the BLR affected by encrypting datapages
containing metadata?

Thanks,
Magnus


------------------------------------------------------------------------------
The Windows 8 Center - In partnership with Sourceforge
Your idea - your app - 30 days.
Get started!
http://windows8center.sourceforge.net/
what-html-developers-need-to-know-about-coding-windows-8-metro-style-apps/
Firebird-Devel mailing list, web interface at 
https://lists.sourceforge.net/lists/listinfo/firebird-devel

Reply via email to