Title: Eric CAUDAL
Hi,
I am not sure this exactly the same topic as Frederic mentioned and I didnot want "to leech" on the topic...

We face another security/data access issue with a customer who would like to be able to hide the salary information from his IT administrator.
After some investigations, the only way I found so far was to remove the root access (+other access) to the customer's IT administrator, which is a kind of rash.

I would expect a way to encrypt some critical data at database level (password, accounting information, salaries).
I am not sure here but I have the feeling that encryption/decryption though should only be possible through a certificate/key at browser/client level to protect the key from the administrator.

Any security expert would be able to enlighten it? Any common practice from other ERP?
--
Eric Caudal
CEO
--
Elico Corporation, Shanghai branch
OpenERP Premium Certified Training Partner 
Cell: + 86 186 2136 1670
Office: + 86 21 6211 8017/27/37
Skype: elico.corp
[email protected]
http://www.elico-corp.com

Elico
        Corp
_______________________________________________
Mailing list: https://launchpad.net/~openerp-community
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~openerp-community
More help   : https://help.launchpad.net/ListHelp

Reply via email to