Repository navigation
Honor login encryption options for Relog DSN that imports Perfmon - #555
Merged
JosephPilov-MSFT (PiJoCoder) merged 4 commits intoSep 22, 2026
Merged
Conversation
Configure the ODBC DSN used by relog.exe to respect the Encrypt and Trust Server Certificate options the user selects when connecting SqlNexus to SQL Server, and modernize DSN driver selection. Changes: - BLGImporter: read Encrypt/TrustServerCertificate from the connection string and propagate them into the DSN so relog negotiates the same transport security as the rest of the app. - DSNCreator: append Encrypt and TrustServerCertificate keywords; try modern drivers first (ODBC Driver 18 -> 17 -> legacy "SQL Server") with logging and graceful fallback. - Extract BuildDsnSettings() as a testable helper (P/Invoke stays out of unit tests). - Rename DSN from "Nexus" to "SQLNexusDSN" via a shared constant so the registration and relog "-o SQL:<DSN>!<db>" argument stay in sync. - Add DSNCreatorTests (6 MSTest cases) and reference PerfmonImporter from the unit test project.
…elogEncryptConnection_pijocoder
…elogEncryptConnection_pijocoder
…lity fixes, and tests Improve the ODBC DSN creation used by relog.exe for Perfmon (.blg) import so it is future-proof, reliable, and fully unit-tested, while preserving the existing DSN settings and Encrypt / TrustServerCertificate behavior. DSN driver selection (future-proof): - Enumerate installed ODBC drivers via SQLGetInstalledDrivers instead of a hardcoded list. Prefer modern "ODBC Driver NN for SQL Server" drivers newest-version-first, so a future driver (19/20/...) is used automatically with no code change. - Keep the legacy "SQL Server" driver as a last-resort fallback (it largely ignores encryption keywords; warn when used with Encrypt). - Fall back to probing known driver names if enumeration fails, and log that it did. - Extract GetPreferredDrivers() as a pure, testable ordering helper. Reliability / correctness: - Fix malformed ODBC token in BuildDsnSettings SQL-auth path (stray ';' before UID). - Create the DSN once per import instead of once per file. - Report partial-import status when the user cancels part-way through. - Extract ReadEncryptionSettings() and make its fail-closed logging null-safe so it never throws when Util.Logger is unset (e.g. outside the WinForms host). - Do not log connection strings or credentials. Tests / infrastructure: - Add [InternalsVisibleTo] (with public key) so internal helpers are testable. - Add BLGImporterEncryptionTests and expand DSNCreatorTests to cover driver ordering, future versions, empty/null/legacy-only cases, and exact DSN token construction. All 15 PerfmonImporter unit tests pass; full solution build is clean.
Contributor
Andre Savioli (asavioliMSFT)
approved these changes
Sep 22, 2026
JosephPilov-MSFT (PiJoCoder)
deleted the
RelogEncryptConnection_pijocoder
branch
September 22, 2026 15:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Investigation Summary
Investigated whether
relog.exe, which SQL Nexus uses to import PerfMon (.blg) data into the repository database, can support encrypted SQL Server connections.Initial testing of the current SQL Nexus import path showed SQL Server sessions with:
indicating that the existing SQL Nexus configuration is not using SQL Server transport encryption.
To determine whether this was a limitation of Relog itself or of the DSN configuration, a separate test was performed using a manually created ODBC DSN configured with a modern SQL Server ODBC driver and encryption enabled.
relog.exe "D:\SQLLogScout\output\myserver_sql2017cs_20260901T1343469219_Perfmon.out_000001.blg" -f SQL -o SQL:SqlNexusTestDSN!CounterLogRelog successfully imported the .blg file into SQL Server and populated the expected CounterData and CounterDetails tables. SQL Server subsequently reported:
When I ran this query:
Root Cause
The ODBC DSN that SQL Nexus auto-creates for
relog.exe(inPerfmonImporter.DSNCreator) was:"SQL Server"ODBC driver (sqlsrv32.dll), which does not honor modern encryption keywords.Encrypt/TrustServerCertificateattributes, so it never negotiated transport encryption regardless of how the user connected SQL Nexus to SQL Server.As a result, the Perfmon import path always connected with
encrypt_option = FALSE, even when the rest of the application used an encrypted connection.Changes
Honor the app's encryption options for the relog DSN
BLGImporternow readsEncryptandTrustServerCertificatefrom the SQL Nexus connection string (Microsoft.Data.SqlClient, whereEncryptis aSqlConnectionEncryptOption;Mandatory/Strict=> encrypt,Optional=> no encryption) and propagates them into the DSN, so relog negotiates the same transport security as the rest of the app.DSNCreatorappends theEncryptandTrustServerCertificatekeywords to the DSN attribute string.Future-proof ODBC driver selection
SQLGetInstalledDrivers, preferring modern"ODBC Driver NN for SQL Server"drivers newest-version-first, with the legacy"SQL Server"driver kept only as a last-resort fallback (and a warning logged if it is used while encryption was requested). A newer driver (19/20/...) is picked up automatically with no code change.SQLGetInstalledDriversresult buffer is parsed by walking the double-null-terminated block and stopping at the list terminator, rather than trusting the returned length (whose char/byte semantics are ambiguous across ODBC versions).Reliability and correctness
;was prefixed onto theUIDkeyword).Debug.WriteLinewhenUtil.Loggeris unset, e.g. outside the WinForms host) so the handler never throws."Nexus"to"SQLNexusDSN"via a shared constant so the DSN registration and the relog-o SQL:<DSN>!<db>argument stay in sync.Security / privacy
Testing
Make sure you capture a SQL LogScout with one ore more .BLG (Perfmon) files and import it via SQL Nexus
While the BLG import is happening, run this query to ensure that the connection for Relog is encrypted:
Ensure the tables
dbo.CounterData,dbo.CounterDetailsare populated with dataUse the SQL Nexus reports, e.g. Perfmon Summary, to confirm data is there.