[not a newbie, really, but confused by this topic] I've read the many posts here, and articles throughout the web, about how to encrypt and decrypt connection strings and other sensitive data in your web.config file. But the final step always seems to include issuing an aspnet_regiis command on the host...