Sunday, March 25, 2012
Authorization Error in Reporting Services on Windows 2003
I have just reinstalled Reporting Services on win 2003 server that was
added to a domain and has been renamed. Two strange things happen:
1) In IE I am prompted for an ID and password with a basic security
prompt.
2) After supplying the credentials I get some of the report manager web
page but it has a 401 error instead of the folder and options to manage
projects.
The page looks like this:
Error
The request failed with HTTP status 401: Unauthorized.
Home
The reporting services error log contains the following error:
Unknown!ui!ed8!2/9/2005-20:44:32:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Pa=ADth>/reports/= Home.aspx</Path><NrReq>1</NrReq></Paths></User><=AD/Users>'
Unknown!ui!a24!2/9/2005-20:44:33:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Pa=ADth>/reports/= Pages/Folder.aspx</Path><NrReq>1</NrReq></Paths>=AD</User></Users>'
Unknown!ui!a24!2/9/2005-20:44:34:: e ERROR: The request failed with
HTTP status 401: Unauthorized.
Unknown!ui!a24!2/9/2005-20:44:35:: e ERROR: HTTP status code --> 500
I have not changed any of the config files that are installed.
Thanks for any help in advance,
EricTry restarting IIS. I think that is how they fixed the problem here.|||Try restarting IIS. I think that is how they cured the problem here.
authorization error in reporting services on win2003
I have just reinstalled Reporting Services on win 2003 server that was
added to a domain and has been renamed. Two strange things happen:
1) In IE I am prompted for an ID and password with a basic security
prompt.
2) After supplying the credentials I get some of the report manager web
page but it has a 401 error instead of the folder and options to manage
projects.
The page looks like this:
Error
The request failed with HTTP status 401: Unauthorized.
Home
The reporting services error log contains the following error:
Unknown!ui!ed8!2/9/2005-20:44:32:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Path>/reports/Home.aspx</Path><NrReq>1</NrReq></Paths></User></Users>'
Unknown!ui!a24!2/9/2005-20:44:33:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Path>/reports/Pages/Folder.aspx</Path><NrReq>1</NrReq></Paths></User></Users>'
Unknown!ui!a24!2/9/2005-20:44:34:: e ERROR: The request failed with
HTTP status 401: Unauthorized.
Unknown!ui!a24!2/9/2005-20:44:35:: e ERROR: HTTP status code --> 500
I have not changed any of the config files that are installed.
Thanks for any help in advance,
EricI have no idea, although there if you search Google groups for "sql
2000 reporting services http 401" there are a number of hits which may
be useful. You will probably get a better answer in
microsoft.public.sqlserver.reportingsvcs.
Simon
Authentication Problem x64
Win 2003 Server x64, .Net 2.0 x64 Reporting Services 2005. RS Database is a remote SQL 2005 on the same Domain in the same room. I can only get the report manager to authenticate local users; it will not authenticate Domain users.If I set up a local user and add a New Role Assignment all works OK.I have no problem adding a Domain user to a New Role Assignment, it allows this, but it will not authenticate the user.Adding the Domain user to the Windows Administrators group also has no effect.
Am I missing something simple?
I doubt this has anything to do with the x64-ness of your HW.
When you say "it will not authenticate the user", what exactly do you mean?
|||If I try to log on to http://mymachine/reports with a local user it will let me on.If I try to log on as a Domain user, it keeps bringing up the logon screen. (Windows Authentication)Both users are set up in a role in RS.
|||It sounds to me like IIS is not recognizing the user. Does that user have permissions on the machine aside from being in the RS role?|||If you are asking about the Domain users, NO. I am expecting it to work like Share Point, where you add the Domain user in the site and give it permissions on the site. Am I assuming wrong?|||Can you check the IIS logs on the machine for when the domain user tries to connect?
SRS doesn't grant the user any permissions on the box, so if the user did not have a valid account on the machine before, he still won't be able to have access to SRS because IIS will fail the request before it even gets to SRS.
|||John,
I see the Get entry in the IIS log, no other entries. I see a success audit entry in the Security Log for that user.
If I log on with the the local user, I see the POST entries etc in the IIS log.
Do I need to set up the domain user to have some local rights?
|||I finally wipped the machine clean and started again. Now RS will authenticate a domain user fine.Thursday, March 22, 2012
Authentication Problem
normally no problem for users to connect to the SQL server, I am now trying
to setup access for the IIS on one of the NT4 servers.
I have setup an ODBC connection on the NT4 server and added the IUSR account
for the NT server on the SQL server. However when I open an ASP page that
uses the DBC connection I get the error:
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
AUTHORITY\ANONYMOUS LOGON'.
I have also tried adding an SQL user account rather than a domain account
and tried to setup the ODBC connection using the SQL account but I then get
an error saying that it can't login as it is not associated with a trusted
SQL connection.
See if this helps:
http://support.microsoft.com/default...b;EN-US;247931
HTH,
Vyas, MVP (SQL Server)
http://vyaskn.tripod.com/
Is .NET important for a database professional?
http://vyaskn.tripod.com/poll.htm
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
I have an NT domain with an SQL Server 2000 server. Although there is
normally no problem for users to connect to the SQL server, I am now trying
to setup access for the IIS on one of the NT4 servers.
I have setup an ODBC connection on the NT4 server and added the IUSR account
for the NT server on the SQL server. However when I open an ASP page that
uses the DBC connection I get the error:
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
AUTHORITY\ANONYMOUS LOGON'.
I have also tried adding an SQL user account rather than a domain account
and tried to setup the ODBC connection using the SQL account but I then get
an error saying that it can't login as it is not associated with a trusted
SQL connection.
|||Moving a database from one disk to another on the same machine/same instance
of SQL Server should have NO effect on access..
You mentioned that users of OTHER databases are also having problems... The
table which might have the answer is in master..sysxlogins...
Do a dbcc checktable on it ( and maybe dbcc checkdb) on master... you may
have some corruption problems.
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
> I have an NT domain with an SQL Server 2000 server. Although there is
> normally no problem for users to connect to the SQL server, I am now
trying
> to setup access for the IIS on one of the NT4 servers.
> I have setup an ODBC connection on the NT4 server and added the IUSR
account
> for the NT server on the SQL server. However when I open an ASP page that
> uses the DBC connection I get the error:
> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
> AUTHORITY\ANONYMOUS LOGON'.
> I have also tried adding an SQL user account rather than a domain account
> and tried to setup the ODBC connection using the SQL account but I then
get
> an error saying that it can't login as it is not associated with a trusted
> SQL connection.
>
|||additionally, you might read in Books On Line about the procedure for moving
a log shipping database into production... It includes the tasks of getting
master..sysxlogins to match up with the database users..
Some of the information there will describe how the two tables work together
and how you might fix yours ( if it has been corrupted..)
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
> I have an NT domain with an SQL Server 2000 server. Although there is
> normally no problem for users to connect to the SQL server, I am now
trying
> to setup access for the IIS on one of the NT4 servers.
> I have setup an ODBC connection on the NT4 server and added the IUSR
account
> for the NT server on the SQL server. However when I open an ASP page that
> uses the DBC connection I get the error:
> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
> AUTHORITY\ANONYMOUS LOGON'.
> I have also tried adding an SQL user account rather than a domain account
> and tried to setup the ODBC connection using the SQL account but I then
get
> an error saying that it can't login as it is not associated with a trusted
> SQL connection.
>
Authentication Problem
normally no problem for users to connect to the SQL server, I am now trying
to setup access for the IIS on one of the NT4 servers.
I have setup an ODBC connection on the NT4 server and added the IUSR account
for the NT server on the SQL server. However when I open an ASP page that
uses the DBC connection I get the error:
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for
user 'NT
AUTHORITY\ANONYMOUS LOGON'.
I have also tried adding an SQL user account rather than a domain account
and tried to setup the ODBC connection using the SQL account but I then get
an error saying that it can't login as it is not associated with a trusted
SQL connection.See if this helps:
http://support.microsoft.com/defaul...kb;EN-US;247931
--
HTH,
Vyas, MVP (SQL Server)
http://vyaskn.tripod.com/
Is .NET important for a database professional?
http://vyaskn.tripod.com/poll.htm
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
I have an NT domain with an SQL Server 2000 server. Although there is
normally no problem for users to connect to the SQL server, I am now trying
to setup access for the IIS on one of the NT4 servers.
I have setup an ODBC connection on the NT4 server and added the IUSR account
for the NT server on the SQL server. However when I open an ASP page that
uses the DBC connection I get the error:
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for
user 'NT
AUTHORITY\ANONYMOUS LOGON'.
I have also tried adding an SQL user account rather than a domain account
and tried to setup the ODBC connection using the SQL account but I then get
an error saying that it can't login as it is not associated with a trusted
SQL connection.|||Moving a database from one disk to another on the same machine/same instance
of SQL Server should have NO effect on access..
You mentioned that users of OTHER databases are also having problems... The
table which might have the answer is in master..sysxlogins...
Do a dbcc checktable on it ( and maybe dbcc checkdb) on master... you may
have some corruption problems.
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
> I have an NT domain with an SQL Server 2000 server. Although there is
> normally no problem for users to connect to the SQL server, I am now
trying
> to setup access for the IIS on one of the NT4 servers.
> I have setup an ODBC connection on the NT4 server and added the IUSR
account
> for the NT server on the SQL server. However when I open an ASP page that
> uses the DBC connection I get the error:
> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed fo
r user 'NT
> AUTHORITY\ANONYMOUS LOGON'.
> I have also tried adding an SQL user account rather than a domain account
> and tried to setup the ODBC connection using the SQL account but I then
get
> an error saying that it can't login as it is not associated with a trusted
> SQL connection.
>|||additionally, you might read in Books On Line about the procedure for moving
a log shipping database into production... It includes the tasks of getting
master..sysxlogins to match up with the database users..
Some of the information there will describe how the two tables work together
and how you might fix yours ( if it has been corrupted..)
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
> I have an NT domain with an SQL Server 2000 server. Although there is
> normally no problem for users to connect to the SQL server, I am now
trying
> to setup access for the IIS on one of the NT4 servers.
> I have setup an ODBC connection on the NT4 server and added the IUSR
account
> for the NT server on the SQL server. However when I open an ASP page that
> uses the DBC connection I get the error:
> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed fo
r user 'NT
> AUTHORITY\ANONYMOUS LOGON'.
> I have also tried adding an SQL user account rather than a domain account
> and tried to setup the ODBC connection using the SQL account but I then
get
> an error saying that it can't login as it is not associated with a trusted
> SQL connection.
>
Authentication problem
2 Windows Server 2003 Standard Edtion Servers with Domain Controller, eg.: DC1 & DC2
4 Workstations (Win XP Pro SP2)
2 workstations are member of DC1, eg.: DC1_WS1 & DC1_WS2
and another 2 workstation are member of DC2, eg.: DC2_WS1 & DC2_WS2
SQL Server 2005 Express SP2 is installed on DC1_WS1 (Mix Authentication, Server Name: DC1)
My problem:
1. I use SSMSE on DC1_WS2, connect to DC1 with SQL Server Authentication (sa). Login Failed.
(I did off the firewall, enabled remote connections: Using both TCP/IP and named pipes)
My questions:
1. with the above setup, is it possible to use DC2_WS1 connect to DC1?
2. is my problem will be solved if I install SQL Server 2005 Exprees in DC1?
Please advise. Thanks.
1) You should be able to connect with SQL Authentication. What's your exact error message? What did you see in the server errorlog?
2) Install SQL Server on DC is not recommended.
|||"2) Install SQL Server on DC is not recommended. "
This means SQL Server is better install on workstation?
|||Yes. Just don't share a machine with DC, otherwise, it may cause configuration issue hard to track.Authentication problem
running into problems. The scenario is a server in one domain that will be a
publisher using a remote distributor in a different domain. When trying to
configure the publisher server, I keep getting a 'server does not exist or
access denied' when it tries to configure the remote distributor. I know the
server exists, so I figure I have messed up something in the way they
authenticate with each other. There is a 2-way trust between the domains and
none of the SQL or SQL Agent Services are running under the system accounts.
Any suggestions or links to good info would be most appreciated.
Thanks,
Bob Castleman
DBA Poseur
have a look at this link
http://support.microsoft.com/default...b;en-us;321822
Hilary Cotter
Looking for a SQL Server replication book?
http://www.nwsu.com/0974973602.html
Looking for a FAQ on Indexing Services/SQL FTS
http://www.indexserverfaq.com
"Bob Castleman" <nomail@.here> wrote in message
news:OfeDgG1SFHA.3244@.TK2MSFTNGP15.phx.gbl...
> I am setting up replication for the first time and, as can be expected,
> running into problems. The scenario is a server in one domain that will be
a
> publisher using a remote distributor in a different domain. When trying to
> configure the publisher server, I keep getting a 'server does not exist or
> access denied' when it tries to configure the remote distributor. I know
the
> server exists, so I figure I have messed up something in the way they
> authenticate with each other. There is a 2-way trust between the domains
and
> none of the SQL or SQL Agent Services are running under the system
accounts.
> Any suggestions or links to good info would be most appreciated.
> Thanks,
> Bob Castleman
> DBA Poseur
>
|||THanks!
"Hilary Cotter" <hilary.cotter@.gmail.com> wrote in message
news:OZfKQG2SFHA.2128@.TK2MSFTNGP15.phx.gbl...
> have a look at this link
> http://support.microsoft.com/default...b;en-us;321822
> --
> Hilary Cotter
> Looking for a SQL Server replication book?
> http://www.nwsu.com/0974973602.html
> Looking for a FAQ on Indexing Services/SQL FTS
> http://www.indexserverfaq.com
> "Bob Castleman" <nomail@.here> wrote in message
> news:OfeDgG1SFHA.3244@.TK2MSFTNGP15.phx.gbl...
> a
> the
> and
> accounts.
>
Authentication Problem
normally no problem for users to connect to the SQL server, I am now trying
to setup access for the IIS on one of the NT4 servers.
I have setup an ODBC connection on the NT4 server and added the IUSR account
for the NT server on the SQL server. However when I open an ASP page that
uses the DBC connection I get the error:
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
AUTHORITY\ANONYMOUS LOGON'.
I have also tried adding an SQL user account rather than a domain account
and tried to setup the ODBC connection using the SQL account but I then get
an error saying that it can't login as it is not associated with a trusted
SQL connection.See if this helps:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;247931
--
HTH,
Vyas, MVP (SQL Server)
http://vyaskn.tripod.com/
Is .NET important for a database professional?
http://vyaskn.tripod.com/poll.htm
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
I have an NT domain with an SQL Server 2000 server. Although there is
normally no problem for users to connect to the SQL server, I am now trying
to setup access for the IIS on one of the NT4 servers.
I have setup an ODBC connection on the NT4 server and added the IUSR account
for the NT server on the SQL server. However when I open an ASP page that
uses the DBC connection I get the error:
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
AUTHORITY\ANONYMOUS LOGON'.
I have also tried adding an SQL user account rather than a domain account
and tried to setup the ODBC connection using the SQL account but I then get
an error saying that it can't login as it is not associated with a trusted
SQL connection.|||Moving a database from one disk to another on the same machine/same instance
of SQL Server should have NO effect on access..
You mentioned that users of OTHER databases are also having problems... The
table which might have the answer is in master..sysxlogins...
Do a dbcc checktable on it ( and maybe dbcc checkdb) on master... you may
have some corruption problems.
--
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
> I have an NT domain with an SQL Server 2000 server. Although there is
> normally no problem for users to connect to the SQL server, I am now
trying
> to setup access for the IIS on one of the NT4 servers.
> I have setup an ODBC connection on the NT4 server and added the IUSR
account
> for the NT server on the SQL server. However when I open an ASP page that
> uses the DBC connection I get the error:
> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
> AUTHORITY\ANONYMOUS LOGON'.
> I have also tried adding an SQL user account rather than a domain account
> and tried to setup the ODBC connection using the SQL account but I then
get
> an error saying that it can't login as it is not associated with a trusted
> SQL connection.
>|||additionally, you might read in Books On Line about the procedure for moving
a log shipping database into production... It includes the tasks of getting
master..sysxlogins to match up with the database users..
Some of the information there will describe how the two tables work together
and how you might fix yours ( if it has been corrupted..)
--
Wayne Snyder, MCDBA, SQL Server MVP
Mariner, Charlotte, NC
www.mariner-usa.com
(Please respond only to the newsgroups.)
I support the Professional Association of SQL Server (PASS) and it's
community of SQL Server professionals.
www.sqlpass.org
"MJ" <spaamfree@.belmont.co.uk> wrote in message
news:10dvjd2gvhivcb2@.corp.supernews.com...
> I have an NT domain with an SQL Server 2000 server. Although there is
> normally no problem for users to connect to the SQL server, I am now
trying
> to setup access for the IIS on one of the NT4 servers.
> I have setup an ODBC connection on the NT4 server and added the IUSR
account
> for the NT server on the SQL server. However when I open an ASP page that
> uses the DBC connection I get the error:
> [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'NT
> AUTHORITY\ANONYMOUS LOGON'.
> I have also tried adding an SQL user account rather than a domain account
> and tried to setup the ODBC connection using the SQL account but I then
get
> an error saying that it can't login as it is not associated with a trusted
> SQL connection.
>
Authentication Issues
Windows 2003 Server
SQL Server 2000 w/ SP3
Windows Sharepoint Servics
Problem:
I have created a group on our Domain (INT) called Domain Users. Inside this group I have added individual users that need to be there.
On the SQL Server when I try to add INT\Domain Users I get an error stateing that the user does not exist. Next I tried typing in INT and selecting the browse button. The window opens up listing all Domain users and groups including the one I added 'Domain Users'. I select Domain users from the Drop down list and hit OK. I then hit OK at the bottom of the Add User window and get the error User does not exist.
Any help or insight would be greatly appreciated.
Thank You
Tom McClung
Can you execute the following statement in Query Analyzer and post the output here:
sp_grantlogin 'INT\Domain Users'
Please post both the line containing the error number and error state, and the line containing the error message.
Thanks
Laurentiu
Windows NT User or Group 'INT\Domain Users' not found. Check the name again.
Tom
|||Just a bit more information incase it's needed.
This server is not the domain controller. The domain controller is running Windows 2k Server software.
Tom
|||
Thanks for the information.
I have two additional questions:
(1) Are you able to add any INT user as a SQL login, or do you hit the same error for any INT principal that you attempt to add with sp_grantlogin.
(2) What was the tool that you were using to browse the domain users, which you mentioned in the initial email?
Not sure if it is related, but have you considered upgrading to SP4?
Thanks
Laurentiu
(2) In the SQL server enterprise manager I went to the security folder and then clicked on logins. Then groups. In the group window at the top I typed in INT and clicked the browse button next to it. This brought up a drop down menu of all the INT users and groups correctly.
(3) I will download SP4 and test.
Tom
|||SP4 installed and I still have the same authentication issues.
I can see the INT domain users in the SQL Server Login menu but when I attempt to add the error comes up with user does not exist.
Tom
|||
What is the service account that SQL Server is running under? One possibility might be that the service account cannot query the INT domain. Did you add the Administrator account manually?
You could also attempt to install SQL Server Express and perform the same operation (as a precaution, you should backup your existing databases to avoid any loss). The error messages in SQL Server 2005 provide additional information that could help identify the issue. Make sure you set SQL Server Express to run under the same account as the existing SQL Server 2000 installation.
Thanks
Laurentiu
Also, adding domain groups into local groups on the server, through compmgmt.msc > Local Users and Groups will deterimne if everythings okay at the OS level.
If that is working, it could be that the SQL Service is lacking in user rights, or the account you are interactively logged in with is either local or otherwise unable to enumerate accounts on the domain.|||Make sure u got checked mix authentication mode on ur server.|||
I am having exactly the same problem.
Setup:
SQL Server 2000 Standard Edition SP4; service login account is a domain account that is a member of domain admins (it was not for normal operation; I added it to domain admins to see if login creation would work - it did not)
Windows 2003 Server Standard Edition, SP1 and all subsequent updates installed; it is an AD domain controller in a single-domain forest.
I am logging onto the DC with a domain admin username/password
DCs are replicating fine; I created a test group on one DC and saw it immediately on other DC. For this issue, tried creating a new group on first one DC, then the other (non-SQL Server) one.
As with the initial post, I can see all groups and users - incl. my newly created group - in the security pulldown, but selecting my group fails exactly as initial post specifies. I.e. I am not typing anything (so no typos), just picking from pre-populated lists.
Mixed authentication is enabled. Tried rebooting after creating AD group; still failed. Tried adding SQL Server to AD; still failed. Error message 15401 is unhelpful, nor does MS site have any further helpful info.
Infrastructure works fine; this is a small LAN, everything resolves etc.
The SQL Server has been operational for a month or so. *Nothing* else has been installed on this DC.
We do have some group policy settings in place; very minimal though. Does anyone know if anything in routine group policy could possibly prevent a domain admin logged into Windows 2003 from adding a login for a domain group when the SQL Server service is running under a (separate) domain admin account?
Any help is appreciated. Thanks.
UPDATE: I was able to add my domain group to the BUILTIN Administrators group using AD Users and Computers. The same domain group cannot be added in SQL Server as described above.
|||Mulhall wrote:
This is likely to be unrelated to SQL Server; check DNS is properly configured otherwise comms with DCs will be problematic - use ping, nslookup and arp commands to verify this.
Also, adding domain groups into local groups on the server, through compmgmt.msc > Local Users and Groups will deterimne if everythings okay at the OS level.
If that is working, it could be that the SQL Service is lacking in user rights, or the account you are interactively logged in with is either local or otherwise unable to enumerate accounts on the domain.
The authentication mode does not matter for the operation of creating a login.
Just to make sure I understand this setup: is SQL Server 2000 installed on the DC machine, or on a different machine?
Thanks
Laurentiu
OK, I figured out how to at least fix the symptom temporarily. Maybe someone more expert than me at AD can come up with a fundamental explanation based on what I did.
First, this is NOT a SQL Server issue. It is an Active Directory replication issue.
Initially, I noticed event log entries on my SQL-hosting DC (which was not a GC server - yet) that the Net Logon service was paused due to replication problems. So I started it and it started, but after reboot it went back to paused.
I decided to use the Windows 2003 replmon.exe support tool to check into my DCs' replication status. Indeed, the DC hosting SQL Server showed broken replication from the PDC/GC DC.
Long story short, I made the DC hosting SQL a GC server also. Then, I opened AD Sites & Services on both DCs and deleted the automatically generated NTDS connections, then added my own manually. Left all settings at default (except of course which server was connected).
Then I used replmon.exe to "Synchronize each directory partition with all servers". Invoked this from both my DCs.
This seemed to do the trick. I could now add domain groups in SQL Server. Replmon.exe showed no more red x glyphs.
I had earlier tried replmon.exe and selecting "replicate now" for DC connections in Sites & Services leaving the automatically-generated connections in place. That was spotty, and while replmon.exe showed success a couple of times (no red x glyphs), shortly thereafter the red x glyphs reappeared and Users & Computers changes were no longer propagating.
That's when I created manual replication connections in Sites & Services. Crossing my fingers at this point... we'll see how it goes.
One final piece of info. My second DC - the one hosting SQL Server - is not a 24/7 machine. It is down (on purpose) quite a bit. Generally it is on every day for several hours, and it may or may not be on on weekends.
So, hopefully an AD wizard out there will see this and have a helpful epiphany.
BTW I can't resist one bit of carping. Why on Earth is a vital system tool like replmon.exe NOT in the default Windows 2003 install - meaning I have to go find the CD, then the support tools dir, then decide which of the msi and exe files to run, when unneeded end-user stuff like Windows Media Player, DirectX, and so on are on a default server install?
pelazem wrote:
I am having exactly the same problem.
Setup:
SQL Server 2000 Standard Edition SP4; service login account is a domain account that is a member of domain admins (it was not for normal operation; I added it to domain admins to see if login creation would work - it did not)
Windows 2003 Server Standard Edition, SP1 and all subsequent updates installed; it is an AD domain controller in a single-domain forest.
I am logging onto the DC with a domain admin username/password
DCs are replicating fine; I created a test group on one DC and saw it immediately on other DC. For this issue, tried creating a new group on first one DC, then the other (non-SQL Server) one.
As with the initial post, I can see all groups and users - incl. my newly created group - in the security pulldown, but selecting my group fails exactly as initial post specifies. I.e. I am not typing anything (so no typos), just picking from pre-populated lists.
Mixed authentication is enabled. Tried rebooting after creating AD group; still failed. Tried adding SQL Server to AD; still failed. Error message 15401 is unhelpful, nor does MS site have any further helpful info.
Infrastructure works fine; this is a small LAN, everything resolves etc.
The SQL Server has been operational for a month or so. *Nothing* else has been installed on this DC.
We do have some group policy settings in place; very minimal though. Does anyone know if anything in routine group policy could possibly prevent a domain admin logged into Windows 2003 from adding a login for a domain group when the SQL Server service is running under a (separate) domain admin account?
Any help is appreciated. Thanks.
UPDATE: I was able to add my domain group to the BUILTIN Administrators group using AD Users and Computers. The same domain group cannot be added in SQL Server as described above.
Mulhall wrote:
This is likely to be unrelated to SQL Server; check DNS is properly configured otherwise comms with DCs will be problematic - use ping, nslookup and arp commands to verify this. Also, adding domain groups into local groups on the server, through compmgmt.msc > Local Users and Groups will deterimne if everythings okay at the OS level.
If that is working, it could be that the SQL Service is lacking in user rights, or the account you are interactively logged in with is either local or otherwise unable to enumerate accounts on the domain.
Authentication Issues
Windows 2003 Server
SQL Server 2000 w/ SP3
Windows Sharepoint Servics
Problem:
I have created a group on our Domain (INT) called Domain Users. Inside this group I have added individual users that need to be there.
On the SQL Server when I try to add INT\Domain Users I get an error stateing that the user does not exist. Next I tried typing in INT and selecting the browse button. The window opens up listing all Domain users and groups including the one I added 'Domain Users'. I select Domain users from the Drop down list and hit OK. I then hit OK at the bottom of the Add User window and get the error User does not exist.
Any help or insight would be greatly appreciated.
Thank You
Tom McClung
Can you execute the following statement in Query Analyzer and post the output here:
sp_grantlogin 'INT\Domain Users'
Please post both the line containing the error number and error state, and the line containing the error message.
Thanks
Laurentiu
Windows NT User or Group 'INT\Domain Users' not found. Check the name again.
Tom
|||Just a bit more information incase it's needed.
This server is not the domain controller. The domain controller is running Windows 2k Server software.
Tom
|||
Thanks for the information.
I have two additional questions:
(1) Are you able to add any INT user as a SQL login, or do you hit the same error for any INT principal that you attempt to add with sp_grantlogin.
(2) What was the tool that you were using to browse the domain users, which you mentioned in the initial email?
Not sure if it is related, but have you considered upgrading to SP4?
Thanks
Laurentiu
(2) In the SQL server enterprise manager I went to the security folder and then clicked on logins. Then groups. In the group window at the top I typed in INT and clicked the browse button next to it. This brought up a drop down menu of all the INT users and groups correctly.
(3) I will download SP4 and test.
Tom
|||SP4 installed and I still have the same authentication issues.
I can see the INT domain users in the SQL Server Login menu but when I attempt to add the error comes up with user does not exist.
Tom
|||
What is the service account that SQL Server is running under? One possibility might be that the service account cannot query the INT domain. Did you add the Administrator account manually?
You could also attempt to install SQL Server Express and perform the same operation (as a precaution, you should backup your existing databases to avoid any loss). The error messages in SQL Server 2005 provide additional information that could help identify the issue. Make sure you set SQL Server Express to run under the same account as the existing SQL Server 2000 installation.
Thanks
Laurentiu
Also, adding domain groups into local groups on the server, through compmgmt.msc > Local Users and Groups will deterimne if everythings okay at the OS level.
If that is working, it could be that the SQL Service is lacking in user rights, or the account you are interactively logged in with is either local or otherwise unable to enumerate accounts on the domain.|||Make sure u got checked mix authentication mode on ur server.|||
I am having exactly the same problem.
Setup:
SQL Server 2000 Standard Edition SP4; service login account is a domain account that is a member of domain admins (it was not for normal operation; I added it to domain admins to see if login creation would work - it did not)
Windows 2003 Server Standard Edition, SP1 and all subsequent updates installed; it is an AD domain controller in a single-domain forest.
I am logging onto the DC with a domain admin username/password
DCs are replicating fine; I created a test group on one DC and saw it immediately on other DC. For this issue, tried creating a new group on first one DC, then the other (non-SQL Server) one.
As with the initial post, I can see all groups and users - incl. my newly created group - in the security pulldown, but selecting my group fails exactly as initial post specifies. I.e. I am not typing anything (so no typos), just picking from pre-populated lists.
Mixed authentication is enabled. Tried rebooting after creating AD group; still failed. Tried adding SQL Server to AD; still failed. Error message 15401 is unhelpful, nor does MS site have any further helpful info.
Infrastructure works fine; this is a small LAN, everything resolves etc.
The SQL Server has been operational for a month or so. *Nothing* else has been installed on this DC.
We do have some group policy settings in place; very minimal though. Does anyone know if anything in routine group policy could possibly prevent a domain admin logged into Windows 2003 from adding a login for a domain group when the SQL Server service is running under a (separate) domain admin account?
Any help is appreciated. Thanks.
UPDATE: I was able to add my domain group to the BUILTIN Administrators group using AD Users and Computers. The same domain group cannot be added in SQL Server as described above.
|||Mulhall wrote:
This is likely to be unrelated to SQL Server; check DNS is properly configured otherwise comms with DCs will be problematic - use ping, nslookup and arp commands to verify this.
Also, adding domain groups into local groups on the server, through compmgmt.msc > Local Users and Groups will deterimne if everythings okay at the OS level.
If that is working, it could be that the SQL Service is lacking in user rights, or the account you are interactively logged in with is either local or otherwise unable to enumerate accounts on the domain.
The authentication mode does not matter for the operation of creating a login.
Just to make sure I understand this setup: is SQL Server 2000 installed on the DC machine, or on a different machine?
Thanks
Laurentiu
OK, I figured out how to at least fix the symptom temporarily. Maybe someone more expert than me at AD can come up with a fundamental explanation based on what I did.
First, this is NOT a SQL Server issue. It is an Active Directory replication issue.
Initially, I noticed event log entries on my SQL-hosting DC (which was not a GC server - yet) that the Net Logon service was paused due to replication problems. So I started it and it started, but after reboot it went back to paused.
I decided to use the Windows 2003 replmon.exe support tool to check into my DCs' replication status. Indeed, the DC hosting SQL Server showed broken replication from the PDC/GC DC.
Long story short, I made the DC hosting SQL a GC server also. Then, I opened AD Sites & Services on both DCs and deleted the automatically generated NTDS connections, then added my own manually. Left all settings at default (except of course which server was connected).
Then I used replmon.exe to "Synchronize each directory partition with all servers". Invoked this from both my DCs.
This seemed to do the trick. I could now add domain groups in SQL Server. Replmon.exe showed no more red x glyphs.
I had earlier tried replmon.exe and selecting "replicate now" for DC connections in Sites & Services leaving the automatically-generated connections in place. That was spotty, and while replmon.exe showed success a couple of times (no red x glyphs), shortly thereafter the red x glyphs reappeared and Users & Computers changes were no longer propagating.
That's when I created manual replication connections in Sites & Services. Crossing my fingers at this point... we'll see how it goes.
One final piece of info. My second DC - the one hosting SQL Server - is not a 24/7 machine. It is down (on purpose) quite a bit. Generally it is on every day for several hours, and it may or may not be on on weekends.
So, hopefully an AD wizard out there will see this and have a helpful epiphany.
BTW I can't resist one bit of carping. Why on Earth is a vital system tool like replmon.exe NOT in the default Windows 2003 install - meaning I have to go find the CD, then the support tools dir, then decide which of the msi and exe files to run, when unneeded end-user stuff like Windows Media Player, DirectX, and so on are on a default server install?
sqlpelazem wrote:
I am having exactly the same problem.
Setup:
SQL Server 2000 Standard Edition SP4; service login account is a domain account that is a member of domain admins (it was not for normal operation; I added it to domain admins to see if login creation would work - it did not)
Windows 2003 Server Standard Edition, SP1 and all subsequent updates installed; it is an AD domain controller in a single-domain forest.
I am logging onto the DC with a domain admin username/password
DCs are replicating fine; I created a test group on one DC and saw it immediately on other DC. For this issue, tried creating a new group on first one DC, then the other (non-SQL Server) one.
As with the initial post, I can see all groups and users - incl. my newly created group - in the security pulldown, but selecting my group fails exactly as initial post specifies. I.e. I am not typing anything (so no typos), just picking from pre-populated lists.
Mixed authentication is enabled. Tried rebooting after creating AD group; still failed. Tried adding SQL Server to AD; still failed. Error message 15401 is unhelpful, nor does MS site have any further helpful info.
Infrastructure works fine; this is a small LAN, everything resolves etc.
The SQL Server has been operational for a month or so. *Nothing* else has been installed on this DC.
We do have some group policy settings in place; very minimal though. Does anyone know if anything in routine group policy could possibly prevent a domain admin logged into Windows 2003 from adding a login for a domain group when the SQL Server service is running under a (separate) domain admin account?
Any help is appreciated. Thanks.
UPDATE: I was able to add my domain group to the BUILTIN Administrators group using AD Users and Computers. The same domain group cannot be added in SQL Server as described above.
Mulhall wrote:
This is likely to be unrelated to SQL Server; check DNS is properly configured otherwise comms with DCs will be problematic - use ping, nslookup and arp commands to verify this. Also, adding domain groups into local groups on the server, through compmgmt.msc > Local Users and Groups will deterimne if everythings okay at the OS level.
If that is working, it could be that the SQL Service is lacking in user rights, or the account you are interactively logged in with is either local or otherwise unable to enumerate accounts on the domain.
Authentication Issue - Cannot connect from one wkstation
I am having trouble using windows authentication to connect to a SQL Server
2000 instance on a Windows 2003 Server. I can connect with my domain account
from Computer A but not from Computer B. Other authentication requirements
to the server seem to be fine from Computer B eg I use my domain account to
logon to Computer B and I can remote to the server from Computer B.
I was having some issues with my profile on Computer B so I wonder if this
has affected some cached credentials for SQL Server or something else. Any
help with this would be most appreciated.
Thanks, TadHi,
which error do you get ?
HTH, Jens K. Suessmeyer.
--
http://www.sqlserver2005.de
--|||Hi,
In SQL Query Analyzer:
Unable to connect to server XXXX:
Server: Msg 17, Level 16, State 1
[Microsoft][ODBC SQL Server Driver][DBNETLIB]SQL Server does not exist or
access denied.
In MS SQL Server Mgmt Studio:
Cannot connect to XXXXX.
--
ADDITIONAL INFORMATION:
An error has occurred while establishing a connection to the server. When
connecting to SQL Server 2005, this failure may be caused by the fact that
under the default settings SQL Server does not allow remote connections.
(provider: Named Pipes Provider, error: 40 - Could not open a connection to
SQL Server) (Microsoft SQL Server, Error: 2)
In SQL Enterprise Manager (while trying to register server):
XXXX - SQL Server does not exist or access denied.
ConnectionOpen (Connect())
"Jens" wrote:
> Hi,
> which error do you get ?
> HTH, Jens K. Suessmeyer.
> --
> http://www.sqlserver2005.de
> --
>|||Are the computers in the same domain ? Which authentication method are
you using ?
Jens K. Suessmeyer.
--
http://www.sqlserver2005.de
--|||Tadwick wrote:
> Hi,
> I am having trouble using windows authentication to connect to a SQL Server
> 2000 instance on a Windows 2003 Server. I can connect with my domain account
> from Computer A but not from Computer B. Other authentication requirements
> to the server seem to be fine from Computer B eg I use my domain account to
> logon to Computer B and I can remote to the server from Computer B.
> I was having some issues with my profile on Computer B so I wonder if this
> has affected some cached credentials for SQL Server or something else. Any
> help with this would be most appreciated.
> Thanks, Tad
Are you sure it's an authentication error and not something network
related? Can you even SEE the server from this workstation? Can you
ping it by hostname AND by IP address? Can you connect to SQL via the
IP address?
Tracy McKibben
MCDBA
http://www.realsqlguy.com
Authentication Issue - Cannot connect from one wkstation
I am having trouble using windows authentication to connect to a SQL Server
2000 instance on a Windows 2003 Server. I can connect with my domain account
from Computer A but not from Computer B. Other authentication requirements
to the server seem to be fine from Computer B eg I use my domain account to
logon to Computer B and I can remote to the server from Computer B.
I was having some issues with my profile on Computer B so I wonder if this
has affected some cached credentials for SQL Server or something else. Any
help with this would be most appreciated.
Thanks, Tad
Hi,
which error do you get ?
HTH, Jens K. Suessmeyer.
http://www.sqlserver2005.de
|||Hi,
In SQL Query Analyzer:
Unable to connect to server XXXX:
Server: Msg 17, Level 16, State 1
[Microsoft][ODBC SQL Server Driver][DBNETLIB]SQL Server does not exist or
access denied.
In MS SQL Server Mgmt Studio:
Cannot connect to XXXXX.
ADDITIONAL INFORMATION:
An error has occurred while establishing a connection to the server. When
connecting to SQL Server 2005, this failure may be caused by the fact that
under the default settings SQL Server does not allow remote connections.
(provider: Named Pipes Provider, error: 40 - Could not open a connection to
SQL Server) (Microsoft SQL Server, Error: 2)
In SQL Enterprise Manager (while trying to register server):
XXXX - SQL Server does not exist or access denied.
ConnectionOpen (Connect())
"Jens" wrote:
> Hi,
> which error do you get ?
> HTH, Jens K. Suessmeyer.
> --
> http://www.sqlserver2005.de
> --
>
|||Are the computers in the same domain ? Which authentication method are
you using ?
Jens K. Suessmeyer.
http://www.sqlserver2005.de
|||yes, same domain and Windows authentication
"Jens" wrote:
> Are the computers in the same domain ? Which authentication method are
> you using ?
> Jens K. Suessmeyer.
> --
> http://www.sqlserver2005.de
> --
>
|||Tadwick wrote:
> Hi,
> I am having trouble using windows authentication to connect to a SQL Server
> 2000 instance on a Windows 2003 Server. I can connect with my domain account
> from Computer A but not from Computer B. Other authentication requirements
> to the server seem to be fine from Computer B eg I use my domain account to
> logon to Computer B and I can remote to the server from Computer B.
> I was having some issues with my profile on Computer B so I wonder if this
> has affected some cached credentials for SQL Server or something else. Any
> help with this would be most appreciated.
> Thanks, Tad
Are you sure it's an authentication error and not something network
related? Can you even SEE the server from this workstation? Can you
ping it by hostname AND by IP address? Can you connect to SQL via the
IP address?
Tracy McKibben
MCDBA
http://www.realsqlguy.com
|||Tracy,
Your note just prompted me to the solution. It was not authentication - it
was because I used a custom instance name and was so used to it being there
by default when I open a client side tool that I forgot to specify when my
profile changed on Computer B. Embarassing, but true.
Thanks to you and Jens for getting me there.
Tad
"Tracy McKibben" wrote:
> Tadwick wrote:
> Are you sure it's an authentication error and not something network
> related? Can you even SEE the server from this workstation? Can you
> ping it by hostname AND by IP address? Can you connect to SQL via the
> IP address?
>
> --
> Tracy McKibben
> MCDBA
> http://www.realsqlguy.com
>
Authentication Issue - Cannot connect from one wkstation
I am having trouble using windows authentication to connect to a SQL Server
2000 instance on a Windows 2003 Server. I can connect with my domain accoun
t
from Computer A but not from Computer B. Other authentication requirements
to the server seem to be fine from Computer B eg I use my domain account to
logon to Computer B and I can remote to the server from Computer B.
I was having some issues with my profile on Computer B so I wonder if this
has affected some cached credentials for SQL Server or something else. Any
help with this would be most appreciated.
Thanks, TadHi,
which error do you get ?
HTH, Jens K. Suessmeyer.
http://www.sqlserver2005.de
--|||Hi,
In SQL Query Analyzer:
Unable to connect to server XXXX:
Server: Msg 17, Level 16, State 1
[Microsoft][ODBC SQL Server Driver][DBNETLIB]SQL Server does not
exist or
access denied.
In MS SQL Server Mgmt Studio:
Cannot connect to XXXXX.
ADDITIONAL INFORMATION:
An error has occurred while establishing a connection to the server. When
connecting to SQL Server 2005, this failure may be caused by the fact that
under the default settings SQL Server does not allow remote connections.
(provider: Named Pipes Provider, error: 40 - Could not open a connection to
SQL Server) (Microsoft SQL Server, Error: 2)
In SQL Enterprise Manager (while trying to register server):
XXXX - SQL Server does not exist or access denied.
ConnectionOpen (Connect())
"Jens" wrote:
> Hi,
> which error do you get ?
> HTH, Jens K. Suessmeyer.
> --
> http://www.sqlserver2005.de
> --
>|||Are the computers in the same domain ? Which authentication method are
you using ?
Jens K. Suessmeyer.
http://www.sqlserver2005.de
--|||yes, same domain and Windows authentication
"Jens" wrote:
> Are the computers in the same domain ? Which authentication method are
> you using ?
> Jens K. Suessmeyer.
> --
> http://www.sqlserver2005.de
> --
>|||Tadwick wrote:
> Hi,
> I am having trouble using windows authentication to connect to a SQL Serve
r
> 2000 instance on a Windows 2003 Server. I can connect with my domain acco
unt
> from Computer A but not from Computer B. Other authentication requirement
s
> to the server seem to be fine from Computer B eg I use my domain account t
o
> logon to Computer B and I can remote to the server from Computer B.
> I was having some issues with my profile on Computer B so I wonder if this
> has affected some cached credentials for SQL Server or something else. An
y
> help with this would be most appreciated.
> Thanks, Tad
Are you sure it's an authentication error and not something network
related? Can you even SEE the server from this workstation? Can you
ping it by hostname AND by IP address? Can you connect to SQL via the
IP address?
Tracy McKibben
MCDBA
http://www.realsqlguy.com|||Tracy,
Your note just prompted me to the solution. It was not authentication - it
was because I used a custom instance name and was so used to it being there
by default when I open a client side tool that I forgot to specify when my
profile changed on Computer B. Embarassing, but true.
Thanks to you and Jens for getting me there.
Tad
"Tracy McKibben" wrote:
> Tadwick wrote:
> Are you sure it's an authentication error and not something network
> related? Can you even SEE the server from this workstation? Can you
> ping it by hostname AND by IP address? Can you connect to SQL via the
> IP address?
>
> --
> Tracy McKibben
> MCDBA
> http://www.realsqlguy.com
>sql
Authentication Issue
We have a sql 2005 server that we need to connect to.
I am in one active directory domain (eg DomainA) and the sql 2005 server is in another (eg DomainB).
We are not allowed (by the sql 2005 server provider) to put a trust between the two active directory domains and sql server logins present an issue due to mirroring (this is not a question about mirroring).
Is there a way of logining the EnterpriseManager/QueryAnalyser applications in to the sql server 2005 in DomainB with out logging my whole machine into DomainB and with out using SQL server authentication.
Any help would be greatly apperiated
Hi,
Stored credentials can be found navigating to the to the Control Panel > User Accounts > Choose the User > manage you network accounts. You might have a fixed stored credential enetered there ?
HTH, Jens K. Suessmeyer.
http://www.sqlserver2005.de
Tuesday, March 20, 2012
Authentication failure - can't find domain accounts
We're getting an error where we can't add a login with the full dns name of a user - domain.xyz\user, for example. Get an error 15401, "Windows NT user or group domain.xyz\user' not found". The domain has a different Netbios name and DNS domain names, so we can add the user when we use the form "netbiosname\user". So far so good.
Unfortunately, we have another application - Office Share Point Server whose shared services provider won't run, giving errors in the event log every 60 seconds that "Windows NT user or group 'domain.xyz\user' not found".
It looks as if SQL insists upon listing users in the form netbiosdomainname\user, and applications that look for domain.xyz\user simply fail to authenticate.
Suggestions?
jnfranc at yahoo period com
SQL Server only understands NetBIOS names for Windows principals (i.e. when creating a login), but authentication via SSPI should work normally.
Please let us know if you still require help on this issue, if so, we will need more details regarding the failure, if possible the SQL Server error number/message.
Thanks a lot,
-Raul Garcia
SDE/T
SQL Server Engine
Authentication failure - can't find domain accounts
We're getting an error where we can't add a login with the full dns name of a user - domain.xyz\user, for example. Get an error 15401, "Windows NT user or group domain.xyz\user' not found". The domain has a different Netbios name and DNS domain names, so we can add the user when we use the form "netbiosname\user". So far so good.
Unfortunately, we have another application - Office Share Point Server whose shared services provider won't run, giving errors in the event log every 60 seconds that "Windows NT user or group 'domain.xyz\user' not found".
It looks as if SQL insists upon listing users in the form netbiosdomainname\user, and applications that look for domain.xyz\user simply fail to authenticate.
Suggestions?
jnfranc at yahoo period com
SQL Server only understands NetBIOS names for Windows principals (i.e. when creating a login), but authentication via SSPI should work normally.
Please let us know if you still require help on this issue, if so, we will need more details regarding the failure, if possible the SQL Server error number/message.
Thanks a lot,
-Raul Garcia
SDE/T
SQL Server Engine
sqlMonday, March 19, 2012
Authenticating from Active Directory Domain
inserts it into a table.
A user converted to an Active Directory Domain and the
suser_name comes up as null.
Is this the way it works? Or is there some setting that
has to be changed?
Any help appreciated.
Thanks,
GeorgeDirectly from BOL
suser_name is obsolete and always returns NULL in S2K.
"George Galcik" <anonymous@.discussions.microsoft.com> wrote in message
news:005b01c3dab4$6bf0fdb0$a101280a@.phx.gbl...
quote:|||Thanks for your help, Scott.
> We use a query that gets the suser_name parameter and
> inserts it into a table.
> A user converted to an Active Directory Domain and the
> suser_name comes up as null.
> Is this the way it works? Or is there some setting that
> has to be changed?
> Any help appreciated.
> Thanks,
> George
>
George
quote:
>--Original Message--
>Directly from BOL
>suser_name is obsolete and always returns NULL in S2K.
>"George Galcik" <anonymous@.discussions.microsoft.com>
wrote in message
quote:
>news:005b01c3dab4$6bf0fdb0$a101280a@.phx.gbl...
>
>.
>
Authenticating between Webserver and database Server
Environment:
Webserver on Server1
SqlServer on Server 2
Both machines in the same domain. I have followed the steps in the to create
a domain level account to run the ASPNET process that has access to the
database.
When I try to retrieve data from the DB, i get:
Login failed for user '(null)'. Reason: Not associated with a trusted SQL
Server connection. 18452
Any guidence would be appriciated.See "Security Account Delegation" in BOL.
AMB
"PublicRick" wrote:
> Not sure if this is an ASP.NET or a SQL issue...
> Environment:
> Webserver on Server1
> SqlServer on Server 2
> Both machines in the same domain. I have followed the steps in the to crea
te
> a domain level account to run the ASPNET process that has access to the
> database.
> When I try to retrieve data from the DB, i get:
> Login failed for user '(null)'. Reason: Not associated with a trusted SQL
> Server connection. 18452
> Any guidence would be appriciated.
>|||http://msdn.microsoft.com/library/default.asp?
AND
http://msdn.microsoft.com/library/d...
d19.asp
HTH, Jens SUessmeyer.
"PublicRick" <publicrick@.nospam.nospam> schrieb im Newsbeitrag
news:EE873E20-AA3E-41B5-9030-9F0A2C360A41@.microsoft.com...
> Not sure if this is an ASP.NET or a SQL issue...
> Environment:
> Webserver on Server1
> SqlServer on Server 2
> Both machines in the same domain. I have followed the steps in the to
> create
> a domain level account to run the ASPNET process that has access to the
> database.
> When I try to retrieve data from the DB, i get:
> Login failed for user '(null)'. Reason: Not associated with a trusted SQL
> Server connection. 18452
> Any guidence would be appriciated.
>
Authenticate via Active Directory from PC that's not joined the do
stand-alone, ie. they have not been joined to the domain. They do have an
account on the domain, though, which they use to map drives and such. How
can I set it up so that they can use Enterprise Manager or Query Analyzer by
authenticating with their domain account?Hello,
I suggest that you create a SQL login for each user. You can refer to the
following article:
Adding a SQL Server Login
http://msdn.microsoft.com/library/d...-us/adminsql/ad
_security_9m0e.asp
How to set up Mixed Mode security (Enterprise Manager)
http://msdn.microsoft.com/library/d...-us/howtosql/ht
_6_secrty_68c9.asp
Make sure SQL server use mixed mode Authentication.
If the client can join the domain with a domain user account, you can add
the domain user account as a Windows login. You can refer to the following
web site:
How to grant a Windows user or group login access to SQL Server (Enterprise
Manager)
http://msdn.microsoft.com/library/d...-us/howtosql/ht
_6_secrty_68c9.asp
Granting a Windows User or Group Access to a Database
http://msdn.microsoft.com/library/d...-us/adminsql/ad
_security_2wit.asp
I hope the information is helpful.
Sophie Guo
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
========================================
=============
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
========================================
=============
This posting is provided "AS IS" with no warranties, and confers no rights.
Sunday, March 11, 2012
Auditing changes...By developers
privy to db usernames and passwords?
Not all application users have domain accounts, so we can't use
trusted connections. Instead, we have a single username that the
application (we only have one) uses to perform its work.
We have auditing at the internal application level...Now we need a way
to determine if any of the four developers are possibly manipulating
data.
I briefly looked at application roles, but considering that you can
run sp_setapprole from the QA, that doesn't seem worthwhile.
How is everyone else doing it? Our auditors assure us it is being
done...
Don't you love SOX?
Thanks!
JosephYou can use a server side trace to monitor that login, who
is using it from what workstation and/or what application.
You can monitor with third party products as well. For third
party products and SOX, I've used Compliance Manager from
Idera: http://www.idera.com/Products/SQLcm/Default.aspx
-Sue
On 19 Mar 2007 16:25:28 -0700, "Joseph"
<josephsheppard@.gmail.com> wrote:
>What is the best way to go to track changes by developers that are
>privy to db usernames and passwords?
>Not all application users have domain accounts, so we can't use
>trusted connections. Instead, we have a single username that the
>application (we only have one) uses to perform its work.
>We have auditing at the internal application level...Now we need a way
>to determine if any of the four developers are possibly manipulating
>data.
>I briefly looked at application roles, but considering that you can
>run sp_setapprole from the QA, that doesn't seem worthwhile.
>How is everyone else doing it? Our auditors assure us it is being
>done...
>Don't you love SOX?
>Thanks!
>Joseph|||A couple of questions come to mind:
1) Do the developers need the ability to modify the data outside the applica
tion?
2) If so, how are they logging in? Do they know the single username/password
the application is using?
As Sue posted, a server side trace will show when data is being modified
because you can capture the statements. However, getting past the non-repudi
ation
hurdle (being able to deny you did it) is hard to do unless they are logging
in with an account whose password only they know and they aren't using share
d
accounts of any sort.
K. Brian Kelley, brian underscore kelley at sqlpass dot org
http://www.truthsolutions.com/
> What is the best way to go to track changes by developers that are
> privy to db usernames and passwords?
> Not all application users have domain accounts, so we can't use
> trusted connections. Instead, we have a single username that the
> application (we only have one) uses to perform its work.
> We have auditing at the internal application level...Now we need a way
> to determine if any of the four developers are possibly manipulating
> data.
> I briefly looked at application roles, but considering that you can
> run sp_setapprole from the QA, that doesn't seem worthwhile.
> How is everyone else doing it? Our auditors assure us it is being
> done...
> Don't you love SOX?
> Thanks!
> Joseph
>|||On Mar 19, 7:59 pm, K. Brian Kelley <brian_kel...@.REMOVE-
ME.sqlpass.org> wrote:
> A couple of questions come to mind:
> 1) Do the developers need the ability to modify the data outside the appli
cation?
> 2) If so, how are they logging in? Do they know the single username/passwo
rd
> the application is using?
> As Sue posted, a server side trace will show when data is being modified
> because you can capture the statements. However, getting past the non-repu
diation
> hurdle (being able to deny you did it) is hard to do unless they are loggi
ng
> in with an account whose password only they know and they aren't using sha
red
> accounts of any sort.
> K. Brian Kelley, brian underscore kelley at sqlpass dot orghttp://www.trut
hsolutions.com/
>
>
>
>
>
>
>
>
>
> - Show quoted text -
1) Actually, they *do* need the ability to modify outside of the app,
as it is a relatively new application, and corrections need to be
made.
2) Right now, all connections are being made with the username/
password the application uses. They do know it (although all options
are opened).
I was thinking that the developers could know the database login used
by the app, but then the application would switch to an application
role to get anything done. Thus the Query Analyzer statement: What's
to keep them from launching QA, executing sp_SetAppRole, and then
altering data without any of the application's safequards?
For the record, we are trusting the trail left by the application, and
we aren't concerned about that angle...
Thank you!|||I'm actually surprised that your auditors haven't flagged the fact that the
developers know the login the application uses. This is something most audit
ors
don't like.
My recommendations:
1) Change the login password the application uses and don't give it to the
developers (this will likely require Change Control / System Admin / DBA
/ etc. to be involved to set the connection string for the application).
2) Give the developers access via individual logins. This would preferably
be Windows user accounts given access via a Windows group.
3) Grant the access the developers need via a database role. Make the logins
a member of said role. Don't grant more than they need, for obvious reasons.
4) Audit via either traces or via triggers. Since you aren't worried about
the app, triggers probably aren't necessary.
The bottom line is that as long as they have access to a shared login, it
becomes very difficult to prove who did what. Information you normally see
in traces like hostname and app name can be forged and it is trivial to do
so because it comes from the client, meaning you can't rely on it. Therefore
,
you can't really determine from anything within SQL Server if it's the app
coming in or a developer if a developer intends to be malicious. That is,
unless you force them to their individual accounts.
K. Brian Kelley, brian underscore kelley at sqlpass dot org
http://www.truthsolutions.com/
> On Mar 19, 7:59 pm, K. Brian Kelley <brian_kel...@.REMOVE-
> ME.sqlpass.org> wrote:
>
> 1) Actually, they *do* need the ability to modify outside of the app,
> as it is a relatively new application, and corrections need to be
> made.
> 2) Right now, all connections are being made with the username/
> password the application uses. They do know it (although all options
> are opened).
> I was thinking that the developers could know the database login used
> by the app, but then the application would switch to an application
> role to get anything done. Thus the Query Analyzer statement: What's
> to keep them from launching QA, executing sp_SetAppRole, and then
> altering data without any of the application's safequards?
> For the record, we are trusting the trail left by the application, and
> we aren't concerned about that angle...
> Thank you!
>|||On Mar 19, 11:47 pm, K. Brian Kelley <brian_kel...@.REMOVE-
ME.sqlpass.org> wrote:
> I'm actually surprised that your auditors haven't flagged the fact that th
e
> developers know the login the application uses. This is something most aud
itors
> don't like.
> My recommendations:
> 1) Change the login password the application uses and don't give it to the
> developers (this will likely require Change Control / System Admin / DBA
> / etc. to be involved to set the connection string for the application).
> 2) Give the developers access via individual logins. This would preferably
> be Windows user accounts given access via a Windows group.
> 3) Grant the access the developers need via a database role. Make the logi
ns
> a member of said role. Don't grant more than they need, for obvious reason
s.
> 4) Audit via either traces or via triggers. Since you aren't worried about
> the app, triggers probably aren't necessary.
> The bottom line is that as long as they have access to a shared login, it
> becomes very difficult to prove who did what. Information you normally see
> in traces like hostname and app name can be forged and it is trivial to do
> so because it comes from the client, meaning you can't rely on it. Therefo
re,
> you can't really determine from anything within SQL Server if it's the app
> coming in or a developer if a developer intends to be malicious. That is,
> unless you force them to their individual accounts.
> K. Brian Kelley, brian underscore kelley at sqlpass dot orghttp://www.trut
hsolutions.com/
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> - Show quoted text -
Thanks, Brian!
I've actually made this recommendation in my "Most Secure" plan...It
will just take some time to get the code changes in place.
(Currently, the application reads the credentials from a two-way
encrypted file using TripleDES). I like the idea of a protected
connection string...Perhaps a compiled .dll in the hands of the DBA
(myself)?
These are good recommendations...I appreciate it! If you have any
more thoughts, I would love to hear them.
-Joseph|||>>
> Thanks, Brian!
> I've actually made this recommendation in my "Most Secure" plan...It
> will just take some time to get the code changes in place. (Currently,
> the application reads the credentials from a two-way encrypted file
> using TripleDES). I like the idea of a protected connection
> string...Perhaps a compiled .dll in the hands of the DBA (myself)?
> These are good recommendations...I appreciate it! If you have any
> more thoughts, I would love to hear them.
> -Joseph
>
If it's an ASP.Net application, take a look at aspnet_setreg.exe. More here:
http://support.microsoft.com/kb/329290
Our implementation folks use this for our ASP.NET applications so that the
connection string can be stored encrypted in the registry.
K. Brian Kelley, brian underscore kelley at sqlpass dot org
http://www.truthsolutions.com/