Tuesday, March 27, 2012
Authorization windows - Invalid authorization specification
Another problem with Reporting Services authentication:
We have a windows 2003 server + iis 6.0 +Reporting Setvices
whose reports access to a sql server windows 2003 (both are situated
in the same domain).
Since I must use stored credentials in order to create subscriptions
I've decided to put a user from domain windows in stored
authentication.
As the result I´ve obtain the following error:
Error al procesar el informe. (rsProcessingAborted) Obtener ayuda en
línea
No se puede crear una conexión al origen de datos Ventas.
(rsErrorOpeningConnection) Obtener ayuda en línea
Invalid authorization specification
The user I've chosen is the same that I use to design reports and to
access the sql server usually, so I don´t understand the cause of this
error.
Good. Seeing that it has not work I´ve changed the user to "sa" and
everything works fine.
The unique problem I have that according to the policy secuirty of the
company
it is forbidden to use the sa user in order to execute the reports.
Windows authentication is strongly recommended. Any idea?
Regards
Maciej KiewraHi, Experts.
The ServicePack is the real reason of my problem.
I´ve removed RS and I've installed it again (without applying service pack)
everything ok.
Then I've installed the servicepack and now "windows authentication" does not work.
I know that in the service pack 1 a new System Property has been add that
permits the windows authentication to be disabled, but this parameter is set
to true, so it is not a case.
It seems that Reporting Service is already very premature
Regards
Maciej Kiewra
mkiewra@.mail.fujitsu.es (Maciej Kiewra) wrote in message news:<bc86bf57.0504050912.36611411@.posting.google.com>...
> Hi, Experts.
>
> Another problem with Reporting Services authentication:
> We have a windows 2003 server + iis 6.0 +Reporting Setvices
> whose reports access to a sql server windows 2003 (both are situated
> in the same domain).
> Since I must use stored credentials in order to create subscriptions
> I've decided to put a user from domain windows in stored
> authentication.
> As the result I´ve obtain the following error:
> Error al procesar el informe. (rsProcessingAborted) Obtener ayuda en
> línea
> No se puede crear una conexión al origen de datos Ventas.
> (rsErrorOpeningConnection) Obtener ayuda en línea
> Invalid authorization specification
> The user I've chosen is the same that I use to design reports and to
> access the sql server usually, so I don´t understand the cause of this
> error.
> Good. Seeing that it has not work I´ve changed the user to "sa" and
> everything works fine.
> The unique problem I have that according to the policy secuirty of the
> company
> it is forbidden to use the sa user in order to execute the reports.
> Windows authentication is strongly recommended. Any idea?
> Regards
> Maciej Kiewrasql
Sunday, March 25, 2012
Authorization Error in Reporting Services on Windows 2003
I have just reinstalled Reporting Services on win 2003 server that was
added to a domain and has been renamed. Two strange things happen:
1) In IE I am prompted for an ID and password with a basic security
prompt.
2) After supplying the credentials I get some of the report manager web
page but it has a 401 error instead of the folder and options to manage
projects.
The page looks like this:
Error
The request failed with HTTP status 401: Unauthorized.
Home
The reporting services error log contains the following error:
Unknown!ui!ed8!2/9/2005-20:44:32:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Pa=ADth>/reports/= Home.aspx</Path><NrReq>1</NrReq></Paths></User><=AD/Users>'
Unknown!ui!a24!2/9/2005-20:44:33:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Pa=ADth>/reports/= Pages/Folder.aspx</Path><NrReq>1</NrReq></Paths>=AD</User></Users>'
Unknown!ui!a24!2/9/2005-20:44:34:: e ERROR: The request failed with
HTTP status 401: Unauthorized.
Unknown!ui!a24!2/9/2005-20:44:35:: e ERROR: HTTP status code --> 500
I have not changed any of the config files that are installed.
Thanks for any help in advance,
EricTry restarting IIS. I think that is how they fixed the problem here.|||Try restarting IIS. I think that is how they cured the problem here.
authorization error in reporting services on win2003
I have just reinstalled Reporting Services on win 2003 server that was
added to a domain and has been renamed. Two strange things happen:
1) In IE I am prompted for an ID and password with a basic security
prompt.
2) After supplying the credentials I get some of the report manager web
page but it has a 401 error instead of the folder and options to manage
projects.
The page looks like this:
Error
The request failed with HTTP status 401: Unauthorized.
Home
The reporting services error log contains the following error:
Unknown!ui!ed8!2/9/2005-20:44:32:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Path>/reports/Home.aspx</Path><NrReq>1</NrReq></Paths></User></Users>'
Unknown!ui!a24!2/9/2005-20:44:33:: v VERBOSE: User
map'<Users><User><Name>DOMAIN\Administrator</Name><Paths><Path>/reports/Pages/Folder.aspx</Path><NrReq>1</NrReq></Paths></User></Users>'
Unknown!ui!a24!2/9/2005-20:44:34:: e ERROR: The request failed with
HTTP status 401: Unauthorized.
Unknown!ui!a24!2/9/2005-20:44:35:: e ERROR: HTTP status code --> 500
I have not changed any of the config files that are installed.
Thanks for any help in advance,
EricI have no idea, although there if you search Google groups for "sql
2000 reporting services http 401" there are a number of hits which may
be useful. You will probably get a better answer in
microsoft.public.sqlserver.reportingsvcs.
Simon
Authorization Based on UserId and Parameter Data
I am novice for reporting services.
Is it possible to get the parameters of the report and do authorisation
check based on the parameter value and UserId ?
Or is there other alternative to this kind of requirement..
Thanks,
RaghuHi,
It is possible but not advisable, there is no field mask for the password
field. Best bet is to use custom form for the password authentication.
Amarnath
"RAV" wrote:
> Hi All,
> I am novice for reporting services.
> Is it possible to get the parameters of the report and do authorisation
> check based on the parameter value and UserId ?
> Or is there other alternative to this kind of requirement..
> Thanks,
> Raghu
>
Authentication/Security Issue!
I have installed SQL reporting services on the local system test machine
[standard edition] which points to a DB that is on a different machine.
Everything works ok if I use a domain account and assign security rights for
each report. But in production I will want to have a local windows account
and assign read rights on the reports individually. I tried doing this in
the test environment.
When I try to access the site using the IP I get the windows log on box.
After entering the local user account I can get to the reports but as soon
as I try and run the report it gives me this error:
The permissions granted to user [domain\user] are insufficient for
performing this operation. (rsAccessDenied)
The problem is i am not logged on as a domain user but as a local machine
user.
Was wondering if any of you have come across this error before and possibly
know the cause/solution to this.
Thanks for your help!
Regards
AnilHi Anil:
Even if you go to an IP address for the server, when you run a report
the report is rendered by an IFRAME element with the URL pointing to
the report server by name.
To verify this behavior, just right-click in the report area, select
properties, and look at the URL. You'll notice your address bar might
look like http://x.x.x.x, but the report properties URL will indicate
http://reporting. The server always uses the <ReportServerUrl> element
in RSWebApplication.config.
Since the IFRAME points you back to the server by name, IE is probably
automatically logging you in again with your domain account, which is
not in a Browse role. You can change IE's behavior in Tools ->
Internet Options -> Security -> Custom Level -> User Authentication
(at the bottom of the list).
--
Scott
http://www.OdeToCode.com
On Mon, 16 Aug 2004 12:31:41 +1200, "anil" <test@.test.com> wrote:
>Hi,
>I have installed SQL reporting services on the local system test machine
>[standard edition] which points to a DB that is on a different machine.
>Everything works ok if I use a domain account and assign security rights for
>each report. But in production I will want to have a local windows account
>and assign read rights on the reports individually. I tried doing this in
>the test environment.
>When I try to access the site using the IP I get the windows log on box.
>After entering the local user account I can get to the reports but as soon
>as I try and run the report it gives me this error:
>
>The permissions granted to user [domain\user] are insufficient for
>performing this operation. (rsAccessDenied)
>The problem is i am not logged on as a domain user but as a local machine
>user.
>Was wondering if any of you have come across this error before and possibly
>know the cause/solution to this.
>Thanks for your help!
>Regards
>Anil
>
authentication/db connection issues with new setup
I've pretty much just thrown together a reporting services (2005)
configuration which connects to a mature sql server 2000 database held
elsewhere. Forgive me for probably not having too much of a clue
about how things should be set up, but I had a go.
I'll get straight to the problem.. that is I can view reports from the
machine running the server, using my own credentials or those of
someone else (tested by running IE7 under an alternative account on
the domain).
However, when using those same user credentials but from a different
machine, I get the following error:
An error has occurred during report processing.
Cannot create a connection to data source 'dsTachyon'.
Login failed for user '(null)'. Reason: Not associated with a trusted
SQL Server connection.
Any ideas as to what would be causing this?
cheers,
ChrisMy guess is that it's a "double hop" authentication problem.
You can connect directly to the db when you're on the server, which is a
direct connection. But when you're trying to connect to the db through the
report server, you have one connection hop from your pc to the report
server, and one hop from the report server to the db server. This is called
a double hop.
There are two ways of fixing it.
1) You can connect to the db with a static account that has read access to
the db you get your data from. Instead of using Windows Integrated
Authentication, you use "Credentials stored securely in the report server".
This can be either a SQL account or a Windows account. If you use this, make
sure you're encrypting the data in your report database, in order to encrypt
the password you add.
2) Configure the report server and the db server to use Kerberos, to allow
the credentials to be sent from your pc through the report server to the db
server.
If you want to use Kerberos, start by reading
Configuring Authentication for Reporting Services
http://msdn2.microsoft.com/en-us/library/bb283249.aspx
Specifying Credential and Connection Information
http://msdn2.microsoft.com/en-us/library/ms160330.aspx#
And
Configuring Constrained Delegation for Kerberos (IIS 6.0)
http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/df979570-81f6-4586-83c6-676bb005b13e.mspx?mfr=true
You also need to make sure Anonymous Access to the Report Server web
application is not allowed.
My suggestion is to first see if you're able to connect to the data with the
first setup (using a static account). If it works, you should use Kerberos,
as this is a more secure solution. If it doesn't work with a static account,
you might want to work out why before setting up Kerberos, because it's
usually easier, but less secure to make it work with a static account.
Kaisa M. Lindahl Lervik
"Not Me" <clhumphreys@.gmail.com> wrote in message
news:1174310214.836485.140910@.n59g2000hsh.googlegroups.com...
> Hi,
> I've pretty much just thrown together a reporting services (2005)
> configuration which connects to a mature sql server 2000 database held
> elsewhere. Forgive me for probably not having too much of a clue
> about how things should be set up, but I had a go.
> I'll get straight to the problem.. that is I can view reports from the
> machine running the server, using my own credentials or those of
> someone else (tested by running IE7 under an alternative account on
> the domain).
> However, when using those same user credentials but from a different
> machine, I get the following error:
> An error has occurred during report processing.
> Cannot create a connection to data source 'dsTachyon'.
> Login failed for user '(null)'. Reason: Not associated with a trusted
> SQL Server connection.
> Any ideas as to what would be causing this?
> cheers,
> Chris
>|||On 19 Mar, 14:00, "Kaisa M. Lindahl Lervik" <kais...@.hotmail.com>
wrote:
> My guess is that it's a "double hop" authentication problem.
> You can connect directly to the db when you're on the server, which is a
> direct connection. But when you're trying to connect to the db through the
> report server, you have one connection hop from your pc to the report
> server, and one hop from the report server to the db server. This is called
> a double hop.
Thank you! Great depth to your reply, I've tried the static account
solution and that works so I'll give Kerberos a look.
Cheers,
Chris
Authentication with AD and cookies
We are going to set up Reporting Services 2005. We have two groups of
customers that are going to access our reports; internal and external
customers.
The internal customers should be authenticated through Active Directory,
while the external customers should be authenticated using cookies. The
external customers will first logon to another web-application which has its
own user database. From this application they will have a link to Reporting
Services.
How will I have to set up my reporting services server(s) to achieve this?
The internal and external uses are not going to share reports. However, the
extenal users should access linked reports (ie. same report but different
parameter values).
Thanks in advance for your help.RS doesn't support a mixed security mode, so it has to be either Windows or
custom security. It looks like in your scenario, Windows security could be a
better fit. Assuming that you don't need the external customer identity in
your reports, once the web app authenticates the external customers, it can
connect to RS using a single trusted account, e.g. the identity of the IIS
application pool in Windows Server 2003.
--
HTH,
---
Teo Lachev, MVP, MCSD, MCT
"Microsoft Reporting Services in Action"
"Applied Microsoft Analysis Services 2005"
Home page and blog: http://www.prologika.com/
---
"Billy" <Billy@.discussions.microsoft.com> wrote in message
news:8CBE5F6F-B2A5-44DA-A8DA-E4887C60BF67@.microsoft.com...
> Hi all!
> We are going to set up Reporting Services 2005. We have two groups of
> customers that are going to access our reports; internal and external
> customers.
> The internal customers should be authenticated through Active Directory,
> while the external customers should be authenticated using cookies. The
> external customers will first logon to another web-application which has
> its
> own user database. From this application they will have a link to
> Reporting
> Services.
> How will I have to set up my reporting services server(s) to achieve this?
> The internal and external uses are not going to share reports. However,
> the
> extenal users should access linked reports (ie. same report but different
> parameter values).
> Thanks in advance for your help.
>|||ok.
Is it possible to set up two separate instances of RS om the same server and
then route external users to instance A and internal users to instance B?
"Teo Lachev [MVP]" wrote:
> RS doesn't support a mixed security mode, so it has to be either Windows or
> custom security. It looks like in your scenario, Windows security could be a
> better fit. Assuming that you don't need the external customer identity in
> your reports, once the web app authenticates the external customers, it can
> connect to RS using a single trusted account, e.g. the identity of the IIS
> application pool in Windows Server 2003.
> --
> HTH,
> ---
> Teo Lachev, MVP, MCSD, MCT
> "Microsoft Reporting Services in Action"
> "Applied Microsoft Analysis Services 2005"
> Home page and blog: http://www.prologika.com/
> ---
> "Billy" <Billy@.discussions.microsoft.com> wrote in message
> news:8CBE5F6F-B2A5-44DA-A8DA-E4887C60BF67@.microsoft.com...
> > Hi all!
> >
> > We are going to set up Reporting Services 2005. We have two groups of
> > customers that are going to access our reports; internal and external
> > customers.
> >
> > The internal customers should be authenticated through Active Directory,
> > while the external customers should be authenticated using cookies. The
> > external customers will first logon to another web-application which has
> > its
> > own user database. From this application they will have a link to
> > Reporting
> > Services.
> >
> > How will I have to set up my reporting services server(s) to achieve this?
> > The internal and external uses are not going to share reports. However,
> > the
> > extenal users should access linked reports (ie. same report but different
> > parameter values).
> >
> > Thanks in advance for your help.
> >
>
>|||I don't think this scenario is officially supported but it looks like when
there is a will, there is a way
(http://www.sqljunkies.com/HowTo/525B575A-7F61-483A-AC8F-FEC700C34674.scuk).
--
HTH,
---
Teo Lachev, MVP, MCSD, MCT
"Microsoft Reporting Services in Action"
"Applied Microsoft Analysis Services 2005"
Home page and blog: http://www.prologika.com/
---
"Billy" <Billy@.discussions.microsoft.com> wrote in message
news:E6DD5D19-8C25-4C1E-8154-5C736723D80C@.microsoft.com...
> ok.
> Is it possible to set up two separate instances of RS om the same server
> and
> then route external users to instance A and internal users to instance B?
> "Teo Lachev [MVP]" wrote:
>> RS doesn't support a mixed security mode, so it has to be either Windows
>> or
>> custom security. It looks like in your scenario, Windows security could
>> be a
>> better fit. Assuming that you don't need the external customer identity
>> in
>> your reports, once the web app authenticates the external customers, it
>> can
>> connect to RS using a single trusted account, e.g. the identity of the
>> IIS
>> application pool in Windows Server 2003.
>> --
>> HTH,
>> ---
>> Teo Lachev, MVP, MCSD, MCT
>> "Microsoft Reporting Services in Action"
>> "Applied Microsoft Analysis Services 2005"
>> Home page and blog: http://www.prologika.com/
>> ---
>> "Billy" <Billy@.discussions.microsoft.com> wrote in message
>> news:8CBE5F6F-B2A5-44DA-A8DA-E4887C60BF67@.microsoft.com...
>> > Hi all!
>> >
>> > We are going to set up Reporting Services 2005. We have two groups of
>> > customers that are going to access our reports; internal and external
>> > customers.
>> >
>> > The internal customers should be authenticated through Active
>> > Directory,
>> > while the external customers should be authenticated using cookies. The
>> > external customers will first logon to another web-application which
>> > has
>> > its
>> > own user database. From this application they will have a link to
>> > Reporting
>> > Services.
>> >
>> > How will I have to set up my reporting services server(s) to achieve
>> > this?
>> > The internal and external uses are not going to share reports. However,
>> > the
>> > extenal users should access linked reports (ie. same report but
>> > different
>> > parameter values).
>> >
>> > Thanks in advance for your help.
>> >
>>
Authentication Reporting Services and web reportviewer
Hi,
I’ve an application Web which uses to reportviewer to show information. I want that all the users of the application accede to reports by means of he himself user and password. This user is a local user of report’s server. The problem is that when attempt to show report always appear the following error:
The request failed with HTTP status 401: Unauthorized.
The code that use is the following one:
ReportViewer1.ServerReport.ReportServerCredentials = new ReportViewerCredentials("Usuario", "pwd", "servidor");
using System;
using System.Data;
using System.Configuration;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using Microsoft.Reporting.WebForms;
using System.Net;
using System.Security.Principal;
using System.Runtime.InteropServices;
/// <summary>
/// Summary description for ReportViewerCredentials
/// </summary>
public class ReportViewerCredentials : IReportServerCredentials
{
[DllImport("advapi32.dll", SetLastError = true)]
public extern static bool LogonUser(String lpszUsername, String lpszDomain, String lpszPassword, int dwLogonType, int dwLogonProvider, ref IntPtr phToken);
[DllImport("kernel32.dll", CharSet = CharSet.Auto)]
public extern static bool CloseHandle(IntPtr handle);
[DllImport("advapi32.dll", CharSet = CharSet.Auto, SetLastError = true)]
public extern static bool DuplicateToken(IntPtr ExistingTokenHandle,
int SECURITY_IMPERSONATION_LEVEL, ref IntPtr DuplicateTokenHandle);
public ReportViewerCredentials()
{
}
public ReportViewerCredentials(string username)
{
this.Username = username;
}
public ReportViewerCredentials(string username, string password)
{
this.Username = username;
this.Password = password;
}
public ReportViewerCredentials(string username, string password, string domain)
{
this.Username = username;
this.Password = password;
this.Domain = domain;
}
public string Username
{
get
{
return this.username;
}
set
{
string username = value;
if (username.Contains("\\"))
{
this.domain = username.Substring(0, username.IndexOf("\\"));
this.username = username.Substring(username.IndexOf("\\") + 1);
}
else
{
this.username = username;
}
}
}
private string username;
public string Password
{
get
{
return this.password;
}
set
{
this.password = value;
}
}
private string password;
public string Domain
{
get
{
return this.domain;
}
set
{
this.domain = value;
}
}
private string domain;
#region IReportServerCredentials Members
public bool GetBasicCredentials(out string basicUser, out string basicPassword, out string basicDomain)
{
basicUser = username;
basicPassword = password;
basicDomain = domain;
return username != null && password != null && domain != null;
}
public bool GetFormsCredentials(out string formsUser, out string formsPassword, out string formsAuthority)
{
formsUser = username;
formsPassword = password;
formsAuthority = domain;
return username != null && password != null && domain != null;
}
public bool GetFormsCredentials(out Cookie authCookie,out string user, out string password, out string authority)
{
authCookie = null;
user = password = authority = null;
return false;// Not implemented
}
public WindowsIdentity ImpersonationUser
{
get
{
string[] args = new string[3] { this.Domain.ToString(), this.Username.ToString(), this.Password.ToString() };
IntPtr tokenHandle = new IntPtr(0);
IntPtr dupeTokenHandle = new IntPtr(0);
//const int LOGON32_PROVIDER_DEFAULT = 0;
////This parameter causes LogonUser to create a primary token.
//const int LOGON32_LOGON_INTERACTIVE = 2;
const int LOGON32_PROVIDER_DEFAULT = 3;
//This parameter causes LogonUser to create a primary token.
const int LOGON32_LOGON_INTERACTIVE = 9;
const int SecurityImpersonation = 2;
tokenHandle = IntPtr.Zero;
dupeTokenHandle = IntPtr.Zero;
try
{
// Call LogonUser to obtain an handle to an access token.
bool returnValue = LogonUser(args[1], args[0], args[2],
LOGON32_LOGON_INTERACTIVE, LOGON32_PROVIDER_DEFAULT,
ref tokenHandle);
if (false == returnValue)
{
Console.WriteLine("LogonUser failed with error code : {0}",Marshal.GetLastWin32Error());
return null;
}
// Check the identity.
System.Diagnostics.Trace.WriteLine("Before impersonation: "
+ WindowsIdentity.GetCurrent().Name);
bool retVal = DuplicateToken(tokenHandle, SecurityImpersonation, ref dupeTokenHandle);
if (false == retVal)
{
CloseHandle(tokenHandle);
Console.WriteLine("Exception in token duplication.");
return null;
}
// The token that is passed to the following constructor must
// be a primary token to impersonate.
WindowsIdentity newId = new WindowsIdentity(dupeTokenHandle);
WindowsImpersonationContext impersonatedUser = newId.Impersonate();
// Free the tokens.
if (tokenHandle != IntPtr.Zero)
CloseHandle(tokenHandle);
if (dupeTokenHandle != IntPtr.Zero)
CloseHandle(dupeTokenHandle);
// Check the identity.
System.Diagnostics.Trace.WriteLine("After impersonation: "
+ WindowsIdentity.GetCurrent().Name);
return newId;
}
catch (Exception ex)
{
Console.WriteLine("Exception occurred. " + ex.Message);
}
return null;
}
}
public ICredentials NetworkCredentials
{
get
{
return null;// Not using NetworkCredentials to authenticate.
}
}
#endregion
}
Go to the following links, this will solve your problem
http://blogs.msdn.com/bimusings/archive/2005/12/05/500195.aspx
http://www.odetocode.com/Articles/216.aspx
Authentication Problem x64
Win 2003 Server x64, .Net 2.0 x64 Reporting Services 2005. RS Database is a remote SQL 2005 on the same Domain in the same room. I can only get the report manager to authenticate local users; it will not authenticate Domain users.If I set up a local user and add a New Role Assignment all works OK.I have no problem adding a Domain user to a New Role Assignment, it allows this, but it will not authenticate the user.Adding the Domain user to the Windows Administrators group also has no effect.
Am I missing something simple?
I doubt this has anything to do with the x64-ness of your HW.
When you say "it will not authenticate the user", what exactly do you mean?
|||If I try to log on to http://mymachine/reports with a local user it will let me on.If I try to log on as a Domain user, it keeps bringing up the logon screen. (Windows Authentication)Both users are set up in a role in RS.
|||It sounds to me like IIS is not recognizing the user. Does that user have permissions on the machine aside from being in the RS role?|||If you are asking about the Domain users, NO. I am expecting it to work like Share Point, where you add the Domain user in the site and give it permissions on the site. Am I assuming wrong?|||Can you check the IIS logs on the machine for when the domain user tries to connect?
SRS doesn't grant the user any permissions on the box, so if the user did not have a valid account on the machine before, he still won't be able to have access to SRS because IIS will fail the request before it even gets to SRS.
|||John,
I see the Get entry in the IIS log, no other entries. I see a success audit entry in the Security Log for that user.
If I log on with the the local user, I see the POST entries etc in the IIS log.
Do I need to set up the domain user to have some local rights?
|||I finally wipped the machine clean and started again. Now RS will authenticate a domain user fine.Thursday, March 22, 2012
Authentication over the internet
Because reporting services uses Windows authentication and does not allow anonymous access, I have created a windows account (called "RSUser") that has access to my reports. When the user runs a report, I pass in the credentials for this windows account like this...
rs.Credentials = New System.Net.NetworkCredential("RSUser", "password", "domain")
This all works, and the report renders using the permissions from RSUser. The problem is that all the reports use treeviews for drill-down (and some use drill-through). When you expand a drill down you are prompted for a windows login. I think this is because this postback is now coming from the client PC, instead if from the asp.net app (i.e. on the server), and so reporting services needs to anthenticate this new user.
The only solution that I have found for this is developing a security extension for reporting services...
http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
... but this seems like overkill and a very complicated process, and Microsoft says in the article that this is not fully tested and should not be used in a production environment (but that where I need it for).
Does anyone have a solution ?
Craig HBJust a thought: Have you tried to setup a individual Application pool that works with your RSUser Account?
"Craig HB" wrote:
> I am building an asp.net app that will use reporting services to show reports within the application. Users login to the application and when they need to see a report I use web services to render the report. The asp.net app and reporting services are on the same windows 2003 server (not using active directory).
> Because reporting services uses Windows authentication and does not allow anonymous access, I have created a windows account (called "RSUser") that has access to my reports. When the user runs a report, I pass in the credentials for this windows account like this...
> rs.Credentials = New System.Net.NetworkCredential("RSUser", "password", "domain")
> This all works, and the report renders using the permissions from RSUser. The problem is that all the reports use treeviews for drill-down (and some use drill-through). When you expand a drill down you are prompted for a windows login. I think this is because this postback is now coming from the client PC, instead if from the asp.net app (i.e. on the server), and so reporting services needs to anthenticate this new user.
> The only solution that I have found for this is developing a security extension for reporting services...
> http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> ... but this seems like overkill and a very complicated process, and Microsoft says in the article that this is not fully tested and should not be used in a production environment (but that where I need it for).
> Does anyone have a solution ?
> Craig HB|||Craig,
You are right. You get prompted because the drilldown and drillthough
interactive features require URL acccess and request goes out on the client
side of the application.
In a nutshell, if your reports have interactive features you need to go for
URL access. For Internet-oriented apps this means writing a custom security
extension. It is not that involved to write and I have deployed an
application that uses a custom security extension in a production
environment. There are some gotchas to avoid but in general my experience
writing custom security extensions have been positive and you will learn a
lot about how RS handles authentication and authorization.
--
Hope this helps.
---
Teo Lachev, MCSD, MCT
Author: "Microsoft Reporting Services in Action"
http://www.prologika.com
"Gash" <Gash@.discussions.microsoft.com> wrote in message
news:FFF038F5-4A21-4DFA-846C-6A3A84683D2D@.microsoft.com...
> Just a thought: Have you tried to setup a individual Application pool that
works with your RSUser Account?
> "Craig HB" wrote:
> > I am building an asp.net app that will use reporting services to show
reports within the application. Users login to the application and when they
need to see a report I use web services to render the report. The asp.net
app and reporting services are on the same windows 2003 server (not using
active directory).
> >
> > Because reporting services uses Windows authentication and does not
allow anonymous access, I have created a windows account (called "RSUser")
that has access to my reports. When the user runs a report, I pass in the
credentials for this windows account like this...
> >
> > rs.Credentials = New System.Net.NetworkCredential("RSUser", "password",
"domain")
> >
> > This all works, and the report renders using the permissions from
RSUser. The problem is that all the reports use treeviews for drill-down
(and some use drill-through). When you expand a drill down you are prompted
for a windows login. I think this is because this postback is now coming
from the client PC, instead if from the asp.net app (i.e. on the server),
and so reporting services needs to anthenticate this new user.
> >
> > The only solution that I have found for this is developing a security
extension for reporting services...
> >
> >
http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> >
> > ... but this seems like overkill and a very complicated process, and
Microsoft says in the article that this is not fully tested and should not
be used in a production environment (but that where I need it for).
> >
> > Does anyone have a solution ?
> >
> > Craig HB|||Start here
http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
--
Hope this helps.
----
Teo Lachev, MCSD, MCT
Author: "Microsoft Reporting Services in Action"
Publisher website: http://www.manning.com/lachev
Buy it from Amazon.com: http://shrinkster.com/eq
Home page and blog: http://www.prologika.com/
----
"jbmeeh" <jbmeeh@.discussions.microsoft.com> wrote in message
news:3A2F7D63-C267-4CED-A5CC-4B42186B98B6@.microsoft.com...
> Is there any sample code for writing a custom security extension? I have
> already validated the user and I want to provide url access to the report
> server.
> "Teo" wrote:
> > Craig,
> >
> > You are right. You get prompted because the drilldown and drillthough
> > interactive features require URL acccess and request goes out on the
client
> > side of the application.
> >
> > In a nutshell, if your reports have interactive features you need to go
for
> > URL access. For Internet-oriented apps this means writing a custom
security
> > extension. It is not that involved to write and I have deployed an
> > application that uses a custom security extension in a production
> > environment. There are some gotchas to avoid but in general my
experience
> > writing custom security extensions have been positive and you will learn
a
> > lot about how RS handles authentication and authorization.
> >
> > --
> > Hope this helps.
> >
> > ---
> > Teo Lachev, MCSD, MCT
> > Author: "Microsoft Reporting Services in Action"
> > http://www.prologika.com
> >
> >
> > "Gash" <Gash@.discussions.microsoft.com> wrote in message
> > news:FFF038F5-4A21-4DFA-846C-6A3A84683D2D@.microsoft.com...
> > > Just a thought: Have you tried to setup a individual Application pool
that
> > works with your RSUser Account?
> > >
> > > "Craig HB" wrote:
> > >
> > > > I am building an asp.net app that will use reporting services to
show
> > reports within the application. Users login to the application and when
they
> > need to see a report I use web services to render the report. The
asp.net
> > app and reporting services are on the same windows 2003 server (not
using
> > active directory).
> > > >
> > > > Because reporting services uses Windows authentication and does not
> > allow anonymous access, I have created a windows account (called
"RSUser")
> > that has access to my reports. When the user runs a report, I pass in
the
> > credentials for this windows account like this...
> > > >
> > > > rs.Credentials = New System.Net.NetworkCredential("RSUser",
"password",
> > "domain")
> > > >
> > > > This all works, and the report renders using the permissions from
> > RSUser. The problem is that all the reports use treeviews for drill-down
> > (and some use drill-through). When you expand a drill down you are
prompted
> > for a windows login. I think this is because this postback is now coming
> > from the client PC, instead if from the asp.net app (i.e. on the
server),
> > and so reporting services needs to anthenticate this new user.
> > > >
> > > > The only solution that I have found for this is developing a
security
> > extension for reporting services...
> > > >
> > > >
> >
http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> > > >
> > > > ... but this seems like overkill and a very complicated process, and
> > Microsoft says in the article that this is not fully tested and should
not
> > be used in a production environment (but that where I need it for).
> > > >
> > > > Does anyone have a solution ?
> > > >
> > > > Craig HB
> >
> >
> >|||I have seen this article and it is good if I wanted to build a standalone
application to allow access to the report server. However, i have an existing
application with forms authentication in which I want to embed url access to
the report server. I was hoping that there would be code samples or an
article for this particular issue. I don't need to present another form to
the user to capture credentials. Can i use my existing forms authentication
ticket or do I need to create a new one. Do I call the LogonUser webservice
to create a cookie for a user that has been created on the report manager. It
seems like there are a lot of people trying to solve the same problem, but
not too many examples.
"Teo Lachev" wrote:
> Start here
> http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> --
> Hope this helps.
> ----
> Teo Lachev, MCSD, MCT
> Author: "Microsoft Reporting Services in Action"
> Publisher website: http://www.manning.com/lachev
> Buy it from Amazon.com: http://shrinkster.com/eq
> Home page and blog: http://www.prologika.com/
> ----
> "jbmeeh" <jbmeeh@.discussions.microsoft.com> wrote in message
> news:3A2F7D63-C267-4CED-A5CC-4B42186B98B6@.microsoft.com...
> > Is there any sample code for writing a custom security extension? I have
> > already validated the user and I want to provide url access to the report
> > server.
> >
> > "Teo" wrote:
> >
> > > Craig,
> > >
> > > You are right. You get prompted because the drilldown and drillthough
> > > interactive features require URL acccess and request goes out on the
> client
> > > side of the application.
> > >
> > > In a nutshell, if your reports have interactive features you need to go
> for
> > > URL access. For Internet-oriented apps this means writing a custom
> security
> > > extension. It is not that involved to write and I have deployed an
> > > application that uses a custom security extension in a production
> > > environment. There are some gotchas to avoid but in general my
> experience
> > > writing custom security extensions have been positive and you will learn
> a
> > > lot about how RS handles authentication and authorization.
> > >
> > > --
> > > Hope this helps.
> > >
> > > ---
> > > Teo Lachev, MCSD, MCT
> > > Author: "Microsoft Reporting Services in Action"
> > > http://www.prologika.com
> > >
> > >
> > > "Gash" <Gash@.discussions.microsoft.com> wrote in message
> > > news:FFF038F5-4A21-4DFA-846C-6A3A84683D2D@.microsoft.com...
> > > > Just a thought: Have you tried to setup a individual Application pool
> that
> > > works with your RSUser Account?
> > > >
> > > > "Craig HB" wrote:
> > > >
> > > > > I am building an asp.net app that will use reporting services to
> show
> > > reports within the application. Users login to the application and when
> they
> > > need to see a report I use web services to render the report. The
> asp.net
> > > app and reporting services are on the same windows 2003 server (not
> using
> > > active directory).
> > > > >
> > > > > Because reporting services uses Windows authentication and does not
> > > allow anonymous access, I have created a windows account (called
> "RSUser")
> > > that has access to my reports. When the user runs a report, I pass in
> the
> > > credentials for this windows account like this...
> > > > >
> > > > > rs.Credentials = New System.Net.NetworkCredential("RSUser",
> "password",
> > > "domain")
> > > > >
> > > > > This all works, and the report renders using the permissions from
> > > RSUser. The problem is that all the reports use treeviews for drill-down
> > > (and some use drill-through). When you expand a drill down you are
> prompted
> > > for a windows login. I think this is because this postback is now coming
> > > from the client PC, instead if from the asp.net app (i.e. on the
> server),
> > > and so reporting services needs to anthenticate this new user.
> > > > >
> > > > > The only solution that I have found for this is developing a
> security
> > > extension for reporting services...
> > > > >
> > > > >
> > >
> http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> > > > >
> > > > > ... but this seems like overkill and a very complicated process, and
> > > Microsoft says in the article that this is not fully tested and should
> not
> > > be used in a production environment (but that where I need it for).
> > > > >
> > > > > Does anyone have a solution ?
> > > > >
> > > > > Craig HB
> > >
> > >
> > >
>
>|||> Can i use my existing forms authentication
> ticket or do I need to create a new one.
No, you cannot use your app Forms Authentication ticket and you don't have
to have another logon form. Instead, your application needs to call the RS
LogonUser SOAP API once it authenticates the user. You will end up with two
authentication tickets (cookies) but this shouldn't be too much of an issue.
The MS article should be good enough to address you scenario. You just need
to understand how RS Forms Authentication works by debugging the extension.
I have a two-part article in the works for a magazine about Forms
Authentication. Unfortunately, judging by the editors speed, it won't make
it before the end of the year. Meanwhile, you can check the other threads
on this topic. It's been discussed many times.
--
Hope this helps.
----
Teo Lachev, MCSD, MCT
Author: "Microsoft Reporting Services in Action"
Publisher website: http://www.manning.com/lachev
Buy it from Amazon.com: http://shrinkster.com/eq
Home page and blog: http://www.prologika.com/
----
"jbmeeh" <jbmeeh@.discussions.microsoft.com> wrote in message
news:3F687097-1790-4FF9-B8CB-0A163BF3074C@.microsoft.com...
> I have seen this article and it is good if I wanted to build a standalone
> application to allow access to the report server. However, i have an
existing
> application with forms authentication in which I want to embed url access
to
> the report server. I was hoping that there would be code samples or an
> article for this particular issue. I don't need to present another form to
> the user to capture credentials. Can i use my existing forms
authentication
> ticket or do I need to create a new one. Do I call the LogonUser
webservice
> to create a cookie for a user that has been created on the report manager.
It
> seems like there are a lot of people trying to solve the same problem, but
> not too many examples.
> "Teo Lachev" wrote:
> > Start here
> >
http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> >
> > --
> > Hope this helps.
> >
> > ----
> > Teo Lachev, MCSD, MCT
> > Author: "Microsoft Reporting Services in Action"
> > Publisher website: http://www.manning.com/lachev
> > Buy it from Amazon.com: http://shrinkster.com/eq
> > Home page and blog: http://www.prologika.com/
> > ----
> >
> > "jbmeeh" <jbmeeh@.discussions.microsoft.com> wrote in message
> > news:3A2F7D63-C267-4CED-A5CC-4B42186B98B6@.microsoft.com...
> > > Is there any sample code for writing a custom security extension? I
have
> > > already validated the user and I want to provide url access to the
report
> > > server.
> > >
> > > "Teo" wrote:
> > >
> > > > Craig,
> > > >
> > > > You are right. You get prompted because the drilldown and
drillthough
> > > > interactive features require URL acccess and request goes out on the
> > client
> > > > side of the application.
> > > >
> > > > In a nutshell, if your reports have interactive features you need to
go
> > for
> > > > URL access. For Internet-oriented apps this means writing a custom
> > security
> > > > extension. It is not that involved to write and I have deployed an
> > > > application that uses a custom security extension in a production
> > > > environment. There are some gotchas to avoid but in general my
> > experience
> > > > writing custom security extensions have been positive and you will
learn
> > a
> > > > lot about how RS handles authentication and authorization.
> > > >
> > > > --
> > > > Hope this helps.
> > > >
> > > > ---
> > > > Teo Lachev, MCSD, MCT
> > > > Author: "Microsoft Reporting Services in Action"
> > > > http://www.prologika.com
> > > >
> > > >
> > > > "Gash" <Gash@.discussions.microsoft.com> wrote in message
> > > > news:FFF038F5-4A21-4DFA-846C-6A3A84683D2D@.microsoft.com...
> > > > > Just a thought: Have you tried to setup a individual Application
pool
> > that
> > > > works with your RSUser Account?
> > > > >
> > > > > "Craig HB" wrote:
> > > > >
> > > > > > I am building an asp.net app that will use reporting services to
> > show
> > > > reports within the application. Users login to the application and
when
> > they
> > > > need to see a report I use web services to render the report. The
> > asp.net
> > > > app and reporting services are on the same windows 2003 server (not
> > using
> > > > active directory).
> > > > > >
> > > > > > Because reporting services uses Windows authentication and does
not
> > > > allow anonymous access, I have created a windows account (called
> > "RSUser")
> > > > that has access to my reports. When the user runs a report, I pass
in
> > the
> > > > credentials for this windows account like this...
> > > > > >
> > > > > > rs.Credentials = New System.Net.NetworkCredential("RSUser",
> > "password",
> > > > "domain")
> > > > > >
> > > > > > This all works, and the report renders using the permissions
from
> > > > RSUser. The problem is that all the reports use treeviews for
drill-down
> > > > (and some use drill-through). When you expand a drill down you are
> > prompted
> > > > for a windows login. I think this is because this postback is now
coming
> > > > from the client PC, instead if from the asp.net app (i.e. on the
> > server),
> > > > and so reporting services needs to anthenticate this new user.
> > > > > >
> > > > > > The only solution that I have found for this is developing a
> > security
> > > > extension for reporting services...
> > > > > >
> > > > > >
> > > >
> >
http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> > > > > >
> > > > > > ... but this seems like overkill and a very complicated process,
and
> > > > Microsoft says in the article that this is not fully tested and
should
> > not
> > > > be used in a production environment (but that where I need it for).
> > > > > >
> > > > > > Does anyone have a solution ?
> > > > > >
> > > > > > Craig HB
> > > >
> > > >
> > > >
> >
> >
> >|||Is there any sample code for writing a custom security extension? I have
already validated the user and I want to provide url access to the report
server.
"Teo" wrote:
> Craig,
> You are right. You get prompted because the drilldown and drillthough
> interactive features require URL acccess and request goes out on the client
> side of the application.
> In a nutshell, if your reports have interactive features you need to go for
> URL access. For Internet-oriented apps this means writing a custom security
> extension. It is not that involved to write and I have deployed an
> application that uses a custom security extension in a production
> environment. There are some gotchas to avoid but in general my experience
> writing custom security extensions have been positive and you will learn a
> lot about how RS handles authentication and authorization.
> --
> Hope this helps.
> ---
> Teo Lachev, MCSD, MCT
> Author: "Microsoft Reporting Services in Action"
> http://www.prologika.com
>
> "Gash" <Gash@.discussions.microsoft.com> wrote in message
> news:FFF038F5-4A21-4DFA-846C-6A3A84683D2D@.microsoft.com...
> > Just a thought: Have you tried to setup a individual Application pool that
> works with your RSUser Account?
> >
> > "Craig HB" wrote:
> >
> > > I am building an asp.net app that will use reporting services to show
> reports within the application. Users login to the application and when they
> need to see a report I use web services to render the report. The asp.net
> app and reporting services are on the same windows 2003 server (not using
> active directory).
> > >
> > > Because reporting services uses Windows authentication and does not
> allow anonymous access, I have created a windows account (called "RSUser")
> that has access to my reports. When the user runs a report, I pass in the
> credentials for this windows account like this...
> > >
> > > rs.Credentials = New System.Net.NetworkCredential("RSUser", "password",
> "domain")
> > >
> > > This all works, and the report renders using the permissions from
> RSUser. The problem is that all the reports use treeviews for drill-down
> (and some use drill-through). When you expand a drill down you are prompted
> for a windows login. I think this is because this postback is now coming
> from the client PC, instead if from the asp.net app (i.e. on the server),
> and so reporting services needs to anthenticate this new user.
> > >
> > > The only solution that I have found for this is developing a security
> extension for reporting services...
> > >
> > >
> http://msdn.microsoft.com/library/?url=/library/en-us/dnsql2k/html/ufairs.asp?frame=true#ufairs_topic3
> > >
> > > ... but this seems like overkill and a very complicated process, and
> Microsoft says in the article that this is not fully tested and should not
> be used in a production environment (but that where I need it for).
> > >
> > > Does anyone have a solution ?
> > >
> > > Craig HB
>
>|||Teo. Is it possible to use web forms authentication with the standard
edition of RS?
If not, I'm guessing there is no other way to use the viewer over the
Internet..
Thanks, AHH
BTW: I bought your book - best one out there..|||Thanks. No, extending RS requires Enterprise Edition. Sorry.
How about generating reports on the server side of the app and sacrificing
the interactive features and the toolbar?
--
Hope this helps.
----
Teo Lachev, MCSD, MCT
Author: "Microsoft Reporting Services in Action"
Publisher website: http://www.manning.com/lachev
Buy it from Amazon.com: http://shrinkster.com/eq
Home page and blog: http://www.prologika.com/
----
"AHH" <AHH@.discussions.microsoft.com> wrote in message
news:13CACEA1-BD84-4D6A-BB25-63D43E0F56A8@.microsoft.com...
> Teo. Is it possible to use web forms authentication with the standard
> edition of RS?
> If not, I'm guessing there is no other way to use the viewer over the
> Internet..
> Thanks, AHH
> BTW: I bought your book - best one out there..
Tuesday, March 20, 2012
Authentication across internet
From what I have understood, Reporting Services could be configured to use Basic Authentication. In this way, a user can access a RS-server across the internet and he/she will be prompted for a valid username/password when trying to access.
However, from what I can understand this username and password will be sent uncrypted over the Internet (from the client machine to the RS-server), right?
My problem is, I need to give access to users acress the internet to a RS-server. The users uses all kind of operating systems (Windows, Linux, MacOS tec). And the communication needs to be encrypted.
How would you recommend me to implement security for this solution? I guess some kind of "Forms authentication" will have to be used? But how to make sure the data traffic is encrypted? And where do you recommend me to store the username and passwords? In an Active Directory on the server side, or in a separate database on the server side?
regards Andreas
You need to set up your report server to use SSL, that way all communication is encrypted. This would be done in IIS but also requires some config chages to reporting services.
Both Basic authentication and Forms would work in this scenario.
Use AD for the user accounts if possible.
|||Thank you for your quick reply!
My SSL experience is very limited as well, but I guess it means that I need to buy a certificate from some trusted store? Otherwise the clients will always be warned when trying to connect, right?
Regards Andreas
|||If you have a fix client list, give them a link to download your own CA public key should be good enough. Of coz if its facing internet I suggest you pay for SSL. Not only your authentication, your report data are flying nude via the line, I guess that might be another issue and reason why SSL is required.|||Ok, thank you for your answers! An SSL-certificate it will be!
Just so that I didn't missunderstood. If I configure IIS to use SSL, the login name and password will be safly encrypted, even if I use Basic authentication, or?
Regards Andreas
|||Yes, ALL communication is encrypted.sqlMonday, March 19, 2012
Authentication
have two websites on the server. Access to reports is fine using the
http://servername/reportServer, and using IUSR_servername, but I would like
to have reports available via the Internet using domain names. Saw the
earlier post and read I needed to change configuration. I've tried:
<Configuration>
<UI>
<ReportServerUrl>http://servername/ReportServer</ReportServerUrl
<ReportServerExternalURL>http://www.domain.org/ReportServer</ReportServerExternalURL>
</UI>
and
I've added virtual directories under above domain for reportManager and
reportServer giving appropriate read/execute permissions and security under
IIS.
I continue to get: HTTP Error 403 - Forbidden
Can I do this?
And, is it possible to have both domains access the reportServer and not
just one?
Thanks so much
JanetJanet -
In what file was this change supposed to be made for external access?
Thanks,
Ken
"janetb" <janetb@.discussions.microsoft.com> wrote in message
news:207273D1-A54E-49D2-82E8-7EEB65BDFADA@.microsoft.com...
> I have Server2003/SQL2000/IIS6 and have just installed Reporting services.
I
> have two websites on the server. Access to reports is fine using the
> http://servername/reportServer, and using IUSR_servername, but I would
like
> to have reports available via the Internet using domain names. Saw the
> earlier post and read I needed to change configuration. I've tried:
> <Configuration>
> <UI>
> <ReportServerUrl>http://servername/ReportServer</ReportServerUrl>
>
<ReportServerExternalURL>http://www.domain.org/ReportServer</ReportServerExt
ernalURL>
> </UI>
> and
> I've added virtual directories under above domain for reportManager and
> reportServer giving appropriate read/execute permissions and security
under
> IIS.
> I continue to get: HTTP Error 403 - Forbidden
> Can I do this?
> And, is it possible to have both domains access the reportServer and not
> just one?
> Thanks so much
> Janet
>|||Ken
c:\programfiles\microsoft sql server\mssql\reporting services\report
manager\ rswebapplication.config
Janet
"Ken" wrote:
> Janet -
> In what file was this change supposed to be made for external access?
> Thanks,
> Ken
>
> "janetb" <janetb@.discussions.microsoft.com> wrote in message
> news:207273D1-A54E-49D2-82E8-7EEB65BDFADA@.microsoft.com...
> > I have Server2003/SQL2000/IIS6 and have just installed Reporting services.
> I
> > have two websites on the server. Access to reports is fine using the
> > http://servername/reportServer, and using IUSR_servername, but I would
> like
> > to have reports available via the Internet using domain names. Saw the
> > earlier post and read I needed to change configuration. I've tried:
> >
> > <Configuration>
> > <UI>
> > <ReportServerUrl>http://servername/ReportServer</ReportServerUrl>
> >
> <ReportServerExternalURL>http://www.domain.org/ReportServer</ReportServerExt
> ernalURL>
> > </UI>
> >
> > and
> >
> > I've added virtual directories under above domain for reportManager and
> > reportServer giving appropriate read/execute permissions and security
> under
> > IIS.
> >
> > I continue to get: HTTP Error 403 - Forbidden
> >
> > Can I do this?
> > And, is it possible to have both domains access the reportServer and not
> > just one?
> >
> > Thanks so much
> > Janet
> >
>
>
Authenctication to Report Builder
I m really new to reporting service. I dnt know what I did but once I try to access "http://localhost/reports" it will prompt me for username & password. And whatever I typed in is incorrect...
Help Please~
Thank you,
Elton
By default, the reporting services will use NT authentication. You should be able to use the NT administrator account to login.
|||Thankumcsenow,
I thought I tried that before but it does not seem work...Acturally, I m currently open Report server directly from IIS and also I applied the integrated auth.
Cheers,
Elton
Auditing table access
I know that many of the tables were needed years ago for short-term
projects, and are no longer used. I'm trying to find a way to identify
which tables are never accessed by users, so that we can stop those
loads and drop the tables. For this purpose, if nobody SELECTs from a
table in 30 days, I can consider that table dead. And, if anyone
SELECTs from the table even once, I need to keep it around.
This is a high-usage database, so performance is key. I'd rather not
run a Profiler session for 30 days straight, because of the potential
impact on performance. Ideally, I'd like to find something like a
one-time trigger: a table is accessed, a trigger fires and adds that
table to a "Keep Me" list somewhere, then the trigger is disabled. I
don't think SELECT triggers exist in SQL2000, though.
Anyone have creative ideas on how to generate a list of used or unused
tables? Or is there a way I could do this with Profiler without
creating too much overhead?
Cheers!Hi stavros
"stavros" wrote:
> We regularly load data into hundreds of tables in a reporting database.
> I know that many of the tables were needed years ago for short-term
> projects, and are no longer used. I'm trying to find a way to identify
> which tables are never accessed by users, so that we can stop those
> loads and drop the tables. For this purpose, if nobody SELECTs from a
> table in 30 days, I can consider that table dead. And, if anyone
> SELECTs from the table even once, I need to keep it around.
> This is a high-usage database, so performance is key. I'd rather not
> run a Profiler session for 30 days straight, because of the potential
> impact on performance. Ideally, I'd like to find something like a
> one-time trigger: a table is accessed, a trigger fires and adds that
> table to a "Keep Me" list somewhere, then the trigger is disabled. I
> don't think SELECT triggers exist in SQL2000, though.
AFAIK profiler is the only tool that is likely to do this. You could run
multiple profiles that covers the whole period and process each profile
offline rather than having one single set of outputs to process at the end o
f
the period.
> Anyone have creative ideas on how to generate a list of used or unused
> tables? Or is there a way I could do this with Profiler without
> creating too much overhead?
>
This is where source code control is very advantages, just doing textual
searches for your tables will eliminate alot of them. Alternatively if you
use stored procedures, then you could script the stored procedures on their
own and do a textual search. If want to know which procedures are called
without using profiler you could add code that audits the procedure being
run, although this will be an overhead whilst you are collecting the
information and a potential bottleneck. it will also mean a code change.
> Cheers!
>
John
Sunday, March 11, 2012
Auditing table access
I know that many of the tables were needed years ago for short-term
projects, and are no longer used. I'm trying to find a way to identify
which tables are never accessed by users, so that we can stop those
loads and drop the tables. For this purpose, if nobody SELECTs from a
table in 30 days, I can consider that table dead. And, if anyone
SELECTs from the table even once, I need to keep it around.
This is a high-usage database, so performance is key. I'd rather not
run a Profiler session for 30 days straight, because of the potential
impact on performance. Ideally, I'd like to find something like a
one-time trigger: a table is accessed, a trigger fires and adds that
table to a "Keep Me" list somewhere, then the trigger is disabled. I
don't think SELECT triggers exist in SQL2000, though.
Anyone have creative ideas on how to generate a list of used or unused
tables? Or is there a way I could do this with Profiler without
creating too much overhead?
Cheers!
Hi stavros
"stavros" wrote:
> We regularly load data into hundreds of tables in a reporting database.
> I know that many of the tables were needed years ago for short-term
> projects, and are no longer used. I'm trying to find a way to identify
> which tables are never accessed by users, so that we can stop those
> loads and drop the tables. For this purpose, if nobody SELECTs from a
> table in 30 days, I can consider that table dead. And, if anyone
> SELECTs from the table even once, I need to keep it around.
> This is a high-usage database, so performance is key. I'd rather not
> run a Profiler session for 30 days straight, because of the potential
> impact on performance. Ideally, I'd like to find something like a
> one-time trigger: a table is accessed, a trigger fires and adds that
> table to a "Keep Me" list somewhere, then the trigger is disabled. I
> don't think SELECT triggers exist in SQL2000, though.
AFAIK profiler is the only tool that is likely to do this. You could run
multiple profiles that covers the whole period and process each profile
offline rather than having one single set of outputs to process at the end of
the period.
> Anyone have creative ideas on how to generate a list of used or unused
> tables? Or is there a way I could do this with Profiler without
> creating too much overhead?
>
This is where source code control is very advantages, just doing textual
searches for your tables will eliminate alot of them. Alternatively if you
use stored procedures, then you could script the stored procedures on their
own and do a textual search. If want to know which procedures are called
without using profiler you could add code that audits the procedure being
run, although this will be an overhead whilst you are collecting the
information and a potential bottleneck. it will also mean a code change.
> Cheers!
>
John
Auditing table access
I know that many of the tables were needed years ago for short-term
projects, and are no longer used. I'm trying to find a way to identify
which tables are never accessed by users, so that we can stop those
loads and drop the tables. For this purpose, if nobody SELECTs from a
table in 30 days, I can consider that table dead. And, if anyone
SELECTs from the table even once, I need to keep it around.
This is a high-usage database, so performance is key. I'd rather not
run a Profiler session for 30 days straight, because of the potential
impact on performance. Ideally, I'd like to find something like a
one-time trigger: a table is accessed, a trigger fires and adds that
table to a "Keep Me" list somewhere, then the trigger is disabled. I
don't think SELECT triggers exist in SQL2000, though.
Anyone have creative ideas on how to generate a list of used or unused
tables? Or is there a way I could do this with Profiler without
creating too much overhead?
Cheers!Hi stavros
"stavros" wrote:
> We regularly load data into hundreds of tables in a reporting database.
> I know that many of the tables were needed years ago for short-term
> projects, and are no longer used. I'm trying to find a way to identify
> which tables are never accessed by users, so that we can stop those
> loads and drop the tables. For this purpose, if nobody SELECTs from a
> table in 30 days, I can consider that table dead. And, if anyone
> SELECTs from the table even once, I need to keep it around.
> This is a high-usage database, so performance is key. I'd rather not
> run a Profiler session for 30 days straight, because of the potential
> impact on performance. Ideally, I'd like to find something like a
> one-time trigger: a table is accessed, a trigger fires and adds that
> table to a "Keep Me" list somewhere, then the trigger is disabled. I
> don't think SELECT triggers exist in SQL2000, though.
AFAIK profiler is the only tool that is likely to do this. You could run
multiple profiles that covers the whole period and process each profile
offline rather than having one single set of outputs to process at the end of
the period.
> Anyone have creative ideas on how to generate a list of used or unused
> tables? Or is there a way I could do this with Profiler without
> creating too much overhead?
>
This is where source code control is very advantages, just doing textual
searches for your tables will eliminate alot of them. Alternatively if you
use stored procedures, then you could script the stored procedures on their
own and do a textual search. If want to know which procedures are called
without using profiler you could add code that audits the procedure being
run, although this will be an overhead whilst you are collecting the
information and a potential bottleneck. it will also mean a code change.
> Cheers!
>
John
Thursday, March 8, 2012
Audit Tools
available for SQL Server 2000.?
Thanks
The free version would likely be to create your own traces
in SQL Server. Import the traces to a table. Then create the
reports off the trace table you imported.
-Sue
On Tue, 15 Jun 2004 12:14:24 -0400, "Jignesh Doshi"
<nospam@.nospam.com> wrote:
>Are there any Royalty-Free Database Auditing 'Setup and Reporting' Tools
>available for SQL Server 2000.?
>Thanks
>
|||Create several traces:High CPU, Duration, Read and Write.
Script them.
Turn the script into stored procs that write to disk at 1 MB intervals.
Run the procs as startup procedures.
Use a job to import the trace output with the function.
Just a thought.
Tim Net
"Jignesh Doshi" <nospam@.nospam.com> wrote in message
news:%233XszMvUEHA.220@.TK2MSFTNGP10.phx.gbl...
> Are there any Royalty-Free Database Auditing 'Setup and Reporting' Tools
> available for SQL Server 2000.?
> Thanks
>
Friday, February 24, 2012
Attempted to read or write protected memory
Services. The problem is that I have a subscription tied to a report that
emails it around to users and I'm sporadically getting this message:
"Failure sending mail: Attempted to read or write protected memory. This is
often an indication that other memory is corrupt."
(Full error from logs: Error sending email. System.AccessViolationException:
Attempted to read or write protected memory. This is often an indication that
other memory is corrupt.)
I'm not particularly sure why this report is a problem (or if it is) as it's
not all that complicated. The report itself runs fine and never throws the
error, but for some reason it's unable to send email occasionally. If I
reschedule the subscription, it will usually email it out. But it's not
reliable at all.
Reporting Services is running a web cluster here, we also have a SQL Server
2005 database cluster running the underlying metadata repository, the reports
are sent via the SMTP configuration via the RS config files. Everything else
seems to be working hunky dory except for this issue.
Googling hasn't been much help ... I did look in to a few issues which
pointed to images (which I have in the header of the report) not being the
right MIME type, but mine seem to be okay. I have a couple of .NET assemblies
embedded in the report, but I'm just not real sure where to track down the
problem on this issue.
Any ideas on what I can do to track down the failure?
Here's the error from the log files. You can also see in the logs that other
emails are going out okay.
============= LOG INFORMATION BELOW ============= ReportingServicesService!library!c!10/31/2007-05:53:07:: i INFO: Cleaned 0
batch records, 0 policies, 0 sessions, 0 cache entries, 0 snapshots, 0
chunks, 0 running jobs, 0 persisted streams
ReportingServicesService!dbpolling!b!10/31/2007-05:58:07:: EventPolling
processing 2 more items. 2 Total items in internal queue.
ReportingServicesService!dbpolling!4!10/31/2007-05:58:07:: EventPolling
processing item 29cd0331-4666-422c-80ea-f816472daaf0
ReportingServicesService!dbpolling!c!10/31/2007-05:58:07:: EventPolling
processing item 5ce520dd-ae10-4e6f-b8bd-32070237a266
ReportingServicesService!library!4!10/31/2007-05:58:07:: Schedule
4f87d0bc-1f33-475b-96a6-eafab3c721b6 executed at 10/31/2007 5:58:07 AM.
ReportingServicesService!schedule!4!10/31/2007-05:58:07:: Creating Time
based subscription notification for subscription:
b51d5c44-4e93-4b65-8357-5d7de75cf8f8
ReportingServicesService!library!c!10/31/2007-05:58:07:: Schedule
c28239dc-df46-406c-a1f6-a8e4a22a0a98 executed at 10/31/2007 5:58:07 AM.
ReportingServicesService!schedule!c!10/31/2007-05:58:07:: Creating Time
based subscription notification for subscription:
2aa119ba-312c-49b6-9676-43be2eb0dcef
ReportingServicesService!library!c!10/31/2007-05:58:07:: Schedule
c28239dc-df46-406c-a1f6-a8e4a22a0a98 execution completed at 10/31/2007
5:58:07 AM.
ReportingServicesService!library!4!10/31/2007-05:58:07:: Schedule
4f87d0bc-1f33-475b-96a6-eafab3c721b6 execution completed at 10/31/2007
5:58:07 AM.
ReportingServicesService!dbpolling!c!10/31/2007-05:58:07:: EventPolling
finished processing item 5ce520dd-ae10-4e6f-b8bd-32070237a266
ReportingServicesService!dbpolling!c!10/31/2007-05:58:07::
NotificationPolling processing item 8a39847b-b85e-4594-8e4c-4bae0e83945b
ReportingServicesService!dbpolling!b!10/31/2007-05:58:07::
NotificationPolling processing 2 more items. 2 Total items in internal queue.
ReportingServicesService!dbpolling!a!10/31/2007-05:58:07::
NotificationPolling processing item e03f07d1-eb70-499a-b4bd-774d62f76bcb
ReportingServicesService!dbpolling!4!10/31/2007-05:58:07:: EventPolling
finished processing item 29cd0331-4666-422c-80ea-f816472daaf0
ReportingServicesService!library!c!10/31/2007-05:58:08:: i INFO:
Initializing EnableIntegratedSecurity to 'True' as specified in Server
system properties.
ReportingServicesService!library!a!10/31/2007-05:58:08:: i INFO:
Initializing EnableIntegratedSecurity to 'True' as specified in Server
system properties.
ReportingServicesService!emailextension!a!10/31/2007-05:58:10:: Error
sending email. System.AccessViolationException: Attempted to read or write
protected memory. This is often an indication that other memory is corrupt.
at
Microsoft.ReportingServices.EmailDeliveryProvider.EmailProvider.CreateMessage(Notification notification)
at
Microsoft.ReportingServices.EmailDeliveryProvider.EmailProvider.Deliver(Notification notification)
ReportingServicesService!notification!a!10/31/2007-05:58:10:: Notification
e03f07d1-eb70-499a-b4bd-774d62f76bcb completed. Success: False, Status:
Failure sending mail: Attempted to read or write protected memory. This is
often an indication that other memory is corrupt., DeliveryExtension: Report
Server Email, Report: DailyCustomerOrders, Attempt 0
ReportingServicesService!dbpolling!a!10/31/2007-05:58:10::
NotificationPolling finished processing item
e03f07d1-eb70-499a-b4bd-774d62f76bcb
ReportingServicesService!library!c!10/31/2007-05:58:11:: i INFO: Call to
RenderFirst( '/Paramount/CustomerShipments' )
ReportingServicesService!library!c!10/31/2007-05:58:13:: i INFO:
Initializing SqlStreamingBufferSize to default value of '64640' Bytes because
it was not specified in Server system properties.
ReportingServicesService!library!c!10/31/2007-05:58:13:: i INFO:
Initializing SnapshotCompression to 'SQL' as specified in Server system
properties.
ReportingServicesService!library!c!10/31/2007-05:58:16:: i INFO:
Initializing ResponseBufferSizeKb to default value of '64' KB because it was
not specified in Server system properties.
ReportingServicesService!library!c!10/31/2007-05:58:17:: i INFO:
Initializing SessionTimeout to '600' second(s) as specified in Server system
properties.
ReportingServicesService!library!c!10/31/2007-05:58:17:: i INFO:
Initializing EnableExecutionLogging to 'True' as specified in Server system
properties.
ReportingServicesService!emailextension!c!10/31/2007-05:58:17:: Email
successfully sent to "removed" <removed>
ReportingServicesService!notification!c!10/31/2007-05:58:17:: Notification
8a39847b-b85e-4594-8e4c-4bae0e83945b completed. Success: True, Status: Mail
sent to removed, DeliveryExtension: Report Server Email, Report:
CustomerShipments, Attempt 0
ReportingServicesService!dbpolling!c!10/31/2007-05:58:17::
NotificationPolling finished processing item
8a39847b-b85e-4594-8e4c-4bae0e83945b
ReportingServicesService!dbpolling!4!10/31/2007-05:59:07:: EventPolling
processing item fd139fe4-9412-4e96-96ce-3f0aed787b9d
ReportingServicesService!dbpolling!b!10/31/2007-05:59:07:: EventPolling
processing 1 more items. 1 Total items in internal queue.
ReportingServicesService!library!4!10/31/2007-05:59:07:: Schedule
29c40f83-6f27-4302-b739-84cea5b1429d executed at 10/31/2007 5:59:07 AM.
ReportingServicesService!schedule!4!10/31/2007-05:59:07:: Creating Time
based subscription notification for subscription:
2cb9b939-535b-46fb-8ff8-11aa2c5c56b7
ReportingServicesService!library!4!10/31/2007-05:59:07:: Schedule
29c40f83-6f27-4302-b739-84cea5b1429d execution completed at 10/31/2007
5:59:07 AM.
ReportingServicesService!dbpolling!4!10/31/2007-05:59:07:: EventPolling
finished processing item fd139fe4-9412-4e96-96ce-3f0aed787b9d
ReportingServicesService!dbpolling!b!10/31/2007-05:59:07::
NotificationPolling processing 1 more items. 1 Total items in internal queue.
ReportingServicesService!dbpolling!4!10/31/2007-05:59:07::
NotificationPolling processing item 7db9f680-501f-4623-988c-efeab0d1dbca
ReportingServicesService!emailextension!4!10/31/2007-05:59:07:: Error
sending email. System.AccessViolationException: Attempted to read or write
protected memory. This is often an indication that other memory is corrupt.
at
Microsoft.ReportingServices.EmailDeliveryProvider.EmailProvider.CreateMessage(Notification notification)
at
Microsoft.ReportingServices.EmailDeliveryProvider.EmailProvider.Deliver(Notification notification)
ReportingServicesService!notification!4!10/31/2007-05:59:07:: Notification
7db9f680-501f-4623-988c-efeab0d1dbca completed. Success: False, Status:
Failure sending mail: Attempted to read or write protected memory. This is
often an indication that other memory is corrupt., DeliveryExtension: Report
Server Email, Report: WarehouseExceptions, Attempt 0
ReportingServicesService!dbpolling!4!10/31/2007-05:59:07::
NotificationPolling finished processing item
7db9f680-501f-4623-988c-efeab0d1dbca
ReportingServicesService!library!4!10/31/2007-06:03:06:: i INFO: Cleaned 0
batch records, 0 policies, 0 sessions, 0 cache entries, 0 snapshots, 0
chunks, 0 running jobs, 0 persisted streams
ReportingServicesService!library!c!10/31/2007-06:13:07:: i INFO: Cleaned 0
batch records, 0 policies, 0 sessions, 0 cache entries, 0 snapshots, 0
chunks, 0 running jobs, 0 persisted streams
ReportingServicesService!library!c!10/31/2007-06:23:07:: i INFO: Cleaned 0
batch records, 0 policies, 0 sessions, 0 cache entries, 0 snapshots, 0
chunks, 0 running jobs, 0 persisted streams
ReportingServicesService!library!4!10/31/2007-06:33:07:: i INFO: Cleaned 0
batch records, 0 policies, 0 sessions, 0 cache entries, 0 snapshots, 0
chunks, 0 running jobs, 0 persisted streams
ReportingServicesService!dbpolling!9!10/31/2007-06:33:07:: EventPolling
polling service stopped
ReportingServicesService!dbpolling!e!10/31/2007-06:33:07:: EventPolling
heartbeat thread exiting for stop.
ReportingServicesService!dbpolling!9!10/31/2007-06:33:07::
NotificationPolling polling service stopped
ReportingServicesService!dbpolling!10!10/31/2007-06:33:07::
NotificationPolling heartbeat thread exiting for stop.
ReportingServicesService!dbpolling!9!10/31/2007-06:33:07:: SchedulePolling
polling service stopped
ReportingServicesService!dbpolling!9!10/31/2007-06:33:07:: UpgradePolling
polling service stopped
ReportingServicesService!servicecontroller!9!10/31/2007-06:33:11:: Service
controller exiting.Did you find an answer to this?
Monday, February 13, 2012
Attaching a rs2005sbsDW.mdf
Hi all,
I am trying to attach a database using the sample files that come with Microsoft SQL SERVER 2005 reporting services. When I try to attach it fails. What causes this error message?
TITLE: Microsoft SQL Server Management Studio
Attach database failed for Server 'CITS-D011'. (Microsoft.SqlServer.Smo)
For help, click: http://go.microsoft.com/fwlink?ProdName=Microsoft+SQL+Server&ProdVer=9.00.1399.00&EvtSrc=Microsoft.SqlServer.Management.Smo.ExceptionTemplates.FailedOperationExceptionText&EvtID=Attach+database+Server&LinkId=20476
ADDITIONAL INFORMATION:
An exception occurred while executing a Transact-SQL statement or batch. (Microsoft.SqlServer.ConnectionInfo)
Unable to open the physical file "C:\rs2005sbsDW\Setup\Database\rs2005sbsDW_Log.LDF". Operating system error 2: "2(The system cannot find the file specified.)". (Microsoft SQL Server, Error: 5120)
For help, click: http://go.microsoft.com/fwlink?ProdName=Microsoft+SQL+Server&ProdVer=09.00.1399&EvtSrc=MSSQLServer&EvtID=5120&LinkId=20476
BUTTONS:
OK
This error is the logfile. When I try to creae the path by creating directories under drive C, it still fails to attach.
Please help me out.
Ronaldlee
I solved this problem by deleting the incorrect path "C:\rs2005sbsDW\Setup\Database\rs2005sbsDW_Log.LDF"
Thanx
|||I solved the problem by deleting the incorrect path of the log file.
Thnx.