Showing posts with label domain. Show all posts
Showing posts with label domain. Show all posts

Monday, March 19, 2012

active directory with sqll 2005

Hello,
I have an active directoy controller with microsoft SQL 2005 installed
in the same windows 2003 machine.
is there a way to grant a domain user to start/stop sql server without
domain admin privilege?
Many thanks for the help in advance.The local admin on the server would do the trick. Thats what I have on all
SQL servers I manage.
Mohit K. Gupta
B.Sc. CS, Minor Japanese
MCTS: SQL Server 2005
"one2001boy@.yahoo.com" wrote:

> Hello,
> I have an active directoy controller with microsoft SQL 2005 installed
> in the same windows 2003 machine.
> is there a way to grant a domain user to start/stop sql server without
> domain admin privilege?
> Many thanks for the help in advance.
>|||Mohit K. Gupta wrote:
> The local admin on the server would do the trick. Thats what I have on al
l
> SQL servers I manage.
>
For the domain controller on Win 2003, there is no local admin. Your SQL
server must not be on domain controller.
thanks for your help anyway.|||Yeap. Sorry my bad, I wouldn't want SQL Server to be on PDC. The network
guys would make my life a living hell.
Not server guy, but if the service is set to start under set of credentials.
Can those credentials start/stop the service?
Mohit K. Gupta
B.Sc. CS, Minor Japanese
MCTS: SQL Server 2005
"one2001boy@.yahoo.com" wrote:

> Mohit K. Gupta wrote:
> For the domain controller on Win 2003, there is no local admin. Your SQL
> server must not be on domain controller.
> thanks for your help anyway.
>

Active Directory Upgrade and SQL

Would upgrading to Active Directory from a NT4 domain have any effect
on SQL Server 2000 SP3a?
After our upgrade we started having connectivity issues with another
server that it pulls data from over the internet going through ISA
Server 2000. The AD upgrade was done on Sunday and the problem did
not surface until Tuesday morning. Monday it seemed to work just
fine. We get timeout errors. The server it connects to is SQL 2000
as well. Google and Microsoft searches have turned up nothing for me
so far. Any ideas?Assuming these are connection timeouts (as opposed to query timeouts), I
would guess that your domain controller is slow to authenticate your
logins. I would suggest checking other connectivity and see if there are
delays in authenticating when you create/access shares and other such
activity.
Cindy Gross, MCDBA, MCSE
http://cindygross.tripod.com
This posting is provided "AS IS" with no warranties, and confers no rights.

Active Directory Domain Local Groups

Hi,
I have the following problem with AD an RS: when creating a group of users
as a "domain local group" in AD, i'm able to give a specific item-level role
in RS to members of this group. But it looks like rights are not effective
for those users. For example if the group is defined as "reader" on a folder,
group members can't see it in RS!
Everything works fine when the created group is a "global group" in AD.
Thanx in advance.
Greg.I still need help.
Thanx in advance.
"Greg - NEOS" wrote:
> Hi,
> I have the following problem with AD an RS: when creating a group of users
> as a "domain local group" in AD, i'm able to give a specific item-level role
> in RS to members of this group. But it looks like rights are not effective
> for those users. For example if the group is defined as "reader" on a folder,
> group members can't see it in RS!
> Everything works fine when the created group is a "global group" in AD.
> Thanx in advance.
> Greg.

Active Directory Conversion

We are updating an NT domain to Active Directory.
All of our security group within RS are based on local (machine groups)
which contain domain groups as members. So we are pretty comfortable with
the conversion path required there.
We understand how we can change the Data Base Agent and Remote Execution
Agents using rsconfig (-c and -e switches).
The ReportServer Service runs as NT Authority\Network Service and as such
needs no change.
Is there anything else we are missing which must be touched to get to AD?
thanks in advance,
dlrDennis,
My company recently migrated all the users from an NT domain to an AD domain
and since we have been unable to setup new email subscriptions through RS.
Our work around has been to login to the old domain and create the
subscriptions. It seems that the account RS uses does not have permissions to
read the TGGAU attribute on the user account that was used to create and to
process the e-mail subscriptions. Until our RS server is migrated over to the
new AD domain I don't know of a solution to this issue. You can find out more
about it below...hope this helps...
http://support.microsoft.com/default.aspx?scid=kb;en-us;842423
Regards,
Ben Sullins
"Dennis Redfield" wrote:
> We are updating an NT domain to Active Directory.
> All of our security group within RS are based on local (machine groups)
> which contain domain groups as members. So we are pretty comfortable with
> the conversion path required there.
> We understand how we can change the Data Base Agent and Remote Execution
> Agents using rsconfig (-c and -e switches).
> The ReportServer Service runs as NT Authority\Network Service and as such
> needs no change.
> Is there anything else we are missing which must be touched to get to AD?
>
> thanks in advance,
> dlr
>
>|||thanx
"Ben Sullins" <BenSullins@.discussions.microsoft.com> wrote in message
news:5471A631-EA2F-4661-843B-2374D548F7A5@.microsoft.com...
> Dennis,
> My company recently migrated all the users from an NT domain to an AD
domain
> and since we have been unable to setup new email subscriptions through RS.
> Our work around has been to login to the old domain and create the
> subscriptions. It seems that the account RS uses does not have permissions
to
> read the TGGAU attribute on the user account that was used to create and
to
> process the e-mail subscriptions. Until our RS server is migrated over to
the
> new AD domain I don't know of a solution to this issue. You can find out
more
> about it below...hope this helps...
> http://support.microsoft.com/default.aspx?scid=kb;en-us;842423
> Regards,
> Ben Sullins
> "Dennis Redfield" wrote:
> > We are updating an NT domain to Active Directory.
> > All of our security group within RS are based on local (machine groups)
> > which contain domain groups as members. So we are pretty comfortable
with
> > the conversion path required there.
> > We understand how we can change the Data Base Agent and Remote Execution
> > Agents using rsconfig (-c and -e switches).
> > The ReportServer Service runs as NT Authority\Network Service and as
such
> > needs no change.
> >
> > Is there anything else we are missing which must be touched to get to
AD?
> >
> >
> > thanks in advance,
> >
> > dlr
> >
> >
> >
> >

active directory connection

Hi,
can I connect sql server 2000 to active directory, even
thay are on different machine but on the same domain ?
How ?
Thanks a lot!!!Check out :
http://www.atlantamdf.com/presentations/AtlantaMDF_111201_examples.txt for
an example using Linked server and LDAP query from SQL Server ...
--
HTH,
Vinod Kumar
MCSE, DBA, MCAD, MCSD
http://www.extremeexperts.com
"don pasquale" <anonymous@.discussions.microsoft.com> wrote in message
news:06c201c39314$e6bcaea0$a001280a@.phx.gbl...
> Hi,
> can I connect sql server 2000 to active directory, even
> thay are on different machine but on the same domain ?
> How ?
> Thanks a lot!!!
>

Active Directory authorization in RS Standard Edition

It is possible ?
Users connect to database with report data using own Active Directory
domain credentials (not ASPNET account) and users not must write login
and password (login credentials must be send automatic by IE)Bartosz Gorzynski <bartosz.gorzynski@.zapolex.pl> wrote in message news:<#T2XaQU0EHA.3808@.tk2msftngp13.phx.gbl>...
> It is possible ?
> Users connect to database with report data using own Active Directory
> domain credentials (not ASPNET account) and users not must write login
> and password (login credentials must be send automatic by IE)
By changing your securty within ASP.NET to Windows, rather than forms
and then invoking impersonation you should be able to accomplish this.
Samples for this are available at gotdotnet.
Good luck
Cos

Saturday, February 25, 2012

Account to Run SQL under?

Currently, our network/server/domain admins have admin control of our sql
servers. One manager wants to run sql under a special local admin account
to restrict this access, but then we will be effected by the password change
requirement, which could break sql every 90 days.
What is the best way to run sql so that the server admins don't have sql
admin access? Can I run it under "local system", and restrict machine
admins?Its not a wise choice to make the User IDs local to the
server, the reason is that non local user id's (i.e.
domain accounts) can be allocated email accounts so sql
server can send emails, whereas local userid's cannot.
If you do not want local administrators to have system
admin access rights then all you need to so is restrict
the BUILTIN\Administrators rights.
Peter
"Only two things are infinite, the universe and human
stupidity, and I'm not sure about the former."
Albert Einstein
>--Original Message--
>Currently, our network/server/domain admins have admin
control of our sql
>servers. One manager wants to run sql under a special
local admin account
>to restrict this access, but then we will be effected by
the password change
>requirement, which could break sql every 90 days.
>What is the best way to run sql so that the server admins
don't have sql
>admin access? Can I run it under "local system", and
restrict machine
>admins?
>
>.
>|||First of all, it is imposible to stop God from having access. And, in the
domain, Domain Administrators are God. However, you can slow them down
quite a bit. Here is a KB that details the procedures. Also know that if
you use AD Global Groups to grant the SQL Server DBAs administrative access,
which is a Best Practice, all the Domain Admin has to do is add themself or
the Domain Admins group to yours.
How to impede Windows NT administrators from administering a clustered
instance of SQL Server
http://support.microsoft.com/kb/263712/EN-US/
How to change the SQL Server or SQL Server Agent Service account without
using SQL Enterprise Manager in SQL Server 2000
http://support.microsoft.com/default.aspx?scid=kb;en-us;283811
If you suspect foul play, it would be better to run some sort of Audit
Logging on your system and then once captured, bring it the attention of the
Data Center Director's attention. Keep in mind that just like the DBAs,
with great power comes great responsibility. No one should be placed in a
role that they are not qualified, and responsible for, to perform.
Just like the DBAs have the authority to delete every user/system database,
the responsibility is to preserve that data. It is no different for the
Domain Admins. They have the authority to disrupt operations but the
responsibility to preserve them. If you find an individual, or team, that
does not play by these rules, that must be made know to the Operations
Manager, regardless of the title or the position of the offender.
Sincerely,
Anthony Thomas
"Peter The Spate" <anonymous@.discussions.microsoft.com> wrote in message
news:05b901c51b4e$87a454e0$a501280a@.phx.gbl...
Its not a wise choice to make the User IDs local to the
server, the reason is that non local user id's (i.e.
domain accounts) can be allocated email accounts so sql
server can send emails, whereas local userid's cannot.
If you do not want local administrators to have system
admin access rights then all you need to so is restrict
the BUILTIN\Administrators rights.
Peter
"Only two things are infinite, the universe and human
stupidity, and I'm not sure about the former."
Albert Einstein
>--Original Message--
>Currently, our network/server/domain admins have admin
control of our sql
>servers. One manager wants to run sql under a special
local admin account
>to restrict this access, but then we will be effected by
the password change
>requirement, which could break sql every 90 days.
>What is the best way to run sql so that the server admins
don't have sql
>admin access? Can I run it under "local system", and
restrict machine
>admins?
>
>.
>

Account to Run SQL under?

Its not a wise choice to make the User IDs local to the
server, the reason is that non local user id's (i.e.
domain accounts) can be allocated email accounts so sql
server can send emails, whereas local userid's cannot.
If you do not want local administrators to have system
admin access rights then all you need to so is restrict
the BUILTIN\Administrators rights.
Peter
"Only two things are infinite, the universe and human
stupidity, and I'm not sure about the former."
Albert Einstein

>--Original Message--
>Currently, our network/server/domain admins have admin
control of our sql
>servers. One manager wants to run sql under a special
local admin account
>to restrict this access, but then we will be effected by
the password change
>requirement, which could break sql every 90 days.
>What is the best way to run sql so that the server admins
don't have sql
>admin access? Can I run it under "local system", and
restrict machine
>admins?
>
>.
>
First of all, it is imposible to stop God from having access. And, in the
domain, Domain Administrators are God. However, you can slow them down
quite a bit. Here is a KB that details the procedures. Also know that if
you use AD Global Groups to grant the SQL Server DBAs administrative access,
which is a Best Practice, all the Domain Admin has to do is add themself or
the Domain Admins group to yours.
How to impede Windows NT administrators from administering a clustered
instance of SQL Server
http://support.microsoft.com/kb/263712/EN-US/
How to change the SQL Server or SQL Server Agent Service account without
using SQL Enterprise Manager in SQL Server 2000
http://support.microsoft.com/default...b;en-us;283811
If you suspect foul play, it would be better to run some sort of Audit
Logging on your system and then once captured, bring it the attention of the
Data Center Director's attention. Keep in mind that just like the DBAs,
with great power comes great responsibility. No one should be placed in a
role that they are not qualified, and responsible for, to perform.
Just like the DBAs have the authority to delete every user/system database,
the responsibility is to preserve that data. It is no different for the
Domain Admins. They have the authority to disrupt operations but the
responsibility to preserve them. If you find an individual, or team, that
does not play by these rules, that must be made know to the Operations
Manager, regardless of the title or the position of the offender.
Sincerely,
Anthony Thomas

"Peter The Spate" <anonymous@.discussions.microsoft.com> wrote in message
news:05b901c51b4e$87a454e0$a501280a@.phx.gbl...
Its not a wise choice to make the User IDs local to the
server, the reason is that non local user id's (i.e.
domain accounts) can be allocated email accounts so sql
server can send emails, whereas local userid's cannot.
If you do not want local administrators to have system
admin access rights then all you need to so is restrict
the BUILTIN\Administrators rights.
Peter
"Only two things are infinite, the universe and human
stupidity, and I'm not sure about the former."
Albert Einstein

>--Original Message--
>Currently, our network/server/domain admins have admin
control of our sql
>servers. One manager wants to run sql under a special
local admin account
>to restrict this access, but then we will be effected by
the password change
>requirement, which could break sql every 90 days.
>What is the best way to run sql so that the server admins
don't have sql
>admin access? Can I run it under "local system", and
restrict machine
>admins?
>
>.
>

Account to Run SQL under?

Its not a wise choice to make the User IDs local to the
server, the reason is that non local user id's (i.e.
domain accounts) can be allocated email accounts so sql
server can send emails, whereas local userid's cannot.
If you do not want local administrators to have system
admin access rights then all you need to so is restrict
the BUILTIN\Administrators rights.
Peter
"Only two things are infinite, the universe and human
stupidity, and I'm not sure about the former."
Albert Einstein

>--Original Message--
>Currently, our network/server/domain admins have admin
control of our sql
>servers. One manager wants to run sql under a special
local admin account
>to restrict this access, but then we will be effected by
the password change
>requirement, which could break sql every 90 days.
>What is the best way to run sql so that the server admins
don't have sql
>admin access? Can I run it under "local system", and
restrict machine
>admins?
>
>.
>First of all, it is imposible to stop God from having access. And, in the
domain, Domain Administrators are God. However, you can slow them down
quite a bit. Here is a KB that details the procedures. Also know that if
you use AD Global Groups to grant the SQL Server DBAs administrative access,
which is a Best Practice, all the Domain Admin has to do is add themself or
the Domain Admins group to yours.
How to impede Windows NT administrators from administering a clustered
instance of SQL Server
http://support.microsoft.com/kb/263712/EN-US/
How to change the SQL Server or SQL Server Agent Service account without
using SQL Enterprise Manager in SQL Server 2000
http://support.microsoft.com/defaul...kb;en-us;283811
If you suspect foul play, it would be better to run some sort of Audit
Logging on your system and then once captured, bring it the attention of the
Data Center Director's attention. Keep in mind that just like the DBAs,
with great power comes great responsibility. No one should be placed in a
role that they are not qualified, and responsible for, to perform.
Just like the DBAs have the authority to delete every user/system database,
the responsibility is to preserve that data. It is no different for the
Domain Admins. They have the authority to disrupt operations but the
responsibility to preserve them. If you find an individual, or team, that
does not play by these rules, that must be made know to the Operations
Manager, regardless of the title or the position of the offender.
Sincerely,
Anthony Thomas
"Peter The Spate" <anonymous@.discussions.microsoft.com> wrote in message
news:05b901c51b4e$87a454e0$a501280a@.phx.gbl...
Its not a wise choice to make the User IDs local to the
server, the reason is that non local user id's (i.e.
domain accounts) can be allocated email accounts so sql
server can send emails, whereas local userid's cannot.
If you do not want local administrators to have system
admin access rights then all you need to so is restrict
the BUILTIN\Administrators rights.
Peter
"Only two things are infinite, the universe and human
stupidity, and I'm not sure about the former."
Albert Einstein

>--Original Message--
>Currently, our network/server/domain admins have admin
control of our sql
>servers. One manager wants to run sql under a special
local admin account
>to restrict this access, but then we will be effected by
the password change
>requirement, which could break sql every 90 days.
>What is the best way to run sql so that the server admins
don't have sql
>admin access? Can I run it under "local system", and
restrict machine
>admins?
>
>.
>

account change causes DTS package jobs fail

DTS packages and jobs are created as domain administrator accounts
"\\ourdomain\administrator". For some reasons (separate database
account from network account), we switched to new domain administrator
account called "\\ourdomain\sqladm" as SQL Server, service startup
account. Some DTS jobs stop running. In DTSs, server connection uses
NT default acccount. Does anyone know what is going on here? Do I have
to change the DTS owmers to "\\ourdomain\sqladm"? or I have to change
all server connection in DTS packages as SQL account connection?
Thanks in advance.You should not need to change the ownereship of the DTS package. What is
the startup account for SQL Server Agent. It controls the execution of
jobs. Log in as the SQL Server Agent startup account on the server itself
and run the DTS packages that fail form Enterprise Manager. If they fail
there too, it could be a permissions problem with the account.
Rand
This posting is provided "as is" with no warranties and confers no rights.

account change causes DTS package jobs fail

DTS packages and jobs are created as domain administrator accounts
"\\ourdomain\administrator". For some reasons (separate database
account from network account), we switched to new domain administrator
account called "\\ourdomain\sqladm" as SQL Server, service startup
account. Some DTS jobs stop running. In DTSs, server connection uses
NT default acccount. Does anyone know what is going on here? Do I have
to change the DTS owmers to "\\ourdomain\sqladm"? or I have to change
all server connection in DTS packages as SQL account connection?
Thanks in advance.
You should not need to change the ownereship of the DTS package. What is
the startup account for SQL Server Agent. It controls the execution of
jobs. Log in as the SQL Server Agent startup account on the server itself
and run the DTS packages that fail form Enterprise Manager. If they fail
there too, it could be a permissions problem with the account.
Rand
This posting is provided "as is" with no warranties and confers no rights.

account change causes DTS package jobs fail

DTS packages and jobs are created as domain administrator accounts
"\\ourdomain\administrator". For some reasons (separate database
account from network account), we switched to new domain administrator
account called "\\ourdomain\sqladm" as SQL Server, service startup
account. Some DTS jobs stop running. In DTSs, server connection uses
NT default acccount. Does anyone know what is going on here? Do I have
to change the DTS owmers to "\\ourdomain\sqladm"? or I have to change
all server connection in DTS packages as SQL account connection?
Thanks in advance.You should not need to change the ownereship of the DTS package. What is
the startup account for SQL Server Agent. It controls the execution of
jobs. Log in as the SQL Server Agent startup account on the server itself
and run the DTS packages that fail form Enterprise Manager. If they fail
there too, it could be a permissions problem with the account.
Rand
This posting is provided "as is" with no warranties and confers no rights.

Sunday, February 19, 2012

Accessing SWebmObjectSet Objects

I'm working in an environment where domain structure and firewall rules only allow access to a SQL Server - including OS - via a SQL Server client connection. I'm attempting to collect various pieces of information for an inventory database that are not normally accessible through standard t-sql calls.

A specific example is collecting network adapter and IP information via WMI and sp_OAxxx procedures. I've been able to interface WMI and retrieve the SWebmObjectSet collection with the information I want, but I can't seem to get to the individual objects in the collection for two reasons. First, t-sql doesn't have any sort of "for each" construct that allows me to iterate through the objects. Second, the Item() method of SWebmObjectSet requires an object path that I haven't been able to enumerate.

I'm avoiding enabling xp_cmdshell in SQL 2005 so calls such as "ipconfig /all" are not at option at this point.

How can I access the individual objects in the collection via t-sql? Is there another technology I might use? Remember - I can only access via a standard SQL client.

Here is some code I've come up with so far.

-- INITIALIZE SCRIPT

DECLARE@.wmiLocatorINT,

@.wmiServicesINT,

@.wmiObjectSetINT,

@.wmiObjectCountINT,

@.wmiObjectINT,

@.wmiNetAdapterNameNVARCHAR(200),

@.wmiNetAdapterIPNVARCHAR(200),

@.loopIdxINT,

@.oleSourceNVARCHAR(500),

@.oldDescNVARCHAR(500),

@.rcBIGINT,

@.msgNVARCHAR(400)

-- INITIALIZE WMI COM OBJECTS

EXEC @.rc = master.dbo.sp_OACreate 'WbemScripting.SWbemLocator', @.wmiLocator OUTPUT

IF @.rc <> 0 BEGIN

PRINT 'Create WMI object failed'

RETURN

END ELSE BEGIN

EXEC @.rc = master.dbo.sp_OAMethod @.wmiLocator, 'ConnectServer', @.wmiServices OUTPUT, '.'

IF @.rc <> 0 BEGIN

EXEC master.dbo.sp_OADestroy @.wmiLocator

RETURN

END

END

-- COLLECT DESIRED DATA

EXEC@.rc = master.dbo.sp_OAMethod @.wmiServices, 'InstancesOf', @.wmiObjectSet OUTPUT, 'Win32_NetworkAdapterConfiguration'

EXEC@.wmiObjectCount= master.dbo.sp_OAGetProperty @.wmiObjectSet, 'Count', @.wmiObjectCount OUTPUT

SELECT@.loopIdx= 0

WHILE @.loopIdx < @.wmiObjectCount - 1 BEGIN

EXEC@.rc= master.dbo.sp_OAMethod @.wmiObjectSet, 'Item', @.wmiObject OUTPUT, @.loopIdx

IF @.rc <> 0 BEGIN

EXEC@.rc= master.dbo.sp_OAGetErrorInfo @.wmiObjectSet, @.oleSource OUTPUT, @.oldDesc OUTPUT

END ELSE BEGIN

EXEC@.rc= master.dbo.sp_OAGetProperty @.wmiObject, 'Caption', @.wmiNetAdapterName OUTPUT

EXEC@.rc= master.dbo.sp_OAGetProperty @.wmiObject, 'IPAddress', @.wmiNetAdapterIP OUTPUT

END

SELECT@.loopIdx= @.loopIdx + 1

END

-- CLEANUP

EXEC master.dbo.sp_OADestroy @.wmiServices

EXEC master.dbo.sp_OADestroy @.wmiLocator

Is it fair to assume that you have completely explored and discarded the various system metadata, security, stastical and configuration functions, as well as the ODBC functions?

Would it be possible to have a Windows Scheduler task that would freqently run, using SQLCmd.exe to populate a table in the server with the desired information?

|||

If you mean the SQL Server metadata, security, statistical and configuration functions, then yes I have. But it is entirely possible I missed something which is why I posted the question.

It is possible to use the Windows Scheduler as you noted. I'm not a fan of installing DBA utilities on every server I manage if I can get away with a centralized solution. Additionally, there are many devices in scope that have firewall rules preventing console access and/or file transfer mechanisms. In short, the only mechanism I have is a standard SQL client. That is not to say that I couldn't petition the security team for relaxed access, but security is king here and it would be a battle I would likely lose.

One solution I've considered is use of the xp_cmdshell. Enabling it in SQL 2005 is possible, but I would prefer to leave it alone if I can.

Bruce.

|||

This really sounds like a task for an administrative WMI script -controlled and executed by the system administrators, retrieving the data and storing it in a central server for you to access. I would think that such an approach would molify the net administrator's security concerns. Easily done with MOM/SMS or whatever monitoring/management software is being used.

Thursday, February 16, 2012

Accessing SQL Server Accross Domain

I have a concept for an application that I would like to
market, and have a question concerning configuration. My
user interface is built in ADO.Net and VB7, and this is
the part I would like to sell. The end user would use
this UI to access a SQL Server database that I would have
at my location, on my own domain. Is this concept
feasible? Is it possible to grant access on SQL Server to
users from different domains? I am using Windows
Integrated Authentication on my server, and have to as it
is being used with BizTalk Server. Thanks.
JTHi JT,
Thank you for using MSDN Newsgroup! It's my pleasure to assist you with
your issue.
As my understanding of your question, you want to know if you client
application in their domain could access the SQL Server in another domain,
right. If I misunderstood, please feel free to let me know.
To access the SQL Server across domain is possible.
At first, make sure the connection between this two computers is OK.
Please refer to this article:
http://support.microsoft.com/?id=238949
You can test the application environment by the following steps to test
the connectivity:
To test general connectivity:
PING < SQL_Server ip>
To test we can connect to default SQL Server port 1433:
TELNET < SQL_Server ip> 1433
If we can connect, the screen will go blank. The server is awaiting more
commands. Hit any key to return.
If we CANNOT connect, you will get an error:
"Connecting To < ip > ..Could not open connection to the host, on port 1433
No connection could be made because the target machine actively refused
it."
NOTE:
Port 1433 is the default port number for SQL Server. You can check the
actual port number by Server Network Utility. You can get the actual port
number in use by check the properties of TCP/IP (which should be in the
"Enabled Protocols").
Then, use your Query Analyzer to check if it can access the database from
one domain to another.
For information you could refer to or ADO.NET programming, you can refer
to the following materials or ask questions in related newsgroup:
http://support.microsoft.com/?id=216415
http://msdn.microsoft.com/library/d...-us/dnauth/html
/dnauth_security.asp
http://support.microsoft.com/defaul...microsoft.com:
80/support/kb/articles/Q193/1/35.ASP&NoWebContent=1
http://support.microsoft.com/defaul...b;en-us;q176379
Hope this answered your questions. If you still have questions, please feel
free to post new message here and I am ready to help.
Best regards
Baisong Wei
Microsoft Online Support
----
Get Secure! - www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only. Thanks.|||Thanks Baisong,
What type of Authentication does the distant user need to
use? Is it possible for them to use Windows Auth, or do
the need to use SQL Server Auth? Thanks.
JT
quote:

>--Original Message--
>Hi JT,
>Thank you for using MSDN Newsgroup! It's my pleasure to

assist you with
quote:

>your issue.
>As my understanding of your question, you want to know if

you client
quote:

>application in their domain could access the SQL Server

in another domain,
quote:

>right. If I misunderstood, please feel free to let me

know.
quote:

>To access the SQL Server across domain is possible.
>At first, make sure the connection between this two

computers is OK.
quote:

>Please refer to this article:
>http://support.microsoft.com/?id=238949
>You can test the application environment by the

following steps to test
quote:

>the connectivity:
>To test general connectivity:
> PING < SQL_Server ip>
>To test we can connect to default SQL Server port 1433:
> TELNET < SQL_Server ip> 1433
>If we can connect, the screen will go blank. The server

is awaiting more
quote:

>commands. Hit any key to return.
>If we CANNOT connect, you will get an error:
>"Connecting To < ip > ..Could not open connection to the

host, on port 1433
quote:

> No connection could be made because the target machine

actively refused
quote:

>it."
>NOTE:
>Port 1433 is the default port number for SQL Server. You

can check the
quote:

>actual port number by Server Network Utility. You can get

the actual port
quote:

>number in use by check the properties of TCP/IP (which

should be in the
quote:

>"Enabled Protocols").
>Then, use your Query Analyzer to check if it can access

the database from
quote:

>one domain to another.
>For information you could refer to or ADO.NET

programming, you can refer
quote:

>to the following materials or ask questions in related

newsgroup:
quote:

>http://support.microsoft.com/?id=216415
>http://msdn.microsoft.com/library/default.asp?

url=/library/en-us/dnauth/html
quote:

>/dnauth_security.asp
>http://support.microsoft.com/default.aspx?

scid=http://support.microsoft.com:
quote:

>80/support/kb/articles/Q193/1/35.ASP&NoWebContent=1
>http://support.microsoft.com/default.aspx?scid=kb;en-

us;q176379
quote:

>Hope this answered your questions. If you still have

questions, please feel
quote:

>free to post new message here and I am ready to help.
>
>Best regards
>Baisong Wei
>Microsoft Online Support
>----
>Get Secure! - www.microsoft.com/security
>This posting is provided "as is" with no warranties and

confers no rights.
quote:

>Please reply to newsgroups only. Thanks.
>
>
>.
>
|||Hi JT,
Thank you for using MSDN Newsgroup! It's my pleasure to assist you with
your issue.
Both Windows authentication and SQL Server authentication could be used
when your application access the SQL Server across domains. For Windows
Authentication Mode, when the domain that the SQL Server runs in trust the
domain of the application, it can access the SQL Server. For SQL
Authentication Mode, no relation with domain conception, you could add the
SQL Server account and your application could access the SQL Server through
IP.
Please refer to this article, which provide you detailed information of
programming:
HOW TO: Set Up SQL Server with Proxy Server
http://support.microsoft.com/defaul...kb;EN-US;216415
INF: TCP Ports Needed for Communication to SQL Server Through a Firewall
http://support.microsoft.com/?id=287932
HOWTO: Use ADO to Connect to a SQL Server That Is Behind a Firewall
http://support.microsoft.com/defaul...kb;EN-US;269882
Connecting to a SQL Server Data Source
http://msdn.microsoft.com/library/d...-us/adosql/adop
rg01_0ahx.asp
INF: Authentication Methods for Connections to SQL Server in Active Server
Pages
http://support.microsoft.com/?id=247931
Hope this information will be useful to your concern. If you still have
question, please feel free to post new message here and I am ready to help!
Best regards
Baisong Wei
Microsoft Online Support
----
Get Secure! - www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only. Thanks.|||Thank you very much.
JT
quote:

>--Original Message--
>Hi JT,
>Thank you for using MSDN Newsgroup! It's my pleasure to

assist you with
quote:

>your issue.
>Both Windows authentication and SQL Server

authentication could be used
quote:

>when your application access the SQL Server across

domains. For Windows
quote:

>Authentication Mode, when the domain that the SQL Server

runs in trust the
quote:

>domain of the application, it can access the SQL Server.

For SQL
quote:

>Authentication Mode, no relation with domain conception,

you could add the
quote:

>SQL Server account and your application could access the

SQL Server through
quote:

>IP.
>Please refer to this article, which provide you detailed

information of
quote:

>programming:
>HOW TO: Set Up SQL Server with Proxy Server
>http://support.microsoft.com/default.aspx?scid=kb;EN-

US;216415
quote:

>INF: TCP Ports Needed for Communication to SQL Server

Through a Firewall
quote:

>http://support.microsoft.com/?id=287932
>HOWTO: Use ADO to Connect to a SQL Server That Is Behind

a Firewall
quote:

>http://support.microsoft.com/default.aspx?scid=kb;EN-

US;269882
quote:

>Connecting to a SQL Server Data Source
>http://msdn.microsoft.com/library/default.asp?

url=/library/en-us/adosql/adop
quote:

>rg01_0ahx.asp
>INF: Authentication Methods for Connections to SQL

Server in Active Server
quote:

>Pages
>http://support.microsoft.com/?id=247931
>Hope this information will be useful to your concern. If

you still have
quote:

>question, please feel free to post new message here and

I am ready to help!
quote:

>Best regards
>Baisong Wei
>Microsoft Online Support
>----
>Get Secure! - www.microsoft.com/security
>This posting is provided "as is" with no warranties and

confers no rights.
quote:

>Please reply to newsgroups only. Thanks.
>.
>

Thursday, February 9, 2012

Accessing only one database on the SQL server

I have outsider-developer who is using her own laptop (not part of domain) t
o work on a project, I need to get her an access to our SQL database so she
can develop an application she is working on. I created new db, then new sql
user, she had SQL tools on
her laptop so then I registered server for here using this user I just creat
ed, then I gave access to this new created db… my question is what is the
minimun requirments (right/priviladges) so she can work with this new db but
prevent her with accessin
g other databases on the same server… other words I’m looking for scena
rio where she has full control over her db and no control over rest of the d
bs on the same serverPlace her in the dbo role for that database only and she should not have
rights to any other unless you give them to her.
Andrew J. Kelly SQL MVP
"TOM P." <TOMP@.discussions.microsoft.com> wrote in message
news:F7748074-FA4B-4C87-851A-82E5E2D5A4E6@.microsoft.com...
> I have outsider-developer who is using her own laptop (not part of domain)
to work on a project, I need to get her an access to our SQL database so she
can develop an application she is working on. I created new db, then new sql
user, she had SQL tools on her laptop so then I registered server for here
using this user I just created, then I gave access to this new created db.
my question is what is the minimun requirments (right/priviladges) so she
can work with this new db but prevent her with accessing other databases on
the same server. other words I'm looking for scenario where she has full
control over her db and no control over rest of the dbs on the same server|||Thanks, so this user should have only access to this particular DB, public a
nd db_owner roles no server role whatsoever... right?
"Andrew J. Kelly" wrote:

> Place her in the dbo role for that database only and she should not have
> rights to any other unless you give them to her.
> --
> Andrew J. Kelly SQL MVP
>
> "TOM P." <TOMP@.discussions.microsoft.com> wrote in message
> news:F7748074-FA4B-4C87-851A-82E5E2D5A4E6@.microsoft.com...
> to work on a project, I need to get her an access to our SQL database so s
he
> can develop an application she is working on. I created new db, then new s
ql
> user, she had SQL tools on her laptop so then I registered server for here
> using this user I just created, then I gave access to this new created db.
> my question is what is the minimun requirments (right/priviladges) so she
> can work with this new db but prevent her with accessing other databases o
n
> the same server. other words I'm looking for scenario where she has full
> control over her db and no control over rest of the dbs on the same server
>
>|||Yes that is correct. If they only belong to a database role they will not
have permissions outside that database.
Andrew J. Kelly SQL MVP
"TOM P." <TOMP@.discussions.microsoft.com> wrote in message
news:AB24E7E1-4095-450B-8A87-97A4C7CD02DD@.microsoft.com...
> Thanks, so this user should have only access to this particular DB, public
and db_owner roles no server role whatsoever... right?[vbcol=seagreen]
> "Andrew J. Kelly" wrote:
>
domain)[vbcol=seagreen]
she[vbcol=seagreen]
sql[vbcol=seagreen]
here[vbcol=seagreen]
db.[vbcol=seagreen]
she[vbcol=seagreen]
on[vbcol=seagreen]
full[vbcol=seagreen]
server[vbcol=seagreen]