RE: VPN NT Authentication

From: Bill Hollinshead [MS] (billhol@online.microsoft.com)
Date: 10/25/02


From: billhol@online.microsoft.com ("Bill Hollinshead [MS]")
Date: Thu, 24 Oct 2002 22:20:00 GMT


Hi Lisa,

One possibility is the documentation omission that is corrected in
http://support.microsoft.com/support/kb/articles/q277/6/58.asp. Use the
setspn version that is available at
http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/setspn-o
.asp.

Another possibility may be
http://support.microsoft.com/support/kb/articles/q322/1/44.asp, but the
symptoms in the More Information section of that article must match,
otherwise the fix will not help <g>. If the symptoms do match then please
open a Microsoft Support Case with ODBC support to request the HotFix. Note
that the article's HotFix does not guarantee the error will be seen again
(see the last sentence of that article) <g>, and there are times when such
a login failed is required. For example, login 'NULL' tells me it is likely
the Domain is an NT4.0 domain and the account (i.e., SID) being supplied to
SQL Server is unknown. As an alternative workaround, you can configure the
DSN to use the Named Pipes Network-Library instead of the TCP/IP Sockets
Network-Library (both of those Network-Libraries do work over the TCP/IP
Network Protocol).

And you can try pass-through authentication:
0. The client box must be running NT (not Windows ME, 98, etc)
1. Upon the SQL Server box, create a Local account with a password.
2. Upon the client box create the identical Local account and password.
3. Log onto the client as that local account, and attempt to connect to SQL
Server.
Note that Local accounts were set up (not domain accounts).

I have attached the Resource Kit's whoami.exe. It may help you determine
the security context of the account that attempting to use integrated (NT)
authentication (from the client), and thus what SID is being passed to SQL
Server from that client via the VPN.

Thanks,

Bill Hollinshead
Microsoft, SQL Server

This posting is provided "AS IS" with no warranties, and confers no
rights. Subscribe to MSDN & use http://msdn.microsoft.com/newsgroups.






Relevant Pages

  • Re: It must be simple, but...
    ... I tried to run the connectcomputer wizzard on the client again, ... don;t have any of the user settings. ... is there an easy way to transfer all the settings of a local account ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows 2000 Professional Security
    ... >> private and no one other than the client computer's owner knows the ... One day this computer's owner logs on to the client computer ... the local account accesses including that of the default ...
    (microsoft.public.win2000.security)
  • Re: Windows 2000 Professional Security
    ... It is possible if someone else had undetected administrator access to that ... > Can anyone tell me if it's possible for a Windows 2000 Professional client ... One day this computer's owner logs on to the client computer ... the local account accesses including that of the default administor ...
    (microsoft.public.windows.server.security)
  • Re: Windows 2000 Professional Security
    ... It is possible if someone else had undetected administrator access to that ... > Can anyone tell me if it's possible for a Windows 2000 Professional client ... One day this computer's owner logs on to the client computer ... the local account accesses including that of the default administor ...
    (microsoft.public.win2000.security)
  • SuperSocket Info: Bind failed on TCP port 1433
    ... When I try to Install SQL Server 2000 using a local account that is a member ... The logon account cannot be validated for the SQL Server service. ... Windows XP Pro, SP2 and all available windows updates. ... Changing the port number with the Server Network Utility does not ...
    (microsoft.public.sqlserver.connect)