Security Baseline Analyzer

From: Bosko Maksimovic (bosko19_at_hotmail.com)
Date: 06/29/03


Date: Sun, 29 Jun 2003 03:43:38 -0400


Good evening/morning,

I'm using the Baseline Analyzer to help in securing a SBS
2000 server. I implemented the advice of creating a
dedicated SQL Server account and setting the SQLSERVER and
SQLAgent services to start up with that account. Upon
doing so the SBA reported the errors listed below... Any
insight on why the errors occur would be appreciated!

1. ISSUE: Folder Permissions

RESULT: Permissions on the SQL Server installation folders
are not set properly.

ERROR IN DETAIL: USER - Invalid SID returned by the OS

2. ISSUE: Service Accounts

RESULT: SQL Server and/or SQL Server Agent Services
accounts are members of the local Administrators group or
run as LocalSystem.

ERROR: This is a Domain Account. Baseline Security
Analyzer cannot determine whether it belongs to the Domain
Admins group due to the following error: 122 The data area
passed to a system call is too small.

Thank you for your time in advance!

Sincerely,
Bosko Maksimovic



Relevant Pages

  • Re: Error 15401 using sp_grantlogin (not addressed by current KB articles)
    ... Restarting Windows 2000 resolved the problem for this particular account, ... confused when it sees a duplicate SID. ... > One way to get SQL Server to agree with the renamed NT ... > Preview (to ensure the script was created), ...
    (microsoft.public.sqlserver.security)
  • Re: SharePoint V3 Install Error
    ... But it our case it had to do with Group Policies that forbid the account of ... WSS FAQ:www.wssv3faq.com/wss.collutions.com ... Event Source: WindowsSharePointServices3Search ... whatever you are installing WSS as sufficient rights to the SQL Server ...
    (microsoft.public.sharepoint.windowsservices)
  • RE: Problems with WebParts
    ... to a database called aspnetdb. ... > The connection string specifies a local SQL Server Express instance using a ... > server account must have read and write access to the applications directory. ... > This is necessary because the web server account will automatically create ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Cannot connect to Query Analyzer
    ... For Query Analyzer, I tried replacing the file as you suggested but had the ... same results (Enterprise Manager starts up fine, ... I created an account on my laptop and changed SQL ... Try replacing the MMC app for SQL Server from the original ...
    (microsoft.public.sqlserver.connect)
  • Problems with WebParts
    ... The connection string specifies a local SQL Server Express instance using a ... database location within the applications App_Data directory. ... server account must have read and write access to the applications directory. ... logged-in user needs the dbcreator privilege in the appropriate SQL Server ...
    (microsoft.public.dotnet.framework.aspnet)