Re: Expire passwords

From: Uttam Parui[MS] (uttamkp_at_online.microsoft.com)
Date: 08/11/03


Date: Mon, 11 Aug 2003 08:06:48 GMT


Whenever possible, you should require Windows Authentication Mode for
connections to SQL Server. This will shield your SQL Server installation
from most Internet-based attacks by restricting connections to Microsoft
Windows® user and domain user accounts. Your server will also benefit from
Windows security enforcement mechanisms such as stronger authentication
protocols and mandatory password complexity and expiration. Also,
credentials delegation (the ability to bridge credentials across multiple
servers) is only available in Windows Authentication Mode. On the client
side, Windows Authentication Mode eliminates the need to store passwords,
which is a major vulnerability in applications that use standard SQL Server
logins.

For more things to do to secure your SQL Server 2000, visit
http://www.microsoft.com/sql/techinfo/administration/2000/security/securings
qlserver.asp

Regards,

Uttam Parui
SQL Server Developer Support Engineer, MCDBA, MCSE, MCT
Product Support Services
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.

Are you secure? For information about the Strategic Technology Protection
Program and to order your FREE Security Tool Kit, please visit
http://www.microsoft.com/security.



Relevant Pages

  • Re: Select permission denied on object [tablename] database
    ... appropriate permissions (by default, it uses the ASPNET local user). ... your SQL server is running in Windows Authentication mode, ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Select permission denied on object [tablename] database
    ... it uses the ASPNET local user). ... > your SQL server is running in Windows Authentication mode, ... >> The connection is getting opened but it is throwing the exception in ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: User ID issue - urgent
    ... Is your SQL Server configured to only support Trusted Connections? ... SQL Server and Windows Authentication Mode ... I add the ID under the default security tab, ...
    (microsoft.public.sqlserver.security)
  • Re: Yukon and mixed mode for msde database?
    ... Michael Tissington ... > "We recommend using Windows Authentication mode when possible. ... Mixed mode is required when working with SQL Server 7.0. ...
    (microsoft.public.sqlserver.msde)
  • RE: MS03-031: Cumulative Security Patch for SQL Server
    ... Microsoft SQL Server 2000 by using named pipes, ... Connection could not be established. ... To obtain a hotfix to resolve this error message, ... SQL Server Developer Support Engineer, MCDBA, MCSE, MCT ...
    (microsoft.public.sqlserver.security)