Re: Delegation Failure

From: Les Connor [SBS MVP] (les.connor_at_DEL.cfive.ca)
Date: 01/29/04


Date: Wed, 28 Jan 2004 17:50:52 -0600

Let's be careful here ;-).

This is kind of an SBS question, it was wrongly cross posted to a whole
bunch of newsgroups and the discussion might not necessarily accurately
reflect an SBS scenario. Such as the following:

> Generally speaking, running two important services on one machine is
unsafe.
> If one is compromised, the other one will fall too. We do not recommend
> running anything on a DC.

--
Les Connor [SBS MVP]
-------------------------------------
SBS Rocks !
"Dmitri Gavrilov [MSFT]" <dmitrig@online.microsoft.com> wrote in message
news:eSmSyWe5DHA.2556@TK2MSFTNGP09.phx.gbl...
> What service account is SQL using? NetworkService or LocalSystem? Note
that
> when it was living on a member server, those accounts were mapped to the
> computer account, and this account was used when SQL was accessing network
> resources. Now, when SQL lives on the DC, so called "loopback
> authentication" is taking place, and SQL comes to DC authenticated as
> NetworkServer or LocalSystem, respectively.
>
> Generally speaking, running two important services on one machine is
unsafe.
> If one is compromised, the other one will fall too. We do not recommend
> running anything on a DC.
>
> --
> Dmitri Gavrilov
> SDE, Active Directory Core
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
> Use of included script samples are subject to the terms specified at
> http://www.microsoft.com/info/cpyright.htm
>
> "Paul L" <nospam@loring.net> wrote in message
> news:u5x2oRc5DHA.2392@TK2MSFTNGP11.phx.gbl...
> > I have a domain with SBS2003 server running IIS on one machine and
Windows
> > Server 2003 running SQL 2000 on another.  IIS uses integrated
> authentication
> > only, and delegation between IIS and SQL was working as advertised (all
> the
> > right checkboxes in Active Dir we set correctly, SQL used the
> authenticated
> > client, etc).
> >
> > We recently added the server with SQL as a Domain Controller so it could
> be
> > used as a backup.  Once it came on line, delegation stopped working, and
> IIS
> > attempts to log in to SQL as the 'NT AUTHORITY\ANONYMOUS LOGON' user,
> which,
> > of course, fails.
> >
> > I am going to remove the DC off of the SQL server, but I though someone
> > might know why having the second DC on the SQL server kills delegation.
> >
> > Thanks,
> > Paul
> >
> >
> >
>
>


Relevant Pages

  • Re: Redundancy design in SBS Domain
    ... But virtualization was not on my radar, and Exchange and SQL need more with each iteration. ... I originally went the SBS route because it was by far the cheapest was to get a server up and running with SQL Server at the time. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 Std - SQL Eval expired...will un-installing break SBS fun
    ... I agree with Claus that you're able to remove SQL 2005 instances if you did ... you can get SBS R2 which already contains SQL Server 2005 ... Workgroup Edition, and upgrade Sharepoint instance, and install other ...
    (microsoft.public.windows.server.sbs)
  • Re: sharepoint error
    ... If you are using SBS 2003 Premium Edition the easiest way is to follow ... to upgrade the SharePoint named instance. ... and search on "Migrating from WMSDE to SQL Server" ... Microsoft Small Business Server Support ...
    (microsoft.public.windows.server.sbs)
  • Re: WSUS
    ... Les Connor [SBS MVP] ... Is your server exhibiting significant performance problems, and if so, how ... SQL Server: ... >No wonder SBS brings servers with 4GB of RAM to their knees. ...
    (microsoft.public.windows.server.sbs)
  • RE: Confusion on standard security methodologies.
    ... Application will talk to a back-end SQL ... By "back-end," I assume you mean on a different box from IIS? ... If SQL is on a separate box, you won't be able to use NT authentication ... impersonations (meaning that once passed to the IIS server, ...
    (microsoft.public.inetserver.iis.security)