Re: Locking down SQL Server 2005



Take a look at
VIEW ANY DATABASE and VIEW DEFINITION commands in the BOL



"Thomas Pauls" <Thomas Pauls@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4EDA6956-2C8A-4BEA-AC3A-0E6AAEF6C2A3@xxxxxxxxxxxxxxxx
Microsoft says that the SQL Serve 2005 is secure by default. But what can
you
additionally do, to secure the server?
I'm thinking of turning off protocols, that are not needed (i.e. Named
Pipes), setting Windows Authentication only, enable SSL encryption,
letting
the "Surface Area Configuration for Features" features disabled or
applying
the hisecws security template on the server.
Should stored procedures, that are not needed be disabled or deleted, or
should the "BUILTIN\Administrators" Group be removed from the sysadmin
role?
As far as I know, the "Security Configuration Wizard", that came with
Windows Server 2003 SP1 has no Role for "SQL 2005".
Do you have further proposals or is there a locking down guide for SQL
Server 2005?

Thx for your Help


.



Relevant Pages

  • Re: Connection fails to Analysis Services 2005 using Developer Edi
    ... when you try to change the AS config, do you do this on the server himself ... Unable to write data to the transport connection: ... And when I try to change the setup using the Surface Area Configuration ... To configure Analysis Service remote connections, ...
    (microsoft.public.sqlserver.olap)
  • Re: Need Feedback on Trans. Replication w/ Remote Distributor
    ... Built-in log shipping works over SMB protocols. ... BOL describes the built-in stuff for Log Shipping in Enterprise ... The SQL 2000 resource kit has some more information on roll your ... Microsoft SQL Server MVP ...
    (microsoft.public.sqlserver.replication)
  • Re: Error
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... the network or Internet, and then try again. ... You are trying to use a file that is stored on a server, ... protocols in the Player are not enabled. ...
    (microsoft.public.windowsmedia.player)
  • Re: Socket Server with Encryption help
    ... Authentication protocols are fiercely difficult to get right. ... "Practical Cryptography" book, that was suggested to you earlier, could be ... Client connects into Server and Server accepts the connection. ...
    (microsoft.public.dotnet.security)
  • Re: Capturing Windows Login Name
    ... annoyance of typing their user names and passwords again. ... that among other protocols supports NTLM. ... server in the last step, ... a site under the same Windows controller domain, ...
    (comp.lang.php)