Re: SPN Requirement



Your welcome Bo - the spns can sometimes be nasty to deal
with. You should be sitting okay now though. Keep us posted.

-Sue

On Tue, 10 Oct 2006 21:35:02 -0700, Erik Bo Sørensen
<ErikBoSrensen@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Dear Sue et al

Thank you Sue for translating the Error code (I?ll better find out how to
translate these myself ? that could have saved me ? and this newsgroup ? a
lot of time).

Making SQLSrvRunas member of Domain Admin and restarting SQL Server -
"solved the problem".

As Sue point out, making the SQL Service account member of the domain
administrators group is of cause not an acceptable solution - and would be in
conflict with the Microsoft hardening recommendations for secure database
servers:

?Run the SQL Server service using a least privileged account to minimize the
damage that can be done by an attacker who manages to execute operating
system commands from SQL Server. The SQL Server service account should not be
granted elevated privileges such as membership to the Administrators group.?

I?ll look into the blog, Sue mentioned and will get back to conclude this
thread WHEN
I?m wiser!

Thanks again Sue for your time and effort spend and wise advises!

.



Relevant Pages

  • Re: SPN Requirement
    ... Making SQLSrvRunas member of Domain Admin and restarting SQL Server - ... As Sue point out, making the SQL Service account member of the domain ... The SQL Server service account should not be ...
    (microsoft.public.sqlserver.security)
  • Re: Run SQL Server as domain user
    ... that stuff (SQL Server' s adding your SQL Server service account to those builtin groups automatically) would not happen automatically if you would not use SQL Server Configuration Manager for changing your SQL Server services... ...
    (microsoft.public.sqlserver.setup)
  • Re: file backup component
    ... Otherwise you can try to use audit techniques to find out who's trying to access the LDF file. ... file backup app or any other app that need LDF file a while. ... he meant something that belongs to the SQL server itself. ... Delay the start of the SQL server service until manual start. ...
    (microsoft.public.windowsxp.embedded)
  • Re: Who is using MSMQ?
    ... To add on to the other responses, the MSMQ warning messages you get from the ... SQL Server Service Manager are the same ones you get from the Windows MMC ...
    (microsoft.public.sqlserver.security)
  • RE: Upgrade from 2005 to 2008: Invalid Credentials
    ... it seems that this issue was related to NETWORK SERVICE account for SSIS service could not be validated on DC. ... Please first go to your Services pane, double click your SQL Server Integration Services, switch to the Log On tab to check if the service account is NETWORK SERVICE account. ... Install SQL Server 2008 from the Command Prompt ... Microsoft Online Community Support ...
    (microsoft.public.sqlserver.setup)