Tuesday, March 27, 2012
Cannot register server
In Enterprise manager, from server PM, I registered server VED but
cannot register server JF. I see it in the list of proposed server, but
when I enter the SQL user code and password, an error message tells me
that server cannot be registered because of time out. But I tried that
last week and everything worked properly. I have been told that nothing
had been changed.
Looking forward to receiving some feedback on the above.
Regards
Patrick
A few things to try :-
Can you ping server JF
Is it listening on the default port 1433, use telnet to establish
Is SQL Server running on server JF or has the service been stopped
HTH. Ryan
"Patrick" <pmenage@.intnet.mu> wrote in message
news:1137472586.261082.252830@.o13g2000cwo.googlegr oups.com...
>I am working on a LAN with 3 servers, VED, PM, JF
> In Enterprise manager, from server PM, I registered server VED but
> cannot register server JF. I see it in the list of proposed server, but
> when I enter the SQL user code and password, an error message tells me
> that server cannot be registered because of time out. But I tried that
> last week and everything worked properly. I have been told that nothing
> had been changed.
> Looking forward to receiving some feedback on the above.
> Regards
> Patrick
>
|||Is latest version of MDAC installed on youre client machine?
Check for it also.
Regards
Amish
|||The MDAC has not been chenged
amish wrote:
> Is latest version of MDAC installed on youre client machine?
> Check for it also.
>
> Regards
> Amish
|||I can Ping the machine, I even see it in the list of proposed servers
to register. it seems that it is not a network problem.
|||I have the same problem on my client machine and I update MDAC to MDAC
2.8 and it was solved.
http://www.microsoft.com/downloads/d...displaylang=en
- To download MDAC Version
http://support.microsoft.com/default.aspx?kbid=301202 - To Check MDAC
Version
Check also for TCP IP port using telnet <server ip> <port> or check
if you have any other entry for this server name in client server
utility.
Regards
Amish
Cannot register server
In Enterprise manager, from server PM, I registered server VED but
cannot register server JF. I see it in the list of proposed server, but
when I enter the SQL user code and password, an error message tells me
that server cannot be registered because of time out. But I tried that
last week and everything worked properly. I have been told that nothing
had been changed.
Looking forward to receiving some feedback on the above.
Regards
PatrickA few things to try :-
Can you ping server JF
Is it listening on the default port 1433, use telnet to establish
Is SQL Server running on server JF or has the service been stopped
HTH. Ryan
"Patrick" <pmenage@.intnet.mu> wrote in message
news:1137472586.261082.252830@.o13g2000cwo.googlegroups.com...
>I am working on a LAN with 3 servers, VED, PM, JF
> In Enterprise manager, from server PM, I registered server VED but
> cannot register server JF. I see it in the list of proposed server, but
> when I enter the SQL user code and password, an error message tells me
> that server cannot be registered because of time out. But I tried that
> last week and everything worked properly. I have been told that nothing
> had been changed.
> Looking forward to receiving some feedback on the above.
> Regards
> Patrick
>|||Is latest version of MDAC installed on youre client machine?
Check for it also.
Regards
Amish|||The MDAC has not been chenged
amish wrote:
> Is latest version of MDAC installed on youre client machine?
> Check for it also.
>
> Regards
> Amish|||I can Ping the machine, I even see it in the list of proposed servers
to register. it seems that it is not a network problem.|||I have the same problem on my client machine and I update MDAC to MDAC
2.8 and it was solved.
http://www.microsoft.com/downloads/...&displaylang=en
- To download MDAC Version
http://support.microsoft.com/default.aspx?kbid=301202 - To Check MDAC
Version
Check also for TCP IP port using telnet <server ip> <port> or check
if you have any other entry for this server name in client server
utility.
Regards
Amishsql
Cannot register server
In Enterprise manager, from server PM, I registered server VED but
cannot register server JF. I see it in the list of proposed server, but
when I enter the SQL user code and password, an error message tells me
that server cannot be registered because of time out. But I tried that
last week and everything worked properly. I have been told that nothing
had been changed.
Looking forward to receiving some feedback on the above.
Regards
PatrickA few things to try :-
Can you ping server JF
Is it listening on the default port 1433, use telnet to establish
Is SQL Server running on server JF or has the service been stopped
--
HTH. Ryan
"Patrick" <pmenage@.intnet.mu> wrote in message
news:1137472586.261082.252830@.o13g2000cwo.googlegroups.com...
>I am working on a LAN with 3 servers, VED, PM, JF
> In Enterprise manager, from server PM, I registered server VED but
> cannot register server JF. I see it in the list of proposed server, but
> when I enter the SQL user code and password, an error message tells me
> that server cannot be registered because of time out. But I tried that
> last week and everything worked properly. I have been told that nothing
> had been changed.
> Looking forward to receiving some feedback on the above.
> Regards
> Patrick
>|||Is latest version of MDAC installed on youre client machine?
Check for it also.
Regards
Amish|||The MDAC has not been chenged
amish wrote:
> Is latest version of MDAC installed on youre client machine?
> Check for it also.
>
> Regards
> Amish|||I can Ping the machine, I even see it in the list of proposed servers
to register. it seems that it is not a network problem.|||I have the same problem on my client machine and I update MDAC to MDAC
2.8 and it was solved.
http://www.microsoft.com/downloads/details.aspx?FamilyID=6C050FE3-C795-4B7D-B037-185D0506396C&displaylang=en
- To download MDAC Version
http://support.microsoft.com/default.aspx?kbid=301202 - To Check MDAC
Version
Check also for TCP IP port using telnet <server ip> <port> or check
if you have any other entry for this server name in client server
utility.
--
Regards
Amish
Sunday, March 25, 2012
Cannot register 6.5 server
I'm using my computer (Windows XP Professional) to
administrate remote sql servers 6.5, 7.0, and 2000. I can
successfully register all servers except one, sql server
6.5. Difference between this one and the other 6.5
servers is that it uses Named Pipes server library, and
the other ones use TCP/IP. I created an alias for this
specific server (with named pipes), but still, I get an
error message: "A connection could not be established to
<server name>. [DB Library] Unable to connect: SQL Server
is unavailable or does not exist."
At the same time I can ping the server... I can also
register this server from the other, Windows 2000 PC...
Any ideas?
Thanks,
BakiCan you map a drive to the \\<SQL Server Machine>\IPC$ share from the
WIndows XP machine. Named pipes requires a trusted connection and you may
not be able to establish that from the XP machine. If you cannot map a
drive then you will not be able to use named pipes. You may have to switch
to TCP/IP
Rand
This posting is provided "as is" with no warranties and confers no rights.|||Hi,
Are you saying that I cannot connect to this server using
Named Pipes if I'm not logged on to the same domain as
sql server is?
Thanks,
Baki
quote:
>--Original Message--
>Can you map a drive to the \\<SQL Server Machine>\IPC$
share from the
quote:
>WIndows XP machine. Named pipes requires a trusted
connection and you may
quote:
>not be able to establish that from the XP machine. If
you cannot map a
quote:
>drive then you will not be able to use named pipes. You
may have to switch
quote:
>to TCP/IP
>Rand
>This posting is provided "as is" with no warranties and
confers no rights.
quote:|||You have to access to the machine at the OS level. Named pipes requries
>.
>
that you have access to the machine. You do not have to be in the same
domain, but there does need to be some type of trust to use named pipes. If
your NT account has an account on the SQL Server machine you should be able
to use named pipes.
Either way named pipes requires a trust. This is documented in Books on
Line.
Rand
Thsi posting is proved "AS IS" with no warranties, and confers no rights.
Saturday, February 25, 2012
Cannot install SP1 on SQL Server 2005 (64bit)
Hi,
I'm having problems installing SP1 on one of our servers.
If I try to install the x64 version of SP1 setup says it can not update my server and I should use x86 version. Trying to install the x86 version results in the message I should use x64 version....
Any ideas?
Regards, Jan
What version of SQL do you have on the machine? x64 or x86? And when are you getting the error?
Thanks,
Sam Lester (MSFT)
Hi Sam,
version is Microsoft SQL Server Standard Edition (64-bit). I get this error after doubleclicking the service pack .exe file.
Regards,
Jan
|||OK, just to confirm what is on the box, can you go to Add/Remove Programs, click on change, and then on Report. This will show everything that the discovery process finds associated with SQL Server. This may help us figure out why the detection is giving you the error.
Also, can you supply the package name that you're trying to run?
Thanks,
Sam
Hi Sam,
here is the report:
SIAM
The following components are installed on this server
MSSQLSERVER
Analysis Services
[Version: 9.00.1399.06 Edition: Standard Edition (64-bit) Patch level: 9.00.1399.06 Language: English (United States)]
Database Engine
[Version: 9.00.1399.06 Edition: Standard Edition (64-bit) Patch level: 9.00.1399.06 Language: English (United States)]
Common components
Integration Services
[Version: 9.00.1399.06 Edition: Standard Edition (64-bit) Patch level: 9.00.1399.06 Language: English (United States)]
Notification Services
[Version: 9.00.1399.06 Edition: Standard Edition (64-bit) Patch level: 9.00.1399.06 Language: English (United States)]
Workstation Components
[Version: 9.00.1399.06 Edition: Standard Edition (64-bit) Patch level: 9.00.1399.06 Language: English (United States)]
Regards,
Jan
|||Great, thanks for posting the info! And to confirm, are you running this SP1 package:
SQLServer2005SP1-KB913090-x64-ENU.exe
from
http://www.microsoft.com/downloads/details.aspx?familyid=cb6c71ea-d649-47ff-9176-e7cac58fd4bc&displaylang=en
Thanks,
Sam
Hi,
no I didn't run this package but SQLServer2005SP1-KB913090-x64-ENU.exe (most of our server are german version).
With the englisch version installation worked - thanks for the great support.
Anyway, the error message is a bit misleading...
Regards,
Jan
Thursday, February 16, 2012
Cannot generate SSPI Context?
access and receive an error, see below. I can only see the server in Ent Mgr
if I remote to the server where SQL 2000 resides and run Ent mgr from there.
The SQL 2000 Named Intance resides on a Windows server 2003
The error I receive is:
Cannot generate SSPI Context?
After i change the SQL Server Service Account, i am getting above error
message. I change the service account 5 machines but i have only problem
with one server.
Please any body help me?You can define an alias and force the connection to using "name pipe" , there
is an KB article on it..
"Ram" wrote:
> I am trying to connect to one of our SQL servers via Ent mgr - I cannot
> access and receive an error, see below. I can only see the server in Ent Mgr
> if I remote to the server where SQL 2000 resides and run Ent mgr from there.
> The SQL 2000 Named Intance resides on a Windows server 2003
> The error I receive is:
> Cannot generate SSPI Context?
> After i change the SQL Server Service Account, i am getting above error
> message. I change the service account 5 machines but i have only problem
> with one server.
> Please any body help me?
>|||Or you can add the sqlserver service account to 'impersonate a user after
authentication' user rights assignment in security policy.
"Anthony" wrote:
> You can define an alias and force the connection to using "name pipe" , there
> is an KB article on it..
> "Ram" wrote:
> > I am trying to connect to one of our SQL servers via Ent mgr - I cannot
> > access and receive an error, see below. I can only see the server in Ent Mgr
> > if I remote to the server where SQL 2000 resides and run Ent mgr from there.
> >
> > The SQL 2000 Named Intance resides on a Windows server 2003
> >
> > The error I receive is:
> > Cannot generate SSPI Context?
> >
> > After i change the SQL Server Service Account, i am getting above error
> > message. I change the service account 5 machines but i have only problem
> > with one server.
> >
> > Please any body help me?
> >
> >|||Thanks for reply. we already added local administrator group and SQL Server
security as a sys administrator group also. I can connect using SQL
Authetication but i can't connect using Windows authetication. I also Added
Client network utility alias also. still doesn't work.
Ram
"Olu Adedeji" wrote:
> Or you can add the sqlserver service account to 'impersonate a user after
> authentication' user rights assignment in security policy.
> "Anthony" wrote:
> > You can define an alias and force the connection to using "name pipe" , there
> > is an KB article on it..
> >
> > "Ram" wrote:
> >
> > > I am trying to connect to one of our SQL servers via Ent mgr - I cannot
> > > access and receive an error, see below. I can only see the server in Ent Mgr
> > > if I remote to the server where SQL 2000 resides and run Ent mgr from there.
> > >
> > > The SQL 2000 Named Intance resides on a Windows server 2003
> > >
> > > The error I receive is:
> > > Cannot generate SSPI Context?
> > >
> > > After i change the SQL Server Service Account, i am getting above error
> > > message. I change the service account 5 machines but i have only problem
> > > with one server.
> > >
> > > Please any body help me?
> > >
> > >|||Hi Ram,
What operating system you have on computer from which you want to access SQL
server, is that computer member of workgroup or member of domain?
Regards,
Daniel
"Ram" <Ram@.discussions.microsoft.com> wrote in message
news:7B139AF7-E0E0-403F-B37D-96727A54F08E@.microsoft.com...
> Thanks for reply. we already added local administrator group and SQL
Server
> security as a sys administrator group also. I can connect using SQL
> Authetication but i can't connect using Windows authetication. I also
Added
> Client network utility alias also. still doesn't work.
> Ram
> "Olu Adedeji" wrote:
> > Or you can add the sqlserver service account to 'impersonate a user
after
> > authentication' user rights assignment in security policy.
> >
> > "Anthony" wrote:
> >
> > > You can define an alias and force the connection to using "name pipe"
, there
> > > is an KB article on it..
> > >
> > > "Ram" wrote:
> > >
> > > > I am trying to connect to one of our SQL servers via Ent mgr - I
cannot
> > > > access and receive an error, see below. I can only see the server in
Ent Mgr
> > > > if I remote to the server where SQL 2000 resides and run Ent mgr
from there.
> > > >
> > > > The SQL 2000 Named Intance resides on a Windows server 2003
> > > >
> > > > The error I receive is:
> > > > Cannot generate SSPI Context?
> > > >
> > > > After i change the SQL Server Service Account, i am getting above
error
> > > > message. I change the service account 5 machines but i have only
problem
> > > > with one server.
> > > >
> > > > Please any body help me?
> > > >
> > > >|||Hi Ram,
What operating system you have on computer from which you want to access SQL
server, is that computer member of workgroup or member of domain?
Regards,
Daniel
"Ram" <Ram@.discussions.microsoft.com> wrote in message
news:7B139AF7-E0E0-403F-B37D-96727A54F08E@.microsoft.com...
> Thanks for reply. we already added local administrator group and SQL
Server
> security as a sys administrator group also. I can connect using SQL
> Authetication but i can't connect using Windows authetication. I also
Added
> Client network utility alias also. still doesn't work.
> Ram
> "Olu Adedeji" wrote:
> > Or you can add the sqlserver service account to 'impersonate a user
after
> > authentication' user rights assignment in security policy.
> >
> > "Anthony" wrote:
> >
> > > You can define an alias and force the connection to using "name pipe"
, there
> > > is an KB article on it..
> > >
> > > "Ram" wrote:
> > >
> > > > I am trying to connect to one of our SQL servers via Ent mgr - I
cannot
> > > > access and receive an error, see below. I can only see the server in
Ent Mgr
> > > > if I remote to the server where SQL 2000 resides and run Ent mgr
from there.
> > > >
> > > > The SQL 2000 Named Intance resides on a Windows server 2003
> > > >
> > > > The error I receive is:
> > > > Cannot generate SSPI Context?
> > > >
> > > > After i change the SQL Server Service Account, i am getting above
error
> > > > message. I change the service account 5 machines but i have only
problem
> > > > with one server.
> > > >
> > > > Please any body help me?
> > > >
> > > >
Cannot generate SSPI Context?
access and receive an error, see below. I can only see the server in Ent Mgr
if I remote to the server where SQL 2000 resides and run Ent mgr from there.
The SQL 2000 Named Intance resides on a Windows server 2003
The error I receive is:
Cannot generate SSPI Context?
After i change the SQL Server Service Account, i am getting above error
message. I change the service account 5 machines but i have only problem
with one server.
Please any body help me?You can define an alias and force the connection to using "name pipe" , ther
e
is an KB article on it..
"Ram" wrote:
> I am trying to connect to one of our SQL servers via Ent mgr - I cannot
> access and receive an error, see below. I can only see the server in Ent M
gr
> if I remote to the server where SQL 2000 resides and run Ent mgr from ther
e.
> The SQL 2000 Named Intance resides on a Windows server 2003
> The error I receive is:
> Cannot generate SSPI Context?
> After i change the SQL Server Service Account, i am getting above error
> message. I change the service account 5 machines but i have only problem
> with one server.
> Please any body help me?
>|||Or you can add the sqlserver service account to 'impersonate a user after
authentication' user rights assignment in security policy.
"Anthony" wrote:
[vbcol=seagreen]
> You can define an alias and force the connection to using "name pipe" , th
ere
> is an KB article on it..
> "Ram" wrote:
>|||Thanks for reply. we already added local administrator group and SQL Server
security as a sys administrator group also. I can connect using SQL
Authetication but i can't connect using Windows authetication. I also Added
Client network utility alias also. still doesn't work.
Ram
"Olu Adedeji" wrote:
[vbcol=seagreen]
> Or you can add the sqlserver service account to 'impersonate a user after
> authentication' user rights assignment in security policy.
> "Anthony" wrote:
>|||Hi Ram,
What operating system you have on computer from which you want to access SQL
server, is that computer member of workgroup or member of domain?
Regards,
Daniel
"Ram" <Ram@.discussions.microsoft.com> wrote in message
news:7B139AF7-E0E0-403F-B37D-96727A54F08E@.microsoft.com...
> Thanks for reply. we already added local administrator group and SQL
Server
> security as a sys administrator group also. I can connect using SQL
> Authetication but i can't connect using Windows authetication. I also
Added[vbcol=seagreen]
> Client network utility alias also. still doesn't work.
> Ram
> "Olu Adedeji" wrote:
>
after[vbcol=seagreen]
, there[vbcol=seagreen]
cannot[vbcol=seagreen]
Ent Mgr[vbcol=seagreen]
from there.[vbcol=seagreen]
error[vbcol=seagreen]
problem[vbcol=seagreen]|||Hi Ram,
What operating system you have on computer from which you want to access SQL
server, is that computer member of workgroup or member of domain?
Regards,
Daniel
"Ram" <Ram@.discussions.microsoft.com> wrote in message
news:7B139AF7-E0E0-403F-B37D-96727A54F08E@.microsoft.com...
> Thanks for reply. we already added local administrator group and SQL
Server
> security as a sys administrator group also. I can connect using SQL
> Authetication but i can't connect using Windows authetication. I also
Added[vbcol=seagreen]
> Client network utility alias also. still doesn't work.
> Ram
> "Olu Adedeji" wrote:
>
after[vbcol=seagreen]
, there[vbcol=seagreen]
cannot[vbcol=seagreen]
Ent Mgr[vbcol=seagreen]
from there.[vbcol=seagreen]
error[vbcol=seagreen]
problem[vbcol=seagreen]
Tuesday, February 14, 2012
Cannot generate SSPI Context?
access and receive an error, see below. I can only see the server in Ent Mgr
if I remote to the server where SQL 2000 resides and run Ent mgr from there.
The SQL 2000 Named Intance resides on a Windows server 2003
The error I receive is:
Cannot generate SSPI Context?
After i change the SQL Server Service Account, i am getting above error
message. I change the service account 5 machines but i have only problem
with one server.
Please any body help me?
You can define an alias and force the connection to using "name pipe" , there
is an KB article on it..
"Ram" wrote:
> I am trying to connect to one of our SQL servers via Ent mgr - I cannot
> access and receive an error, see below. I can only see the server in Ent Mgr
> if I remote to the server where SQL 2000 resides and run Ent mgr from there.
> The SQL 2000 Named Intance resides on a Windows server 2003
> The error I receive is:
> Cannot generate SSPI Context?
> After i change the SQL Server Service Account, i am getting above error
> message. I change the service account 5 machines but i have only problem
> with one server.
> Please any body help me?
>
|||Or you can add the sqlserver service account to 'impersonate a user after
authentication' user rights assignment in security policy.
"Anthony" wrote:
[vbcol=seagreen]
> You can define an alias and force the connection to using "name pipe" , there
> is an KB article on it..
> "Ram" wrote:
|||Thanks for reply. we already added local administrator group and SQL Server
security as a sys administrator group also. I can connect using SQL
Authetication but i can't connect using Windows authetication. I also Added
Client network utility alias also. still doesn't work.
Ram
"Olu Adedeji" wrote:
[vbcol=seagreen]
> Or you can add the sqlserver service account to 'impersonate a user after
> authentication' user rights assignment in security policy.
> "Anthony" wrote:
|||Hi Ram,
What operating system you have on computer from which you want to access SQL
server, is that computer member of workgroup or member of domain?
Regards,
Daniel
"Ram" <Ram@.discussions.microsoft.com> wrote in message
news:7B139AF7-E0E0-403F-B37D-96727A54F08E@.microsoft.com...
> Thanks for reply. we already added local administrator group and SQL
Server
> security as a sys administrator group also. I can connect using SQL
> Authetication but i can't connect using Windows authetication. I also
Added[vbcol=seagreen]
> Client network utility alias also. still doesn't work.
> Ram
> "Olu Adedeji" wrote:
after[vbcol=seagreen]
, there[vbcol=seagreen]
cannot[vbcol=seagreen]
Ent Mgr[vbcol=seagreen]
from there.[vbcol=seagreen]
error[vbcol=seagreen]
problem[vbcol=seagreen]
|||Hi Ram,
What operating system you have on computer from which you want to access SQL
server, is that computer member of workgroup or member of domain?
Regards,
Daniel
"Ram" <Ram@.discussions.microsoft.com> wrote in message
news:7B139AF7-E0E0-403F-B37D-96727A54F08E@.microsoft.com...
> Thanks for reply. we already added local administrator group and SQL
Server
> security as a sys administrator group also. I can connect using SQL
> Authetication but i can't connect using Windows authetication. I also
Added[vbcol=seagreen]
> Client network utility alias also. still doesn't work.
> Ram
> "Olu Adedeji" wrote:
after[vbcol=seagreen]
, there[vbcol=seagreen]
cannot[vbcol=seagreen]
Ent Mgr[vbcol=seagreen]
from there.[vbcol=seagreen]
error[vbcol=seagreen]
problem[vbcol=seagreen]
Cannot generate SSPI context on laptop from different domain
I have Domain A with several SQL servers installed. One WinXP Pro laptop
user reports that he can't connect to any SQL server instances using Windows
authentication (the servers run win2k3 OS SP1 with SQL 2000 sp4 & 2005 sp1)
and gets the error:
Cannot generate SSPI context. (.Net SqlClient Data Provider)
His laptop is unique in that it's part of another domain, Domain B which has
no trust relationship with Domain A, nor should it. When he is in the office
at Domain A, he logs in to his laptop using cached domain credentials for
Domain B,and has entered a Managed Network Password entry for the SQL server
s
in Domain A.
It appears that if I have him log into his laptop using a local account
rather than his domain account (from Domain B) the Managed Network Password
entry works and he can successfully connect to the SQL servers on Domain A.
Any suggestions on how I can get the Windows security token of the user
account to successfully connect to SQL Server in this situation where he is
using cached domain credentials (Domain B) with a Managed Network Password
(For Domain A). I would prefer not to make a trust between the domains while
still allowing him to connect to SQL using his existing laptop profile.
Thanks!Hi,
I understand that you would like to establish a connection from your laptop
computer in domain B to your SQL Server instance in domain A. The two
separated domains are non-trusted.
If I have misunderstood, please let me know.
As far as I know, if two separated domains have no trust relationship, any
one of the two domains could not connect to the other's SQL Server
instances with Windows Authentication by using its peer domain's user
account. To establish a connection, you can create a same local user
account with the same password on both of the computers which belong to the
two different domains. Cached domain account may have permission to access
the share resources in domain B; however it could not be used to connect to
SQL Server instance. That is not secure.
Appreciate your understanding on this limitation. If you have any other
questions or concerns, please feel free to let us know. Have a good day!
Best regards,
Charles Wang
Microsoft Online Community Support
========================================
=============
Get notification to my posts through email? Please refer to:
http://msdn.microsoft.com/subscript...ault.aspx#notif
ications
If you are using Outlook Express, please make sure you clear the check box
"Tools/Options/Read: Get 300 headers at a time" to see your reply promptly.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscript...t/default.aspx.
========================================
==============
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
========================================
==============
This posting is provided "AS IS" with no warranties, and confers no rights.
========================================
==============|||Hi,
I am interested in this issue. Would you mind letting me know the result of
the suggestions? If you need further assistance, feel free to let me know.
I will be more than happy to be of assistance.
Charles Wang
Microsoft Online Community Support
========================================
==============
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
========================================
==============
This posting is provided "AS IS" with no warranties, and confers no rights.
========================================
==============|||Hey Charles,
Thanks for the suggestion and explanation.
If I understand the workaround you suggest it's similar to the workaround I
implemented in that the user logs into his laptop using a local account
rather than his domain account (cached from Domain B), I then added a Manage
d
Network Password entry for a domain user account for the user in Domain A an
d
he can then successfully connect to the SQL servers on Domain A.
The problem is caused by the fact that the laptop is part of Domain B and
there is no trust relationship set up between the domains. I wanted to solve
the problem by getting the Managed Network Password entry to work while he i
s
logged in to his laptop with his domain account cached from Domain B.
However, I understand from your explanation that this is not feasible.
"Charles Wang[MSFT]" wrote:
> Hi,
> I am interested in this issue. Would you mind letting me know the result o
f
> the suggestions? If you need further assistance, feel free to let me know.
> I will be more than happy to be of assistance.
> Charles Wang
> Microsoft Online Community Support
> ========================================
==============
> When responding to posts, please "Reply to Group" via
> your newsreader so that others may learn and benefit
> from this issue.
> ========================================
==============
> This posting is provided "AS IS" with no warranties, and confers no rights
.
> ========================================
==============
>|||Hi Matt,
Thanks for your response.
Appreciate your understanding that this is a by design limitation. If it is
allowed, SQL Server may face many security issues. At least a simple
scenario that we can imagine is that any other users can use this cache
accout to attack SQL Server.
Your workaround is similar as my suggested workaround. Both of them are
safe, since any user who wants to use the user account to log in SQL Server
must know the correct password. For a cache account, we may just know its
user name, but do not know its password, so there may be potential security
problem if it is allowed to be used to connect to SQL Server.
Please feel free to let me know if you need further assistance on this
issue. Have a good day!
Best regards,
Charles Wang
Microsoft Online Community Support
========================================
=============
Get notification to my posts through email? Please refer to:
http://msdn.microsoft.com/subscript...ault.aspx#notif
ications
If you are using Outlook Express, please make sure you clear the check box
"Tools/Options/Read: Get 300 headers at a time" to see your reply promptly.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscript...t/default.aspx.
========================================
==============
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
========================================
==============
This posting is provided "AS IS" with no warranties, and confers no rights.
========================================
==============
Cannot generate SSPI context on laptop from different domain
I have Domain A with several SQL servers installed. One WinXP Pro laptop
user reports that he can't connect to any SQL server instances using Windows
authentication (the servers run win2k3 OS SP1 with SQL 2000 sp4 & 2005 sp1)
and gets the error:
Cannot generate SSPI context. (.Net SqlClient Data Provider)
His laptop is unique in that it's part of another domain, Domain B which has
no trust relationship with Domain A, nor should it. When he is in the office
at Domain A, he logs in to his laptop using cached domain credentials for
Domain B,and has entered a Managed Network Password entry for the SQL servers
in Domain A.
It appears that if I have him log into his laptop using a local account
rather than his domain account (from Domain B) the Managed Network Password
entry works and he can successfully connect to the SQL servers on Domain A.
Any suggestions on how I can get the Windows security token of the user
account to successfully connect to SQL Server in this situation where he is
using cached domain credentials (Domain B) with a Managed Network Password
(For Domain A). I would prefer not to make a trust between the domains while
still allowing him to connect to SQL using his existing laptop profile.
Thanks!
Hi,
I understand that you would like to establish a connection from your laptop
computer in domain B to your SQL Server instance in domain A. The two
separated domains are non-trusted.
If I have misunderstood, please let me know.
As far as I know, if two separated domains have no trust relationship, any
one of the two domains could not connect to the other's SQL Server
instances with Windows Authentication by using its peer domain's user
account. To establish a connection, you can create a same local user
account with the same password on both of the computers which belong to the
two different domains. Cached domain account may have permission to access
the share resources in domain B; however it could not be used to connect to
SQL Server instance. That is not secure.
Appreciate your understanding on this limitation. If you have any other
questions or concerns, please feel free to let us know. Have a good day!
Best regards,
Charles Wang
Microsoft Online Community Support
================================================== ===
Get notification to my posts through email? Please refer to:
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications
If you are using Outlook Express, please make sure you clear the check box
"Tools/Options/Read: Get 300 headers at a time" to see your reply promptly.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscriptions/support/default.aspx.
================================================== ====
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
================================================== ====
This posting is provided "AS IS" with no warranties, and confers no rights.
================================================== ====
|||Hi,
I am interested in this issue. Would you mind letting me know the result of
the suggestions? If you need further assistance, feel free to let me know.
I will be more than happy to be of assistance.
Charles Wang
Microsoft Online Community Support
================================================== ====
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
================================================== ====
This posting is provided "AS IS" with no warranties, and confers no rights.
================================================== ====
|||Hey Charles,
Thanks for the suggestion and explanation.
If I understand the workaround you suggest it's similar to the workaround I
implemented in that the user logs into his laptop using a local account
rather than his domain account (cached from Domain B), I then added a Managed
Network Password entry for a domain user account for the user in Domain A and
he can then successfully connect to the SQL servers on Domain A.
The problem is caused by the fact that the laptop is part of Domain B and
there is no trust relationship set up between the domains. I wanted to solve
the problem by getting the Managed Network Password entry to work while he is
logged in to his laptop with his domain account cached from Domain B.
However, I understand from your explanation that this is not feasible.
"Charles Wang[MSFT]" wrote:
> Hi,
> I am interested in this issue. Would you mind letting me know the result of
> the suggestions? If you need further assistance, feel free to let me know.
> I will be more than happy to be of assistance.
> Charles Wang
> Microsoft Online Community Support
> ================================================== ====
> When responding to posts, please "Reply to Group" via
> your newsreader so that others may learn and benefit
> from this issue.
> ================================================== ====
> This posting is provided "AS IS" with no warranties, and confers no rights.
> ================================================== ====
>
|||Hi Matt,
Thanks for your response.
Appreciate your understanding that this is a by design limitation. If it is
allowed, SQL Server may face many security issues. At least a simple
scenario that we can imagine is that any other users can use this cache
accout to attack SQL Server.
Your workaround is similar as my suggested workaround. Both of them are
safe, since any user who wants to use the user account to log in SQL Server
must know the correct password. For a cache account, we may just know its
user name, but do not know its password, so there may be potential security
problem if it is allowed to be used to connect to SQL Server.
Please feel free to let me know if you need further assistance on this
issue. Have a good day!
Best regards,
Charles Wang
Microsoft Online Community Support
================================================== ===
Get notification to my posts through email? Please refer to:
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications
If you are using Outlook Express, please make sure you clear the check box
"Tools/Options/Read: Get 300 headers at a time" to see your reply promptly.
Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscriptions/support/default.aspx.
================================================== ====
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from this issue.
================================================== ====
This posting is provided "AS IS" with no warranties, and confers no rights.
================================================== ====
Sunday, February 12, 2012
Cannot generate SSPI context
Im having trouble connecting to the SQL2005 default instance installed on
one of my sql servers within my domain. I have a second SQL2005 server that
I
can connect to just fine. Both are in the same OU.
This particular server, I can connect to AS2005, but not to SQL2005. I keep
getting the 'Cannot generate SSPI context. (.Net SqlClient Data Provider)'
error. I've not changed anything in terms of settings on my PC, nor have any
settings been changed on the SQL server, though I was able to connect to
SQL2005 for this server last week. Something obviously has changed, but I
have no idea where to look. One of the other SysAdmins has no problems
connecting to the database.
I'm hoping this is just something simple to fix.
regards,
AnatoliAll the below is happening while I'm attempting to connect remotely from my
XP SP2 pc using SSMS.
Further to this, I've found that I can connect to the server in question
remotely using the SA account. I can also, connect to SQL2005 locally with m
y
network account from within an RDP session.
"Anatoli" wrote:
> Hi,
> Im having trouble connecting to the SQL2005 default instance installed on
> one of my sql servers within my domain. I have a second SQL2005 server tha
t I
> can connect to just fine. Both are in the same OU.
> This particular server, I can connect to AS2005, but not to SQL2005. I kee
p
> getting the 'Cannot generate SSPI context. (.Net SqlClient Data Provider)'
> error. I've not changed anything in terms of settings on my PC, nor have a
ny
> settings been changed on the SQL server, though I was able to connect to
> SQL2005 for this server last week. Something obviously has changed, but I
> have no idea where to look. One of the other SysAdmins has no problems
> connecting to the database.
> I'm hoping this is just something simple to fix.
> regards,
> Anatoli|||Anatoli,
check these links.
http://support.microsoft.com/kb/811889/
http://msdn2.microsoft.com/en-us/library/ms191153.aspx
http://msdn2.microsoft.com/en-us/library/ms189585.aspx
Hope this helps
Markus|||Markus,
Thanks for your reply. From what I can tell, this problem is specific to my
domain account. That is that I can connect remotely to the SQL server using
the SA account, but I can't connect using my domain account. I tried using
another PC from which one of other admins was able to easily connect to
SQL2005. I don't use a roaming profile, and this was the first time I logged
onto that PC and still I got the same error. Again, when I logged in locally
to the SQL server I didn't have any problems SSMS connecting.
So from what I can tell, there aren't any setting issues on the SQL server
side nor are there any issues from my PC side as I'm able to connect to othe
r
instances of SQL 2005 with my domain account.
Are there any settings associated with the login to cause such an error?
"MarkusB" wrote:
> Anatoli,
> check these links.
> http://support.microsoft.com/kb/811889/
> http://msdn2.microsoft.com/en-us/library/ms191153.aspx
> http://msdn2.microsoft.com/en-us/library/ms189585.aspx
> Hope this helps
> Markus
>|||Turned out to be how the system guys upgraded the server to W2K3, SQL and AS
2005. They blew away the old sql server and installed W2K3, SQL/AS 2005, but
never removed the computer object out of AD. Used the SETSPN.exe utility
determine that there was more than one SPN for that particular server.
regards,
"Anatoli" wrote:
[vbcol=seagreen]
> Markus,
> Thanks for your reply. From what I can tell, this problem is specific to m
y
> domain account. That is that I can connect remotely to the SQL server usin
g
> the SA account, but I can't connect using my domain account. I tried using
> another PC from which one of other admins was able to easily connect to
> SQL2005. I don't use a roaming profile, and this was the first time I logg
ed
> onto that PC and still I got the same error. Again, when I logged in local
ly
> to the SQL server I didn't have any problems SSMS connecting.
> So from what I can tell, there aren't any setting issues on the SQL server
> side nor are there any issues from my PC side as I'm able to connect to ot
her
> instances of SQL 2005 with my domain account.
> Are there any settings associated with the login to cause such an error?
> "MarkusB" wrote:
>
Cannot generate SSPI context
Im having trouble connecting to the SQL2005 default instance installed on
one of my sql servers within my domain. I have a second SQL2005 server that I
can connect to just fine. Both are in the same OU.
This particular server, I can connect to AS2005, but not to SQL2005. I keep
getting the 'Cannot generate SSPI context. (.Net SqlClient Data Provider)'
error. I've not changed anything in terms of settings on my PC, nor have any
settings been changed on the SQL server, though I was able to connect to
SQL2005 for this server last week. Something obviously has changed, but I
have no idea where to look. One of the other SysAdmins has no problems
connecting to the database.
I'm hoping this is just something simple to fix.
regards,
AnatoliAll the below is happening while I'm attempting to connect remotely from my
XP SP2 pc using SSMS.
Further to this, I've found that I can connect to the server in question
remotely using the SA account. I can also, connect to SQL2005 locally with my
network account from within an RDP session.
"Anatoli" wrote:
> Hi,
> Im having trouble connecting to the SQL2005 default instance installed on
> one of my sql servers within my domain. I have a second SQL2005 server that I
> can connect to just fine. Both are in the same OU.
> This particular server, I can connect to AS2005, but not to SQL2005. I keep
> getting the 'Cannot generate SSPI context. (.Net SqlClient Data Provider)'
> error. I've not changed anything in terms of settings on my PC, nor have any
> settings been changed on the SQL server, though I was able to connect to
> SQL2005 for this server last week. Something obviously has changed, but I
> have no idea where to look. One of the other SysAdmins has no problems
> connecting to the database.
> I'm hoping this is just something simple to fix.
> regards,
> Anatoli|||Anatoli,
check these links.
http://support.microsoft.com/kb/811889/
http://msdn2.microsoft.com/en-us/library/ms191153.aspx
http://msdn2.microsoft.com/en-us/library/ms189585.aspx
Hope this helps
Markus|||Markus,
Thanks for your reply. From what I can tell, this problem is specific to my
domain account. That is that I can connect remotely to the SQL server using
the SA account, but I can't connect using my domain account. I tried using
another PC from which one of other admins was able to easily connect to
SQL2005. I don't use a roaming profile, and this was the first time I logged
onto that PC and still I got the same error. Again, when I logged in locally
to the SQL server I didn't have any problems SSMS connecting.
So from what I can tell, there aren't any setting issues on the SQL server
side nor are there any issues from my PC side as I'm able to connect to other
instances of SQL 2005 with my domain account.
Are there any settings associated with the login to cause such an error?
"MarkusB" wrote:
> Anatoli,
> check these links.
> http://support.microsoft.com/kb/811889/
> http://msdn2.microsoft.com/en-us/library/ms191153.aspx
> http://msdn2.microsoft.com/en-us/library/ms189585.aspx
> Hope this helps
> Markus
>|||Turned out to be how the system guys upgraded the server to W2K3, SQL and AS
2005. They blew away the old sql server and installed W2K3, SQL/AS 2005, but
never removed the computer object out of AD. Used the SETSPN.exe utility
determine that there was more than one SPN for that particular server.
regards,
"Anatoli" wrote:
> Markus,
> Thanks for your reply. From what I can tell, this problem is specific to my
> domain account. That is that I can connect remotely to the SQL server using
> the SA account, but I can't connect using my domain account. I tried using
> another PC from which one of other admins was able to easily connect to
> SQL2005. I don't use a roaming profile, and this was the first time I logged
> onto that PC and still I got the same error. Again, when I logged in locally
> to the SQL server I didn't have any problems SSMS connecting.
> So from what I can tell, there aren't any setting issues on the SQL server
> side nor are there any issues from my PC side as I'm able to connect to other
> instances of SQL 2005 with my domain account.
> Are there any settings associated with the login to cause such an error?
> "MarkusB" wrote:
> > Anatoli,
> >
> > check these links.
> > http://support.microsoft.com/kb/811889/
> >
> > http://msdn2.microsoft.com/en-us/library/ms191153.aspx
> > http://msdn2.microsoft.com/en-us/library/ms189585.aspx
> >
> > Hope this helps
> >
> > Markus
> >
> >