Showing posts with label windows. Show all posts
Showing posts with label windows. Show all posts

Thursday, March 29, 2012

Performance prolem when deploying

Hi,

We have a quite simple asp.net application that works fne on my XP
development box. When we deploy it to a Windows 2003 Server performance is
really poor when rendering pages. When I turn tracing on it shows that it
takes more than 15 seconds between "Begin Render" and "End Render". All
application logic is in OnLoad which takes less than 0,1 seconds to complete
on both machines. The weird thing is that if we request this page locally
(from the server box) it takes 0,1 seconds. Authentication is Anonymous and
we don't find any errors anywhere. The statusline text in IE is flickering
while the request is being processed.

So, the question is: How come the times varies depending on where the
request comes from? It must be security related somehow but I can't figure
it out.

Thanks !

Mansyou probably have a large payload whose impact only shows up with a network
request. check how big your viewstate is. if you use netscape, check page
info, if ie, save the page to disk, and check the file size.

-- bruce (sqlwork.com)

"Mans" <mans@.nomail.com> wrote in message
news:uQLgeta5DHA.2496@.TK2MSFTNGP09.phx.gbl...
> Hi,
> We have a quite simple asp.net application that works fne on my XP
> development box. When we deploy it to a Windows 2003 Server performance is
> really poor when rendering pages. When I turn tracing on it shows that it
> takes more than 15 seconds between "Begin Render" and "End Render". All
> application logic is in OnLoad which takes less than 0,1 seconds to
complete
> on both machines. The weird thing is that if we request this page locally
> (from the server box) it takes 0,1 seconds. Authentication is Anonymous
and
> we don't find any errors anywhere. The statusline text in IE is flickering
> while the request is being processed.
> So, the question is: How come the times varies depending on where the
> request comes from? It must be security related somehow but I can't figure
> it out.
> Thanks !
> Mans
There are also some useful tools that let you see what is going on between
your browser and the server. The best is http://www.httpwatch.com/ . There's
also http://www.blunck.info/iehttpheaders.html

If it is the size of the output that is the problem then look at optimising
it - removing viewstate if you aren't using it etc... You can also reduce
the size with Http Compression - http://www.intesoft.net/aspaccelerator/

- Simon Green
InteSoft IT Ltd

"bruce barker" <nospam_brubar@.safeco.com> wrote in message
news:eQZuARd5DHA.632@.TK2MSFTNGP12.phx.gbl...
> you probably have a large payload whose impact only shows up with a
network
> request. check how big your viewstate is. if you use netscape, check page
> info, if ie, save the page to disk, and check the file size.
> -- bruce (sqlwork.com)
>
> "Mans" <mans@.nomail.com> wrote in message
> news:uQLgeta5DHA.2496@.TK2MSFTNGP09.phx.gbl...
> > Hi,
> > We have a quite simple asp.net application that works fne on my XP
> > development box. When we deploy it to a Windows 2003 Server performance
is
> > really poor when rendering pages. When I turn tracing on it shows that
it
> > takes more than 15 seconds between "Begin Render" and "End Render". All
> > application logic is in OnLoad which takes less than 0,1 seconds to
> complete
> > on both machines. The weird thing is that if we request this page
locally
> > (from the server box) it takes 0,1 seconds. Authentication is Anonymous
> and
> > we don't find any errors anywhere. The statusline text in IE is
flickering
> > while the request is being processed.
> > So, the question is: How come the times varies depending on where the
> > request comes from? It must be security related somehow but I can't
figure
> > it out.
> > Thanks !
> > Mans
Hi...

Do you have used any client side implementation in the code behind pages..

As you have written there is flickering in the status bar, there is is some
kind to and from from server to browser before rendering the html..

Can you spcify some portion of the first aspx page....

"Mans" <mans@.nomail.com> wrote in message
news:uQLgeta5DHA.2496@.TK2MSFTNGP09.phx.gbl...
> Hi,
> We have a quite simple asp.net application that works fne on my XP
> development box. When we deploy it to a Windows 2003 Server performance is
> really poor when rendering pages. When I turn tracing on it shows that it
> takes more than 15 seconds between "Begin Render" and "End Render". All
> application logic is in OnLoad which takes less than 0,1 seconds to
complete
> on both machines. The weird thing is that if we request this page locally
> (from the server box) it takes 0,1 seconds. Authentication is Anonymous
and
> we don't find any errors anywhere. The statusline text in IE is flickering
> while the request is being processed.
> So, the question is: How come the times varies depending on where the
> request comes from? It must be security related somehow but I can't figure
> it out.
> Thanks !
> Mans

Saturday, March 24, 2012

Permission Denied Writing to a file

I'm getting a 'permission denied' error when I try to write to a file. I'm running Windows XP Professions, FAT32, and I've set the aspnet user to be an administrator. And I still get this error. I know it's not that the folder doesn't exist, because if I change the path to one that doesn't exist I get the appropriate error that it doesn't exist.

Help.

buzzWow! I hope this server is not exposed to the Internet in any way.
First, you should use NTFS and not FAT32 (there are no permissions on FAT32 disks).
And making ASPNET an administrator is something you should never do. You could edit the machine.config file instead and make the process use SYSTEM instead of ASPNET. I don't even recommend doing this, and you should really just give enough rights on the directories to ASPNET so that you can write to your file.
Does this help?
I'm just in development on my desktop for now, which is why it's FAT32, and the only reason why I made the ASPNET account an admin was to troubleshoot my permission denied error. That's why I mentioned it, because even with it being an admin I'm still getting this error.
You should use NTFS on your dev machines too. I doubt that you will be able to sort this one out except if you use NTFS. I haven't checked this, but I wouldn't be surprised if we used low permissions by default if the file system is Fat, as there are no permissions on this file system.
And 'low permissions' means no write permission, ever, anywhere? That would be remarkably restrictive, wouldn't it? Aren't there some IIS settings I can look at? I also went into my app in IIS and gave write permission in there and that didn't work either.

Thanks for your input.

buzz
Once again, I'm not sure about that at all.
But usually, a web site has no need to write files.
And it would be incredibly dangerous to allow writing to an unprotected file system by default.
I strongly recommend you use NTFS in all circumstances. Fat32 is only there for Win9x compatibility.
I see, well I'll look into converting to NTFS.

>> But usually, a web site has no need to write files.

Is this true? I'm not an expert, but what about uploading files, etc? Also, I want to write to a file for logging purposes, for when my database goes down.

Thanks for all your help!

buzz
Yes, that's why I said "usually".
Most sites don't need to upload files. And if you upload, you should do so in a directory that's not acessible from the web, for obvious security reasons, whenever possible. And you should always require reliable authentication when you allow for it.
Logging can be done using the System.Diagnostics namespace, using the standard Windows event logs.

Permission Failures with an embedded windows form. What’s the proper way to do this?

I have a windows web form control that opens up a serial port. When I try to embed it an HTML file, I get a securityException when it opens the port. --System.Security.SecurityException: Request for permission of type System.Security.Permissions.SecurityPermission, mscorlib,.......

1) Is there any way I can just tell the browser to trust this object, or just completely trust anything and everything from a certain web site?

2) Right now I had the DLL download from the server when the page loads. It is quite small so speed isn't an issue, I like the concept of downloading it everytime it is used because it will be easier to keep updated. But in terms of permission I was wondering if the proper way may be to install it as a plug in or addon?

The syntax I currently use is :

<object id="SIOControl1"classid="http:SIOControl.dll#SIOControl.SIOTestControl" height="500" width="500" VIEWASTEXT>

You cant programatically "tell" the browser to just trust it, nor can you tell the browser to trust everything from a specific site, not from your application. Imagine the huge security hole that would be. What you CAN do is as the "user" of said site:

Through Internet Options > Sites > Trusted Sites:

Add the address of your website to the trusted sites section. Then set the security of that "zone" to match what you need to accomplish what you're after.


I don't think the solution is as simple as adding it to a trusted site. Just for testing purposes I did that, and set all IE secuirty options and it still dosn't work.

I've tried to add FullTrust to the site with caspol, but to tell you the truth, I just can seem to figure out the proper command.

I've tried: caspol -addgroup LocalIntranet -urlhttp://localhost/SIOControl/* FullTrust

but it tells me that I have an Invalid Label or name, but when I do a caspol -lg I see LocalIntranet there?

Permissions - giving "everyone" full permissions is bad ?

Hi all,
I have developed an ASP.NET application, on my Windows XP using visual studi
o 2003 professional.
Now I want to deploy this app to a windows 2003 web edition server, so my cu
stomers can test the app.
I have prepared a new site on the windows 2003 server, and copied all files
over to this server.
It works perfectly, but when my app tries to create / write to a TXT file, i
t throws an "System.UnauthorizedAccessException" exception. If I test ASPX f
iles which does not try to create a TXT file, I get no exception.
So I go into the properties for the dir where this TXT file is, and adds ASP
NET user and gives it "modify" permissions - no luck!
I then do the same with the "IUSR_<machine>" user - no luck!
Finally, in total desperation, I add the "Everyone" user and gives it FULL a
ccess, and then my ASP.NET application works ...
My question is now :
1) How do I setup the right permissions ? I cannot be true, that I need to a
dd full permissions to the "Everyone" user account ...
Am I missing something here ? Please help me ...
Regards,
Tony Fonager, DenmarkHi Tony:
One of the best ways to debug an issue like this is to turn on
auditing for objects and then get a log of exactly who is being denied
permission.
For some more information see:
http://odetocode.com/Blogs/scott/ar.../06/22/283.aspx
Scott
http://www.OdeToCode.com
On Tue, 13 Jul 2004 12:58:02 -0700, Tony Fonager
<fonager@.newsgroups.nospam> wrote:

>Hi all,
>I have developed an ASP.NET application, on my Windows XP using visual stud
io 2003 professional.
>Now I want to deploy this app to a windows 2003 web edition server, so my c
ustomers can test the app.
>I have prepared a new site on the windows 2003 server, and copied all files
over to this server.
>It works perfectly, but when my app tries to create / write to a TXT file,
it throws an "System.UnauthorizedAccessException" exception. If I test ASPX
files which does not try to create a TXT file, I get no exception.
>So I go into the properties for the dir where this TXT file is, and adds AS
PNET user and gives it "modify" permissions - no luck!
>I then do the same with the "IUSR_<machine>" user - no luck!
>Finally, in total desperation, I add the "Everyone" user and gives it FULL
access, and then my ASP.NET application works ...
>My question is now :
>1) How do I setup the right permissions ? I cannot be true, that I need to
add full permissions to the "Everyone" user account ...
>Am I missing something here ? Please help me ...
>
>Regards,
>Tony Fonager, Denmark
Oh, forgot to mention, I think what you'll find on your 2003 server is
that the NETWORK SERVICE account will be the context trying to write
to the file.
--s
On Tue, 13 Jul 2004 12:58:02 -0700, Tony Fonager
<fonager@.newsgroups.nospam> wrote:

>Hi all,
>I have developed an ASP.NET application, on my Windows XP using visual stud
io 2003 professional.
>Now I want to deploy this app to a windows 2003 web edition server, so my c
ustomers can test the app.
>I have prepared a new site on the windows 2003 server, and copied all files
over to this server.
>It works perfectly, but when my app tries to create / write to a TXT file,
it throws an "System.UnauthorizedAccessException" exception. If I test ASPX
files which does not try to create a TXT file, I get no exception.
>So I go into the properties for the dir where this TXT file is, and adds AS
PNET user and gives it "modify" permissions - no luck!
>I then do the same with the "IUSR_<machine>" user - no luck!
>Finally, in total desperation, I add the "Everyone" user and gives it FULL
access, and then my ASP.NET application works ...
>My question is now :
>1) How do I setup the right permissions ? I cannot be true, that I need to
add full permissions to the "Everyone" user account ...
>Am I missing something here ? Please help me ...
>
>Regards,
>Tony Fonager, Denmark
Scott
http://www.OdeToCode.com
Scott,
That was exactly the account I needed to change permissions for - thanks alo
t, now I can control permissions, and I just tested it with success.
And thanks for at FAST reply :-)
-
Tony Fonager
"Scott Allen" wrote:

> Oh, forgot to mention, I think what you'll find on your 2003 server is
> that the NETWORK SERVICE account will be the context trying to write
> to the file.
> --s
> On Tue, 13 Jul 2004 12:58:02 -0700, Tony Fonager
> <fonager@.newsgroups.nospam> wrote:
>
> --
> Scott
> http://www.OdeToCode.com
>

Wednesday, March 21, 2012

Permissions Problem

I am running Windows XP Home edition with a Cassini server, usingDreamweaver MX 2004. Im just running Cassini as a local server,so I can test my web sites, but I have a problem. When I create adatabase and try to test it, it doesn't work. I get a 403 errorforbidden, I am the only user on my computer and I am administator, soI should have full permissions, but I guess I don't. When I gointo properties under my website folder, there is no security tab, Imguessing because Im the only user. So now Im lost on what to do,any suggestions?
Can you please let me know which database you are using (though I'm guessing you mean Access)? I will then move your message to the relevant database forum.

Yeah, sorry not to include that, Im using access.

I don't think this has anything to do with the database per se. A403 error means the web server is denying access to the page it isbeing requested to serve. I'd check folder permissions.

There are no permissions on my folder, the security tab isnt eventhere. I think its because I am the only user on my computer, soeverything should have full permissions.

Skerb wrote:

There are no permissions on my folder, the security tab isnt even there. I think its because I am the only user on my computer, so everything should have full permissions.

The reason that you do not have the Security tab is that you are using Windows XP Home. In this operating system, Simple File Sharing is always enabled, which means that you will never see the Security tab (at least, according to MSDN).
May I ask that you copy (not move) your .mdb database file into the same folder as your .aspx page. In your .aspx page (or web.config), update the connection string to point to this new version of your Access database. Thismay be a simple solution to your permissions problem.
The web pages, database, and web.config are already in the same folderSad [:(]

Permissions to create asp.net site

Hi.

I am creating an asp.net application using Windows 2000 Server and
VS.NET 2002. My account is part of the administrators group. I need to
share this machine with another developer. What permissions should I
give to his account in order he can successfuly create asp.net
applications, without being an administrator?

Thanks,
Robert ScheerI never run as an admin on my development box. (You should stop running as
an admin yourself.) The trickiest part to get set up is debugging. Set the
user up as a debugger user. Also, you need to run the aspnet_wp process
using the credentials of the person who is using it to get full debugging -
you can edit this directly in machine.config, and you should also
investigate the aspnet_setreg utility to encrypt these credentials so you
don't have them just sitting in plain text. I have no problems with this
configuration creating and editing asp.net applications.

--
Chris Jackson
Software Engineer
Microsoft MVP - Windows Client
Windows XP Associate Expert
--
More people read the newsgroups than read my email.
Reply to the newsgroup for a faster response.
(Control-G using Outlook Express)
--

"Robert Scheer" <rbscheer@.my-deja.com> wrote in message
news:cfd22ab6.0312011803.6ffa9ccd@.posting.google.c om...
> Hi.
> I am creating an asp.net application using Windows 2000 Server and
> VS.NET 2002. My account is part of the administrators group. I need to
> share this machine with another developer. What permissions should I
> give to his account in order he can successfuly create asp.net
> applications, without being an administrator?
> Thanks,
> Robert Scheer
Hi Chris.

What problems can I find as an administrator when developing on my .net machine?

Thanks,
Robert Scheer

"Chris Jackson" <chrisjATmvpsDOTorgNOSPAM> wrote in message news:<e03UkKPuDHA.1740@.TK2MSFTNGP12.phx.gbl>...
> I never run as an admin on my development box. (You should stop running as
> an admin yourself.) The trickiest part to get set up is debugging. Set the
> user up as a debugger user. Also, you need to run the aspnet_wp process
> using the credentials of the person who is using it to get full debugging -
> you can edit this directly in machine.config, and you should also
> investigate the aspnet_setreg utility to encrypt these credentials so you
> don't have them just sitting in plain text. I have no problems with this
> configuration creating and editing asp.net applications.
> --
> Chris Jackson
> Software Engineer
> Microsoft MVP - Windows Client
> Windows XP Associate Expert
> --
> More people read the newsgroups than read my email.
> Reply to the newsgroup for a faster response.
> (Control-G using Outlook Express)
> --
> "Robert Scheer" <rbscheer@.my-deja.com> wrote in message
> news:cfd22ab6.0312011803.6ffa9ccd@.posting.google.c om...
> > Hi.
> > I am creating an asp.net application using Windows 2000 Server and
> > VS.NET 2002. My account is part of the administrators group. I need to
> > share this machine with another developer. What permissions should I
> > give to his account in order he can successfuly create asp.net
> > applications, without being an administrator?
> > Thanks,
> > Robert Scheer

Permissions to Sql2005 database from IIS

Hi everyone, hope your all looking forward to xmas.
I am setting up a Sql2005 database on a Windows Server, running Windows
Server 2003. The database is going to be accessed via users using an
ASP.Net website.
My website is running the normal IUSR account. And users must login to
the website, which uses Forms Authentication.
I do not want to give users access directly to tables, so have created
many stored procedures which will carry out the operations that i would
like users to be able to do.
I do not want to use Sql Authentication.
How should i setup permissions on my database?
At the moment i have set up the NETWORK SERVICE account (account for
running asp.net) on my server to be a role member of the db_owner group
for the database. This allows the user access to all the object in my
database, as everything is owned by dbo.
Is this correct? This doesnt sound right to me? Do i have to setup
another user in my Sql database?IM new to SQL 2005 as well, but Im working through the implementation and
Maintainence book and it expplicitly tells you not to user the Network
Service account because it has too many privilages. It reccomends setting up
a new account to manage each instance.
"Nemisis" <darrens2005@.hotmail.com> wrote in message
news:1166537606.961583.187640@.a3g2000cwd.googlegroups.com...
> Hi everyone, hope your all looking forward to xmas.
> I am setting up a Sql2005 database on a Windows Server, running Windows
> Server 2003. The database is going to be accessed via users using an
> ASP.Net website.
> My website is running the normal IUSR account. And users must login to
> the website, which uses Forms Authentication.
> I do not want to give users access directly to tables, so have created
> many stored procedures which will carry out the operations that i would
> like users to be able to do.
> I do not want to use Sql Authentication.
> How should i setup permissions on my database?
> At the moment i have set up the NETWORK SERVICE account (account for
> running asp.net) on my server to be a role member of the db_owner group
> for the database. This allows the user access to all the object in my
> database, as everything is owned by dbo.
> Is this correct? This doesnt sound right to me? Do i have to setup
> another user in my Sql database?
>
Hi nemesis.
Is you database server & Web Server located on the same machine?
If yes
You could create a local (technical) user account & have the application
run under an application pool with the technical user account.
On the DB level , just create the login & user account and grant execute
on the stored procedure.
If No
instead of a local (technical) user account have a domain account made.
the rest of the setup is just the same.
As a side note , never have any application account part of db_owner ,
this means the app. could just drop all tables in your DB .
Yvesl
Nemisis wrote:
Nemisis wrote:
> Hi everyone, hope your all looking forward to xmas.
> I am setting up a Sql2005 database on a Windows Server, running Windows
> Server 2003. The database is going to be accessed via users using an
> ASP.Net website.
> My website is running the normal IUSR account. And users must login to
> the website, which uses Forms Authentication.
> I do not want to give users access directly to tables, so have created
> many stored procedures which will carry out the operations that i would
> like users to be able to do.
> I do not want to use Sql Authentication.
> How should i setup permissions on my database?
> At the moment i have set up the NETWORK SERVICE account (account for
> running asp.net) on my server to be a role member of the db_owner group
> for the database. This allows the user access to all the object in my
> database, as everything is owned by dbo.
> Is this correct? This doesnt sound right to me? Do i have to setup
> another user in my Sql database?
> Hi everyone, hope your all looking forward to xmas.
> I am setting up a Sql2005 database on a Windows Server, running Windows
> Server 2003. The database is going to be accessed via users using an
> ASP.Net website.
> My website is running the normal IUSR account. And users must login to
> the website, which uses Forms Authentication.
> I do not want to give users access directly to tables, so have created
> many stored procedures which will carry out the operations that i would
> like users to be able to do.
> I do not want to use Sql Authentication.
> How should i setup permissions on my database?
> At the moment i have set up the NETWORK SERVICE account (account for
> running asp.net) on my server to be a role member of the db_owner group
> for the database. This allows the user access to all the object in my
> database, as everything is owned by dbo.
> Is this correct? This doesnt sound right to me? Do i have to setup
> another user in my Sql database?
>
Thanks alot for this, my database server and web server are on the same
machine.
I will try to setup a account and set the correct permission first
thing in the morning.
The new account that i will setup, does it need access to the tables?
Because before when i tried to execute a stored procedure, it said that
select permissions had to be set on the table as well. Is this still
the case'
Should the new account be apart of a role in the database? Or should i
created my own?
Thanks again for your help so far.
Hi,
Assuming you're only using stored procedure your new user (lets call him
LOCALSERVER\TEST) does not need any access to the tables.
It needs EXECUTE right to the stored procedures.
here's the script to grant access.
GRANT EXECUTE ON [dbo].[AddSp] TO [LOCALSERVER\TEST]
GRANT EXECUTE ON [dbo].[GetSp] TO [LOCALSERVER\TEST]
For Role Membership, well it all depends on what your requirements are.
For more informed help you should probably ask this newsgroup:
microsoft.public.sqlserver.server
however my 2c:
Since your Database will be accessed only through 1 user account( the
one that your web app. runs under) I don't think it's necessary to
create any Role.
YvesL
Nemisis wrote:
> Thanks alot for this, my database server and web server are on the same
> machine.
> I will try to setup a account and set the correct permission first
> thing in the morning.
> The new account that i will setup, does it need access to the tables?
> Because before when i tried to execute a stored procedure, it said that
> select permissions had to be set on the table as well. Is this still
> the case'
> Should the new account be apart of a role in the database? Or should i
> created my own?
> Thanks again for your help so far.
>
Yves. L. wrote:
> Hi,
> Assuming you're only using stored procedure your new user (lets call him
> LOCALSERVER\TEST) does not need any access to the tables.
> It needs EXECUTE right to the stored procedures.
> here's the script to grant access.
> GRANT EXECUTE ON [dbo].[AddSp] TO [LOCALSERVER\TEST]
> GRANT EXECUTE ON [dbo].[GetSp] TO [LOCALSERVER\TEST]
>
> For Role Membership, well it all depends on what your requirements are.
> For more informed help you should probably ask this newsgroup:
> microsoft.public.sqlserver.server
> however my 2=80c:
> Since your Database will be accessed only through 1 user account( the
> one that your web app. runs under) I don't think it's necessary to
> create any Role.
> YvesL
Yves,
What about if i need to run dynamic Sql? Will this still be ok? I
hear that there are some problems when running dynamic Sql?
>
> Yves,
> What about if i need to run dynamic Sql? Will this still be ok? I
> hear that there are some problems when running dynamic Sql?
>
I suppose that you mean SQL statements in code ?
Then you'll need to set the proper permission on the necessary tables,
views, etc,... or make your user part of the db_datawriter or
db_datareader roles (see the docs for reference).
Anyway, you wrote earlier that you have SP'for all data access, so you
should be fine .
Regards,
YvesL
Yes the users only execute stored procedures, but within some of the
stored procedures, i execute dynamic Sql, using the execute_sql system
stored procedure.
I was told that it was not a good idea to make a user apart of the
db_owner role, is making them a part of the db_datareader and
db_datawriter role ok?
I am using Sql2005, so does this still apply? I didnt know if i should
do something different for Sql2005?
Thanks
> Yes the users only execute stored procedures, but within some of the
> stored procedures, i execute dynamic Sql, using the execute_sql system
> stored procedure.
I don't know about that, you'll have to try it out or ask the sqlserver
newsgroup.

> I was told that it was not a good idea to make a user apart of the
> db_owner role, is making them a part of the db_datareader and
> db_datawriter role ok?
Have a look at
ms-help://MS.VSCC.v80/MS.VSIPCC.v80/MS.SQLSVR.v9.en/udb9/html/7f3fa5f6-6b50-
43bb-9047-1544ade55e39.htm
it describes what access users get for those database roles
Regards,
YvesL

Permissions to Sql2005 database from IIS

Hi everyone, hope your all looking forward to xmas.

I am setting up a Sql2005 database on a Windows Server, running Windows
Server 2003. The database is going to be accessed via users using an
ASP.Net website.

My website is running the normal IUSR account. And users must login to
the website, which uses Forms Authentication.

I do not want to give users access directly to tables, so have created
many stored procedures which will carry out the operations that i would
like users to be able to do.

I do not want to use Sql Authentication.

How should i setup permissions on my database?

At the moment i have set up the NETWORK SERVICE account (account for
running asp.net) on my server to be a role member of the db_owner group
for the database. This allows the user access to all the object in my
database, as everything is owned by dbo.

Is this correct? This doesnt sound right to me? Do i have to setup
another user in my Sql database?IM new to SQL 2005 as well, but Im working through the implementation and
Maintainence book and it expplicitly tells you not to user the Network
Service account because it has too many privilages. It reccomends setting up
a new account to manage each instance.

"Nemisis" <darrens2005@.hotmail.comwrote in message
news:1166537606.961583.187640@.a3g2000cwd.googlegro ups.com...

Quote:

Originally Posted by

Hi everyone, hope your all looking forward to xmas.
>
I am setting up a Sql2005 database on a Windows Server, running Windows
Server 2003. The database is going to be accessed via users using an
ASP.Net website.
>
My website is running the normal IUSR account. And users must login to
the website, which uses Forms Authentication.
>
I do not want to give users access directly to tables, so have created
many stored procedures which will carry out the operations that i would
like users to be able to do.
>
I do not want to use Sql Authentication.
>
How should i setup permissions on my database?
>
At the moment i have set up the NETWORK SERVICE account (account for
running asp.net) on my server to be a role member of the db_owner group
for the database. This allows the user access to all the object in my
database, as everything is owned by dbo.
>
Is this correct? This doesnt sound right to me? Do i have to setup
another user in my Sql database?
>


Hi nemesis.

Is you database server & Web Server located on the same machine?

If yes
You could create a local (technical) user account & have the application
run under an application pool with the technical user account.
On the DB level , just create the login & user account and grant execute
on the stored procedure.

If No
instead of a local (technical) user account have a domain account made.
the rest of the setup is just the same.

As a side note , never have any application account part of db_owner ,
this means the app. could just drop all tables in your DB .

Yvesl

Nemisis wrote:

Nemisis wrote:

Quote:

Originally Posted by

Hi everyone, hope your all looking forward to xmas.
>
I am setting up a Sql2005 database on a Windows Server, running Windows
Server 2003. The database is going to be accessed via users using an
ASP.Net website.
>
My website is running the normal IUSR account. And users must login to
the website, which uses Forms Authentication.
>
I do not want to give users access directly to tables, so have created
many stored procedures which will carry out the operations that i would
like users to be able to do.
>
I do not want to use Sql Authentication.
>
How should i setup permissions on my database?
>
At the moment i have set up the NETWORK SERVICE account (account for
running asp.net) on my server to be a role member of the db_owner group
for the database. This allows the user access to all the object in my
database, as everything is owned by dbo.
>
Is this correct? This doesnt sound right to me? Do i have to setup
another user in my Sql database?
>
Hi everyone, hope your all looking forward to xmas.
>
I am setting up a Sql2005 database on a Windows Server, running Windows
Server 2003. The database is going to be accessed via users using an
ASP.Net website.
>
My website is running the normal IUSR account. And users must login to
the website, which uses Forms Authentication.
>
I do not want to give users access directly to tables, so have created
many stored procedures which will carry out the operations that i would
like users to be able to do.
>
I do not want to use Sql Authentication.
>
How should i setup permissions on my database?
>
At the moment i have set up the NETWORK SERVICE account (account for
running asp.net) on my server to be a role member of the db_owner group
for the database. This allows the user access to all the object in my
database, as everything is owned by dbo.
>
Is this correct? This doesnt sound right to me? Do i have to setup
another user in my Sql database?
>


Thanks alot for this, my database server and web server are on the same
machine.

I will try to setup a account and set the correct permission first
thing in the morning.

The new account that i will setup, does it need access to the tables?
Because before when i tried to execute a stored procedure, it said that
select permissions had to be set on the table as well. Is this still
the case??

Should the new account be apart of a role in the database? Or should i
created my own?

Thanks again for your help so far.
Hi,
Assuming you're only using stored procedure your new user (lets call him
LOCALSERVER\TEST) does not need any access to the tables.
It needs EXECUTE right to the stored procedures.

here's the script to grant access.
GRANT EXECUTE ON [dbo].[AddSp] TO [LOCALSERVER\TEST]
GRANT EXECUTE ON [dbo].[GetSp] TO [LOCALSERVER\TEST]

For Role Membership, well it all depends on what your requirements are.
For more informed help you should probably ask this newsgroup:
microsoft.public.sqlserver.server

however my 2c:
Since your Database will be accessed only through 1 user account( the
one that your web app. runs under) I don't think it's necessary to
create any Role.

YvesL

Nemisis wrote:

Quote:

Originally Posted by

Thanks alot for this, my database server and web server are on the same
machine.
>
I will try to setup a account and set the correct permission first
thing in the morning.
>
The new account that i will setup, does it need access to the tables?
Because before when i tried to execute a stored procedure, it said that
select permissions had to be set on the table as well. Is this still
the case??
>
Should the new account be apart of a role in the database? Or should i
created my own?
>
Thanks again for your help so far.
>


Yves. L. wrote:

Quote:

Originally Posted by

Hi,
Assuming you're only using stored procedure your new user (lets call him
LOCALSERVER\TEST) does not need any access to the tables.
It needs EXECUTE right to the stored procedures.
>
here's the script to grant access.
GRANT EXECUTE ON [dbo].[AddSp] TO [LOCALSERVER\TEST]
GRANT EXECUTE ON [dbo].[GetSp] TO [LOCALSERVER\TEST]
>
>
>
For Role Membership, well it all depends on what your requirements are.
For more informed help you should probably ask this newsgroup:
microsoft.public.sqlserver.server
>
however my 2c:
Since your Database will be accessed only through 1 user account( the
one that your web app. runs under) I don't think it's necessary to
create any Role.
>
YvesL


Yves,

What about if i need to run dynamic Sql? Will this still be ok? I
hear that there are some problems when running dynamic Sql?
>

Quote:

Originally Posted by

Yves,
>
What about if i need to run dynamic Sql? Will this still be ok? I
hear that there are some problems when running dynamic Sql?
>


I suppose that you mean SQL statements in code ?
Then you'll need to set the proper permission on the necessary tables,
views, etc,... or make your user part of the db_datawriter or
db_datareader roles (see the docs for reference).

Anyway, you wrote earlier that you have SP'for all data access, so you
should be fine .

--
Regards,
YvesL
Yes the users only execute stored procedures, but within some of the
stored procedures, i execute dynamic Sql, using the execute_sql system
stored procedure.

I was told that it was not a good idea to make a user apart of the
db_owner role, is making them a part of the db_datareader and
db_datawriter role ok?

I am using Sql2005, so does this still apply? I didnt know if i should
do something different for Sql2005?

Thanks
Yes the users only execute stored procedures, but within some of the

Quote:

Originally Posted by

stored procedures, i execute dynamic Sql, using the execute_sql system
stored procedure.


I don't know about that, you'll have to try it out or ask the sqlserver
newsgroup.

Quote:

Originally Posted by

>
I was told that it was not a good idea to make a user apart of the
db_owner role, is making them a part of the db_datareader and
db_datawriter role ok?


Have a look at
ms-help://MS.VSCC.v80/MS.VSIPCC.v80/MS.SQLSVR.v9.en/udb9/html/7f3fa5f6-6b50-43bb-9047-1544ade55e39.htm

it describes what access users get for those database roles

--
Regards,
YvesL
Hope u all had a merry xmas, and happy new year too you all.

I have followed the steps in the article
http://www.sommarskog.se/grantperm.html.

1. Create a certificate
2. Create a user associated with that certificate
3. Grant that user SELECT rights on the table
4. Sign the procedure with the certificate EACH TIME you have changed
the procedure

Encase you dont know, i have had to create this certificate as i am
executing dynamic Sql within some of my stored procedures, and i dont
want to give the user any permissions to the tables.

I am a lil confused, as i have to create a user (above) to associate
with the certificate, and i have to give that user permissions to the
table directly. Would it not have been easier just to give the main
user (web application IIS user, NETWORK SERVICE) direct permissions to
the tables, instead of setting another user up?

Could someone please clarify why this is the case and the benefits of
it, i have to also inform other people why we are going to set the
application up like this.

Thanks

Permissions wizard

Hi all
on my local IIS (Windows XP) I can
Website -> Right click -> All Tasks -> Permissions Wizard
And select my settings from the secure web site template.
On my test server Windows Server 2003, I cand find this option. Would anyone
be able to tell me how to install this template or manually set the
permissions the same as a secure web site
thanks in advance
AndyI know when you create a web site in windows server 2003 you can uncheck the
allow unominous access.
Hope that helps you out.
Good Luck
DWS
"AAJ" wrote:

> Hi all
> on my local IIS (Windows XP) I can
> Website -> Right click -> All Tasks -> Permissions Wizard
> And select my settings from the secure web site template.
> On my test server Windows Server 2003, I cand find this option. Would anyo
ne
> be able to tell me how to install this template or manually set the
> permissions the same as a secure web site
> thanks in advance
> Andy
>
>

Permissions wizard

Hi all

on my local IIS (Windows XP) I can

Website -> Right click -> All Tasks -> Permissions Wizard

And select my settings from the secure web site template.

On my test server Windows Server 2003, I cand find this option. Would anyone
be able to tell me how to install this template or manually set the
permissions the same as a secure web site

thanks in advance

AndyI know when you create a web site in windows server 2003 you can uncheck the
allow unominous access.

Hope that helps you out.

Good Luck
DWS

"AAJ" wrote:

> Hi all
> on my local IIS (Windows XP) I can
> Website -> Right click -> All Tasks -> Permissions Wizard
> And select my settings from the secure web site template.
> On my test server Windows Server 2003, I cand find this option. Would anyone
> be able to tell me how to install this template or manually set the
> permissions the same as a secure web site
> thanks in advance
> Andy
>