Unix Technical Forum

Risks of single MSSQL domain account for mult servers?

This is a discussion on Risks of single MSSQL domain account for mult servers? within the SQL Server forums, part of the Microsoft SQL Server category; --> Greetings: I am trying to conceive what risks might be created by running multiple SQL servers within a domain ...


Go Back   Unix Technical Forum > Database Server Software > Microsoft SQL Server > SQL Server

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-29-2008, 03:57 AM
D Barry
 
Posts: n/a
Default Risks of single MSSQL domain account for mult servers?

Greetings:

I am trying to conceive what risks might be created by running
multiple SQL servers within a domain under a single domain account, as
opposed to 1) running under the local service account or 2) multiple
domain service accounts.

In this case, all the SQL servers are SQL2000 running on Win2003. The
service account is assigned only to the "Domain Users" group.

We do use linked server calls, and I have played and suceeded getting
Kereberos up to avoid double hop issues when using Windows Auth. In
fact, this is one of the reasons that sparked the question in my mind
-- in all the MS Kerebos SQL<->SQL examples, the SQL servers run under
a unique service account.


As an aside, most of the servers are "line of business" servers, but
HR runs under a unique server with more sensitive information. I don't
really think that merits a seperate service account, but again, I
could well be missing something.


I mostly looking for food for thought, but concrete examples of
gotchas would be appreciated.

Thanks all.

d.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-29-2008, 03:57 AM
Russell Fields
 
Posts: n/a
Default Re: Risks of single MSSQL domain account for mult servers?

D (or should I call you d?),

One drawback of using a single service account is that a breach of security
on that account means a breach on all of your SQL Servers.

(Yes, it is easier to only have one account to manage. Also, once upon a
time (a long time ago) it made replication easier.)

Russell Fields
"D Barry" <google@dcbarry.com> wrote in message
news:6d9b9a07.0405201046.548244c2@posting.google.c om...
> Greetings:
>
> I am trying to conceive what risks might be created by running
> multiple SQL servers within a domain under a single domain account, as
> opposed to 1) running under the local service account or 2) multiple
> domain service accounts.
>
> In this case, all the SQL servers are SQL2000 running on Win2003. The
> service account is assigned only to the "Domain Users" group.
>
> We do use linked server calls, and I have played and suceeded getting
> Kereberos up to avoid double hop issues when using Windows Auth. In
> fact, this is one of the reasons that sparked the question in my mind
> -- in all the MS Kerebos SQL<->SQL examples, the SQL servers run under
> a unique service account.
>
>
> As an aside, most of the servers are "line of business" servers, but
> HR runs under a unique server with more sensitive information. I don't
> really think that merits a seperate service account, but again, I
> could well be missing something.
>
>
> I mostly looking for food for thought, but concrete examples of
> gotchas would be appreciated.
>
> Thanks all.
>
> d.



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-29-2008, 03:58 AM
D Barry
 
Posts: n/a
Default Re: Risks of single MSSQL domain account for mult servers?

Russell:

It's "d.". "D." is just too pompous... ;-)

I should have stated the breach against one is a breach of all
arugument. (We do use nice long complex passwords.) I'm looking for
other

"Russell Fields" <RussellFields@NoMailPlease.Com> wrote in message news:<ubmx4TqPEHA.2976@TK2MSFTNGP10.phx.gbl>...
> D (or should I call you d?),
>
> One drawback of using a single service account is that a breach of security
> on that account means a breach on all of your SQL Servers.
>
> (Yes, it is easier to only have one account to manage. Also, once upon a
> time (a long time ago) it made replication easier.)
>
> Russell Fields
> "D Barry" <google@dcbarry.com> wrote in message
> news:6d9b9a07.0405201046.548244c2@posting.google.c om...
> > Greetings:
> >
> > I am trying to conceive what risks might be created by running
> > multiple SQL servers within a domain under a single domain account, as
> > opposed to 1) running under the local service account or 2) multiple
> > domain service accounts.
> >

<snip>

> > Thanks all.
> >
> > d.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:25 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com