Re: IIS & SQL, dedicated user account & GPO



ChipW wrote:

SBS'03 Prem SP1, using ISA'04
I am setting up a dedicated IIS server (2 nics) for hosting a site that will use data from a SQL DB on the SBS server (2 nics). From what I read, a dedicated domain user account is the securest way to allow IIS to access SQL without a lot of maintenance . My problem/question comes in at the GPO problems I could experiance. I have password changes forced every 45 days (yes, strong), but I don't want this account to have to change. Also, is thier an easy way to setup this account without all the frills the wizard normally adds, like mailboxes, etc. Basically all I want the account to be able to do is allow IIS to access the tables and queries I specify in EM and nothing else...


Thanks is advance

Chip

Create the account using the normal AD methods, rather than the SBS wizards.

Secondly, tick the "Password Never Expires" box in the account properties to effectively exempt it from the password GPO.

Mind you, you should find that you have a suitable user account already - the IUSR_* or IWAM_* account for the IIS server.

--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.
.



Relevant Pages

  • Re: IIS 6.0 and SQL server
    ... domain account, or it needs to be a local account on both machines with ... should be true both if you are using Windows authentication in SQL, ... if you are using SQL authentication in SQL but the SQL client on the IIS ...
    (microsoft.public.inetserver.iis.security)
  • RE: Which account on SQL 2005 web sync via https
    ... Well - to take a stab in the dark on this one, it seems the account you are ... permissions when you are running in a domain environment. ... Configure a Publication to Allow for Web Synchronization (SQL ... Configure IIS for Web Synchronization ...
    (microsoft.public.sqlserver.replication)
  • Re: Connecting to SQL through ASP
    ... > I think i have followed the instructions for connecting to SQL Server ... > Created local account with same name as IIS ...
    (microsoft.public.inetserver.iis.security)
  • Connecting to SQL through ASP
    ... I think i have followed the instructions for connecting to SQL Server ... IIS 5.0 machine running on win2000 pro ... Created local account with same name as IIS ...
    (microsoft.public.inetserver.iis.security)
  • Re: kerberos the story so far
    ... I have put the IIS machine into a local group and assigned it owner in the ... One the I have noticed is that running the AuthDiag tool on the SQL box says ... where my IIS front end server could not obtain a kerberos ... > It looks like you registered the SPN for the SQL service user account. ...
    (microsoft.public.win2000.active_directory)