Showing posts with label report. Show all posts
Showing posts with label report. Show all posts

Friday, March 30, 2012

Instance caching without default parameter values

I am working with a well-studied DBA who claims that all report parameters
must have default values in order to configure instance caching. Is there
any truth to this? I don't see anything of this kind in BOL.
We actually get rsProcessAborted errors if they don't have defaults (even
though reports only execute when all parameters are provided.)
--
Paul Turley, MCSD, MCDBA, MSF, MCT
nospam at scout-master.comThis might help someone figure it out. It looks like a Reporting Services
issue to me...I'm the DBA ;)
----
--
Start snippet from Report_Server.log
----
--
aspnet_wp!processing!eec!4/26/2005-16:51:08:: e ERROR: An exception has
occurred in data source 'AGG'. Details: System.IndexOutOfRangeException:
Index was outside the bounds of the array.
at
Microsoft.ReportingServices.Library.IndexedStreamHeader.get_LastUncompressed
Offset()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.get_Interna
lUncompressedLength()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.FillBuffer(
)
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream..ctor(Strea
m store)
at
Microsoft.ReportingServices.Library.SnapshotChunkStreamFactory.CreateReadStr
eam(Guid snapshotDataID, Boolean isPermanentSnapshot, String chunkName,
Int32 chunkType, String& mimeType)
at
Microsoft.ReportingServices.Library.ReportSnapshot.GetReportChunk(String
name, ReportChunkTypes type, String& mimeType)
at Microsoft.ReportingServices.ReportProcessing.b..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.g..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.aw.c()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Boolean& A_0)
at Microsoft.ReportingServices.ReportProcessing.aw.b()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Object A_0)
aspnet_wp!processing!d20!4/26/2005-16:51:08:: e ERROR: An exception has
occurred in data source 'AGG2'. Details: System.IndexOutOfRangeException:
Index was outside the bounds of the array.
at
Microsoft.ReportingServices.Library.IndexedStreamHeader.get_LastUncompressed
Offset()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.get_Interna
lUncompressedLength()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.FillBuffer(
)
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream..ctor(Strea
m store)
at
Microsoft.ReportingServices.Library.SnapshotChunkStreamFactory.CreateReadStr
eam(Guid snapshotDataID, Boolean isPermanentSnapshot, String chunkName,
Int32 chunkType, String& mimeType)
at
Microsoft.ReportingServices.Library.ReportSnapshot.GetReportChunk(String
name, ReportChunkTypes type, String& mimeType)
at Microsoft.ReportingServices.ReportProcessing.b..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.g..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.aw.c()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Boolean& A_0)
at Microsoft.ReportingServices.ReportProcessing.aw.b()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Object A_0)
aspnet_wp!processing!eec!4/26/2005-16:51:08:: e ERROR: An exception has
occurred. Trying to abort processing. Details:
System.IndexOutOfRangeException: Index was outside the bounds of the array.
at
Microsoft.ReportingServices.Library.IndexedStreamHeader.get_LastUncompressed
Offset()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.get_Interna
lUncompressedLength()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.FillBuffer(
)
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream..ctor(Strea
m store)
at
Microsoft.ReportingServices.Library.SnapshotChunkStreamFactory.CreateReadStr
eam(Guid snapshotDataID, Boolean isPermanentSnapshot, String chunkName,
Int32 chunkType, String& mimeType)
at
Microsoft.ReportingServices.Library.ReportSnapshot.GetReportChunk(String
name, ReportChunkTypes type, String& mimeType)
at Microsoft.ReportingServices.ReportProcessing.b..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.g..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.aw.c()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Boolean& A_0)
at Microsoft.ReportingServices.ReportProcessing.aw.b()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Object A_0)
aspnet_wp!processing!d20!4/26/2005-16:51:08:: e ERROR: An exception has
occurred. Trying to abort processing. Details:
System.IndexOutOfRangeException: Index was outside the bounds of the array.
at
Microsoft.ReportingServices.Library.IndexedStreamHeader.get_LastUncompressed
Offset()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.get_Interna
lUncompressedLength()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.FillBuffer(
)
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream..ctor(Strea
m store)
at
Microsoft.ReportingServices.Library.SnapshotChunkStreamFactory.CreateReadStr
eam(Guid snapshotDataID, Boolean isPermanentSnapshot, String chunkName,
Int32 chunkType, String& mimeType)
at
Microsoft.ReportingServices.Library.ReportSnapshot.GetReportChunk(String
name, ReportChunkTypes type, String& mimeType)
at Microsoft.ReportingServices.ReportProcessing.b..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.g..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.aw.c()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Boolean& A_0)
at Microsoft.ReportingServices.ReportProcessing.aw.b()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Object A_0)
aspnet_wp!processing!eec!4/26/2005-16:51:08:: i INFO: Merge abort handler
called. Aborting data sources ...
aspnet_wp!processing!eec!4/26/2005-16:51:08:: i INFO: Data source
'Staging_xxxxxx_Reader': Abort handler called. CanAbort = True.
aspnet_wp!processing!d20!4/26/2005-16:51:08:: i INFO: Some other thread is
aborting processing.
aspnet_wp!processing!eec!4/26/2005-16:51:08:: i INFO: Abort callback
successful.
aspnet_wp!processing!d20!4/26/2005-16:51:08:: e ERROR: Throwing
Microsoft.ReportingServices.ReportProcessing.ProcessingAbortedException: An
error has occurred during report processing., ;
Info:
Microsoft.ReportingServices.ReportProcessing.ProcessingAbortedException: An
error has occurred during report processing. -->
System.IndexOutOfRangeException: Index was outside the bounds of the array.
at
Microsoft.ReportingServices.Library.IndexedStreamHeader.get_LastUncompressed
Offset()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.get_Interna
lUncompressedLength()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.FillBuffer(
)
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream..ctor(Strea
m store)
at
Microsoft.ReportingServices.Library.SnapshotChunkStreamFactory.CreateReadStr
eam(Guid snapshotDataID, Boolean isPermanentSnapshot, String chunkName,
Int32 chunkType, String& mimeType)
at
Microsoft.ReportingServices.Library.ReportSnapshot.GetReportChunk(String
name, ReportChunkTypes type, String& mimeType)
at Microsoft.ReportingServices.ReportProcessing.b..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.g..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.aw.c()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Boolean& A_0)
at Microsoft.ReportingServices.ReportProcessing.aw.b()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Object A_0)
-- End of inner exception stack trace --
aspnet_wp!processing!d20!4/26/2005-16:51:08:: e ERROR: Data source
'Staging_xxxxxx_Reader': An error has occurred. Details:
Microsoft.ReportingServices.ReportProcessing.ProcessingAbortedException: An
error has occurred during report processing. -->
System.IndexOutOfRangeException: Index was outside the bounds of the array.
aspnet_wp!processing!d20!4/26/2005-16:51:08:: w WARN: Data source
'Staging_xxxxxx_Reader': Report processing has been aborted.
aspnet_wp!processing!d20!4/26/2005-16:51:08:: e ERROR: Throwing
Microsoft.ReportingServices.ReportProcessing.ProcessingAbortedException: An
error has occurred during report processing., ;
Info:
Microsoft.ReportingServices.ReportProcessing.ProcessingAbortedException: An
error has occurred during report processing. -->
System.IndexOutOfRangeException: Index was outside the bounds of the array.
at
Microsoft.ReportingServices.Library.IndexedStreamHeader.get_LastUncompressed
Offset()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.get_Interna
lUncompressedLength()
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream.FillBuffer(
)
at
Microsoft.ReportingServices.Library.BufferedCompressedReadStream..ctor(Strea
m store)
at
Microsoft.ReportingServices.Library.SnapshotChunkStreamFactory.CreateReadStr
eam(Guid snapshotDataID, Boolean isPermanentSnapshot, String chunkName,
Int32 chunkType, String& mimeType)
at
Microsoft.ReportingServices.Library.ReportSnapshot.GetReportChunk(String
name, ReportChunkTypes type, String& mimeType)
at Microsoft.ReportingServices.ReportProcessing.b..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.g..ctor(DataSet A_0,
Int32 A_1, UInt32 A_2, GetReportChunk A_3)
at Microsoft.ReportingServices.ReportProcessing.aw.c()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Boolean& A_0)
at Microsoft.ReportingServices.ReportProcessing.aw.b()
at Microsoft.ReportingServices.ReportProcessing.a0.a(Object A_0)
-- End of inner exception stack trace --
aspnet_wp!library!d20!04/26/2005-16:51:08:: i INFO: Initializing
EnableExecutionLogging to 'True' as specified in Server system properties.
aspnet_wp!webserver!d20!04/26/2005-16:51:08:: e ERROR: Reporting Services
error Microsoft.ReportingServices.Diagnostics.Utilities.RSException: An
error has occurred during report processing. -->
Microsoft.ReportingServices.ReportProcessing.ProcessingAbortedException: An
error has occurred during report processing. -->
System.IndexOutOfRangeException: Index was outside the bounds of the array.
----
--
End snippet from Report_Server.log
----
--
-- HTH
Regards,
Don R. Watters
Walt Disney Internet Group
"Paul Turley" <nospam@.turleyfamily_dot_org> wrote in message
news:ONjOkApSFHA.3184@.TK2MSFTNGP14.phx.gbl...
> I am working with a well-studied DBA who claims that all report parameters
> must have default values in order to configure instance caching. Is there
> any truth to this? I don't see anything of this kind in BOL.
> We actually get rsProcessAborted errors if they don't have defaults (even
> though reports only execute when all parameters are provided.)
> --
> Paul Turley, MCSD, MCDBA, MSF, MCT
> nospam at scout-master.com
>|||As for the first part, no, the cache is based on a combination of report,
credentials, and parameter values. As for the second one, I don't know what
specific error you are getting.
--
Brian Welcker
Group Program Manager
Microsoft SQL Server Reporting Services
This posting is provided "AS IS" with no warranties, and confers no rights.
"Paul Turley" <nospam@.turleyfamily_dot_org> wrote in message
news:ONjOkApSFHA.3184@.TK2MSFTNGP14.phx.gbl...
>I am working with a well-studied DBA who claims that all report parameters
>must have default values in order to configure instance caching. Is there
>any truth to this? I don't see anything of this kind in BOL.
> We actually get rsProcessAborted errors if they don't have defaults (even
> though reports only execute when all parameters are provided.)
> --
> Paul Turley, MCSD, MCDBA, MSF, MCT
> nospam at scout-master.com
>|||The specific error is in my other post, on Paul's main thread.
-- Don
"Brian Welcker [MSFT]" <bwelcker@.online.microsoft.com> wrote in message
news:%235mdZw6SFHA.616@.TK2MSFTNGP12.phx.gbl...
> As for the first part, no, the cache is based on a combination of report,
> credentials, and parameter values. As for the second one, I don't know
what
> specific error you are getting.
> --
> Brian Welcker
> Group Program Manager
> Microsoft SQL Server Reporting Services
> This posting is provided "AS IS" with no warranties, and confers no
rights.
> "Paul Turley" <nospam@.turleyfamily_dot_org> wrote in message
> news:ONjOkApSFHA.3184@.TK2MSFTNGP14.phx.gbl...
> >I am working with a well-studied DBA who claims that all report
parameters
> >must have default values in order to configure instance caching. Is
there
> >any truth to this? I don't see anything of this kind in BOL.
> >
> > We actually get rsProcessAborted errors if they don't have defaults
(even
> > though reports only execute when all parameters are provided.)
> >
> > --
> > Paul Turley, MCSD, MCDBA, MSF, MCT
> > nospam at scout-master.com
> >
>|||Try refreshing your dataset and deleting and readding the dataset to your
table.
"Paul Turley" wrote:
> I am working with a well-studied DBA who claims that all report parameters
> must have default values in order to configure instance caching. Is there
> any truth to this? I don't see anything of this kind in BOL.
> We actually get rsProcessAborted errors if they don't have defaults (even
> though reports only execute when all parameters are provided.)
> --
> Paul Turley, MCSD, MCDBA, MSF, MCT
> nospam at scout-master.com
>
>

Wednesday, March 28, 2012

Installing Web Server and Database Server not in the same DOMAIN

Hello All,
I'm installing the RS using the "Standard Deployment Model" suggested
by BOL, which uses one Web Server as the Report Server and the Report
Manager and another as the Report Server Database.
According to BOL:
"The SQL Server instance hosting the report server database must be in
the same domain as the report server or in a trusted domain with the
report server."
Although, in my case, these two machines are not in the same domain,
neither could be. Is there any workaround for it'
It's quite urgent because while I was testing RS in DEV, wich has just
one machine, everything was fine, but now that I'm deploying RS to
Production, I realized that I don't have both Prd machines on the same
domain.
I'd appreciate any help.
Thanks in advance,
Vinicius BellinoThe workaround is laid out right there -- create a domain trust.
--
Cheers,
'(' Jeff A. Stucker
\
Business Intelligence
www.criadvantage.com
---
"Vinicius Bellino" <vbellino@.uol.com.br> wrote in message
news:93d12908.0503021209.165adea4@.posting.google.com...
> Hello All,
> I'm installing the RS using the "Standard Deployment Model" suggested
> by BOL, which uses one Web Server as the Report Server and the Report
> Manager and another as the Report Server Database.
> According to BOL:
> "The SQL Server instance hosting the report server database must be in
> the same domain as the report server or in a trusted domain with the
> report server."
> Although, in my case, these two machines are not in the same domain,
> neither could be. Is there any workaround for it'
> It's quite urgent because while I was testing RS in DEV, wich has just
> one machine, everything was fine, but now that I'm deploying RS to
> Production, I realized that I don't have both Prd machines on the same
> domain.
> I'd appreciate any help.
> Thanks in advance,
> Vinicius Bellino|||Do you realize that you have to have a SQL Server license for the web server
and then one for SQL Server. My feeling is to have SQL Server on the web
server even if it is just as the object store (i.e. the data being reported
off of is somewhere else). SQL Server is very good at managing it's
resources and I have had no problem doing this.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Vinicius Bellino" <vbellino@.uol.com.br> wrote in message
news:93d12908.0503021209.165adea4@.posting.google.com...
> Hello All,
> I'm installing the RS using the "Standard Deployment Model" suggested
> by BOL, which uses one Web Server as the Report Server and the Report
> Manager and another as the Report Server Database.
> According to BOL:
> "The SQL Server instance hosting the report server database must be in
> the same domain as the report server or in a trusted domain with the
> report server."
> Although, in my case, these two machines are not in the same domain,
> neither could be. Is there any workaround for it'
> It's quite urgent because while I was testing RS in DEV, wich has just
> one machine, everything was fine, but now that I'm deploying RS to
> Production, I realized that I don't have both Prd machines on the same
> domain.
> I'd appreciate any help.
> Thanks in advance,
> Vinicius Bellino|||"Bruce L-C [MVP]" <bruce_lcNOSPAM@.hotmail.com> wrote in message news:<OjYvW22HFHA.1476@.TK2MSFTNGP09.phx.gbl>...
> Do you realize that you have to have a SQL Server license for the web server
> and then one for SQL Server. My feeling is to have SQL Server on the web
> server even if it is just as the object store (i.e. the data being reported
> off of is somewhere else). SQL Server is very good at managing it's
> resources and I have had no problem doing this.
>
> --
> Bruce Loehle-Conger
> MVP SQL Server Reporting Services
> "Vinicius Bellino" <vbellino@.uol.com.br> wrote in message
> news:93d12908.0503021209.165adea4@.posting.google.com...
> > Hello All,
> >
> > I'm installing the RS using the "Standard Deployment Model" suggested
> > by BOL, which uses one Web Server as the Report Server and the Report
> > Manager and another as the Report Server Database.
> >
> > According to BOL:
> >
> > "The SQL Server instance hosting the report server database must be in
> > the same domain as the report server or in a trusted domain with the
> > report server."
> >
> > Although, in my case, these two machines are not in the same domain,
> > neither could be. Is there any workaround for it'
> >
> > It's quite urgent because while I was testing RS in DEV, wich has just
> > one machine, everything was fine, but now that I'm deploying RS to
> > Production, I realized that I don't have both Prd machines on the same
> > domain.
> >
> > I'd appreciate any help.
> >
> > Thanks in advance,
> >
> > Vinicius Bellino
Bruce,
I've thought about installing SQL Server in my Web Server as well, but
the only point was the supposed new SQL Server's license. Now I have
no more reasons not to do this. So, thank you!
Regards,
Vinicius Bellinosql

Installing VS .NET after Installing Reporting Services

I installed VS .NET after installing Reporting Services. When I bring up VS,
I don't see the Report Designer choices. What do I need to do to make them
appear?If you installed RS without VS.Net then what you installed is the server
piece. What you need to do now is install the report designer. Rerun setup
and install just the report designer.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Bob Sherman" <Bob Sherman@.discussions.microsoft.com> wrote in message
news:BEB7E965-CA6C-434B-A931-2AE7A27EB8F1@.microsoft.com...
> I installed VS .NET after installing Reporting Services. When I bring up
VS,
> I don't see the Report Designer choices. What do I need to do to make them
> appear?
>

Installing two instances of Report server

Can we install two instances of report server on the same machine?. We want to use the same hardware for two different methods of custom authentication. Both the server applications would then talk to the same database.

cvajre,

Here's a step by step way of implementing 2 reporting instances.

http://bloggingabout.net/blogs/mglaser/archive/2006/12/18/multiple-reporting-services-instances-on-one-machine.aspx

Ham

installing to another website

Hi,
I am trying to install Reporting Services on our web
server and one of the requirements says I have to install
the report server's virtual directory to the default
website. The problem is, the default website's ip is
unassigned most of the time, and is frequently either
being configured differently for testing or is out of
commission most of the time. Now, there are other
websites on the server that I'd rather use, and I was
wondering if it is possible to create the report server's
virtual directory in a website other than the default
one?
Thanks,
MarkThis article explains how to change the website that RS is hosted on.
http://www.sqljunkies.com/HowTo/525B575A-7F61-483A-AC8F-FEC700C34674.scuk
Craig
Mark Hackenberg wrote:
> Hi,
> I am trying to install Reporting Services on our web
> server and one of the requirements says I have to install
> the report server's virtual directory to the default
> website. The problem is, the default website's ip is
> unassigned most of the time, and is frequently either
> being configured differently for testing or is out of
> commission most of the time. Now, there are other
> websites on the server that I'd rather use, and I was
> wondering if it is possible to create the report server's
> virtual directory in a website other than the default
> one?
> Thanks,
> Mark|||That article really helped. It laid everything out step
by step. Thanks for the help.
>--Original Message--
>This article explains how to change the website that RS
is hosted on.
>http://www.sqljunkies.com/HowTo/525B575A-7F61-483A-AC8F-
FEC700C34674.scuk
>
>Craig
>Mark Hackenberg wrote:
>> Hi,
>> I am trying to install Reporting Services on our web
>> server and one of the requirements says I have to
install
>> the report server's virtual directory to the default
>> website. The problem is, the default website's ip is
>> unassigned most of the time, and is frequently either
>> being configured differently for testing or is out of
>> commission most of the time. Now, there are other
>> websites on the server that I'd rather use, and I was
>> wondering if it is possible to create the report
server's
>> virtual directory in a website other than the default
>> one?
>> Thanks,
>> Mark
>.
>|||Thank you sooo much Craig. This article told the steps exactly.
No one had a clue what to do. I was mucking around with this for ages.
<b>Just brilliant</b>
"Craig Riter" wrote:
> This article explains how to change the website that RS is hosted on.
> http://www.sqljunkies.com/HowTo/525B575A-7F61-483A-AC8F-FEC700C34674.scuk
>
> Craig
> Mark Hackenberg wrote:
> > Hi,
> >
> > I am trying to install Reporting Services on our web
> > server and one of the requirements says I have to install
> > the report server's virtual directory to the default
> > website. The problem is, the default website's ip is
> > unassigned most of the time, and is frequently either
> > being configured differently for testing or is out of
> > commission most of the time. Now, there are other
> > websites on the server that I'd rather use, and I was
> > wondering if it is possible to create the report server's
> > virtual directory in a website other than the default
> > one?
> >
> > Thanks,
> >
> > Mark
>

Monday, March 26, 2012

Installing SSRS report designer with Visual Studio 2005

I have VS 2005 installed on my workstation. I have Sql Server 2005 on a
database server, and
just installed Reporting Services on a web server.
How do I install the Report Services report designer on my workstation in VS
2005?
thanks,
Bob M..Just place the dick into drive of your computer and start installation.
During the installation, you can choose to install client tool only.
"Bob Murdoch" <ram_re_move_5@.erols.com> wrote in message
news:uwjclTfBIHA.4752@.TK2MSFTNGP04.phx.gbl...
>I have VS 2005 installed on my workstation. I have Sql Server 2005 on a
>database server, and
> just installed Reporting Services on a web server.
> How do I install the Report Services report designer on my workstation in
> VS 2005?
> thanks,
> Bob M..
>|||"Norman Yuan" <NoAddress@.NoEmail.fake> wrote in message
> Just place the dick into drive of your computer and start installation.
> During the installation, you can choose to install client tool only.
>
Besides the slip of the keyboard, which disk are you referring to? When I
try to use the Sql Server 2005 disk, the Reporting Services option is grayed
out (presumably because I don't have IIS installed on my workstation?).
thanks,
Bob M..|||I do not not what kind of disk your SQL Server2005 is on. I have heard it
may be on 2 CDs or 1 DVD. Mine is from MSDN subscription, which has two
setup.exe - one for the server part and one for client tools part.
Whatever you have, you should install client components only, including
Connectivity components, Management tools, Business Intelligence Development
Studio (this is what you need!), SDK, documentation... You do not need to
install RS for report designing, unless you want to.
"Bob Murdoch" <ram_re_move_5@.erols.com> wrote in message
news:OSnjevfBIHA.2004@.TK2MSFTNGP06.phx.gbl...
> "Norman Yuan" <NoAddress@.NoEmail.fake> wrote in message
>> Just place the dick into drive of your computer and start installation.
>> During the installation, you can choose to install client tool only.
> Besides the slip of the keyboard, which disk are you referring to? When I
> try to use the Sql Server 2005 disk, the Reporting Services option is
> grayed out (presumably because I don't have IIS installed on my
> workstation?).
> thanks,
> Bob M..
>

Installing SSRS 2005 in web server and cluster environment.

Hi,

I am installing SSRS 2005 with the following scenario:

- Report Server and Report Manager will be installed on web server

- The repository databases (ReportServer and ReportServerTempDB) will be hosted in SQL2005 cluster server.

Both servers are running Win2003 SP1, SQL/SSRS 2005 SP1

When I try to browse the ReportServer virtual directory from IIS on the web server, the system keep asking username and password. After 3 times trials and it failed eventhough the username and password is correct.

The error message is:

HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials.
Internet Information Services (IIS)

I've been searching on the web and found couple of articles talking about this issue. I've tried some of them like: http://support.microsoft.com/kb/887993 or even this one: http://groups.google.ca/group/microsoft.public.sqlserver.reportingsvcs/browse_frm/thread/991c9178ceab8f58/8f1a447aa60ad837?lnk=st&q=reporting+services+the+server+is+not+responding&rnum=3&hl=en#8f1a447aa60ad837

But this doesn't work.

I've checked both event viewer both web server and SQL server, but I can't see any information that tell me what had happened.

I also look at BOL, but doesn't help much.

Is there anyone can help me or point me to the right direction? Is there any guide document that explains step-by-step how to install SSRS in my scenario or similiar?

Many Thanks,

Usman Tjiudri

I have the exact same issue in a identical envirnonment configuration. Did you get this resolved?

I`m looking at a few articles re Kerberos....

|||Hi,

Yes, finally I got this issue resolved.
After looking for answer almost everywhere, I finally turn to Microsoft Support and they gave me a very quick response (less than 24 hours).
Before I talk about the solution, I need to clarify something here - my environment is Win2003 Server R2 (not Win2003 SP1 as mentioned in previous email) - may be there's a SP1 for R2.
The issue is caused by IIS. Apparently R2 has different version of IIS with normal Win2003 Server.
You need to uninstall completely IIS on your server (may be you need to backup IIS metadata) and install IIS for R2. You can get the software from R2 disc.
If you still can't solve the issue, log it to Microsoft Support.

Let me know how it goes.

Hope This Help,
Usman Tjiudri

Installing SSRS 2005 in web server and cluster environment.

Hi,

I am installing SSRS 2005 with the following scenario:

- Report Server and Report Manager will be installed on web server

- The repository databases (ReportServer and ReportServerTempDB) will be hosted in SQL2005 cluster server.

Both servers are running Win2003 SP1, SQL/SSRS 2005 SP1

When I try to browse the ReportServer virtual directory from IIS on the web server, the system keep asking username and password. After 3 times trials and it failed eventhough the username and password is correct.

The error message is:

HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials.
Internet Information Services (IIS)

I've been searching on the web and found couple of articles talking about this issue. I've tried some of them like: http://support.microsoft.com/kb/887993 or even this one: http://groups.google.ca/group/microsoft.public.sqlserver.reportingsvcs/browse_frm/thread/991c9178ceab8f58/8f1a447aa60ad837?lnk=st&q=reporting+services+the+server+is+not+responding&rnum=3&hl=en#8f1a447aa60ad837

But this doesn't work.

I've checked both event viewer both web server and SQL server, but I can't see any information that tell me what had happened.

I also look at BOL, but doesn't help much.

Is there anyone can help me or point me to the right direction? Is there any guide document that explains step-by-step how to install SSRS in my scenario or similiar?

Many Thanks,

Usman Tjiudri

I have the exact same issue in a identical envirnonment configuration. Did you get this resolved?

I`m looking at a few articles re Kerberos....

|||Hi,

Yes, finally I got this issue resolved.
After looking for answer almost everywhere, I finally turn to Microsoft Support and they gave me a very quick response (less than 24 hours).
Before I talk about the solution, I need to clarify something here - my environment is Win2003 Server R2 (not Win2003 SP1 as mentioned in previous email) - may be there's a SP1 for R2.
The issue is caused by IIS. Apparently R2 has different version of IIS with normal Win2003 Server.
You need to uninstall completely IIS on your server (may be you need to backup IIS metadata) and install IIS for R2. You can get the software from R2 disc.
If you still can't solve the issue, log it to Microsoft Support.

Let me know how it goes.

Hope This Help,
Usman Tjiudri

sql

INstalling sql2005 Express

I have this report while installing this product.
Something about ASP.NET. O yes, it is Vista Business.
System Configuration Check
- WMI Service Requirement (Success)
Messages
* WMI Service Requirement
* Check Passed
- MSXML Requirement (Success)
Messages
* MSXML Requirement
* Check Passed
- Operating System Minimum Level Requirement (Success)
Messages
* Operating System Minimum Level Requirement
* Check Passed
- Operating System Service Pack Level Requirement. (Success)
Messages
* Operating System Service Pack Level Requirement.
* Check Passed
- SQL Server Edition Operating System Compatibility (Success)
Messages
* SQL Server Edition Operating System Compatibility
* Check Passed
- Minimum Hardware Requirement (Success)
Messages
* Minimum Hardware Requirement
* Check Passed
- IIS Feature Requirement (Success)
Messages
* IIS Feature Requirement
* Check Passed
- Pending Reboot Requirement (Success)
Messages
* Pending Reboot Requirement
* Check Passed
- Performance Monitor Counter Requirement (Success)
Messages
* Performance Monitor Counter Requirement
* Check Passed
- Default Installation Path Permission Requirement (Success)
Messages
* Default Installation Path Permission Requirement
* Check Passed
- Internet Explorer Requirement (Success)
Messages
* Internet Explorer Requirement
* Check Passed
- COM Plus Catalog Requirement (Success)
Messages
* COM Plus Catalog Requirement
* Check Passed
- ASP.Net Version Registration Requirement (Warning)
Messages
* ASP.Net Version Registration Requirement
* Failed to find the ASP.Net Version Registration with Microsoft Internet
Information Services (IIS).
- Minimum MDAC Version Requirement (Success)
Messages
* Minimum MDAC Version Requirement
* Check Passed
- Edition Change Check (Success)
Messages
* Edition Change Check
* Check Passed
ThanksMark,
You will either need to enable ASP on II6 (Disabled by default) or register
it so you can then enable it, to register refer
http://msdn2.microsoft.com/en-us/library/k6h9cz8h(VS.80).aspx
to enable,
Open IIS Manager > Select Web Service Extensions, select the appropiate
service and "Allow" it..
Cheers
Matt
"Markgoldin" wrote:
> I have this report while installing this product.
> Something about ASP.NET. O yes, it is Vista Business.
> System Configuration Check
> - WMI Service Requirement (Success)
> Messages
> * WMI Service Requirement
> * Check Passed
>
> - MSXML Requirement (Success)
> Messages
> * MSXML Requirement
> * Check Passed
>
> - Operating System Minimum Level Requirement (Success)
> Messages
> * Operating System Minimum Level Requirement
> * Check Passed
>
> - Operating System Service Pack Level Requirement. (Success)
> Messages
> * Operating System Service Pack Level Requirement.
> * Check Passed
>
> - SQL Server Edition Operating System Compatibility (Success)
> Messages
> * SQL Server Edition Operating System Compatibility
> * Check Passed
>
> - Minimum Hardware Requirement (Success)
> Messages
> * Minimum Hardware Requirement
> * Check Passed
>
> - IIS Feature Requirement (Success)
> Messages
> * IIS Feature Requirement
> * Check Passed
>
> - Pending Reboot Requirement (Success)
> Messages
> * Pending Reboot Requirement
> * Check Passed
>
> - Performance Monitor Counter Requirement (Success)
> Messages
> * Performance Monitor Counter Requirement
> * Check Passed
>
> - Default Installation Path Permission Requirement (Success)
> Messages
> * Default Installation Path Permission Requirement
> * Check Passed
>
> - Internet Explorer Requirement (Success)
> Messages
> * Internet Explorer Requirement
> * Check Passed
>
> - COM Plus Catalog Requirement (Success)
> Messages
> * COM Plus Catalog Requirement
> * Check Passed
>
> - ASP.Net Version Registration Requirement (Warning)
> Messages
> * ASP.Net Version Registration Requirement
> * Failed to find the ASP.Net Version Registration with Microsoft Internet
> Information Services (IIS).
>
> - Minimum MDAC Version Requirement (Success)
> Messages
> * Minimum MDAC Version Requirement
> * Check Passed
>
> - Edition Change Check (Success)
> Messages
> * Edition Change Check
> * Check Passed
>
> Thanks
>|||While I am using Vista that I dont have right now but I am opening I IS
Manager on my XP box
and I dont see Web Service Extensions. Can you please give me more details?
"Aussie Matt" <AussieMatt@.discussions.microsoft.com> wrote in message
news:0EDEC0DE-B6FE-4F75-9C77-1BC63068D9D7@.microsoft.com...
> Mark,
> You will either need to enable ASP on II6 (Disabled by default) or
> register
> it so you can then enable it, to register refer
> http://msdn2.microsoft.com/en-us/library/k6h9cz8h(VS.80).aspx
> to enable,
> Open IIS Manager > Select Web Service Extensions, select the appropiate
> service and "Allow" it..
> Cheers
> Matt
>
>
> "Markgoldin" wrote:
>> I have this report while installing this product.
>> Something about ASP.NET. O yes, it is Vista Business.
>> System Configuration Check
>> - WMI Service Requirement (Success)
>> Messages
>> * WMI Service Requirement
>> * Check Passed
>>
>> - MSXML Requirement (Success)
>> Messages
>> * MSXML Requirement
>> * Check Passed
>>
>> - Operating System Minimum Level Requirement (Success)
>> Messages
>> * Operating System Minimum Level Requirement
>> * Check Passed
>>
>> - Operating System Service Pack Level Requirement. (Success)
>> Messages
>> * Operating System Service Pack Level Requirement.
>> * Check Passed
>>
>> - SQL Server Edition Operating System Compatibility (Success)
>> Messages
>> * SQL Server Edition Operating System Compatibility
>> * Check Passed
>>
>> - Minimum Hardware Requirement (Success)
>> Messages
>> * Minimum Hardware Requirement
>> * Check Passed
>>
>> - IIS Feature Requirement (Success)
>> Messages
>> * IIS Feature Requirement
>> * Check Passed
>>
>> - Pending Reboot Requirement (Success)
>> Messages
>> * Pending Reboot Requirement
>> * Check Passed
>>
>> - Performance Monitor Counter Requirement (Success)
>> Messages
>> * Performance Monitor Counter Requirement
>> * Check Passed
>>
>> - Default Installation Path Permission Requirement (Success)
>> Messages
>> * Default Installation Path Permission Requirement
>> * Check Passed
>>
>> - Internet Explorer Requirement (Success)
>> Messages
>> * Internet Explorer Requirement
>> * Check Passed
>>
>> - COM Plus Catalog Requirement (Success)
>> Messages
>> * COM Plus Catalog Requirement
>> * Check Passed
>>
>> - ASP.Net Version Registration Requirement (Warning)
>> Messages
>> * ASP.Net Version Registration Requirement
>> * Failed to find the ASP.Net Version Registration with Microsoft
>> Internet
>> Information Services (IIS).
>>
>> - Minimum MDAC Version Requirement (Success)
>> Messages
>> * Minimum MDAC Version Requirement
>> * Check Passed
>>
>> - Edition Change Check (Success)
>> Messages
>> * Edition Change Check
>> * Check Passed
>>
>> Thanks|||Hi Mark,
What version of IIS are you running ?
...Matt
"Mark Goldin" wrote:
> While I am using Vista that I dont have right now but I am opening I IS
> Manager on my XP box
> and I dont see Web Service Extensions. Can you please give me more details?
> "Aussie Matt" <AussieMatt@.discussions.microsoft.com> wrote in message
> news:0EDEC0DE-B6FE-4F75-9C77-1BC63068D9D7@.microsoft.com...
> > Mark,
> > You will either need to enable ASP on II6 (Disabled by default) or
> > register
> > it so you can then enable it, to register refer
> >
> > http://msdn2.microsoft.com/en-us/library/k6h9cz8h(VS.80).aspx
> >
> > to enable,
> > Open IIS Manager > Select Web Service Extensions, select the appropiate
> > service and "Allow" it..
> >
> > Cheers
> >
> > Matt
> >
> >
> >
> >
> >
> > "Markgoldin" wrote:
> >
> >> I have this report while installing this product.
> >> Something about ASP.NET. O yes, it is Vista Business.
> >>
> >> System Configuration Check
> >>
> >> - WMI Service Requirement (Success)
> >> Messages
> >> * WMI Service Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - MSXML Requirement (Success)
> >> Messages
> >> * MSXML Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Operating System Minimum Level Requirement (Success)
> >> Messages
> >> * Operating System Minimum Level Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Operating System Service Pack Level Requirement. (Success)
> >> Messages
> >> * Operating System Service Pack Level Requirement.
> >>
> >> * Check Passed
> >>
> >>
> >> - SQL Server Edition Operating System Compatibility (Success)
> >> Messages
> >> * SQL Server Edition Operating System Compatibility
> >>
> >> * Check Passed
> >>
> >>
> >> - Minimum Hardware Requirement (Success)
> >> Messages
> >> * Minimum Hardware Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - IIS Feature Requirement (Success)
> >> Messages
> >> * IIS Feature Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Pending Reboot Requirement (Success)
> >> Messages
> >> * Pending Reboot Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Performance Monitor Counter Requirement (Success)
> >> Messages
> >> * Performance Monitor Counter Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Default Installation Path Permission Requirement (Success)
> >> Messages
> >> * Default Installation Path Permission Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Internet Explorer Requirement (Success)
> >> Messages
> >> * Internet Explorer Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - COM Plus Catalog Requirement (Success)
> >> Messages
> >> * COM Plus Catalog Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - ASP.Net Version Registration Requirement (Warning)
> >> Messages
> >> * ASP.Net Version Registration Requirement
> >>
> >> * Failed to find the ASP.Net Version Registration with Microsoft
> >> Internet
> >> Information Services (IIS).
> >>
> >>
> >> - Minimum MDAC Version Requirement (Success)
> >> Messages
> >> * Minimum MDAC Version Requirement
> >>
> >> * Check Passed
> >>
> >>
> >> - Edition Change Check (Success)
> >> Messages
> >> * Edition Change Check
> >>
> >> * Check Passed
> >>
> >>
> >>
> >> Thanks
> >>
>
>|||Well, on Vista it is 7. On Xp whatever comes with it.
"Aussie Matt" <AussieMatt@.discussions.microsoft.com> wrote in message
news:2F90EE6E-9D66-4671-8A94-9D39280B0F86@.microsoft.com...
> Hi Mark,
> What version of IIS are you running ?
> ...Matt
> "Mark Goldin" wrote:
>> While I am using Vista that I dont have right now but I am opening I IS
>> Manager on my XP box
>> and I dont see Web Service Extensions. Can you please give me more
>> details?
>> "Aussie Matt" <AussieMatt@.discussions.microsoft.com> wrote in message
>> news:0EDEC0DE-B6FE-4F75-9C77-1BC63068D9D7@.microsoft.com...
>> > Mark,
>> > You will either need to enable ASP on II6 (Disabled by default) or
>> > register
>> > it so you can then enable it, to register refer
>> >
>> > http://msdn2.microsoft.com/en-us/library/k6h9cz8h(VS.80).aspx
>> >
>> > to enable,
>> > Open IIS Manager > Select Web Service Extensions, select the appropiate
>> > service and "Allow" it..
>> >
>> > Cheers
>> >
>> > Matt
>> >
>> >
>> >
>> >
>> >
>> > "Markgoldin" wrote:
>> >
>> >> I have this report while installing this product.
>> >> Something about ASP.NET. O yes, it is Vista Business.
>> >>
>> >> System Configuration Check
>> >>
>> >> - WMI Service Requirement (Success)
>> >> Messages
>> >> * WMI Service Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - MSXML Requirement (Success)
>> >> Messages
>> >> * MSXML Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Operating System Minimum Level Requirement (Success)
>> >> Messages
>> >> * Operating System Minimum Level Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Operating System Service Pack Level Requirement. (Success)
>> >> Messages
>> >> * Operating System Service Pack Level Requirement.
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - SQL Server Edition Operating System Compatibility (Success)
>> >> Messages
>> >> * SQL Server Edition Operating System Compatibility
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Minimum Hardware Requirement (Success)
>> >> Messages
>> >> * Minimum Hardware Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - IIS Feature Requirement (Success)
>> >> Messages
>> >> * IIS Feature Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Pending Reboot Requirement (Success)
>> >> Messages
>> >> * Pending Reboot Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Performance Monitor Counter Requirement (Success)
>> >> Messages
>> >> * Performance Monitor Counter Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Default Installation Path Permission Requirement (Success)
>> >> Messages
>> >> * Default Installation Path Permission Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Internet Explorer Requirement (Success)
>> >> Messages
>> >> * Internet Explorer Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - COM Plus Catalog Requirement (Success)
>> >> Messages
>> >> * COM Plus Catalog Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - ASP.Net Version Registration Requirement (Warning)
>> >> Messages
>> >> * ASP.Net Version Registration Requirement
>> >>
>> >> * Failed to find the ASP.Net Version Registration with Microsoft
>> >> Internet
>> >> Information Services (IIS).
>> >>
>> >>
>> >> - Minimum MDAC Version Requirement (Success)
>> >> Messages
>> >> * Minimum MDAC Version Requirement
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >> - Edition Change Check (Success)
>> >> Messages
>> >> * Edition Change Check
>> >>
>> >> * Check Passed
>> >>
>> >>
>> >>
>> >> Thanks
>> >>
>>|||I have no clue what do I need to do on my Vista to make RS running, not even
running, at least get installed.
I think it's time for a modern OS to have "Format hard drive" as addition to
Ok, Cancel.
"Aussie Matt" <AussieMatt@.discussions.microsoft.com> wrote in message
news:0EDEC0DE-B6FE-4F75-9C77-1BC63068D9D7@.microsoft.com...
> Mark,
> You will either need to enable ASP on II6 (Disabled by default) or
> register
> it so you can then enable it, to register refer
> http://msdn2.microsoft.com/en-us/library/k6h9cz8h(VS.80).aspx
> to enable,
> Open IIS Manager > Select Web Service Extensions, select the appropiate
> service and "Allow" it..
> Cheers
> Matt
>
>
> "Markgoldin" wrote:
>> I have this report while installing this product.
>> Something about ASP.NET. O yes, it is Vista Business.
>> System Configuration Check
>> - WMI Service Requirement (Success)
>> Messages
>> * WMI Service Requirement
>> * Check Passed
>>
>> - MSXML Requirement (Success)
>> Messages
>> * MSXML Requirement
>> * Check Passed
>>
>> - Operating System Minimum Level Requirement (Success)
>> Messages
>> * Operating System Minimum Level Requirement
>> * Check Passed
>>
>> - Operating System Service Pack Level Requirement. (Success)
>> Messages
>> * Operating System Service Pack Level Requirement.
>> * Check Passed
>>
>> - SQL Server Edition Operating System Compatibility (Success)
>> Messages
>> * SQL Server Edition Operating System Compatibility
>> * Check Passed
>>
>> - Minimum Hardware Requirement (Success)
>> Messages
>> * Minimum Hardware Requirement
>> * Check Passed
>>
>> - IIS Feature Requirement (Success)
>> Messages
>> * IIS Feature Requirement
>> * Check Passed
>>
>> - Pending Reboot Requirement (Success)
>> Messages
>> * Pending Reboot Requirement
>> * Check Passed
>>
>> - Performance Monitor Counter Requirement (Success)
>> Messages
>> * Performance Monitor Counter Requirement
>> * Check Passed
>>
>> - Default Installation Path Permission Requirement (Success)
>> Messages
>> * Default Installation Path Permission Requirement
>> * Check Passed
>>
>> - Internet Explorer Requirement (Success)
>> Messages
>> * Internet Explorer Requirement
>> * Check Passed
>>
>> - COM Plus Catalog Requirement (Success)
>> Messages
>> * COM Plus Catalog Requirement
>> * Check Passed
>>
>> - ASP.Net Version Registration Requirement (Warning)
>> Messages
>> * ASP.Net Version Registration Requirement
>> * Failed to find the ASP.Net Version Registration with Microsoft
>> Internet
>> Information Services (IIS).
>>
>> - Minimum MDAC Version Requirement (Success)
>> Messages
>> * Minimum MDAC Version Requirement
>> * Check Passed
>>
>> - Edition Change Check (Success)
>> Messages
>> * Edition Change Check
>> * Check Passed
>>
>> Thanks

Friday, March 23, 2012

Installing SQL Server Reporting Services

Current machine Windows XP Pro with sp2. Successfully installed all portions
of Reporting Services with exception to Report Designer to SQL Server 2000.
The message which appears at almost the conclusion of installation states
"There is a problem with this Windows Installer package. A program run as
part of the setup did not finish as expected. Contact your support personnel
or package vendor.". Then it rolls back the installation.
Looking through the Event Logs it shows there was an error registered due to
the msvcr71.dll. The error value is:
Error value: C0000013
Disk type: 5
This file is on the CD for the Reporting Services and it should not be
damaged, in use, etc. by any other process other than that of the installer.
After installing all but the designer, I even installed service pack 1 for
Reporting Services and still have the same result.
Ideas?
Your thoughts on this matter will be appreciated.Just wanted to post the resolution to the situation below.
From the event log it showed that it had a problem with the msvcr71.dll.
Comparing the datetime of the file on the CD to that of the system, they were
different.
So I copied the contents of the CD to the hard drive to point to the older
file to see if it would help. The result, it did not help so I put the
original file from the CD back into the Reportin Services install directory
of my hard drive.
In reading other posts regarding installs, there was a file mentioned in the
01SEP2004 post by Daniel Reib [MSFT] to an 'install problem' (original
subject for posting), which was RSRun.msi.
I installed this file with Visual Studio .NET open and within a project. It
seemed to be having a problem without VS.NET being open, at least on 2
machines. In the past attempts the event log showed that it was having a
problem starting up the VS.NET and that is why I opened the application and
project while installing. The install was successful and the Report Designer
is working.
Hope this helps some other people that experienced a similar issue.
-Guy
"Guy G" wrote:
> Current machine Windows XP Pro with sp2. Successfully installed all portions
> of Reporting Services with exception to Report Designer to SQL Server 2000.
> The message which appears at almost the conclusion of installation states
> "There is a problem with this Windows Installer package. A program run as
> part of the setup did not finish as expected. Contact your support personnel
> or package vendor.". Then it rolls back the installation.
> Looking through the Event Logs it shows there was an error registered due to
> the msvcr71.dll. The error value is:
> Error value: C0000013
> Disk type: 5
> This file is on the CD for the Reporting Services and it should not be
> damaged, in use, etc. by any other process other than that of the installer.
> After installing all but the designer, I even installed service pack 1 for
> Reporting Services and still have the same result.
> Ideas?
> Your thoughts on this matter will be appreciated.
>

Monday, March 19, 2012

Integrated Security Problem

We are trying to control the access an individual user has to a report, for
example: 1) Bob has access to the customer report; 2) Judy has access to
all the reports; and 3) James has access only to the vendor report.
In order to accomplish this we are trying to use 'Integrated Security'
credentialing for out Data Sources. When we try to access reports after
setting 'Inetgrated Security', we get the error: "Login failed for user
'(null)'. Reason: Not associated with a trusted SQL Server connection."
It appears that the user's credentials are not being passed from the Web
Server to the SQL Server when trying to access the reports, however, Report
Manager functions perfectly. Both the Web Server and SQL Server are running
on Windows 2003 Server.
What can we do configure the Report Server so it behaves like Report
Manager?
Thanks,
TomHello Tom,
To understand the issue better, I'd like to know how users access the
reports. Do they access reports via remport manager or via a customized web
application that using report server?
If the issue occurs within report manager when users try to access the
report, it seems that this is caused by the configuration of the credential
to access the data source of the specific reports.
I suggest that you configure the shared or custome data source of the
reports with the following configuration:
1. credentials supplied by the user running the report.
Each user need to input crediential to access data source each time.
2. Credential stored securely in the report server.
Report server save this credential and use this credential to access data
source no matter which user request the report
3. Windows NT Integrated security.
Each client use his log on credential to access data source of the reports.
You have to add login for the domain account and create users/grant
permission on the database the report requsts.
It seems that you check "Windows NT Integrated security" but the client
domain user does not have proper login added on the data source sql server
for the specific reports.
Thanks & Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Partner Support
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
| From: "Tom Bean" <tbean@.newsgroup.nospam>
| Subject: Integrated Security Problem
| Date: Tue, 16 Aug 2005 16:37:27 -0500
| Lines: 21
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| X-RFC2646: Format=Flowed; Original
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| Newsgroups: microsoft.public.sqlserver.reportingsvcs
| NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.sqlserver.reportingsvcs:50514
| X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
|
| We are trying to control the access an individual user has to a report,
for
| example: 1) Bob has access to the customer report; 2) Judy has access
to
| all the reports; and 3) James has access only to the vendor report.
|
| In order to accomplish this we are trying to use 'Integrated Security'
| credentialing for out Data Sources. When we try to access reports after
| setting 'Inetgrated Security', we get the error: "Login failed for user
| '(null)'. Reason: Not associated with a trusted SQL Server connection."
|
| It appears that the user's credentials are not being passed from the Web
| Server to the SQL Server when trying to access the reports, however,
Report
| Manager functions perfectly. Both the Web Server and SQL Server are
running
| on Windows 2003 Server.
|
| What can we do configure the Report Server so it behaves like Report
| Manager?
|
| Thanks,
| Tom
|
|
||||Peter,
Our users need to access reports via the ReportServer web site, i.e.
http://domain/ReportServer, customized web applications, and Windows
applications. In addition, a few users need to access reports with Report
Manager to set the report properties and security.
We need to use Integrated Security to control a user's access to a
particular report, however, we can't get this to work.
For example, one of the reports has its data sources set up with these
options selected: 'A custom data source', "Connection Type: Microsoft SQL
Server', 'Connection String: data source=Dev01Sql;initial catalog=Vendor',
'Windows NT Integrated Security'.
I am an administrator for Dev01Sql and can access every database on the
server, but when I try to run the report from Report Manager or from the
ReportServer web site, I get the Reporting Services Error page with the
message "Login failed for user '(null)'. Reason: Not associated with a
trusted SQL Server connection."
Since Report Manager is accessing the ReportServer and ReportServerTempDB on
Dev01Sql using my credentials, I don't understand why the report cannot be
rendered. Is there some setting for the ReportServer web site that can be
changed to allow the same access to render the reports that Report Manager
has?
Thanks,
Tom
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
> Hello Tom,
> To understand the issue better, I'd like to know how users access the
> reports. Do they access reports via remport manager or via a customized
> web
> application that using report server?
> If the issue occurs within report manager when users try to access the
> report, it seems that this is caused by the configuration of the
> credential
> to access the data source of the specific reports.
> I suggest that you configure the shared or custome data source of the
> reports with the following configuration:
> 1. credentials supplied by the user running the report.
> Each user need to input crediential to access data source each time.
> 2. Credential stored securely in the report server.
> Report server save this credential and use this credential to access data
> source no matter which user request the report
> 3. Windows NT Integrated security.
> Each client use his log on credential to access data source of the
> reports.
> You have to add login for the domain account and create users/grant
> permission on the database the report requsts.
> It seems that you check "Windows NT Integrated security" but the client
> domain user does not have proper login added on the data source sql server
> for the specific reports.
> Thanks & Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Partner Support
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> =====================================================>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> --
> | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | Subject: Integrated Security Problem
> | Date: Tue, 16 Aug 2005 16:37:27 -0500
> | Lines: 21
> | X-Priority: 3
> | X-MSMail-Priority: Normal
> | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | X-RFC2646: Format=Flowed; Original
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
> | Xref: TK2MSFTNGXA01.phx.gbl
> microsoft.public.sqlserver.reportingsvcs:50514
> | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> |
> | We are trying to control the access an individual user has to a report,
> for
> | example: 1) Bob has access to the customer report; 2) Judy has access
> to
> | all the reports; and 3) James has access only to the vendor report.
> |
> | In order to accomplish this we are trying to use 'Integrated Security'
> | credentialing for out Data Sources. When we try to access reports after
> | setting 'Inetgrated Security', we get the error: "Login failed for user
> | '(null)'. Reason: Not associated with a trusted SQL Server connection."
> |
> | It appears that the user's credentials are not being passed from the Web
> | Server to the SQL Server when trying to access the reports, however,
> Report
> | Manager functions perfectly. Both the Web Server and SQL Server are
> running
> | on Windows 2003 Server.
> |
> | What can we do configure the Report Server so it behaves like Report
> | Manager?
> |
> | Thanks,
> | Tom
> |
> |
> |
>|||Hello Tom,
It seems that your credential only has permssion on ReportServer and
ReportServerTempDB other than the data source of the report itself.
Please double check if you could connect to the SQL server hosting the data
source of the report itself by using Query Analyzer. I assume it is a
different server from the report server. If not, please add your domain
accunt to the login of the server and add the proper database user mapping
to the login.
Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Partner Support
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
| From: "Tom Bean" <tbean@.newsgroup.nospam>
| References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
<Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| Subject: Re: Integrated Security Problem
| Date: Wed, 17 Aug 2005 14:33:04 -0500
| Lines: 131
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| X-RFC2646: Format=Flowed; Original
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| Newsgroups: microsoft.public.sqlserver.reportingsvcs
| NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.sqlserver.reportingsvcs:50575
| X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
|
| Peter,
|
| Our users need to access reports via the ReportServer web site, i.e.
| http://domain/ReportServer, customized web applications, and Windows
| applications. In addition, a few users need to access reports with
Report
| Manager to set the report properties and security.
|
| We need to use Integrated Security to control a user's access to a
| particular report, however, we can't get this to work.
|
| For example, one of the reports has its data sources set up with these
| options selected: 'A custom data source', "Connection Type: Microsoft
SQL
| Server', 'Connection String: data source=Dev01Sql;initial
catalog=Vendor',
| 'Windows NT Integrated Security'.
|
| I am an administrator for Dev01Sql and can access every database on the
| server, but when I try to run the report from Report Manager or from the
| ReportServer web site, I get the Reporting Services Error page with the
| message "Login failed for user '(null)'. Reason: Not associated with a
| trusted SQL Server connection."
|
| Since Report Manager is accessing the ReportServer and ReportServerTempDB
on
| Dev01Sql using my credentials, I don't understand why the report cannot
be
| rendered. Is there some setting for the ReportServer web site that can
be
| changed to allow the same access to render the reports that Report
Manager
| has?
|
| Thanks,
| Tom
|
|
| "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
| > Hello Tom,
| >
| > To understand the issue better, I'd like to know how users access the
| > reports. Do they access reports via remport manager or via a customized
| > web
| > application that using report server?
| >
| > If the issue occurs within report manager when users try to access the
| > report, it seems that this is caused by the configuration of the
| > credential
| > to access the data source of the specific reports.
| >
| > I suggest that you configure the shared or custome data source of the
| > reports with the following configuration:
| >
| > 1. credentials supplied by the user running the report.
| >
| > Each user need to input crediential to access data source each time.
| >
| > 2. Credential stored securely in the report server.
| >
| > Report server save this credential and use this credential to access
data
| > source no matter which user request the report
| >
| > 3. Windows NT Integrated security.
| >
| > Each client use his log on credential to access data source of the
| > reports.
| > You have to add login for the domain account and create users/grant
| > permission on the database the report requsts.
| >
| > It seems that you check "Windows NT Integrated security" but the client
| > domain user does not have proper login added on the data source sql
server
| > for the specific reports.
| >
| > Thanks & Regards,
| >
| > Peter Yang
| > MCSE2000/2003, MCSA, MCDBA
| > Microsoft Online Partner Support
| >
| > When responding to posts, please "Reply to Group" via your newsreader so
| > that others may learn and benefit from your issue.
| >
| > =====================================================| >
| >
| > This posting is provided "AS IS" with no warranties, and confers no
| > rights.
| >
| >
| > --
| > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | Subject: Integrated Security Problem
| > | Date: Tue, 16 Aug 2005 16:37:27 -0500
| > | Lines: 21
| > | X-Priority: 3
| > | X-MSMail-Priority: Normal
| > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | X-RFC2646: Format=Flowed; Original
| > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
| > | Xref: TK2MSFTNGXA01.phx.gbl
| > microsoft.public.sqlserver.reportingsvcs:50514
| > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > |
| > | We are trying to control the access an individual user has to a
report,
| > for
| > | example: 1) Bob has access to the customer report; 2) Judy has
access
| > to
| > | all the reports; and 3) James has access only to the vendor report.
| > |
| > | In order to accomplish this we are trying to use 'Integrated Security'
| > | credentialing for out Data Sources. When we try to access reports
after
| > | setting 'Inetgrated Security', we get the error: "Login failed for
user
| > | '(null)'. Reason: Not associated with a trusted SQL Server
connection."
| > |
| > | It appears that the user's credentials are not being passed from the
Web
| > | Server to the SQL Server when trying to access the reports, however,
| > Report
| > | Manager functions perfectly. Both the Web Server and SQL Server are
| > running
| > | on Windows 2003 Server.
| > |
| > | What can we do configure the Report Server so it behaves like Report
| > | Manager?
| > |
| > | Thanks,
| > | Tom
| > |
| > |
| > |
| >
|
|
||||Peter,
As I told you in my previous message, I am an administrator on the SQL
Server hosting all the databases used to manage and render the reports. I
can access every database on the server. Therefore, that is not the
problem.
Do you have any other suggestions?
Tom
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> Hello Tom,
> It seems that your credential only has permssion on ReportServer and
> ReportServerTempDB other than the data source of the report itself.
> Please double check if you could connect to the SQL server hosting the
> data
> source of the report itself by using Query Analyzer. I assume it is a
> different server from the report server. If not, please add your domain
> accunt to the login of the server and add the proper database user mapping
> to the login.
> Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Partner Support
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> =====================================================>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> --
> | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> | Subject: Re: Integrated Security Problem
> | Date: Wed, 17 Aug 2005 14:33:04 -0500
> | Lines: 131
> | X-Priority: 3
> | X-MSMail-Priority: Normal
> | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | X-RFC2646: Format=Flowed; Original
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
> | Xref: TK2MSFTNGXA01.phx.gbl
> microsoft.public.sqlserver.reportingsvcs:50575
> | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> |
> | Peter,
> |
> | Our users need to access reports via the ReportServer web site, i.e.
> | http://domain/ReportServer, customized web applications, and Windows
> | applications. In addition, a few users need to access reports with
> Report
> | Manager to set the report properties and security.
> |
> | We need to use Integrated Security to control a user's access to a
> | particular report, however, we can't get this to work.
> |
> | For example, one of the reports has its data sources set up with these
> | options selected: 'A custom data source', "Connection Type: Microsoft
> SQL
> | Server', 'Connection String: data source=Dev01Sql;initial
> catalog=Vendor',
> | 'Windows NT Integrated Security'.
> |
> | I am an administrator for Dev01Sql and can access every database on the
> | server, but when I try to run the report from Report Manager or from the
> | ReportServer web site, I get the Reporting Services Error page with the
> | message "Login failed for user '(null)'. Reason: Not associated with a
> | trusted SQL Server connection."
> |
> | Since Report Manager is accessing the ReportServer and
> ReportServerTempDB
> on
> | Dev01Sql using my credentials, I don't understand why the report cannot
> be
> | rendered. Is there some setting for the ReportServer web site that can
> be
> | changed to allow the same access to render the reports that Report
> Manager
> | has?
> |
> | Thanks,
> | Tom
> |
> |
> | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
> | > Hello Tom,
> | >
> | > To understand the issue better, I'd like to know how users access the
> | > reports. Do they access reports via remport manager or via a
> customized
> | > web
> | > application that using report server?
> | >
> | > If the issue occurs within report manager when users try to access the
> | > report, it seems that this is caused by the configuration of the
> | > credential
> | > to access the data source of the specific reports.
> | >
> | > I suggest that you configure the shared or custome data source of the
> | > reports with the following configuration:
> | >
> | > 1. credentials supplied by the user running the report.
> | >
> | > Each user need to input crediential to access data source each time.
> | >
> | > 2. Credential stored securely in the report server.
> | >
> | > Report server save this credential and use this credential to access
> data
> | > source no matter which user request the report
> | >
> | > 3. Windows NT Integrated security.
> | >
> | > Each client use his log on credential to access data source of the
> | > reports.
> | > You have to add login for the domain account and create users/grant
> | > permission on the database the report requsts.
> | >
> | > It seems that you check "Windows NT Integrated security" but the
> client
> | > domain user does not have proper login added on the data source sql
> server
> | > for the specific reports.
> | >
> | > Thanks & Regards,
> | >
> | > Peter Yang
> | > MCSE2000/2003, MCSA, MCDBA
> | > Microsoft Online Partner Support
> | >
> | > When responding to posts, please "Reply to Group" via your newsreader
> so
> | > that others may learn and benefit from your issue.
> | >
> | > =====================================================> | >
> | >
> | > This posting is provided "AS IS" with no warranties, and confers no
> | > rights.
> | >
> | >
> | > --
> | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | Subject: Integrated Security Problem
> | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
> | > | Lines: 21
> | > | X-Priority: 3
> | > | X-MSMail-Priority: Normal
> | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | X-RFC2646: Format=Flowed; Original
> | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | Path:
> TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
> | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > microsoft.public.sqlserver.reportingsvcs:50514
> | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > |
> | > | We are trying to control the access an individual user has to a
> report,
> | > for
> | > | example: 1) Bob has access to the customer report; 2) Judy has
> access
> | > to
> | > | all the reports; and 3) James has access only to the vendor report.
> | > |
> | > | In order to accomplish this we are trying to use 'Integrated
> Security'
> | > | credentialing for out Data Sources. When we try to access reports
> after
> | > | setting 'Inetgrated Security', we get the error: "Login failed for
> user
> | > | '(null)'. Reason: Not associated with a trusted SQL Server
> connection."
> | > |
> | > | It appears that the user's credentials are not being passed from the
> Web
> | > | Server to the SQL Server when trying to access the reports, however,
> | > Report
> | > | Manager functions perfectly. Both the Web Server and SQL Server are
> | > running
> | > | on Windows 2003 Server.
> | > |
> | > | What can we do configure the Report Server so it behaves like Report
> | > | Manager?
> | > |
> | > | Thanks,
> | > | Tom
> | > |
> | > |
> | > |
> | >
> |
> |
> |
>|||Hello Tom,
Going forward, I'd like to know the following information:
1. Which identity the applciation pool uses for the default web
site/reporting service? Is it Network service? If you temporarily add
Network service account or any identity for the applicaiton pool into local
admin groups, does it make any difference?
2. Did you try to run Query Analyzer to connect to the data source of the
specific report by using Windows authentication, is there any problem?
3. Did you check in reporting service log to see if there is any detailed
errors for this problem?
4. Does the issue occur with all domain users with local admin rights and
SQL server admin rights?
Thanks & Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Partner Support
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
| From: "Tom Bean" <tbean@.newsgroup.nospam>
| References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
<Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
<#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
<vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
| Subject: Re: Integrated Security Problem
| Date: Thu, 18 Aug 2005 10:06:55 -0500
| Lines: 217
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| X-RFC2646: Format=Flowed; Original
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| Message-ID: <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
| Newsgroups: microsoft.public.sqlserver.reportingsvcs
| NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.sqlserver.reportingsvcs:50644
| X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
|
| Peter,
|
| As I told you in my previous message, I am an administrator on the SQL
| Server hosting all the databases used to manage and render the reports.
I
| can access every database on the server. Therefore, that is not the
| problem.
|
| Do you have any other suggestions?
|
| Tom
|
| "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
| > Hello Tom,
| >
| > It seems that your credential only has permssion on ReportServer and
| > ReportServerTempDB other than the data source of the report itself.
| >
| > Please double check if you could connect to the SQL server hosting the
| > data
| > source of the report itself by using Query Analyzer. I assume it is a
| > different server from the report server. If not, please add your domain
| > accunt to the login of the server and add the proper database user
mapping
| > to the login.
| >
| > Regards,
| >
| > Peter Yang
| > MCSE2000/2003, MCSA, MCDBA
| > Microsoft Online Partner Support
| >
| > When responding to posts, please "Reply to Group" via your newsreader so
| > that others may learn and benefit from your issue.
| >
| > =====================================================| >
| >
| > This posting is provided "AS IS" with no warranties, and confers no
| > rights.
| >
| >
| > --
| > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| > | Subject: Re: Integrated Security Problem
| > | Date: Wed, 17 Aug 2005 14:33:04 -0500
| > | Lines: 131
| > | X-Priority: 3
| > | X-MSMail-Priority: Normal
| > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | X-RFC2646: Format=Flowed; Original
| > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
| > | Xref: TK2MSFTNGXA01.phx.gbl
| > microsoft.public.sqlserver.reportingsvcs:50575
| > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > |
| > | Peter,
| > |
| > | Our users need to access reports via the ReportServer web site, i.e.
| > | http://domain/ReportServer, customized web applications, and Windows
| > | applications. In addition, a few users need to access reports with
| > Report
| > | Manager to set the report properties and security.
| > |
| > | We need to use Integrated Security to control a user's access to a
| > | particular report, however, we can't get this to work.
| > |
| > | For example, one of the reports has its data sources set up with these
| > | options selected: 'A custom data source', "Connection Type: Microsoft
| > SQL
| > | Server', 'Connection String: data source=Dev01Sql;initial
| > catalog=Vendor',
| > | 'Windows NT Integrated Security'.
| > |
| > | I am an administrator for Dev01Sql and can access every database on
the
| > | server, but when I try to run the report from Report Manager or from
the
| > | ReportServer web site, I get the Reporting Services Error page with
the
| > | message "Login failed for user '(null)'. Reason: Not associated with a
| > | trusted SQL Server connection."
| > |
| > | Since Report Manager is accessing the ReportServer and
| > ReportServerTempDB
| > on
| > | Dev01Sql using my credentials, I don't understand why the report
cannot
| > be
| > | rendered. Is there some setting for the ReportServer web site that
can
| > be
| > | changed to allow the same access to render the reports that Report
| > Manager
| > | has?
| > |
| > | Thanks,
| > | Tom
| > |
| > |
| > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| > | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
| > | > Hello Tom,
| > | >
| > | > To understand the issue better, I'd like to know how users access
the
| > | > reports. Do they access reports via remport manager or via a
| > customized
| > | > web
| > | > application that using report server?
| > | >
| > | > If the issue occurs within report manager when users try to access
the
| > | > report, it seems that this is caused by the configuration of the
| > | > credential
| > | > to access the data source of the specific reports.
| > | >
| > | > I suggest that you configure the shared or custome data source of
the
| > | > reports with the following configuration:
| > | >
| > | > 1. credentials supplied by the user running the report.
| > | >
| > | > Each user need to input crediential to access data source each time.
| > | >
| > | > 2. Credential stored securely in the report server.
| > | >
| > | > Report server save this credential and use this credential to access
| > data
| > | > source no matter which user request the report
| > | >
| > | > 3. Windows NT Integrated security.
| > | >
| > | > Each client use his log on credential to access data source of the
| > | > reports.
| > | > You have to add login for the domain account and create users/grant
| > | > permission on the database the report requsts.
| > | >
| > | > It seems that you check "Windows NT Integrated security" but the
| > client
| > | > domain user does not have proper login added on the data source sql
| > server
| > | > for the specific reports.
| > | >
| > | > Thanks & Regards,
| > | >
| > | > Peter Yang
| > | > MCSE2000/2003, MCSA, MCDBA
| > | > Microsoft Online Partner Support
| > | >
| > | > When responding to posts, please "Reply to Group" via your
newsreader
| > so
| > | > that others may learn and benefit from your issue.
| > | >
| > | > =====================================================| > | >
| > | >
| > | > This posting is provided "AS IS" with no warranties, and confers no
| > | > rights.
| > | >
| > | >
| > | > --
| > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | > | Subject: Integrated Security Problem
| > | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
| > | > | Lines: 21
| > | > | X-Priority: 3
| > | > | X-MSMail-Priority: Normal
| > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | > | X-RFC2646: Format=Flowed; Original
| > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | > | Path:
| > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
| > | > | Xref: TK2MSFTNGXA01.phx.gbl
| > | > microsoft.public.sqlserver.reportingsvcs:50514
| > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > | > |
| > | > | We are trying to control the access an individual user has to a
| > report,
| > | > for
| > | > | example: 1) Bob has access to the customer report; 2) Judy has
| > access
| > | > to
| > | > | all the reports; and 3) James has access only to the vendor
report.
| > | > |
| > | > | In order to accomplish this we are trying to use 'Integrated
| > Security'
| > | > | credentialing for out Data Sources. When we try to access reports
| > after
| > | > | setting 'Inetgrated Security', we get the error: "Login failed
for
| > user
| > | > | '(null)'. Reason: Not associated with a trusted SQL Server
| > connection."
| > | > |
| > | > | It appears that the user's credentials are not being passed from
the
| > Web
| > | > | Server to the SQL Server when trying to access the reports,
however,
| > | > Report
| > | > | Manager functions perfectly. Both the Web Server and SQL Server
are
| > | > running
| > | > | on Windows 2003 Server.
| > | > |
| > | > | What can we do configure the Report Server so it behaves like
Report
| > | > | Manager?
| > | > |
| > | > | Thanks,
| > | > | Tom
| > | > |
| > | > |
| > | > |
| > | >
| > |
| > |
| > |
| >
|
|
||||Peter,
The answers to your questions are:
1. The application pool for the web site is running under NetworkService.
We added NetworkService to the local admin group and it still doesn't work.
2. We have connected to the databases used by the reports with Query
Analyzer using Windows authentication with no problem. We did this logged
on as users with permissions ranging from Users to Administrators.
In addition, when we set up the 'Connect Using' property of the data sources
to 'The credentials supplied by the user running the report' and check 'Use
as Windows credentials when connecting to the data source', we can supply
the same login name and password as the used to start Windows and
successfully render the report.
3. I checked the reporting service log and found many entries in the
ExecutionLogs table that failed with a StatusCode = 101
(rsProcessingAborted) but couldn't find any detailed information about what
caused the failure.
4. Yes, the problem occurs with all domain users with local admin rights
and SQL server admin rights.
Thanks,
Tom
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> Hello Tom,
> Going forward, I'd like to know the following information:
> 1. Which identity the applciation pool uses for the default web
> site/reporting service? Is it Network service? If you temporarily add
> Network service account or any identity for the applicaiton pool into
> local
> admin groups, does it make any difference?
> 2. Did you try to run Query Analyzer to connect to the data source of the
> specific report by using Windows authentication, is there any problem?
> 3. Did you check in reporting service log to see if there is any detailed
> errors for this problem?
> 4. Does the issue occur with all domain users with local admin rights and
> SQL server admin rights?
> Thanks & Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Partner Support
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> =====================================================>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> --
> | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> | Subject: Re: Integrated Security Problem
> | Date: Thu, 18 Aug 2005 10:06:55 -0500
> | Lines: 217
> | X-Priority: 3
> | X-MSMail-Priority: Normal
> | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | X-RFC2646: Format=Flowed; Original
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | Message-ID: <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
> | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
> | Xref: TK2MSFTNGXA01.phx.gbl
> microsoft.public.sqlserver.reportingsvcs:50644
> | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> |
> | Peter,
> |
> | As I told you in my previous message, I am an administrator on the SQL
> | Server hosting all the databases used to manage and render the reports.
> I
> | can access every database on the server. Therefore, that is not the
> | problem.
> |
> | Do you have any other suggestions?
> |
> | Tom
> |
> | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> | > Hello Tom,
> | >
> | > It seems that your credential only has permssion on ReportServer and
> | > ReportServerTempDB other than the data source of the report itself.
> | >
> | > Please double check if you could connect to the SQL server hosting the
> | > data
> | > source of the report itself by using Query Analyzer. I assume it is a
> | > different server from the report server. If not, please add your
> domain
> | > accunt to the login of the server and add the proper database user
> mapping
> | > to the login.
> | >
> | > Regards,
> | >
> | > Peter Yang
> | > MCSE2000/2003, MCSA, MCDBA
> | > Microsoft Online Partner Support
> | >
> | > When responding to posts, please "Reply to Group" via your newsreader
> so
> | > that others may learn and benefit from your issue.
> | >
> | > =====================================================> | >
> | >
> | > This posting is provided "AS IS" with no warranties, and confers no
> | > rights.
> | >
> | >
> | > --
> | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> | > | Subject: Re: Integrated Security Problem
> | > | Date: Wed, 17 Aug 2005 14:33:04 -0500
> | > | Lines: 131
> | > | X-Priority: 3
> | > | X-MSMail-Priority: Normal
> | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | X-RFC2646: Format=Flowed; Original
> | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | Path:
> TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
> | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > microsoft.public.sqlserver.reportingsvcs:50575
> | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > |
> | > | Peter,
> | > |
> | > | Our users need to access reports via the ReportServer web site, i.e.
> | > | http://domain/ReportServer, customized web applications, and Windows
> | > | applications. In addition, a few users need to access reports with
> | > Report
> | > | Manager to set the report properties and security.
> | > |
> | > | We need to use Integrated Security to control a user's access to a
> | > | particular report, however, we can't get this to work.
> | > |
> | > | For example, one of the reports has its data sources set up with
> these
> | > | options selected: 'A custom data source', "Connection Type:
> Microsoft
> | > SQL
> | > | Server', 'Connection String: data source=Dev01Sql;initial
> | > catalog=Vendor',
> | > | 'Windows NT Integrated Security'.
> | > |
> | > | I am an administrator for Dev01Sql and can access every database on
> the
> | > | server, but when I try to run the report from Report Manager or from
> the
> | > | ReportServer web site, I get the Reporting Services Error page with
> the
> | > | message "Login failed for user '(null)'. Reason: Not associated with
> a
> | > | trusted SQL Server connection."
> | > |
> | > | Since Report Manager is accessing the ReportServer and
> | > ReportServerTempDB
> | > on
> | > | Dev01Sql using my credentials, I don't understand why the report
> cannot
> | > be
> | > | rendered. Is there some setting for the ReportServer web site that
> can
> | > be
> | > | changed to allow the same access to render the reports that Report
> | > Manager
> | > | has?
> | > |
> | > | Thanks,
> | > | Tom
> | > |
> | > |
> | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | > | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
> | > | > Hello Tom,
> | > | >
> | > | > To understand the issue better, I'd like to know how users access
> the
> | > | > reports. Do they access reports via remport manager or via a
> | > customized
> | > | > web
> | > | > application that using report server?
> | > | >
> | > | > If the issue occurs within report manager when users try to access
> the
> | > | > report, it seems that this is caused by the configuration of the
> | > | > credential
> | > | > to access the data source of the specific reports.
> | > | >
> | > | > I suggest that you configure the shared or custome data source of
> the
> | > | > reports with the following configuration:
> | > | >
> | > | > 1. credentials supplied by the user running the report.
> | > | >
> | > | > Each user need to input crediential to access data source each
> time.
> | > | >
> | > | > 2. Credential stored securely in the report server.
> | > | >
> | > | > Report server save this credential and use this credential to
> access
> | > data
> | > | > source no matter which user request the report
> | > | >
> | > | > 3. Windows NT Integrated security.
> | > | >
> | > | > Each client use his log on credential to access data source of the
> | > | > reports.
> | > | > You have to add login for the domain account and create
> users/grant
> | > | > permission on the database the report requsts.
> | > | >
> | > | > It seems that you check "Windows NT Integrated security" but the
> | > client
> | > | > domain user does not have proper login added on the data source
> sql
> | > server
> | > | > for the specific reports.
> | > | >
> | > | > Thanks & Regards,
> | > | >
> | > | > Peter Yang
> | > | > MCSE2000/2003, MCSA, MCDBA
> | > | > Microsoft Online Partner Support
> | > | >
> | > | > When responding to posts, please "Reply to Group" via your
> newsreader
> | > so
> | > | > that others may learn and benefit from your issue.
> | > | >
> | > | > =====================================================> | > | >
> | > | >
> | > | > This posting is provided "AS IS" with no warranties, and confers
> no
> | > | > rights.
> | > | >
> | > | >
> | > | > --
> | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | > | Subject: Integrated Security Problem
> | > | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
> | > | > | Lines: 21
> | > | > | X-Priority: 3
> | > | > | X-MSMail-Priority: Normal
> | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | > | X-RFC2646: Format=Flowed; Original
> | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | > | Path:
> | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
> | > | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > | > microsoft.public.sqlserver.reportingsvcs:50514
> | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > | > |
> | > | > | We are trying to control the access an individual user has to a
> | > report,
> | > | > for
> | > | > | example: 1) Bob has access to the customer report; 2) Judy has
> | > access
> | > | > to
> | > | > | all the reports; and 3) James has access only to the vendor
> report.
> | > | > |
> | > | > | In order to accomplish this we are trying to use 'Integrated
> | > Security'
> | > | > | credentialing for out Data Sources. When we try to access
> reports
> | > after
> | > | > | setting 'Inetgrated Security', we get the error: "Login failed
> for
> | > user
> | > | > | '(null)'. Reason: Not associated with a trusted SQL Server
> | > connection."
> | > | > |
> | > | > | It appears that the user's credentials are not being passed from
> the
> | > Web
> | > | > | Server to the SQL Server when trying to access the reports,
> however,
> | > | > Report
> | > | > | Manager functions perfectly. Both the Web Server and SQL Server
> are
> | > | > running
> | > | > | on Windows 2003 Server.
> | > | > |
> | > | > | What can we do configure the Report Server so it behaves like
> Report
> | > | > | Manager?
> | > | > |
> | > | > | Thanks,
> | > | > | Tom
> | > | > |
> | > | > |
> | > | > |
> | > | >
> | > |
> | > |
> | > |
> | >
> |
> |
> |
>|||Hello Tom,
Before we go further, I'd like to confirm if SQL server (data source of the
report) and IIS are in the same machine. The issue seems to be a problem
that IIS/Report server are in different machine hosting SQL server.
If it is the case, I suggest that you change the following configuration if
you are using Win2k/2k3 AD so that delegation is properly enabled
1. In AD: The Middle Computer should be trusted for delegation
2. In AD: The domain account under which SQL server is running should not
be marked as "sensitive for delegation", and "Accont is trusted for
delegation" shall be marked.
810572.KB.EN-US HOW TO: Configure an ASP.NET Application for a Delegation
Scenario
http://support.microsoft.com/default.aspx?scid=KB;EN-US;810572
For Win2003, you have to do both the above steps as under Win2k, and
additionally you have to do the following
1. In the middle computer: the domain account that IIS 6 application pool
associated with default Website MUST have Set ImpersonatePriviledge
granted. By default the application pool used by reporting services is the
deafult applciaton pool.
Note that this priviledge is new to Windows 2003.
2. The name of the privilege is "Impersonate a client after
authentication", you can grant it using Local Security Policy.
3. "Account is trusted for delegation " must be set to for above account.
Please refer to the following article for more details about
troubleshooting this issue
Troubleshooting Kerberos Delegation
http://www.microsoft.com/downloads/details.aspx?FamilyID=99b0f94f-e28a-4726-
bffe-2f64ae2f59a2&displaylang=en
How To Configure IIS to Support Both Kerberos and NTLM Authentication
http://support.microsoft.com/default.aspx?kbid=215383
Information about SQL Server 2000 Kerberos support, including SQL Server
virtual servers on server clusters
http://support.microsoft.com/?id=319723
Note: By using Windows authentication, each user access the report shall
have the proper permission on the sql server of data source.
Hope this information is helpful.
Best Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Partner Support
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
| From: "Tom Bean" <tbean@.newsgroup.nospam>
| References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
<Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
<#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
<vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
<u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
<LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl>
| Subject: Re: Integrated Security Problem
| Date: Fri, 19 Aug 2005 16:02:50 -0500
| Lines: 338
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| X-RFC2646: Format=Flowed; Original
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| Message-ID: <uf1hzFQpFHA.3512@.TK2MSFTNGP15.phx.gbl>
| Newsgroups: microsoft.public.sqlserver.reportingsvcs
| NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP15.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.sqlserver.reportingsvcs:50786
| X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
|
| Peter,
|
| The answers to your questions are:
|
| 1. The application pool for the web site is running under
NetworkService.
| We added NetworkService to the local admin group and it still doesn't
work.
|
| 2. We have connected to the databases used by the reports with Query
| Analyzer using Windows authentication with no problem. We did this
logged
| on as users with permissions ranging from Users to Administrators.
|
| In addition, when we set up the 'Connect Using' property of the data
sources
| to 'The credentials supplied by the user running the report' and check
'Use
| as Windows credentials when connecting to the data source', we can supply
| the same login name and password as the used to start Windows and
| successfully render the report.
|
| 3. I checked the reporting service log and found many entries in the
| ExecutionLogs table that failed with a StatusCode = 101
| (rsProcessingAborted) but couldn't find any detailed information about
what
| caused the failure.
|
| 4. Yes, the problem occurs with all domain users with local admin rights
| and SQL server admin rights.
|
| Thanks,
| Tom
|
| "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| news:LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl...
| > Hello Tom,
| >
| > Going forward, I'd like to know the following information:
| >
| > 1. Which identity the applciation pool uses for the default web
| > site/reporting service? Is it Network service? If you temporarily add
| > Network service account or any identity for the applicaiton pool into
| > local
| > admin groups, does it make any difference?
| >
| > 2. Did you try to run Query Analyzer to connect to the data source of
the
| > specific report by using Windows authentication, is there any problem?
| >
| > 3. Did you check in reporting service log to see if there is any
detailed
| > errors for this problem?
| >
| > 4. Does the issue occur with all domain users with local admin rights
and
| > SQL server admin rights?
| >
| > Thanks & Regards,
| >
| > Peter Yang
| > MCSE2000/2003, MCSA, MCDBA
| > Microsoft Online Partner Support
| >
| > When responding to posts, please "Reply to Group" via your newsreader so
| > that others may learn and benefit from your issue.
| >
| > =====================================================| >
| >
| >
| > This posting is provided "AS IS" with no warranties, and confers no
| > rights.
| >
| >
| > --
| > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| > <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| > <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
| > | Subject: Re: Integrated Security Problem
| > | Date: Thu, 18 Aug 2005 10:06:55 -0500
| > | Lines: 217
| > | X-Priority: 3
| > | X-MSMail-Priority: Normal
| > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | X-RFC2646: Format=Flowed; Original
| > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | Message-ID: <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
| > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| > | Xref: TK2MSFTNGXA01.phx.gbl
| > microsoft.public.sqlserver.reportingsvcs:50644
| > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > |
| > | Peter,
| > |
| > | As I told you in my previous message, I am an administrator on the SQL
| > | Server hosting all the databases used to manage and render the
reports.
| > I
| > | can access every database on the server. Therefore, that is not the
| > | problem.
| > |
| > | Do you have any other suggestions?
| > |
| > | Tom
| > |
| > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| > | news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
| > | > Hello Tom,
| > | >
| > | > It seems that your credential only has permssion on ReportServer
and
| > | > ReportServerTempDB other than the data source of the report itself.
| > | >
| > | > Please double check if you could connect to the SQL server hosting
the
| > | > data
| > | > source of the report itself by using Query Analyzer. I assume it is
a
| > | > different server from the report server. If not, please add your
| > domain
| > | > accunt to the login of the server and add the proper database user
| > mapping
| > | > to the login.
| > | >
| > | > Regards,
| > | >
| > | > Peter Yang
| > | > MCSE2000/2003, MCSA, MCDBA
| > | > Microsoft Online Partner Support
| > | >
| > | > When responding to posts, please "Reply to Group" via your
newsreader
| > so
| > | > that others may learn and benefit from your issue.
| > | >
| > | > =====================================================| > | >
| > | >
| > | > This posting is provided "AS IS" with no warranties, and confers no
| > | > rights.
| > | >
| > | >
| > | > --
| > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| > | > | Subject: Re: Integrated Security Problem
| > | > | Date: Wed, 17 Aug 2005 14:33:04 -0500
| > | > | Lines: 131
| > | > | X-Priority: 3
| > | > | X-MSMail-Priority: Normal
| > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | > | X-RFC2646: Format=Flowed; Original
| > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | > | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | > | Path:
| > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
| > | > | Xref: TK2MSFTNGXA01.phx.gbl
| > | > microsoft.public.sqlserver.reportingsvcs:50575
| > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > | > |
| > | > | Peter,
| > | > |
| > | > | Our users need to access reports via the ReportServer web site,
i.e.
| > | > | http://domain/ReportServer, customized web applications, and
Windows
| > | > | applications. In addition, a few users need to access reports
with
| > | > Report
| > | > | Manager to set the report properties and security.
| > | > |
| > | > | We need to use Integrated Security to control a user's access to a
| > | > | particular report, however, we can't get this to work.
| > | > |
| > | > | For example, one of the reports has its data sources set up with
| > these
| > | > | options selected: 'A custom data source', "Connection Type:
| > Microsoft
| > | > SQL
| > | > | Server', 'Connection String: data source=Dev01Sql;initial
| > | > catalog=Vendor',
| > | > | 'Windows NT Integrated Security'.
| > | > |
| > | > | I am an administrator for Dev01Sql and can access every database
on
| > the
| > | > | server, but when I try to run the report from Report Manager or
from
| > the
| > | > | ReportServer web site, I get the Reporting Services Error page
with
| > the
| > | > | message "Login failed for user '(null)'. Reason: Not associated
with
| > a
| > | > | trusted SQL Server connection."
| > | > |
| > | > | Since Report Manager is accessing the ReportServer and
| > | > ReportServerTempDB
| > | > on
| > | > | Dev01Sql using my credentials, I don't understand why the report
| > cannot
| > | > be
| > | > | rendered. Is there some setting for the ReportServer web site
that
| > can
| > | > be
| > | > | changed to allow the same access to render the reports that Report
| > | > Manager
| > | > | has?
| > | > |
| > | > | Thanks,
| > | > | Tom
| > | > |
| > | > |
| > | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| > | > | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
| > | > | > Hello Tom,
| > | > | >
| > | > | > To understand the issue better, I'd like to know how users
access
| > the
| > | > | > reports. Do they access reports via remport manager or via a
| > | > customized
| > | > | > web
| > | > | > application that using report server?
| > | > | >
| > | > | > If the issue occurs within report manager when users try to
access
| > the
| > | > | > report, it seems that this is caused by the configuration of the
| > | > | > credential
| > | > | > to access the data source of the specific reports.
| > | > | >
| > | > | > I suggest that you configure the shared or custome data source
of
| > the
| > | > | > reports with the following configuration:
| > | > | >
| > | > | > 1. credentials supplied by the user running the report.
| > | > | >
| > | > | > Each user need to input crediential to access data source each
| > time.
| > | > | >
| > | > | > 2. Credential stored securely in the report server.
| > | > | >
| > | > | > Report server save this credential and use this credential to
| > access
| > | > data
| > | > | > source no matter which user request the report
| > | > | >
| > | > | > 3. Windows NT Integrated security.
| > | > | >
| > | > | > Each client use his log on credential to access data source of
the
| > | > | > reports.
| > | > | > You have to add login for the domain account and create
| > users/grant
| > | > | > permission on the database the report requsts.
| > | > | >
| > | > | > It seems that you check "Windows NT Integrated security" but the
| > | > client
| > | > | > domain user does not have proper login added on the data source
| > sql
| > | > server
| > | > | > for the specific reports.
| > | > | >
| > | > | > Thanks & Regards,
| > | > | >
| > | > | > Peter Yang
| > | > | > MCSE2000/2003, MCSA, MCDBA
| > | > | > Microsoft Online Partner Support
| > | > | >
| > | > | > When responding to posts, please "Reply to Group" via your
| > newsreader
| > | > so
| > | > | > that others may learn and benefit from your issue.
| > | > | >
| > | > | > =====================================================| > | > | >
| > | > | >
| > | > | > This posting is provided "AS IS" with no warranties, and
confers
| > no
| > | > | > rights.
| > | > | >
| > | > | >
| > | > | > --
| > | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | > | > | Subject: Integrated Security Problem
| > | > | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
| > | > | > | Lines: 21
| > | > | > | X-Priority: 3
| > | > | > | X-MSMail-Priority: Normal
| > | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | > | > | X-RFC2646: Format=Flowed; Original
| > | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | > | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | > | > | Path:
| > | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
| > | > | > | Xref: TK2MSFTNGXA01.phx.gbl
| > | > | > microsoft.public.sqlserver.reportingsvcs:50514
| > | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > | > | > |
| > | > | > | We are trying to control the access an individual user has to
a
| > | > report,
| > | > | > for
| > | > | > | example: 1) Bob has access to the customer report; 2) Judy
has
| > | > access
| > | > | > to
| > | > | > | all the reports; and 3) James has access only to the vendor
| > report.
| > | > | > |
| > | > | > | In order to accomplish this we are trying to use 'Integrated
| > | > Security'
| > | > | > | credentialing for out Data Sources. When we try to access
| > reports
| > | > after
| > | > | > | setting 'Inetgrated Security', we get the error: "Login
failed
| > for
| > | > user
| > | > | > | '(null)'. Reason: Not associated with a trusted SQL Server
| > | > connection."
| > | > | > |
| > | > | > | It appears that the user's credentials are not being passed
from
| > the
| > | > Web
| > | > | > | Server to the SQL Server when trying to access the reports,
| > however,
| > | > | > Report
| > | > | > | Manager functions perfectly. Both the Web Server and SQL
Server
| > are
| > | > | > running
| > | > | > | on Windows 2003 Server.
| > | > | > |
| > | > | > | What can we do configure the Report Server so it behaves like
| > Report
| > | > | > | Manager?
| > | > | > |
| > | > | > | Thanks,
| > | > | > | Tom
| > | > | > |
| > | > | > |
| > | > | > |
| > | > | >
| > | > |
| > | > |
| > | > |
| > | >
| > |
| > |
| > |
| >
|
|
||||Peter,
Sorry I took so long getting back to you but we wanted to be sure we had
solved our problem before responding.
First, we set "Trust computer for delegation" in Active Directory for the
middle computer and the problem went away. Then, because we had tried so
many different settings, we uninstalled Reporting Services and reinstalled
it to ensure we were starting with an unmodified installation. Once
Reporting Services was reinstalled, the only change we made was to again set
"Trust computer for delegation" in Active Directory for the middle computer
and the problem was solved.
We had tried this setting before but it didn't solve the problem. The only
explanation for the setting not solving the problem the first time is that
we must have tried to access the reports before the change had time to
propogate through our network.
Thanks for your assistance. I hope this thread will save someone else some
of the headaches.
Tom
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:lIKJndspFHA.940@.TK2MSFTNGXA01.phx.gbl...
> Hello Tom,
> Before we go further, I'd like to confirm if SQL server (data source of
> the
> report) and IIS are in the same machine. The issue seems to be a problem
> that IIS/Report server are in different machine hosting SQL server.
> If it is the case, I suggest that you change the following configuration
> if
> you are using Win2k/2k3 AD so that delegation is properly enabled
> 1. In AD: The Middle Computer should be trusted for delegation
> 2. In AD: The domain account under which SQL server is running should not
> be marked as "sensitive for delegation", and "Accont is trusted for
> delegation" shall be marked.
> 810572.KB.EN-US HOW TO: Configure an ASP.NET Application for a Delegation
> Scenario
> http://support.microsoft.com/default.aspx?scid=KB;EN-US;810572
> For Win2003, you have to do both the above steps as under Win2k, and
> additionally you have to do the following
> 1. In the middle computer: the domain account that IIS 6 application
> pool
> associated with default Website MUST have Set ImpersonatePriviledge
> granted. By default the application pool used by reporting services is
> the
> deafult applciaton pool.
> Note that this priviledge is new to Windows 2003.
> 2. The name of the privilege is "Impersonate a client after
> authentication", you can grant it using Local Security Policy.
> 3. "Account is trusted for delegation " must be set to for above account.
> Please refer to the following article for more details about
> troubleshooting this issue
> Troubleshooting Kerberos Delegation
> http://www.microsoft.com/downloads/details.aspx?FamilyID=99b0f94f-e28a-4726-
> bffe-2f64ae2f59a2&displaylang=en
> How To Configure IIS to Support Both Kerberos and NTLM Authentication
> http://support.microsoft.com/default.aspx?kbid=215383
> Information about SQL Server 2000 Kerberos support, including SQL Server
> virtual servers on server clusters
> http://support.microsoft.com/?id=319723
> Note: By using Windows authentication, each user access the report shall
> have the proper permission on the sql server of data source.
> Hope this information is helpful.
> Best Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Partner Support
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> =====================================================>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> --
> | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
> <LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> | Subject: Re: Integrated Security Problem
> | Date: Fri, 19 Aug 2005 16:02:50 -0500
> | Lines: 338
> | X-Priority: 3
> | X-MSMail-Priority: Normal
> | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | X-RFC2646: Format=Flowed; Original
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | Message-ID: <uf1hzFQpFHA.3512@.TK2MSFTNGP15.phx.gbl>
> | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP15.phx.gbl
> | Xref: TK2MSFTNGXA01.phx.gbl
> microsoft.public.sqlserver.reportingsvcs:50786
> | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> |
> | Peter,
> |
> | The answers to your questions are:
> |
> | 1. The application pool for the web site is running under
> NetworkService.
> | We added NetworkService to the local admin group and it still doesn't
> work.
> |
> | 2. We have connected to the databases used by the reports with Query
> | Analyzer using Windows authentication with no problem. We did this
> logged
> | on as users with permissions ranging from Users to Administrators.
> |
> | In addition, when we set up the 'Connect Using' property of the data
> sources
> | to 'The credentials supplied by the user running the report' and check
> 'Use
> | as Windows credentials when connecting to the data source', we can
> supply
> | the same login name and password as the used to start Windows and
> | successfully render the report.
> |
> | 3. I checked the reporting service log and found many entries in the
> | ExecutionLogs table that failed with a StatusCode = 101
> | (rsProcessingAborted) but couldn't find any detailed information about
> what
> | caused the failure.
> |
> | 4. Yes, the problem occurs with all domain users with local admin
> rights
> | and SQL server admin rights.
> |
> | Thanks,
> | Tom
> |
> | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | news:LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> | > Hello Tom,
> | >
> | > Going forward, I'd like to know the following information:
> | >
> | > 1. Which identity the applciation pool uses for the default web
> | > site/reporting service? Is it Network service? If you temporarily add
> | > Network service account or any identity for the applicaiton pool into
> | > local
> | > admin groups, does it make any difference?
> | >
> | > 2. Did you try to run Query Analyzer to connect to the data source of
> the
> | > specific report by using Windows authentication, is there any problem?
> | >
> | > 3. Did you check in reporting service log to see if there is any
> detailed
> | > errors for this problem?
> | >
> | > 4. Does the issue occur with all domain users with local admin rights
> and
> | > SQL server admin rights?
> | >
> | > Thanks & Regards,
> | >
> | > Peter Yang
> | > MCSE2000/2003, MCSA, MCDBA
> | > Microsoft Online Partner Support
> | >
> | > When responding to posts, please "Reply to Group" via your newsreader
> so
> | > that others may learn and benefit from your issue.
> | >
> | > =====================================================> | >
> | >
> | >
> | > This posting is provided "AS IS" with no warranties, and confers no
> | > rights.
> | >
> | >
> | > --
> | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> | > <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> | > <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> | > | Subject: Re: Integrated Security Problem
> | > | Date: Thu, 18 Aug 2005 10:06:55 -0500
> | > | Lines: 217
> | > | X-Priority: 3
> | > | X-MSMail-Priority: Normal
> | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | X-RFC2646: Format=Flowed; Original
> | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | Message-ID: <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
> | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | Path:
> TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
> | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > microsoft.public.sqlserver.reportingsvcs:50644
> | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > |
> | > | Peter,
> | > |
> | > | As I told you in my previous message, I am an administrator on the
> SQL
> | > | Server hosting all the databases used to manage and render the
> reports.
> | > I
> | > | can access every database on the server. Therefore, that is not the
> | > | problem.
> | > |
> | > | Do you have any other suggestions?
> | > |
> | > | Tom
> | > |
> | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | > | news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> | > | > Hello Tom,
> | > | >
> | > | > It seems that your credential only has permssion on ReportServer
> and
> | > | > ReportServerTempDB other than the data source of the report
> itself.
> | > | >
> | > | > Please double check if you could connect to the SQL server hosting
> the
> | > | > data
> | > | > source of the report itself by using Query Analyzer. I assume it
> is
> a
> | > | > different server from the report server. If not, please add your
> | > domain
> | > | > accunt to the login of the server and add the proper database user
> | > mapping
> | > | > to the login.
> | > | >
> | > | > Regards,
> | > | >
> | > | > Peter Yang
> | > | > MCSE2000/2003, MCSA, MCDBA
> | > | > Microsoft Online Partner Support
> | > | >
> | > | > When responding to posts, please "Reply to Group" via your
> newsreader
> | > so
> | > | > that others may learn and benefit from your issue.
> | > | >
> | > | > =====================================================> | > | >
> | > | >
> | > | > This posting is provided "AS IS" with no warranties, and confers
> no
> | > | > rights.
> | > | >
> | > | >
> | > | > --
> | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> | > | > | Subject: Re: Integrated Security Problem
> | > | > | Date: Wed, 17 Aug 2005 14:33:04 -0500
> | > | > | Lines: 131
> | > | > | X-Priority: 3
> | > | > | X-MSMail-Priority: Normal
> | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | > | X-RFC2646: Format=Flowed; Original
> | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | > | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | > | Path:
> | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
> | > | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > | > microsoft.public.sqlserver.reportingsvcs:50575
> | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > | > |
> | > | > | Peter,
> | > | > |
> | > | > | Our users need to access reports via the ReportServer web site,
> i.e.
> | > | > | http://domain/ReportServer, customized web applications, and
> Windows
> | > | > | applications. In addition, a few users need to access reports
> with
> | > | > Report
> | > | > | Manager to set the report properties and security.
> | > | > |
> | > | > | We need to use Integrated Security to control a user's access to
> a
> | > | > | particular report, however, we can't get this to work.
> | > | > |
> | > | > | For example, one of the reports has its data sources set up with
> | > these
> | > | > | options selected: 'A custom data source', "Connection Type:
> | > Microsoft
> | > | > SQL
> | > | > | Server', 'Connection String: data source=Dev01Sql;initial
> | > | > catalog=Vendor',
> | > | > | 'Windows NT Integrated Security'.
> | > | > |
> | > | > | I am an administrator for Dev01Sql and can access every database
> on
> | > the
> | > | > | server, but when I try to run the report from Report Manager or
> from
> | > the
> | > | > | ReportServer web site, I get the Reporting Services Error page
> with
> | > the
> | > | > | message "Login failed for user '(null)'. Reason: Not associated
> with
> | > a
> | > | > | trusted SQL Server connection."
> | > | > |
> | > | > | Since Report Manager is accessing the ReportServer and
> | > | > ReportServerTempDB
> | > | > on
> | > | > | Dev01Sql using my credentials, I don't understand why the report
> | > cannot
> | > | > be
> | > | > | rendered. Is there some setting for the ReportServer web site
> that
> | > can
> | > | > be
> | > | > | changed to allow the same access to render the reports that
> Report
> | > | > Manager
> | > | > | has?
> | > | > |
> | > | > | Thanks,
> | > | > | Tom
> | > | > |
> | > | > |
> | > | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in
> message
> | > | > | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
> | > | > | > Hello Tom,
> | > | > | >
> | > | > | > To understand the issue better, I'd like to know how users
> access
> | > the
> | > | > | > reports. Do they access reports via remport manager or via a
> | > | > customized
> | > | > | > web
> | > | > | > application that using report server?
> | > | > | >
> | > | > | > If the issue occurs within report manager when users try to
> access
> | > the
> | > | > | > report, it seems that this is caused by the configuration of
> the
> | > | > | > credential
> | > | > | > to access the data source of the specific reports.
> | > | > | >
> | > | > | > I suggest that you configure the shared or custome data source
> of
> | > the
> | > | > | > reports with the following configuration:
> | > | > | >
> | > | > | > 1. credentials supplied by the user running the report.
> | > | > | >
> | > | > | > Each user need to input crediential to access data source each
> | > time.
> | > | > | >
> | > | > | > 2. Credential stored securely in the report server.
> | > | > | >
> | > | > | > Report server save this credential and use this credential to
> | > access
> | > | > data
> | > | > | > source no matter which user request the report
> | > | > | >
> | > | > | > 3. Windows NT Integrated security.
> | > | > | >
> | > | > | > Each client use his log on credential to access data source of
> the
> | > | > | > reports.
> | > | > | > You have to add login for the domain account and create
> | > users/grant
> | > | > | > permission on the database the report requsts.
> | > | > | >
> | > | > | > It seems that you check "Windows NT Integrated security" but
> the
> | > | > client
> | > | > | > domain user does not have proper login added on the data
> source
> | > sql
> | > | > server
> | > | > | > for the specific reports.
> | > | > | >
> | > | > | > Thanks & Regards,
> | > | > | >
> | > | > | > Peter Yang
> | > | > | > MCSE2000/2003, MCSA, MCDBA
> | > | > | > Microsoft Online Partner Support
> | > | > | >
> | > | > | > When responding to posts, please "Reply to Group" via your
> | > newsreader
> | > | > so
> | > | > | > that others may learn and benefit from your issue.
> | > | > | >
> | > | > | > =====================================================> | > | > | >
> | > | > | >
> | > | > | > This posting is provided "AS IS" with no warranties, and
> confers
> | > no
> | > | > | > rights.
> | > | > | >
> | > | > | >
> | > | > | > --
> | > | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | > | > | Subject: Integrated Security Problem
> | > | > | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
> | > | > | > | Lines: 21
> | > | > | > | X-Priority: 3
> | > | > | > | X-MSMail-Priority: Normal
> | > | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | > | > | X-RFC2646: Format=Flowed; Original
> | > | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | > | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | > | > | Path:
> | > | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
> | > | > | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > | > | > microsoft.public.sqlserver.reportingsvcs:50514
> | > | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > | > | > |
> | > | > | > | We are trying to control the access an individual user has
> to
> a
> | > | > report,
> | > | > | > for
> | > | > | > | example: 1) Bob has access to the customer report; 2) Judy
> has
> | > | > access
> | > | > | > to
> | > | > | > | all the reports; and 3) James has access only to the vendor
> | > report.
> | > | > | > |
> | > | > | > | In order to accomplish this we are trying to use 'Integrated
> | > | > Security'
> | > | > | > | credentialing for out Data Sources. When we try to access
> | > reports
> | > | > after
> | > | > | > | setting 'Inetgrated Security', we get the error: "Login
> failed
> | > for
> | > | > user
> | > | > | > | '(null)'. Reason: Not associated with a trusted SQL Server
> | > | > connection."
> | > | > | > |
> | > | > | > | It appears that the user's credentials are not being passed
> from
> | > the
> | > | > Web
> | > | > | > | Server to the SQL Server when trying to access the reports,
> | > however,
> | > | > | > Report
> | > | > | > | Manager functions perfectly. Both the Web Server and SQL
> Server
> | > are
> | > | > | > running
> | > | > | > | on Windows 2003 Server.
> | > | > | > |
> | > | > | > | What can we do configure the Report Server so it behaves
> like
> | > Report
> | > | > | > | Manager?
> | > | > | > |
> | > | > | > | Thanks,
> | > | > | > | Tom
> | > | > | > |
> | > | > | > |
> | > | > | > |
> | > | > | >
> | > | > |
> | > | > |
> | > | > |
> | > | >
> | > |
> | > |
> | > |
> | >
> |
> |
> |
>|||Peter,
I wonder if you could help me with another problem. I am trying to call a
static method in a custom assembly with one of my reports but get the error
"[BC30469] Reference to a non-shared member requires an object reference".
The declaration of the method I am calling is: public static string
Decrypt(string encryptedText). The only thing references used in my custom
assembly are System, System.Data, and System.XML.
I am having the same problem with calling the
System.Web.HttpUtility.UrlDecode method.
I have added references to both my custom assembly and System.Web via the
References tab in Report Properties.
I can't think of anything else to do. Please help.
Thanks,
Tom
"Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
news:lIKJndspFHA.940@.TK2MSFTNGXA01.phx.gbl...
> Hello Tom,
> Before we go further, I'd like to confirm if SQL server (data source of
> the
> report) and IIS are in the same machine. The issue seems to be a problem
> that IIS/Report server are in different machine hosting SQL server.
> If it is the case, I suggest that you change the following configuration
> if
> you are using Win2k/2k3 AD so that delegation is properly enabled
> 1. In AD: The Middle Computer should be trusted for delegation
> 2. In AD: The domain account under which SQL server is running should not
> be marked as "sensitive for delegation", and "Accont is trusted for
> delegation" shall be marked.
> 810572.KB.EN-US HOW TO: Configure an ASP.NET Application for a Delegation
> Scenario
> http://support.microsoft.com/default.aspx?scid=KB;EN-US;810572
> For Win2003, you have to do both the above steps as under Win2k, and
> additionally you have to do the following
> 1. In the middle computer: the domain account that IIS 6 application
> pool
> associated with default Website MUST have Set ImpersonatePriviledge
> granted. By default the application pool used by reporting services is
> the
> deafult applciaton pool.
> Note that this priviledge is new to Windows 2003.
> 2. The name of the privilege is "Impersonate a client after
> authentication", you can grant it using Local Security Policy.
> 3. "Account is trusted for delegation " must be set to for above account.
> Please refer to the following article for more details about
> troubleshooting this issue
> Troubleshooting Kerberos Delegation
> http://www.microsoft.com/downloads/details.aspx?FamilyID=99b0f94f-e28a-4726-
> bffe-2f64ae2f59a2&displaylang=en
> How To Configure IIS to Support Both Kerberos and NTLM Authentication
> http://support.microsoft.com/default.aspx?kbid=215383
> Information about SQL Server 2000 Kerberos support, including SQL Server
> virtual servers on server clusters
> http://support.microsoft.com/?id=319723
> Note: By using Windows authentication, each user access the report shall
> have the proper permission on the sql server of data source.
> Hope this information is helpful.
> Best Regards,
> Peter Yang
> MCSE2000/2003, MCSA, MCDBA
> Microsoft Online Partner Support
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> =====================================================>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> --
> | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
> <LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> | Subject: Re: Integrated Security Problem
> | Date: Fri, 19 Aug 2005 16:02:50 -0500
> | Lines: 338
> | X-Priority: 3
> | X-MSMail-Priority: Normal
> | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | X-RFC2646: Format=Flowed; Original
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | Message-ID: <uf1hzFQpFHA.3512@.TK2MSFTNGP15.phx.gbl>
> | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP15.phx.gbl
> | Xref: TK2MSFTNGXA01.phx.gbl
> microsoft.public.sqlserver.reportingsvcs:50786
> | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> |
> | Peter,
> |
> | The answers to your questions are:
> |
> | 1. The application pool for the web site is running under
> NetworkService.
> | We added NetworkService to the local admin group and it still doesn't
> work.
> |
> | 2. We have connected to the databases used by the reports with Query
> | Analyzer using Windows authentication with no problem. We did this
> logged
> | on as users with permissions ranging from Users to Administrators.
> |
> | In addition, when we set up the 'Connect Using' property of the data
> sources
> | to 'The credentials supplied by the user running the report' and check
> 'Use
> | as Windows credentials when connecting to the data source', we can
> supply
> | the same login name and password as the used to start Windows and
> | successfully render the report.
> |
> | 3. I checked the reporting service log and found many entries in the
> | ExecutionLogs table that failed with a StatusCode = 101
> | (rsProcessingAborted) but couldn't find any detailed information about
> what
> | caused the failure.
> |
> | 4. Yes, the problem occurs with all domain users with local admin
> rights
> | and SQL server admin rights.
> |
> | Thanks,
> | Tom
> |
> | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | news:LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> | > Hello Tom,
> | >
> | > Going forward, I'd like to know the following information:
> | >
> | > 1. Which identity the applciation pool uses for the default web
> | > site/reporting service? Is it Network service? If you temporarily add
> | > Network service account or any identity for the applicaiton pool into
> | > local
> | > admin groups, does it make any difference?
> | >
> | > 2. Did you try to run Query Analyzer to connect to the data source of
> the
> | > specific report by using Windows authentication, is there any problem?
> | >
> | > 3. Did you check in reporting service log to see if there is any
> detailed
> | > errors for this problem?
> | >
> | > 4. Does the issue occur with all domain users with local admin rights
> and
> | > SQL server admin rights?
> | >
> | > Thanks & Regards,
> | >
> | > Peter Yang
> | > MCSE2000/2003, MCSA, MCDBA
> | > Microsoft Online Partner Support
> | >
> | > When responding to posts, please "Reply to Group" via your newsreader
> so
> | > that others may learn and benefit from your issue.
> | >
> | > =====================================================> | >
> | >
> | >
> | > This posting is provided "AS IS" with no warranties, and confers no
> | > rights.
> | >
> | >
> | > --
> | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> | > <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> | > <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
> | > | Subject: Re: Integrated Security Problem
> | > | Date: Thu, 18 Aug 2005 10:06:55 -0500
> | > | Lines: 217
> | > | X-Priority: 3
> | > | X-MSMail-Priority: Normal
> | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | X-RFC2646: Format=Flowed; Original
> | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | Message-ID: <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
> | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | Path:
> TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
> | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > microsoft.public.sqlserver.reportingsvcs:50644
> | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > |
> | > | Peter,
> | > |
> | > | As I told you in my previous message, I am an administrator on the
> SQL
> | > | Server hosting all the databases used to manage and render the
> reports.
> | > I
> | > | can access every database on the server. Therefore, that is not the
> | > | problem.
> | > |
> | > | Do you have any other suggestions?
> | > |
> | > | Tom
> | > |
> | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
> | > | news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
> | > | > Hello Tom,
> | > | >
> | > | > It seems that your credential only has permssion on ReportServer
> and
> | > | > ReportServerTempDB other than the data source of the report
> itself.
> | > | >
> | > | > Please double check if you could connect to the SQL server hosting
> the
> | > | > data
> | > | > source of the report itself by using Query Analyzer. I assume it
> is
> a
> | > | > different server from the report server. If not, please add your
> | > domain
> | > | > accunt to the login of the server and add the proper database user
> | > mapping
> | > | > to the login.
> | > | >
> | > | > Regards,
> | > | >
> | > | > Peter Yang
> | > | > MCSE2000/2003, MCSA, MCDBA
> | > | > Microsoft Online Partner Support
> | > | >
> | > | > When responding to posts, please "Reply to Group" via your
> newsreader
> | > so
> | > | > that others may learn and benefit from your issue.
> | > | >
> | > | > =====================================================> | > | >
> | > | >
> | > | > This posting is provided "AS IS" with no warranties, and confers
> no
> | > | > rights.
> | > | >
> | > | >
> | > | > --
> | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
> | > | > | Subject: Re: Integrated Security Problem
> | > | > | Date: Wed, 17 Aug 2005 14:33:04 -0500
> | > | > | Lines: 131
> | > | > | X-Priority: 3
> | > | > | X-MSMail-Priority: Normal
> | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | > | X-RFC2646: Format=Flowed; Original
> | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | > | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
> | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | > | Path:
> | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
> | > | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > | > microsoft.public.sqlserver.reportingsvcs:50575
> | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > | > |
> | > | > | Peter,
> | > | > |
> | > | > | Our users need to access reports via the ReportServer web site,
> i.e.
> | > | > | http://domain/ReportServer, customized web applications, and
> Windows
> | > | > | applications. In addition, a few users need to access reports
> with
> | > | > Report
> | > | > | Manager to set the report properties and security.
> | > | > |
> | > | > | We need to use Integrated Security to control a user's access to
> a
> | > | > | particular report, however, we can't get this to work.
> | > | > |
> | > | > | For example, one of the reports has its data sources set up with
> | > these
> | > | > | options selected: 'A custom data source', "Connection Type:
> | > Microsoft
> | > | > SQL
> | > | > | Server', 'Connection String: data source=Dev01Sql;initial
> | > | > catalog=Vendor',
> | > | > | 'Windows NT Integrated Security'.
> | > | > |
> | > | > | I am an administrator for Dev01Sql and can access every database
> on
> | > the
> | > | > | server, but when I try to run the report from Report Manager or
> from
> | > the
> | > | > | ReportServer web site, I get the Reporting Services Error page
> with
> | > the
> | > | > | message "Login failed for user '(null)'. Reason: Not associated
> with
> | > a
> | > | > | trusted SQL Server connection."
> | > | > |
> | > | > | Since Report Manager is accessing the ReportServer and
> | > | > ReportServerTempDB
> | > | > on
> | > | > | Dev01Sql using my credentials, I don't understand why the report
> | > cannot
> | > | > be
> | > | > | rendered. Is there some setting for the ReportServer web site
> that
> | > can
> | > | > be
> | > | > | changed to allow the same access to render the reports that
> Report
> | > | > Manager
> | > | > | has?
> | > | > |
> | > | > | Thanks,
> | > | > | Tom
> | > | > |
> | > | > |
> | > | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in
> message
> | > | > | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
> | > | > | > Hello Tom,
> | > | > | >
> | > | > | > To understand the issue better, I'd like to know how users
> access
> | > the
> | > | > | > reports. Do they access reports via remport manager or via a
> | > | > customized
> | > | > | > web
> | > | > | > application that using report server?
> | > | > | >
> | > | > | > If the issue occurs within report manager when users try to
> access
> | > the
> | > | > | > report, it seems that this is caused by the configuration of
> the
> | > | > | > credential
> | > | > | > to access the data source of the specific reports.
> | > | > | >
> | > | > | > I suggest that you configure the shared or custome data source
> of
> | > the
> | > | > | > reports with the following configuration:
> | > | > | >
> | > | > | > 1. credentials supplied by the user running the report.
> | > | > | >
> | > | > | > Each user need to input crediential to access data source each
> | > time.
> | > | > | >
> | > | > | > 2. Credential stored securely in the report server.
> | > | > | >
> | > | > | > Report server save this credential and use this credential to
> | > access
> | > | > data
> | > | > | > source no matter which user request the report
> | > | > | >
> | > | > | > 3. Windows NT Integrated security.
> | > | > | >
> | > | > | > Each client use his log on credential to access data source of
> the
> | > | > | > reports.
> | > | > | > You have to add login for the domain account and create
> | > users/grant
> | > | > | > permission on the database the report requsts.
> | > | > | >
> | > | > | > It seems that you check "Windows NT Integrated security" but
> the
> | > | > client
> | > | > | > domain user does not have proper login added on the data
> source
> | > sql
> | > | > server
> | > | > | > for the specific reports.
> | > | > | >
> | > | > | > Thanks & Regards,
> | > | > | >
> | > | > | > Peter Yang
> | > | > | > MCSE2000/2003, MCSA, MCDBA
> | > | > | > Microsoft Online Partner Support
> | > | > | >
> | > | > | > When responding to posts, please "Reply to Group" via your
> | > newsreader
> | > | > so
> | > | > | > that others may learn and benefit from your issue.
> | > | > | >
> | > | > | > =====================================================> | > | > | >
> | > | > | >
> | > | > | > This posting is provided "AS IS" with no warranties, and
> confers
> | > no
> | > | > | > rights.
> | > | > | >
> | > | > | >
> | > | > | > --
> | > | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
> | > | > | > | Subject: Integrated Security Problem
> | > | > | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
> | > | > | > | Lines: 21
> | > | > | > | X-Priority: 3
> | > | > | > | X-MSMail-Priority: Normal
> | > | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
> | > | > | > | X-RFC2646: Format=Flowed; Original
> | > | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
> | > | > | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
> | > | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
> | > | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
> | > | > | > | Path:
> | > | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
> | > | > | > | Xref: TK2MSFTNGXA01.phx.gbl
> | > | > | > microsoft.public.sqlserver.reportingsvcs:50514
> | > | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
> | > | > | > |
> | > | > | > | We are trying to control the access an individual user has
> to
> a
> | > | > report,
> | > | > | > for
> | > | > | > | example: 1) Bob has access to the customer report; 2) Judy
> has
> | > | > access
> | > | > | > to
> | > | > | > | all the reports; and 3) James has access only to the vendor
> | > report.
> | > | > | > |
> | > | > | > | In order to accomplish this we are trying to use 'Integrated
> | > | > Security'
> | > | > | > | credentialing for out Data Sources. When we try to access
> | > reports
> | > | > after
> | > | > | > | setting 'Inetgrated Security', we get the error: "Login
> failed
> | > for
> | > | > user
> | > | > | > | '(null)'. Reason: Not associated with a trusted SQL Server
> | > | > connection."
> | > | > | > |
> | > | > | > | It appears that the user's credentials are not being passed
> from
> | > the
> | > | > Web
> | > | > | > | Server to the SQL Server when trying to access the reports,
> | > however,
> | > | > | > Report
> | > | > | > | Manager functions perfectly. Both the Web Server and SQL
> Server
> | > are
> | > | > | > running
> | > | > | > | on Windows 2003 Server.
> | > | > | > |
> | > | > | > | What can we do configure the Report Server so it behaves
> like
> | > Report
> | > | > | > | Manager?
> | > | > | > |
> | > | > | > | Thanks,
> | > | > | > | Tom
> | > | > | > |
> | > | > | > |
> | > | > | > |
> | > | > | >
> | > | > |
> | > | > |
> | > | > |
> | > | >
> | > |
> | > |
> | > |
> | >
> |
> |
> |
>|||Hello Tom,
Glad to hear the issue is resolved! You may want to post this issue in a
new thread so that it could be traced properly by others in the community.
For shared function, you shall call it via Code component. For example
public shared function Fn(input As Integer)
if input = 1
return "Hello!"
else
return "Bye!"
end if
end function
In the report, you refer to it as: =Code.Fn( CInt(Fields!CustomerID.Value ))
Hope this is helpful.
Best Regards,
Peter Yang
MCSE2000/2003, MCSA, MCDBA
Microsoft Online Partner Support
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
--
| From: "Tom Bean" <tbean@.newsgroup.nospam>
| References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
<Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
<#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
<vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
<u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
<LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl>
<uf1hzFQpFHA.3512@.TK2MSFTNGP15.phx.gbl>
<lIKJndspFHA.940@.TK2MSFTNGXA01.phx.gbl>
| Subject: Re: Integrated Security Problem
| Date: Mon, 29 Aug 2005 18:56:27 -0500
| Lines: 509
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| X-RFC2646: Format=Flowed; Original
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| Message-ID: <Ox0UmVPrFHA.3080@.TK2MSFTNGP15.phx.gbl>
| Newsgroups: microsoft.public.sqlserver.reportingsvcs
| NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP15.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.sqlserver.reportingsvcs:51381
| X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
|
| Peter,
|
| I wonder if you could help me with another problem. I am trying to call
a
| static method in a custom assembly with one of my reports but get the
error
| "[BC30469] Reference to a non-shared member requires an object
reference".
| The declaration of the method I am calling is: public static string
| Decrypt(string encryptedText). The only thing references used in my
custom
| assembly are System, System.Data, and System.XML.
|
| I am having the same problem with calling the
| System.Web.HttpUtility.UrlDecode method.
|
| I have added references to both my custom assembly and System.Web via the
| References tab in Report Properties.
|
| I can't think of anything else to do. Please help.
|
| Thanks,
| Tom
|
| "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| news:lIKJndspFHA.940@.TK2MSFTNGXA01.phx.gbl...
| > Hello Tom,
| >
| > Before we go further, I'd like to confirm if SQL server (data source of
| > the
| > report) and IIS are in the same machine. The issue seems to be a problem
| > that IIS/Report server are in different machine hosting SQL server.
| >
| > If it is the case, I suggest that you change the following
configuration
| > if
| > you are using Win2k/2k3 AD so that delegation is properly enabled
| >
| > 1. In AD: The Middle Computer should be trusted for delegation
| >
| > 2. In AD: The domain account under which SQL server is running should
not
| > be marked as "sensitive for delegation", and "Accont is trusted for
| > delegation" shall be marked.
| >
| > 810572.KB.EN-US HOW TO: Configure an ASP.NET Application for a
Delegation
| > Scenario
| > http://support.microsoft.com/default.aspx?scid=KB;EN-US;810572
| >
| > For Win2003, you have to do both the above steps as under Win2k, and
| > additionally you have to do the following
| >
| > 1. In the middle computer: the domain account that IIS 6 application
| > pool
| > associated with default Website MUST have Set ImpersonatePriviledge
| > granted. By default the application pool used by reporting services is
| > the
| > deafult applciaton pool.
| >
| > Note that this priviledge is new to Windows 2003.
| >
| > 2. The name of the privilege is "Impersonate a client after
| > authentication", you can grant it using Local Security Policy.
| >
| > 3. "Account is trusted for delegation " must be set to for above
account.
| >
| > Please refer to the following article for more details about
| > troubleshooting this issue
| >
| > Troubleshooting Kerberos Delegation
| >
http://www.microsoft.com/downloads/details.aspx?FamilyID=99b0f94f-e28a-4726-
| > bffe-2f64ae2f59a2&displaylang=en
| >
| > How To Configure IIS to Support Both Kerberos and NTLM Authentication
| > http://support.microsoft.com/default.aspx?kbid=215383
| >
| > Information about SQL Server 2000 Kerberos support, including SQL Server
| > virtual servers on server clusters
| > http://support.microsoft.com/?id=319723
| >
| > Note: By using Windows authentication, each user access the report shall
| > have the proper permission on the sql server of data source.
| >
| > Hope this information is helpful.
| >
| > Best Regards,
| >
| > Peter Yang
| > MCSE2000/2003, MCSA, MCDBA
| > Microsoft Online Partner Support
| >
| > When responding to posts, please "Reply to Group" via your newsreader so
| > that others may learn and benefit from your issue.
| >
| > =====================================================| >
| >
| > This posting is provided "AS IS" with no warranties, and confers no
| > rights.
| >
| >
| > --
| > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| > <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| > <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
| > <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
| > <LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl>
| > | Subject: Re: Integrated Security Problem
| > | Date: Fri, 19 Aug 2005 16:02:50 -0500
| > | Lines: 338
| > | X-Priority: 3
| > | X-MSMail-Priority: Normal
| > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | X-RFC2646: Format=Flowed; Original
| > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | Message-ID: <uf1hzFQpFHA.3512@.TK2MSFTNGP15.phx.gbl>
| > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP15.phx.gbl
| > | Xref: TK2MSFTNGXA01.phx.gbl
| > microsoft.public.sqlserver.reportingsvcs:50786
| > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > |
| > | Peter,
| > |
| > | The answers to your questions are:
| > |
| > | 1. The application pool for the web site is running under
| > NetworkService.
| > | We added NetworkService to the local admin group and it still doesn't
| > work.
| > |
| > | 2. We have connected to the databases used by the reports with Query
| > | Analyzer using Windows authentication with no problem. We did this
| > logged
| > | on as users with permissions ranging from Users to Administrators.
| > |
| > | In addition, when we set up the 'Connect Using' property of the data
| > sources
| > | to 'The credentials supplied by the user running the report' and check
| > 'Use
| > | as Windows credentials when connecting to the data source', we can
| > supply
| > | the same login name and password as the used to start Windows and
| > | successfully render the report.
| > |
| > | 3. I checked the reporting service log and found many entries in the
| > | ExecutionLogs table that failed with a StatusCode = 101
| > | (rsProcessingAborted) but couldn't find any detailed information about
| > what
| > | caused the failure.
| > |
| > | 4. Yes, the problem occurs with all domain users with local admin
| > rights
| > | and SQL server admin rights.
| > |
| > | Thanks,
| > | Tom
| > |
| > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| > | news:LjuVM2JpFHA.3472@.TK2MSFTNGXA01.phx.gbl...
| > | > Hello Tom,
| > | >
| > | > Going forward, I'd like to know the following information:
| > | >
| > | > 1. Which identity the applciation pool uses for the default web
| > | > site/reporting service? Is it Network service? If you temporarily
add
| > | > Network service account or any identity for the applicaiton pool
into
| > | > local
| > | > admin groups, does it make any difference?
| > | >
| > | > 2. Did you try to run Query Analyzer to connect to the data source
of
| > the
| > | > specific report by using Windows authentication, is there any
problem?
| > | >
| > | > 3. Did you check in reporting service log to see if there is any
| > detailed
| > | > errors for this problem?
| > | >
| > | > 4. Does the issue occur with all domain users with local admin
rights
| > and
| > | > SQL server admin rights?
| > | >
| > | > Thanks & Regards,
| > | >
| > | > Peter Yang
| > | > MCSE2000/2003, MCSA, MCDBA
| > | > Microsoft Online Partner Support
| > | >
| > | > When responding to posts, please "Reply to Group" via your
newsreader
| > so
| > | > that others may learn and benefit from your issue.
| > | >
| > | > =====================================================| > | >
| > | >
| > | >
| > | > This posting is provided "AS IS" with no warranties, and confers no
| > | > rights.
| > | >
| > | >
| > | > --
| > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| > | > <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| > | > <vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl>
| > | > | Subject: Re: Integrated Security Problem
| > | > | Date: Thu, 18 Aug 2005 10:06:55 -0500
| > | > | Lines: 217
| > | > | X-Priority: 3
| > | > | X-MSMail-Priority: Normal
| > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | > | X-RFC2646: Format=Flowed; Original
| > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | > | Message-ID: <u0dgMaApFHA.1048@.tk2msftngp13.phx.gbl>
| > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | > | Path:
| > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| > | > | Xref: TK2MSFTNGXA01.phx.gbl
| > | > microsoft.public.sqlserver.reportingsvcs:50644
| > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > | > |
| > | > | Peter,
| > | > |
| > | > | As I told you in my previous message, I am an administrator on
the
| > SQL
| > | > | Server hosting all the databases used to manage and render the
| > reports.
| > | > I
| > | > | can access every database on the server. Therefore, that is not
the
| > | > | problem.
| > | > |
| > | > | Do you have any other suggestions?
| > | > |
| > | > | Tom
| > | > |
| > | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in message
| > | > | news:vBo$GQ9oFHA.3472@.TK2MSFTNGXA01.phx.gbl...
| > | > | > Hello Tom,
| > | > | >
| > | > | > It seems that your credential only has permssion on
ReportServer
| > and
| > | > | > ReportServerTempDB other than the data source of the report
| > itself.
| > | > | >
| > | > | > Please double check if you could connect to the SQL server
hosting
| > the
| > | > | > data
| > | > | > source of the report itself by using Query Analyzer. I assume
it
| > is
| > a
| > | > | > different server from the report server. If not, please add your
| > | > domain
| > | > | > accunt to the login of the server and add the proper database
user
| > | > mapping
| > | > | > to the login.
| > | > | >
| > | > | > Regards,
| > | > | >
| > | > | > Peter Yang
| > | > | > MCSE2000/2003, MCSA, MCDBA
| > | > | > Microsoft Online Partner Support
| > | > | >
| > | > | > When responding to posts, please "Reply to Group" via your
| > newsreader
| > | > so
| > | > | > that others may learn and benefit from your issue.
| > | > | >
| > | > | > =====================================================| > | > | >
| > | > | >
| > | > | > This posting is provided "AS IS" with no warranties, and
confers
| > no
| > | > | > rights.
| > | > | >
| > | > | >
| > | > | > --
| > | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | > | > | References: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | > | > <Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl>
| > | > | > | Subject: Re: Integrated Security Problem
| > | > | > | Date: Wed, 17 Aug 2005 14:33:04 -0500
| > | > | > | Lines: 131
| > | > | > | X-Priority: 3
| > | > | > | X-MSMail-Priority: Normal
| > | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | > | > | X-RFC2646: Format=Flowed; Original
| > | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | > | > | Message-ID: <#S4$PK2oFHA.3756@.TK2MSFTNGP09.phx.gbl>
| > | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | > | > | Path:
| > | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
| > | > | > | Xref: TK2MSFTNGXA01.phx.gbl
| > | > | > microsoft.public.sqlserver.reportingsvcs:50575
| > | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > | > | > |
| > | > | > | Peter,
| > | > | > |
| > | > | > | Our users need to access reports via the ReportServer web
site,
| > i.e.
| > | > | > | http://domain/ReportServer, customized web applications, and
| > Windows
| > | > | > | applications. In addition, a few users need to access reports
| > with
| > | > | > Report
| > | > | > | Manager to set the report properties and security.
| > | > | > |
| > | > | > | We need to use Integrated Security to control a user's access
to
| > a
| > | > | > | particular report, however, we can't get this to work.
| > | > | > |
| > | > | > | For example, one of the reports has its data sources set up
with
| > | > these
| > | > | > | options selected: 'A custom data source', "Connection Type:
| > | > Microsoft
| > | > | > SQL
| > | > | > | Server', 'Connection String: data source=Dev01Sql;initial
| > | > | > catalog=Vendor',
| > | > | > | 'Windows NT Integrated Security'.
| > | > | > |
| > | > | > | I am an administrator for Dev01Sql and can access every
database
| > on
| > | > the
| > | > | > | server, but when I try to run the report from Report Manager
or
| > from
| > | > the
| > | > | > | ReportServer web site, I get the Reporting Services Error page
| > with
| > | > the
| > | > | > | message "Login failed for user '(null)'. Reason: Not
associated
| > with
| > | > a
| > | > | > | trusted SQL Server connection."
| > | > | > |
| > | > | > | Since Report Manager is accessing the ReportServer and
| > | > | > ReportServerTempDB
| > | > | > on
| > | > | > | Dev01Sql using my credentials, I don't understand why the
report
| > | > cannot
| > | > | > be
| > | > | > | rendered. Is there some setting for the ReportServer web site
| > that
| > | > can
| > | > | > be
| > | > | > | changed to allow the same access to render the reports that
| > Report
| > | > | > Manager
| > | > | > | has?
| > | > | > |
| > | > | > | Thanks,
| > | > | > | Tom
| > | > | > |
| > | > | > |
| > | > | > | "Peter Yang [MSFT]" <petery@.online.microsoft.com> wrote in
| > message
| > | > | > | news:Mc24g2uoFHA.944@.TK2MSFTNGXA01.phx.gbl...
| > | > | > | > Hello Tom,
| > | > | > | >
| > | > | > | > To understand the issue better, I'd like to know how users
| > access
| > | > the
| > | > | > | > reports. Do they access reports via remport manager or via a
| > | > | > customized
| > | > | > | > web
| > | > | > | > application that using report server?
| > | > | > | >
| > | > | > | > If the issue occurs within report manager when users try to
| > access
| > | > the
| > | > | > | > report, it seems that this is caused by the configuration
of
| > the
| > | > | > | > credential
| > | > | > | > to access the data source of the specific reports.
| > | > | > | >
| > | > | > | > I suggest that you configure the shared or custome data
source
| > of
| > | > the
| > | > | > | > reports with the following configuration:
| > | > | > | >
| > | > | > | > 1. credentials supplied by the user running the report.
| > | > | > | >
| > | > | > | > Each user need to input crediential to access data source
each
| > | > time.
| > | > | > | >
| > | > | > | > 2. Credential stored securely in the report server.
| > | > | > | >
| > | > | > | > Report server save this credential and use this credential
to
| > | > access
| > | > | > data
| > | > | > | > source no matter which user request the report
| > | > | > | >
| > | > | > | > 3. Windows NT Integrated security.
| > | > | > | >
| > | > | > | > Each client use his log on credential to access data source
of
| > the
| > | > | > | > reports.
| > | > | > | > You have to add login for the domain account and create
| > | > users/grant
| > | > | > | > permission on the database the report requsts.
| > | > | > | >
| > | > | > | > It seems that you check "Windows NT Integrated security"
but
| > the
| > | > | > client
| > | > | > | > domain user does not have proper login added on the data
| > source
| > | > sql
| > | > | > server
| > | > | > | > for the specific reports.
| > | > | > | >
| > | > | > | > Thanks & Regards,
| > | > | > | >
| > | > | > | > Peter Yang
| > | > | > | > MCSE2000/2003, MCSA, MCDBA
| > | > | > | > Microsoft Online Partner Support
| > | > | > | >
| > | > | > | > When responding to posts, please "Reply to Group" via your
| > | > newsreader
| > | > | > so
| > | > | > | > that others may learn and benefit from your issue.
| > | > | > | >
| > | > | > | > =====================================================| > | > | > | >
| > | > | > | >
| > | > | > | > This posting is provided "AS IS" with no warranties, and
| > confers
| > | > no
| > | > | > | > rights.
| > | > | > | >
| > | > | > | >
| > | > | > | > --
| > | > | > | > | From: "Tom Bean" <tbean@.newsgroup.nospam>
| > | > | > | > | Subject: Integrated Security Problem
| > | > | > | > | Date: Tue, 16 Aug 2005 16:37:27 -0500
| > | > | > | > | Lines: 21
| > | > | > | > | X-Priority: 3
| > | > | > | > | X-MSMail-Priority: Normal
| > | > | > | > | X-Newsreader: Microsoft Outlook Express 6.00.2900.2180
| > | > | > | > | X-RFC2646: Format=Flowed; Original
| > | > | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
| > | > | > | > | Message-ID: <OmIWKrqoFHA.3552@.TK2MSFTNGP10.phx.gbl>
| > | > | > | > | Newsgroups: microsoft.public.sqlserver.reportingsvcs
| > | > | > | > | NNTP-Posting-Host: 71.4.140.141.ptr.us.xo.net 71.4.140.141
| > | > | > | > | Path:
| > | > | > TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.phx.gbl
| > | > | > | > | Xref: TK2MSFTNGXA01.phx.gbl
| > | > | > | > microsoft.public.sqlserver.reportingsvcs:50514
| > | > | > | > | X-Tomcat-NG: microsoft.public.sqlserver.reportingsvcs
| > | > | > | > |
| > | > | > | > | We are trying to control the access an individual user
has
| > to
| > a
| > | > | > report,
| > | > | > | > for
| > | > | > | > | example: 1) Bob has access to the customer report; 2)
Judy
| > has
| > | > | > access
| > | > | > | > to
| > | > | > | > | all the reports; and 3) James has access only to the
vendor
| > | > report.
| > | > | > | > |
| > | > | > | > | In order to accomplish this we are trying to use
'Integrated
| > | > | > Security'
| > | > | > | > | credentialing for out Data Sources. When we try to access
| > | > reports
| > | > | > after
| > | > | > | > | setting 'Inetgrated Security', we get the error: "Login
| > failed
| > | > for
| > | > | > user
| > | > | > | > | '(null)'. Reason: Not associated with a trusted SQL Server
| > | > | > connection."
| > | > | > | > |
| > | > | > | > | It appears that the user's credentials are not being
passed
| > from
| > | > the
| > | > | > Web
| > | > | > | > | Server to the SQL Server when trying to access the
reports,
| > | > however,
| > | > | > | > Report
| > | > | > | > | Manager functions perfectly. Both the Web Server and SQL
| > Server
| > | > are
| > | > | > | > running
| > | > | > | > | on Windows 2003 Server.
| > | > | > | > |
| > | > | > | > | What can we do configure the Report Server so it behaves
| > like
| > | > Report
| > | > | > | > | Manager?
| > | > | > | > |
| > | > | > | > | Thanks,
| > | > | > | > | Tom
| > | > | > | > |
| > | > | > | > |
| > | > | > | > |
| > | > | > | >
| > | > | > |
| > | > | > |
| > | > | > |
| > | > | >
| > | > |
| > | > |
| > | > |
| > | >
| > |
| > |
| > |
| >
|
|
|