Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Monday, March 26, 2012

Forcing password changes.

Is there a way to force password changes for SQL logins? I'd like to do some
thing similar to our NT authentication.Hi,
SQL Server do not have password / user policies, so you cant force password
changes or set any other policies for SQL
server authenticated users.
Thanks
Hari
MCDBA
"Francis Kamp" <anonymous@.discussions.microsoft.com> wrote in message
news:E2AD754B-E88B-49D4-ADA0-6F68F8338F5C@.microsoft.com...
> Is there a way to force password changes for SQL logins? I'd like to do
something similar to our NT authentication.|||Not in the current product. You can look forward to this feature in Yukon
http://www.microsoft.com/technet/tr...xt/SQLSYSec.asp
HTH
Jasper Smith (SQL Server MVP)
I support PASS - the definitive, global
community for SQL Server professionals -
http://www.sqlpass.org
"Francis Kamp" <anonymous@.discussions.microsoft.com> wrote in message
news:E2AD754B-E88B-49D4-ADA0-6F68F8338F5C@.microsoft.com...
> Is there a way to force password changes for SQL logins? I'd like to do
something similar to our NT authentication.

Forcing password change

Is there a way in Sql Server 2000 to enforce the password change to the sql autheticated user?Hi,

There is now setting you can configure to do so. But master..syslogins has a column (updatedate) so you could make a job that select every login that havent change their password for, let say for a, month.

Select loginname from master..syslogins where datediff(Month,updatedate,getdate())>1


Now you can decide if you make a cursor that change all the password (which givs you the problem to tell the users) or you email (job too perhaps) them and ask them change themself.

I hope this is useful
/Madasql

Wednesday, March 21, 2012

Force user to Change their password

Is there a way in sql server 2000 to force users to change their passwords periodically?Hi,

There is now setting you can configure to do so. But master..syslogins has a column (updatedate) so you could make a job that select every login that havent change their password for, let say for a, month.

Select loginname from master..syslogins where datediff(Month,updatedate,getdate())>1


Now you can decide if you make a cursor that change all the password (which givs you the problem too tell users) or you email them ask them to do so.

I hope this is useful
/Mada|||I think it's master.dbo.sysxlogins which contains a field named xdate2 which is basically the last time the password was changed.But the fact is that there is no other way to do this,unless you email the users about their password expiration.Sybase has a "Sysetmwide password configuration option" which was very useful in defining the serverwide password expiration dyas.|||Hi Old hand,

If you use NT-account in your sql server you can set a expiration period in the user manager.

/Mada

force password for sql login

Hi all,
I am using third party application that can only use sql authentication. If
we use windows authentication it will accept any password once the username
is correct. If we are force to use sql authentication, is there a script or a
way that we can force the sql users to change password every 3 months for
example. Any help will be greatly appreciated.Hi,
If you are using SQL Server 2005, you can enforce your windows password
policy.
But in case you are using SQL Server 2000, you will have to write a few
proc's to maintain things like password expiry etc. I am sure there are
articles regarding this. In fact I have gone thru' one, but dont have the
link at the moment.
Thank you.
Regards,
Karthik
"deseotu5" wrote:
> Hi all,
> I am using third party application that can only use sql authentication. If
> we use windows authentication it will accept any password once the username
> is correct. If we are force to use sql authentication, is there a script or a
> way that we can force the sql users to change password every 3 months for
> example. Any help will be greatly appreciated.|||Password and user policy is incorporated only from SQL 2005. If you have SQL
2005 then you can
enable the "Enforse Password Expiry" option for the required logins.
For SQL 2000 or older versions do not have Password policies for SQL Server
logins. The only way is
by 2 layer of authentication. First layer will be SQL Server and then it
will be creating application tables for authentication with a modified date
column. So verify the application table whne the password update happend
last time and based on that force the application change password
or expiry.
Thanks
Hari
SQL Server MVP
"deseotu5" <deseotu5@.discussions.microsoft.com> wrote in message
news:3C08100E-B7A7-4674-B424-48C29989F787@.microsoft.com...
> Hi all,
> I am using third party application that can only use sql authentication.
> If
> we use windows authentication it will accept any password once the
> username
> is correct. If we are force to use sql authentication, is there a script
> or a
> way that we can force the sql users to change password every 3 months for
> example. Any help will be greatly appreciated.

Monday, March 19, 2012

force password for sql login

Hi all,
I am using third party application that can only use sql authentication. If
we use windows authentication it will accept any password once the username
is correct. If we are force to use sql authentication, is there a script or
a
way that we can force the sql users to change password every 3 months for
example. Any help will be greatly appreciated.Hi,
If you are using SQL Server 2005, you can enforce your windows password
policy.
But in case you are using SQL Server 2000, you will have to write a few
proc's to maintain things like password expiry etc. I am sure there are
articles regarding this. In fact I have gone thru' one, but dont have the
link at the moment.
Thank you.
Regards,
Karthik
"deseotu5" wrote:

> Hi all,
> I am using third party application that can only use sql authentication. I
f
> we use windows authentication it will accept any password once the usernam
e
> is correct. If we are force to use sql authentication, is there a script o
r a
> way that we can force the sql users to change password every 3 months for
> example. Any help will be greatly appreciated.|||Password and user policy is incorporated only from SQL 2005. If you have SQL
2005 then you can
enable the "Enforse Password Expiry" option for the required logins.
For SQL 2000 or older versions do not have Password policies for SQL Server
logins. The only way is
by 2 layer of authentication. First layer will be SQL Server and then it
will be creating application tables for authentication with a modified date
column. So verify the application table whne the password update happend
last time and based on that force the application change password
or expiry.
Thanks
Hari
SQL Server MVP
"deseotu5" <deseotu5@.discussions.microsoft.com> wrote in message
news:3C08100E-B7A7-4674-B424-48C29989F787@.microsoft.com...
> Hi all,
> I am using third party application that can only use sql authentication.
> If
> we use windows authentication it will accept any password once the
> username
> is correct. If we are force to use sql authentication, is there a script
> or a
> way that we can force the sql users to change password every 3 months for
> example. Any help will be greatly appreciated.