Category: Blog

  • Password for SQL Server Service Accounts

    I wrote recently about my philosophy for service accounts, and wanted to add a few more thoughts.

    Security is important for our database servers. One of the loopholes that everyone should be aware of is that the service running SQL Server has complete control over the service and potentially if this account were compromised, the security of our installation would be at risk.

    In this post I wanted to address two things related to service account passwords. The mechanics of building and working with these passwords and the ongoing maintenance in terms of changing the passwords.

    Creating Passwords

    One of the tools I recommend for anyone administering computer systems, including my parents on their personal computers, is a password manager. There should be a way for you to create and store complex passwords that are not easily guessed. I use Password Safe, but 1Password, KeyPass, and others are just as good.

    Typically I’ve used these to store the administrative passwords for various systems for all DBAs, sysops, etc. to use. However I haven’t used these for service accounts.

    Why not?

    Mostly because I don’t think any of us should be logging in as services. Apart from initial setup and testing, we shouldn’t use service accounts for anything.

    I always recommend long, complex, random passwords for services. The password should be created and written down long enough for someone to enter it twice in the areas reserved for credentials, and then the paper should be destroyed.

    I write these down because I want extremely long (20+), random strings that aren’t memorable and are really a one-time use string. Used just long enough to enter into the Services applet or as a credential in a PoSh (or other) script.

    If you use groups for your account rights, and you should even for service accounts (SQL Server makes this easy), you can always use another account to test access. Grant it the same permissions and groups, and perform your tests.

    Changing Passwords

    I don’t worry about changing service account passwords. Yes, I know this isn’t recommended, but services rarely change or are used to log on, we can limit the access of an account to a particular machine, and since the password isn’t stored, it’s not very vulnerable to cracking.

    If you are worried, then create a new, long, random string for the particular service(s) that are suspected to be vulnerable.

    I don’t allow expiration of service account passwords, though in a few organizations that have required yearly service account password changes, we’ve scheduled the changes for slow periods, not waiting until the expiration occurred. I can almost guarantee that accounts will expire during a critical time when machines should not go down.

    One caution. I know that changing passwords to long, complex strings is hard, and that there’s a temptation to set services to the same password or use some pattern to build passwords.

    Don’t.

    Patterns are poor security, and coupling services together with the same password (or account) is not worth the risk of issues if one system requires a change or the password is disclosed.

    banner_468x60_2015_speaking

  • Culture Differences: US v UK

    This is a bit of an off topic post from the technical stuff, but there’s a bit of a tie-in, so stick with me.

    I had to get a tire fixed this morning. I actually owned a replacement tire, so I just needed someone to mount it on the existing wheel (the existing tire needed to come off). I stopped by Discount Tire this morning in Parker, and I had a quick conversation with the salesman, Brian. He arranged for the service, even gave me a discount, and told me it would take about an hour.

    At this point I knew I needed to do some work, and at 9am, I wanted some coffee. I mentioned this to Brian, who said, “It’s a long walk to get coffee.”

    He noted that Starbucks was quite a distance for a walk. Certainly it was a hot day, approaching 85F as I exited the shop with my laptop, but a long walk?

    My friends and colleagues in the UK would laugh at this. I had to go down a busy road, and it was warm, but 0.6mi is “long”? I think not. Certainly no navigational issues following the blue dotted path.

    2015-07-27 12_53_47-Starbucks, South Parker Road, Parker, CO to Discount Tire Store - Parker, CO - G

    This struck me as strange as I walked along the road. Certainly I think lots of people in the US might see this as a long walk. They would perhaps ask the shop for a ride, or they’d stay in the store and skip coffee. I suspect that lots of people think any distance outside of the parking lot of an establishment might be seen as “long”.

    Far too many of us in the US as lazy in this manner, not willing to move dozens, much less hundreds, of yards. I’ve seen people wait minutes for a close parking spot to a store, when there were plenty of parking spots seconds away.

    I thought about this as I walked, and as I walked back. The thought bothered me a bit as I tried to answer some emails and check on SQLServerCentral. Why do we struggle with simple movement in the US? Are so many of us really wedded to cars that much? A summer morning is hot, but it’s a few minutes in the sun.

    I was curious how far I traveled in terms of steps, so I checked my Fitbit before leaving Starbucks. It was around 3,100 steps for the day. I checked when I got in my car, and I was at 4,500 steps. That’s about 1,400 steps for a cup of coffee. Each way, of course, but just a mile.

    When I think about how little we need to walk, it’s amazing. My job is worse than many in some ways. My meetings are at my desk. My commute is a few dozen steps. Getting lunch in the kitchen is maybe 50 steps. If I don’t make a concerted effort to move, I can easily spend a day at work and get to 6:00pm having traveled less than 2,000 steps.

    That’s sedentary.

    I do make an effort to exercise and move. Certainly I could do better with my diet, but I am at least attempting to move. That goal was one thing that kept me going on my running streak. I often felt refreshed and no matter how much time I’d spent in front of a computer, I at least ran a mile.

    We can all make an effort to move a bit more, especially those of us that spend lots of time in front of a computer. Taking breaks, walking up and down stairs, parking far away, scheduling walking meetings at times, or just making sure we spend some time before/after work moving.

    Many of you will have long lives, regardless of how you treat your body. Your career might not be affected at all by poor physical health. However the quality of your life is lower, in my opinion, if you aren’t taking care of yourself a bit.

    In the past we often had daily exercise as we lived. We walked around, we had to work to grow our food, or transport it, or just to find social company. Today we can avoid much of that, but I’m not sure we should.

    Find some exercise in the margins, find a sport you enjoy, or just take some long walks to contemplate life and enjoy your own, or a friend’s, company.

  • Get Away from the Heat and Learn some Database Version Control

    I have enjoyed the trips I’ve made to New Orleans and Baton Rouge in the past. It’s a good getaway, stopping in the French Quarter for a few minutes before an easy drive up the road. However it’s warm, and I can’t ever get my wife or kids to come with me. For some reason, they don’t seem to enjoy the warm, August Baton Rouge weather. I, however, am looking forward to a jog around University Lake.

    LSU University Lake at BREC Milford Wampold Park

    This might be the best time to run, but I’ll likely be going around when it’s sunnier, and a touch warmer.

    However if you want to get out of the heat, perhaps you’d like to come learn about Database Version Control with Ike Ellis and me? Redgate Software has partnered with Crafting Bytes to deliver our workshop in Baton Rouge. We’ve put the workshops on sale, and only $100 for a full day of training.

    What will we cover?

    We’ll show you how to get your database in a Version Control System (VCS). We use Redgate’s tools, but the idea of using version control can be done in other ways. I’m running the labs, and you’ll see how you can keep track of all of your database DDL code, including Lookup data!

    2015-07-23 18_45_53-DLM-Workshop-2015-02-19-1708-export-i-fg1k1eq0 - VMware Workstation

    We are also covering some advanced features that the Redgate tools make easier. Things like branching, merging, and deployments. How many of you would love to know that development is done and we can deploy our changes like this:

    2015-07-23 17_14_22-Schema Compare_Deploy - Microsoft SQL Server Management Studio

    I’ll show you how you can deploy your changes right from inside SSMS.

    This is an in-depth workshop, covering way more than I could ever do at a SQL Saturday or conference. What’s more, we provide you with a VM and let you actually work through the skills we teach you. You will get real practice during the day to give you the confidence and practice for your own environment back at the office.

    I hope to see you at either the workshop or SQL Saturday #423 in Baton Rouge.

  • My SQL Server Service Account Philosophy

    Recently someone sent me a question about service accounts. They weren’t sure how they should go about setting accounts up for various instances and services in their environments. Specifically they asked me about having domain accounts, or accounts separate for services.

    Note that I’ve managed SQL Server for years this way in environments up to hundreds of instances. I haven’t managed thousands, so there might be issues with this philosophy at scale.

    Here’s how I view service accounts. In a short list, I try to manage things like this:

    • Domain accounts for the SQL database engine and SQL Agent
    • Separate accounts for all instances and all Agent services
    • Long, complex, one-time passwords that aren’t stored.

    This has worked well for me, providing separation of services so that password changes or security issues on one instance don’t affect other instances.

    It’s also been scalable in that I rarely setup SQL Server instances. In most organizations I’ve worked in, we are adding a few instances a week at the most. The overhead to create two new accounts per instance (db engine and Agent) is minimal.

    Note that I would also have a separate domain account for SSAS or other items I install.

    With today’s rapid provisioning of machines through virtualized environments, I realize this isn’t necessarily a good hard and fast rule. If I expect an instance to be a production level instance and live for some period of time in the organization, I’d follow this philosophy.

    However if I am bringing online development and test instances that may not be kept around permanently, I think the local service accounts are fine. These will probably handle your needs and are worth scripting into your VM/instance creation process.

    I’ll add a few more thoughts on this across other posts, but there’s my idea in a nutshell.