Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, March 30, 2012

Report effective permissions for all users?

As our customers demand that we tighten our IT security in the company,
I've been asked to prepare a report quarterly showing, for each user in
Active directory, what his effective permissions are for every table in
every database that he has permission for on our SQL Server 2000 server. I
searched a bit for a tool to do this, but all I found was the PERMISSIONS()
function for showing effective permissions of the current user. Is there
any way to do it for an arbitrary user, without logging in as them?Ross Presser (rpresser@.imtek.com) writes:
> As our customers demand that we tighten our IT security in the company,
> I've been asked to prepare a report quarterly showing, for each user in
> Active directory, what his effective permissions are for every table in
> every database that he has permission for on our SQL Server 2000 server.
> I searched a bit for a tool to do this, but all I found was the
> PERMISSIONS() function for showing effective permissions of the current
> user. Is there any way to do it for an arbitrary user, without logging
> in as them?

You would have to trawl system tables like syspermissions for this. I
decline to provide any samples, because you need account for roles,
including fixed server roles.

This you would do per database. You could set up views for all system
tables that are of interest like:

CREATE VIEW serverpermissions AS
SELECT dbname = 'master', * FROM master.dbo.syspermissions
UNION ALL
SELECT 'model', * FROM model.dbo.syspermissions
UNION ALL
...

Preferably such views would be built dynamically.

I would estimate that the devlopment time for a correct report would be
at least 40 hours. And it might produces over 100 pages of output that
I doubt that no one will ever get through.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se

Books Online for SQL Server SP3 at
http://www.microsoft.com/sql/techin.../2000/books.asp|||On Wed, 15 Sep 2004 22:19:42 +0000 (UTC), Erland Sommarskog wrote:

> Ross Presser (rpresser@.imtek.com) writes:
>> As our customers demand that we tighten our IT security in the company,
>> I've been asked to prepare a report quarterly showing, for each user in
>> Active directory, what his effective permissions are for every table in
>> every database that he has permission for on our SQL Server 2000 server.
>> I searched a bit for a tool to do this, but all I found was the
>> PERMISSIONS() function for showing effective permissions of the current
>> user. Is there any way to do it for an arbitrary user, without logging
>> in as them?
> You would have to trawl system tables like syspermissions for this. I
> decline to provide any samples, because you need account for roles,
> including fixed server roles.
> This you would do per database. You could set up views for all system
> tables that are of interest like:
> CREATE VIEW serverpermissions AS
> SELECT dbname = 'master', * FROM master.dbo.syspermissions
> UNION ALL
> SELECT 'model', * FROM model.dbo.syspermissions
> UNION ALL
> ...
> Preferably such views would be built dynamically.
> I would estimate that the devlopment time for a correct report would be
> at least 40 hours. And it might produces over 100 pages of output that
> I doubt that no one will ever get through.

Well, I may have talked them down somewhat. Here's what I offered them:

http://www.sql-server-performance.com/rd_auditing2.asp has a stored
procedure that will list all roles that each database user belongs to.

The system stored procedure sp_helprotect lists all explicitly granted
permissions in the database, whether to a role or a database user, but not
including the system defined server roles or database roles like db_reader.

The system stored procedure sp_helplogins shows all the logins defined on
the server, and which database user and roles they map to in each database.

Between these three, I can picture a script that enumerates effective
permissions on each database object. for each sql login. Such a chart would
probably be 10-30 pages long at our site.

The last piece would be a script that takes each Active Directory user and
determines which sql login would apply. Determining a user's permissions
would then require looking up their AD user to find the sql login, then
looking up the sql login to find the permissions.

Looking forward, we plan to revise our security so that:
(a) all permissions are set at the user-defined role level
(b) no logins (except sa) are assigned to any system-defined server or
database roles
(c) sa is the dbo of all databases

What do you think?|||Ross Presser (rpresser@.imtek.com) writes:
> Looking forward, we plan to revise our security so that:
> (a) all permissions are set at the user-defined role level
> (b) no logins (except sa) are assigned to any system-defined server or
> database roles
> (c) sa is the dbo of all databases
> What do you think?

This does not sound right to me. It sounds almost right, but if I understand
this alright, all administration will be performed thruogh the "sa" account.
If you have exactly one DBA who knows this password, that is OK.

If you have more than one DBA, each one who is entitled to do admin
work on the server should be granted admin rights, either explicitly
or through BUILTIN/Administrators.

Anonymous high-power accounts like "sa" is not a good thing, since this
makes impossible to hold anyone accountable.

But plain users should be granted access through roles, and not by user.
And having only plain users and sysadmin users makes things a little easier.
But for security it's only good if you can afford to give anyone who needs
to something beyond simple access admin rights.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se

Books Online for SQL Server SP3 at
http://www.microsoft.com/sql/techin.../2000/books.asp|||>> What do you think?
> This does not sound right to me. It sounds almost right, but if I understand
> this alright, all administration will be performed thruogh the "sa" account.
> If you have exactly one DBA who knows this password, that is OK.
> If you have more than one DBA, each one who is entitled to do admin
> work on the server should be granted admin rights, either explicitly
> or through BUILTIN/Administrators.
> Anonymous high-power accounts like "sa" is not a good thing, since this
> makes impossible to hold anyone accountable.
> But plain users should be granted access through roles, and not by user.
> And having only plain users and sysadmin users makes things a little easier.
> But for security it's only good if you can afford to give anyone who needs
> to something beyond simple access admin rights.

Very good point, but not quite what I intended. Although sa would be the
dbo, administration would be done through non-sa accounts that belonged to
user-defined roles that had been granted the needed admin rights, at
whatever granularity was needed.

I just didn't want any users getting rights that were not from roles, by
virtue of them being the dbo of a database (or owner of a table, etc.)

But now that I type these words, I realize that to prevent users from
owning databases or other objects, I will have to do all admin as sa, just
like you said! That's not very good...

Can the owner of an object be reassigned by some stored proc? Then I could
create the table as rpresser then immediately reassign it to sa (still as
rpresser).|||Ross Presser (rpresser@.imtek.com) writes:
> Can the owner of an object be reassigned by some stored proc? Then I could
> create the table as rpresser then immediately reassign it to sa (still as
> rpresser).

sp_changeobjectowner. rpresser would then have to have dbo permissions to
do this.

And in such case you should just as well say CREATE TABLE dbo.ladida the
first time round.

But I would suggest that it is better that you are logged in as
DOMAIN\rpresser and this account is a member of BUILTIN\Administrator.

You may want to pursue the topic in microsoft.sqlserver.public.security.
I might not be able to contribute more on the thread, since I'm going away
on holiday tomorrow.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se

Books Online for SQL Server SP3 at
http://www.microsoft.com/sql/techin.../2000/books.asp

Wednesday, March 21, 2012

Report Builder with Forms Authentication

Hi,

After implementing custom security extension for forms authentication, the report server works fine with Report Manager and web application. However, there is a problem with Report Builder.

It gives SecurityException "That assembly does not allow partially trusted callers.". Its becos I am using my own security assembly for authentication. I resolved this issue by using the following in my assemblyinfo.cs

[assembly: System.Security.Permissions.PermissionSet(System.Security.Permissions.SecurityAction.RequestMinimum, Name="FullTrust")]

However, now when I login to Report Builder it gives me error System.IO.FileNotFoundException. Its not able to find my security assembly.

I also tried giving FullTrust to the assembly using Framework 2.0 Configuration. I read somewhere that the ClickOnce application caches its last called settings in the manifest file and you have to delete the manifest and manually alter the security in the application settings(properties).

Is this true? Is there any solution to this issue? Is this really an issue with clickonce application?

This is really urgent. Any suggestions.

Thanks in advance.

Is there any solution to this?
This is really frustrating. We are duplicating all our security code into CustomSecurity Extension module. At least it stopped giving error at the point, where the call was made to an assembly. Dont know if it will really work, even after moving all the code to extension module.

I just hope someone from MS at least reads this post, if not care to reply.
I hope this helps someone.

Thankssql

Report Builder Security Filter Examples

Does anyone have any examples on how to use the security filters in
report builder models. Do you setup a standard filter. How do you pass
the user back to the server in the query?
ThanksI have the same type of question...I need to be able to pass parameters
(userid) back to my model due to security setup in our system...we have
several 'user-access' tables for varying levels of security. For
example, any given user has access to specific accounts, but only
certain members within that account and only specific coverages within
those members. I don't see how I can set this up using roles but
perhaps I'm just missing it.|||the getuserid() function can be used... but... reportbuilder keep in cache
the first user which access a filter object where the getuserid() function
is used!!!
so if an "administrator" try the model, then every other users use the same
access!!!
but using the getuserid() into reportbuilder himself (the user create a
report and explicitly setup a filter) then the ID used is the right one, but
its not a good solution.
I'll do some other tests and keep you informed.
"tim" <tbush@.ccmsi.com> wrote in message
news:1141664357.097038.87240@.i40g2000cwc.googlegroups.com...
>I have the same type of question...I need to be able to pass parameters
> (userid) back to my model due to security setup in our system...we have
> several 'user-access' tables for varying levels of security. For
> example, any given user has access to specific accounts, but only
> certain members within that account and only specific coverages within
> those members. I don't see how I can set this up using roles but
> perhaps I'm just missing it.
>|||I will be posting an entry on my blog (http://blogs.msdn.com/bobmeyers)
shortly explaining how to use security filters.
FYI, the incorrect behavior of the GETUSERID() function is a known issue
that is fixed in SP1, which will be available shortly.
"Jéjé" wrote:
> the getuserid() function can be used... but... reportbuilder keep in cache
> the first user which access a filter object where the getuserid() function
> is used!!!
> so if an "administrator" try the model, then every other users use the same
> access!!!
> but using the getuserid() into reportbuilder himself (the user create a
> report and explicitly setup a filter) then the ID used is the right one, but
> its not a good solution.
> I'll do some other tests and keep you informed.
>
> "tim" <tbush@.ccmsi.com> wrote in message
> news:1141664357.097038.87240@.i40g2000cwc.googlegroups.com...
> >I have the same type of question...I need to be able to pass parameters
> > (userid) back to my model due to security setup in our system...we have
> > several 'user-access' tables for varying levels of security. For
> > example, any given user has access to specific accounts, but only
> > certain members within that account and only specific coverages within
> > those members. I don't see how I can set this up using roles but
> > perhaps I'm just missing it.
> >
>
>|||thanks!
your blog appear to be great and usefull.
favorites favorites... ;-)
"Bob Meyers - MSFT" <BobMeyersMSFT@.discussions.microsoft.com> wrote in
message news:D083E8EC-F89C-4E6A-AE99-0BEFDE4F877B@.microsoft.com...
>I will be posting an entry on my blog (http://blogs.msdn.com/bobmeyers)
> shortly explaining how to use security filters.
> FYI, the incorrect behavior of the GETUSERID() function is a known issue
> that is fixed in SP1, which will be available shortly.
> "Jéjé" wrote:
>> the getuserid() function can be used... but... reportbuilder keep in
>> cache
>> the first user which access a filter object where the getuserid()
>> function
>> is used!!!
>> so if an "administrator" try the model, then every other users use the
>> same
>> access!!!
>> but using the getuserid() into reportbuilder himself (the user create a
>> report and explicitly setup a filter) then the ID used is the right one,
>> but
>> its not a good solution.
>> I'll do some other tests and keep you informed.
>>
>> "tim" <tbush@.ccmsi.com> wrote in message
>> news:1141664357.097038.87240@.i40g2000cwc.googlegroups.com...
>> >I have the same type of question...I need to be able to pass parameters
>> > (userid) back to my model due to security setup in our system...we have
>> > several 'user-access' tables for varying levels of security. For
>> > example, any given user has access to specific accounts, but only
>> > certain members within that account and only specific coverages within
>> > those members. I don't see how I can set this up using roles but
>> > perhaps I'm just missing it.
>> >
>>|||Thanks Bob...I look forward to it...I am stumped.
J=E9j=E9 wrote:
> thanks!
> your blog appear to be great and usefull.
> favorites favorites... ;-)
> "Bob Meyers - MSFT" <BobMeyersMSFT@.discussions.microsoft.com> wrote in
> message news:D083E8EC-F89C-4E6A-AE99-0BEFDE4F877B@.microsoft.com...
> >I will be posting an entry on my blog (http://blogs.msdn.com/bobmeyers)
> > shortly explaining how to use security filters.
> >
> > FYI, the incorrect behavior of the GETUSERID() function is a known issue
> > that is fixed in SP1, which will be available shortly.
> >
> > "J=E9j=E9" wrote:
> >
> >> the getuserid() function can be used... but... reportbuilder keep in
> >> cache
> >> the first user which access a filter object where the getuserid()
> >> function
> >> is used!!!
> >>
> >> so if an "administrator" try the model, then every other users use the
> >> same
> >> access!!!
> >> but using the getuserid() into reportbuilder himself (the user create a
> >> report and explicitly setup a filter) then the ID used is the right on=e,
> >> but
> >> its not a good solution.
> >>
> >> I'll do some other tests and keep you informed.
> >>
> >>
> >> "tim" <tbush@.ccmsi.com> wrote in message
> >> news:1141664357.097038.87240@.i40g2000cwc.googlegroups.com...
> >> >I have the same type of question...I need to be able to pass paramete=rs
> >> > (userid) back to my model due to security setup in our system...we h=ave
> >> > several 'user-access' tables for varying levels of security. For
> >> > example, any given user has access to specific accounts, but only
> >> > certain members within that account and only specific coverages with=in
> >> > those members. I don't see how I can set this up using roles but
> >> > perhaps I'm just missing it.
> >> >
> >>
> >>
> >>|||how can I get SQL userid into the model rather than the Windows ID?|||to use the SQL Server user id , use SQL servers syntaxes (suser_sname or
user_name and other user_id functions)
"tim" <bush.timothy@.gmail.com> wrote in message
news:1144296426.518067.71590@.i40g2000cwc.googlegroups.com...
> how can I get SQL userid into the model rather than the Windows ID?
>|||thanks...was finally able to use SUSER_SNAME(SUSER_SID()) to get what I
needed. Now I'm trying to get the filters to work with it.|||Note that with the SP1 version of BOL (which will be available for download
when SP1 is released), there is a tutorial that walks you through how to set
up security filters using the GetUserID().
"tim" wrote:
> Thanks Bob...I look forward to it...I am stumped.
> Jéjé wrote:
> > thanks!
> >
> > your blog appear to be great and usefull.
> > favorites favorites... ;-)
> >
> > "Bob Meyers - MSFT" <BobMeyersMSFT@.discussions.microsoft.com> wrote in
> > message news:D083E8EC-F89C-4E6A-AE99-0BEFDE4F877B@.microsoft.com...
> > >I will be posting an entry on my blog (http://blogs.msdn.com/bobmeyers)
> > > shortly explaining how to use security filters.
> > >
> > > FYI, the incorrect behavior of the GETUSERID() function is a known issue
> > > that is fixed in SP1, which will be available shortly.
> > >
> > > "Jéjé" wrote:
> > >
> > >> the getuserid() function can be used... but... reportbuilder keep in
> > >> cache
> > >> the first user which access a filter object where the getuserid()
> > >> function
> > >> is used!!!
> > >>
> > >> so if an "administrator" try the model, then every other users use the
> > >> same
> > >> access!!!
> > >> but using the getuserid() into reportbuilder himself (the user create a
> > >> report and explicitly setup a filter) then the ID used is the right one,
> > >> but
> > >> its not a good solution.
> > >>
> > >> I'll do some other tests and keep you informed.
> > >>
> > >>
> > >> "tim" <tbush@.ccmsi.com> wrote in message
> > >> news:1141664357.097038.87240@.i40g2000cwc.googlegroups.com...
> > >> >I have the same type of question...I need to be able to pass parameters
> > >> > (userid) back to my model due to security setup in our system...we have
> > >> > several 'user-access' tables for varying levels of security. For
> > >> > example, any given user has access to specific accounts, but only
> > >> > certain members within that account and only specific coverages within
> > >> > those members. I don't see how I can set this up using roles but
> > >> > perhaps I'm just missing it.
> > >> >
> > >>
> > >>
> > >>
>

Monday, March 12, 2012

Report Builder and custom security - can I pass credentials as a parameter?

Hello,

I'm analyzing how our company can use security extensions along with the Report Builder. While testing custom security extensions I found that Report Builder is prompting me for the user name/password whenever I launch it from the browser. This is great, but I also need to launch it from the win forms application that already has been authenticated. Can I pass a user name/password as a parameter to the report builder so it does not show login dialog when I launch it from the application?

Thank you,

Leonid.

Hi,

Slightly off topic - we are setting out to do exactly the same thing - a custom security extension to an ADAM instance and with Report Builder access needed as well.

How hard was it to implement the extension? I have been looking here : http://msdn2.microsoft.com/en-us/library/ms152825.aspx. It does not seem so hard, but I am concerned in general about anything new.

Good luck with getting and answer to yoru question.

Mark

|||

I played with a sample code from Microsoft: http://msdn2.microsoft.com/en-us/library/ms160724.aspx, so I didn't write a single line of code.

Configuring is tedious, you should be very careful following all the steps they describe, but other than that - everything works fine. I haven't tried to revert it back, though :)

Leonid

P.S. In the instructions I skipped the following step because they obiously fixed CreateUserStore.sql script to do detect ASP user name automatically and forgot to update the documentation:

"Locate "LocalMachine" towards the end of the script and replace it with your own computer name. For Windows 2003 users, replace LocalMachine\ASPNET with NT AUTHORITY\NETWORK SERVICE (except when in IIS 5 compatibility mode). "

|||

Custom security should work with report builder - including the new in-model security

Report builder will always prompt for logon credentials even though you may have been already authenticated to the server - it is due to a limitation of the ClickOnce technology that report builder uses.

Report Builder and custom security - can I pass credentials as a parameter?

Hello,

I'm analyzing how our company can use security extensions along with the Report Builder. While testing custom security extensions I found that Report Builder is prompting me for the user name/password whenever I launch it from the browser. This is great, but I also need to launch it from the win forms application that already has been authenticated. Can I pass a user name/password as a parameter to the report builder so it does not show login dialog when I launch it from the application?

Thank you,

Leonid.

Hi,

Slightly off topic - we are setting out to do exactly the same thing - a custom security extension to an ADAM instance and with Report Builder access needed as well.

How hard was it to implement the extension? I have been looking here : http://msdn2.microsoft.com/en-us/library/ms152825.aspx. It does not seem so hard, but I am concerned in general about anything new.

Good luck with getting and answer to yoru question.

Mark

|||

I played with a sample code from Microsoft: http://msdn2.microsoft.com/en-us/library/ms160724.aspx, so I didn't write a single line of code.

Configuring is tedious, you should be very careful following all the steps they describe, but other than that - everything works fine. I haven't tried to revert it back, though :)

Leonid

P.S. In the instructions I skipped the following step because they obiously fixed CreateUserStore.sql script to do detect ASP user name automatically and forgot to update the documentation:

"Locate "LocalMachine" towards the end of the script and replace it with your own computer name. For Windows 2003 users, replace LocalMachine\ASPNET with NT AUTHORITY\NETWORK SERVICE (except when in IIS 5 compatibility mode). "

|||

Custom security should work with report builder - including the new in-model security

Report builder will always prompt for logon credentials even though you may have been already authenticated to the server - it is due to a limitation of the ClickOnce technology that report builder uses.

Friday, March 9, 2012

Report builder and custom security

We need to implement SQL Server 2005 Report Builder using our own security
model. We use application level authentication, in which a user ID and
password is verified against a record in the sql server database. So, we
don't use Windows Authentication. The problem is that we need to implement
the reporting builder as our ad-hoc reporting tool, but we need each user to
have his own private folder on the server. I've found only four articles on
http://msdn2.microsoft.com which talks about custom security extension, but
none of those is even close to what I'm looking for. I'm sure that there're
folks out there who've done this before.
Any suggestion or lead will be greatly appreciated.
Thanks,
Gilgameshhave you activated the "My Reports" option in reporting services?
this create a /My Reports folder and each user will have a private folder.
"Gilgamesh" <gilgamesh4ever@.aol.com> wrote in message
news:ONYLrGK0HHA.5644@.TK2MSFTNGP05.phx.gbl...
> We need to implement SQL Server 2005 Report Builder using our own security
> model. We use application level authentication, in which a user ID and
> password is verified against a record in the sql server database. So, we
> don't use Windows Authentication. The problem is that we need to implement
> the reporting builder as our ad-hoc reporting tool, but we need each user
> to have his own private folder on the server. I've found only four
> articles on http://msdn2.microsoft.com which talks about custom security
> extension, but none of those is even close to what I'm looking for. I'm
> sure that there're folks out there who've done this before.
> Any suggestion or lead will be greatly appreciated.
> Thanks,
> Gilgamesh
>|||Yes, I have. The problem is that My Reports works only if you use Windows
Autehtication. As I explained in the posting, we use database authetication.
-G
"Jeje" <willgart@.hotmail.com> wrote in message
news:Oz1e7LM0HHA.1164@.TK2MSFTNGP02.phx.gbl...
> have you activated the "My Reports" option in reporting services?
> this create a /My Reports folder and each user will have a private folder.
>
> "Gilgamesh" <gilgamesh4ever@.aol.com> wrote in message
> news:ONYLrGK0HHA.5644@.TK2MSFTNGP05.phx.gbl...
>> We need to implement SQL Server 2005 Report Builder using our own
>> security model. We use application level authentication, in which a user
>> ID and password is verified against a record in the sql server database.
>> So, we don't use Windows Authentication. The problem is that we need to
>> implement the reporting builder as our ad-hoc reporting tool, but we need
>> each user to have his own private folder on the server. I've found only
>> four articles on http://msdn2.microsoft.com which talks about custom
>> security extension, but none of those is even close to what I'm looking
>> for. I'm sure that there're folks out there who've done this before.
>> Any suggestion or lead will be greatly appreciated.
>> Thanks,
>> Gilgamesh
>>|||Have you implemented custom security in Reporting Services? I don't use
Report Builder but in the end you end up with a RDL just like if it had been
designed in Report Designer.
So, my question is, do you have your custom security implemented in any way
with RS? That is the first thing you will need to do.
http://msdn2.microsoft.com/en-us/library/ms152825.aspx
--
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Gilgamesh" <gilgamesh4ever@.aol.com> wrote in message
news:ercOBrW0HHA.4236@.TK2MSFTNGP06.phx.gbl...
> Yes, I have. The problem is that My Reports works only if you use Windows
> Autehtication. As I explained in the posting, we use database
> authetication.
> -G
> "Jeje" <willgart@.hotmail.com> wrote in message
> news:Oz1e7LM0HHA.1164@.TK2MSFTNGP02.phx.gbl...
>> have you activated the "My Reports" option in reporting services?
>> this create a /My Reports folder and each user will have a private
>> folder.
>>
>> "Gilgamesh" <gilgamesh4ever@.aol.com> wrote in message
>> news:ONYLrGK0HHA.5644@.TK2MSFTNGP05.phx.gbl...
>> We need to implement SQL Server 2005 Report Builder using our own
>> security model. We use application level authentication, in which a user
>> ID and password is verified against a record in the sql server database.
>> So, we don't use Windows Authentication. The problem is that we need to
>> implement the reporting builder as our ad-hoc reporting tool, but we
>> need each user to have his own private folder on the server. I've found
>> only four articles on http://msdn2.microsoft.com which talks about
>> custom security extension, but none of those is even close to what I'm
>> looking for. I'm sure that there're folks out there who've done this
>> before.
>> Any suggestion or lead will be greatly appreciated.
>> Thanks,
>> Gilgamesh
>>
>|||Bruce
ok, i need to do the same thing. But i am having some trouble with
configuring the secruity extension (Forms Authenication). i have an
question on the User Accounts database part.
The instructions say to replace the "LocalMachine" towards the end of
the createuserstore.sql. But i don't see any mention of that in the
script at all. Any ideas?
INSTRUCTIONS:
Locate "LocalMachine" towards the end of the script and replace it
with your own computer name. For Windows 2003 users, replace
LocalMachine\ASPNET with NT AUTHORITY\NETWORK SERVICE (except when in
IIS 5 compatibility mode).
createuserstore SCRIPT:
exec ('sp_grantlogin [' + @.ASPUserName + ']');
-- Add a database login for the UserAccounts database for the ASPNET
account
exec ('sp_grantdbaccess [' + @.ASPUserName + ']');
-- Grant execute permissions to the LookupUser and RegisterUser stored
procs
exec ('grant execute on LookupUser to [' + @.ASPUserName + ']');
exec ('grant execute on RegisterUser to [' + @.ASPUserName + ']');
------
Have you implemented custom security in Reporting Services? I don't
use
Report Builder but in the end you end up with a RDL just like if it
had been
designed in Report Designer.
So, my question is, do you have your custom security implemented in
any way
with RS? That is the first thing you will need to do.
http://msdn2.microsoft.com/en-us/library/ms152825.aspx
On Jul 29, 3:15 pm, "Bruce L-C [MVP]" <bruce_lcNOS...@.hotmail.com>
wrote:
> Have you implemented custom security in Reporting Services? I don't use
> Report Builder but in the end you end up with a RDL just like if it had been
> designed in Report Designer.
> So, my question is, do you have your custom security implemented in any way
> with RS? That is the first thing you will need to do.http://msdn2.microsoft.com/en-us/library/ms152825.aspx
> --
> Bruce Loehle-Conger
> MVP SQL Server Reporting Services
> "Gilgamesh" <gilgamesh4e...@.aol.com> wrote in message
> news:ercOBrW0HHA.4236@.TK2MSFTNGP06.phx.gbl...
>
> > Yes, I have. The problem is that My Reports works only if you use Windows
> > Autehtication. As I explained in the posting, we use database
> > authetication.
> > -G
> > "Jeje" <willg...@.hotmail.com> wrote in message
> >news:Oz1e7LM0HHA.1164@.TK2MSFTNGP02.phx.gbl...
> >> have you activated the "My Reports" option in reporting services?
> >> this create a /My Reports folder and each user will have a private
> >> folder.
> >> "Gilgamesh" <gilgamesh4e...@.aol.com> wrote in message
> >>news:ONYLrGK0HHA.5644@.TK2MSFTNGP05.phx.gbl...
> >> We need to implement SQL Server 2005 Report Builder using our own
> >> security model. We use application level authentication, in which a user
> >> ID and password is verified against a record in the sql server database.
> >> So, we don't use Windows Authentication. The problem is that we need to
> >> implement the reporting builder as our ad-hoc reporting tool, but we
> >> need each user to have his own private folder on the server. I've found
> >> only four articles onhttp://msdn2.microsoft.comwhich talks about
> >> custom security extension, but none of those is even close to what I'm
> >> looking for. I'm sure that there're folks out there who've done this
> >> before.
> >> Any suggestion or lead will be greatly appreciated.
> >> Thanks,
> >> Gilgamesh- Hide quoted text -
> - Show quoted text -|||Sorry, I have not implemented this. I suggest a separate post specifically
about that. Also, you might want to post it at the web based forums as well.
http://forums.microsoft.com/msdn/showforum.aspx?forumid=82&siteid=1
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Ryan Swann" <swannryan@.gmail.com> wrote in message
news:1185807504.059515.124770@.57g2000hsv.googlegroups.com...
> Bruce
> ok, i need to do the same thing. But i am having some trouble with
> configuring the secruity extension (Forms Authenication). i have an
> question on the User Accounts database part.
> The instructions say to replace the "LocalMachine" towards the end of
> the createuserstore.sql. But i don't see any mention of that in the
> script at all. Any ideas?
>
> INSTRUCTIONS:
> Locate "LocalMachine" towards the end of the script and replace it
> with your own computer name. For Windows 2003 users, replace
> LocalMachine\ASPNET with NT AUTHORITY\NETWORK SERVICE (except when in
> IIS 5 compatibility mode).
> createuserstore SCRIPT:
>
> exec ('sp_grantlogin [' + @.ASPUserName + ']');
> -- Add a database login for the UserAccounts database for the ASPNET
> account
> exec ('sp_grantdbaccess [' + @.ASPUserName + ']');
> -- Grant execute permissions to the LookupUser and RegisterUser stored
> procs
> exec ('grant execute on LookupUser to [' + @.ASPUserName + ']');
> exec ('grant execute on RegisterUser to [' + @.ASPUserName + ']');
> ------
> Have you implemented custom security in Reporting Services? I don't
> use
> Report Builder but in the end you end up with a RDL just like if it
> had been
> designed in Report Designer.
> So, my question is, do you have your custom security implemented in
> any way
> with RS? That is the first thing you will need to do.
> http://msdn2.microsoft.com/en-us/library/ms152825.aspx
>
>
>
>
> On Jul 29, 3:15 pm, "Bruce L-C [MVP]" <bruce_lcNOS...@.hotmail.com>
> wrote:
>> Have you implemented custom security in Reporting Services? I don't use
>> Report Builder but in the end you end up with a RDL just like if it had
>> been
>> designed in Report Designer.
>> So, my question is, do you have your custom security implemented in any
>> way
>> with RS? That is the first thing you will need to
>> do.http://msdn2.microsoft.com/en-us/library/ms152825.aspx
>> --
>> Bruce Loehle-Conger
>> MVP SQL Server Reporting Services
>> "Gilgamesh" <gilgamesh4e...@.aol.com> wrote in message
>> news:ercOBrW0HHA.4236@.TK2MSFTNGP06.phx.gbl...
>>
>> > Yes, I have. The problem is that My Reports works only if you use
>> > Windows
>> > Autehtication. As I explained in the posting, we use database
>> > authetication.
>> > -G
>> > "Jeje" <willg...@.hotmail.com> wrote in message
>> >news:Oz1e7LM0HHA.1164@.TK2MSFTNGP02.phx.gbl...
>> >> have you activated the "My Reports" option in reporting services?
>> >> this create a /My Reports folder and each user will have a private
>> >> folder.
>> >> "Gilgamesh" <gilgamesh4e...@.aol.com> wrote in message
>> >>news:ONYLrGK0HHA.5644@.TK2MSFTNGP05.phx.gbl...
>> >> We need to implement SQL Server 2005 Report Builder using our own
>> >> security model. We use application level authentication, in which a
>> >> user
>> >> ID and password is verified against a record in the sql server
>> >> database.
>> >> So, we don't use Windows Authentication. The problem is that we need
>> >> to
>> >> implement the reporting builder as our ad-hoc reporting tool, but we
>> >> need each user to have his own private folder on the server. I've
>> >> found
>> >> only four articles onhttp://msdn2.microsoft.comwhich talks about
>> >> custom security extension, but none of those is even close to what
>> >> I'm
>> >> looking for. I'm sure that there're folks out there who've done this
>> >> before.
>> >> Any suggestion or lead will be greatly appreciated.
>> >> Thanks,
>> >> Gilgamesh- Hide quoted text -
>> - Show quoted text -
>|||I got evreything working, let me know if someone needs some help with it
"Bruce L-C [MVP]" wrote:
> Sorry, I have not implemented this. I suggest a separate post specifically
> about that. Also, you might want to post it at the web based forums as well.
> http://forums.microsoft.com/msdn/showforum.aspx?forumid=82&siteid=1
>
> --
> Bruce Loehle-Conger
> MVP SQL Server Reporting Services
> "Ryan Swann" <swannryan@.gmail.com> wrote in message
> news:1185807504.059515.124770@.57g2000hsv.googlegroups.com...
> > Bruce
> >
> > ok, i need to do the same thing. But i am having some trouble with
> > configuring the secruity extension (Forms Authenication). i have an
> > question on the User Accounts database part.
> >
> > The instructions say to replace the "LocalMachine" towards the end of
> > the createuserstore.sql. But i don't see any mention of that in the
> > script at all. Any ideas?
> >
> >
> > INSTRUCTIONS:
> >
> > Locate "LocalMachine" towards the end of the script and replace it
> > with your own computer name. For Windows 2003 users, replace
> > LocalMachine\ASPNET with NT AUTHORITY\NETWORK SERVICE (except when in
> > IIS 5 compatibility mode).
> >
> > createuserstore SCRIPT:
> >
> >
> > exec ('sp_grantlogin [' + @.ASPUserName + ']');
> >
> > -- Add a database login for the UserAccounts database for the ASPNET
> > account
> > exec ('sp_grantdbaccess [' + @.ASPUserName + ']');
> >
> > -- Grant execute permissions to the LookupUser and RegisterUser stored
> > procs
> > exec ('grant execute on LookupUser to [' + @.ASPUserName + ']');
> > exec ('grant execute on RegisterUser to [' + @.ASPUserName + ']');
> >
> > ------
> > Have you implemented custom security in Reporting Services? I don't
> > use
> > Report Builder but in the end you end up with a RDL just like if it
> > had been
> > designed in Report Designer.
> >
> > So, my question is, do you have your custom security implemented in
> > any way
> > with RS? That is the first thing you will need to do.
> > http://msdn2.microsoft.com/en-us/library/ms152825.aspx
> >
> >
> >
> >
> >
> >
> >
> >
> > On Jul 29, 3:15 pm, "Bruce L-C [MVP]" <bruce_lcNOS...@.hotmail.com>
> > wrote:
> >> Have you implemented custom security in Reporting Services? I don't use
> >> Report Builder but in the end you end up with a RDL just like if it had
> >> been
> >> designed in Report Designer.
> >>
> >> So, my question is, do you have your custom security implemented in any
> >> way
> >> with RS? That is the first thing you will need to
> >> do.http://msdn2.microsoft.com/en-us/library/ms152825.aspx
> >>
> >> --
> >> Bruce Loehle-Conger
> >> MVP SQL Server Reporting Services
> >>
> >> "Gilgamesh" <gilgamesh4e...@.aol.com> wrote in message
> >>
> >> news:ercOBrW0HHA.4236@.TK2MSFTNGP06.phx.gbl...
> >>
> >>
> >>
> >> > Yes, I have. The problem is that My Reports works only if you use
> >> > Windows
> >> > Autehtication. As I explained in the posting, we use database
> >> > authetication.
> >> > -G
> >>
> >> > "Jeje" <willg...@.hotmail.com> wrote in message
> >> >news:Oz1e7LM0HHA.1164@.TK2MSFTNGP02.phx.gbl...
> >> >> have you activated the "My Reports" option in reporting services?
> >> >> this create a /My Reports folder and each user will have a private
> >> >> folder.
> >>
> >> >> "Gilgamesh" <gilgamesh4e...@.aol.com> wrote in message
> >> >>news:ONYLrGK0HHA.5644@.TK2MSFTNGP05.phx.gbl...
> >> >> We need to implement SQL Server 2005 Report Builder using our own
> >> >> security model. We use application level authentication, in which a
> >> >> user
> >> >> ID and password is verified against a record in the sql server
> >> >> database.
> >> >> So, we don't use Windows Authentication. The problem is that we need
> >> >> to
> >> >> implement the reporting builder as our ad-hoc reporting tool, but we
> >> >> need each user to have his own private folder on the server. I've
> >> >> found
> >> >> only four articles onhttp://msdn2.microsoft.comwhich talks about
> >> >> custom security extension, but none of those is even close to what
> >> >> I'm
> >> >> looking for. I'm sure that there're folks out there who've done this
> >> >> before.
> >>
> >> >> Any suggestion or lead will be greatly appreciated.
> >>
> >> >> Thanks,
> >> >> Gilgamesh- Hide quoted text -
> >>
> >> - Show quoted text -
> >
> >
>
>

Report Builder 401

When attempting to run Report Builder I get error below. After reading
earlier posts I have tried several combinations on the File Security
properties of the 6 Report Builder files and seem to get the furthest (I get
the Application Run - Security Warning dialog) while enabling Anonymous
access using the Report Server service account and also using Authenticated
access (Integrated Windows Authentication). I also tried changing the
RSWebApplication.Config from FullTrust to Partial Trust but that did not work.
Thanks in advance for any help
Please note that unlike earlier posts I have a Win32Exception at the end of
the error detail.
PLATFORM VERSION INFO
Windows : 5.1.2600.131072 (Win32NT)
Common Language Runtime : 2.0.50727.42
System.Deployment.dll : 2.0.50727.42 (RTM.050727-4200)
mscorwks.dll : 2.0.50727.42 (RTM.050727-4200)
dfdll.dll : 2.0.50727.42 (RTM.050727-4200)
dfshim.dll : 2.0.50727.42 (RTM.050727-4200)
SOURCES
Deployment url :
http://reporting.voyagerlearning.com/ReportServer/ReportBuilder/ReportBuilder.application
Server : Microsoft-IIS/6.0
X-Powered-By : ASP.NET
X-AspNet-Version: 2.0.50727
Application url :
http://reporting.voyagerlearning.com/ReportServer/ReportBuilder/ReportBuilder.exe.manifest
Server : Microsoft-IIS/6.0
X-Powered-By : ASP.NET
X-AspNet-Version: 2.0.50727
IDENTITIES
Deployment Identity : ReportBuilder.application, Version=9.0.2047.0,
Culture=neutral, PublicKeyToken=c3bce3770c238a49, processorArchitecture=msil
Application Identity : ReportBuilder.exe, Version=9.0.2047.0,
Culture=neutral, PublicKeyToken=c3bce3770c238a49, processorArchitecture=msil,
type=win32
APPLICATION SUMMARY
* Online only application.
* Trust url parameter is set.
ERROR SUMMARY
Below is a summary of the errors, details of these errors are listed later
in the log.
* Activation of
http://reporting.voyagerlearning.com/ReportServer/ReportBuilder/ReportBuilder.application resulted in exception. Following failure messages were detected:
+ Downloading
http://reporting.voyagerlearning.com/ReportServer/ReportBuilder/reportbuilder.chm.deploy did not succeed.
+ The remote server returned an error: (401) Unauthorized.
+ The logon attempt failed
COMPONENT STORE TRANSACTION FAILURE SUMMARY
No transaction error was detected.
WARNINGS
There were no warnings during this operation.
OPERATION PROGRESS STATUS
* [8/9/2006 11:26:32 PM] : Activation of
http://reporting.voyagerlearning.com/ReportServer/ReportBuilder/ReportBuilder.application has started.
* [8/9/2006 11:26:32 PM] : Processing of deployment manifest has
successfully completed.
* [8/9/2006 11:26:32 PM] : Installation of the application has started.
* [8/9/2006 11:26:32 PM] : Processing of application manifest has
successfully completed.
* [8/9/2006 11:26:35 PM] : Request of trust and detection of platform is
complete.
ERROR DETAILS
Following errors were detected during this operation.
* [8/9/2006 11:26:35 PM]
System.Deployment.Application.DeploymentDownloadException (Unknown subtype)
- Downloading
http://reporting.voyagerlearning.com/ReportServer/ReportBuilder/reportbuilder.chm.deploy did not succeed.
- Source: System.Deployment
- Stack trace:
at
System.Deployment.Application.SystemNetDownloader.DownloadSingleFile(DownloadQueueItem next)
at System.Deployment.Application.SystemNetDownloader.DownloadAllFiles()
at
System.Deployment.Application.FileDownloader.Download(SubscriptionState
subState)
at
System.Deployment.Application.DownloadManager.DownloadDependencies(SubscriptionState
subState, AssemblyManifest deployManifest, AssemblyManifest appManifest, Uri
sourceUriBase, String targetDirectory, String group, IDownloadNotification
notification, DownloadOptions options)
at
System.Deployment.Application.ApplicationActivator.DownloadApplication(SubscriptionState
subState, ActivationDescription actDesc, Int64 transactionId, TempDirectory&
downloadTemp)
at
System.Deployment.Application.ApplicationActivator.InstallApplication(SubscriptionState subState, ActivationDescription actDesc)
at
System.Deployment.Application.ApplicationActivator.PerformDeploymentActivation(Uri activationUri, Boolean isShortcut)
at
System.Deployment.Application.ApplicationActivator.ActivateDeploymentWorker(Object state)
-- Inner Exception --
System.Net.WebException
- The remote server returned an error: (401) Unauthorized.
- Source: System
- Stack trace:
at System.Net.HttpWebRequest.GetResponse()
at
System.Deployment.Application.SystemNetDownloader.DownloadSingleFile(DownloadQueueItem next)
-- Inner Exception --
System.ComponentModel.Win32Exception
- The logon attempt failed
- Source: System
- Stack trace:
at System.Net.NTAuthentication.GetOutgoingBlob(Byte[] incomingBlob,
Boolean throwOnError, SecurityStatus& statusCode)
at System.Net.NTAuthentication.GetOutgoingBlob(String incomingBlob)
at System.Net.NegotiateClient.DoAuthenticate(String challenge, WebRequest
webRequest, ICredentials credentials, Boolean preAuthenticate)
at System.Net.NegotiateClient.Authenticate(String challenge, WebRequest
webRequest, ICredentials credentials)
at System.Net.AuthenticationManager.Authenticate(String challenge,
WebRequest request, ICredentials credentials)
at System.Net.AuthenticationState.AttemptAuthenticate(HttpWebRequest
httpWebRequest, ICredentials authInfo)
at System.Net.HttpWebRequest.CheckResubmitForAuth()
at System.Net.HttpWebRequest.CheckResubmit(Exception& e)
COMPONENT STORE TRANSACTION DETAILS
No transaction information is available.Never mind. Just use How to Enable Anonymous Access on the ReportBuilder
Folder in Configure a Report Server for Report Builder Access

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Report Builder "Report Execution Error"

I get this error with Report Builder "Report Execution Error" the report might not be valid or the server could not process the data.
For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

What does this error mean?

I did get my report to run, it seems to work if I add another filter or limit the data to reduce the number of rows returned.

see

http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=101047&SiteID=1|||I am using domain names and I still get this same error and when I go to EVENT VIEWER, I always get this error as well

aspnet_wp.exe (PID: 2828) was recycled because memory consumption exceeded the 690 MB (60 percent of available RAM).
Perhaps my server memory is the problem, not enought? I wish it gave me a message relating to the real problem. Its when I am returning a large number of rows but I don't know what the exact limit is.

|||

Hello,

Did you ever get a response to your posting or figure out what the cause/solution was?

I am hitting a similar issue when i return a large set of data from the Report Server (SQL 2005 Reporting Services). A report will run fine with a smaller set of data, but when I run it with less restrictive filter criteria (which results in a larger data set), I get the error below (which I believe is the same error you were getting):

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method.

Any help is greatly appreciated!

|||

Hi, next you get this error, could you please grab recent report server logs (ReportServer__{date}.log) and send them to almineev tata microsoft todtod com

thanks!

|||

Alexandre,

would you mind posting that email address again?

Brian

|||I have sent the above requested info to Alexandre - am awaiting a response|||The error with DTD prohibited usually appears as a result of report processing/rendering running out of memory.|||

Perhaps in the next Service Pack of SQL 2005, MSFT can provide a more specific error message or one that provides more insight into the issue?

Is there any documentation on the amount of data (rows/columns) that SQL reporting services can handle?

Are there settings that allow you to allocate more memory for Reporting Services?

Thanks!

Brian

|||

Hello,

I use the ReportingServices from MS SQL Server 2005 Standard Edition.

The services are used by ASP.NET client (ReportViewer-control). Sometimes, I get the following error-message when I try to open the webform with the ReportViewer-control:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Then I found this thread about the problem in msdn. Now my questions:

- Do the ReportingServices have a problem with large amount of data?

- Which workaround should we use to avoid this problem?

Thanks in advance.

|||

Hi,

Did anyone of you got the solution for this issue.

I am facing the same issue:

For security reasons DTD is prohibited in this XML document. To enable DTD processing set the ProhibitDtd property on XmlReaderSettings to false and pass the settings into XmlReader.Create method

Kindly suggest!!!

Regards,

Evan

|||

I have the same isssue .but actually when no data return by the search condition , it also have this issue .

Hope some one can help.

|||

I'm having this issue and it's not disk space or memory, any other help on this issue. There never seemed to be a straight answer.

|||

Did anyone manage to fix this error? I can add filters and drag and drop columns, i can see data in filters, but when I run report I get "report execution error the report might not be valid or the server could not process the data"

thanks

|||

Hi,

No, I never received a real answer to this issue, we were in the process of testing Report Builder so we just stopped using it. JJones

Saturday, February 25, 2012

Report across multiple db

Can I use BIDS to create a report that will cross other DB's and servers?
For example - I have a customer DB that has social security #'s on Server1
DB-abc and I want to link to another server Server2 DB-efg - and create a
report with data elements from both DB's.yes, create a Linked Server to the second DB Server. After that you have the
possibility to create a view getting the data from both DB's. build the
report on this view and you are done.
hope this helps.
Regards, Rene
"Joe" schrieb:
> Can I use BIDS to create a report that will cross other DB's and servers?
> For example - I have a customer DB that has social security #'s on Server1
> DB-abc and I want to link to another server Server2 DB-efg - and create a
> report with data elements from both DB's.
>
>|||Just a heads up. Be very very careful with linked tables. If you do a
heterogenous join you will be pulling a massive amount of data locally. With
SQL 2000 it would do this sometimes even when the query was all on a single
remote database as I found out when I went against a large table. SQL 2005
is better at this but you will still see issues with heterogenous joins.
Linked tables are easy to use but dangerous.
One suggestion, do not use four part naming. Use openquery instead. Limit
the data as much as possible bringing it into a temp table and then do your
join there.
--
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Rene Fehr" <ReneFehr@.discussions.microsoft.com> wrote in message
news:7242A398-BC81-4DB3-A946-0A4DA7567C2E@.microsoft.com...
> yes, create a Linked Server to the second DB Server. After that you have
> the
> possibility to create a view getting the data from both DB's. build the
> report on this view and you are done.
> hope this helps.
> Regards, Rene
> "Joe" schrieb:
>> Can I use BIDS to create a report that will cross other DB's and servers?
>> For example - I have a customer DB that has social security #'s on
>> Server1
>> DB-abc and I want to link to another server Server2 DB-efg - and create a
>> report with data elements from both DB's.
>>