﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>SQLServerCentral / Discuss Content Posted by Brian Kelley / Article Discussions / Article Discussions by Author  / SQL Server Security: Fixed Roles / Latest Posts</title><generator>InstantForum.NET v2.9.0</generator><description>SQLServerCentral</description><link>http://www.sqlservercentral.com/Forums/</link><webMaster>notifications@sqlservercentral.com</webMaster><lastBuildDate>Tue, 21 May 2013 15:35:16 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>I actually just ran into a "problem" involving the server roles in SQL Server 2000 (and I believe 2005).  We have a VB application used in house, and users have a SQL Server login.  Logging in the application uses the user_name() function.  Some of our users also belong to server roles.  We've found that for those users, user_name() returns "dbo" instead of their user name.  Instead, we apparently need to use something like system_user to return their actual user name.  This seems stupid really, but apparently is a known issue?  It was news to us, and now we need to change a good number of our stored procedures.  Bah!</description><pubDate>Mon, 07 May 2007 07:15:00 GMT</pubDate><dc:creator>Pete T-366679</dc:creator></item><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>It would be nice to put links in this old article to articles you published (later)which deal with SS 2005. And links to articles about fixed database roles and server logins  - because all these go in a package ... Or I'm wrong?</description><pubDate>Sun, 06 May 2007 18:12:00 GMT</pubDate><dc:creator>Iordan Slavov</dc:creator></item><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>&lt;P&gt;Yah.&lt;/P&gt;&lt;P&gt;I set an sp as a startup, created a login Hacker with access to Master as db_datawriter, db_datareader and db_ddladmin. Connected as Hacker user in Management Studio I was able to modify the stored procedure to add a line for adding this Hacker to Sysadmin role. I did re-check that the Hacker person did not have ANY server roles.&lt;/P&gt;&lt;P&gt;I was able to restart the SQL Server from Management Studio connected to SQL Server as Hacker. After I restarted the service the Hacker person was a sysadmin. While I can find the explanation that I was able to restart the service (Management Studio is run under the logged in user process that is a Windows login and my Windows login has admin rights) I find the whole thing sort of ... you know. I will re-test it Monday just to make sure. My SQL Server is 2005 RTM. I will re-test on SP 1 and SP2.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description><pubDate>Fri, 04 May 2007 15:47:00 GMT</pubDate><dc:creator>Yelena Varshal</dc:creator></item><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>We republish popular articles periodically. It gives new people to the site a chance to catch them.</description><pubDate>Fri, 04 May 2007 07:27:00 GMT</pubDate><dc:creator>Steve Jones - SSC Editor</dc:creator></item><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>why did you republished 2003 article?</description><pubDate>Fri, 04 May 2007 04:44:00 GMT</pubDate><dc:creator>EugeneZ-162636</dc:creator></item><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>That is indeed a good article, in future looking forward to read some more on same topic</description><pubDate>Fri, 04 May 2007 01:11:00 GMT</pubDate><dc:creator>Jaiprakash M Bankolli</dc:creator></item><item><title>RE: SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>Great article!!I was wondering, what security setup do you put in place for your development environments?  I have been trying to set up a development environment without giving the developers sysadmin rights, but most of our developers create DTS packages which make it hard to share development.  I do not want to use SQL logins to get around this.ThanksDean ChristieEdited by - dmc-co on 11/04/2003  12:35:31 PM</description><pubDate>Sun, 02 Nov 2003 12:49:00 GMT</pubDate><dc:creator>dmc-co</dc:creator></item><item><title>SQL Server Security: Fixed Roles</title><link>http://www.sqlservercentral.com/Forums/Topic17399-59-1.aspx</link><description>Comments posted to this topic are about the content posted at &lt;A HREF=http://www.sqlservercentral.com/columnists/bkelley/sqlserversecurityfixedroles.asp&gt;http://www.sqlservercentral.com/columnists/bkelley/sqlserversecurityfixedroles.asp&lt;/A&gt;</description><pubDate>Sat, 18 Oct 2003 00:00:00 GMT</pubDate><dc:creator>K. Brian Kelley</dc:creator></item></channel></rss>