Solved

FileStream with Sql Server Authentification

Posted on 2009-06-29
4
428 Views
Last Modified: 2013-11-08
Hi there,

Can someone help me understand how I can configure a Sql Server 2008 filestream share so that it can be used on a web site that uses forms authentication and sql server authentication?
0
Comment
Question by:karakav
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Mark Wills
ID: 24741702
Well, you don't need a share per se. It is "owned" by sql server. SQL Server 2008 can store blobs in its own private NTFS namespace rather than in the database itself. The database contains pointers to that namespace (and it's contents are named for SQL server so no longer represents the original doco name).

So, it is the SQL Server (and agent) accounts that need access to that folder, and best via a domain accout for those services. The advantage is that SQL server manages it and you can hide all of it from the outside world.

There is a really good whitepaper : http://msdn.microsoft.com/en-us/library/cc949109.aspx

And a discussion : http://blogs.msdn.com/rdoherty/archive/2007/10/12/getting-traction-with-sql-server-2008-filestream.aspx

And an example : http://msdn.microsoft.com/en-us/library/cc716724.aspx  and http://mtaulty.com/CommunityServer/blogs/mike_taultys_blog/archive/2008/09/08/10729.aspx

And everything else you ever wanted to know about filestream (as a developer) : http://msdn.microsoft.com/en-us/library/bb895234.aspx

Sorry about the links, but they really are the best answers...

0
 
LVL 4

Author Comment

by:karakav
ID: 24742757
I actually implemented FileStream in a web application. The only downside is that I use integrated security and there everything is working perfectly. However I have to consider using forms authentication and sql server authentication and that's were I get a access denied error. I want to workaroung that problem but still use forms and sql server authentication.
0
 
LVL 51

Accepted Solution

by:
Mark Wills earned 500 total points
ID: 24745551
Well, that is going to be fun, because "to access the FILESTREAM BLOB by using Win32, Windows Authorization must be enabled." (from the manual)

So, you will need to create a domain user, give them access to those folders / directories add them or associate them with a SQL login and then login using that SQL login. The only account that is granted NTFS permissions to the FILESTREAM container is the account under which the SQL Server service account runs. So, you MUST use the OpenSqlFilestream APIs



0
 
LVL 4

Author Closing Comment

by:karakav
ID: 31598090
In other words, it is impossible to take advantage of FileStream without using Windows authentication. Thanks any way.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article explains how to reset the password of the sa account on a Microsoft SQL Server.  The steps in this article work in SQL 2005, 2008, 2008 R2, 2012, 2014 and 2016.
Ever needed a SQL 2008 Database replicated/mirrored/log shipped on another server but you can't take the downtime inflicted by initial snapshot or disconnect while T-logs are restored or mirror applied? You can use SQL Server Initialize from Backup…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

775 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question