February 9, 2012  
   Login  
Forum  
 
ForumForumEnesys RS Data ...Enesys RS Data ...Support - RS Da...Support - RS Da...SSRS integrated with MOSS 2007 mode with trusted account connectionSSRS integrated with MOSS 2007 mode with trusted account connection
Previous Previous
 
Next Next
New Post
 2/25/2010 6:06 PM
 

HI,

We are looking into your product and have a question regarding using it in SSRS and MOSS integrated mode.

We have separated WFE, SSRS (no database) and SQL server (with all databases from MOSS and SSRS) in our environment. We have SQL Sever 2005 SP3 for both database and SSRS. MOSS is SP2 with 10/2009 CU. We are using NTLM so we use trusted account in our Central Admin to configure everything. Reports are running well since last summer and we are expanding.

If we want to deploy your product to our environment, is it going to work under current configuration or we have to enable Kerberos?

 

Thank you very much.

New Post
 2/25/2010 7:24 PM
 

Hi,

If you are running reports using specific credentials, you won’t have any problem.

If you would like to run reports under the credentials of the user running the report (Windows authentication), Kerberos is the way to go (double hop limitation).

That said, if you have configured Reporting Services using a trusted account (within Central Admin), I guess that you are running your reports using specific credentials. As far as I know, a trusted account will not work well with reports that would be run using Windows Integrated Security.

Hope this helps,


Frederic LATOUR
ENESYS
New Post
 2/25/2010 8:16 PM
 

Frédéric LATOUR wrote
 

Hi,

If you are running reports using specific credentials, you won’t have any problem.

If you would like to run reports under the credentials of the user running the report (Windows authentication), Kerberos is the way to go (double hop limitation).

That said, if you have configured Reporting Services using a trusted account (within Central Admin), I guess that you are running your reports using specific credentials. As far as I know, a trusted account will not work well with reports that would be run using Windows Integrated Security.

Hope this helps,

 

Thank you very much for your answer. So our environment should have no problem to use your product to read list data from MOSS and design reports?

 

What types of reports, as far as you know, needs integrated windows authentication to run only?

 

 

New Post
 2/25/2010 9:52 PM
 


Indeed no problems until you use specific credentials for running the report.

 

Windows Authentication may be useful if:

- you want to ensure that whatever the user running the reports, he will not have access to SharePoint data for which he doesn’t have permissions even if for some reason he has access to the report.

- you pull out items from a list that contains folders with different permissions. The user running the report will get the items for which he doesn’t have permission.

- When rolling up list items in an entire site collection.

Let me know if you need additional information.

Have you downloaded an evaluation yet?

Regards,


Frederic LATOUR
ENESYS
New Post
 2/25/2010 10:23 PM
 

Frédéric LATOUR wrote
 


Indeed no problems until you use specific credentials for running the report.

 

Windows Authentication may be useful if:

- you want to ensure that whatever the user running the reports, he will not have access to SharePoint data for which he doesn’t have permissions even if for some reason he has access to the report.

- you pull out items from a list that contains folders with different permissions. The user running the report will get the items for which he doesn’t have permission.

- When rolling up list items in an entire site collection.

Let me know if you need additional information.

Have you downloaded an evaluation yet?

Regards,

 

If we enable Kerberos and use windows integrated quhentication, your product and report is able to use the same SharePoint user permission to trim the data at run time? Report designer does not have to do it in the report design or SQL ststement/Stored Procedure?

 

Thanks.

New Post
 2/26/2010 12:20 PM
 

We are using the credentials defined at the data source level to pull out data from SharePoint. Therefore, if you configure your data source with Windows Authentication, ERSDE will use the credentials of the user running the report for retrieving SharePoint data.

image

You don’t have to anything special when designing the report.

Hope this clarifies.


Frederic LATOUR
ENESYS
New Post
 2/26/2010 2:07 PM
 

Frédéric LATOUR wrote

We are using the credentials defined at the data source level to pull out data from SharePoint. Therefore, if you configure your data source with Windows Authentication, ERSDE will use the credentials of the user running the report for retrieving SharePoint data.

image

You don’t have to anything special when designing the report.

Hope this clarifies.

 

Thank you very much and I think I am getting better idea. Let me describe what I understand for now and correct me anything you find:

 

With Kerberos, SharePoint user credential can be used to trim the report data returned from a Sharepoint list.

Without Kerberor, trusted account is required and this account has to be defined in the data source file in a report library. Since this account may have different user permission (or no permission to any SharePoint list if it's for database connection only), to the one who is running the report, the returned results are not trimmed with the permission who is running the report.

Is this correct? Or in both case, returned results are the same?

 

Thank you very much.

New Post
 3/1/2010 10:49 PM
 

Hi,

Sorry for the delay.

You would need to user Kerberos (or a single machine deployment) for using current user credentials to trim sharepoint items.

Trusted account won’t let you use Windows Authentication at the data source level.

Regards,

 


Frederic LATOUR
ENESYS
Previous Previous
 
Next Next
ForumForumEnesys RS Data ...Enesys RS Data ...Support - RS Da...Support - RS Da...SSRS integrated with MOSS 2007 mode with trusted account connectionSSRS integrated with MOSS 2007 mode with trusted account connection

 
You need to login for posting to the forums.
If you don't have a login, click here to register.
 
Copyright 2010 Enesys - All rights reserved Terms Of UsePrivacy Statement