BUG: Password Dangling and Decrypted When Changing Security Mode For Replication

ID: Q238206


The information in this article applies to:

BUG #: 56128(SQLBUG_70)

SYMPTOMS

If the connection information used by replication agents to login to the subscriber is changed from "SQL Server Authentication" to "Impersonating SQLServer Agent account", the encrypted password for the SQL User account in the MSsubscriber_info table is not removed and instead decrypted. The connection information can be changed by selecting "Configure Publishing and Distribution Wizard", located under the "Subscribers" tab.


RESOLUTION

A supported fix that corrects this problem is now available from Microsoft, but it has not been fully regression tested and should be applied only to systems experiencing this specific problem. If you are not severely affected by this specific problem, Microsoft recommends that you wait for the next SQL Server Service Pack that contains this fix.

To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information on support costs, please go to the following address on the World Wide Web:

http://www.microsoft.com/support/supportnet/overview/overview.asp
The English version of this fix should have the following file attributes or later:


   File name 
   ----------

   S70713.exe
 
NOTE: Due to file dependencies, the most recent hotfix or feature that contains the above files may also contain additional files.



NOTE: If this product was already installed on your computer when you purchased it from the Original Equipment Manufacturer (OEM) and you need this fix, please call the Pay Per Incident number listed on the above Web site. If you contact Microsoft to obtain this fix, and if it is determined that you only require the fix you requested, no fee will be charged. However, if you request additional technical support, and if your no-charge technical support period has expired, or if you are not eligible for standard no-charge technical support, you may be charged a non-refundable fee.

For more information about eligibility for no-charge technical support, see the following article in the Microsoft Knowledge Base:
Q154871 Determining If You Are Eligible for No-Charge Technical Support


STATUS

Microsoft has confirmed this to be a problem in SQL Server version 7.0.


MORE INFORMATION

Though decrypted, this information is about a SQL User account and is available only to the members of the Sysadmin role. The login and password fields in the MSsubscriber_info table in the Distribution database are used to store SQL Server username and password, not the Windows NT username and password.

Additional query words: repl security prb cleartext clear text pwd info


Keywords          : kbSQLServ700bug 
Version           : winnt:7.0
Platform          : winnt 
Issue type        : kbbug 

Last Reviewed: July 29, 1999