%3CLINGO-SUB%20id%3D%22lingo-sub-317473%22%20slang%3D%22en-US%22%3EError%20Message%20%22Login%20failed.%20The%20login%20is%20from%20an%20untrusted%20domain%20and%20cannot%20be%20used%20with%20Windows%20authentication.%22%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-317473%22%20slang%3D%22en-US%22%3E%0A%20%26lt%3Bmeta%20http-equiv%3D%22Content-Type%22%20content%3D%22text%2Fhtml%3B%20charset%3DUTF-8%22%20%2F%26gt%3B%3CSTRONG%3E%20First%20published%20on%20MSDN%20on%20Dec%2019%2C%202012%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%3CP%3EMy%20name%20is%20Archana%20CM%20from%20Microsoft%20SQL%20Developer%20Support%20team%2C%20we%20support%20SQL%20Connectivity%20issue%20along%20with%20data%20access%20technologies%20and%20SSIS.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EI%20had%20chance%20to%20work%20with%20SQL%20DBA%20who%20was%20having%20issues%20while%20connecting%20to%20his%20SQL%20server%20machine.%20We%20have%20seen%20many%20issue%20with%20connectivity%20to%20SQL%20but%20the%20solution%20we%20provider%20to%20his%20issue%20was%20sample%20and%20different.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EIn%20today's%20blog%20I%20am%20sharing%20my%20experience%20on%20how%20we%20could%20resolve%20the%20issue%20for%20him%20and%20what%20issues%20he%20was%20facing%20.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EMain%20issue%20was%20When%20the%20BizTalk%20service%20is%20executed%20%2C%20it%20was%20throwing%20the%20below%20error%20message%20on%20the%20application%20server%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EError%20Message%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EFailed%20to%20contact%20the%20SSO%20database%3A%20A%20network-related%20or%20instance-specific%20error%20occurred%20while%20establishing%20a%20connection%20to%20SQL%20Server.%20The%20server%20was%20not%20found%20or%20was%20not%20accessible.%20Verify%20that%20the%20instance%20name%20is%20correct%20and%20that%20SQL%20Server%20is%20configured%20to%20allow%20remote%20connections.%20(provider%3A%20Named%20Pipes%20Provider%2C%20error%3A%2040%20-%20Could%20not%20open%20a%20connection%20to%20SQL%20Server)%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EData%20Source%3DSQLSERVERNAME%3BIntegrated%20Security%3DSSPI%3BInitial%20Catalog%3DSSODB%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EError%20code%3A%200x800710D9%2C%20Unable%20to%20read%20from%20or%20write%20to%20the%20database.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EI%20followed%20all%20the%20steps%20that%20we%20do%20to%20troubleshoot%20an%20connectivity%20issue%20but%20none%20of%20those%20steps%20were%20able%20to%20resolve%20this%20issue.%20Some%20important%20steps%20are%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EStep%201%3A%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EDid%20UDL%20test%2C%20it%20was%20failing%20to%20connect%20to%20SQLServer%20%22SQLSERVERNAME%22%20from%20BIZTalk%20Server.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EError%20Message%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EMicrosoft%20Data%20Link%20Error%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ETest%20connection%20failed%20because%20of%20an%20error%20in%20initializing%20provider.%20%5BDBNETLIB%5D%5BConnectionOpen%20(Connect()).%5DSQL%20Server%20does%20not%20exist%20or%20access%20denied.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EOK%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EStep%202%3A%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ECreated%20the%20SQL%20account%20and%20tested%20it%20%2C%20it%20was%20still%20failing.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EMicrosoft%20Data%20Link%20Error%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ETest%20connection%20failed%20because%20of%20an%20error%20in%20initializing%20provider.%20Login%20failed.%20The%20login%20is%20from%20an%20untrusted%20domain%20and%20cannot%20be%20used%20with%20Windows%20authentication.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EOK%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EStep%203%3A%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EWe%20forced%20Np%2C%20TCp%20with%20port%201433%20but%20it%20was%20still%20same%20issue.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ESQL%20Server%20Native%20Client%20Data%20Link%20Error%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%5BMicrosoft%20SQL%20Server%20Native%20Client%2010.0%5D%3A%20Login%20failed.%20The%20login%20is%20from%20an%20untrusted%20domain%20and%20cannot%20be%20used%20with%20Windows%20authentication.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EOK%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EStep%204%3A%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EMade%20a%20registry%20change%20to%20%22%20DisableLoopbackCheck%22%20under%20%22%20HKEY_LOCAL_MACHINE%5CSYSTEM%5CCurrentControlSet%5CControl%5CLsa%22%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EWe%20added%20this%20registry%20change%20and%20rebooted%2C%20still%20it%20was%20failing%20with%20error%20below%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ESQL%20Server%20Native%20Client%20Data%20Link%20Error%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%5BMicrosoft%20SQL%20Server%20Native%20Client%2010.0%5D%3A%20Login%20timeout%20expired%20%5BMicrosoft%20SQL%20Server%20Native%20Client%2010.0%5D%3A%20A%20network-related%20or%20instance-specific%20error%20has%20occurred%20while%20establishing%20a%20connection%20to%20SQL%20Server.%20Server%20is%20not%20found%20or%20not%20accessible.%20Check%20if%20instance%20name%20is%20correct%20and%20if%20SQL%20Server%20is%20configured%20to%20allow%20remote%20connections.%20For%20more%20information%20see%20SQL%20Server%20Books%20Online.%20%5BMicrosoft%20SQL%20Server%20Native%20Client%2010.0%5D%3A%20Named%20Pipes%20Provider%3A%20Could%20not%20open%20a%20connection%20to%20SQL%20Server%20%5B53%5D.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EOK%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E---------------------------%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EStep%205%3A%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EI%20collected%20Netmon%20and%20Profiler%20%2C%20I%20could%20see%20all%20the%20connections%20and%20communication%20happening%20from%20BIZTAlk%20server%20to%20SQL%20Server%20in%20SQL%20Profiler%20%26amp%3B%20Netmon%20but%20still%20we%20could%20see%20Login%20failed%20issue.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3ESteps%206%3A%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EChecked%20for%20Kerberos%2C%20Kerberos%20was%20not%20enabled%20on%20Active%20Directory.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EWe%20enabled%20Kerberos%20on%20active%20directory.%20I%20could%20also%20see%20correct%20SPN%20for%20SQL%20account%20for%20SQL%20server%20but%20again%20it%20was%20same%20result.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EEven%20after%20changes%20and%20correct%20settings%20BizTalk%20was%20not%20able%20to%20successfully%20connect%20to%20SQL%20server.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EThought%20may%20be%20issue%20with%20security.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EWe%20added%20the%20SQL%20account%20to%20%22Access%20this%20computer%20from%20network%22%20Policy%20under%20Local%20Security%20Policy%20-%26gt%3B%20Local%20Policies%20-%26gt%3B%20User%20Rights%20Assignment%20-%26gt%3B%20Access%20this%20computer%20from%20network%22%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EThis%20resolved%20the%20issue%20for%20us.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EYes%2C%20only%20this%20setting%20under%20Local%20security%20Policy%20didn%E2%80%99t%20resolve%20the%20issue%20along%20with%20that%20Kerberos%20was%20very%20important.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EHope%20this%20blog%20and%20my%20experience%20will%20help%20you%20to%20troubleshoot%20similar%20issues.%3C%2FP%3E%3CBR%20%2F%3E%3CP%3EHappy%20Troubleshooting!!!!%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%3CSTRONG%3E%20Author%20%3A%20Archana(MSFT)%20SQL%20Developer%20Engineer%2C%20Microsoft%20%3C%2FSTRONG%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%3CSTRONG%3E%20Reviewed%20by%20%3A%20Snehadeep(MSFT)%2C%20SQL%20Developer%20Technical%20Lead%20%2C%20Microsoft%20%3C%2FSTRONG%3E%3C%2FP%3E%0A%20%0A%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-317473%22%20slang%3D%22en-US%22%3EFirst%20published%20on%20MSDN%20on%20Dec%2019%2C%202012%20My%20name%20is%20Archana%20CM%20from%20Microsoft%20SQL%20Developer%20Support%20team%2C%20we%20support%20SQL%20Connectivity%20issue%20along%20with%20data%20access%20technologies%20and%20SSIS.%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-317473%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
First published on MSDN on Dec 19, 2012

My name is Archana CM from Microsoft SQL Developer Support team, we support SQL Connectivity issue along with data access technologies and SSIS.


I had chance to work with SQL DBA who was having issues while connecting to his SQL server machine. We have seen many issue with connectivity to SQL but the solution we provider to his issue was sample and different.


In today's blog I am sharing my experience on how we could resolve the issue for him and what issues he was facing .


Main issue was When the BizTalk service is executed , it was throwing the below error message on the application server


Error Message


==================


Failed to contact the SSO database: A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server)


Data Source=SQLSERVERNAME;Integrated Security=SSPI;Initial Catalog=SSODB


Error code: 0x800710D9, Unable to read from or write to the database.


I followed all the steps that we do to troubleshoot an connectivity issue but none of those steps were able to resolve this issue. Some important steps are


Step 1:


Did UDL test, it was failing to connect to SQLServer "SQLSERVERNAME" from BIZTalk Server.


Error Message


==============


Microsoft Data Link Error


---------------------------


Test connection failed because of an error in initializing provider. [DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.


---------------------------


OK


---------------------------


Step 2:


Created the SQL account and tested it , it was still failing.


Microsoft Data Link Error


---------------------------


Test connection failed because of an error in initializing provider. Login failed. The login is from an untrusted domain and cannot be used with Windows authentication.


---------------------------


OK


---------------------------


Step 3:


We forced Np, TCp with port 1433 but it was still same issue.


SQL Server Native Client Data Link Error


---------------------------


[Microsoft SQL Server Native Client 10.0]: Login failed. The login is from an untrusted domain and cannot be used with Windows authentication.


---------------------------


OK


---------------------------


Step 4:


Made a registry change to " DisableLoopbackCheck" under " HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa"


We added this registry change and rebooted, still it was failing with error below


SQL Server Native Client Data Link Error


---------------------------


[Microsoft SQL Server Native Client 10.0]: Login timeout expired [Microsoft SQL Server Native Client 10.0]: A network-related or instance-specific error has occurred while establishing a connection to SQL Server. Server is not found or not accessible. Check if instance name is correct and if SQL Server is configured to allow remote connections. For more information see SQL Server Books Online. [Microsoft SQL Server Native Client 10.0]: Named Pipes Provider: Could not open a connection to SQL Server [53].


---------------------------


OK


---------------------------


Step 5:


I collected Netmon and Profiler , I could see all the connections and communication happening from BIZTAlk server to SQL Server in SQL Profiler & Netmon but still we could see Login failed issue.


Steps 6:


Checked for Kerberos, Kerberos was not enabled on Active Directory.


We enabled Kerberos on active directory. I could also see correct SPN for SQL account for SQL server but again it was same result.


Even after changes and correct settings BizTalk was not able to successfully connect to SQL server.


Thought may be issue with security.


We added the SQL account to "Access this computer from network" Policy under Local Security Policy -> Local Policies -> User Rights Assignment -> Access this computer from network"


This resolved the issue for us.


Yes, only this setting under Local security Policy didn’t resolve the issue along with that Kerberos was very important.


Hope this blog and my experience will help you to troubleshoot similar issues.


Happy Troubleshooting!!!!



Author : Archana(MSFT) SQL Developer Engineer, Microsoft


Reviewed by : Snehadeep(MSFT), SQL Developer Technical Lead , Microsoft