SQL Server Science
Technical Articles for the DBA / Developer
Home » security

Can You Delete That Certificate? The Store Will Not Tell You.

2026-09-17 · by Hannah Vernon · in security

There is a certificate in LocalMachine\My on one of your SQL Servers. Nobody knows what it is for. The subject is unhelpful, it was issued before you started, and the person who installed it has…

sql-login-syncer: Copy SQL Server Logins Without Losing SIDs or Passwords

2026-08-18 · by Hannah Vernon · in security, tools

The spent three posts building up to a practical conclusion: SQL Server maps database users to logins by SID, not by name, and any login you recreate from scratch gets a new SID. showed the…

Logins, SIDs, and Kerberos from First Principles, Part 8: Auditing Logins with Service Broker

2026-08-17 · by Hannah Vernon · in configuration, security

The series so far has answered who can connect ( showed even that requires asking Windows) and how they prove it ( and ). The closing question is who actually does. Group-based access means the…

Logins, SIDs, and Kerberos from First Principles, Part 7: Is Your Kerberos Still Using RC4?

2026-08-16 · by Hannah Vernon · in security, troubleshooting

got your connections onto Kerberos. This part asks an uncomfortable follow-up: encrypted with what? You probably have not thought about Kerberos encryption types recently. That is fair; the protocol mostly just works and has for…

Logins, SIDs, and Kerberos from First Principles, Part 6: SPNs and the Silent NTLM Fallback

2026-08-15 · by Hannah Vernon · in security, troubleshooting

The first five parts of this series were about who you are: SIDs, logins, groups. This one is about how you prove it. When a Windows principal connects to SQL Server with integrated authentication, one…

Logins, SIDs, and Kerberos from First Principles, Part 5: Windows Groups and the Invisible Members

2026-08-14 · by Hannah Vernon · in configuration, security

Every post in this series so far has dealt with principals you can see: a login row in sys.server_principals with a name and a SID. Windows groups break that comfortable assumption. Grant a group a…

1 2 … 5 Next »

Search

Categories

  • AI for DBAs
  • announcements
    • events
  • basics
    • localization
  • configuration
  • Data Architecture
  • DMVs
  • documentation
  • extended-events
  • Git for DBAs
  • High Availability
  • Hot Takes
  • Internals
  • maintenance
    • patching
  • Opinion
  • performance
  • PostgreSQL
  • Professional Development
  • recovery
  • reporting
  • ROLLBACK;
  • security
    • data security
  • service broker
  • SQL Server Agent
  • statistics
  • sys
  • t-sql
    • xml
  • tools
    • data masking
    • wsus
  • troubleshooting
  • Uncategorized

Pages

  • About SQL Server Science
  • Get Better Help with a Minimal, Complete, and Verifiable Example, or MCVE
  • Privacy Policy

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright © 2026 SQL Server Science