Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

Saturday, 9 July 2016

SQL Server Express 2008 error -2146893007, service won't start for Microsoft Office Accounting 2009

Just discovered the old accounts package, Microsoft Office Accounting 2009 won't load. It reports ExecuteRestricted.exe crashed, then tries to load MS Office Accounts again and prompts to start a new company. After a bit of digging through Event Viewer for useful error codes we found that trying to start the SQL Server (SQLEXPRESS) service failed, reporting error -2146893007.

Event Viewer indicates that this is an SSL related error. So, we realised that TLS 1.0 had recently been disabled on this PC in line with PCI recommendations. We use the excellent IISCrypto utility to achieve this quickly and simply. Reinstating TLS 1.0 (no reboot required) allowed the SQLEXPRESS service to start up again.

Tuesday, 21 October 2014

Another obscure Trustwave PCI scan fail - SBS 2011 fails CVE-2010-3332 / MS10-070, vulnerability in ASP.NET Could Allow Information Disclosure

After clearing up the SharePoint issues, there was just one remaining failure issue in the Trustwave PCI scan of an SBS 2011 server.

The fix turned out to be running the .NET Framework Cleanup Tool from Aaron Stebner at Microsoft, and removing .NET 1.0 and 1.1.

There's some more detailed discussion over at Technet

Monday, 20 October 2014

SharePoint 2010 on SBS 2011 failing Trustwave PCI scan (aka WSS_Search SPSearchDatabase Database is too old)

[ bonus points - that's got to be the biggest post title yet :-) ]

An SBS 2011 server, all patched up with the latest Microsoft Update fixes failed a Trustwave PCI security scan. When we looked at the detail most of the fail points were around SharePoint vulnerabilities.

Looking at the SharePoint Central Administration console, the Health Analyzer was throwing up warnings about out of date databases and upgrades required. they're no entirely straightforward because there's a difference between content databases and other databases.

With SharePoint updates you do need to run the upgrade tool sometimes after Microsoft Updates have been loaded, to get the database to upgrade too.

Start a Command Shell with administrative rights (or the SharePoint PowerShell) and run this command;
PSConfig.exe -cmd upgrade -inplace b2b -force -cmd applicationcontent -install -cmd installfeatures

That cleared all but one of the Health Analyzer warnings for us. The remaining one was the "WSS_Search SPSearchDatabase Database is too old" or more strictly, WSS_Search_servername. We had trouble tracking down that database GUID to issue a PS upgrade, as mentioned on the Technet forum.

Restarting services and rebooting didn't seem to clear either. The only info we could Google was the upgrade command above. In the end, having run the command repeatedly, the database upgraded and the warning cleared. It appeared to take 2-3 repeats of that command before WSS_Search was up to date.

Let you know about the PCI re-scan, I've just requested it ...

Trust 1&1 Internet for your domain name registration, from only £1.99/year!. Check now!