Database – Component Services Security Settings question

comdatabasewindows-server-2003

I am getting the error "New transaction cannot enlist in the specified transaction coordinator" when performing a query that uses a database link.

I have asked our Sys Admins to make the following changes (see URL) to our Component Services configuration, specifically the security settings:

http://www.howtogeek.com/howto/windows/fix-new-transaction-cannot-enlist-in-the-specified-transaction-coordinator-on-server-2003-sp2/

These changes are to a server that is behind the corporate firewall. I am trying to anticipate what possible objections our Sys Admins may have be to making this change, since it appears to be loosening security.

Can anyone give me some insight into understanding the risk involved in making this change?

Best Answer

Are both machines that are going to be involved in the distributed transactions win2003 machines? If so, you can use the mutual authentication option instead of the No Authentication option. If one or both of the machines are win2000, then mutual authentication is not possible.

Also, "Allow Remote Administration" probably does not need to be checked off.

See this link: http://technet.microsoft.com/en-us/library/cc753510(WS.10).aspx

These two things may help put your sys admin at ease a bit.