Search This Blog

Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Monday, January 11, 2021

Event Triggered Scheduled Task - On Process Start

I wanted to run a powershell script when a specific process started.

I knew you could create event triggered scheduled tasks, and have used this before based on a specific event id.. However this time the eventid is going to be the same for a lot of different process start events so needed to find a way to filter this. Turns out you can edit the filter manually in Task Scheduler and this allows you to fully edit the XPath queries of the event XML.

To enable this, you must first turn on Audit Process Tracking for Success, in Local Security Policy


Now in the scheduled tasks

Edit the event filter, the query is below. You can get the field and values from looking at the XML in the event viewer under eventdata
this is the line in the query below that will need to be updated for the specific process.

<QueryList>
  <Query Id="0" Path="System">
    <Select Path="Security">
        *[System[Provider[@Name='Microsoft-Windows-Security-Auditing'] and Task = 13312 and (band(Keywords,9007199254740992)) and (EventID=4688)]]
        and
        *[EventData[Data[@Name='NewProcessName'] and (Data='C:\temp\process.exe')]]
    </Select>
  </Query>
</QueryList>



Share/Bookmark

Monday, May 15, 2017

Changing SQL Server Named Instance from dynamic port to static port - (“The target principal name is incorrect.  Cannot generate SSPI context. “) fun!!

Recently had an issue where an engineer had decided to change an existing SQL Server from using dynamic ports to a static port.

The server was a named instance.

servername\instancename

Having made the change using SQL Server Management Studio (SSMS) on the actual server he did not notice that access to the server instance via SSMS remotely had stopped working.

Trying to connect remotely to the server resulted in a

“The target principal name is incorrect.  Cannot generate SSPI context. “

error dialog appearing.

after a bit of investigation it was clear this was a problem with the Service Principal Name (SPN) that had been created. There are a number of troubleshooting articles about this issue and I list them in the references below.

One of the solutions is to remove and recreate the SPN. This involves using the setSPN.exe, however you need to know structure the URLs. However whilst looking at this I cam across this

Kerberos Configuration Manager for SQL server

This tool actual checks your SPNs and will generate a script to fix it, or you can just click fix and it will run the script.

In the end this is all I used to fix my issue

 

 

References

https://support.microsoft.com/en-us/help/811889/how-to-troubleshoot-the-cannot-generate-sspi-context-error-message

https://support.microsoft.com/en-in/help/2985455/kerberos-configuration-manager-for-sql-server-is-available

https://blogs.msdn.microsoft.com/farukcelik/2013/05/21/new-tool-microsoft-kerberos-configuration-manager-for-sql-server-is-ready-to-resolve-your-kerberosconnectivity-issues/

https://social.technet.microsoft.com/Forums/systemcenter/en-US/b879b1a7-c996-4a3f-8e9d-a70ebdffca44/spns-for-named-sql-instances?forum=operationsmanagergeneral

https://support.microsoft.com/en-us/help/823938/how-to-configure-sql-server-to-listen-on-a-specific-port

https://social.msdn.microsoft.com/Forums/sqlserver/en-US/65bcf7a3-ae42-43ae-958e-11dccb123e80/setspn-kerberos-and-named-instances?forum=sqlsecurity

https://social.technet.microsoft.com/wiki/contents/articles/18996.active-directory-powershell-script-to-list-all-spns-used.aspx


Share/Bookmark

Saturday, March 14, 2015

Mounting a windows share permanantly in Ubuntu 14.04

I wanted to setup a machine that would allow me to play music in my garage, as such I thought it would be a good exercise to use Ubuntu as I spend most of my life in Windows.

My music is on a windows machine at home currently and available via a windows share.

The Ubuntu installation of 14.04 was trouble free, and it sees the windows network straight away and I was able to browse around the windows share.
However it was not particularly easy to add these network shares to my playlist in either Rhythmbox or Clementine media players. It must be said that I made certain assumptions that because I could see and browse and play music from the network, after a vanilla install of Ubuntu, I thought everything was in place to access these folders. This is not the case

I wanted a easier a method, and this appeared to be mounting the windows share within Ubunutu permanently. To be honest it sounded straight forward however I encountered a few hurdles and I want to detail here what I did to get this up and running. I have pulled together a few articles/forum posts into this posting. I include these references at the bottom of this page.

In Ubuntu you can mount drives via the mount command, and you can do that manually every time you reboot, however if you want to get it to mount automatically then you need to add commands to the /etc/fstab (file system table) file, which is read by the mount command every time you reboot.

Note: I got confused, being from windows CIFS is an older variation of SMB, and as such is frowned upon. However using cifs in linux seemed to be recommended, eventually I believe this is just a naming issue. It seems that the smbfs is an older deprecated module, and that the current smb/cifs module for ubuntu is called cifs, however it supports current mordern variations of smb (inc 3.02). So by using the vers=3.02 in the options section of the mount command I was able to force SMB version. (I was connecting to a windows 8.1 machine, hence why I could use 3.02).


 As I said a number of items are not installed by default which caused me issues when  trying to mount. These were
  • winbind - netbios name resolution
  • cifs util - provides a helper for connecting to smb shares

Netbios - name resolution 
(not sure if this is needed but its one of the hoops I jumped through)

sudo apt-get install winbind
Then we need to tell Ubuntu to use wins lookup, we do this by editing a file that dictates how and in what order Ubuntu will attempt name resolution. Open the /etc/nsswitch.conf file, look for the line that starts hosts: and add wins prior to dns.

sudo gedit /etc/nsswitch.conf

hosts: files wins dns

Save the file.

CIFS (smb access)
sudo apt-get install cifs-utils

Now we add the mount commands to the /etc/fstab file. Now we can include the username and password as free text in this file, and that may be acceptable in most home scenarios. But we can put the credentials in a seperate file and then restrict access to that file to help protect the contents. This credential file can then be refernced in the mount commands.

gedit ~/.smbcredentials

Note: ~ here is short hand for /home/, now whilst ~ works in the command line you will find it does not always work within files. Therefore you will see later on we expand ~ fully in fstab.

In .smbcredentials enter these two lines, replacing and for the windows username and password
username=  
password=

Save this file.


Lets create the folder where we want to mount the windows share. I used the /media/ folder

sudo mkdir /media/

Ok, now we will enter the commands for the mount command into the fstab file. When Ubuntu is booting it will run these lines against the mount exe.

sudo gedit /etc/fstab

Add the following line (note: you can ommit vers=3.02 and it will default to smb1, however if you know the correct smb vers for your windows machine you should be able to specify it here)
/// /media/Mount cifs credentials=/home//.smbcredentials,iocharset=utf8,sec=ntlm,vers=3.02 0 0

Save the file

Now we can force the mount command to rerun all commands in the fstab file

sudo mount -a

Now everything being good, we should be able to access the windows share under the mount point we created.

In addition the mount should be available after a reboot.

Troubleshooting
I kept getting the following message whenever I tried to mount, this was because I had not installed the CIFS UTILS (again I made the assumption because I browse the network everything was already installed).I believe you can get this message for a number of reasons and the best way to figure it out is to use the command it suggests dmesg | tail

mount: wrong fs type, bad option, bad superblock on //windowsserver/share, missing codepage or helper program, or other error (for several filesystems (e.g. nfs, cifs) you might need a /sbin/mount. helper program) In some cases useful info is found in syslog - try dmesg | tail or so

References
https://wiki.ubuntu.com/MountWindowsSharesPermanently
https://help.ubuntu.com/community/MountWindowsSharesPermanently
https://wiki.samba.org/index.php/LinuxCIFSKernel

https://wiki.samba.org/index.php/Samba3/SMB2
https://www.thomas-krenn.com/en/wiki/Mounting_a_Windows_Share_in_Linux
http://stackoverflow.com/questions/74626/how-do-you-force-a-cifs-connection-to-unmount







Share/Bookmark

Monday, June 09, 2014

Prevent RAS leasing IPs from DHCP server

We had a Windows 2008 R2 server that was setup as a network policy server, which I believe installed the RAS service. Now the server has been around for a while so I must add that I am not sure if RRAS had been installed in the past and used, and then uninstalled, but RRAS was not installed at this time.

We were having an issue that this RAS server was grabbing blocks of 10 IP addresses from our DHCP server. After looking into this in became apparent that it was probably RRAS that was responsible, however as I say it was not installed. I did not fancy installing the RRAS role (in case it screwed up the current setup).

So…. I went looking for a Registry setting to turn off DHCP leasing for RAS or reduce the number of IPs that it gobbled up. Eventually I cam across this setting, which by default (or absence) is 10. This setting tells RAS how many IP addresses to grab.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\IP
Value Name: InitialAddressPoolSize
Data Type: REG_DWORD

Now this looked promising so I opened this key in the registry, and then stumbled across this beauty. This seemed to be more to my liking… actually turning DHCP leasing off… Surprised smile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters\IP
Value Name: InitialAddressPoolSize
Data Type: REG_DWORD
Value: 1

It was set to one, and a quick lookup found something for windows CE, that stated 1=on and 0=off.

  1. So I changed to 0.
  2. deleted the DHCP leases and restarted the RAS service.

Hoorah no more DHCP leases from the RAS server.

I am hoping this is correct, if you want to try it, its at your own risk. But for now it seems to have worked.

References

http://community.spiceworks.com/topic/97183-prevent-ras-entries-in-dhcp


Share/Bookmark

Sunday, July 28, 2013

XenServer Installation–Dell R710

I recently had to install XenServer onto a Dell R710.

This is an unlicensed install, Xen Server is now open source so this valid.

However in a unlicensed install updating the xenserver has to be down via the console.

Note: I had issues installing on to the R710 initially, I kept getting an unrecoverable error message. Stating something about the utility partition being unsupported on partition 2 (I cannot remember the exact message but I could not find anything on the internet about the message). However I fixed the problem by recreating the RAID5 array (PERC H700) and then reinitialising the array. Then I could happily install XenServer.

Once installed, I was able to browse to the XenServer IP I assigned via http, and I download XenCenter.

Once downloaded, I installed XenCenter on my Windows 7 x64 machine.

I then added the XenServer to XenCenter.

I then bonded to of the NICs together in an active-passive format (for redundancy). This took the nic setup I chose during installation, and applied it across the bonded nics. It was very easy to do.

There were 2 hot fixes to apply and this is where it started to depart from easyland.

With the unlicensed version they do not support installation of updates very the XenCenter, which would have been nice, you have to use the command line. I am not familiar with XenServer so this process was a bit alien to me.

1. Download the hotfixes and unzip the files.

2. Connect to XenServer via SFTP (I used FileZilla via SFTP, using root to connect).

3. I then changed to the \tmp folder and created a \tmp\updates folder, and uploaded the hot fixes into that folder. You only need the *.xsupdate files, not the *.tar.bz2 files.

4. Now we have to add to the pool database. In XenCenter goto the console. Change directory to the \tmp\updates folder.

5. xe patch-upload filename=<Path of file and name>

6. Record the UUID that is returned. Repeat step 5 for however many updates have been uploaded.

7. Run xe patch-list, this will list out the updates and you can check. 

8. Run xe host-list, this will list out the UUID of the hosts. Not these UUIDs as these will be needed.

9. Now run xe patch-apply uuid=<UUID of the patch> host-uuid=<UUID of the host>

10. Repeat for all updates and then reboot the host server.

11. Once the reboot has completed you should be able to review the updates in XenCenter under the General tab for the host server, under the updates section.

References:

http://support.citrix.com/article/CTX132791


Share/Bookmark

Tuesday, January 22, 2013

Moving IIS7+ configuration to another IIS7+ server

We have had to move config from one server to another, and we have discovered a general procedure for achieving this. We were just trying to copy over the applicationhost.config, but found sometimes the application pools would fall over.

Now as you might be aware, the majority of IIS7 website config is held in the applicationhost.config file, usually located in the

<windows folder>\system32\inetsrv\config

folder. There are instances where the config will be configured in web.config files, in the root of the website\virtual directory physical folders. But I won’t go into that here.

You can just copy over the applicationhost.config file to the new server, but you will have problems with passwords as the encrypted machine keys will not match. We need to export from the original sever and import into the new server. You can do this.

aspnet_regiis.exe found here

c:\windows\Microsoft.NET\Framework64\v2.0.50727\

Exporting

aspnet_regiis.exe -px "iisConfigurationKey" C:\temp\iisConfKey.xml -pri
aspnet_regiis.exe -px "iisWasKey" C:\temp\iisWasKey.xml -pri

Copy files to new server.

Importing (use -exp so the keys can be exported again)

aspnet_regiis.exe -pi "iisConfigurationKey" c:\temp\iisconfkey.xml -exp
aspnet_regiis.exe -pi "iisWasKey" c:\temp\iisWasKey.xml -exp

This should allow the application pools to properly function.


Share/Bookmark

Thursday, November 29, 2012

Sapphire HD7850–Intermittent Audio Drop Out

Back in June 2012 I created a Home Theatre PC, i was really happy with the setup except that when I ran the audio through the HDMI to the receiver, I had intermittent sound dropouts. Now the dropouts were literally for a second, but it was random and is really annoying.

I tried a number of things, but nothing worked. Anyway I put up with issue for a while, I had other things going on and assumed that etiher Sapphire, AMD or Onkyo (receiver) would fix the issue.

So after 6 months, I have now found a solution. It was in a thread on the issue I was having.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Video\{XXXX...}\0000
( 'XXXX' means device number. There are several device number folder and u should find 'AdapterDesc' in 0000 folder which key value is 'amd radeon HD 7XXX Series'. )
At that '0000' folder, Change 'PP_SclkDeepSleepDisable REG_DWORD' value 0 to 1.

I rebooted, and touch wood the problem has gone.

References are here

http://www.overclockers.com/forums/showthread.php?s=13d1bbb978d7106ac1b27ca8efa9374d&p=7337754#post7337754

There was another solution that seemed to work, but needed to be done after each reboot. The above registry entry should work all the time.

http://www.overclock.net/t/1295464/intermittent-hdmi-audio-output-on-7970-12-8-drivers


Share/Bookmark

Thursday, April 26, 2012

Create an anonymous share in Windows 2008 server

I wanted to mount an iso in Hyper-V across a network share, however Hyper-V will not let you do this. It is due to security which I won’t go into here. To get round this you have to either copy the iso locally or create the remote share to allow anonymous access. Now this is obviouly a security issue, so  you should judge whether this solution is suitable for you, but for me it makes sense.

I am grabbing the necessary fragment from a fuller article here by Scott Havens.

In an environment without Active Directory (like my home network), or when the machines in question are in domains that don’t talk with each other, we need something else.  One option is to enable anonymous access to the share where the ISOs are stored.  This solution is fine for my home network, and may be feasible for other small networks where security isn’t as much of an issue.  While the instructions below are for Windows Home Server specifically, they are easily adapted to a bog-standard (non-WHS) file server.

  1. First, go to Administrative Tools->Local Security Policy.

    In Security Settings/Local Policies/Security Options, make the following changes:

    - Network Access: Do not allow anonymous enumeration of SAM accounts and shares – Disabled
    - Network Access: Let Everyone permissions apply to anonymous users – Enabled
    - Network Access: Restrict anonymous access to Named Pipes and Shares – Disabled
    - Network Access: Shares that can be accessed anonymously – Add SOFTWARE (or the appropriate share) to the existing list

    In Security Settings/Local Policies/User Rights Assignment:

    - Access this computer from a network – Add ANONYMOUS LOGON and Everyone if they’re not already there

  2. After closing the Local Security Settings window you’ll need to reboot the server or force application of security policy via gpupdate.
  3. Then, open up Computer Management and go to System Tools->Local Users and Groups->Groups.
    Windows Home Server creates several security groups that provide read-only and read/write access to the shares it manages.  Find which group offers Read-Only access to the share and add Everyone to this group.  On my computer, the Software share is managed by RO_8 and RW_8, so I added Everyone to the RO_8 group.
  4. While you’re in Computer Management, go to System Tools->Shared Folders->Shares.  In the properties for the appropriate share, add Everyone to the Share Permissions.

Share/Bookmark

Wednesday, April 25, 2012

Win2k8R2 - Unable to rename a connection–already exists

I image a lot of machines, saves me having to keep going through the complete setup with each machine.

On a couple of occasions I have had issues with network connections, it seems windows retains the old imaged server nic info, but it sees the hardware on the new server as new. Therefore it will not add them teaming or call them the right name if you have renamed them.

On trying to rename them to the same name you had on the original machine, you will get an error saying the name already exits. But in network connections they will not show up, even if you start device manager and select view\hidden devices they will not show.

You need to run the following from an elevated command prompt

SET DEVMGR_SHOW_NONPRESENT_DEVICES=1

and then open device manager, select view\show hidden devices. The devices that are no longer present on the new machine will be greyed out and can be uninstalled.

You will now be able to rename the connection.


Share/Bookmark

Monday, August 15, 2011

Getting round restricted Windows filenames (unc)

I recently had an issue with restricted filenames.

Normally windows will not let you create a file that has one of the restricted filenames, this is a hangover from windows past.

CON, AUX, COM1, COM2, COM3, COM4, LPT1, LPT2, LPT3, PRN, NUL

One of the systems used a UNC reference to access storage on a remote server share. By using the UNC the access allowed the system to create a file called con.xxxxx.doc, this file was in fact an uploaded user file.

The problem came when a backup process tried to access the file locally and compress and encrypt it. The process failed because of the file name.

So what to do. In the end I used the same trick that allowed the file to be created. I just referenced the file using a unc (\\servername\c$\…. etc..) rather than locally (c:\…. etc..)


Share/Bookmark

Wednesday, July 27, 2011

IIS 7–resetting site to root inheritance

I wanted to reset some sites, on a multiple site IIS server, to pick up their logging settings from the root.

After some digging around I have found that you have to edit the “applicationhost.config” to achieve this.

The file can be found here

%windir%\System32\inetsrv\config

Site information is held within this XML file, find the site section with the corresponding site name you are looking for. In this example “Default Web Site”.

<site name="Default Web Site" id="1" serverAutoStart="true">
<application path="/">
<virtualDirectory path="/" physicalPath="C:\inetpub\wwwroot\defaultwebsite" />
</application>
<bindings>
<binding protocol="http" bindingInformation="*:80:testy.test.commy" />
</bindings>
<logFile logFormat="W3C" directory="E:\weblogs" />
</site>


Now just delete the <logfile ….> entry completely and save.



You should now find in the IIS gui that the logging settings are now picking up the root settings. Hoorah!


Share/Bookmark

Monday, July 25, 2011

Linking Folders (mklink)–(Or adding adding a remote folder within another folder ;o) )

Sounds easy right? Just copy or move it! Buts that's not what I wanted.

I had a server where it had some usb attached storage that I wanted to be available within an existing shared folder… ok let me try and make it clearer..

I had a share on a server called “pictures”, which was a share of a local folder d:\pictures, i could access this share with a unc address

\\servername\pictures

This would show me the content of d:\pictures.

Now I had a lot of archive pictures on a usb drive and ideally I would of like them to be all accessible via the share (i did not really want to have to created another share).

So how do I do this in windows. Well from Vista / Windows 2008 server there is a command called mklink. This command allows you to add a reference to another folder within a folder.

So we have d:\pictures and in there we have a range of folders and files. Now out usb drive is attached and using the drive letter z:\. So I want to allow the contents of z:\ to be visible within d:\pictures. So I use the following command form the command prompt within the d:\pictures folder.

mklink /D /J externalStorage1 Z:\

Now if I dir in the d:\pictures folder, I will see a new folder called externalStorage1 and if I change directory to externalStorage1 I can see the contents of the z:\ drive. In addition if I browse the share remotely

\\servername\pictures

you will find that you can see and access externalstorage1.

excellent.

Note: You must use /J to create what they call a directory junction (a hard link to a folder), there are hard and soft links and I will leave you to work out the differences. However I will say that if you don’t use /J and you will find that the link will not work when viewing across the network share.


Share/Bookmark

Wednesday, July 20, 2011

Installing multiple certificates on multiple remote servers

note: While doing this I had a strange issue where the certutil (running via psexec ) started complaining about arguments “Expected no more than 1 args, received x”). The command was running fine before, it just stopped working and returning this error. In the end I wiped the certutil command file (CertUtilCommands.bat) and built it from scratch, running certutil –f initially which got a dump output, then built up to the full command, doing this got the whole process working again. Its a strange one and I cannot explain it but this got it working again)

Disclaimer: While I believe all will work below, I cannot guarantee it. Please ensure you test before trying anything (which is of course what everyone does).

In my first article about installing certificates to multiple servers I used ps exec to install one certificate in pfx format.

The time arose that I had to renew this certificate, but the supplier had also changed one of their upstream server certificate so I had to install that to. So what I have done is reworked my first article and built a mechanism that allows the certutil commands to be contained in one file.

Now I wanted to attach a file to this blog post with all the necessary files, however that was not possible as blogger will not allow me to attach files… Sad smile…

So below I show the folder structure, describe folder purpose and then I give the file contents for all the batch files.

Folders

image

  • pstools is available from Microsoft here
  • CertutilFiles, this folder contains the certuil files needed to be copied to the remote machine. These files should be from a Win2k3 server (see image below).

image

  • CertFiles – This is where to put the certificate files (*.crt, *.pfx) etc that you want to install.
  • reports – this is an empty folder that will contain outputs of stdout for the commands run. May help if issues encountered.

Files

serverlist.txt – a basic list of the servers you want to run the commands on. This will obviously need to be changed to your server list.

server1
server2


cc.bat – this is the primary file (run cc from the command prompt). It will prompt you for information.



ECHO OFF
:InputServerList
SET /p vserverList=Please enter filename of server list (default="serverlist.txt") :-

IF "%vserverList%"=="" (
SET vserverList=serverlist.txt
)

SET voptions=

SET /p vuser=Please enter username (default="<system account - will not have network access on remote machine>") :-

IF NOT "%vuser%" == "" (
SET voptions=-u %vuser%
) ELSE (
GOTO nouser
)

SET /p vpassword=Please enter password :-

SET voptions=%voptions% -p %vpassword%
GOTO userset

:noUser
SET voptions=-s

:userset


MD reports

FOR /F "eol=# tokens=1 delims=," %%A IN (.\%vserverList%) DO START CMD /C "startcerts.bat %%A %voptions% %vuser%>reports\output_command_%%A.txt"



startcerts.bat – This sets up a windows share on the local machine, this will allow the remote server to copy the files. The local computer IP is passed to the remote server, (IP passed only if nslookup works locally resolving the computer name to an IP), if this fails the computer name is passed. (If the computername is passed to the remote server then it will need to be resolvable at the remote server.).


The share will be removed at the end of the process.




note: I have found that psexec has issue with some antivirus software (returning all pipes busy error). If you encounter this then you should stop the antivirus software for the duration of the script. I include a net stop and net start command in the batch file, you will need to add the service name.



note:the script had issue trying to connect back to itself so I have now catered for that scenario by removing the credentials, in the psexec command, if the machine is connecting to itself.




SET Sharename=installcerts2%1
SET localserverip=

FOR /F "skip=4 tokens=2 delims=:" %%A IN ('2^>NUL nslookup %COMPUTERNAME%') DO (
SET localserverip=%%A
)

IF "%localserverip%" == "" (
SET localserverip=%COMPUTERNAME%
)

REM if localmachine name = remote machine reset options to run on local machine
IF /I "%1" == "%COMPUTERNAME%" (
SET voptions=
)

net share %Sharename%=%CD% /GRANT:everyone,READ

REM stop antivirus service, have found on win2k8 servers that this will prevent psexec from running, returning all pipes busy error.
net stop "<antivirus service>"

CALL .\PsTools\psexec \\%1 %voptions% -f -c certRemoteSetup.bat %localserverip% %Sharename%

CALL .\PsTools\psexec \\%1 -s -f -c CertUtilCommands.bat

CALL .\PsTools\psexec \\%1 %voptions% -f -c certRemoteClearUp.bat

REM stop antivirus service, have found on win2k8 servers that this will prevent psexec from running, returning all pipes busy error.
net start "<antivirus service>"

openfiles
/disconnect /A %3

net share %Sharename% \\%COMPUTERNAME% /DELETE


certRemoteSetup.bat – This copies the files in the folders certutilfiles and certfiles to the local windows temp folder (%windir%/temp). Only issue I have found here is that if the computer name of the local machine cannot be resolved from the remote server then the copy will fail as it cannot find the files to run.



xcopy /Y \\%1\%2\CertutilFiles\*.* %windir%\Temp\CertInstall\
xcopy /Y \\%1\%2\CertFiles\*.* %windir%\Temp\CertInstall\


CertUtilCommands.bat – This is the file that will need to be edited for your specific requirements.



C:
CD %windir%\Temp\CertInstall\

Certutil -f -addstore Authroot
.\<certificate1filename>.crt

Certutil -f -addstore CA
.\<certificate2filename>.crt

certutil -f -p
<password> -importpfx .\<certificate3filename>.pfx


certRemoteClearUp.bat – Delete all copied files and remove directory



DEL /Q /S %windir%\Temp\CertInstall\*.*
RD /Q /S %windir%\Temp\CertInstall

Share/Bookmark

Monday, July 11, 2011

Multiple Standalone Windows Servers: DNS Suffix List

note: I am not sure what causes windows to reload this list, but I currently believe if you run ipconfig /flushdns and gpupdate /force this seems to reload the values. OK, in addition to this if they don’t work I have found that if disable and enable one your network adapters this will force the change to be picked up. I had teamed NICs, so was able to disable/enable a secondary adapter so not losing connectivity.

Recently I wanted to add a dns suffix to a range of windows servers, whilst this would have been easy had the servers existed in a domain. All the servers had were standalone so Group policy was not an option.

After searching the internet for a while I was still no clearer in what was the best option for configuring standalone servers. I did not want to mess with primary dns suffixes or have to setup specific connection specific dns suffixes.

I wanted a solution that would apply to all connections on the servers, and a solution I was able to apply remotely to all servers.

After messing with local policies, manual settings and registry settings. The best solution I found was a registry entry.

  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient
  • String Value (REG_SZ): SearchList=dnssuffix1,dnssuffix2,dnss……

So I created a registry file with the necessary entries (see below)

Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient]
"SearchList"="dnssuffix1,dnssuffix2,dnssuffix3"


So a quick script using psexec and this was run on all servers.



Job Done…


Share/Bookmark

Wednesday, July 06, 2011

Win2k8: Change primary dns suffix from command line

A quick one here,  I needed to add dns suffix to some servers that were not in a domain. The servers were all in a WORKGROUP.

I was adding a dns entry to the dns server, so I could get rid of the legacy dependence on host files, which were a nightmare to manage.

So I needed a command that allowed me to do this, and I could then run remotely. The command is netdom, and does other things but below I show how to use it to change the primary dns suffix. The primary dns suffix can be manually changed in windows by going to

  • Control Panel
  • System
  • “Change Settings” (under Computer Name section)
  • “Change”
  • “More”

Example:

    • Servername: TestServer
    • DNS Suffix: testsub.test

netdom computername TestServer /add:TestServer .testsub.test

netdom computername TestServer /makeprimary:TestServer .testsub.test


Share/Bookmark

Sunday, July 03, 2011

Setting up a standalone (non-domain) Windows Server 2008 as Time Server (ntp) and its client servers.

Before I start this I have to say that a lot of the information I give below can be obtained in the following excellent articles. I do recommend reading these articles as it fully explains the w32tmn service.  I have tried to just simplify for my specific scenario.
http://blogs.technet.com/b/industry_insiders/archive/2006/08/29/w32-tm-service.aspx

http://www.piclist.com/techref/os/win/w32time.htm

edit: NTPTool – I used this tool to help me fault find issues, its free and a great little tool (http://www.ntp-time-server.com/ntp-server-tool.html)

note: Please ensure there is nothing running on port 123, existing ntp software, or if you are using the ntptool I refer to, ensure this tool is closed when you are starting the service. The service will start ok, but nothing will work, and even with debugging login turned on you will find the w32tim service does not give you any informative error messages, it will just time out trying to connect.

note: another issue I found was that it would appear that after syncing for a while the clients would then fail to sync. I discovered this after spending hours trying to debug a new client I was setting up (it was behind a firewall so I figured I had something misconfigured. But in the end a restart for the ntp server fixed the problem…..) Grrrr… man I  love wasting my time chasing my tail, thanks MS!. In the end I set up a scheduled task to restart the w32time service daily, hopefully this fixes my issue.

For reference the errors I was seeing the the w32time service log on the client was.

  • “Packet test 8 failed (bad value for root delay or root dispersion).”

additional info: I got this error a few times setting up a new server to talk to the ntp server. In each case it was resolved by a restart of the w32time service on the ntp serve machine. Strange but that's MS.

additional info: mmmm maybe it wasn’t MSs fault….. Smile , I found that while configuring the clients I actually configured the server as well (via scripts) so it was trying to sync with itself. I have now corrected this its syncing with an external source. Fingers crossed this fixes the issue.

additional info: Something I have just discovered is that in Windows 2008 the windows time service is by default set to manual. The trigger to start the service is in task scheduler under Microsoft\Windows\TimeSynchronisation.

This means after a restart the time service will not sync until the scheduler event is triggered, by default this is weekly on Sunday @ 01:00.


I have recently had to setup an internal ntp server to allow our servers to have consistent internal time.

Originally we had an ntp server setup on our firewall, due to an upgrade of the firewall this was no longer possible.

The decision was to create a couple of servers internally to sync with an external (internet) time source and then allow all other internal servers to sync with these servers… Sounds easy enough… :) You’d have thought so….

I was certain you could set windows as a time server, however on investigation I found that it wasn’t a nice straight easy process to setup the ntp server and its client server to sync from the newly created internal  ntp server.

Below I detail what I had to do to get this up and running, and the problems I had and what I did to overcome them.

Background.

Our environment is a server farm containing a number of standalone servers. No Domain, which would have automatically have set up the servers to sync with a DC.

Procedure

Setup ntp server

To force a standalone server to become an ntp server, instead of just an ntp client, you must change a few registry entries.

HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Parameters

In the above registry key check that TYPE is set to ‘NTP’, it should be if the server is NOT in a domain. It was in my scenario.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config\

Modify the DWORD AnnounceFlags, set it to 5 (it probably is set to 10).
5 here is a combination of 0x04 - Always reliable time server and 0x01 -Always time server.

Next we enable the ntp server

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer\

Modify the DWORD Enabled to 1 (should be 0).

Next we setup up the polling interval, if this is default it is probably set to 7 days (604800 seconds).

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\

Modify the DWORD SpecialPollInterval to 1800 (decimal), this will set polling to every 30 minutes.

Now I set up my time source using the GUI (right clicking the clock, adjust date/time settings, etc..) on this server, however as you will see later I had issue with the internal servers doing this. So I include here the w32tm command to do the same thing from the command line, running from the command line fixed the issues I had later.

(Please watch the quotes here, ensure they are the right type (I had issue that something kept reformatting the quotes to “xxx” from "xxx", this caused problems, so is you copy and paste the below command I would replace the quotes manually to ensure you have the correct type. This took me a while to track down.)

w32Tm /configure /manualpeerlist:"timeserver1.com,0x09 timeserver2.com,0x09"  /syncfromflags:manual /update

Here we configure a list of servers for our ntp server to sync to.

/manualpeerlist: This is a space delimited list of servers with mode.

mode (0x09) – Is a code to tell w32time service how to sync. In our case we have combined 2 mode values to create 0x09 (0x01 and 0x08 )

Mode Values

  • 0x01 - use special poll interval SpecialInterval
  • 0x02 - UseAsFallbackOnly
  • 0x04 - send request as SymmetricActive mode
  • 0x08 - send request as Client mode

/syncfromflags: Set to manual which informs the time service that our list of servers is conatined in th peerlist.

/update: Should alert the time service that update to configuration has occurred and it should implement them, it will also resync time.

(more info / more info2)

In the image below I have tried to show the issue that confused me for a while. I was expecting my changes to be picked up by the windows adjust/date time gui. In the example below I  set the peerlist to wwv.nist.gov, the gui was used originally to set the time server to time.nist.gov. All I will say is ignore this diaglog if you are stup w32time from th ecommand prompt this gui is just confusing.image

If you are having issue with the time service not picking up your changes, you can try restarting the w32time service.

net stop w32time && net start w32time

Setup windows servers as ntp clients to our windows ntp server

First we need to change the polling interval so the time service syncs more regularly. The default is probably set to 7 days (604800 seconds).

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\

Modify the DWORD SpecialPollInterval to 900 (decimal), this will set polling to every 15 minutes.

I had real issue just trying to use the server settings value in the “adjust time/date settings dialog” in windows. It just did not work. The only way I got this to work was to use the command line.

w32tm /configure /manualpeerlist:<IP of configured internal ntp server>,<mode> /syncfromflags:manual /update

Now I tried to use (w32tm /resync) to force a rysnc but I got an error message, however I have since found that the clock had synched, so not sure what the error message was about.

w32tm /resync
Sending resync command to local computer
The computer did not resync because no time data was available.

note: if you need to configure a windows 2000 server then this can be done using the command.

net time /setsntp:<server>

net stop w32time && net start w32time

*********************************************************************
*********************************************************************

w32tm Parameters

http://technet.microsoft.com/en-us/library/cc773263(WS.10).aspx

w32tm registry entries

http://support.microsoft.com/kb/q223184/

Setting Up logging for NTP

http://support.microsoft.com/kb/816043

 

Reference URLs

http://support.microsoft.com/kb/816042

http://support.microsoft.com/kb/875424

http://www.streetdirectory.com/travel_guide/114492/computers/how_to_configure_a_windows_time_server.html

http://www.winserverkb.com/Uwe/Forum.aspx/windows-server-networking/10/NTP-bug-in-Windows-2003

Excellent articles on time service in  windows.

http://blogs.technet.com/b/industry_insiders/archive/2006/08/29/w32-tm-service.aspx

http://www.piclist.com/techref/os/win/w32time.htm

NTPTool

http://www.ntp-time-server.com/ntp-server-tool.html


Share/Bookmark

Wednesday, June 22, 2011

Dell Bluetooth, Minicard 370–current updated drivers.

I have a DELL latitude 6500, with this I have a Bluetooth mouse (Microsoft BT 5000). It worked for a month or two and then disconnected from the laptop and then would not re-pair with the laptop.

On review it seemed that by installing the BT drivers from the DELL website for the laptop I could fix this issue.

However on review of the drivers on the DELL site, they are quite old. To cut a long story short finding newer drivers was not easy, however in the end I came across this guy who had done the same thing.

The DELL mini-card is in fact a Broadcom card. He had found drivers on a couple of sites, in the end I grabbed a x64 windows 7 driver from the gateway site.

This allowed me to re-pair my mouse and laptop, and has also given me updated drivers for the Bluetooth stack on my DELL latitude laptop.


Share/Bookmark

Tuesday, May 31, 2011

Windows: Add multiple DNS servers to NIC (netSh)

Note: I have now changed the script slightly. I have added a IPCONFIG /ALL at the top, this allows me to easily review the connection name (and also copy and paste into the input field if needed).
Also I have found the address=”” parameter is not valid in versions prior to netsh in windows 2008, so now it is just addr=””
I have highlighted the changes in PURPLE in the script below.

Recently I had to configure a number of servers. I had to change the dns server IP addresses.

Now I did not want to go through all the servers 1 by 1, changing the IPs in the GUI.

Enter left, Netsh. This great little tool, allows you to configure a whole range of things within windows. But in my case I was just interested in dns servers.

First command sets the default dns server ip, then the following commands add the additional dns servers and specifies where they sit in the order via index=n.

Netsh interface ip set dns name="<connectionname>" source="static" address="x.x.x.x"

Netsh interface ip add dns name="Team 1" addr="x.x.x.x" index=2

Netsh interface ip add dns name="Team 1" addr="x.x.x.x" index=3

Netsh interface ip add dns name="Team 1" addr="x.x.x.x" index=4

Now put this into a batch file and we are laughing. Login and run, job done.

Now this does assume all servers will have a network adapter named the same thing, so I may have to change if I come across a different adapter name. mmmmm, that gets me thinking I can get round that by setting up an input into the batch file……

OK, so I did do that and here is the batch file contents. It prompts for a interface name (it has a default setting, as most of the NICs in my setup have the same name), also takes an comma separated list of dns server ip’s. The first in the server ip list will be the default dns server, and then the rest will be added in order (so the last in the list in the batch file will be the last in the dns server list).

So if you are going  to use this make sure you change the list to dns server ips and also change the defaultNIC variable to your most common NIC name.

IPCONFIG /ALL

SETLOCAL ENABLEDELAYEDEXPANSION

SET DNSServerIPaddresses=10.0.0.1,10.0.0.2,10.0.0.3,10.0.0.4
SET DefaultNIC=Nic1
SET /A Index=1

:InputNetworkAdapter
SET /p vAdapterName=Please enter network adapter name (default="%DefaultNIC%") :-

FOR %%A IN (%DNSServerIPaddresses%) DO (
    IF !Index! equ 1 (
        Netsh interface ip set dns name="%vAdapterName%" source="static" addr="%%A"
    )
    IF !Index! gtr 1 (
        Netsh interface ip add dns name="%vAdapterName%" addr="%%A" index=!Index!
    ) 
    SET /A Index=!Index!+1
)

mmm, this has got me thinking now…. with some psexec magic should be able to get this done remotely without having to connect to each machine….. O well I will save that for another day, I need to get this moving…. Smile

addition – run remotely on multiple servers.

OK, so I did use psexec and it worked a treat. I create two batch files and copied psexec into the same folder. Then I create a list of servers names, the script will prompt for a serverlist. I also created a subfolder called reports, I crate textfile of the stdout of the psexec command. the output contains a ipconfig /all berfore and after running the netsh lines, this will allow for reviewing and you can ensure that the change has held.

This script should happily work on windows 2000, 2003 and 2008 servers.

startAutoDNS.bat

:InputServerList
SET /p vserverList=Please enter filename of server list (default="serverlist.txt") :-

IF "%vserverList%"=="" (
    SET vserverList=serverlist.txt
)

FOR /F "eol=# tokens=1 delims=," %%A IN (.\%vserverList%) DO START CMD /C ".\psexec \\%%A -s -f -c autosetDNS.bat>reports\output_setDNS_%%A.txt"

autoSetDNS.bat

SETLOCAL ENABLEDELAYEDEXPANSION

IPCONFIG /ALL

SET AdapterNames=Team 1,Local Area Connection,Local Area Connection 2,Local Area Connection 3,Local Area Connection 4
REM substitute
SET AdapterNames=%AdapterNames: =/%
SET DNSServerIPaddresses=10.0.0.1,10.0.0.2,10.0.0.3,10.0.04

FOR %%B IN (%AdapterNames%) DO (
    SET /A Index=1
    SET vAdaptername=%%B
    SET vAdaptername=!vAdaptername:/= !
    FOR %%A IN (%DNSServerIPaddresses%) DO (
        IF !Index! equ 1 (
            Netsh interface ip set dns name="!vAdaptername!" source="static" addr="%%A"
        )
        IF !Index! gtr 1 (
            Netsh interface ip add dns name="!vAdaptername!" addr="%%A" index=!Index!
        )
        SET /A Index=!Index!+1
    )
)

IPCONFIG /ALL


Share/Bookmark

Tuesday, May 17, 2011

Throttle a windows network transfer (copy)

A while back I wanted to try and throttle a file copy between servers across a wan link vpn.

I struggled to find a solution to this, however in the end I came across a program from nullsoft (creators of winamp), its a freebie and was developed ages ago. However I have found the program to work extremely well.

To transfer to a network location you have to be able to map a drive to that location, and you can only copy entire folders. But for what I wanted this is fine.

You can then control bandwidth on the slider bar.

The program is called nscopy, it was available from nullsoft directly but that link appears to be gone. However I have found a download here

http://www.softpedia.com/get/System/File-Management/NSCopy.shtml

image


Share/Bookmark

Monday, May 16, 2011

PowerShell: List full path info for all files of specified extensions

I needed to get a list including path of all the files in a massive folder structure of a specified file extensions.

To do this I used PowerShell, using the Get-Childitem cmdlet to list folder content recursively and filtered to just list *.dll’s and *.exe’s. This is then piped to the foreach-object to iterate through and list the full file name (which includes path). This is then piped to the out-file cmdlet which dumps the contents into a text file.

Get-ChildItem \\remoteserver\remoteserverfolderpath  -Recurse -Include "*.dll","*.exe" | foreach-object {$_.Fullname} | Out-File c:\files.txt –width 1024


Share/Bookmark