Monday, April 1, 2013

CAS Array configurations for Exchange 2010

Came across this while I was having a time getting to know Cas arrays and NLBs!

http://eightwone.com/2010/01/27/exchange-2010s-cas-arrays-nlb/

Friday, March 8, 2013

Redhat agent deployment failure Ops Manager 2012 SP1

Adding more some spice to work, my second agent deployment failed with the following error!

Agent verification failed. Error detail: The server certificate on the destination computer (redhatfs.mydomain.local:1270) has the following errors:
The SSL certificate could not be checked for revocation. The server used to check for revocation might be unreachable.
The SSL certificate contains a common name (CN) that does not match the hostname.
It is possible that:
1. The destination certificate is signed by another certificate authority not trusted by the management server.
2. The destination has an invalid certificate, e.g., its common name (CN) does not match the fully qualified domain name (FQDN) used for the connection. The FQDN used for the connection is: redhatfs.mydomain.local.
3. The servers in the resource pool have not been configured to trust certificates signed by other servers in the pool.

The server certificate on the destination computer (redhatfs.mydomain.local:1270) has the following errors:
The SSL certificate could not be checked for revocation. The server used to check for revocation might be unreachable.
The SSL certificate contains a common name (CN) that does not match the hostname.
It is possible that:
1. The destination certificate is signed by another certificate authority not trusted by the management server.
2. The destination has an invalid certificate, e.g., its common name (CN) does not match the fully qualified domain name (FQDN) used for the connection. The FQDN used for the connection is: redhatfs.mydomain.local.
3. The servers in the resource pool have not been configured to trust certificates signed by other servers in the pool.



The common name in the certificate received from my redhat server was not correct. why??
due to my carelessness, in my first attempt, I had tried to deploy the agents BEFORE creating the DNS host record! When this happens, the agent on Redhat Server sends a certificate with localhost as the CN for the Management Server to sign and verify. Correcting myself, I created a DNS record for the Redhat server and tried redeploying the agent but
no luck while the same error kept coming up.

I removed the Opsmanager agent in Redhat but still no luck.

command: rpm –e scx

trying to solve the issue, I came across the following article on how to change the CN of the certificate presented to the management server.

http://technet.microsoft.com/en-us/library/dd891009.aspX

Eventhough you remove the scom agent on linux, it will not delete the old certificates. you need to change the values of CN to the FQDN of the redhat server. Deleting the files deployed by the agent will work. These files are located in /etc/opt/microsoft/scx folder.

agent deployment for linux servers are not as straight forward as windows servers. Check you covered up your prerequisites! click here for the steps.

I changed the CN to the hostname of the redhat server and tried agent deployment again. and it did succeed!!

Called it a day!

Thursday, November 29, 2012

Resetting a forgotten Administrator Password for windows server 2008 R2

  • Boot onto DVD of Windows Server 2008
  • Choose “Repair your computer”
  • Launch cmd
  • Go to D:\windows\system32 //why D? because the system disk is replaced to D :
  • Rename Utilman.exe to Utilman.exe.bak
  • Copy cmd.exe to Utilman.exe
  • Reboot on Windows
  • Do the keyboard shortcut Windows + U when on the logon screen
  • net user administrator Newpass123 inside the cmd
  • log on with the domain admin account and this new pass
  • change the password to remember it if needed
  • Reboot on the DVD to put back the original Utilman.exe
I will have to try this on a domain controller to check the repercussions!!!

P.S.
it works on a domain controller! time to think about windows security??

Wednesday, November 7, 2012

Exchange Storage Architecture

http://technet.microsoft.com/en-us/library/bb124808%28v=exchg.65%29.aspx

RPC Server Unavailable!!!

One of my clients had a DC in one of the branch sites which dose not recieve replications. I was able to resolve the DNS issues it had and get the zone up and running on the server but AD Replication issue still prevails.

When a replication is forced from AD sites and Services console, it gives out the following error..

I came across this valuable artical on technet while i was on a quick lookout on web. Gotta try these out and check why it goes wrong!! will post my findings soon!

Click here to view the article.

Thursday, August 23, 2012

A Quick view on Dynamic Access Control in Server 8

Hi Guys,

This is a great video which gets Dynamic Access Control in a nutshell. Pretty impressive feature which gets file classification to the next level where the files gets classified depending on the contents!! and isolating the location of the file from classification equation making the life easier for users as well as administrators leveraging centralized management capabilities of the AD!!!

Check the video!


Friday, August 17, 2012

Windows Server 2012 installation Options

Hello mates,  in this post, we will be looking into the installation options of windows server 2012. Server core and full scale installation was available to us since server 2008. But with Sever 2012, the ability to change between the core and full installation and vice-versa without a reinstallation was made available.

Why to and fro?
As we all know, installing the server core reduces attack surface and increase the performance of the box. But with the command prompt available as the only interface for the server, sometimes it can be a cumbersome process to make configurations and so on. With the options available to switch between the core and full installation, GUI becomes a complete toolkit to be used only when needed. 

All right! we start with a Full installation.

Open up a PowerShell console and  type the following command.
uninstall-windowsfeature Server-gui-mgmt-infra –restart

pwrshell

the uninstallation of the GUI will then begin..

remove

Upon the reboot, you may notice the avatar has gone!

startup

When you log in, a command prompt window will greet you. you may use command prompt, windows PowerShell and Remote Server Administration Toolkit to manage and make further configurations.

To revert back to the GUI fire up powershell and enter the following command.
INstall-windowsfeature server-gui-mgmt-infra,server-gui-shell –restart

reinstall

GUI installation will then start and upon completion the server will reboot. Note the the avatar back in the log in screen. Full version of the server will be available without any issue.

log2

Apart form this, “Minimal Server interface” is also available, which is similar to the full installation but without Internet Explorer, Windows Explorer, Desktop and start screen. Microsoft Management Console (MMC), Server Manager, and a subset of Control Panel are still present.
Starting with a Server with a GUI installation, you can convert to the Minimal Server Interface at any time using Server Manager.
Go to server manager> manage> remove roles and features and untick server graphical shell.
 
minimal

Apart from this check this technet article to find details on features on demand and converting an installation to Full version which was installed initially as Server Core.