Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

nielsm posted:

Don't filter on DistinguishedName like that, if you're only interested in objects under a specific OU use the -SearchBase parameter instead. (Is that a real OU in your environment? Do you want that in a post on SA?)

At this point I don't care, but thanks for the thought.

-searchbase keeps returning that I can't search outside our admin DC, whereas filtering distinguishedname at least killed that error.

I'll give your code a shot and see if I don't hang myself.

Edit, yep, same error, supplied distinguishedname must belong to one of the following partitions:'CN=Configuration,DC=Foo,DC=ca , CN=Schema,CN=Configuration,DC=Foo,DC=ca , DC=ADMIN,DC=Foo,DC=ca ,
DC=ForestDnsZones,DC=NorQuest,DC=ca , DC=DomainDnsZones,DC=ADMIN,DC=Foo,DC=ca'.

What I need is on the EDU DC.
And yeah, I guess I do care, so I'm going to go back and edit the DC out.

Bunni-kat fucked around with this message at 19:58 on Aug 25, 2017

Adbot
ADBOT LOVES YOU

nielsm
Jun 1, 2009



But if you do the Filter on DN does that actually find any of the relevant objects? From the error when you use -SearchBase it sounds like your PowerShell AD module can't actually access any other OUs at all.

Tigren
Oct 3, 2003

Ursine Catastrophe posted:

Immersion is the best way to learn :eng101: says the person who devs in python and just got full on dumped into a from scratch golang project

As a python dev learning golang for fun, I think you'll love it. Or at the very least, not hate it. It's pretty simple syntactically and has a great standard library. And "super simple" concurrency is soooo nice.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

nielsm posted:

But if you do the Filter on DN does that actually find any of the relevant objects? From the error when you use -SearchBase it sounds like your PowerShell AD module can't actually access any other OUs at all.

So... there's no way around that, is there?

stevewm
May 10, 2005
Telecom saga continues...

CenturyLink fails for the 3rd time.. But finally got more to the story. No one ever bothered to submit the order to "engineering" so no one ever bothered to even try running the line to the building.

They finally figured this out after the 3rd attempt at installation.


At this point neither provider is going to have service active by opening day (and we ordered back in in the first week of June!). In fact neither provider has even started the work to run lines to our building. So I am having to bring in a CradlePoint router from Verizon Wireless just so we can get internet service! Hopefully they manage not to gently caress that up too.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

nielsm posted:

But if you do the Filter on DN does that actually find any of the relevant objects? From the error when you use -SearchBase it sounds like your PowerShell AD module can't actually access any other OUs at all.

Turns out there's a god-damned -server property I never knew about! Once that was put in, import-csv plus your script worked perfectly.

THANK YOU EVERYONE FOR THE HELP. I worked through lunch bashing my head figuring this out, so I get to go home an hour early.

Thanks Ants
May 21, 2004

#essereFerrari


stevewm posted:

Telecom saga continues...

CenturyLink fails for the 3rd time.. But finally got more to the story. No one ever bothered to submit the order to "engineering" so no one ever bothered to even try running the line to the building.

They finally figured this out after the 3rd attempt at installation.


At this point neither provider is going to have service active by opening day (and we ordered back in in the first week of June!). In fact neither provider has even started the work to run lines to our building. So I am having to bring in a CradlePoint router from Verizon Wireless just so we can get internet service! Hopefully they manage not to gently caress that up too.

Not to gloat but

Thanks Ants posted:

Oh how cute, getting optimistic about a communications provider hitting a schedule.

Sickening
Jul 16, 2007

Black summer was the best summer.
Is there something in chrome and certificates that makes it so much different than loving internet explorer? I have been in the process of properly assigning certs to admin consoles and such for https, but for some reason chrome hates them but internet explorer sees them as being fine.

Thanks Ants
May 21, 2004

#essereFerrari


Trust chain?

If you run it through https://www.ssllabs.com/ssltest/ (assuming you want to do that) do you get any warnings?

MC Fruit Stripe
Nov 26, 2002

around and around we go
People really are helpless. I'm on probably 2 calls per week where we end up sitting around doing absolutely nothing until the meeting organizer arrives, and that person is invariably late because meetings run long and things happen. It's not their fault. We know why we're having this meeting, do we REALLY need the PM to open the discussion with the questions we all know are coming?

Thanks Ants
May 21, 2004

#essereFerrari


Are they actually meetings that need to take place and can't be solved by a few emails, phone calls, chat messages or whatever - or are they meetings that managers use to fill their days with and draw out to the allocated duration?

Scikar
Nov 20, 2005

5? Seriously?

Sickening posted:

Is there something in chrome and certificates that makes it so much different than loving internet explorer? I have been in the process of properly assigning certs to admin consoles and such for https, but for some reason chrome hates them but internet explorer sees them as being fine.

Chrome recently removed support for certificates that use the deprecated CommonName field only, and don't have a SubjectAlternativeName. Most guides out there for setting up an internal CA don't mention this, especially since it's a total pain in the rear end to do in OpenSSL (you have to either add the SAN entries in openssl.cnf or pass them through as envars). It's fairly painless when requesting a cert through AD CS though if your CA is on Windows.

Sickening
Jul 16, 2007

Black summer was the best summer.

Scikar posted:

Chrome recently removed support for certificates that use the deprecated CommonName field only, and don't have a SubjectAlternativeName. Most guides out there for setting up an internal CA don't mention this, especially since it's a total pain in the rear end to do in OpenSSL (you have to either add the SAN entries in openssl.cnf or pass them through as envars). It's fairly painless when requesting a cert through AD CS though if your CA is on Windows.

Yep, just figured that out. Thanks scikar.

MC Fruit Stripe
Nov 26, 2002

around and around we go

Thanks Ants posted:

Are they actually meetings that need to take place and can't be solved by a few emails, phone calls, chat messages or whatever - or are they meetings that managers use to fill their days with and draw out to the allocated duration?
Man I can't even tell the difference anymore

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Avenging_Mikon posted:

Turns out there's a god-damned -server property I never knew about! Once that was put in, import-csv plus your script worked perfectly.

THANK YOU EVERYONE FOR THE HELP. I worked through lunch bashing my head figuring this out, so I get to go home an hour early.

Nice work. On to the next powershell challenge :cheers:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Scikar posted:

Chrome recently removed support for certificates that use the deprecated CommonName field only, and don't have a SubjectAlternativeName. Most guides out there for setting up an internal CA don't mention this, especially since it's a total pain in the rear end to do in OpenSSL (you have to either add the SAN entries in openssl.cnf or pass them through as envars). It's fairly painless when requesting a cert through AD CS though if your CA is on Windows.

Holy poo poo this was actually the secret to an issue I was fighting this afternoon. Thanks for this.

NeuralSpark
Apr 16, 2004

Scikar posted:

Chrome recently removed support for certificates that use the deprecated CommonName field only, and don't have a SubjectAlternativeName. Most guides out there for setting up an internal CA don't mention this, especially since it's a total pain in the rear end to do in OpenSSL (you have to either add the SAN entries in openssl.cnf or pass them through as envars). It's fairly painless when requesting a cert through AD CS though if your CA is on Windows.

Just got hit with this Monday. Sigh.

Crowley
Mar 13, 2003
Someone kill me! I have to move 19 meeting room calendars from Public Folders to O365 Resources. Is there any way I can do this simpler than setting them to list view and copy/past the old (and slow!) way?

ConfusedUs
Feb 24, 2004

Bees?
You want fucking bees?
Here you go!
ROLL INITIATIVE!!





stevewm posted:

Telecom saga continues...

CenturyLink fails for the 3rd time.. But finally got more to the story. No one ever bothered to submit the order to "engineering" so no one ever bothered to even try running the line to the building.

They finally figured this out after the 3rd attempt at installation.


At this point neither provider is going to have service active by opening day (and we ordered back in in the first week of June!). In fact neither provider has even started the work to run lines to our building. So I am having to bring in a CradlePoint router from Verizon Wireless just so we can get internet service! Hopefully they manage not to gently caress that up too.

One of our offices moved, scheduled the install six months in advance, and was still working off of hotspots six months after the move.

Yes, it took a year to get working internet to that location.

Thanks Ants
May 21, 2004

#essereFerrari


I'll never complain about a 60 working day lead time ever again

sfwarlock
Aug 11, 2007
Herewith, the end of Marvin Yellowstache and this whole lovely environment.

(I was let loose on my own Wednesday afternoon and there's so much shadow IT going on here it's ridiculous. There is at least one case where someone brought their old personal laptop, stuck it under a desk, and made it a fileshare with the aid of an external drive. Which of course is now full of files with names like Zootopia.2016.720p.BluRay.DTS.x264-FuzerHD.mkv.)

A few things I learned today:

- The proper way to plug in a new device, such as a USB mouse, to a docking station is to do the following:
-- Shutdown
-- Undock
-- Plug in the new thing
-- Redock
-- Boot up

- Wireless keyboards and mice are useless because only one or two people in a cubicle cluster can have them, otherwise they create "destructive interference" which leads to people typing and mousing on each other's computers. Therefore to be fair no one is allowed to have them.

(Plenty of people have them.)

- Programs with installers usually install viruses* along with the program. But if you can download the program just as an .exe which doesn't install, just runs, it's perfectly safe and doesn't have a virus.

(*: Which, to be fair, is too true these days.)

Today, though. Today... Marvin will sometimes close a ticket even before he does the work so the SLA doesn't time out. (The SLAs there are ridiculous, I have to admit. 4 working hours to close a high priority ticket sounds good on paper until you get three of them at once, because any work stoppage is high priority, right?) That is not a thing that I do, which meant a few of mine timed out. That led to me having a friendly little chat with our boss (who I only met at the interview) about what an SLA is and why it is very important to actually do work.

Then...

Agrikk posted:

throw you under the bus at every opportunity until you are fired for cause

sfwarlock posted:

(This bit him in the rear end about 3 pm today when he handed me a laptop with the post-it "update the bios" on it. It shut off mid update. It is now a paperweight. I looked up the ticket. "Randomly turning itself off." is the key phrase there.)

Guess who got bus-undersided for this paperweighted laptop. Which he claims he cannot recover any data off of.

(Knowing this guy, he probably opened up the hard drive, scrubbed the platter with a wet wipe, dried with compressed air, then broke out the sata-to-ide converter to try plugging it into a 40-pin IDE cable. )

That led to another fun conversation in the mid afternoon.

While I was on the train on the way home, my phone rang. It was the dude from the company that got me in here. He reiterated all of the above and then added that the client said I knew very little about IT and had a bad attitude on top of that. It's not my first gig from him, so he is aware of how off base they are, but he said he has no choice given that feedback but to remove me from the contract. Gladdest I ever was to be fired, I just hope that it doesn't affect my ability to get future gigs from that company.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

sfwarlock posted:

While I was on the train on the way home, my phone rang. It was the dude from the company that got me in here. He reiterated all of the above and then added that the client said I knew very little about IT and had a bad attitude on top of that. It's not my first gig from him, so he is aware of how off base they are, but he said he has no choice given that feedback but to remove me from the contract. Gladdest I ever was to be fired, I just hope that it doesn't affect my ability to get future gigs from that company.

At least your half-completed pod showed up on the ejector rails for you to bail before you got really stuck there. That place sounds like it's exactly one cryptolocker away from insolvency.

Levitate
Sep 30, 2005

randy newman voice

YOU'VE GOT A LAFRENIÈRE IN ME
Why the gently caress couldn't someone rip there hard drive out of the laptop and copy any important poo poo to another

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Levitate posted:

Why the gently caress couldn't someone rip there hard drive out of the laptop and copy any important poo poo to another

You see, he's very bad at IT and has a bad attitude on top of it, so get him out of there before he eventually has enough clout to call Marvin on his bullshit! Marvin will work 'really hard' on the issue and recover the data a few days from now, proving how awesome he is, and how much of a good idea it was to fire that rear end in a top hat sfwarlock.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

sfwarlock posted:

While I was on the train on the way home, my phone rang. It was the dude from the company that got me in here. He reiterated all of the above and then added that the client said I knew very little about IT and had a bad attitude on top of that. It's not my first gig from him, so he is aware of how off base they are, but he said he has no choice given that feedback but to remove me from the contract. Gladdest I ever was to be fired, I just hope that it doesn't affect my ability to get future gigs from that company.

What the flying gently caress

Sorry for comparing you to turtlicious, and it sucks you got fired for essentially being too competent. I feel like some of Marvin's behaviors have been learned to save his rear end from management willing to fire him for not immediately knowing something without googling it.

Wibla
Feb 16, 2011

You dodged all the bullets.


Best of luck on the next one!

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Wibla posted:

You dodged all the bullets.


Best of luck on the next one!

Agreed, sorry it turned out to be poo poo but at least you're not stuck there. Sounds toxic.

DigitalMocking
Jun 8, 2010

Wine is constant proof that God loves us and loves to see us happy.
Benjamin Franklin
poo poo pissing me off: support contracts.

Doing budgets for next year, it would literally cost us less to mothball our core switches and replace them with a new-gen stack with 3/year support than it would be to re-up.

Gave both quotes to my director, I don't care either way, operational or capital. I'd honestly rather just build a stack of new switches, I get more 10gb and 40/80gb ports this way.

edit: I guess I can stack these cores on top of the HP cores that are still in my cube. I'll build a tower of cores.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

DigitalMocking posted:

poo poo pissing me off: support contracts.

Doing budgets for next year, it would literally cost us less to mothball our core switches and replace them with a new-gen stack with 3/year support than it would be to re-up.

Gave both quotes to my director, I don't care either way, operational or capital. I'd honestly rather just build a stack of new switches, I get more 10gb and 40/80gb ports this way.

edit: I guess I can stack these cores on top of the HP cores that are still in my cube. I'll build a tower of cores.

I wonder, do vendors do that on purpose so IT has leverage to get old gear upgraded? :thunk:

Volguus
Mar 3, 2009
The best thing about getting kicked in the butt? Moving forward.

DigitalMocking
Jun 8, 2010

Wine is constant proof that God loves us and loves to see us happy.
Benjamin Franklin

Avenging_Mikon posted:

I wonder, do vendors do that on purpose so IT has leverage to get old gear upgraded? :thunk:

I know they do, but this stuff is 3 years old and still actively sold, it's their only 'core' blade platform.

Wizard of the Deep
Sep 25, 2005

Another productive workday

Avenging_Mikon posted:

Turns out there's a god-damned -server property I never knew about! Once that was put in, import-csv plus your script worked perfectly.

To add to this (and depending on how fuckered your AD infrastructure is), you know how Everything* In PowerShell Is An Object? Half of everything can be a drive, with New-PSDrive and the ActiveDirectory module as the provider. You can specify a domain and domain controller, map it as an AD drive, and treat the users, computers, and groups as objects, while the OUs are kind of similar to folders. Walk down the tree and get-aduser! Create a new group in the OU you're currently in! The possibilities are limitless! The possibilities are also objects.

code:

>New-PSDrive -name contosoEDU: -provider ActiveDirectory -server dc1.contoso.edu
>cd contosoEDU:
PS\contosoEDU:>_

This may not be worth it if you don't have a Active Directory forest that's aspiring to its leafy namesake, like I do. BUT IT'S FUCKIN' SWEET.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

DigitalMocking posted:

I know they do, but this stuff is 3 years old and still actively sold, it's their only 'core' blade platform.

I was kidding, I'm bad at it so I don't blame you for not realizing. There's no way it's for customers' benefit. It's so they can churn out more hardware to keep sales numbers up. If it was to our benefit then your still-produced cores would be cheaper to re-up.

Thanks Ants
May 21, 2004

#essereFerrari


DigitalMocking posted:

I know they do, but this stuff is 3 years old and still actively sold, it's their only 'core' blade platform.

Get a quote to buy them again with support

RFC2324
Jun 7, 2012

http 418


I'm late, but

wrong.

DigitalMocking
Jun 8, 2010

Wine is constant proof that God loves us and loves to see us happy.
Benjamin Franklin

Thanks Ants posted:

Get a quote to buy them again with support

I'm honestly considering just buying a whole new core+blades on ebay and leaving the thing as a cold spare.

For around 8 grand I can get a fully loaded core to use versus spending 42k on support. Half the time the community is better at answering questions than the actual support personnel are.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
Email came in a few minutes ago, "new user starting Monday".

My initial reaction is "guess who's not logging in until after lunch on their first day!" But this lady is going to be on the same org level as me, and it would impact my work to start with a bad impression.

Looks like I'm bailing out their department and working on a Sunday

milk milk lemonade
Jul 29, 2016
If you were actually that dog in your picture I'd be rubbing your nose in that post right now

Thanks Ants
May 21, 2004

#essereFerrari


How are you going to get it done when you aren't even due to see the email until tomorrow morning?

Adbot
ADBOT LOVES YOU

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
That's a pretty good point. I'm more concerned that this supervisor isn't submitting the new employee through the onboarding process implemented early this year.

I guess this one is worthwhile to raise a stink over. Wish me luck, this is the same supervisor I mouthed off to a few weeks ago. He's gonna get real tired of me!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply