Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
RFC2324
Jun 7, 2012

http 418

MC Fruit Stripe posted:

Ima smack the poo poo out you kid, Frisco is amazing.

We did think about Carrollton though - good central location, on the rise with Castle Hills. But, Frisco, come on, it's Frisco.

We have Sneaky Petes :colbert:

Adbot
ADBOT LOVES YOU

J
Jun 10, 2001

Migishu posted:

So I mentioned to my manager if they could try to not scheduled meetings before I start as it makes it hard for me to get to them, and they were all cool with it.

So instead they scheduled a 1hr meeting with a whole bunch of people at a time where I have another 1hr meeting.

For fucks sake.

Meetings are hard. A while ago a bunch of VIPs kept managing to schedule conflicting meetings in the same conference room. Eventually it somehow fell into my lap to write up how to include the conference room in your meeting request so that it would appear booked to others, which I did. As it turns out, that was too hard. An executive assistant ended up printing out a room reservation form that had name, date, and time of meeting on it and taping it to the conference room door. That didn't last long, for reasons that I never heard. They ended up just going back to the original system of booking conflicting meetings and arguing about it. :shrug:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Alereon posted:

Not work-related, but I built a gaming computer out of oldish but still decent parts as a favor for a family friend who has a gamer son but not enough money to keep them equipped. A couple months later it stopped booting Windows with an INACCESSIBLE BOOT DEVICE error, so I assumed the HDD failed. After running diagnostics I couldn't find the problem, turns out the kid found a Tumblr saying if you went into the BIOS and set the SATA controller to IDE mode, you'd get higher framerates in League of Legends :psyduck:

:allears:

On the bright side, take this chance to explain what those actually are to help build a technically educated kid that will not be asking us to "do the needful" in 15 years.

nitrogen
May 21, 2004

Oh, what's a 217°C difference between friends?

MC Fruit Stripe posted:

Ima smack the poo poo out you kid, Frisco is amazing.

We did think about Carrollton though - good central location, on the rise with Castle Hills. But, Frisco, come on, it's Frisco.

Frisco: home of the MILF.

BaseballPCHiker
Jan 16, 2006

Fractale posted:

there was a point, many years ago, a tech manager was questioning my technical background because i used linux.

he thought linux was a virus.

the CTO wouldn't go to icanhazip.com because he thought he could get hacked by the website, even though it could clearly benefit for our project on many levels. it also was cleared by websense.

but nope, gonna get hacked.

Wasn't there a guy around here who worked for a school or something that got a new hotshot CIO that came in and made some dismissive claim about Linux and then took the dudes laptop without his knowledge, formatted it and installed windows?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Please tell me that did not actually happen.

MC Fruit Stripe
Nov 26, 2002

around and around we go
Oh it absolutely did, that was an instant classic

FlapYoJacks
Feb 12, 2009
I like the recruiters who refuse to acknowledge that a company needs to actually pay for relocation.

recruiter: The job is in NYC
me: Great; what's the relocation package?
recruiter: Oh they don't have a relocation package, but you can move you, and your family/dog out there on your own dime right?

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD

nitrogen posted:

Frisco: home of the MILF.

Bored housewives make the best girlfriends

Skandranon
Sep 6, 2008
fucking stupid, dont listen to me

Alereon posted:

Not work-related, but I built a gaming computer out of oldish but still decent parts as a favor for a family friend who has a gamer son but not enough money to keep them equipped. A couple months later it stopped booting Windows with an INACCESSIBLE BOOT DEVICE error, so I assumed the HDD failed. After running diagnostics I couldn't find the problem, turns out the kid found a Tumblr saying if you went into the BIOS and set the SATA controller to IDE mode, you'd get higher framerates in League of Legends :psyduck:

Cmon, that is pretty funny. Way better than the old "PRESS ALT-F4 TO LOAD MAP FASTER!!!".

lord of the files
Sep 4, 2012

BaseballPCHiker posted:

Wasn't there a guy around here who worked for a school or something that got a new hotshot CIO that came in and made some dismissive claim about Linux and then took the dudes laptop without his knowledge, formatted it and installed windows?

i have no idea, but if the guy installed windows 8.1 on it i'd assume that the guy was either a sadistic rear end in a top hat or legitimately concerned because it might've had KALI?

lord of the files
Sep 4, 2012

Alereon posted:

Not work-related, but I built a gaming computer out of oldish but still decent parts as a favor for a family friend who has a gamer son but not enough money to keep them equipped. A couple months later it stopped booting Windows with an INACCESSIBLE BOOT DEVICE error, so I assumed the HDD failed. After running diagnostics I couldn't find the problem, turns out the kid found a Tumblr saying if you went into the BIOS and set the SATA controller to IDE mode, you'd get higher framerates in League of Legends :psyduck:

gotta git gud on dem MOBAs.

at least he didn't sign up for those free riot point cards, i hear a lot of those sites run some malicious scripts.

RFC2324
Jun 7, 2012

http 418

Skandranon posted:

Cmon, that is pretty funny. Way better than the old "PRESS ALT-F4 TO LOAD MAP FASTER!!!".

mewse
May 2, 2006

Alereon posted:

Not work-related, but I built a gaming computer out of oldish but still decent parts as a favor for a family friend who has a gamer son but not enough money to keep them equipped. A couple months later it stopped booting Windows with an INACCESSIBLE BOOT DEVICE error, so I assumed the HDD failed. After running diagnostics I couldn't find the problem, turns out the kid found a Tumblr saying if you went into the BIOS and set the SATA controller to IDE mode, you'd get higher framerates in League of Legends :psyduck:

Kid was clever enough to change that setting but not to change it back?

Super-NintendoUser
Jan 16, 2004

COWABUNGERDER COMPADRES
Soiled Meat
Ugh. So now I get to figure out this:

The system we are installing at MAJOR BANK, does LDAP authentication. However, you have to setup a user on our system, and then link it to an LDAP dn, which then allows you to authenticate. Their ldap usernames are, for example mine would be IVEJON, but in our system they requested login in firstname.lastname.

Now, overnight they publish this list of user entitlement changes, so "x user is hired, he gets access to your system, y user is fired, loses access, z username changes due to marriage" or whatever. Our system needs to scoop up this data, and then use it to re-write our users table with all the changes.

This isn't a problem. What is a problem, though, is the only identifier they give us in this list is the users email address. Which is neither the login name for our system or their LDAP username. Furthermore, I need to then figure out their LDAP dn, which includes something like this:

cn=IVEJON,ou=NYC,ou=USA,ou=USERS,ou=ACCOUNTS,dc=bankdn,dc=com

The last five items aren't regular for anyone, also they have several different domains, so each user lives in one of them, but I don't know which. Nor do I know the location or region they are in.

The source of the list has no way of adding more data, because a bunch of other services scoop it up, so if they changed the CSV they generate, it could break all of them. Another problem is that sometimes they move users, so I need to be able to scrub users and change their identity in our table. I need to do this on a linux system that I don't have root on, and I also can't install software on. Then I need to somehow integrate with our java-based servlets that read/write the data.

I told them it's impossible, because I have no way of actually linking what I'm given to any sort of LDAP identity. I think they'll give me their windows login too, which is DOMAIN\IVEJON, so with that, I can get started, but without installing ldaptools on the server, I don't think I can do it.

Skandranon
Sep 6, 2008
fucking stupid, dont listen to me

mewse posted:

Kid was clever enough to change that setting but not to change it back?

Probably panicked like in above picture, and higher level thinking went out the window.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

SIR FAT JONY IVES posted:

Ugh. So now I get to figure out this:

The system we are installing at MAJOR BANK, does LDAP authentication. However, you have to setup a user on our system, and then link it to an LDAP dn, which then allows you to authenticate. Their ldap usernames are, for example mine would be IVEJON, but in our system they requested login in firstname.lastname.

Now, overnight they publish this list of user entitlement changes, so "x user is hired, he gets access to your system, y user is fired, loses access, z username changes due to marriage" or whatever. Our system needs to scoop up this data, and then use it to re-write our users table with all the changes.

This isn't a problem. What is a problem, though, is the only identifier they give us in this list is the users email address. Which is neither the login name for our system or their LDAP username. Furthermore, I need to then figure out their LDAP dn, which includes something like this:

cn=IVEJON,ou=NYC,ou=USA,ou=USERS,ou=ACCOUNTS,dc=bankdn,dc=com

The last five items aren't regular for anyone, also they have several different domains, so each user lives in one of them, but I don't know which. Nor do I know the location or region they are in.

The source of the list has no way of adding more data, because a bunch of other services scoop it up, so if they changed the CSV they generate, it could break all of them. Another problem is that sometimes they move users, so I need to be able to scrub users and change their identity in our table. I need to do this on a linux system that I don't have root on, and I also can't install software on. Then I need to somehow integrate with our java-based servlets that read/write the data.

I told them it's impossible, because I have no way of actually linking what I'm given to any sort of LDAP identity. I think they'll give me their windows login too, which is DOMAIN\IVEJON, so with that, I can get started, but without installing ldaptools on the server, I don't think I can do it.

Godspeed brave soldier. (That wasn't helpful, I know)
Alternatively if I think of some other way to do this I'll post back, but ldaptools is obviously the goto answer here.

nielsm
Jun 1, 2009



Skandranon posted:

Probably panicked like in above picture, and higher level thinking went out the window.

Or the idea that changes seen are straight up irreversible.

My first experience with tech support was when I was 8 or so, 1992 or 1992. I was toying around with DOSSHELL on my parent's IBM. Some time before I had read about having a boot diskette being an important recovery tool, in case something goes wrong with a computer. And I had prepared one!

It just happened that DOSSHELL froze hard, at least sufficiently hard that I couldn't get it to live again, and I had the thought: Ooh, if I turn off the computer now I'll definitely need that boot disk. So turn off PC, plop in boot disk, turn back on, and what happens?
pre:
Enter current date: 
Enter current time: 
A>_
Well gently caress! The computer forgot the date and time, the prompt is all wrong, and I can't start Windows either now! Computer broken!

Call IBM's support. The suggestion is obviously to just remove the diskette and reboot, and everything works as it should.
Crisis averted.

The knowledge I was missing, was that first, a boot disk is not necessary for most normal crashes, second that a computer can boot in many ways and they don't necessarily reflect on each other, and lastly that a boot disk usually needs something more than just FORMAT A: /S on it, to be useful.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

nielsm posted:

a boot disk usually needs something more than just FORMAT A: /S on it, to be useful.

This is the best boot disk

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.

J posted:

Meetings are hard. A while ago a bunch of VIPs kept managing to schedule conflicting meetings in the same conference room. Eventually it somehow fell into my lap to write up how to include the conference room in your meeting request so that it would appear booked to others, which I did. As it turns out, that was too hard. An executive assistant ended up printing out a room reservation form that had name, date, and time of meeting on it and taping it to the conference room door. That didn't last long, for reasons that I never heard. They ended up just going back to the original system of booking conflicting meetings and arguing about it. :shrug:

We have four conference rooms here and plenty of conflicts. I configured a room list in Exchange so now everyone can see availability quite easily. The list will even display any open conference room based on the time needed.

No one uses it.

evol262
Nov 30, 2010
#!/usr/bin/perl

SIR FAT JONY IVES posted:

I told them it's impossible, because I have no way of actually linking what I'm given to any sort of LDAP identity. I think they'll give me their windows login too, which is DOMAIN\IVEJON, so with that, I can get started, but without installing ldaptools on the server, I don't think I can do it.

Non-comedy suggestion from years in banking:

Build the openldap client utils (and any dependencies you need) in your homedir.

If they have some annoying security script which checks homedirs for executables (they might), remember that you can execute binaries with "/lib64/ld-linux-64-64.so.2 /path/to/ldapsearch". You could do all of this in a non-executable script which you exec directly as "bash somescript" or "python somescript" (security people should be mad that this is a suggestion)

If they use a regular number of letters (IVEJON looks like the first 3), and their email scheme follows any normal format (and isn't ${firstletter}${lastname}), you can probably trivially script grabbing those and doing a wildcard LDAP search for the presumed dn, or the first 3 of their last name and first letter of their first name, sending a list of potential matches to some poor sod working the night shift to reconcile.

This all falls down if they require authenticated binds, disabled wildcard searches, or a bunch of other stupid poo poo.

Godspeed indeed.

Alliterate Addict
Jul 10, 2012

dreaming of that face again

it's bright and blue and shimmering

grinning wide and comforting me with it's three warm and wild eyes

nielsm posted:

Or the idea that changes seen are straight up irreversible.

Sometimes they are, sometimes they aren’t. My own “enough knowledge to be dangerous” comes from the time I found “create shortcut” in the context menu in Windows 95. Holy poo poo, these files shrunk so much! I can fit so much more on my floppy now! Now to delete the originals and... wait what

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Hey, look at that, sales pissing me off again.

Cold sales email from Symantic asking for 15 minutes to talk about encryption and data breach solutions.

Subject of such email?

"Data breach"

That's it, nothing else.

You know what? You can just gently caress right off. You do not send me an email with the subject of "Data breach" over a cold sales call. That's borderline phishing and completely unprofessional for a company as large as Symantec. That's what I would expect from those overseas mailing list people, not a multi-million dollar security company.

Caconym
Feb 12, 2013

Gwaihir posted:

I have it good- normal Users can't choose a ticket priority, and even if they ask for a sev1 ticket it can/will only be used for issues that are bringing down entire sites. (Router is dead, whole site down. Vendor's software on the AS400 puked and corrupted some of their their un-journaled database tables, whole state is down :v: , etc. )

Oh, users can't here either, but with 70.000 of the creatures and 2000+ applications poo poo be breaking.

Yes, it's healtcare.

Super-NintendoUser
Jan 16, 2004

COWABUNGERDER COMPADRES
Soiled Meat

evol262 posted:

Non-comedy suggestion from years in banking:

Build the openldap client utils (and any dependencies you need) in your homedir.

If they have some annoying security script which checks homedirs for executables (they might), remember that you can execute binaries with "/lib64/ld-linux-64-64.so.2 /path/to/ldapsearch". You could do all of this in a non-executable script which you exec directly as "bash somescript" or "python somescript" (security people should be mad that this is a suggestion)

If they use a regular number of letters (IVEJON looks like the first 3), and their email scheme follows any normal format (and isn't ${firstletter}${lastname}), you can probably trivially script grabbing those and doing a wildcard LDAP search for the presumed dn, or the first 3 of their last name and first letter of their first name, sending a list of potential matches to some poor sod working the night shift to reconcile.

This all falls down if they require authenticated binds, disabled wildcard searches, or a bunch of other stupid poo poo.

Godspeed indeed.

I set it up on my dev server, and got it to work against my ldap server, so I have a POC of my PM. I put in the requests with their team to install openldap-client, which is all I am missing to make it work. It was actually easier than I figured. Here's my string:

code:
BASH-root@devserver /root# ldapsearch -x -h dc1.em.corp -b "OU=mycompany,DC=em,DC=corp" -D "sir.jony@company.corp" -w MYPASSWORD -LLL "(sAMAccountName=jony.ives)" dn

Returns:
dn: CN=SIR FAT JONY IVES,OU=Ps,OU=Users,OU=Usa,OU=mycompany,DC=em,DC=corp

That should do it. However, I need to use TLS (-Z) and I think I'm allowed to search ldap with the service account they gave me. It works, but I don't know if that's by accident. Hopefully they install that package and I can do what I need. I'm just having an awful time with TLS on my dev server, I can't get the cert to work. Time to head over to the Linux thread for help with that one.

Super-NintendoUser
Jan 16, 2004

COWABUNGERDER COMPADRES
Soiled Meat

evol262 posted:

If they use a regular number of letters (IVEJON looks like the first 3), and their email scheme follows any normal format (and isn't ${firstletter}${lastname}), you can probably trivially script grabbing those and doing a wildcard LDAP search for the presumed dn, or the first 3 of their last name and first letter of their first name, sending a list of potential matches to some poor sod working the night shift to reconcile.

1) The names aren't regular, I have both IVEJON and IVESJON as accounts due to some problems with on boarding. Other users are similarly irregular
2) Their email scheme is firstname.lastname as far as I can tell, but this is a huge worldwide bank, they must have some overlap.
3) It has to be 100% hands off automated. No intern can work around this.

My main problem, is that I'm not a dev. I'm a system engineer, so my job is to get the system setup and all the processes started for the application specialists that are supposed to do all this stuff. Problem is I'm supposed to be doing the ldap authentication setup, which I have working, I just used the test DN they gave me, and it works fine. So I show this to the PM and he says "great, now generate this for all 500 users and import it." I told him "no, that's not my job, get a developer to do that." I have no visibility in to the identity drop box, the upload process, or the import process. Even if I get a methode that works in command line, the AS needs to integrate it with their wonky java process that does the importing.

I'm just going to write a command line script (I don't know python enough) but it will look like this:

./find_dn.bash -o sAMAccountName %s -d ldap.server.com -c creditials_for_listing.file -t tls.cert

and it'll just spit out a dn, then they can just consume that and kill themselves for all I care.

MC Fruit Stripe
Nov 26, 2002

around and around we go
Dear person,

For some reason, I can't say this to you in a professional capacity. If I did, I would be disciplined for having poor communication skills. Personally, I think a statement as succinct as the following indicates strong communication skills, as it cuts right to the heart of the issue. You are a loving idiot and I wouldn't piss on you if you were on fire.

Signed,
Stripe

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer

SIR FAT JONY IVES posted:

I told them it's impossible, because I have no way of actually linking what I'm given to any sort of LDAP identity. I think they'll give me their windows login too, which is DOMAIN\IVEJON, so with that, I can get started, but without installing ldaptools on the server, I don't think I can do it.
Is perl available? Its ldap modules might be useful. Could give you just enough access to the customer's directory structure to get along.

Aunt Beth fucked around with this message at 20:38 on Aug 13, 2015

Super-NintendoUser
Jan 16, 2004

COWABUNGERDER COMPADRES
Soiled Meat

Aunt Beth posted:

Is perl available? Its ldap modules might be useful. Could give you just enough access to the customer's directory structure to get along.

Not sure, I don't know perl, but the developers do. They also know java and python, but you can do it in bash easily, I just need them to give me access and get TLS working, which is unrelated to this nonsense.

mewse
May 2, 2006

Someone getting upset with *me* because of something they told someone else 3 weeks ago, and that someone else is on vacation.

Sickening
Jul 16, 2007

Black summer was the best summer.

RFC2324 posted:

Lewisville is where its at... If you like hellholes, anyway

Man, you got so close to actually live in a nice town like flower mound but missed.

Caconym
Feb 12, 2013

I need to connect to a webservice and no-one could tell me anything about the config.
By poring over enough design documents and some random testing I found out only the front end proxy does authentication, and then forwards the requests on port 80 to the back end.
Also the firewall is open from clients to the back end. :downsgun:

It's the first time I've used the phrase "Well, at least it makes everything but the risk analysis easy." in an email.
Why do I care enough that poo poo like this makes me angry?

Rhymenoserous
May 23, 2008

Alereon posted:

Not work-related, but I built a gaming computer out of oldish but still decent parts as a favor for a family friend who has a gamer son but not enough money to keep them equipped. A couple months later it stopped booting Windows with an INACCESSIBLE BOOT DEVICE error, so I assumed the HDD failed. After running diagnostics I couldn't find the problem, turns out the kid found a Tumblr saying if you went into the BIOS and set the SATA controller to IDE mode, you'd get higher framerates in League of Legends :psyduck:

I now have this wild urge to leave little gems like this all over the internet. Geek Squad will love me.

Rhymenoserous
May 23, 2008

mewse posted:

Someone getting upset with *me* because of something they told someone else 3 weeks ago, and that someone else is on vacation.

"You shoulda put in a ticket :smug:"

Moey
Oct 22, 2010

I LIKE TO MOVE IT
No one ever download VMTurbo's free monitoring software. They will call you everyday, forever.

RFC2324
Jun 7, 2012

http 418

Sickening posted:

Man, you got so close to actually live in a nice town like flower mound but missed.

You have no clue just how close, I am on 3040 halfway between Flower Mound and I-35

MC Fruit Stripe
Nov 26, 2002

around and around we go
Email sent to bosses.

All,

Due to a stomach ache I will have tomorrow, I will be unavailable for most of Friday. I apologize for any inconvenience this might cause.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Moey posted:

No one ever download VMTurbo's free monitoring software. They will call you everyday, forever.

This is a universal truth for any free piece of software that requires contact info to download.

RFC2324
Jun 7, 2012

http 418

MC Fruit Stripe posted:

Email sent to bosses.

All,

Due to a stomach ache I will have tomorrow, I will be unavailable for most of Friday. I apologize for any inconvenience this might cause.

Preemptively calling in hung over has worked for me on a couple occasions.

Adbot
ADBOT LOVES YOU

Daylen Drazzi
Mar 10, 2007

Why do I root for Notre Dame? Because I like pain, and disappointment, and anguish. Notre Dame Football has destroyed more dreams than the Irish Potato Famine, and that is the kind of suffering I can get behind.
Due to a paperwork snafu the entire SharePoint team was given an unexpected week-long vacation. At least, that's what they've been told. The last time it happened our EMC guy was told he'd be back in 6 weeks or so - we didn't see him again for 9 months. If the Air Force SharePoint pages go down, don't expect to see them again for a week or two unless rebooting the servers is the fix.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply