Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


Sickening posted:

I am living this hell right now due to old sins by my boss. First, he made the unforgivable sin of making service accounts with simple names. Fax was the username that ran the fax software services. He then also had web facing servers with open RDP access. Of course this means that these boxes have had brute force attempts for years and the guessable account names get constantly locked out.

I am in the process of unfucking these issues right now because we have some friends in russia it appears that is dead loving set on brute forcing these systems after constant blacklisting of their ip's.

Bonus, it appears some of our oldest system have his own loving user account running them as a service. It appears he was resetting his password every 90 days x times (x being the amount he needed to change it back to his old password) to keep services running but was too embarrassed to tell me.

If you don't see any reason why legitimate traffic would come into your network from Russia, China etc. then is blocking it all at your firewall an option?

Adbot
ADBOT LOVES YOU

Super Slash
Feb 20, 2006

You rang ?

wyoak posted:

Anytime a consultant hears "file share" they immediately get a Sharepoint boner
As a little litmus test on the day I asked some people "So a little question, say... what would it be like if you could no longer use the file server? or a better question is how would you describe it?", they pretty much instantly went wide eyed in an panic and I had to quickly allay them saying it's only hypothetical.

So yeah, perspective.

Potato Salad
Oct 23, 2014

nobody cares


Super Slash posted:

As a little litmus test on the day I asked some people "So a little question, say... what would it be like if you could no longer use the file server? or a better question is how would you describe it?", they pretty much instantly went wide eyed in an panic and I had to quickly allay them saying it's only hypothetical.

So yeah, perspective.

You trying to justify a budget increase?

Super Slash
Feb 20, 2006

You rang ?
I'm forever fishing for a budget, this however was more fishing for requirements.

The two girls I asked already sit opposite from me and are completely unrelated to this project, however they do work in customer facing roles so they still apply. It was a good thing their manager was sat nearby as well since their genuine reaction was more explanation ever needed, I just looked at him and said "So... uh, what do you think of that proposal now?"

I think beforehand besides RDS I also asked about Citrix, but that was a no-go since they're a Microsoft shop only.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Thanks Ants posted:

If you don't see any reason why legitimate traffic would come into your network from Russia, China etc. then is blocking it all at your firewall an option?

We block pretty much all countries outside the US on our inbound firewall rules for most of our customers. It's the easiest route to go, though none of them have legitimate business need for inbound connections from outside the US, so that makes it easy.

Starkk
Dec 31, 2008


Last year my company migrated to a new domain. The user registry GUID in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList now has two SIDs, one for the old domain and one for the new domain, both are pointing to the same user profile folder. This hasn't caused too many problems, until now. We are in the process of rolling out Windows 10 in place upgrades to corporate HQ where I work, only for beta users that opt in.

The problem I've been running into is that the upgrade is now duplicating the user profile folder and adding .000 to the end of it. I believe this is because of the migration that happened last year. Windows is seeing the old domain GUID first and attaching the profile folder to it, then it is seeing the new domain GUID with the same path as the old domain and creating a new user profile folder with .000 appended to the end.

This is now causing issues with any program that uses the user profile folder as those programs are still pointing at the non .000 user profile folder.
My googlefu is failing me in finding any situations like this but I'm sure others have run into this? Is there a way to script the removal of the old profile GUID, or maybe put something in the task sequence that ignores the old GUID and only users the new one?

mindphlux
Jan 8, 2004

by R. Guyovich
I am stumped. I have a fresh install of Server 2016 Essentials. I have set up AD, and checked prerequisites for installing Exchange 2016.

I go to install Exchange, and the prerequisites check hangs up on an error starting MSDTC - I believe an access or permissions error. I have tried to troubleshoot the MSDTC service not starting - checked permissions on windows\sys32\msdtc to include all NT AUTHORITY\Network Service accounts, changed ownership of that directory - basically the service just tries to start and immediately stops.

Not sure why this would happen on a fresh install. Anyone have any troubleshooting tips? I can't seem to figure out where MSDTC events are being logged, which I'm sure would be a start...

peak debt
Mar 11, 2001
b& :(
Nap Ghost
Did you look under Event Viewer -> Application Logs -> Microsoft ?
Microsoft has lately started putting all their stuff there instead of the old Windows Logs.

If you still can't see anything, try the menu View -> Show Analytic Logs

mindphlux
Jan 8, 2004

by R. Guyovich
dude get on aim

12:29 AM - ╚╔╩╦╠ mindphlux: goddamnit
12:30 AM - ╚╔╩╦╠ mindphlux: I spent like 7-8 hours on this
12:30 AM - ╚╔╩╦╠ mindphlux: https://blogs.msdn.microsoft.com/distributedservices/2015/03/08/the-dtc-service-cannot-start/#comment-8555
12:30 AM - ╚╔╩╦╠ mindphlux: gently caress msdtc
12:30 AM - ╚╔╩╦╠ mindphlux: people kept telling me it had to do with a permissions issue or I needed to reinstall windows components or some poo poo
12:31 AM - ╚╔╩╦╠ mindphlux: just one stupid registry key keeping msdtc service from starting because it thought SYSPREP IN PROGRESS BWEEP ALERT DANGER

Dr. Arbitrary
Mar 15, 2006

Bleak Gremlin
Does anyone have a good resource on figuring out the basics of NuGet, OneGet, Chocolatey, etc.?
I'm supposed to get something sorta like apt-get set up for windows at work, and I'm not sure I understand which one does what.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Dr. Arbitrary posted:

Does anyone have a good resource on figuring out the basics of NuGet, OneGet, Chocolatey, etc.?
I'm supposed to get something sorta like apt-get set up for windows at work, and I'm not sure I understand which one does what.
NuGet is mostly geared towards developers using Visual Studio, and it's maintained by Microsoft.
Chocolatey is supposed to be more of a fully-featured package manager but it's pretty bad and I wouldn't recommend using it.
OneGet is like Chocolatey, but for package managers or repositories. So you install OneGet, and then you install OneGet's repo for Chocolatey or PECL or Ruby gems or whatever.

What does your end goal look like?

Dr. Arbitrary
Mar 15, 2006

Bleak Gremlin

anthonypants posted:

NuGet is mostly geared towards developers using Visual Studio, and it's maintained by Microsoft.
Chocolatey is supposed to be more of a fully-featured package manager but it's pretty bad and I wouldn't recommend using it.
OneGet is like Chocolatey, but for package managers or repositories. So you install OneGet, and then you install OneGet's repo for Chocolatey or PECL or Ruby gems or whatever.

What does your end goal look like?

End goal is that we've got a central repository of trusted software at versions that we like, and there's an effective tool for getting that software onto servers when requested, or updated when puppet or some other tool notices that some server has an ancient version of putty installed.

Methanar
Sep 26, 2013

by the sex ghost

Dr. Arbitrary posted:

End goal is that we've got a central repository of trusted software at versions that we like, and there's an effective tool for getting that software onto servers when requested, or updated when puppet or some other tool notices that some server has an ancient version of putty installed.

What about using something like S3, or your own webserver, to host a repo of MSIs and having puppet pull those down.

FISHMANPET
Mar 3, 2007

Sweet 'N Sour
Can't
Melt
Steel Beams
This is why I think "devops" and "infrastructure as code" is dumb and stupid, at least on the windows side. There isn't even a standard way to install software? It's hopeless.

buffbus
Nov 19, 2012
I've used SCCM at the last few places I've been. When properly configured, users can either have software silently pushed based on custom queries or they can open a menu and select it.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

"properly configured"

:(

buffbus
Nov 19, 2012
Yeah, "properly configured" isn't usually the state in which I find it, not to make it sound impossible to set up. It's just that many admins try to use it like an old version of altiris and manually feed it computer names for software targeting, not aware how flexible it can be.

devmd01
Mar 7, 2006

Elektronik
Supersonik
Oh God, Altiris/Symantec Management Platform. I had the displeasure a while back of standing up a brand new SMP 7.1 install to replace an old DS 6.x, that was painful.

Without any vendor help, just the basic one week administration class.

Squatch Ambassador
Nov 12, 2008

What? Never seen a shaved Squatch before?
I was playing around with the Win10 Creators Update this morning, and I noticed the dialog box for copying profiles now has a "Mandatory Profile" checkbox. Checking this box when creating a mandatory profile causes the start menu and Win10 apps to not work when signed in with a roaming profile, and if you leave it blank everything works fine. :thumbsup:

Now to wait and see if Microsoft ever releases documentation explaining what that checkbox is supposed to do.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Posting this here too, cause yay this is new with the creators update as well.

Anyone know how to remove this error? It's obnoxious:



Also shows up in the system tray like this.

CLAM DOWN
Feb 13, 2007




What have you set your Windows Firewall to permit inbound?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

CLAM DOWN posted:

What have you set your Windows Firewall to permit inbound?

:mad:

...everything, of course.

Thanks Ants
May 21, 2004

#essereFerrari


Whatever CDN Microsoft use now is better than the one they were using at the time Windows 10 launched. The manual download of the Creator's Update is maxing out our 100Mbps pipe quite happily.

Flummoxed
Sep 21, 2005
I'm not sure the new Security Centre is all hooked up correctly - I most definitely have Windows Firewall off, but it continues to report it as 'Firewall is on'..

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Flummoxed posted:

I'm not sure the new Security Centre is all hooked up correctly - I most definitely have Windows Firewall off, but it continues to report it as 'Firewall is on'..

Yeah mine shows Firewall is off, but it's definitely on.

Hopefully the new admx files are out soon that has some settings to turn off the warnings for this.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Hungry Computer posted:

I was playing around with the Win10 Creators Update this morning, and I noticed the dialog box for copying profiles now has a "Mandatory Profile" checkbox. Checking this box when creating a mandatory profile causes the start menu and Win10 apps to not work when signed in with a roaming profile, and if you leave it blank everything works fine. :thumbsup:

Now to wait and see if Microsoft ever releases documentation explaining what that checkbox is supposed to do.
https://technet.microsoft.com/en-us/itpro/windows/manage/mandatory-user-profile ?????????

Thanks Ants
May 21, 2004

#essereFerrari


Is there a way to change the server that Azure AD Connect tries to write settings back to (it got renamed because it wasn't documented that AAD Connect was on it), or is my best bet going to be to bring Azure AD Connect up on another box in staging mode and then bin the existing instance once I'm sure the sync filtering is configured correctly?

Squatch Ambassador
Nov 12, 2008

What? Never seen a shaved Squatch before?

:confused: I'm not sure what you're trying to say, that page doesn't mention the thing I'm talking about.


If I check that box the resulting mandatory profiles are broken similar to how they were in 1511, but the fixes I used for 1511 don't work. If I leave it blank the mandatory profile works the same as they do in 1607.

CLAM DOWN
Feb 13, 2007




I'm looking for a product that can do file replication between servers in different forests with no trust, I'm hoping to duplicate DFS-R functionality as closely as possible (obvs except for namespaces, etc). Any suggestions?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

CLAM DOWN posted:

I'm looking for a product that can do file replication between servers in different forests with no trust, I'm hoping to duplicate DFS-R functionality as closely as possible (obvs except for namespaces, etc). Any suggestions?

Uhhh, Dropbox?

CLAM DOWN
Feb 13, 2007




GreenNight posted:

Uhhh, Dropbox?

Should specify that this must be on-prem with no internet or cloud anything.

Thanks Ants
May 21, 2004

#essereFerrari


Do you need real-time two-way sync?

CLAM DOWN
Feb 13, 2007




Thanks Ants posted:

Do you need real-time two-way sync?

Optimally being able to decide that per share would be nice, like have some as two-way some as one-way, but yeah real-time a la DFS-R is required.

Maneki Neko
Oct 27, 2000

CLAM DOWN posted:

I'm looking for a product that can do file replication between servers in different forests with no trust, I'm hoping to duplicate DFS-R functionality as closely as possible (obvs except for namespaces, etc). Any suggestions?

I haven't tried it across forests (although it seems to support that use case from the bullet points) but have you looked at peerlink? We have one client that uses it and it's a solid ok:

http://www.peersoftware.com/products/file-collaboration/peerlink.html

Internet Explorer
Jun 1, 2005





Feel free to ignore me if I'm an idiot, but you can use DFS-R without a domain. Couldn't you use it across forests? DFS-N is definitely a no-go, but it seems like DFS-R should work?

CLAM DOWN
Feb 13, 2007




Maneki Neko posted:

I haven't tried it across forests (although it seems to support that use case from the bullet points) but have you looked at peerlink? We have one client that uses it and it's a solid ok:

http://www.peersoftware.com/products/file-collaboration/peerlink.html

I'll check it out, thanks!

Internet Explorer posted:

Feel free to ignore me if I'm an idiot, but you can use DFS-R without a domain. Couldn't you use it across forests? DFS-N is definitely a no-go, but it seems like DFS-R should work?

AFAIK even just DFS-R has to be able to store replication info in a domain. You might be thinking of the old school FRS

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.
DFS-R has AD DS as a hard requirement.

Internet Explorer
Jun 1, 2005





Yeah, you guys are right. I was confusing the purpose of DFS Standalone namespaces, which, as the name implies, is related to DFS-N, but does not require a domain.

Does your storage do file sharing? I know EMC had a pretty good sync, but it's been a while. I think NetApp does too. If those are options, that's where I would look. Have you looked into PeerLink?

CLAM DOWN
Feb 13, 2007




Thanks for the input everyone, yeah I had no illusion that any form of DFS could work here.

I will check out PeerLink, thanks for that tip! I also found this one https://www.goodsync.com/ which looks like it could fill the need perfectly.

We do have EMC stuff available but this is a really specific use case and purpose and it just won't work here, already checked into that. Unfortunate, but I gotta figure out how to fit a solution into these constraints. I'm hopeful that either of those two above software solutions will work!

Adbot
ADBOT LOVES YOU

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


A quick heads up for anyone with WSUS: you might not be able to sync with Microsoft Update right now if you have the Upgrades classification selected. Turning it off makes syncing function again. It must have something to do with the Creator's Update.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply