<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>a blog about nothing</title>
	<atom:link href="http://adfordummiez.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://adfordummiez.com</link>
	<description>...besides Active Directory</description>
	<lastBuildDate>Thu, 15 Nov 2012 15:51:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>An overview for ITPros, Introducing Windows 8</title>
		<link>http://adfordummiez.com/?p=413</link>
		<comments>http://adfordummiez.com/?p=413#comments</comments>
		<pubDate>Thu, 15 Nov 2012 15:49:04 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[nothing]]></category>
		<category><![CDATA[learning]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=413</guid>
		<description><![CDATA[If you&#8217;d like a glance/overview of Win8 for ITPros, I recomend you to have a look at the &#8220;Introducing Windows 8&#8243; preview. Text stolen from the MCP newsletter: &#8220;This complimentary e-book explores the great new features Windows 8 offers for IT professionals and businesses. It&#8217;s designed to help prepare you for deployment of Windows 8, [...]]]></description>
				<content:encoded><![CDATA[<p>If you&#8217;d like a glance/overview of Win8 for ITPros, I recomend you to have a look at the &#8220;Introducing Windows 8&#8243; preview.</p>
<p>Text stolen from the MCP newsletter:</p>
<p>&#8220;<em>This complimentary e-book explores the great new features Windows 8 offers for IT professionals and businesses. It&#8217;s designed to help prepare you for deployment of Windows 8, deliver apps, and manage recovery, security, and virtualization</em>&#8221;</p>
<p>You can download it from here: <a href="http://download.microsoft.com/download/B/1/E/B1E7F4C9-304D-456C-BD96-A2287FA7871D/Microsoft_Press_ebook_Introducing_Windows_8_PDF.pdf">http://download.microsoft.com/download/B/1/E/B1E7F4C9-304D-456C-BD96-A2287FA7871D/Microsoft_Press_ebook_Introducing_Windows_8_PDF.pdf</a></p>
<p>&nbsp;</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=413</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IP-HTTPS certificate</title>
		<link>http://adfordummiez.com/?p=399</link>
		<comments>http://adfordummiez.com/?p=399#comments</comments>
		<pubDate>Wed, 03 Oct 2012 10:03:24 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[Configuring]]></category>
		<category><![CDATA[nothing]]></category>
		<category><![CDATA[UAG]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=399</guid>
		<description><![CDATA[If you use DirectAccess (DA), should you use a certificate on the IP-HTTPS listener from your internal CA or from a third party CA? If you use a certificate from your internal CA, you&#8217;ll have to publish the CRL so it can be reached from the outside. If you don&#8217;t do it, external DA clients [...]]]></description>
				<content:encoded><![CDATA[<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;">If you use DirectAccess (DA), should you use a certificate on the IP-HTTPS listener from your internal CA or from a third party CA?</span></span></span></p>
<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;">If you use a certificate from your internal CA, you&#8217;ll have to publish the CRL so it can be reached from the outside. If you don&#8217;t do it, external DA clients will remove the CRL from the cache after 24 hours and they will not be able to check if the certificate has been revoked or similar. DA will not work for them until they put their laptop in the internal network, and are able to reach the CRL.</span></span></span></p>
<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;">The default time for the cache is 24 hours.</span></span></span></p>
<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;">So I would not bother publishing the CRL, but instead use a third party certificate on the IP-HPPS listener.</span></span></span></p>
<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;">If you use or consider using DA without UAG, Win8 has a lot of improvements regarding DA (features you only found in UAG). </span></span></span></p>
<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;">For a complete list check out <a title="http://technet.microsoft.com/nb-no/library/hh831416.aspx" href="http://technet.microsoft.com/nb-no/library/hh831416.aspx">http://technet.microsoft.com/nb-no/library/hh831416.aspx</a></span></span></span></p>
<p><span style="font-size: medium;"><span style="color: #000000;"><span style="font-family: Calibri;"><br />
</span></span></span></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=399</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Troubleshooting slow logon/boot on Win7</title>
		<link>http://adfordummiez.com/?p=390</link>
		<comments>http://adfordummiez.com/?p=390#comments</comments>
		<pubDate>Fri, 17 Aug 2012 08:33:36 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=390</guid>
		<description><![CDATA[As I mentioned earlier in a post, causes of slow logons can be many things and troubleshooting this is often time consuming. I recommend you to download the ADK tools for Win8 (for the moment it&#8217;s for the Consumer preview) and use the &#8220;Windows Performance Recorder&#8221; and &#8220;Windows Performance Analyzer&#8221; to help you find the culprit. To get an [...]]]></description>
				<content:encoded><![CDATA[<p>As I mentioned earlier in a <a title="post" href="http://adfordummiez.com/?p=86">post</a>, causes of slow logons can be many things and troubleshooting this is often time consuming. I recommend you to download the <a title="ADK tools" href="http://www.microsoft.com/en-us/download/details.aspx?id=28997" target="_blank">ADK tools </a>for Win8 (for the moment it&#8217;s for the Consumer preview) and use the &#8220;Windows Performance Recorder&#8221; and &#8220;Windows Performance Analyzer&#8221; to help you find the culprit.</p>
<p>To get an overview of the tool and some examples, take a look at this excellent TechEd session: <a title="How many coffees can you drink while Windows 7 boots?" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WCL305" target="_blank">How many coffees can you drink while Windows 7 boots?</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=390</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GPO to remove ISATAP blocking from DNS</title>
		<link>http://adfordummiez.com/?p=362</link>
		<comments>http://adfordummiez.com/?p=362#comments</comments>
		<pubDate>Mon, 06 Aug 2012 17:54:22 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[Configuring]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=362</guid>
		<description><![CDATA[When you use DirectAccess (DA) you have to unblock ISATAP on your DNS servers, so when clients do a DNS lookup for ISATAP they will get an answer. If you add a new domain controller with the DNS role, you must remember to remove ISATAP from the block list. You removed it on your DNS [...]]]></description>
				<content:encoded><![CDATA[<p>When you use DirectAccess (DA) you have to unblock ISATAP on your DNS servers, so when clients do a DNS lookup for ISATAP they will get an answer.</p>
<p>If you add a new domain controller with the DNS role, you must remember to remove ISATAP from the block list. You removed it on your DNS servers when you configured DA long time ago, but will you or your successor remember to remove the blocking if you add a new DC/DNS?</p>
<p>I didn&#8217;t until I saw a 7600 event id on the new DC/DNS&#8230;</p>
<p>Too see the current settings:</p>
<p><code>dnscmd /info /globalqueryblocklist</code></p>
<p>To remove ISATAP manually from the block list:</p>
<p><code>dnscmd /config /globalqueryblocklist wpad</code></p>
<p>To avoid this from happening in the future, I configured a Group Policy (GPO) to do the job. I reckon a GPO is more reliable than a Teflon brain.</p>
<p>Open the Group Policy Management consol.</p>
<h4>Create the WMI:</h4>
<p>First you need to create a WMI filter so the GPO only apply to servers with the DNS server role. Give it a meaningful name.</p>
<pre>Query:  SELECT id FROM Win32_ServerFeature WHERE id = "13"</pre>
<p>(ID 13 = DNS Server)</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/08/p1.jpg"><img class="alignnone size-medium wp-image-363" title="p1" src="http://adfordummiez.com/wp-content/uploads/2012/08/p1-300x215.jpg" alt="" width="300" height="215" /></a></p>
<h4>Create the GPO/GPP:</h4>
<p>Group Policy Objects -&gt; New</p>
<p>Give it a name. I called it &#8220;GPP_Unblock_ISATAP&#8221;.</p>
<p>Computer Configuration – Preferences – Windows Settings – Registry</p>
<p>Choose New – Registry Item</p>
<p>Action: Update</p>
<p>Path: HKLM\System\CurrentControlSet\Services\DNS\Parameters</p>
<p>Name: GlobalQueryBlockList</p>
<p>Value to remove: isatap</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/08/p2.jpg"><img class="alignnone size-medium wp-image-364" title="p2" src="http://adfordummiez.com/wp-content/uploads/2012/08/p2-300x232.jpg" alt="" width="300" height="232" /></a></p>
<p>Link the GPO to the WMI filter you created:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/08/p3.jpg"><img class="alignnone size-medium wp-image-365" title="p3" src="http://adfordummiez.com/wp-content/uploads/2012/08/p3-300x84.jpg" alt="" width="300" height="84" /></a></p>
<p>Link the GPO to the OU where your DNS servers reside. I linked it to the Domain Controllers OU since we don&#8217;t have any standalone DNS servers. The WMI filter will anyway only apply to DNS servers, so you can link it higher up.</p>
<p>You&#8217;ll have to restart the DNS server service, or reboot the server before the setting is applied to the DNS server. Check the status &#8220;dnscmd /info /globalqueryblocklist&#8221;. If ISATAP is not present you are good to go.</p>
<p>Notice this only apply to Win2008 and newer, since legacy OS don&#8217;t have the Win32_ServerFeature class.</p>
<p>If you have Win2003 DNS servers, you&#8217;ll see that the WMI filter return &#8220;false&#8221; and the GPO will not apply:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/08/p4.jpg"><img class="alignnone size-medium wp-image-366" title="p4" src="http://adfordummiez.com/wp-content/uploads/2012/08/p4-300x42.jpg" alt="" width="300" height="42" /></a></p>
<p>On Win2008 and newer:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/08/p5.jpg"><img class="alignnone size-medium wp-image-367" title="p5" src="http://adfordummiez.com/wp-content/uploads/2012/08/p5-300x29.jpg" alt="" width="300" height="29" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=362</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TechEd Europe 2012</title>
		<link>http://adfordummiez.com/?p=349</link>
		<comments>http://adfordummiez.com/?p=349#comments</comments>
		<pubDate>Wed, 18 Jul 2012 09:48:21 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[nothing]]></category>
		<category><![CDATA[learning]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=349</guid>
		<description><![CDATA[Were you unable to attend at TechEd Europe 2012 in Amsterdam? Don&#8217;t worry. You can view all the sessions on-demand at Microsoft Channel 9 for free. TechEd: Microsoft Channel 9 &#160; By the time your rss reader get this post here is 1 comments ,Welcome you come to leave your opinion !]]></description>
				<content:encoded><![CDATA[<p>Were you unable to attend at TechEd Europe 2012 in Amsterdam?</p>
<p>Don&#8217;t worry. You can view all the sessions on-demand at Microsoft Channel 9 for free.</p>
<p>TechEd: <a title="Microsoft Channel 9" href="http://channel9.msdn.com/Events/TechEd/Europe/2012" target="_blank">Microsoft Channel 9</a></p>
<p>&nbsp;</p>
By the time  your rss reader get this post here is <strong> 1 </strong>comments ,Welcome you come to leave your opinion !]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=349</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Publish Lync with UAG</title>
		<link>http://adfordummiez.com/?p=326</link>
		<comments>http://adfordummiez.com/?p=326#comments</comments>
		<pubDate>Thu, 24 May 2012 10:00:52 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[Lync]]></category>
		<category><![CDATA[nothing]]></category>
		<category><![CDATA[UAG]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=326</guid>
		<description><![CDATA[Do you use Microsoft Forefront UAG 2010 to publish Lync and having problems to get it to work? My co-worker Robert had struggeled with this for some time, but finally he managed to get Lync and mobility to work over UAG. First we tried using the TMG part of the UAG and it worked, but [...]]]></description>
				<content:encoded><![CDATA[<p>Do you use Microsoft Forefront UAG 2010 to publish Lync and having problems to get it to work?</p>
<p>My co-worker Robert had struggeled with this for some time, but finally he managed to get Lync and mobility to work over UAG.</p>
<p>First we tried using the TMG part of the UAG and it worked, but I could not restart the server after the configuration. If I restarted the server the HTTP and HTTPS traffic was blocked by the default rule of the TMG. Other weirdo&#8217;s did also happened if we changed the UAG config.</p>
<p>We started a SR with Microsoft and they told us that using the TMG part of the UAG was not supported. It can work in some cases but if you do some configuration changes in UAG it can be broken. MS says that you should never touch the TMG settings on a UAG server.</p>
<p>So here is what we did on the UAG:</p>
<p>We added one more public IP address to the External leg of the UAG, so we have two IP addresses for Lync. One IP for lyncweb, meet and dialin. The second IP was dedicated for lyncdiscover.</p>
<p>We created a new HTTPS trunk for lyncweb, meet and dialin and changed the Session settings like this:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync1.png"><img class="alignnone size-medium wp-image-327" title="lync1" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync1-300x183.png" alt="" width="300" height="183" /></a></p>
<p>Important: The &#8220;Disable scripting for portal application&#8221; have to be ticked on the Lync trunk. This cannot be ticked on a trunk for i.e. Exchange or SharePoint. Therefor you have to create a new dedicated trunk for Lync.</p>
<p>We created a new http trunk for lyncdiscover and changed the Session settings like this:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync2.png"><img class="alignnone size-medium wp-image-328" title="lync2" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync2-300x190.png" alt="" width="300" height="190" /></a></p>
<p>Our uag console now looks like this:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync3.png"><img class="alignnone size-medium wp-image-329" title="lync3" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync3-300x160.png" alt="" width="300" height="160" /></a></p>
<p>The https Lync looks like this:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync4.png"><img class="alignnone size-medium wp-image-330" title="lync4" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync4-300x228.png" alt="" width="300" height="228" /></a></p>
<p>The http lyncdiscover looks like this:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync5.png"><img class="alignnone size-medium wp-image-331" title="lync5" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync5-300x238.png" alt="" width="300" height="238" /></a></p>
<p><span style="text-decoration: underline;">Update:</span></p>
<p>Mobile clients will get logon servers unencrypted if you configuring the lyncdiscover on a HTTP trunk. You can skip the extra IP and configure the lyncdiscover on the Lync HTTPS trunk by doing:</p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync6.png"><img class="alignnone size-medium wp-image-346" title="lync6" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync6-300x195.png" alt="" width="300" height="195" /></a></p>
<p><a href="http://adfordummiez.com/wp-content/uploads/2012/05/lync7.png"><img class="alignnone size-medium wp-image-347" title="lync7" src="http://adfordummiez.com/wp-content/uploads/2012/05/lync7-197x300.png" alt="" width="197" height="300" /></a></p>
<p>Credit to Robert for getting this to work. Hope it will work for you too <img src='http://adfordummiez.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&nbsp;</p>
By the time  your rss reader get this post here is <strong> 11 </strong>comments ,Welcome you come to leave your opinion !]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=326</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Where should I register the SPN?</title>
		<link>http://adfordummiez.com/?p=317</link>
		<comments>http://adfordummiez.com/?p=317#comments</comments>
		<pubDate>Sat, 21 Apr 2012 12:28:44 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[Configuring]]></category>
		<category><![CDATA[Kerberos]]></category>
		<category><![CDATA[SPN]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=317</guid>
		<description><![CDATA[For proper Kerberos authentication to take place, the Service Principal Names (SPNs) have to be registered correctly on the correct account. SPNs are AD attributes that uniquely identifies an instance of a service for a given target host. If you have a SQL server where the SQL service run under the Network Service or Local System [...]]]></description>
				<content:encoded><![CDATA[<p>For proper Kerberos authentication to take place, the Service Principal Names (SPNs) have to be registered correctly on the correct account.</p>
<p>SPNs are AD attributes that uniquely identifies an instance of a service for a given target host.</p>
<p>If you have a SQL server where the SQL service run under the Network Service or Local System account, the SPN for SQL should be registered on the machine account. If you have set the service to run under a service account (a domain user account), the SPN should be registered on the domain user.</p>
<p>SPNs registered on a machine account will be registered automatically, but if you use a user account you&#8217;ll have to register the SPN manually. You can use the setspn.exe tool, or use adsiedit.msc.</p>
<p>You can only register the unique SPN on one account. If you have duplicate SPNs in the forest, Kerberos authentication will fail.</p>
<p>If you have an IIS server (version 6 or prior) the Service class (http) should be registered on the application pool Identity the site is using. This is not the case if you have IIS 7/7.5. By default IIS 7 has enabled &#8220;Kernel-Mode authentication&#8221;.  The Kerberos Service ticket is then encrypted with the Machine account password no matter what account is set to run the application pool.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=317</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIC2012</title>
		<link>http://adfordummiez.com/?p=303</link>
		<comments>http://adfordummiez.com/?p=303#comments</comments>
		<pubDate>Mon, 16 Jan 2012 17:13:22 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[AD in general]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[learning]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=303</guid>
		<description><![CDATA[This weekend I attended at the NIC2012 conference in Oslo. Many interesting sessions were on the schedule like DS MVP Brian Desmond’s “What&#8217;s new in Windows Server 8 Active Directory” and “Kerberos uncovered”. Key notes from WinServer 8 AD: USN Rollback preventions when restoring a snapshot (PDCe needs to be on a Win Server 8 [...]]]></description>
				<content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-family: Calibri;">This weekend I attended at the NIC2012 conference in Oslo.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Many interesting sessions were on the schedule like DS MVP Brian Desmond’s “What&#8217;s new in Windows Server 8 Active Directory” and “Kerberos uncovered”.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Key notes from WinServer 8 AD:</span></span></p>
<ul>
<li><span style="font-size: small;"><span style="font-family: Calibri;">USN Rollback preventions when restoring a snapshot (PDCe needs to be on a Win Server 8 DC)</span></span></li>
<li><span style="font-size: small;"><span style="font-family: Calibri;">Support for cloning DCs (handy when you have to deploy dozens of them)</span></span></li>
<li><span style="font-size: small;"><span style="font-family: Calibri;">GUI for the AD Recycle Bin and Fine Grained Password Policy</span></span></li>
<li><span style="font-size: small;"><span style="font-family: Calibri;">Dcpromo.exe is gone (you promote a DC from the server manager)</span></span></li>
<li><span style="font-size: small;"><span style="font-family: Calibri;">AD delivers the mechanism for file server access with Claims Based Authentication</span></span></li>
<li><span style="font-size: small;"><span style="font-family: Calibri;">A huge amount of new Powershell cmdlets</span></span></li>
</ul>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Unfortunately it looks like the video for this session is missing, t</span></span><span style="font-size: small;"><span style="font-family: Calibri;">hough I’d recommend you to have a look at some other sessions like:</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">“Kerberos uncovered” by Brian Desmond:<br />
</span></span><a href="http://vimeo.com/nicconf/review/35059113/4695c41e86"><span style="font-family: Calibri; color: #0000ff; font-size: small;">http://vimeo.com/nicconf/review/35059113/4695c41e86</span></a></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">”How to Not Screw Up Your PKI Environment“ by Brian Komar:<br />
</span></span><a href="http://vimeo.com/nicconf/review/35053082/aaff51b192"><span style="font-family: Calibri; color: #0000ff; font-size: small;">http://vimeo.com/nicconf/review/35053082/aaff51b192</span></a></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">“What’s new in Windows 8 Hyper-V” by Ronald Beeklaar:<br />
</span></span><a href="http://vimeo.com/nicconf/review/35059126/939388d621"><span style="font-family: Calibri; color: #0000ff; font-size: small;">http://vimeo.com/nicconf/review/35059126/939388d621</span></a></p>
<p>&nbsp;</p>
<p>All sessions: <a href="http://www.nic2012.com/nic2012_agenda">http://www.nic2012.com/nic2012_agenda</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=303</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reset the Secure Channel</title>
		<link>http://adfordummiez.com/?p=286</link>
		<comments>http://adfordummiez.com/?p=286#comments</comments>
		<pubDate>Tue, 25 Oct 2011 07:28:20 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[PowerShell]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=286</guid>
		<description><![CDATA[When a computer joins a domain, a computer account is created in AD. The computer account gets its own password that will expire after 30 days (default). When the password expire, the computer itself will initiate a password change with a DC in its domain. When the computer starts up, it uses this password to [...]]]></description>
				<content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-family: Calibri;">When a computer joins a domain, a computer account is created in AD. The computer account gets its own password that will expire after 30 days (default). When the password expire, the computer itself will initiate a password change with a DC in its domain.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">When the computer starts up, it uses this password to create a secure channel (SC) with a DC. The computer will request to sign all traffic that passes the SC. If a DC says &#8220;go ahead&#8221;, all traffic that is signed passes through this channel.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Traffic like NTLM pass through authentication is typically signed traffic.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">So what will happen if there is a mismatch between the computer account password? The computer tries to authenticate, but the DC says this is not the correct password. </span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">The SC is down.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Tools like &#8220;netdom&#8221; could be used to reset the password, but this only worked to reset the SC between two DCs. It was not possible to reset the SC on a domain member. The computer had to rejoin the domain.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Syntax:</span></span></p>
<p><em>netdom resetpwd /server:&lt;Name of a DC&gt; /userd:domain\administrator /passwordd:admin_password</em></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Netdom was written back in the NT4 days, and a new tool has taken over. Not just taken over for Netdom, but also for tools like Nltest. Windows PowerShell.<br />
</span></span></p>
<p><strong><span style="font-size: small;"><span style="font-family: Calibri;">To reset the SC between a computer and a DC:</span></span></strong></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Open PowerShell on the computer and run the *cmdlet:</span></span></p>
<p><strong><span style="color: #3366ff; font-size: small;"><span style="font-family: Calibri;">Test-ComputerSecureChannel -repair</span></span></strong></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">*The cmdlet requires PowerShell 2.0, which is pre-installed on Win7/2008R2.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">In Win8 there are thousands of new cmdlets, so if you have not began to look at PS. Now is a good time. </span></span></p>
<p>&nbsp;</p>
<p><span style="font-size: small;"><span style="font-family: Calibri;"><strong>References:</strong></span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">PowerShell 2.0 for XP, 2003, Vista, 2008: <a href="http://support.microsoft.com/kb/968929">http://support.microsoft.com/kb/968929</a></span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Symptoms of a broken SC: <a href="http://blogs.technet.com/b/asiasupp/archive/2007/01/18/typical-symptoms-when-secure-channel-is-broken.aspx">http://blogs.technet.com/b/asiasupp/archive/2007/01/18/typical-symptoms-when-secure-channel-is-broken.aspx</a></span></span></p>
<p><span style="font-size: small;"><span style="font-family: Calibri;">Test-ComputerSecureChannel cmdlet: <a href="http://technet.microsoft.com/en-us/library/dd367893.aspx">http://technet.microsoft.com/en-us/library/dd367893.aspx</a></span></span></p>
<p><span style="font-family: Calibri; font-size: small;"> </span></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up ]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=286</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Accessing Dynamics CRM 2011 from the Internet</title>
		<link>http://adfordummiez.com/?p=275</link>
		<comments>http://adfordummiez.com/?p=275#comments</comments>
		<pubDate>Wed, 19 Oct 2011 21:03:25 +0000</pubDate>
		<dc:creator>Rune</dc:creator>
				<category><![CDATA[nothing]]></category>
		<category><![CDATA[Configuring]]></category>
		<category><![CDATA[CRM]]></category>

		<guid isPermaLink="false">http://adfordummiez.com/?p=275</guid>
		<description><![CDATA[To access Dynamics CRM 4 (on premise) from the Internet, you&#8217;d to configure IFD and you could use i.e. ISA in a DMZ if you didn&#8217;t want the CRM server to be facing the Internet. If you decided to use ISA you couldn&#8217;t use the built-in security provided by ISA/UAG, but you had to just [...]]]></description>
				<content:encoded><![CDATA[<p><span style="font-size: small;">To access Dynamics CRM 4 (on premise) from the Internet, you&#8217;d to configure IFD and you could use i.e. ISA in a DMZ if you didn&#8217;t want the CRM server to be facing the Internet.</span></p>
<p><span style="font-size: small;">If you decided to use ISA you couldn&#8217;t use the built-in security provided by ISA/UAG, but you had to just tunnel all traffic through and let the CRM server authenticate the user. This was not so cool, but it</span><span style="font-size: small;"> was fairly easy to set up and configure.</span></p>
<p><span style="font-size: small;">With the release of Dynamics CRM 2011 things started to get a little more complicated. If you wanted to access CRM from the Internet you&#8217;d to configure claims-based authentication, ADFS 2.0 and IFD. UAG was not supported.</span></p>
<p><span style="font-size: small;">I was taken by surprise when I read about this, since Microsoft uses UAG to make i.e. Exchange and SharePoint more secure. Did they forget about CRM? </span></p>
<p><span style="font-size: small;">Products like Citrix Access Gateway began to take a sole lead.</span></p>
<p><span style="font-size: small;">Things changed with the release of UAG Service Pack 1. CRM is now supported to be published via UAG. You don&#8217;t need to set up ADFS and claims. Let the UAG do the job to secure and authenticate the users. With or without two-factor authentication like RSA. </span></p>
<p><span style="font-size: small;">Easy to configure, easy to understand <img src='http://adfordummiez.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></p>
<p><span style="font-size: small;"> <a href="http://adfordummiez.com/wp-content/uploads/2011/10/uag1.jpg"><img class="alignnone size-medium wp-image-276" title="uag1" src="http://adfordummiez.com/wp-content/uploads/2011/10/uag1-238x300.jpg" alt="" width="238" height="300" /></a></span></p>
<p><span style="font-size: small;"><a href="http://adfordummiez.com/wp-content/uploads/2011/10/uag2.jpg"><img class="alignnone size-medium wp-image-277" title="uag2" src="http://adfordummiez.com/wp-content/uploads/2011/10/uag2-300x54.jpg" alt="" width="300" height="54" /></a></span></p>
<p>&nbsp;</p>
<p><span style="font-size: small;">Reference:</span></p>
<p><span style="font-size: small;">Publishing: <a title="http://technet.microsoft.com/en-us/library/hh490315.aspx" href="http://technet.microsoft.com/en-us/library/hh490315.aspx" target="_blank">http://technet.microsoft.com/en-us/library/hh490315.aspx</a><br />
UAG: <a href="http://www.microsoft.com/en-us/server-cloud/forefront/unified-access-gateway.aspx">http://www.microsoft.com/en-us/server-cloud/forefront/unified-access-gateway.aspx<br />
</a></span></p>
<p>&nbsp;</p>
By the time  your rss reader get this post here is <strong> 3 </strong>comments ,Welcome you come to leave your opinion !]]></content:encoded>
			<wfw:commentRss>http://adfordummiez.com/?feed=rss2&#038;p=275</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
