Search This Blog

Monday, August 13, 2007

Secure Public Relations Excuse Bingo

Wanna play security excuse bingo for management? If so, click here

Tuesday, July 24, 2007

Group Policy failure

Troubleshooting steps for GPOs when it fail for one user, not the best solution though... But I heard that it is not uncommon to have this situation and Jesper blogged it all, so if you're interested in our steps to try to find a solution, click here.

Windows Vista Security

Hi, Jesper have once again written an excellent article about ACLs, if you're interested, click here. It is from the book Windows Vista Security written by Jesper M. Johansson and Roger A. Grimes.

Staging folders

Do not mix staging folders and prestaging. They are completely different things!

I got the below from my friend Thomas Bittner, it was written by his team for the APS (All Purpose Server) guide.

Staging folders are used to isolate the files from the changes on the file system, and amortize the cost of compression and computing RDC hashes across multiple partners.
Here is some background on current staging space management. There are three values that are important to staging space management.

· Staging size in MB (configured per-replicated folder in AD)
· Staging low watermark percentage (configured per-server via WMI, applies to all replicated folders on the server)
· Staging high watermark percentage (configured per-server via WMI, applies to all replicated folders on the server)

DFS Replication will do roughly the following when trying to stage a file:
· Request a reservation for staging space for the file based on an estimate of the file size.
· If the currently used staging space is less than the configured staging size, the file is allowed to stage regardless of the reservation amount. This allows large files to replicate and not get stuck with the familiar “huge file” replication blocker on FRS. The reservation amount is accounted for in the used staging space.
· After staging completes, DFS Replication fixes up the reservation amount by using the actual used amount. Note that due to compression, there could been different file sizes.
· If the used staging space is higher than the high watermark, staging space cleanup is triggered. Staging space cleanup will clean up until it hits the low watermark or there are no more files that are candidates for cleanup i.e., all files in staging are actively being used. Note that the cleanup is on a per replicated folder scope.

There are several factors that affect the size of staging. Without going into theories, here are some rules of thumb:
· It is desirable to set the staging folder to be as large as possible (as available space) and comparable to the size of the replicated folder. Hence if the size of the replicated folder is 24.5 GB, then ideally a staging folder of comparable size is desirable. Note that this amortizes the cost of staging and hash calculation over all connections. It is also a best practice to locate the staging folder on a different spindle to prevent disk contention.
· If staging cannot be set comparable to the size of the replicated folder, then reduce the size by 20%. Depending on how well the data compresses, staging files will be 30-50% of the original file size.
· Note that the mentioned two recommendations are particularly important if all the data is preexisting and DFS Replication must process all content at the same time during initial replication. On the other hand, if the replicated folder is relatively empty and gradually grows over time, the recommendation is to determine the projected size of the replicated folder and size the staging appropriately.
· If the size of the staging folder cannot be set proportional to the size of the replicated folder, then increase the size of the staging folder to be equal to the five largest files in the replicated folder.

Prestage DFS-R

A lot of people are wondering how to prestage DFS-R, so here are the steps:

Make sure that the primary member has the latest version of each file. This is done during configuration of replication because it will be seen as authoritative during first replication. This is similar as doing a D2/D4 restore of a broken sysvol.

During first replication these things will happen:

[P1 = Primary]
[M1 = Member]

Scenario 1:
File1 exists on both P1 and M1 and are identical = File is not replicated, but metadata is to update the replication DB on M1.

Scenario 2:
File2 exists on both P1 and M1, but is newer on P1 = File2 will be replicated, and the file on M1 will be treated as a conflict and moved to a special folder called something like "conflict or deleted"

Scenario 3:
File3 does not exist on P1, but gets created on M1 during first replication = File3 will replicate to P1.

Scenario 4:
File4 exist on both P1 and M1, but gets deleted during first replication = The deletion doesn't replicate.

Tuesday, July 17, 2007

Finally a new post!

I know it has been a long time since I blogged so don't start ;)

Have you ever installed a 64-bit OS for personal use? If not, think twice!
I just got my new Dell machine, dual-core 4GB RAM and all sorts of goodies (but NO fancy graphics card, it will only be used as a test machine for servers). Ok, I ordered it with XP 64-bit from Dell, but I forgot to order the darn wireless card. So I thought you could call Dell, tell them that you just ordered a new machine from them and give them the specs...
How stupid was I!!!! First they say that they have no wireless card that support 64-bit, so I told him there was an option during the "configure my computer" wizard that had an option for a wireless card. He says, NO we don't have any wireless cards that supports 64-bit.

Now I'm getting a bit worried, so I (during the time I was on the phone with him) ran through the wizard again and did some screen shots and sent them to him. He says that it is impossible, which forced me to ask him:
"So you have a NIC that customers can order with the wizard that will not work when the computer arrives?"

His answer:
"Yes, but people should know what they order"

Which I replied to:
"But I had to tell you what a 64-bit OS is! And you are selling these things!"

He replied:
"You need to call another NIC supplier."

So, I went to MS website and scrolled through the HCL for 64-bit XP, and guess what! There is a Dell card that will work! But unfortunately the Dell website actually lists 2 NICs with the same name and on the HCL the one that is NOT manufactured by Dell is the one that will work on 64-bit. (The name on Dell's website is 1450)

Conclusion:
You get the correct hardware from the HCL, the company that sells them have 2 NICs available with the same name and NO specs so you can't tell which one is supported or not!

Guess what, I will not order a Dell NIC, I will find another manufacturer on the HCL and order from them......


BTW - Next post will be DFSR in R2....

Ok, back to work now :)

Sunday, April 08, 2007

Back from South Africa...

I'm back in Sweden, but in less than 6 hours it is take off heading to Brisbane, Australia. After a couple of days work I'm off again to Santiago, Chile for a couple of days and then I'm heading for London, UK.
So, what am I doing during these short stays you might wonder.... Well, in Johannesburg, South Africa we realized that we wasn't told the whole truth about the environment... Let's just say new forests and domains was discovered so we thought that it would be better if myself and Wolfgang, who is responsible for Exchange, would be the ones going to the major locations and do some discovery work, i.e. run our scripts to find out the details and the truth about the environment.

So what we will be doing the next 12 days is a trip around the world... And people were impressed by doing it in 80 days.... :)

Monday, March 05, 2007

Windows - the story

A friend of mine just sent me this link about the story behind Windows. I don't know if it is the absolute truth, but it sure is fun :)

Wednesday, February 21, 2007

...it has been a long time since I posted

Yes, I know I haven't been posting for a while. It's been crazy with all the travels and work, so I honestly just haven't had any time for it.

This morning I received an e-mail confirming a new contract, basically I will be travelling the next 18 month doing a massive forest/domain consolidation/migration. Hopefully I will have time to post some interesting things that will be discovered during this work and post it here. At this point I have no knowledge about exactly how big it is, but I do know we are talking about 100s of DCs... Which will be some good fun :)

At the moment my schedule looks like this:

- Feb 28 thru March 3 in Germany
- March 11 thru March 16 in Germany
- March 18 thru April 27 in South Africa

After that I will know more about what needs to be done and also the travel plans for the next few months...

...Oh if you are interested I will post a few "findings" I did when I had to do LCS troubleshooting which is very interesting/strange/goofy...

Monday, August 21, 2006

Advanced AD Troubleshooting and Theory

The dates for my course are now available at Cornerstone's website. Contact Cornerstone if you want to attend.

Friday, August 18, 2006

Tuesday, August 01, 2006

Sad day for MS/Good day for Jesper.

As you might know, Jesper M. Johansson is leaving Microsoft. He's a buddy and whatever makes him (and his family) happy makes me happy! Good luck with the new job!

As a MS employee he has been (to me):
- A good friend.
- Known as a "know-how" person.
- He's respected amongst his peers.
- His presentation skills are great (I wish I was half as good).

Future (knowing Jesper):
- A good friend.
- Known as a "know-how" person.
- He's respected amongst his peers.
- His presentation skills are great.
- Don't stop reading his blog! He will continue posting useful things.
- He will stay on top of his area.
- He will not leave the "security business"

When the new URL is known to his blog, I will post it.

Wednesday, July 05, 2006

lastLogonTimestamp

So yet another question about how to find out the last logon time for users.... Ok, here is how it works in Windows 2003.

One of the new attributes in Windows 2003 is lastLogonTimestamp which can be used to retrieve the last logon time for users, good so we have a new attribute to use! Sounds easy, right?

But this is not as trivial as you might think! The lastLogonTimestamp is not always showing the truth since it is only replicated every 14 days... Then take into account that when you read the value for the attribute it is stored as a 64-bit integer calculated from 1601 January 1st in 100-nano secs interval. (No, it was not MS fault. It was the darn Cobol programmers!!)

And another funny thing is that VBScript can't handle 64-bit integers!!!!! So you need to break it down into two 32-bit integers with IADsLargeInteger, which has two properties:

highpart = store the high 32-bits
lowpart = store the low 32-bits

…then you add them to get a single value.

So how would a script that does this look like you might wonder.

I will not just put the code here but rather I will walk you through how to “think” to solve it. (If you really need the code and don’t know how to write it, send me an e-mail).

  1. Use “Get” to retrieve the attribute (lastLogonTimestamp)

  2. Store the value in an IADsLargeInteger object

  3. Combine the highpart and lowpart values into one value by taking the highpart * (2^32) and add the lowpart.

Ok, step 3 which is one line of code will give us the last logon for a user. But it will give us the time in a format of how many 100-nano secs intervals occurred since  Jan 1, 1601 and the user’s last logon.

The value might look like this: 2.5643571264596E+16

This, at least to me, looks kind of hard to read. And I bet the one asked for the report will not be happy if you give him/her this….. So now we need to do something about it, but first a little bit on nanosecs:

1 second = 1,000,000,000 nanosecs = 10,000,000 nanosec intervals per second (10,000,000 * 100 = 1,000,000,000). This means that there are 600,000,000 100-nano secs intervals per minute.

  1. To find out how many minutes elapsed since Jan 1, 1601 and last logon we can take the last logon time and divide it by (60*10000000).

  2. If we want to find out the number of days that have elapsed we dived the last logon time with 1440 (which is the number of minutes per 24 hrs).

The above steps (5 and 6) can be done in one step if you want…..

  1. Now we know how many days elapsed since Jan 1, 1601 so we take that and add it to Jan 1, 1601 (“last logon time” + #1/1/1601#) and we get the result in an easy to read format!


But I assume it is W2K3 otherwise you need to use the lastLogon which is not replicated at all, which means you have to retrieve it from all DCs and then compare the values, sounds boring but can be solved with some code...

Saturday, June 24, 2006

Rome

Yep, here once again with Carola, if we could give anyone advice for visiting Rome it would be:

  • Stay at the Hilton Cavalieri.

  • Go to the private club “Blue” by the sea (40 minutes by car from the hotel and the hotel will arrange a private driver)

Oh! And just to mention, we got engaged the 20th of June at Blue!

More details later!

Sunday, May 21, 2006

Mark Arnold missed the plane

I’m not alone!!

My good friend Mark Arnold is visiting this weekend, he was supposed to fly in on Friday and land at 13.20... Guess what happens, he missed the plane… And no, he didn’t even try to get to the airport in time because he missed the date!! Yes, the man missed the plane by a day!!

BTW - if you have the chance to attend Exchange Forum in Sweden this week, check out Mark's presentation about Exchange 2007. I've had the luck to see the .ppts and it looks good, if Mark is speaking about Exchange I will listen.

Tuesday, March 14, 2006

Good cluster configuration...

I just remembered a conversation I had with a mate of mine, he stated that the only good cluster configuration is Inactive/Passive... Go figure.... :)

Monday, March 13, 2006

The fast recovery components

The fast recovery components

Creation of Shadow Copies
As I stated earlier, the process of creation initiates by the requestor (a backup program) contacting the Volume Shadow Copy Service (VSC service) to request a copy of the System State. The VSC service will act as a coordinator and notifies the System State writers to prepare for writing data for creation of a shadow copy.
Once the data is ready for the actual backup process each writer notifies the VSC service which then relays information to the backup requestor. Next step is that the requestor halts Active Directory I/O writes as long as it takes the provider to create single point-in-time copies of the three volumes. Usually this takes just a few seconds and should have no to little impact on Active Directory operations.

After the copy is made the VSC service will be instructed to break the connection with the original and the copy. At this point the shadow copy becomes read-only and the original will continue as usual (read/write). Now we are at the point where the shadow copy is no longer associated with a particular server and resides on the SAN until we need it.

Using EFS on virtual DCs

I just read this post about the possibility to use EFS to encrypt a DC that is running as a virtual machine. Sounds interesting, need to spend some time in the lab :)

Thursday, March 09, 2006

When do you need to recover AD?

...hopefully never!
But just in case, I will describe something called Fast Recovery during the following days...

There are alternatives to tape backups such as lag sites, but I will not go into that but rather I will talk about how it is possible to use shadow copies instead. I find it interesting and in conjunction with tape backups it can be effective.

The reason way I found this interesting is because it is fast and use a mirroring process that doesn't affect the system performance much. So in order to understand this we need some information how the underlying services works. Not to get into bit-level discussion I will give an overview:

Volume Shadow Copy (I will call it VSC)
With VSC you can create point-in-time snapshots of a volume, the service itself coordinates with other applications like backup software for instance and storage hardware to enable app-aware data management and it also support backup of open files.

There are three components that are needed in order to make a full shadow copy:
1. Requestor, which is the utility that request the copy (or rather request for the creation)
2. Writer, this is the software (app-specific) that makes sure that the data is ready to be copied.
3. Provider, this component gives the functionality to make the copy. VSC can use 3rd party hardware provider if needed.

Virtual Disk Service (I will call it VDS)
To make it short, it provides volume management with a single Windows interface which is used to manage storage devices. It also provides APIs for ISVs and IHVs to create storage solutions. The service itself use two CLI utilities, Diskpart and Diskraid. The Diskpart command is used to control creation, deletion and extension of dynamic and basic disk partitions. Diskraid is used to configure hardware RAID, to be specific, it is used to create, extend, delete and unmask LUs (logical units) on SANs.

Well, it simply makes your VSC data available for use. It do this by unmasking the backups stored on SAN. This means that it makes them visible and change the status from read-only to read/write. It also mounts the volume on the server. The whole process is called transport and is a virtual process since the data is on the storage array.

That is all I have time for now, got to catch a flight. I will continue another day :)

Windows Server 2003 Disaster Recovery

As many of you already know, besides the project in Finland I also do a tour (ExpertZone) in Sweden. One of the sessions is about troubleshooting AD and I get a lot of questions about recovery and the different ways of doing it.

Most people tend to have similar questions so I will start a series of posts about this topic, so keep an eye on this blog if you're interested in disaster recovery :)