powdarrmonkey Posted October 14, 2008 Posted October 14, 2008 I know I bang on about it a lot, but I'm after some feedback for development (otherwise I bore easily, and nobody wants that ) So if you've deployed it (or haven't) any comments?
dyoung5 Posted October 17, 2008 Posted October 17, 2008 Hi Powdarrmonkey, I have deployed it in production, and am in the process of finding out if its doing its job (I will have long gone home when it runs). It does seem to be working generally though. One problem I have come across is that Sophos AntiVirus detects it as "suspiciuous" behaviour, because of one of the registry changes it makes(not sure which one). I have setup an exception so it runs without complaining, but I would be greatful if you looked into this. And finally to say a big THANK YOU. This is much better than our previous solution, which, if the computer was already off would either try to wake it up, just to shut it down again, or wait until it was next switched on! It is sooo easy to setup and deploy, I did it in 5 mins last week. Regards, David
powdarrmonkey Posted October 17, 2008 Author Posted October 17, 2008 Cool beans I'm all glowy and warm inside. Deploy-and-forget was one of the most important goals, so I'm glad you've found it that easy. You'll know if it's been doing its thing because there are event logs generated. If all is well, you'll see one when it invokes shutdown.exe, and one very soon afterwards with any errors encountered. If that one's blank, then all went to plan. You may see other messages too, such as whether a user aborted it. As to Sophos, I'm a bit in the dark. Does it generate any logs you can send me?
IrritableTech Posted October 17, 2008 Posted October 17, 2008 I have tried it on a single machine, and will be placing it on a suite next week I think. Seems to do exactly what I wanted (and it's a great name). My PsShutdown script takes far too long to work through. Just one question, can I run multiple policies? I'd like to run say a policy which runs at 6pm giving the option to abort shut down, and then run again at 10pm forcing a shutdown.
powdarrmonkey Posted October 17, 2008 Author Posted October 17, 2008 I can't take credit for the name, but still. Group policies are inherited in the normal way, so just create multiple policy objects, load the template into each, and specify your settings. You can also apply a policy at the top of a tree and be more specific further down, so you could enable it at the top and specify your times on different OUs, for maximum flexibility.
dyoung5 Posted October 17, 2008 Posted October 17, 2008 All Sophos says is that it is suspicious behaviour type HIPS/Reg-Mod13 You can get more info here HIPS/RegMod-013 - Suspicious behavior - Sophos security analysis and perhaps send them a sample so they can allow it in a future release. Like I said, we're ok as I have set it to ignore, but I know a lot of schools use Sophos, and I'm sure you dont want to release an app that frightens everyone with virus threats! 1
powdarrmonkey Posted October 19, 2008 Author Posted October 19, 2008 @terrovis: Sorry, I should have read your question more carefully. No, it's not possible for a machine to try shutting down more than once a day (though I'm looking into a way of doing it). My aim is to keep it as lean as possible, for various reasons, so although you can specify different policies for different machines, you can't currently specify multiple for one machine. I should have seen the distinction the first time
IrritableTech Posted October 21, 2008 Posted October 21, 2008 @terrovis: Sorry, I should have read your question more carefully. No, it's not possible for a machine to try shutting down more than once a day (though I'm looking into a way of doing it). My aim is to keep it as lean as possible, for various reasons, so although you can specify different policies for different machines, you can't currently specify multiple for one machine. I should have seen the distinction the first time Thanks for the update. In the mean time I'll probably use Shutdownertron in combination with psshutdown to achieve my goal.
jonnellan Posted October 22, 2008 Posted October 22, 2008 Just downloaded shutdownertron V1.3, it sounds like just what we are looking for, although a facility to wake the PC's up would be nice. Our network clients run vista(x32). I have attempted to install it on a test PC locally and it wouldnt take. Said i didnt have permission to start services but i was local admin so shouldnt be any problems, can start/stop other services? Also event in logs show : "Service cannot be started. The service process could not connect to the service controller". Not really investigated this too much yet. But just wondered if shutdownertron will actually run on vista ?
powdarrmonkey Posted October 22, 2008 Author Posted October 22, 2008 Mmm, tricky. There isn't any reason why it shouldn't run on Vista, but I haven't tried it myself. What version of the .net framework do you have running? (requires at least 2.0). When I hit half term next week I'll have a play for you. I do have a waking up thing in progress, but it's not ready for general release yet.
jonnellan Posted October 23, 2008 Posted October 23, 2008 we are running .net framework version 3.5 so im guessing it should be ok on that score?
Psymon Posted October 23, 2008 Posted October 23, 2008 1.0, 2.0 and 3.0+ are actually standalone in a wierd way. You cant just install 3.0+ and the predecessors use it, you actually need to install each one individually. 1.0 will only run .net 1.0 apps, 2.0 will only run 2.0apps etc...
powdarrmonkey Posted October 23, 2008 Author Posted October 23, 2008 The chances are you run 2.0 already, but it's worth just checking.
JJonas Posted October 29, 2008 Posted October 29, 2008 Ive deployed to my 5 main computer areas and it is working well. Im looking to deploy across the whole school and know I can do this by adding it to my default domain policy but how do I prevent it from deploying to my servers if I do this?
powdarrmonkey Posted October 29, 2008 Author Posted October 29, 2008 Generally I wouldn't use the default domain policy for anything except password policies. If you haven't already, put all your workstations in an Organisational Unit and create a new group policy object on that unit, and put your severs in another OU. You could also add your servers to a new security group, and tell your policy object to be blocked from members of that group. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now