-
Posts
64 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by mrmontymick
-
Sorry, way to geeky moment there, TGT = Ticket Granting Ticket. The master ticket if you like which allows you authenticate to all other Kerberos services. The restart question is probably the more important of the two to have an answer to....
-
Does the server A have a TGT for itself? If you stop and restart the KDC once the server has started does it do it quickly or is it as slow as initial start-up?
-
Netdiag often returns “kerberos does not have a ticket for host” because the Server 2003 version of netdiag doesn't work properly. Have you tried using Klist instead? It's in the Resource Kit. That may provide more useful information.
-
Do .I.T. Technicians have an organisation like CILIP?
mrmontymick replied to HTCIT's topic in General Chat
That's probably a breach of the BCS Code of Conduct you know... ;-D -
Microsoft launches 'child-friendly' Internet Explorer
mrmontymick replied to FN-GM's topic in IT News
We've been using IE8 and ePortal together since September 09 and so far haven't encountered any issues.... (Now crossing all fingers and toes to keep it that way) -
I seem to remember that I was talking to Mark at Computer Products a while back and he offered to buy back unused toner from me. I didn't have any at the time but it may be worth contacting them to see if they are still doing it and if they're interested in what you have. http://www.edugeek.net/forums/members/cpltd.html
-
I know what you mean, it wasn't my first choice. I normally don't rush into Serco upgrades as they tend to come back and bite us but we are in reports season and with the number of ePortal issues we needed to do something. I'm keeping all my fingers and toes crossed though....
-
We put the 21st Jan Admin and the 28th Jan ePortal on last night. Apart from the normal bodges to get it working again after an upgrade so far it appears to be working ok. Certainly haven't had any screams yet. And yes, we too were having problems with the previoud release, particularly on data entry into ePortal, report fields etc....
-
Wireless Access Authentication using PKCS#12 certificate
mrmontymick replied to mrmontymick's topic in Wireless Networks
Hi, No, not using a RADIUS server at the moment, the MSM-750 can be joined as a member server to the domain so effectively it can perform an AD login for wireless authentication purposes. What I can't do is generate the appropriate machine certificate for the MSM-750.... When you create a VSC (Virtual Service Controller) under the wireless protection settings you can specify local or remote authentication - under the remote tab you have the option of RADIUS or Active Directory but the access controller is failing to be trusted by the DC because it doesn't have an appropriate machine certificate generated for it. What I can't do is get my CA to generate this certificate. Hope that makes sense. The option do do authentication this way isn't one I have come across before I have only ever used RADIUS before. -
Wireless Access Authentication using PKCS#12 certificate
mrmontymick replied to mrmontymick's topic in Wireless Networks
Hi, I don't even have machines connecting at the moment never mind lack of GPO's. Without getting this certificate sorted I can't even make a wireless connection... -
This one has me scratching my head, and that's not a good thing as it's rubbing off what little hair I have left! We have a HP MSM-750 Wireless Access controller (formerly a Colubris MSC-5500). As part of it's functionality you can get it to authenticate by Active Directory Username and Password to issue a wireless connection. Steps as follows: 1. User boots laptop 2. Logon screen displayed 3. User enters AD username/password combo 4. Laptop pre-authenticates to wireless using AD username/password combo 5. If AD username/password correct then issue IP address and then pass logon request over to AD to perform logon on the machine as normal. However, the machine has to have two certificates on it to accomplish this, one is the Trusted Root Authority Certificate, this has been put on. The second one is a PKCS#12 certificate which it asks for in the name of the controller and to be issued by the Trusted Root Authority. My root authority is my MS Enterprise CA. Can I get this beast to issue a PKCS#12 certificate - in your (or my) dreams! I have tried creating a template and issuing it to the Certification Authority and then generating a custom certificate request in the name of my controller ( wireless.school.local for arguments sake) but the CA responds with the following error: The DNS name is unavailable and cannot be added to the Subject Alternate Name. 0x8009480f (-2146875377) Denied by policy module. This is a lot of hours work and the sum total is at present a fairly irritating error message! So, what I'm asking is: 1. Anyone got one of these beasts and made it work successfully in this mode rather than giving up and using a RADIUS server? 2. Anyone know how to generate a PKCS#12 certificate using MS Enterprise CA and not get annoying error messages? 3. Anyone want to buy a lightly used Wireless Controller??? 4. Anyone got a walkthrough they found out on the great unwashed web that explains things more clearly than the HP MSM-750 manual which is translated from the Serbo-Croat by a goat? 5. Anyone here able to say - "You dummy - don't do that - do this!" Scratch number three but any help on any of the others would be gratefully received.
-
Any teachers that we give password reset ability have a VBScript on their desktop that they run. They type in the students username and their password is reset. Generally find it much easier than trying to show teachers how to use the admin tools.
-
Some good points in there particularly the last one, that does often happen - if you move to a new position in the company, are promoted etc you will be asked to take on a new contract under the MSP's standard terms and conditions at which point you do lose any TUPE protection. ETO's are difficult to substantiate a lot of the time which is why they are not widely used. To be honest I think employers, although most will deny this, tend to sideline TUPE'd people that they want to get rid of in the hope that they will get bored or p*ssed off and leave. Come to think of it they will probably all deny that(!).
-
I'm going to do this in general outsourcing terms as I've been through that process several times, I understand that it wond't be entirely accurate to the peculiarities and quirks of BSF but I'm hoping it will be similar. What’s your job title before and after BSF? In general lower level staff retain a very similar job title; Technicians stay as technicians etc. The only general exception to this is when the outsource company splits technicians into different support groups - for example a remote support group and a field service group. This often happens to reduce costs and to try to provide a more immediate remote service rather than having to have a physical body on the ground. Who employs you before and after BSF? Post-transfer you would be employed by the managed service provider. What role did you play, if any? In outsourcing terms I have been involved in the process on a more junior level (ie getting transferred) and then later managing being outsourced and also bringing in an outsourced team into my own team (i.e. I was the managed service provider) Did the managed service work as expected? Who is your service provider? What I would say on this is the managed service works as CONTRACTED not necessarily as EXPECTED. This is an area where a lot of people fall over - because they have not been careful enough when drawing up the contracts for the managed service. This needs to be studied in depth and gone over again and again to make sure you have got it right before you sign on the dotted line. What issues did you as an ICT support team face before and after BSF? The area where most friction comes for lower level staff is the challenge of new working procedures and having to toe the line of the new MSP. For higher level staff it's fitting in with the Corporate culture and ethos of their new provider. For both it's the impact of often going from a very small team to a much larger one with a wider variety of scenarios and equipment to deal with. What impact has BSF had on your job role/description? Th thing to remember is that outsourcing does not have to keep your role exactly the same - you are outsourced on the same terms and conditions but it does not guarantee your role will be identical - often it is not - often this can be a good thing for you as it gives you the chance to do something new and more interesting. Have you lost members of your team because of BSF? There is nearly always loss during the outsourcing process - on a couple of fronts. 1. Staff panic before the process happens and run out and find a different job. Often if you are not careful you can lose good staff this way if they get nervous and you cannot allay their fears. 2. After the process has completed some people cannot cope with the change of circumstances and move on. 3. The MSP may decided that it doesn't need you and make you redundant - don't panic this is a very little used option and the evidence for it has to be bullet-proof or it's a world of hurt for the MSP. Have you lost pay due to BSF? You do not lose pay or benefits as part of the process - you must not be disadvantaged during the TUPE process. If your role then changes or the employer introduces a new whole company policy on say - company cars - you can be subsumed into this. But in essence no, you should not lose pay. Hope that makes sense and is helpful. Sorry it's not more specific to BSF.
-
Don't have any direct BSF knowledge although the authority here is putting together a BSF bid so may well shortly! Have had numerous dealings with RM and to be honest do think that they are below average when it comes to most things. Not the worst but definately a could do better - only my point of view of course. On the subject of TUPE, as from my previous post, I have been TUPE'd myself twice and managed a TUPE situation three times for other people so do have a reasonable amount of experience in this area. From this I do have a reasonable amount of understanding of the outsourcing process, which from my understanding is a fairly common part of the BSF bid. Outsourcing like most things has it's ups and it's down, the other poster is right to say that generally lower level staff tend to do better out of the process, more senior and managerial staff tend to encounter more issues during the process - I doubt the outsourcing involved in BSF is much different - outsourcing can be a good thing but it has to be handled both extremely carefully and very well by all parties concerned.
-
We are looking at it for the integration with Office. I suspect that's why most people do.
-
I have a similarish situation as we have the same server setup and Moodle running on it. We don't host the school website but are looking at Sharepoint on it. As an initial reaction I'm not sure that your external website and internal intranet should be on the same box unless you have a bulletproof security system setup. Technically however I'd be interested to see this one. I just have this feeling in the back of my head that I'm going to break something if I put sharepoint on - so I hope you get a positive response!
-
TUPE does allow for a variation of contract in two main ways - the transferring employee and incoming employer can negotiate a change of contact and agree terms as long as the change is not seen to be to the detriment of the employee. Secondly under the ETO terms an incoming employer can vary the terms and conditions of employment. ETO stands for economic, technical, organisational. This being the three primary reasons that are allowed. It is not often used as the defining scope is quite narrow and can be difficult for an employer to defend and if judged to be grossly detrimental to the incoming employee can be a fairly sticky situation for the incoming employer. However an NDA or confidentiality agreement can be seen to be outside the scope of the terms and conditions of employment as it can be judged to be an organisational policy agreement thereby negating any issue under TUPE guidelines. So, to be blunt, yes you can gag people if you are 1. Devious enough, 2. Have good enough lawyers. Allegedly! :-P
-
*URGENT* Accessing somones email in exchnage 2003/outlook
mrmontymick replied to kevbaz's topic in Windows
Solid advice if ever I heard it. -
*URGENT* Accessing somones email in exchnage 2003/outlook
mrmontymick replied to kevbaz's topic in Windows
That's not always the same thing - often it is but not always. There should be an Exchange Administrators group on your AD make sure you are in that. By full access do you mean you want to effectively "be" that person - send/receive as them etc or do you just want to see the contents and read their mailbox? -
I'm glad it's all working If you ever find the lan card changer do feel free to take them out the back and beat them with a big stick - I might even pop over and help out...
-
Don't forget to look back at this thread and undo any test changes we have made. Particularly the ALLOW ALL rule on the ISA server - that must be taken back off or you are leaving yourself wide open.
-
Yes, I would think that's an issue, from memory I think if it's not working then the ISA server drops to the default DENY ALL state. Does the Microsoft Firewall server definately show as running in services? What happens if you try and start it manually from a CMD box: net start fwsrv
-
If you go into ISA Server Management Console and right click on "Firewall Policy" and then New -> Access rule you will bring up the appropriate wizard. Give it a name such as TEST ALLOW ALL and click next Select "Allow" and click next Under "This Rule Applies to...." select "All Protocols" and click next Select Access Rule source as "Internal" - click next Select Access Rule destination as "External" click next Click this rule applies to "Everyone" - or "All Users" - Can't remember which one of these it is. - Or you can specify your Exchange server and Web server by computer name. Then click finish. Now do the same again but have Access rule source as "external" and access rule destination as "internal" Make sure both rules are at the top of your firewall rules list and click apply changes at the top of the ISA page - wait a couple of minutes for it to update and then try your exchange and web access. * Sorry if the instructions are slightly vague I don't have an ISA server in the building I'm in at the moment. It is hopefully close enough to make sense!
-
Can you just confirm your version of ISA.... I think you said 2003 earlier but from memory ISA comes in 2000, 2004, 2006 versions and then Forefront TMG is replacing it later this year.
