-
Posts
13,543 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Geoff
-
Blender can also do video editing. https://www.blender.org
-
@ReadTheNetwork I've never used App-V in SCCM. Can you point me towards a guide?
-
Linux equivalent is LXC. You've also got Docker Containers which is used in the real world. All good stuff though.
-
We use lync for this, but I imagine you could do something for free with Jabber.
-
AppDiscovery.log and AppIntectEval.log may also have clues.
-
Bookmark this page. It lists a lot of the useful SCCM log files. Unfortuantly not new ones in 2012 though https://blogs.msdn.microsoft.com/lxchen/2009/04/03/a-list-of-sccm-log-files/ The one you want to look at is on the client and it's the AppEnforce.log file. This should tell you what is going on. Also if you still have no joy, try wrapping up the MSI deployment in the Powershell App Deploy Toolkit. PowerShell App Deployment Toolkit You get much better error handling and logging at a minimum. Plus it's easier to test packages before you put them into SCCM.
-
Depends how buggy the firewall is. Turn the debugging on and post the SIP conversation. You may also need to get wireshark out and actually inspect the packet headers at various points on your network.
-
This is a firewall issue. Most likely you have sort of SIP 'feature' turned on in the firewall that can't handle rewrting two SIP channels at the same time. It's usually called 'SIP ALG' or something. https://www.voip-info.org/wiki/view/Routers+SIP+ALG
-
Run Powershell script on initial logon per machine
Geoff replied to thimon's topic in How do you do....it?
Check if there is a pinned edge button on the taskbar then remove it if you found it? That way you don't need to care if you ran the script before (and as a bonus it'll remove the pin if it gets readded at a later date for some reason). The location pinned applications are stored are in %AppData%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar -
New Azure AD Connect install - missing Powershell modules
Geoff replied to 3s-gtech's topic in Cloud Services
Download Details | Microsoft Connect -
The only issues I've had have been disk usage (so I stuck quotas on) and speed (so I shared it via a Windows VM with a ton of ram for caching).
-
The other thing that might be messing it up at the branch sites is the routing. It looks like I might need to change to subnet directed broadcasts and my switch configs? https://www.experts-exchange.com/questions/25283286/Allowing-wake-on-lan-packets-to-traverse-WAN-using-SCCM.html Doesn't explain why it doesn't work as I expect at the main site though.
-
It's application deployments. So for example. I had a Flash update to deadline at 1pm yesterday. However I have a nightly maintainence schedule set to run from 1am to 4am. I'd like ideally the machines to WoL at both times. I was unaware of the PKI requirement. However I have PKI setup as I wanted HTTPS for my DPs anyway. As per this blog: https://blogs.technet.microsoft.com/configmgrdogs/2015/01/21/configmgr-2012-r2-certificate-requirements-and-https-configuration/
-
I had assumed that if I had WoL configured in SCCM it would use WoL to turn machines on in their maintenance windows if there was a deployment or update due for the device. This does not seem to be happening. Has anyone else got SCCM configured so this does happen?
-
The underlying kerberos setup is fine (and has been running ok for years). I managed to create a keytab with my domain admin account with your instructions: root@fshelpdesk:/etc# klist -k geoffk-da.keytab Keytab name: FILE:geoffk-da.keytab KVNO Principal ---- -------------------------------------------------------------------------- 1 [email protected] and login: root@fshelpdesk:/etc# kinit Geoffk-da -k -t geoffk-da.keytab root@fshelpdesk:/etc# klist Ticket cache: FILE:/tmp/krb5cc_0 Default principal: [email protected] Valid starting Expires Service principal 04/01/17 15:38:29 05/01/17 01:38:29 krbtgt/[email protected] renew until 05/01/17 01:38:29
-
You can get the OEM drivers straight off broadcom too. https://www.broadcom.com/support/ethernet-nic Also try a linux live CD, just to check the hardware is actually ok and they haven't died somehow.
-
I had duplicate SPNs which I've removed. I've also followed the guidance in this stack overflow answer and created a second user account for the vhost and its Kerberos SPN: centos - Apache kerberos authentication to Active Directory not happening. (Is KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN related?) - Server Fault However I now get this error in my logs: [Wed Jan 04 14:57:04.367867 2017] [authz_core:debug] [pid 2023] mod_authz_core.c(802): [client 172.31.1.25:57795] AH01626: authorization result of Require valid-user : denied (no authenticated user yet) [Wed Jan 04 14:57:04.367919 2017] [authz_core:debug] [pid 2023] mod_authz_core.c(802): [client 172.31.1.25:57795] AH01626: authorization result of : denied (no authenticated user yet) [Wed Jan 04 14:57:04.367945 2017] [auth_kerb:debug] [pid 2023] src/mod_auth_kerb.c(1652): [client 172.31.1.25:57795] kerb_authenticate_user entered with user (NULL) and auth_type Kerberos [Wed Jan 04 14:57:04.368001 2017] [auth_kerb:debug] [pid 2023] src/mod_auth_kerb.c(1260): [client 172.31.1.25:57795] Acquiring creds for [email protected] [Wed Jan 04 14:57:04.379675 2017] [auth_kerb:debug] [pid 2023] src/mod_auth_kerb.c(1121): [client 172.31.1.25:57795] GSS-API major_status:000d0000, minor_status:025ea101 [Wed Jan 04 14:57:04.379876 2017] [auth_kerb:error] [pid 2023] [client 172.31.1.25:57795] gss_acquire_cred() failed: Unspecified GSS failure. Minor code may provide more information (, No key table entry found matching HTTP/fshelpdesk.uk.forbessolicitors.co.uk@) I tried the login suggestion @jinnantonnixx and I get this: root@fshelpdesk:/etc# kinit ~dokuwiki-kerberos -k -t /etc/dokuwiki.uk.forbessolicitors.co.uk.keytab kinit: Keytab contains no suitable keys for [email protected] while getting initial credentials This serverfault page points to rDNS being an issue. Wrong principal in request (SSH/ GSSAPI/Kerberos/Debian) - Server Fault As I am using vhosts my rdns does not resolve to my forward dns for this host. I am wondering if that is the issue.
-
Grabbed Astroneer over the holidays based on some Youtubers gameplay footage. Quite ejoying it even though I broke my own 'don't buy pre-release / early access games'.
-
I've had a VM running Request Tracker on Ubuntu for ages. It uses mod_auth_kerberos for authentication. I also had dokuwiki in a sub directory on the webserver. To tidy things up I decided to move dokuwiki to it's own vhost on the same server. However after I've done this kerberos SSO fails. initally it was complaining about the SPN not matching [Wed Jan 04 09:34:20.156753 2017] [authz_core:debug] [pid 32419] mod_authz_core.c(802): [client 172.31.250.47:55634] AH01626: authorization result of Require valid-user : denied (no authenticated user yet) [Wed Jan 04 09:34:20.156911 2017] [authz_core:debug] [pid 32419] mod_authz_core.c(802): [client 172.31.250.47:55634] AH01626: authorization result of : denied (no authenticated user yet) [Wed Jan 04 09:34:20.156989 2017] [auth_kerb:debug] [pid 32419] src/mod_auth_kerb.c(1652): [client 172.31.250.47:55634] kerb_authenticate_user entered with user (NULL) and auth_type Kerberos [Wed Jan 04 09:34:20.157068 2017] [auth_kerb:debug] [pid 32419] src/mod_auth_kerb.c(1260): [client 172.31.250.47:55634] Acquiring creds for [email protected] [Wed Jan 04 09:34:20.166005 2017] [auth_kerb:debug] [pid 32419] src/mod_auth_kerb.c(1406): [client 172.31.250.47:55634] Verifying client data using KRB5 GSS-API with our SPNEGO lib [Wed Jan 04 09:34:20.166356 2017] [auth_kerb:debug] [pid 32419] src/mod_auth_kerb.c(1422): [client 172.31.250.47:55634] Client didn't delegate us their credential [Wed Jan 04 09:34:20.166437 2017] [auth_kerb:debug] [pid 32419] src/mod_auth_kerb.c(1441): [client 172.31.250.47:55634] GSS-API token of length 9 bytes will be sent back [Wed Jan 04 09:34:20.166543 2017] [auth_kerb:debug] [pid 32419] src/mod_auth_kerb.c(1121): [client 172.31.250.47:55634] GSS-API major_status:000d0000, minor_status:96c73a90 [Wed Jan 04 09:34:20.166669 2017] [auth_kerb:error] [pid 32419] [client 172.31.250.47:55634] gss_accept_sec_context() failed: Unspecified GSS failure. Minor code may provide more information (, Wrong principal in request) I've regenereted the keytab and added in the extra SPN for the new vhost. ktutil: read_kt /etc/krb5.keytab ktutil: l slot KVNO Principal ---- ---- --------------------------------------------------------------------- 1 9 HTTP/[email protected] 2 10 HTTP/[email protected] Now I get a different error blaming IE for trying to use NTLM authentication (when it isn't). [Wed Jan 04 10:23:37.613722 2017] [authz_core:debug] [pid 558] mod_authz_core.c(802): [client 172.31.250.47:58755] AH01626: authorization result of : denied (no authenticated user yet) [Wed Jan 04 10:23:37.613737 2017] [auth_kerb:debug] [pid 558] src/mod_auth_kerb.c(1652): [client 172.31.250.47:58755] kerb_authenticate_user entered with user (NULL) and auth_type Kerberos [Wed Jan 04 10:23:37.613797 2017] [auth_kerb:debug] [pid 558] src/mod_auth_kerb.c(1260): [client 172.31.250.47:58755] Acquiring creds for [email protected] [Wed Jan 04 10:23:37.624509 2017] [auth_kerb:debug] [pid 558] src/mod_auth_kerb.c(1406): [client 172.31.250.47:58755] Verifying client data using KRB5 GSS-API [Wed Jan 04 10:23:37.624540 2017] [auth_kerb:debug] [pid 558] src/mod_auth_kerb.c(1422): [client 172.31.250.47:58755] Client didn't delegate us their credential [Wed Jan 04 10:23:37.624547 2017] [auth_kerb:debug] [pid 558] src/mod_auth_kerb.c(1450): [client 172.31.250.47:58755] Warning: received token seems to be NTLM, which isn't supported by the Kerberos module. Check your IE configuration. [Wed Jan 04 10:23:37.624553 2017] [auth_kerb:debug] [pid 558] src/mod_auth_kerb.c(1121): [client 172.31.250.47:58755] GSS-API major_status:00010000, minor_status:00000000 [Wed Jan 04 10:23:37.624568 2017] [auth_kerb:error] [pid 558] [client 172.31.250.47:58755] gss_accept_sec_context() failed: An unsupported mechanism was requested (, Unknown error)
-
I'd try telnetting it and running SMTP commands against it to see if it works. You should be able to telnet in and manually send an email. https://www.port25.com/how-to-check-an-smtp-connection-with-a-manual-telnet-session-2/
-
[VEEAM] - Multiple .AVHDX Files being created but not deleted
Geoff replied to FragglePete's topic in Enterprise Software
There used to be a setting on the Hyper-v tab of the advanced settings for the backup job. It doesn't look like it exists any more. BTW I googled a bit more and this is apparently a problem with Microsofts own backup tools too. https://blog.workinghardinit.work/2015/10/15/remove-lingering-backup-checkpoints-from-a-hyper-v-virtual-machine/ -
[VEEAM] - Multiple .AVHDX Files being created but not deleted
Geoff replied to FragglePete's topic in Enterprise Software
This is Microsofts fault. Assuming you ticked the box to tell it to delete the checkpoints all Veeam does is ask the VSS to make a backup checkpoint then remove it. What happens when you try and remove the checkpoints with powershell? List checkpoints: Get-VMSnapshot -VMName vmwithcheckpoint.domain.com -ComputerName hyper-v.domain.com| fl Deletes checkpoints: Get-VMSnapshot -VMName vmwithcheckpoint.domain.com -ComputerName hyper-v.domain.com| Remove-VMSnapshot -
Updating deployed SCCM Packages with supersedance
Geoff replied to Geoff's topic in Enterprise Software
Alright well I've just chucked out Flash 24.0.0.186 with supersedence so we'll see. -
The question is, should I bother? What's best practice here? I have PSADT based SCCM Application Packages for Flash, Java, Adobe Reader DC, etc and due to the historic nature of some of the clients I had to write in some pretty complex uninstall routines in the pre-installation step of the PSADT script. So given that should I bother telling SCCM that the new version of Adobe is an upgrade of the old package or should I not bother and simply remove the deployments for the old one and push the new one out? Or should I supersede the old version with the new one?
-
Just got a Microsoft Surface Hub. Very impressed with it. Not sure if it's suitable for a school though.
