<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kernel Confusion &#187; Tools</title>
	<atom:link href="http://fitzzz.de/index.php/category/tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://fitzzz.de</link>
	<description>Blogging about my work as an IT consultant</description>
	<lastBuildDate>Wed, 11 Aug 2010 10:16:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>DirectAccess Connectivity Assistant</title>
		<link>http://fitzzz.de/index.php/2010/03/09/directaccess-connectivity-assistant/</link>
		<comments>http://fitzzz.de/index.php/2010/03/09/directaccess-connectivity-assistant/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 17:29:25 +0000</pubDate>
		<dc:creator>Christoph Schmidt</dc:creator>
				<category><![CDATA[Direct Access]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Tool]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://fitzzz.de/?p=222</guid>
		<description><![CDATA[DirectAccess is a great technology and I love to use it. If I get connection problems, I just open up my command line and examine the ipconfig output to see if something’s wrong. But is this something all your customers and colleagues are capable to do? I think not. Especially in rather large deployments, DirectAccess [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a title="DA Information" href="http://www.microsoft.com/windows/enterprise/products/windows-7/features.aspx" target="_blank">DirectAccess</a></strong> is a great technology and I love to use it. If I get connection problems, I just open up my command line and examine the ipconfig output to see if something’s wrong. But is this something all your customers and colleagues are capable to do? I think not. Especially in rather large deployments, DirectAccess might put your help desk under a lot of pressure.</p>
<p>To reduce such calls and ease the complexity of debugging actual problems, Microsoft’s <a href="http://technet.microsoft.com/en-us/library/ff384241.aspx" target="_blank">DirectAccess Connectivity Assistant</a> might come in handy. It’s a small tool that notifies the user of his current connection status and helps to provide valuable information to the help desk.</p>
<p>So let me show it to you in action.<br />
After setup it will show up in the user’s tray bar.</p>
<div id="attachment_224" class="wp-caption alignnone" style="width: 297px"><a href="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_1.png"><img class="size-full wp-image-224" title="da_assistant_1" src="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_1.png" alt="DirectAccess Connectivity Assistant in traybar" width="287" height="43" /></a><p class="wp-caption-text">DirectAccess Connectivity Assistant in traybar</p></div>
<p>A simple single click informs about the current status (as does the tooltip).</p>
<div id="attachment_225" class="wp-caption alignnone" style="width: 322px"><a href="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_2.png"><img class="size-full wp-image-225" title="da_assistant_2" src="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_2.png" alt="DirectAccess Connectivity Assistant balloon" width="312" height="134" /></a><p class="wp-caption-text">DirectAccess Connectivity Assistant balloon</p></div>
<p>A right-click offers two options: “Advanced Diagnostics” and a DNS preferation setting (we will come to that later)</p>
<div id="attachment_227" class="wp-caption alignnone" style="width: 235px"><a href="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_3.png"><img class="size-full wp-image-227" title="da_assistant_3" src="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_3.png" alt="DirectAccess Connectivity Assistant right-click menue" width="225" height="95" /></a><p class="wp-caption-text">DirectAccess Connectivity Assistant right-click menue</p></div>
<p>The “Advanced Diagnostics” window offers more detailed information about the status and will generate log files upon its launch. Those can be send via the “Email logs” button to a prespecified address. It also has a link to your company’s help desk web page.</p>
<div id="attachment_228" class="wp-caption alignnone" style="width: 391px"><a href="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_4.png"><img class="size-full wp-image-228" title="da_assistant_4" src="http://fitzzz.de/wp-content/uploads/2010/03/da_assistant_4.png" alt="DirectAccess Connectivity Assistant Advanced Diagnostics" width="381" height="398" /></a><p class="wp-caption-text">DirectAccess Connectivity Assistant Advanced Diagnostics</p></div>
<p>You will need to use the supplied ADMX/ADML files to configure the agent via Group Policy.<br />
To do this, on your Domain Controller, copy the “<strong>DirectAccess Connectivity Assistant GP.admx</strong>” file to the folder <strong>“%systemroot%\PolicyDefinitions</strong>” and then copy the “<strong>DirectAccess Connectivity Assistant GP.adml</strong>” file to the folder “<strong>%systemroot%\PolicyDefinititions\<em>language</em></strong>”. For example “<strong>%systemroot%\PolicyDefinitions\en-us</strong>” or “<strong>%systemroot%\PolicyDefinitions\de-DE</strong>”.</p>
<p>After that, you can launch the Group Policy Management MMC, open your DirectAccess GPO and navigate to “Computer Configuration / Administrative Templates / DirectAccess Connectivity Assistant”. You can now specify a couple of settings needed to use the tool.</p>
<p>At this point, I would like you to read the Deployment Guide supplied with the <a href="http://technet.microsoft.com/en-us/library/ff384241.aspx" target="_blank">download</a>, as it will help you to successfully deploy and configure your Assistant.</p>
]]></content:encoded>
			<wfw:commentRss>http://fitzzz.de/index.php/2010/03/09/directaccess-connectivity-assistant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The case of the slow smartcard</title>
		<link>http://fitzzz.de/index.php/2009/11/25/the-case-of-the-slow-smartcard/</link>
		<comments>http://fitzzz.de/index.php/2009/11/25/the-case-of-the-slow-smartcard/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 08:10:17 +0000</pubDate>
		<dc:creator>Christoph Schmidt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Smartcard]]></category>
		<category><![CDATA[Tool]]></category>

		<guid isPermaLink="false">http://fitzzz.de/?p=38</guid>
		<description><![CDATA[Computers tend to get slower over time, the more you use it, the faster this will happen. But is this true for hardware as well? In this case: smartcards? I didn’t believe it until I got my hands on a few cards from employees that complained about very slow read times. Our company enrolled smartcards [...]]]></description>
			<content:encoded><![CDATA[<p>Computers tend to get slower over time, the more you use it, the faster this will happen. But is this true for hardware as well? In this case: smartcards? I didn’t believe it until I got my hands on a few cards from employees that complained about very slow read times. Our company enrolled smartcards for Direct Access usage (and I love this Windows Server 2008 R2 feature!).</p>
<div id="attachment_48" class="wp-caption alignright" style="width: 160px"><a href="http://fitzzz.de/wp-content/uploads/2009/11/smartcard_tool.png" target="_blank"><img class="size-thumbnail wp-image-48 " title="smartcard_tool" src="http://fitzzz.de/wp-content/uploads/2009/11/smartcard_tool-150x150.png" alt="vSEC:CMS Key Tool" width="150" height="150" /></a><p class="wp-caption-text">vSEC:CMS Key Tool</p></div>
<p>In the logon screen, it took Windows nearly 45 seconds to read the slowest card and ask for the PIN. Wow! There was no evidence against the card reader, nor the other hardware, as a slow card was slow on all test systems.</p>
<p>But what can you do? Format C! And C stands for “card”. The simplest answers are the best! A short “bing” later, I found a tool named vSEC:CMS Key Tool, provided freely by <a href="http://www.versasec.com/cms.keytool.html" target="_blank">Versatile Security</a>. With it you can set the smartcard’s PIN and AdminPIN, unblock the user’s passcode and manage certificates. In this particular case, I deleted the original cert and reissued it. And guess what: as good (fast) as new!</p>
]]></content:encoded>
			<wfw:commentRss>http://fitzzz.de/index.php/2009/11/25/the-case-of-the-slow-smartcard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Get an overview of your Sharepoint Farm</title>
		<link>http://fitzzz.de/index.php/2009/11/22/get-an-overview-of-your-sharepoint-farm/</link>
		<comments>http://fitzzz.de/index.php/2009/11/22/get-an-overview-of-your-sharepoint-farm/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 23:52:11 +0000</pubDate>
		<dc:creator>Christoph Schmidt</dc:creator>
				<category><![CDATA[Sharepoint]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Farm]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MOSS]]></category>
		<category><![CDATA[SSP]]></category>
		<category><![CDATA[Tool]]></category>

		<guid isPermaLink="false">http://fitzzz.de/?p=12</guid>
		<description><![CDATA[A Microsoft Sharepoint Server can be very complicated, to say the least. Last week I had the task to establish Kerberos authentication throughout a very small Sharepoint environment, consisting just of a MS SQL 2008 Server and the Office Sharepoint Server itself. The installation was based on Microsoft&#8217;s best-practice recommendations, so every application pool and Windows service [...]]]></description>
			<content:encoded><![CDATA[<p>A Microsoft Sharepoint Server can be very complicated, to say the least. Last week I had the task to establish Kerberos authentication throughout a very small Sharepoint environment, consisting just of a MS SQL 2008 Server and the Office Sharepoint Server itself. The installation was based on Microsoft&#8217;s best-practice recommendations, so every application pool and Windows service  had it&#8217;s own domain user.</p>
<p>Looking up all interesting data can take some time, especially if you did not setup these servers yourself. I stumbled upon a small tool that gathers useful data about Office Sharepoint and Sharepoint Services environments. It is called <a href="http://www.codeplex.com/SPSFarmReport">SPSFarmReport</a> and is an open-source project at <a title="Codeplex" href="http://www.codeplex.com/" target="_blank">Codeplex</a>.</p>
<p>The following &#8220;questions&#8221; will be answered by the tool: </p>
<ul>
<li>How many servers exist in the farm?</li>
<li>What services are run by each server in your farm? Which server is the Query/Indexer?</li>
<li>Which server(s) host(s) the Central Administration web site in the farm?</li>
<li>How many SSPs exist in the farm?</li>
<li>Which is the default SSP in the farm?</li>
<li>What is the URL of the administration site of an SSP?</li>
<li>What is the URL of the My Site provider of an SSP?</li>
<li>What Web applications are associated with each SSP?</li>
<li>Which application pool is associated with each web application in the farm?</li>
<li>Which account is used to run a specific application pool?</li>
<li>How many content databases are associated with each web application and how many site collections does each have?</li>
<li>What AAMs are configured for each web application?</li>
</ul>
<p>You run it on one of the Sharepoint servers and it will gather all the data from there and create an HTML result file.</p>
<p>It really helped me to get an overview and locate all the accounts I had configure for Kerberos.</p>
<p>Get it here: <a href="http://www.codeplex.com/SPSFarmReport">http://www.codeplex.com/SPSFarmReport</a></p>
]]></content:encoded>
			<wfw:commentRss>http://fitzzz.de/index.php/2009/11/22/get-an-overview-of-your-sharepoint-farm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
