Search This Blog

Wednesday, February 26, 2014

fix up Mdaemon outlook connector license issue

fix up Mdaemon outlook connector license issue - - -

this client got 25 license, I deleted one user, and tried to add another.

To my horror, I dont have the option to enable the new user to use outlook connector.

eventually sussed out a configuration file groupware dat , that file holds all OC userlist,

I noticed there is a duplicate when I changed an user mailbox last year. remove the duplicate, I got a free license to re-assign to the new user.

another day of heroic rootkit clean action -- tssdkiller did it, and I recovered it from bluescreen

another day of heroic rootkit clean action

the customer said they killed , but the anti-virus program wont start/run in real-time protection

avast can't do it,

remove avast,

install avast 2014 , it got an error, failed to install

install avir , installed ok, but avir failed to enable real time protection

tried nod32 online scan,  97% , the browser crashed

run malwarebyte scan, nothing found

then I spoted kapersky tssdkiller in my toolkit, run it, I saw a driver error message,

run again, it found a rootkit, kill it many times

started the PC in normal mode, crashed big time.... long story short

win32k.sys

page_fault_in_nonpaged_area

STOP : oxoooooo50

search the net, found internet comment about ati/amd driver package crashes win32k.sys. did a manual , driver only install of display driver.

all good.

btw the PC is windows XP x64 with SP2




Sunday, February 23, 2014

Windows Server 2012 R2 Essentials migration from small business server 2003

http://technet.microsoft.com/en-us/library/dn408634.aspx

there is a migtation path for sbs 2003 , yeah, small biz server 2003

but bear in mind essentials server only support 25 users, 50 devices



Saturday, February 22, 2014

Friday, February 21, 2014

system center advisor is now free

https://www.systemcenteradvisor.com/

it is a very interesting product

Thursday, February 20, 2014

shadow a terminal server 2012 R2 session --- can't do it via task mgr

shadow a terminal server 2012 R2 session --- can't do it via task mgr

http://microsoftplatform.blogspot.nl/2013/07/detailed-walkthrough-on-remote-control.html

have to do it
via server manager  --- Remote desktop services --- connections

right-click on the connection, then shadow to your hearts content


Wednesday, February 19, 2014

share nothing migration between server 2012 R2 hyper-v hosts

share nothing migration between server 2012 R2 hyper-v hosts\

it's that easy ,

right-click on the hyper-v VM you want to move, click move,

got an error regarding the VM switch, in the drop-down box , select the destination switch

then asked for the path on the remote server; enter it like e:\storage\hyper-v

finally the the VM got moved in my case, its a PDC, yeah it got moved over , and started

Wednesday, February 12, 2014

add remove access role to server 2012 R2 got error "Please restart your computer to finish update"

this is confusing as I tried to add remove access role, then I restarted the server many times, I still got this error.
“The request to add or remove features on the specified server failed. the operation cannot be completed because the server that you specified requires a restart.”
the event logs shows
  • The MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID with the currently configured password due to the following error:
    Logon failure: the user has not been granted the requested logon type at this computer.
    Service: MSSQL$MICROSOFT##WID
    Domain and account: NT SERVICE\MSSQL$MICROSOFT##WID
    This service account does not have the required user right "Log on as a service."

google search had some links
http://social.technet.microsoft.com/Forums/windowsserver/en-US/ae2baa1b-3aba-4d84-9a3c-0588b9a0f298/wsus-roles-install-on-server-2012-fails?forum=winserverwsus

http://support.microsoft.com/kb/2832204

http://social.msdn.microsoft.com/Forums/en-US/12d973bd-7210-48dc-95cb-d732da03eac9/windows-internal-database-and-log-on-as-a-service-on-windows-server-2012-vm?forum=WAVirtualMachinesforWindows
http://eskonr.com/2013/06/wsus-role-failed-on-windows-server-2012-with-error-the-operation-cannot-be-completed-because-the-server-that-you-specified-requires-a-restart/

resolution :

  • Assign the Log on as a service user right to NT SERVICE\ALL SERVICES in the GPO that defines the user right.
  • Exclude the computer from the GPO that defines the user right.  ( I am not sure about this)

so I checked domain policy , domain controller policy ( as I tried to setup pptp server on the 2012 R2 DC), the problem persists,
then do secpol.msc, I noticed NT SERVICE\ALL SERVICES is listed under denied logon as a service.
I manually remove the NT SERVICE\ALL SERVICES from the denied-list; WID sucessfully install, so is remote access role

interestingly, is there a local security policy on a domain controller ?




Monday, February 10, 2014

activate open volume license for an Office 365 M account

Subscription Activation
Once the product keys have been retrieved from VLSC, the next step is to redeem them on the Office 365 portal and get started with the subscription. We strongly encourage you to work with your customer to complete this process.
Step 1: Go to office.com/setup365
Step 2: Enter the 5x5 product keys you retrieved from VLSC. If you have multiple product keys to complete the desired user count, you can add them now by clicking “add more product keys.”
Step 3: Enter the required information regarding the customer organization. It’s

Thursday, February 6, 2014

import outlook express 6.0 emails to windows 8.1 , windows essentials 2012

import outlook express 6.0 emails to windows 8.1 , windows essentials 2012

Billy's mum moved to the retirement village in town. I got hired to move stuff over from the old windows xp home PC to a brand new w8.1 notebook

they bought office 2013 student and home vesion, so there is no outlook

windows 8 mail app wont work with local isp pop3 server,

download windows essentials 2012, this includes the live mail, in the free live mail, you can import outlook express 6.0 emails

so in windows xp, in outlook express 6, in one of the options , find the mail store location, copy it over via a usb disc

should be all good

a step to step guide for setting up an IPSEC VPN tunnel between Sonicwall and fortigate 5.0: aggressive mode , local id, remote ike id

a step to step guide for setting up an IPSEC VPN tunnel between Sonicwall TZ200 and fortigate 5.0

a brief outline,

I worked on building a tunnel this week.

I am configuring the sonicwall at a customer's premise, Christ is configuring the fortigate on the cloud-host side.

we finally got the VPN showing up as established. but the nightmare begins as we can't ping each other.

asked the circuit provider, they said they are not doing any filtering.

scratch my head, squeeze my brain for a couple of days for the dilemma.

tried again troubleshooting the issue with Christ over the phone

change main mode to aggressive mode , then back again, in aggressive mode, the sonciwall logs show the remote peer doesn't support NAT traversal

Christ ticked the enable NAT on the fortigate

still no luck,

I asked Christ to put in the peer id which is optional on the fortigate, and use the local id of the external interface (this may not matter)

then lots of messages showed up in the sonicwall complaining no such policy for FQDN id: xxxx.xxxx.xxxx.xxxx

Christ reminded me FQDN is domain name,

alas, I seemed to see the light

the sonicwall local ike id / remote ike id , I put in as IP address by default, while fortigate send out the remote id as FQDN.

change the remote ike id to domain names on the sonicwall, tracert / ping returned 22ms.

eventually nailed it

so in summary,

aggressive mode -- this mode shows more messages about the tunnell, more clues about an issue
local ID or local IKE ID on the fortigate /sonicwall
remote ID / remote IKE ID on the fortinet and dell firewalls - make sure the type is matching


Sunday, February 2, 2014

itunes msvcr80.dll error after failed update

itunes msvcr80.dll error after failed update

tried sfc /scannow

manually copied msvcr80.dll

all failed without any luck

in apple forum, it's suggested to un-install the following

iTunes
Apple Software Update
Apple Mobile Device Support
Bonjour
Apple Application Support


then install itunes again

this worked for me.

what a relief

Active directory recycle bin needs forest functional level of your environment is set to Windows Server 2008 R2

forest functional level of your environment is set to Windows Server 2008 R2, then AD recycle bin will be available

http://technet.microsoft.com/en-us/library/dd379481(v=ws.10).aspx