that's becasue the TDO ( trusted domain object) has been corrupted as i have been informed once from Microsoft
Busbar, one of the Experts out there, blog that wonderfull post and i wanted to share it with you
http://busbar.blogspot.com/2008/03/what-to-do-parentchild-domain-trust-is.html
Monday, March 31, 2008
when you send digitally signed message through exchange 2007 edge server, the message cannot be verfied on the destination
as the address say, when you send digitally signed message through exchange 2007 edge server, the message cannot be verfied on the destination, that has been raised for a while, by escalation case by myself, and after further investigation on that subject working with the support team whom they made a lot of work ( and me as well) i managed to fix that, it was a bug !
a bug in which when you send email from outlook in HTML format, it will reach the destination in unverfied format, and a red arrow in the front of head of the message, and that's only happen when you send HTML messages with attachement in it, that's also mean when you send HTML messages in HTML format without attachement it WILL be verified, so the problem came in sending attachement
sawing saw, i disabled the attachement filter on the edge servers, and voila ! it woked fine..
i reported that to Microsoft and hopefully a fix will be available on rollup update 2 for exchange SP1
btw, you still can use remove-attachementfilterentry cmdlet but i didn't tested that actually
Good luck with your implementation
Dr.Kernel
______________________
Edited:
Install Rollup update 2 for exchange 2007 SP1 and that will fix the issue
http://support.microsoft.com/kb/949703/
Regards
a bug in which when you send email from outlook in HTML format, it will reach the destination in unverfied format, and a red arrow in the front of head of the message, and that's only happen when you send HTML messages with attachement in it, that's also mean when you send HTML messages in HTML format without attachement it WILL be verified, so the problem came in sending attachement
sawing saw, i disabled the attachement filter on the edge servers, and voila ! it woked fine..
i reported that to Microsoft and hopefully a fix will be available on rollup update 2 for exchange SP1
btw, you still can use remove-attachementfilterentry cmdlet but i didn't tested that actually
Good luck with your implementation
Dr.Kernel
______________________
Edited:
Install Rollup update 2 for exchange 2007 SP1 and that will fix the issue
http://support.microsoft.com/kb/949703/
Regards
Tuesday, December 25, 2007
Remote Server Administration Tools (RSAT) Beta is now available!
This is something that of you have been waiting for a while now! Remote Server Administration Tools (RSAT) is essentially the WS08 version of the "Admin Pack". RSAT allows you to install many of the WS08 management tools on a Vista SP1 computer so you can remotely manage WS08 servers (full servers and server core). Some of the tools included in RSAT can also be used to manage WS03 servers as well.
More details about RSAT are pasted below.
=========================================
Microsoft® Remote Server Administration Tools enables IT administrators to remotely manage roles and features in Windows Server® 2008 from a computer running Windows Vista with Service Pack 1. It includes support for remote management of computers running a Server Core or Full Server installation of Windows Server 2008. This feature has been requested by customers as a replacement for the Windows Server 2003 Administration Tools Pack.
To test the Remote Server Administration Tools Beta and obtain customer feedback, Microsoft offers a Feature Focus program for this update, starting November 28, 2007 on the Microsoft Connect site. By participating in the program, you have the opportunity to try the new Remote Server Administration Tools, and provide feedback directly to the product team. The download is available as part of the Windows Beta program
More details about RSAT are pasted below.
=========================================
Microsoft® Remote Server Administration Tools enables IT administrators to remotely manage roles and features in Windows Server® 2008 from a computer running Windows Vista with Service Pack 1. It includes support for remote management of computers running a Server Core or Full Server installation of Windows Server 2008. This feature has been requested by customers as a replacement for the Windows Server 2003 Administration Tools Pack.
To test the Remote Server Administration Tools Beta and obtain customer feedback, Microsoft offers a Feature Focus program for this update, starting November 28, 2007 on the Microsoft Connect site. By participating in the program, you have the opportunity to try the new Remote Server Administration Tools, and provide feedback directly to the product team. The download is available as part of the Windows Beta program
Monday, December 24, 2007
CENTRO = SMALL BUSINESS SERVER SBS 2008
Centro" = Windows Essential Business Server
Essential Business Server combines Windows Server 2008, Exchange Server 2007, System Center Essentials, Forefront Security for Exchange, the next version of ISA and SQL Server 2008 (in Premium Edition) into an "all-in-one" solution. But the product is truly more than the sum of its parts and delivers new technology above and beyond the component products. Essential Business Server provides a single point of management for all of the components and workloads, as well as third party software applications, and incorporates an incredible amount of best practices. We estimate set up will require 75% fewer steps than what is required today, for example. In addition, it has a single server license and a single client access license, as well as features to help IT track, manage and re-assign licenses.
Microsoft hardware partners that are already planning to support Essential Business Server include Fujitsu Siemens, HP, IBM and Intel. Software partners already developing or planning on creating "Add-Ins" for the Essential Business Server console include CA, Citrix, FullArmor, McAfee, Quest, Symantec and Trend Micro. Microsoft applications will add-in, too, of course.
Thursday, November 29, 2007
E12 SP1 Released and its features
Hi Friends,
As we all know that Exchange 2007 SP1 will be released for production tomorrow 30/11/2007 after a while in market as a beta release. Now I will navigate you for the SP1 features and enhancements:
- Support for IPv4 and IP6
If you installed Exchange 2007 SP1 on windows Server 2008 you have an option to enter the IPv6 format
- CAS Improvement
o GUI for administering POP3 and IMAP4 for authentication, connection and ports setting
o EAS Improvement:
§ An Exchange ActiveSync default mailbox policy is created.
§ Enhanced Exchange ActiveSync mailbox policy settings have been added.
§ Remote Wipe confirmation has been added
§ Direct Push performance enhancements have been added
o Changes to Outlook Web Access Light so that Outlook Web Access does not time out while a user is composing a long entry.
o Changes to Outlook Web Access Premium The following features have been added to Outlook Web Access Premium in Exchange 2007 SP1:
§ Users can create and edit Personal Distribution Lists.
§ Users can create and edit server side rules.
§ WebReady Document Viewing has added support for some Office 2007 file formats
§ Users will have access to the dumpster from Outlook Web Access and will be able to use the Recover Deleted Items feature.
§ A monthly calendar view has been added.
§ Move and copy commands have been added to the Outlook Web Access user interface.
§ Public Folders are supported through the /owa virtual directory.
§ S/MIME support has been added.
- HUB Improvement
o Improvements in Transport Rule in the Back Pressure Future
o The addition of transport configuration options to the Exchange Management Console
- MB Improvement
o Public folder management by using the Exchange Management Console in MB server Role
o New public folder features
o Mailbox management improvements
o Ability to import and export mailbox by using .pst files
o New performance monitor counters for online database defragmentation
o Standby continuous replication
o New quorum models (disk and file share witness)
- Unified Communication
o Many features and enhancement for UM server role [ check the website]
And Support for public folder access. Public folders can now be created, deleted, edited, and synchronized by using the Exchange Web Services.
I will give a brief of SCR new feature in Exchange 2007 SP1
o Standby continuous replication
Basically, a regional cluster solution, or remote site recovery that Microsoft present to us out of the box. In brief instead of using LCR to replicate the database to a local hard drive in the Exchange Server 2007 server, SCR lets the copy of the storage group take place on multiple remote Exchange Server 2007 server within the site or between two sites. In the event the production server fails, then the copy generated by SCR can be mounted and run. I really love the MS Exchange team !
Regards,
As we all know that Exchange 2007 SP1 will be released for production tomorrow 30/11/2007 after a while in market as a beta release. Now I will navigate you for the SP1 features and enhancements:
- Support for IPv4 and IP6
If you installed Exchange 2007 SP1 on windows Server 2008 you have an option to enter the IPv6 format
- CAS Improvement
o GUI for administering POP3 and IMAP4 for authentication, connection and ports setting
o EAS Improvement:
§ An Exchange ActiveSync default mailbox policy is created.
§ Enhanced Exchange ActiveSync mailbox policy settings have been added.
§ Remote Wipe confirmation has been added
§ Direct Push performance enhancements have been added
o Changes to Outlook Web Access Light so that Outlook Web Access does not time out while a user is composing a long entry.
o Changes to Outlook Web Access Premium The following features have been added to Outlook Web Access Premium in Exchange 2007 SP1:
§ Users can create and edit Personal Distribution Lists.
§ Users can create and edit server side rules.
§ WebReady Document Viewing has added support for some Office 2007 file formats
§ Users will have access to the dumpster from Outlook Web Access and will be able to use the Recover Deleted Items feature.
§ A monthly calendar view has been added.
§ Move and copy commands have been added to the Outlook Web Access user interface.
§ Public Folders are supported through the /owa virtual directory.
§ S/MIME support has been added.
- HUB Improvement
o Improvements in Transport Rule in the Back Pressure Future
o The addition of transport configuration options to the Exchange Management Console
- MB Improvement
o Public folder management by using the Exchange Management Console in MB server Role
o New public folder features
o Mailbox management improvements
o Ability to import and export mailbox by using .pst files
o New performance monitor counters for online database defragmentation
o Standby continuous replication
o New quorum models (disk and file share witness)
- Unified Communication
o Many features and enhancement for UM server role [ check the website]
And Support for public folder access. Public folders can now be created, deleted, edited, and synchronized by using the Exchange Web Services.
I will give a brief of SCR new feature in Exchange 2007 SP1
o Standby continuous replication
Basically, a regional cluster solution, or remote site recovery that Microsoft present to us out of the box. In brief instead of using LCR to replicate the database to a local hard drive in the Exchange Server 2007 server, SCR lets the copy of the storage group take place on multiple remote Exchange Server 2007 server within the site or between two sites. In the event the production server fails, then the copy generated by SCR can be mounted and run. I really love the MS Exchange team !
Regards,
Saturday, November 24, 2007
SCCM Extras
Microsoft Links
1- System Center Configuration Manager 2007 Toolkit
Overview
The following list provides specific information about each tool in the toolkit.
Client Spy - A tool to help troubleshoot issues related to software distribution, inventory, and software metering on Configuration Manager 2007 clients.
Policy Spy - A policy viewer to help review and troubleshoot the policy system on Configuration Manager 2007 clients.
Trace32 - A log viewer that provides a way to easily view and monitor log files created and updated by Configuration Manager 2007 clients and servers.
Security Configuration Wizard Template for Configuration Manager 2007 - An attack-surface reduction tool for the Microsoft Windows Server 2003 operating system with Service Pack 1 and Service Pack 2 (SP1 and SP2) that determines the minimum functionality required for a server's role or roles, and disables functionality that is not required.
DCM Model Verification - A tool used by desired configuration management content administrators for the validation and testing of configuration items and baselines authored externally from the Configuration Manager console.
DCM Digest Conversion - A tool used by desired configuration management content administrators to convert existing SMS 2003 Desired Configuration Management Solution templates to Desired Configuration Management 2007 configuration items.
DCM Substitution Variables - A tool used by desired configuration management content administrators for authoring desired configuration management configuration items that use chained setting and object discovery.
http://www.microsoft.com/downloads/details.aspx?FamilyID=948E477E-FD3B-4A09-9015-141683C7AD5F&displaylang=en
=========================
2- System Center Configuration Manager 2007 Configuration Pack
Overview
Software installation errors and misconfigurations compromise security and stability, resulting in escalated support costs. The System Center Configuration Manager 2007 Configuration Pack can help prevent errors, increasing your organizational uptime and helping you build a more secure and reliable Configuration Manager 2007 infrastructure. This Configuration Pack contains Configuration Items intended to manage your Configuration Manager 2007 site system roles using the desired configuration management component in Configuration Manager 2007. This configuration pack monitors the following site system roles: management points, distribution points, and software update points. The Configuration Pack can also monitor Windows Server Update Services (WSUS) components on software update points or upstream WSUS servers. To manage your site system roles with this Configuration Pack, import and assign the Microsoft System Center Configuration Manager 2007 Server Roles configuration baseline to a collection which contains your Configuration Manager 2007 site systems. While there is one configuration baseline for all site systems, it evaluates compliance only for roles configured on the site system. For example, if a computer has only the distribution point role, it will not be evaluated for management point configurations. To understand in detail what each configuration item will be evaluating, review the properties of that configuration Iitem in the context of the Configuration Manager 2007 Server Role being addressed. System Center Configuration Manager 2007 site roles covered:
• Management points • Distribution points • Software update points
http://www.microsoft.com/downloads/details.aspx?familyid=45586F82-1816-4AEB-A0DC-ADE1859820B9&displaylang=en
=================================
3- System Center Configuration Manager 2007 Vulnerability Assessment Configuration Pack
Overview
Software installation errors and misconfigurations compromise security and stability, resulting in escalated support costs. System Center Configuration Manager 2007 Vulnerability Assessment Configuration Pack can help prevent errors, increasing your organizational uptime and helping you build a more secure infrastructure. This configuration pack provides vulnerability assessment reporting for common software misconfigurations using the desired configuration management component in Configuration Manager 2007. The Configuration Manager 2007 Vulnerability Assessment Configuration Pack monitors the configuration of Microsoft Windows operating systems, Internet Explorer, Microsoft Office, SQL Server, and Internet Information Services (IIS). To use this Configuration Pack, import and assign the three configuration baselines (Vulnerability Assessment: IIS Baseline, Vulnerability Assessment: SQL Server Baseline, Vulnerability Assessment: Windows Baseline) to a collection containing the computers you want to monitor. To understand in detail what each configuration item will be evaluating, review the properties of the configuration item. Scenarios:
• Scan for potential security issues that may exist because of misconfigurations. • Example checks:
o Are unnecessary services installed and running? o Do shared folders have appropriate permissions? o Is Windows Firewall enabled? o Are strong passwords enforced? o Are unsecured guest accounts enabled?
http://www.microsoft.com/downloads/details.aspx?familyid=FC6989E9-68A3-43B1-8019-72BC1B9C5FF3&displaylang=en
1- System Center Configuration Manager 2007 Toolkit
Overview
The following list provides specific information about each tool in the toolkit.
Client Spy - A tool to help troubleshoot issues related to software distribution, inventory, and software metering on Configuration Manager 2007 clients.
Policy Spy - A policy viewer to help review and troubleshoot the policy system on Configuration Manager 2007 clients.
Trace32 - A log viewer that provides a way to easily view and monitor log files created and updated by Configuration Manager 2007 clients and servers.
Security Configuration Wizard Template for Configuration Manager 2007 - An attack-surface reduction tool for the Microsoft Windows Server 2003 operating system with Service Pack 1 and Service Pack 2 (SP1 and SP2) that determines the minimum functionality required for a server's role or roles, and disables functionality that is not required.
DCM Model Verification - A tool used by desired configuration management content administrators for the validation and testing of configuration items and baselines authored externally from the Configuration Manager console.
DCM Digest Conversion - A tool used by desired configuration management content administrators to convert existing SMS 2003 Desired Configuration Management Solution templates to Desired Configuration Management 2007 configuration items.
DCM Substitution Variables - A tool used by desired configuration management content administrators for authoring desired configuration management configuration items that use chained setting and object discovery.
http://www.microsoft.com/downloads/details.aspx?FamilyID=948E477E-FD3B-4A09-9015-141683C7AD5F&displaylang=en
=========================
2- System Center Configuration Manager 2007 Configuration Pack
Overview
Software installation errors and misconfigurations compromise security and stability, resulting in escalated support costs. The System Center Configuration Manager 2007 Configuration Pack can help prevent errors, increasing your organizational uptime and helping you build a more secure and reliable Configuration Manager 2007 infrastructure. This Configuration Pack contains Configuration Items intended to manage your Configuration Manager 2007 site system roles using the desired configuration management component in Configuration Manager 2007. This configuration pack monitors the following site system roles: management points, distribution points, and software update points. The Configuration Pack can also monitor Windows Server Update Services (WSUS) components on software update points or upstream WSUS servers. To manage your site system roles with this Configuration Pack, import and assign the Microsoft System Center Configuration Manager 2007 Server Roles configuration baseline to a collection which contains your Configuration Manager 2007 site systems. While there is one configuration baseline for all site systems, it evaluates compliance only for roles configured on the site system. For example, if a computer has only the distribution point role, it will not be evaluated for management point configurations. To understand in detail what each configuration item will be evaluating, review the properties of that configuration Iitem in the context of the Configuration Manager 2007 Server Role being addressed. System Center Configuration Manager 2007 site roles covered:
• Management points • Distribution points • Software update points
http://www.microsoft.com/downloads/details.aspx?familyid=45586F82-1816-4AEB-A0DC-ADE1859820B9&displaylang=en
=================================
3- System Center Configuration Manager 2007 Vulnerability Assessment Configuration Pack
Overview
Software installation errors and misconfigurations compromise security and stability, resulting in escalated support costs. System Center Configuration Manager 2007 Vulnerability Assessment Configuration Pack can help prevent errors, increasing your organizational uptime and helping you build a more secure infrastructure. This configuration pack provides vulnerability assessment reporting for common software misconfigurations using the desired configuration management component in Configuration Manager 2007. The Configuration Manager 2007 Vulnerability Assessment Configuration Pack monitors the configuration of Microsoft Windows operating systems, Internet Explorer, Microsoft Office, SQL Server, and Internet Information Services (IIS). To use this Configuration Pack, import and assign the three configuration baselines (Vulnerability Assessment: IIS Baseline, Vulnerability Assessment: SQL Server Baseline, Vulnerability Assessment: Windows Baseline) to a collection containing the computers you want to monitor. To understand in detail what each configuration item will be evaluating, review the properties of the configuration item. Scenarios:
• Scan for potential security issues that may exist because of misconfigurations. • Example checks:
o Are unnecessary services installed and running? o Do shared folders have appropriate permissions? o Is Windows Firewall enabled? o Are strong passwords enforced? o Are unsecured guest accounts enabled?
http://www.microsoft.com/downloads/details.aspx?familyid=FC6989E9-68A3-43B1-8019-72BC1B9C5FF3&displaylang=en
Sunday, November 18, 2007
Step-By-Step Guide: Configure System Center Configuration Manager 2007 For Native Mode By Certificate
Hi Guys
Today, I present to you the first document in the internet that guide you to configure certificates for SCCM 2007 preparing it for the native mode
the file is attached as .pdf and it's allowed to be published everywhere but please credit that to Dr.Kernel as the owner
Download Link:
http://msaadexpert.googlepages.com/SCCM_NativeMode.pdf
Today, I present to you the first document in the internet that guide you to configure certificates for SCCM 2007 preparing it for the native mode
the file is attached as .pdf and it's allowed to be published everywhere but please credit that to Dr.Kernel as the owner
Download Link:
http://msaadexpert.googlepages.com/SCCM_NativeMode.pdf
Thursday, November 15, 2007
10 Steps guide to configure Certificate based authentication between Agents and Management Server
I made this guide to configure certificate based authentication between ths SCOM RMS server and agents in non-trusted domain. Tarek did helped me at the first place by telling me about momcertimport.exe tool that i didn't knew about it at the time being, then i figured it out after a while
Download:
http://tarek.ismail.googlepages.com/CertificateOpsMgr2007.pdf
it's posted at Tarek's blog earlier that i had no blog at that time :)
Download:
http://tarek.ismail.googlepages.com/CertificateOpsMgr2007.pdf
it's posted at Tarek's blog earlier that i had no blog at that time :)
Monday, November 12, 2007
SCOM 2007 Parametrs
Well well well, what we have here ...
have you tried to run the /? command on every .exe file you ever see ? actually that's me :)
and here is the result of what i got on the SCOM executable file
C:\Program Files\System Center Operations Manager2007>Microsoft.MOM.UI.Console.exe /?
i liked that /clearcache one looks usefull
Microsoft Forefront Client Security Health Management Pack for MOM 2005
The Forefront Client Security Management Pack allows you to monitor key Client Security components from a centralized MOM location in order to ensure that your Client Security environment is running efficiently.
This is to mention that it's just arrived, more details will come soon
http://www.microsoft.com/downloads/details.aspx?FamilyID=0672b4ca-c6dc-4093-bae6-30eb1560a429&DisplayLang=en
This is to mention that it's just arrived, more details will come soon
http://www.microsoft.com/downloads/details.aspx?FamilyID=0672b4ca-c6dc-4093-bae6-30eb1560a429&DisplayLang=en
Subscribe to:
Posts (Atom)

