<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows on Evan Hoffman</title><link>https://evan.wtf/tags/windows/</link><description>Recent content in Windows on Evan Hoffman</description><generator>Hugo</generator><language>en-US</language><copyright>Evan Hoffman</copyright><lastBuildDate>Sun, 18 Sep 2011 12:22:46 +0000</lastBuildDate><atom:link href="https://evan.wtf/tags/windows/index.xml" rel="self" type="application/rss+xml"/><item><title>Exchange (OWA) CAS crashes with 503 error - again</title><link>https://evan.wtf/2011/09/18/exchange-owa-cas-crashes-with-503-error-again/</link><pubDate>Sun, 18 Sep 2011 12:22:46 +0000</pubDate><guid>https://evan.wtf/2011/09/18/exchange-owa-cas-crashes-with-503-error-again/</guid><description>&lt;p&gt;This just started happening &lt;a href="https://evan.wtf/evan/?p=986"&gt;again&lt;/a&gt;, with these errors appearing in the event viewer:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;Log Name: System&#10;Source: Microsoft-Windows-WAS&#10;Date: 9/18/2011 11:16:33 AM&#10;Event ID: 5011&#10;Task Category: None&#10;Level: Warning&#10;Keywords: Classic&#10;User: N/A&#10;Computer: exch2010fe1&#10;Description:&#10;A process serving application pool &amp;#39;MSExchangeOWAAppPool&amp;#39; suffered a&#10;fatal communication error with the Windows Process Activation Service.&#10;The process id was &amp;#39;3760&amp;#39;. The data field contains the error number.&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Log Name: System&#10;Source: Microsoft-Windows-WAS&#10;Date: 9/17/2011 6:47:07 AM&#10;Event ID: 5009&#10;Task Category: None&#10;Level: Warning&#10;Keywords: Classic&#10;User: N/A&#10;Computer: exch2010fe1&#10;Description:&#10;A process serving application pool &amp;lsquo;MSExchangeOWAAppPool&amp;rsquo; terminated&#10;unexpectedly. The process id was &amp;lsquo;3108&amp;rsquo;. The process exit code was&#10;&amp;lsquo;0x800703e9&amp;rsquo;.&lt;/p&gt;</description></item><item><title>Renaming a single-label domain to a FQDN</title><link>https://evan.wtf/2011/04/07/renaming-a-single-label-domain-to-a-fqdn/</link><pubDate>Thu, 07 Apr 2011 17:56:54 +0000</pubDate><guid>https://evan.wtf/2011/04/07/renaming-a-single-label-domain-to-a-fqdn/</guid><description>&lt;p&gt;Long ago &amp;ndash; eons, perhaps &amp;ndash; before I had anything to do with the Windows environment here, someone created the AD domain in my company as a single-label domain (e.g. instead of &amp;ldquo;example.com&amp;rdquo; our domain is just &amp;ldquo;example&amp;rdquo;). Over the years this has led to lots of &amp;ldquo;fun&amp;rdquo; on the part of Windows admins who&amp;rsquo;ve worked here as the implications of this choice became more apparent.&lt;/p&gt;&#10;&lt;p&gt;Since I inherited this system about a year ago, I haven&amp;rsquo;t really bumped up against any problems stemming from the single-label domain issue&amp;hellip; until now. I recently attempted to add a new Windows 2008r2 file server to our DFS replication group/namespace. This totally failed for some mysterious reason. Well, I shouldn&amp;rsquo;t say &amp;ldquo;totally&amp;rdquo; failed, as I was able to add it to the DFS replication group, but unable to add it to the DFS namespace. In my attempt to debug the namespace issue, I deleted the namespace and attempted to recreate it, but just kept getting this error: &lt;strong&gt;The namespace cannot be queried. The specified domain either does not exist or could not be contacted.&lt;/strong&gt;. I couldn&amp;rsquo;t do anything with the namespace - even clicking on it in the DFS Management console brought up an error. After some searching I found that this was likely due to having a single-label domain. I wasn&amp;rsquo;t sure why the error was happening even on Windows 2003 machines though, maybe joining a 2008r2 box to the domain made some schema changes? I tried a few suggestions like editing the hosts file but nothing seemed to resolve this.&lt;/p&gt;</description></item><item><title>Autodiscover mysteriously stopped working (Exchange 2010)</title><link>https://evan.wtf/2011/03/01/autodiscover-mysteriously-stopped-working-exchange-2010/</link><pubDate>Tue, 01 Mar 2011 12:30:30 +0000</pubDate><guid>https://evan.wtf/2011/03/01/autodiscover-mysteriously-stopped-working-exchange-2010/</guid><description>&lt;p&gt;I had &lt;a href="http://technet.microsoft.com/en-us/library/bb124251.aspx"&gt;Autodiscover&lt;/a&gt; working for months but recently it just stopped. I&amp;rsquo;m not sure why, but it may be related to removing the last Exchange 2003 servers from service recently. Maybe some setting got wiped from AD when I uninstalled Exchange 2003 (as per &lt;a href="http://technet.microsoft.com/en-us/library/bb288905%28EXCHG.80%29.aspx"&gt;the procedure&lt;/a&gt; Microsoft gives). Basically what was happening was that the email address field was being autopopulated by the user&amp;rsquo;s UPN rather than their email address. Since we have a &lt;a href="http://support.microsoft.com/kb/300684"&gt;single label domain&lt;/a&gt;, the UPN isn&amp;rsquo;t a valid email address, and autodiscovery fails.&lt;/p&gt;</description></item><item><title>Wasted time with Exchange 2010, SquirrelMail, and IMAP-SSL</title><link>https://evan.wtf/2010/11/30/wasted-time-with-exchange-2010-squirrelmail-and-imap-ssl/</link><pubDate>Tue, 30 Nov 2010 17:32:11 +0000</pubDate><guid>https://evan.wtf/2010/11/30/wasted-time-with-exchange-2010-squirrelmail-and-imap-ssl/</guid><description>&lt;p&gt;I&amp;rsquo;m setting up SquirrelMail to point to my Exchange 2010 server via IMAP (don&amp;rsquo;t ask) and couldn&amp;rsquo;t get SM to talk to Exchange on port 993 (imaps). Even though the servers on the same subnet, any time passwords are being sent over the network I like to opt for SSL. I found a couple of sites suggesting that the problem was that there was no SSL certificate installed, but I knew for a fact there was a valid certificate because I could get to &lt;a href="https://webmail.example.com/"&gt;https://webmail.example.com/&lt;/a&gt; for OWA.&lt;/p&gt;</description></item><item><title>Using Zabbix for SNMP monitoring disk usage percent for Windows hosts</title><link>https://evan.wtf/2010/11/05/using-zabbix-for-snmp-monitoring-disk-usage-percent-for-windows-hosts/</link><pubDate>Fri, 05 Nov 2010 09:44:22 +0000</pubDate><guid>https://evan.wtf/2010/11/05/using-zabbix-for-snmp-monitoring-disk-usage-percent-for-windows-hosts/</guid><description>&lt;p&gt;A few years ago we moved from Nagios to Zabbix for our server monitoring needs. I wasn&amp;rsquo;t a big fan of Nagios, finding it a pain to manage with its myriad configuration files. It&amp;rsquo;s probably gotten better since I last toyed with it but since we moved to Zabbix I haven&amp;rsquo;t had much reason to look at Nagios again.&lt;/p&gt;&#10;&lt;p&gt;I also try to use SNMP monitoring for everything. SNMP is widely supported - all sorts of hardware has SNMP support, and with the net-snmp package you can pretty easily create your own SNMP-monitorable stuff on Linux. Since almost all of our stuff runs on Linux this has worked out pretty well, but our Exchange server is &lt;em&gt;probably&lt;/em&gt; going to be running on Windows for the foreseeable future. Windows has SNMP support, it&amp;rsquo;s just not on by default. However, even when it&amp;rsquo;s enabled it doesn&amp;rsquo;t have the simple &amp;ldquo;dskPercent&amp;rdquo; monitoring I&amp;rsquo;ve come to know and love with net-snmp on Linux, which simply tells you how full a given disk is as a percent. This makes it easy to set alerts when a disk reaches 80% full.&lt;/p&gt;</description></item><item><title>Exchange 2010 Post-Upgrade weirdness: can't edit Mail Non-Universal Group or Security Group</title><link>https://evan.wtf/2010/10/21/exchange-2010-post-upgrade-weirdness-cant-edit-mail-non-universal-group-or-security-group-2/</link><pubDate>Thu, 21 Oct 2010 22:29:38 +0000</pubDate><guid>https://evan.wtf/2010/10/21/exchange-2010-post-upgrade-weirdness-cant-edit-mail-non-universal-group-or-security-group-2/</guid><description>&lt;p&gt;Now that everyone&amp;rsquo;s been moved to Exchange 2010 we&amp;rsquo;ve started using the 2010 Exchange Managment Console/Shell exclusively which has revealed some weirdness. First, we created a new group in AD using an old script (which used LDAP) and created a Mail-enabled Global Security group. We put people in the group, and everything seemed to be working fine until it was discovered that users in the group couldn&amp;rsquo;t see the group in the Global Address List. Users not in the group had no problem seeing the group. Additionally, users in the group couldn&amp;rsquo;t see &lt;em&gt;users&lt;/em&gt; added directly in 2010. This only appeared to affect the GAL; the users were able to send/receive email fine with the full SMTP addresses.&lt;/p&gt;</description></item><item><title>Exchange 2010 Post-Upgrade weirdness: can't edit Mail Non-Universal Group or Security Group</title><link>https://evan.wtf/2010/10/21/exchange-2010-post-upgrade-weirdness-cant-edit-mail-non-universal-group-or-security-group/</link><pubDate>Thu, 21 Oct 2010 22:29:38 +0000</pubDate><guid>https://evan.wtf/2010/10/21/exchange-2010-post-upgrade-weirdness-cant-edit-mail-non-universal-group-or-security-group/</guid><description>&lt;p&gt;Now that everyone&amp;rsquo;s been moved to Exchange 2010 we&amp;rsquo;ve started using the 2010 Exchange Managment Console/Shell exclusively which has revealed some weirdness. First, we created a new group in AD using an old script (which used LDAP) and created a Mail-enabled Global Security group. We put people in the group, and everything seemed to be working fine until it was discovered that users in the group couldn&amp;rsquo;t see the group in the Global Address List. Users not in the group had no problem seeing the group. Additionally, users in the group couldn&amp;rsquo;t see &lt;em&gt;users&lt;/em&gt; added directly in 2010. This only appeared to affect the GAL; the users were able to send/receive email fine with the full SMTP addresses.&lt;/p&gt;</description></item><item><title>Finally, all users moved from Exchange 2003 to Exchange 2010.</title><link>https://evan.wtf/2010/10/12/finally-all-users-moved-from-exchange-2003-to-exchange-2010/</link><pubDate>Tue, 12 Oct 2010 15:29:44 +0000</pubDate><guid>https://evan.wtf/2010/10/12/finally-all-users-moved-from-exchange-2003-to-exchange-2010/</guid><description>&lt;p&gt;I&amp;rsquo;ve been working on migrating our Exchange environment from 2003 to 2010 for several months. My &lt;a href="https://evan.wtf/2010/04/14/moving-an-exchange-2003-server-to-another-location-with-minimal-risk-and-disruption/"&gt;first post about this&lt;/a&gt; is from April 14th, when I was just trying to virtualize our existing Exchange 2003 system. Once that was complete, I started playing around with Exchange 2010 around June or July, and had most of the users moved over to 2010 by the end of August. The last holdouts were Blackberry users. I couldn&amp;rsquo;t move their mailboxes because our BES was hosted on our original Exchange 2003 server.&lt;/p&gt;</description></item><item><title>One reason I hate iTunes.</title><link>https://evan.wtf/2010/09/16/one-reason-i-hate-itunes/</link><pubDate>Thu, 16 Sep 2010 08:04:43 +0000</pubDate><guid>https://evan.wtf/2010/09/16/one-reason-i-hate-itunes/</guid><description>&lt;p&gt;I&amp;rsquo;ve always hated iTunes. It&amp;rsquo;s a huge pile of bloatware and it&amp;rsquo;s slow as poo. It&amp;rsquo;s like 100 mb or more for an mp3 player. I remember winamp playing mp3s when it was a 500k download. Anyway.&lt;/p&gt;&#10;&lt;p&gt;I keep all my music on a Linux machine running samba. This way it&amp;rsquo;s available to every machine in the house. When I had Winamp on all my machines this was wonderful. But now that I&amp;rsquo;m forced into iTunes (thanks to having an iPhone), it turns out to be a major pain. In iTunes I unchecked the box for &amp;ldquo;let iTunes keep my libary organized&amp;rdquo; to prevent it from copying the entire library to each computer&amp;rsquo;s local disk. Initially adding my library of ~4000 tracks to iTunes takes over an hour (100 mbit wire) - it would take about 5 minutes in Winamp, even reading the ID3 tags for each track as it was added (rather than lazily as the song was played).&lt;/p&gt;</description></item><item><title>Converting Exchange 2003 conference rooms to Exchange 2010</title><link>https://evan.wtf/2010/09/01/converting-exchange-2003-conference-rooms-to-exchange-2010/</link><pubDate>Wed, 01 Sep 2010 13:25:27 +0000</pubDate><guid>https://evan.wtf/2010/09/01/converting-exchange-2003-conference-rooms-to-exchange-2010/</guid><description>&lt;p&gt;I&amp;rsquo;m wrapping up moving mailboxes to Exchange 2010. The last ones to be moved (except for BlackBerry users&amp;hellip; thanks BES) are the conference rooms. So the first step was to move them using the Local Move tool, which was pretty simple. But I don&amp;rsquo;t want them in 2010 as user mailboxes if they can be designated as &amp;ldquo;rooms,&amp;rdquo; which they can. So here&amp;rsquo;s how I&amp;rsquo;m doing it:&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Identify the mailboxes to be moved&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>ldapsearch example on Active Directory</title><link>https://evan.wtf/2010/08/26/ldapsearch-on-active-directory-2/</link><pubDate>Thu, 26 Aug 2010 10:40:18 +0000</pubDate><guid>https://evan.wtf/2010/08/26/ldapsearch-on-active-directory-2/</guid><description>&lt;p&gt;Just putting this here for safekeeping since I couldn&amp;rsquo;t remember the exact syntax.&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;[evan@ehoffman 10:35:50 ~]$ ldapsearch -x -LLL -D &amp;#34;ldapuser@example.com&amp;#34; -w password -b &amp;#34;OU=Users,DC=example,DC=com&amp;#34; -s sub -H ldaps://activedirectory.example.com &amp;#34;(sn=hoffman)&amp;#34; cn mail displayName samaccountname&#10;dn: CN=Evan Hoffman,OU=Tech,OU=Users,DC=example,DC=com&#10;cn: Evan Hoffman&#10;displayName: Evan D. Hoffman&#10;sAMAccountName: ehoffman&#10;mail: Evan.Hoffman@example.com&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Explanation: Connect to &lt;strong&gt;activedirectory.example.com&lt;/strong&gt; using ldaps (SSL) with simple authentication, binding as &lt;strong&gt;&lt;a href="mailto:ldapuser@example.com"&gt;ldapuser@example.com&lt;/a&gt;&lt;/strong&gt; with password &lt;strong&gt;password&lt;/strong&gt;; search for &lt;strong&gt;(sn=hoffman)&lt;/strong&gt; within the &lt;strong&gt;OU=Users,DC=example,DC=com&lt;/strong&gt; search base (branch), and search the &lt;strong&gt;sub&lt;/strong&gt;tree. Return the &lt;strong&gt;cn&lt;/strong&gt;, &lt;strong&gt;displayName&lt;/strong&gt;, and &lt;strong&gt;samaccountname&lt;/strong&gt; fields.&lt;/p&gt;</description></item><item><title>ldapsearch on Active Directory</title><link>https://evan.wtf/2010/08/26/ldapsearch-on-active-directory/</link><pubDate>Thu, 26 Aug 2010 10:40:18 +0000</pubDate><guid>https://evan.wtf/2010/08/26/ldapsearch-on-active-directory/</guid><description>&lt;p&gt;Just putting this here for safekeeping since I couldn&amp;rsquo;t remember the exact syntax.&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;[evan@ehoffman 10:35:50 ~]$ ldapsearch -x -LLL -D &amp;#34;ldapuser@example.com&amp;#34; -w password -b &amp;#34;OU=Users,DC=example,DC=com&amp;#34; -s sub -H ldaps://activedirectory.example.com &amp;#34;(sn=hoffman)&amp;#34; cn mail displayName samaccountname&#10;dn: CN=Evan Hoffman,OU=Tech,OU=Users,DC=example,DC=com&#10;cn: Evan Hoffman&#10;displayName: Evan D. Hoffman&#10;sAMAccountName: ehoffman&#10;mail: Evan.Hoffman@example.com&#10;&lt;/code&gt;&lt;/pre&gt;</description></item><item><title>Exchange 2010 - Out-of-office response (OOF) won't turn off?</title><link>https://evan.wtf/2010/08/11/exchange-2010-out-of-office-response-oof-wont-turn-off-2/</link><pubDate>Wed, 11 Aug 2010 12:44:34 +0000</pubDate><guid>https://evan.wtf/2010/08/11/exchange-2010-out-of-office-response-oof-wont-turn-off-2/</guid><description>&lt;p&gt;Two users reported the same problem this week: they turned on their out-of-office reply while they were out, then came back and turned it off. Except even after they turned it off, the autoreply was still being sent out. I had them log in to OWA and make sure it was off (maybe some weird bug with Outlook not registering the change in the server), which it was in both cases. I Googled hard and fast and couldn&amp;rsquo;t find anyone with this same problem.&lt;/p&gt;</description></item><item><title>Exchange 2010 - Out-of-office response (OOF) won't turn off?</title><link>https://evan.wtf/2010/08/11/exchange-2010-out-of-office-response-oof-wont-turn-off/</link><pubDate>Wed, 11 Aug 2010 12:44:34 +0000</pubDate><guid>https://evan.wtf/2010/08/11/exchange-2010-out-of-office-response-oof-wont-turn-off/</guid><description>&lt;p&gt;Two users reported the same problem this week: they turned on their out-of-office reply while they were out, then came back and turned it off. Except even after they turned it off, the autoreply was still being sent out. I had them log in to OWA and make sure it was off (maybe some weird bug with Outlook not registering the change in the server), which it was in both cases. I Googled hard and fast and couldn&amp;rsquo;t find anyone with this same problem.&lt;/p&gt;</description></item><item><title>Changing Active Directory Password in Browser through OWA 2010</title><link>https://evan.wtf/2010/08/05/changing-active-directory-password-in-browser-through-owa-2010/</link><pubDate>Thu, 05 Aug 2010 11:29:41 +0000</pubDate><guid>https://evan.wtf/2010/08/05/changing-active-directory-password-in-browser-through-owa-2010/</guid><description>&lt;p&gt;A few months ago I was on a quest to figure out how to change my Active Directory password via a browser (for Linux/Mac users). I &lt;a href="https://evan.wtf/2010/01/13/victory-change-active-directory-password-via-ldap-through-browser/"&gt;finally figured it out&lt;/a&gt;, but since I&amp;rsquo;ve been working on this Exchange 2010 migration I noticed one of the features of OWA (Outlook Web App) in Exchange 2010 is that you can change the AD password right in the browser from within the app:&lt;/p&gt;&#10;&lt;p&gt;&lt;a href="https://evan.wtf/wp-content/uploads/2010/08/change-password-owa1.png"&gt;&lt;img src="https://evan.wtf/wp-content/uploads/2010/08/change-password-owa1.png" alt="" title="Change Password OWA"&gt;&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Outlook 2007 &amp; Exchange 2010 Autodiscover SSL certificate error annoyance</title><link>https://evan.wtf/2010/07/27/outlook-2007-exchange-2010-autodiscover-ssl-certificate-error-annoyance/</link><pubDate>Tue, 27 Jul 2010 11:51:54 +0000</pubDate><guid>https://evan.wtf/2010/07/27/outlook-2007-exchange-2010-autodiscover-ssl-certificate-error-annoyance/</guid><description>&lt;p&gt;One of the more annoying side effects of migrating my mailbox to Exchange 2010 has been the nagging of Outlook 2007&amp;rsquo;s Autodiscovery feature. Now, every time I start Outlook I get hit with a certificate error for autodiscover.domain.com. Now, autodiscover.domain.com is a CNAME to mail.domain.com, which is the OWA URL for the CAS. The SSL certificate is valid - but it&amp;rsquo;s valid for mail.domain.com. I could buy &lt;a href="http://affiliate.godaddy.com/redirect/57C9CDCFC2D9286731DFC80559FF75B02AA47A2EADDA2D5CC2407E21C4FBC792" title="Go Daddy $12.99 SSL Sale!"&gt;a SSL certificate from GoDaddy for $12.99&lt;/a&gt; (an insanely great price, btw) for &amp;ldquo;autodiscover&amp;rdquo; but that would also require using another IP address on the CAS (since you can can only bind one SSL certificate to an IP:port pair), and that seems like a waste of an IP address.&lt;/p&gt;</description></item><item><title>The Joy of Migrating from Exchange 2003 to 2010</title><link>https://evan.wtf/2010/07/20/migrating-from-exchange-2003-to-2010-and-other-fun-bits/</link><pubDate>Tue, 20 Jul 2010 13:57:13 +0000</pubDate><guid>https://evan.wtf/2010/07/20/migrating-from-exchange-2003-to-2010-and-other-fun-bits/</guid><description>&lt;p&gt;I&amp;rsquo;ve been working on migrating from Exchange 2003 to Exchange 2010 for several weeks. Actually, at this point it feels like several months. Now that I think about it, I guess that&amp;rsquo;s because it&amp;rsquo;s actually &lt;em&gt;been&lt;/em&gt; several months.&lt;/p&gt;&#10;&lt;p&gt;Back in January or February, I got fed up with the Exchange setup I inherited: our Exchange 2003 server was running on a server in the basement of our office, on non-UPS power, with a power company that likes to pull shenanigans (like 3-4 hour outages every few months). In addition, the physical machine itself has some weird bug where it would hang at the POST screen complaining about some USB device, even though there are no USB devices plugged in, and USB is disabled in the BIOS. Meanwhile, in the datacenter, I had recently finished migrating most of our ancient physical servers to virtual machines on beautiful new hardware. It didn&amp;rsquo;t take long to see the solution that seemed to be obvious: move Exchange to the datacenter, in a VM.&lt;/p&gt;</description></item><item><title>vCenter: Error parsing the server "(server IP)" "clients.xml" file</title><link>https://evan.wtf/2010/06/23/vcenter-error-parsing-the-server-clients-xml-file-2/</link><pubDate>Wed, 23 Jun 2010 12:18:59 +0000</pubDate><guid>https://evan.wtf/2010/06/23/vcenter-error-parsing-the-server-clients-xml-file-2/</guid><description>&lt;p&gt;I got the above error today after running Windows Update on my XP VM a few days ago. A quick search showed that the error is caused by a Microsoft update to the .NET framework. To resolve it, remove update KB980773 (Add/Remove programs, make sure &amp;ldquo;Show Updates&amp;rdquo; is checked; KB980773 is under &amp;ldquo;Microsoft .NET Framework 2.0 Service Pack 2&amp;rdquo;). I removed it and was able to log in without problems.&lt;/p&gt;</description></item><item><title>vCenter: Error parsing the server "(server IP)" "clients.xml" file</title><link>https://evan.wtf/2010/06/23/vcenter-error-parsing-the-server-clients-xml-file/</link><pubDate>Wed, 23 Jun 2010 12:18:59 +0000</pubDate><guid>https://evan.wtf/2010/06/23/vcenter-error-parsing-the-server-clients-xml-file/</guid><description>&lt;p&gt;I got the above error today after running Windows Update on my XP VM a few days ago. A quick search showed that the error is caused by a Microsoft update to the .NET framework. To resolve it, remove update KB980773 (Add/Remove programs, make sure &amp;ldquo;Show Updates&amp;rdquo; is checked; KB980773 is under &amp;ldquo;Microsoft .NET Framework 2.0 Service Pack 2&amp;rdquo;). I removed it and was able to log in without problems.&lt;/p&gt;</description></item><item><title>Hygiene Management?</title><link>https://evan.wtf/2010/06/03/hygiene-management/</link><pubDate>Thu, 03 Jun 2010 15:55:39 +0000</pubDate><guid>https://evan.wtf/2010/06/03/hygiene-management/</guid><description>&lt;p&gt;I&amp;rsquo;m installing Exchange 2010 and in the docs it shows a bunch of groups that get created in the AD Schema during the domain prep part. After running prep, I looked to see if the groups were there, and sure enough they were (yay). What caught my eye was that one of the groups is called &lt;strong&gt;Hygiene Management&lt;/strong&gt;. I thought maybe this was an Easter Egg from MS, but &lt;a href="http://technet.microsoft.com/en-us/library/dd776125.aspx"&gt;apparently&lt;/a&gt; it&amp;rsquo;s just the name of the group of people who can manage the Exchange antivirus/antispam features. Still funny though.&lt;/p&gt;</description></item><item><title>Moving an Exchange 2003 server to another location with minimal risk and disruption?</title><link>https://evan.wtf/2010/04/14/moving-an-exchange-2003-server-to-another-location-with-minimal-risk-and-disruption/</link><pubDate>Wed, 14 Apr 2010 01:38:51 +0000</pubDate><guid>https://evan.wtf/2010/04/14/moving-an-exchange-2003-server-to-another-location-with-minimal-risk-and-disruption/</guid><description>&lt;p&gt;So our Exchange server is located in our office building. This made sense at the time because that&amp;rsquo;s where the users are. Over time though, this has proved problematic for a few reasons. Primarily, our office is certainly not a datacenter and doesn&amp;rsquo;t offer the amenities of one - clean, reliable power, and redundant cooling. In an average year we lose power probably 10-15 times, often for an hour or more. The rest of our production environment is hosted in a top-tier datacenter, so after a while I started to wonder why our Exchange server wasn&amp;rsquo;t there, and making plans to move it there. Oh, and did I mention I&amp;rsquo;m not an Exchange admin in any sense of the term? I just inherited the Exchange server about 2 months ago.&lt;/p&gt;</description></item><item><title>Victory! Change Active Directory Password via LDAP through browser</title><link>https://evan.wtf/2010/01/13/victory-change-active-directory-password-via-ldap-through-browser/</link><pubDate>Wed, 13 Jan 2010 13:51:43 +0000</pubDate><guid>https://evan.wtf/2010/01/13/victory-change-active-directory-password-via-ldap-through-browser/</guid><description>&lt;p&gt;I had to give up on PHP and go to Perl, but it turned out not to be so bad. Users can now change their Active Directory passwords via a self-service web page that doesn&amp;rsquo;t require admin credentials. The Perl code is below. Authentication to the script is done via .htaccess LDAP authentication, so the REMOTE_USER env variable is assumed to contain the user&amp;rsquo;s username (sAMAccountName) by the time this script is called. There is a simple check for $ENV{HTTPS} to ensure the script is called via SSL, and AD requires password changes to be done via ldaps, so the whole thing &lt;em&gt;should&lt;/em&gt; be encrypted end to end.&lt;/p&gt;</description></item></channel></rss>