#LL @ME

AppSense Upgrade from 8.0 to 8.1

Recently I have to upgrade AppSense from version 8.0 to 8.1

Our 8.1 environment was messy, the Outlook profile (e.g. registry entries) was stored in both Managed application registry and Desktop Settings registry. This caused a lot of problems, like secondary mailbox not being retained, unable to use "Send To Email" from any other application, etc.

To fix this, I had to do the following:

After the upgrade was done to 8.1, before the users start using Outlook, I exported all the users from EM personalisation DB, using the SQL query bellow:


SELECT [Name]

FROM [AppSensePersonalizationDB].[dbo].[User]

WHERE [DomainName] = 'DOMAIN'


Please note, my DB name is AppSensePersonalizationDB, yours probably has different name

Then save the result as a txt file, e.g. users.txt, which has entry like the following:


user1

user2

user3


You have to install AppSense EM Manager Tools to be able to use the EMPRegUtil. Once installed, create a batch file:

@echo off

SET EMPRegUtilConnectionString=Data Source=EMDB;Initial Catalog=AppSensePersonalizationDB;Integrated Security=SSPI


for /f "tokens=*" %%i IN (users.txt) DO call:doit %%i

:doit

if "%~1" == "" goto end

@echo %~1

@echo exporting MS Office 2010 Outlook profiles...

EMPRegUtil EXPORT DOMAIN\%~1 "Production" "MS Office 2010" "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook" C:\temp\%~1.reg

@echo deleting MS Office 2010 Outlook profiles...

EMPRegUtil DELETE DOMAIN\%~1 "Production" "MS Office 2010" "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem"

@echo deleting Session Data Outlook profiles...

EMPRegUtil DELETE DOMAIN\%~1 "Production" "Session Data" "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem"

@echo importing to Session Data Outlook profiles...

EMPRegUtil IMPORT DOMAIN\%~1 "Production" "Session Data" C:\temp\%~1.reg

:end

Please note:

my database server name is: EMDB

Run the batch script, it will export the Outlook profile from Managed application, delete the registry from managed application, delete the registry from session data and import the registry back to session data



Exchange 2007 Restore

Had to restore someone else mailbox today - using NetBackup 7.

Steps involved:
  • Create the Recovery Storage Group
  • Restore the Storage Group that has the database of the mailbox to be restored to the Recovery Storage Group
  • Mount the database in that Recovery Storage Group
  • Create an empty mailbox (AD User + Mailbox)
  • Restore the mailbox to the new mailbox

Restore-Mailbox -RSGMailbox 'Doe, John' -RSGDatabase 'Recovery Storage Group\Mailbox Database 01' -id 'new mailbox' -TargetFolder 'myFolder'


Passed CCA for XenDesktop 5

Passed CCA for XenDesktop 5 - Next will be CCA for XenServer

Active Directory DNS Waiting for Initial Replication

When you boot the 1st domain controller within the environment which has more than 1 DC, by default the DC is waiting for initial inbound replication from the other DC. But because this is the first DC you boot, this is going to take a while

To avoid this, add the following key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
Value name: Repl Perform Initial Synchronizations
Value type: REG_DWORD
Value data: 0

Add Reboot!
Do not use this method in the producation environment

MOSS 2007 Shared Service Provider - ACCESS DENIED

I have just done a clean MOSS 2007 installation and tried to open the Shared Service Provider Link and got a BIG ACCESS DENIED ERROR!!

Here is the fix

http://support.microsoft.com/kb/896861


PowerShell AD Group Membership Listing

To get the member of a particular group in Active Directory:

Get-ADGroup -filter 'name -eq "Group Name" | Get-ADGroupMember -Recursive | fl name

Replace the "Group Name" with the group name from which you want to get the member of

PS3 Media Server + Samsung TV

Just got my Samsung TV, connected to the network WiFi.
Got the PS3 Media Server installed on my OSX, with a little bit tweak:

PS3 Media Server\renderers\Samsung.conf:

MimeTypesChanges=audio/wav=audio/L16|video/x-matroska=video/avi
StreamExtensions=mkv,mp3,mp4,avi

The movies are streamed awesomely to the TV!

Citrix XenApp Management Console Bug

Citrix XenApp 5 or 4.5FP2 has got a bug - when you launch CMC and run the discovery, it does not find the XenApp farm, only the Web Interface module.

To fix it, run the following:

cd %CommonProgramFiles%\Citrix\*Present*
%windir%\microsoft.net\framework\v2.0.50727\regasm /codebase pse.core.dll
cd %CommonProgramFiles%\Citrix\*Framew*
CmiLaunch.exe

Run the discovery again and it should find it now

Upgrade IOS on 877W ISR Wireless Module

It is a bit tricky to update the AP module inside the Cisco ISR 877 Series.

1st, assign an IP address to the VLAN of the router

interface vlan 1
ip address x.x.x.x y.y.y.y
no shut

2nd, assign the wlan-ap 0 interface with IP unnumbered

interface wlan-ap 0
ip unnumbered vlan 1

3nd, access the wlan-ap 0 module console

service-module wlan-ap 0 session

4th, assign an IP address to BVI0/BVI1 interface

interface BVI0
ip address z.z.z.z y.y.y.y
no shut

5th, get the IOS image from the tftp

archive download-sw tftp://x.x.x.x/ios.version.tar

6th, write mem and reload

wr mem
reload

HP Blade E-Fuse

To reset one of the blades on the HP enclosure, telnet to the OA, then issue the following command:

reset server [bay no]

[bay no] is the bay number of the blade that you want to reset

Remote Assistant with Mandatory Profile

By default, you cannot launch Remote Assistant to help a user who is running on Mandatory Profile. For example, running XenDesktop + AppSense + Mandatory Profile is a good mix of technologies - however when a user having problem, you won't be able to start Remote Assistant session to their XenDesktop session.

To fix this, use the following VBScript to modify the registry:

Option Explicit
Const HKLM = &H80000002

Dim objReg, strRegKey, strRegValue, strRegData, objAdInfo, objUser, username, objWMIService, objAccount, strComputer, wmipath, oShell, usersid, domain
strComputer = "."

Set oShell = CreateObject( "WScript.Shell" )

username = oShell.ExpandEnvironmentStrings("%UserName%")
domain = oShell.ExpandEnvironmentStrings("%UserDomain%")

Set objWMIService = GetObject("winmgmts:\\" & strComputer & "\root\cimv2")
wmipath = "Win32_UserAccount.Name='" & username & "',Domain='" & domain & "'"

Set objAccount = objWMIService.Get(wmipath)
usersid = objAccount.SID

Set objReg = GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & ".\root\default:StdRegProv")
strRegKey = "Software\Microsoft\Windows NT\CurrentVersion\ProfileList\" & usersid & "\"

strRegValue = "State"
strRegData = "0"

objReg.SetStringValue HKLM, strRegKey, strRegValue, strRegData

WScript.Quit 0 'Return success

They way we do it, we attach this VBScript everytime the msra.exe process starts - this makes sure the "State" is set to 0 before the msra.exe process started

Certified ITILv3

Officially ITILv3 certified... what's next??

Netscaler and Citrix Web Interface Setup

This guide assumes you have setup a basic Netscaler (e.g. DNS, NTP, IP) and Citrix Web Interface

Netscaler

Enable Access Gateway features
Access Gateway - Policies - Authentication - Servers (tab)
Add the domain controller

1

Access Gateway - Policies - Authentication - Policies (tab)
Add a new policy

2

Select the Server created earlier and add ns_true as expression

Access Gateway - Policies - Session - Profiles (tab)
Add a new profile

3

4

5

6

Change the Web Interface Address to your local web interface server path
Change the Single Sign-On Domain to your Active Directory domain

Access Gateway - Policies - Session - Policies (tab)
Add a new Policy

7

Add the ns_true expression
Change the Request Profile to the profile created earlier

Access Gateway - Virtual Servers
Add a new virtual server

8

Give an IP address
Select the SSL certificate (click here how to add SSL certificate to NetScaler)

9

10

11

Insert the policy created earlier

12

13

14

Add the URL to the STA

15

Citrix Web Interface

Create a new XenApp Web Sites
Authentication Point: At Access Gateway
Available Method: Explicit
Authentication Method:

16

Add the URL (https) that is publicly available for the user

Secure Access: Gateway Direct

17

Enter the publicly available URL to the address

18

19

Add the STA URL exactly the same with the STA servers you added to the Netscaler

Office 2010 Activation with KMS

To activate Office Suite and Standalone application 2010 using KMS, you can do the following:

Install Microsoft Office 2010 KMS Host License Pack to your KMS Host:
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=97b7b710-6831-4ce5-9ff5-fdc21fe8d965&displaylang=en

It will ask you to enter your Office 2010 KMS Volume License Key

Once entered you are ready to go - note, you need as least 5 clients try to activate Office 2010 before those clients are able to activate via KMS

From the client, you can either wait for Office 2010 to activate itself via KMS or you can force it using:

cscript ospp.vbs /act

note: ospp.vbs is located in your office14 installation folder

If you have already activated your Office using the MAK key, you can change that activation to KMS by entering KMS Client key:

cscript ospp.vbs /inpkey:

The KMS Client key can be found from:

http://technet.microsoft.com/en-us/library/ee624355.aspx

Once you have entered the KMS Client Key, you can either wait or force the activation using ospp.vbs /act

App-V Register and Refresh Server

App-V client needs to be configured to use a specific App-V Server to be able to see all the published application of the user logged in. To do this, you can either specify the server during the App-V client installation or using command line.

To use command line, I used the following method:

Enable user to manage server
Create a GPP for a computer that modifies the following registry entry:

HKLM\SOFTWARE\Microsoft\SoftGrid\4.5\Client\Permissions\ManageServers
set the value to 1

Add the server
Create a GPP for a user that executes the following command:

"%ProgramFiles%\Microsoft Application Virtualization Client\sftmime.com" ADD SERVER: /HOST: /TYPE:rstp

Refresh Application
Create a GPP for a user that executes the following command:

"%ProgramFiles%\Microsoft Application Virtualization Client\sftmime.com" REFRESH SERVER:

Import SSL Certificate to Citrix Netscaler

I use the following method to import SSL Certificate to Citrix Netscaler:
  • Find any Windows 2003 with IIS installed. Generate a CSR from this machine
  • Submit this CSR to your CA to get the private key of it
  • Import this private key to your IIS again
  • Export the certificate both public and private keys as a pfx file
  • Import this .pfx file to the Netscaler, it will generate a new file
  • Open this new file, it should have 2 sections, public and private sections
  • Create 2 new files, one for the public and one for the private section
  • Upload these 2 new files to the Netscaler (you can delete the .pfx and the generated file from Netscaler if you want to)
  • From Netscaler, add a new SSL certificate
  • Give a name to the new Certificate
  • Select the public certificate for the Certificate File Name
  • Select the private certificate for the Private File Name
  • You can use the SSL certificate now with CAG

Linux History Bash

To check the login history:
# last

To clear out the login history:
# > /var/log/wtmp

To check the last command run:
# history

To clear out the command history:
# history -c

Netbackup 7 Disk Staging Cleanup

Using the Netbackup 7 Disk Staging feature is great! Clients are backed up to the staging area (e.g. Disks) and then the backup images from the staging disk are duplicated to the tapes.

Once the backup images are duplicated to the tapes, the images on disk are deleted from the clean-up process. The clean-up process chooses the oldest/expired images within the disk which have been duplicated and delete them.

For unknown reasons (based on my experience) the backup images were stuck on the staging disk. This causes a big problem because the running backup will have no enough space to store the backup image from the client, hence will fail.

To clean them do the following:
  • Make sure the backup images have been duplicated to the tapes (e.g. have second copy), t0 d0 this, from the Netbackup Administration Console, select Netbackup Management - Reports - Images on Media. Select the client and click Run Report. Check the backup that has Media Type: Disk and find the corresponding backup that has the Media Type: Removable Media with the Copy Number: 2. If you have this, this means you are safe to delete the backup images on Disk
  • From Netbackup Administration Console, select Catalog. Change the Action: Verify. Change Disk types: Basic Disk. Change the Date/Time range. Change Copies: Copy 2. Change Policy to the policy that backups the image and click Search Now.
  • Select the backup image on tapes that is the duplicate of the backup images on disk that you want to clean up. Right click on it and select Set Primary Copy. This will make the backup image on tape as the primary copy for restore
  • Change the Copies: Copy 1 and click Search Now
  • Select the backup image on disk that you want to clean up. Right click on it and select Expire
  • Open command prompt and run: bpimage -cleanup -allclients
That should delete the stuck backup images on disk that has just been expired.

Microsoft KMS Host

Recently I have to setup KMS server to activate Windows 2008/R2 and Windows 7 on our network.

Here are some necessary steps/tricks:


  • If a Windows was activated with KMS key, it will automatically become a KMS host
  • Depending on the KMS host OS and the KMS group key entered, different KMS clients can be activated through this KMS host
  • KMS group key C is the highest you can enter which basically can activate all Windows 2008/R2, Vista, and Windows 7 with any edition
  • To enter KMS key, run cmd prompt in escalated mode and do:
slmgr.vbs /ipk

  • To activate KMS host, do:
slmgr.vbs /ato

  • Once KMS host has been activated, check DNS entry for _VLMCS SRV record that points to this KMS host
  • To check how many KMS client has been trying to activate themselves through KMS host, do:
slmgr.vbs /dli

  • Now all the KMS clients (Volume License Key) should by default try to activate through KMS host
  • If you accidentally entered a KMS key to a KMS client, you can de-activate the KMS client by entering the "client type" key. Client type key depends on the Windows version, check on the following link
http://technet.microsoft.com/en-us/library/cc303280.aspx
  • Once you have the client type key, enter it and activate it:
slmgr.vbs /ipk
slmgr.vbs /ato

Script to do file cleanup

The following VBScript can be used to clean files of certain age:


-----------------------------

'* Specify the folder Name & Location here

Foldername="D:\DB Backup"

'* Specify how many days worth of Backup files you wanted to keep on the drive
Days = 7

'* Specify the Output fiel Name & location
LogFileName= "D:\CleanUp.txt"

Counter = 0

Set objFSO = CreateObject("Scripting.FileSystemObject")
Set LogFile=objFSO.OpenTextFile(LogFileName,2,true)

LogFile.WriteBlankLines 1
LogFile.Writeline " **************************************************"
LogFile.Writeline " * Delete Backup files Older than 7 Days *"
LogFile.Writeline " **************************************************"
LogFile.WriteBlankLines 1
LogFile.Writeline " Backup Folder Name .........: " & Foldername
LogFile.Writeline " Deleting files older then...: " & Days & " days"
LogFile.Writeline " Output File ................: " & LogFileName
LogFile.Writeline " Date Deleted ...............: " & Date
LogFile.WriteBlankLines 2

Counter = ViewSubFolders(Foldername, LogFile)

LogFile.WriteBlankLines 3
LogFile.Writeline "Total Old file(s) Deleted.....: " & Counter
LogFile.WriteBlankLines 3

LogFile.Close


Function checkFolder(Foldername, LogFile)
Set objFolder = objFSO.GetFolder(Foldername)
Counter = 0
For Each file in objFolder.Files
FileName=file.name
FileFullName=Foldername & "\" & filename
Set objFile = objFSO.GetFile(FileFullName)

LastModifiedDate=objFile.DateLastModified

LogFile.Writeline "Checking: " & FileName & "," & LastModifiedDate

IsOld=DateCheck(LastModifiedDate)

If IsOld="old" then
objFSO.DeleteFile(FileFullName)
Counter = Counter + 1
LogFile.Writeline "Deleting: " & FileName & "," & LastModifiedDate
end if

FileName=null
FileFullName= null
LastModifiedDate= null
IsOld= null
Set objFile = Nothing
Next

checkFolder = Counter
End Function

Function ViewSubFolders(strFolder, LogFile)
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objFolder = objFSO.GetFolder(strFolder)

Counter = 0

CounterX = checkFolder(strFolder, LogFile)
Counter = Counter + CounterX

For Each SubFolder in objFolder.SubFolders
CounterY = ViewSubFolders(SubFolder,LogFile)
Counter = Counter + CounterY
Next

Set objFolder = Nothing
Set objFSO = Nothing

ViewSubFolders = Counter
End Function

Function DateCheck(Lastmodified)
If DateDiff("d", lastmodified,date) > Days Then
DateCheck="old"
else
DateCheck="new"
end if
end Function



---------------------------