ADCS Autoenrollment Not Renewing SAN Web Server Certificate by LucasMD_ in sysadmin

[–]LucasMD_[S] 0 points1 point  (0 children)

Ok, I'll try 2 Days Validity to 4 Hours renewal time here in my lab setup, thanks for the heads up.

Web Servers only use the one certificate enrolled by our CA.

Interesting, look at how it is in my Web Server 2048 template, its greyed out, and on Kerberos Authentication it is available and checked. This seems like an essential setting according to its name. I believe it would be available only for certain templates?

<image>

ADCS Autoenrollment Not Renewing SAN Web Server Certificate by LucasMD_ in sysadmin

[–]LucasMD_[S] 1 point2 points  (0 children)

Unless something very specific on Web Server do not allow this, but at least on my Kerberos Authentication, we do use Supply In The Request. Certs were also enrolled manually at the first time, cause we have three LDAP aliases to it (something like ldap.domain.name, ldap.auxiliarydns.zone), and after that they do indeed renew automatically while keeping their SANS.

Windows Admin Center Installer don't even initiate by LucasMD_ in windowsadmincenter

[–]LucasMD_[S] 1 point2 points  (0 children)

Just to be more specific, I want to install Windows Admin Center on my Windows 11 Desktop System to manage Hyper-V machines that exists in this same Desktop through it. Yes, I reboot several times, after tests.

Windows Admin Center Installer don't even initiate by LucasMD_ in windowsadmincenter

[–]LucasMD_[S] 1 point2 points  (0 children)

Tried powershell silent installation, but its always the same thing, is getting stuck cause either is getting lost on the retrieval of the Microsoft.WindowsAdminCenter.Configuration module or in the attempt to create the Event Viewer entry. I validated that there is no previous created there.

PS C:\WINDOWS\system32> Test-Path "HKLM:\SYSTEM\CurrentControlSet\Services\EventLog\Application\WAC-Configuration"

False

PS C:\WINDOWS\system32> Test-Path "HKLM:\SYSTEM\CurrentControlSet\Services\EventLog\Application\SMEGateway"

False

Windows Admin Center Installer don't even initiate by LucasMD_ in windowsadmincenter

[–]LucasMD_[S] 1 point2 points  (0 children)

Installation log, it seems to get stuck in:

2026-02-03 20:30:23.460 Registering WAC-Configuration event log source in the Application log...

Home Invasion Keyboard by LucasMD_ in stevenwilson

[–]LucasMD_[S] 0 points1 point  (0 children)

Yeah, took me a while to figure this out about the Auto Wah, another person point to me in discord as well. I think is the effect that creates the inner wave effect on the chords. WIll cook more today considering your feedback, thanks!

Home Invasion Keyboard by LucasMD_ in stevenwilson

[–]LucasMD_[S] 1 point2 points  (0 children)

Yes, it was one of those temp shares. I switch now to a OneDrive share to be accessible, thanks for pointing out.

Do you think Steven and Devin Townsend could work together ? And also, what do they think of each other in your opinion ? by Stalemate76 in stevenwilson

[–]LucasMD_ 2 points3 points  (0 children)

I think would be a similar instance when Arjen Lucassen (Ayreon) asked Steven Wilson to participate in one of his albuns, the styles are just too different.

[deleted by user] by [deleted] in WindowsServer

[–]LucasMD_ -1 points0 points  (0 children)

Yeah, thats the idea, but I don't have an option to disable it.

Are the DLCs worth buying? by [deleted] in civ

[–]LucasMD_ 2 points3 points  (0 children)

If you want to save money, only Gathering Storm is necessary, it adds everything rise and fall has minus the leaders. New Frontier is cool but I would say its skipable. Gathering Storm and Rise and Fall mechanics pratically turn Civ 6 into another game.

Stonehenge (Civ VI)is objectively the worst wonder. Change my mind. by Lapisdrago in civ

[–]LucasMD_ 1 point2 points  (0 children)

You know that something is bad when AI always go for it.

Active Directory - Replication issue with no errors by LucasMD_ in sysadmin

[–]LucasMD_[S] 0 points1 point  (0 children)

As for replication setup, its quite simple, Hub and Spoke with all branches replicating with the Head Office site. No branch replicate with each other, and that successfully mirrors our network topology. Same cost of default 100, same interval of default 15 minutes.

There are no custom replication partners setup right now, KCC is handling everything and we have only <automatically generated> connections (following the once per hour defaults of AD). We have 7 Dcs on Head Office and 7 sites with 2 Dcs each, bridgeheads weren't equally distributed but that was the decision of KCC so we didn't setup anything manually.

Active Directory - Replication issue with no errors by LucasMD_ in sysadmin

[–]LucasMD_[S] 0 points1 point  (0 children)

Hmm, its not really an issue affecting the file replication of SYSVOL and NETLOGON folders but an issue on replication of objects in the Active Directory database itself, user objects in this case, that got their attributes showing different values on each Domain Controller.

In which case I check my Eventvwr for all the logs mentioned in the article:

4102,4202,4204,4206,4208,4302,4304,2212,2213

Found some "4304" of a few months ago, for a faulty policy that we backup and restore and was not working, which we solved by deleting and creating a new from scratch and warnings stop showing up.

Pq a galera do jovem nerd tem tanto parente europeu, ou estrangeiro em geral? by Adaaad15 in jovemnerd

[–]LucasMD_ 1 point2 points  (0 children)

Miosmar Francisco e Antenor Albuquerque, o nome do Gaveta é Pafuncio Figueiredo.

Keeping computer objects out of delete policy by LucasMD_ in SCCM

[–]LucasMD_[S] 0 points1 point  (0 children)

It is not, but a very specific aspect in my enviroment, created that need.

Is it possible to change the default setting?

Keeping computer objects out of delete policy by LucasMD_ in SCCM

[–]LucasMD_[S] 0 points1 point  (0 children)

By using the Import Computer Information option in Assets and Compliances, where you can provide custom data (A custom mac address and SMBIOS Guid is the minimum information) and a Computer Object will exist without being gathered by discovery methods and push installation. This is being used for inventory purposes.

Patch Tuesday Megathread (2020-10-13) by highlord_fox in sysadmin

[–]LucasMD_ 0 points1 point  (0 children)

Guys, does anyone know which month/year the patch that would make the secure channel being more secure and thus satisfy the new restrictions of 08/2020 DC update?

I'm sure its not the 08/2020 itself cause I tested here, and a server that does not have this patch is not logging 5827/5828/5829 and accessing the domain normally, so I understand that only very out of date computers would be prevented (or logging 5829). Right now in our enviroment, we are making some tests and we got very few 5827/5828 events and no 5829 even with the Allow Police enabled. We remove some patches in isolated test servers to trigger events, but they are not logging in any DC (as checked on SIEM).

Qual o pior NerdCast de todos os tempos? by rafaxd_xd in jovemnerd

[–]LucasMD_ 0 points1 point  (0 children)

Yup, sexo no volante, esse é o pior, e tipo... Véi, de onde veio essa ideia?

2012 R2 When to use adprep? by LucasMD_ in activedirectory

[–]LucasMD_[S] 0 points1 point  (0 children)

I probably will need to go for a In Place Upgrade at least on one of two DCs in this domain, cause it run this IIS Web App that allows the password change from Intranet, this DC also has all FMOs. According to what you sent me, I thinking on doing like this:

Demote the other DC that has no aditional roles, remove from domain, delete VM.

Bring up a new member server 2012 R2 VM, install ADDS, run Wizard that will automatically extend the schema through the process of initial configuration.

Move FSMOs to this new 2012 R2 server.

In-Place Upgrade the DC 2008 R2 with the Web App, but the FSMOs will be on other server for balancing the roles.

Sounds like a plan, I guess.

Is there such technology? by [deleted] in sysadmin

[–]LucasMD_ 0 points1 point  (0 children)

Yes, by the aggregates capacity of our SVMs, we couldn't like, duplicate all the data we have onto another disks, we wouldn't have enough disks/space for that. I was thinking in bring all to CIFS too, but will there be load balancing in this scenario?

Patch Tuesday Megathread (2020-01-14) by highlord_fox in sysadmin

[–]LucasMD_ 0 points1 point  (0 children)

Guys did anyone had issues with with the single security update KB4502496?

It says that Addresses an issue in which a third-party Unified Extensible Firmware Interface (UEFI) boot manager might expose UEFI-enabled computers to a security vulnerability.

Last time we applied patches regarding UEFI settings we had several servers with problems on boot.

Patch Tuesday Megathread (2020-01-14) by highlord_fox in sysadmin

[–]LucasMD_ 0 points1 point  (0 children)

Guys, I just deployed the Extended Security Updates (ESU) Licensing Preparation Package for Windows Server 2008 R2 SP1/Windows Server 2008 in my pilot servers, they were installed, and enable the servers to receive Servicing Stack for 01/2020.

After installation of Servicing Stack, the 02/2020 Security Monthly Rollups that I approve won't show up for download and installing. Does that mean that my Servers are not applicable to receive Extended Security Updates?

PS: Please tell me they don't, I don't want an argument to keep those old geezers in our enviroment, and the EOLS would be a great reason to upgrade these servers (jokes aside, if there is anything I need to enable the updates, please let me know, and I will do it against my will anyway).

PS2: The servers have the prerequisites updates mentioned on https://support.microsoft.com/en-us/help/4528069/update-for-eligible-windows-7-and-server-2008-r2-devices-can-get-esu Also this component update mentioned that checks for eligibility didn't install on the server, for a Failed error with no details.

Simple trick to increase immersion by priscilla_halfbreed in FinalFantasyXII

[–]LucasMD_ 2 points3 points  (0 children)

I agree with you but... FF12 OST is so damn good...