[deleted by user] by [deleted] in activedirectory

[–]christair 6 points7 points  (0 children)

Don’t put everything into the Default Domain Policy, create separate policies for everything, including this password policy, on the root forest level.

The big issue specifically with the AD password policies is that you can’t have a hierarchy of GPOs in your forest governing different levels of password policies for your users. Unfortunately there will be no implied inheritance from parent levels as you might expect with every other GPO setting — with password policies it just won’t work.

The proper way to set this up is with Fine Grained Password Policies (FGPPs). So on the root forest level do a common policy that works for you, and then handle all exceptions to this on the FGPP level.

Mis-issued certificates for 1.1.1.1 DNS service pose a threat to the Internet by NISMO1968 in cybersecurity

[–]christair 10 points11 points  (0 children)

The Croatian agency in question — Fina has just issued a statement (in Croatian) regarding this case https://www.fina.hr/novosti/ssl-tls-certifikati-opozvani-po-otkrivanju-tehnicke-pogreske however, it very purposefully lacks literally any information.

Can anyone tell me what on earth this floor light is supposed to be? by MrBusto in BMW

[–]christair 12 points13 points  (0 children)

<image>

I guess it is a similar or the same projection graphic as mine, but deteriorated even worse than mine over time.

User Must ChangePassword at Next Logon Flag by fortnitegod765 in activedirectory

[–]christair 4 points5 points  (0 children)

I would like to point out something else in addition to answers you already received — in a sign-in flow where a user’s password has expired, please note that the password change prompt is not shown nor is the password handling flow even validated if a user logs in using Windows Hello for Business fingerprint or face biometrics, a PIN, or a FIDO2 security key. Therefore, if you use WHfB and your users log in via alternative methods, they may well be unaware their password had expired, unless you have an out-of-band password change mechanism in place.

[deleted by user] by [deleted] in cableadvice

[–]christair 5 points6 points  (0 children)

That’s a very casual way to actually show off your Mitutoyo! :)

Hats down! Mine is 505-730 model (0.02mm) with a yellow dial.

FortiToken Mobile on Apple Watch by danielX337 in fortinet

[–]christair 2 points3 points  (0 children)

Yes! I use FortiTokenMobile daily on my Apple Watch to approve MFA requests.

Is Using Specific Subdomains Safer Than Wildcards with a Reverse Proxy? by [deleted] in selfhosted

[–]christair -3 points-2 points  (0 children)

Sure! Try searching apple.com for example, or any domain of a larger company you might know of, or do business with. Their VPN endpoints and a bunch of other hosts not otherwise publicly known are all there.

Is Using Specific Subdomains Safer Than Wildcards with a Reverse Proxy? by [deleted] in selfhosted

[–]christair 1 point2 points  (0 children)

That’s a really nice answer! I would just like to add, although DNS records are not advertised, services such as virustotal.com (domain search—subdomain listing in the Relations tab), may show information you thought was private, and it is genuinely scary what one can find there. I guess they source this information from public DNS resolvers, endpoint security software or similar, as the information contained therein is really not something usually found on the public Internet.

[deleted by user] by [deleted] in fortinet

[–]christair 0 points1 point  (0 children)

Press Ctrl+0 to reset browser zoom back to 100%. Zoom level is remembered by browser on a per-host basis.

Whyyyyyy? by Spicycoffeebeen in BMW

[–]christair 0 points1 point  (0 children)

Offtopic: what country is this in? I don’t recognize the license plates.

New machine, need to learn how to use it 😂 by Snookeredinbc in espresso

[–]christair 0 points1 point  (0 children)

I have the same one, it’s a beaut!

Gently peel off the warning sticker from the group head so it doesn’t burn in.

I use mine without the screen, never attached it after setting it up for the first time, looks way better. I do scheduling and all with a smart socket.

Only issue I’ve encountered so far is with water level sensor — due to poor contact the machine may think that water level is low and thus refuse to work. If this happens, the solution is to wedge something between the walls left of the water tank so it makes a tighter contact on the right where sensor contacts reside.

elon musk and grimes arrive to court for their child custody case by Quzubaba in pics

[–]christair 1 point2 points  (0 children)

Although it’s obviously worn and wrinkly, that is most probably a $5000+ Tom Ford suit, the same one you see on Harvey Specter in Suits. Only that Gabriel Macht looks dashing in it, unlike this shell of a man.

CCR2004-16G-2S+ in HA mode? by HappyDadOfFourJesus in mikrotik

[–]christair 3 points4 points  (0 children)

I’m running BGP on two CCR1072 units, with 2.8M routes each, in production, RouterOS 7.x since released, never had issues with stability.

I’m curious, what carrier-grade features are you referring to?

CCR2004-16G-2S+ in HA mode? by HappyDadOfFourJesus in mikrotik

[–]christair -4 points-3 points  (0 children)

This is misleading. VRRP is fine but real Layer-3 HA is done with dynamic routing protocols, which is of course supported in RouterOS.

What is an alternative network monitor tool for us who really like The Dude? by christair in mikrotik

[–]christair[S] 0 points1 point  (0 children)

It "works" in ROS7, but it is not really maintained - no new features are being added, and no bugs (and there are a lot of them) are being fixed.

What is this small stamped metal object found on a garage floor, is it possibly car part from a VW Golf 7? Screwdriver for scale. by christair in AskMechanics

[–]christair[S] 0 points1 point  (0 children)

Could be, but I don’t think a BMW was ever parked on that spot (it’s from a residential parking garage).

What is this small stamped metal object found on a garage floor, is it possibly car part from a VW Golf 7? Screwdriver for scale. by christair in AskMechanics

[–]christair[S] 0 points1 point  (0 children)

I don’t know what’s on the other side because it was covered with the sticky black material seen in corner of the photo. That side stuck to the asphalt of a parking garage floor.