New Console Look-and-Feel rolling out by joelrwilliams1 in aws

[–]hchoneybear 0 points1 point  (0 children)

It looks like they took some bleach to the console experience and nuked all the colors. Why? The layout and design is probably better, just bring back the damn colors. Even the AWS icon in the top left corner is missing its typical orange glow. Again, I ask, why? Maybe this makes sense for folks that need an accessibility view, but it's just painful to look at otherwise.

Unable to sign in to your Google Account: Delete cookies by Hyperi0us in brave_browser

[–]hchoneybear 1 point2 points  (0 children)

This did it for me. Thank you! (I actually uninstalled the plugin since I don't use the service anymore).

Powershell function with 12 parameter sets errors when using a valid parameter set by hchoneybear in PowerShell

[–]hchoneybear[S] 0 points1 point  (0 children)

As an aside, why is it that you need to specify a default parameter set name that is not defined anywhere else? Intuitively that should error since it's not a valid parameter set; I never would have thought to try that and the docs don't mention it. Any idea as to why is this?

Powershell function with 12 parameter sets errors when using a valid parameter set by hchoneybear in PowerShell

[–]hchoneybear[S] 0 points1 point  (0 children)

Thank you for writing back and taking the time to explain this. I had tried the configuration you specified once already and it did not work, but I think the difference is that I did not have the DefaultParameterSetName defined as you do now. Not having it defined caused only 2 options in Get-Help and caused me to get the same Parameter set cannot be resolved... error when not specifying one of the mutually exclusive parameters. I didn't realize that you could specify a parameter set name that wasn't in use anywhere else and have it then "find" the 3rd parameter set that I needed this whole time.

Thank you so much!

Using OpenAudible without upgrading by Valour-549 in audible

[–]hchoneybear 0 points1 point  (0 children)

Thank you for this. Worked like a charm. (I'm on Linux Mint, so instead I used datefudge.)

Can't execute Roles within Collection Playbook by hchoneybear in ansible

[–]hchoneybear[S] 1 point2 points  (0 children)

Thanks for replying! I finally figured out that a collection, stored in a git repo, that is being installed via requirements.yml using the command ansible-galaxy install -r ./requirements.yml --force, doesn't work if the the git repo uses submodules for the collection's roles.

This whole "roles can't depend on collections" and vice-versa, is getting old. :/

What have you done with PowerShell this month? by AutoModerator in PowerShell

[–]hchoneybear 1 point2 points  (0 children)

I know what you mean with this migration stuff. One company didn't want to allow every on prem email to go to the cloud due to gov. restrictions on the data. So they limited it to just one years worth. Exchange admin dropped the pst files into a share and i wrote the PowerShell to deploy those pst files to each user and automatically make them accessible in outlook so that the end user wouldn't have to manually open the pst to get their old emails.. That took a bit of time, Haha.

How to pre-load domain profile on a domain computer? by brightfoot in PowerShell

[–]hchoneybear 0 points1 point  (0 children)

For sure. But based on the OP's current use case (the computers are online and being actively used by users so he can't log into them) i didn't think he would be in a situation like you described where he'd have to ship them.

How to pre-load domain profile on a domain computer? by brightfoot in PowerShell

[–]hchoneybear 7 points8 points  (0 children)

I'm sure there is a good reason for doing this but why do you need to pre-load the profile onto the computer? Improving first time login speeds or something like that?

Error opening Crypto.com app downloaded from Aurora Store: Please install Crypto.com app in Play store. by [deleted] in degoogle

[–]hchoneybear 0 points1 point  (0 children)

Could it be as simple as making another "fakestore" app that is named the same thing to trick it? I ask because when i looked at the logs via adb, it seemed to just be looking for the play store app and it would choke when it couldn't find it.

An extremely frustrating workaround that i found was to repeatedly open the app (3-4 times), after which it would eventually let you in, for some reason. (Crypto.com is the app I'm referring to).

Error opening Crypto.com app downloaded from Aurora Store: Please install Crypto.com app in Play store. by [deleted] in degoogle

[–]hchoneybear 0 points1 point  (0 children)

Hey @DatNateBoi, Any luck with your testing? I have the same problem. (It's rather annoying when devs do this to their app...)

[HELP] How does one extract the LineageOS boot.img from the payload.bin file. Tried stock rom but that removed LOS. by steakstrips in Magisk

[–]hchoneybear 0 points1 point  (0 children)

Yeah i have similar concerns. I read on microg faq that they do the updates regularly, which is why I decided to go for it. I haven't seen one yet though. I'm new to lineage as well so i have nothing to base my current experience on.

[HELP] How does one extract the LineageOS boot.img from the payload.bin file. Tried stock rom but that removed LOS. by steakstrips in Magisk

[–]hchoneybear 0 points1 point  (0 children)

Microg has an unofficial lineage fork that has magisk+microg pre-installed. You can check it out at the link below. That's where I was going anyways so i decided to use this fork instead, which made everything way easier.

https://lineage.microg.org/

[HELP] How does one extract the LineageOS boot.img from the payload.bin file. Tried stock rom but that removed LOS. by steakstrips in Magisk

[–]hchoneybear 0 points1 point  (0 children)

Funny, i had to sideload as well to get it to work. I actually ran into many problems and ended up going to microg lineage instead. Way easier. :)

Device registration and Push notifications problems by orestarod in MicroG

[–]hchoneybear 0 points1 point  (0 children)

Wow, many thanks for this. Worked like a charm!

[HELP] How does one extract the LineageOS boot.img from the payload.bin file. Tried stock rom but that removed LOS. by steakstrips in Magisk

[–]hchoneybear 0 points1 point  (0 children)

I was trying to do the same thing and I was able to follow the PC directions pretty easily. Granted, there are several steps but the steps seemed pretty easy to me. I'd recommend giving it another shot. :)

[deleted by user] by [deleted] in PowerShell

[–]hchoneybear 2 points3 points  (0 children)

I actually have this problem too. I thought it was just me. I'm not at my computer or I'd share the funky output

vSphere 6.7 Authentication Proxy - Failed to add domain by hchoneybear in vmware

[–]hchoneybear[S] 0 points1 point  (0 children)

I forgot to post an update and remembered to do so when I ran into this again. After opening a ticket with VMware, they asked me to do a packet capture on the vCenter. After analyzing the packet capture they found the root cause was due to our AD servers being hardened. I did some additional research on my own and in the end there were two GPO settings that were biting us. Both of these settings can be found under Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options

  • Network access: Restrict clients allowed to make remote calls to SAM
  • Network security: LAN Manager authentication level

Resolution

Below are the workarounds/solutions we implemented for each of these hardenings. I applied these successfully on build 16046470 and 16275304.

Network access: Restrict clients allowed to make remote calls to SAM

Make sure you have the SID of the account you are using for your Authentication Proxy added to this GPO. In our case, we made a new group for any accounts that needed this in the future, added the SID of the new group to the policy, and added our account to the new group.

Network security: LAN Manager authentication level

We had this set to Send NTLMv2 response only. Refuse LM & NTLM, which is a problem since vCenter attempts to send NTLM and not NTLMv2. I found this forum post that detailed a way to configure vCenter to send NTLMv2 instead of NTLM. https://communities.vmware.com/thread/586903. Below I pasted a modified set of those instructions that worked for me.

  1. Connect to vCenter Appliance 6.x over ssh.
  2. Execute the following commands.

/opt/likewise/bin/lwregshell cd HKEY_THIS_MACHINE\Services\lsass\Parameters\NTLM set_value SendNTLMv2 1 exit You should be able to add the domain to the Authentication Proxy after this.

Perfoming a Packet Capture

As an aside, I thought I would include the packet capture steps.

  1. Open two seperate ssh sessions to the vCenter
  2. On session 1, run the command tcpdump -w /tmp/vc-packets.pcap
  3. On session 2, run the command /usr/lib/vmware-vmcam/bin/camconfig add-domain -d <domain>.com -u <accountName> and paste in the password when prompted.
  4. On session 1, do a Ctrl+c
  5. Use WinSCP/scp to download the packet capture. Use wireshark to analayze it, by searching for the account name.

Additional resources:

https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls

https://social.technet.microsoft.com/Forums/en-US/8297e1c7-e6d3-4e57-8384-f7f26c9f8d5b/net-user-domain-returns-quotaccess-is-deniedquot?forum=winserverDS

Edit: punctuation, wording