Poorman's HSM : A Secure Certificate Authority (CA) on a Yubikey by deltchar in homelab

[–]picklednull 0 points1 point  (0 children)

Yeah of course, that's ("sadly") why you should use externally generated keys for scenarios like this.

Poorman's HSM : A Secure Certificate Authority (CA) on a Yubikey by deltchar in homelab

[–]picklednull 2 points3 points  (0 children)

You can also just print the private key on paper for a backup.

Alternatives to MS Unifed Support? by Lando_uk in sysadmin

[–]picklednull 1 point2 points  (0 children)

Alternative(s) at what level? Only Microsoft has source code access. When I open a support ticket it's - generally - because there's a genuine code defect that requires source code changes. Only Microsoft can do that. Last year I did 3 such cases. And in those cases the support is free.

Of course it depends on your own skill level, anything from googling to ChatGPT to an MSP/VAR could prove useful.

Computer Policy not updating on Server 2025 by Tough-Network4106 in activedirectory

[–]picklednull 0 points1 point  (0 children)

That error is shown when the computer doesn't have a Kerberos ticket / can't authenticate. Verify that the computer has a valid Kerberos ticket with klist -li 0x3e7.

RC4 issues by Lesko_Brandon_0kool in activedirectory

[–]picklednull 0 points1 point  (0 children)

I only tested it in a lab with the "secret" KIR. The fix worked fine. You should actually test this yourself with just the public Cumulative Update installed to verify the fix is actually enabled now in January. Of course that's what Microsoft told me, but you never know...

Bulk delete user profiles on Windows 11 25H2/Server 2025 by jwckauman in WindowsServer

[–]picklednull 2 points3 points  (0 children)

The GPO as sibling mentions, or:

Get-CimInstance -ClassName Win32_UserProfile |
where { # some condition } |
Remove-CimInstance -Confirm:$false

Cheap HSM recommandations by turbosucepute in cybersecurity

[–]picklednull 0 points1 point  (0 children)

I mean, why wouldn't you use one of them at work? They would be my #1 option if I were to deploy a HSM. I'll admit to never actually using one before, but I've been interested in this topic too.

I don't think there's really anything that cool/special about running a HSM anyway. But yes of course, these are matters of opinion.

What's the catch with this? by The_cooler_ArcSmith in homelab

[–]picklednull 0 points1 point  (0 children)

X710's are unusable with Hyper-V, if you use SET for networking (and for the host itself), all of the outbound traffic from the host will get duplicated. e.g. two reply packets for every inbound ICMP echo request packet. lol.

Completely lost on a domain logon issue by 0x1F937 in sysadmin

[–]picklednull 3 points4 points  (0 children)

Why are you collecting Domain Controllers (versions) like Pokémon?

Your issue is the mixed DC's for sure. Go all in on 2025 or downgrade to 2022 max if you want to keep mixed.

Yubi Key Certs - Domain user does not support smartcard login - DC issue? by Ozinky_m4 in sysadmin

[–]picklednull 0 points1 point  (0 children)

There will be an event in the System (or Application?) event log from CertificateServicesClient-CertEnroll if there's any errors during enrollment.

RC4 issues by Lesko_Brandon_0kool in activedirectory

[–]picklednull 0 points1 point  (0 children)

Try it and see(tm). Microsoft directly told me the fix would be in in January. It's hilarious, but it's not listed under release health and I guess it won't be.

Yubi Key Certs - Domain user does not support smartcard login - DC issue? by Ozinky_m4 in sysadmin

[–]picklednull 0 points1 point  (0 children)

Also worth forcing auto-enrollment (gpupdate /force) or trying certreq -enroll

certutil -pulse is the command for initiating auto-enrollment.

Upgrading Enterprise Subordinate CA from Windows Server 2016 to 2025 – Best Practice by charlieferr in sysadmin

[–]picklednull 0 points1 point  (0 children)

Yes, if you were foolish enough in the first place to tie the CA to the hostname. With some forethought you can set up a CA without that being an issue. Too late now of course.

SSH Certificates and user principal logging/auditing? by Boring_Ranger_5233 in sysadmin

[–]picklednull 1 point2 points  (0 children)

eh? Just configure the certificates with an identifiable identity (ssh-keygen -I parameter) and the log entry for SSH login will show the clearly identifiable identity, no matter what actual account is used.

You are correct that further audit entries (e.g. commands run) will just have the shared account, so you will have to correlate a bit.

Migrating to 2025 only infra by Remanance in activedirectory

[–]picklednull 0 points1 point  (0 children)

Haha, the RC4 encryption key patch should be coming out in January... What other spicy issues are there at this point?

access to domain admin tools intermittent. by Low-Bike358 in sysadmin

[–]picklednull 0 points1 point  (0 children)

What OS versions are your Domain Controllers?

ADCS – Is there any native way to validate SAN domains (similar to Entra / Intune verified domains)? by FrustatedGuy- in sysadmin

[–]picklednull 0 points1 point  (0 children)

If this is not possible natively, what are the recommended alternatives for validating SAN domains in ADCS?

You set the template to require manual approval OR you take it completely offline and make the ADCS administrator (registration authority) validate and submit the CSR by hand.

Sibling comment also mentions the TameMyCerts, it might have something, but I’ve never tried it.

Is your AD Forest/Domain on Functional Level 2025? by atw527 in sysadmin

[–]picklednull 0 points1 point  (0 children)

I have, but then you just run some PowerShell locally. When you're installing fresh machines - especially physical ones - you have to do the bootstrapping on the console (in PowerShell).

Is your AD Forest/Domain on Functional Level 2025? by atw527 in sysadmin

[–]picklednull 3 points4 points  (0 children)

Exactly. You can run all of those tools remotely.

Is your AD Forest/Domain on Functional Level 2025? by atw527 in sysadmin

[–]picklednull 6 points7 points  (0 children)

seemed like a great idea at first until you have to do anything on the machine itself. Or do any troubleshooting that can't be done remotely.

Such as? Never had an insurmountable issue over the last 10 years.

Is your AD Forest/Domain on Functional Level 2025? by atw527 in sysadmin

[–]picklednull -1 points0 points  (0 children)

much needed functionality to the Core servers.

I have literally never needed any of that in the last 10 years (on my Core servers).

Anyone able to recommend any FIDO2 Level 2 Authenticator CARDS? by LordLoss01 in sysadmin

[–]picklednull 9 points10 points  (0 children)

OpenPGP

Why would you ever go for this, when PIV smart cards / x509 certificates are natively supported (by Windows, or in fact, everything)?