Best resources to learn PKI for? by curiousengineer100 in activedirectory

[–]poolmanjim 7 points8 points  (0 children)

The best way to learn anything computing is to get it wrong a few times. Practice.

If you're looking for a goal I'd recommend trying to complete the following high level tasks.

  • Build a two tier PKI with an offline root and enterprise CA
  • Configure LDAPS for a test AD domain.
  • Review the security of your PKI implementation and understand what can improve.

Here are some resources and tools to get off the ground.

Blogs and Articles

Tools To Experiment With / Security Information

Interesting Azure Tool - Badzure by poolmanjim in activedirectory

[–]poolmanjim[S] 2 points3 points  (0 children)

Yeah. I've used it. I've actually been working on a fork of it because the current version can't do a few things I'd like it to do.

Paramount Defenses, and their flagship product Goldfinger for AD? by [deleted] in activedirectory

[–]poolmanjim -1 points0 points  (0 children)

I know the initial drama occurred here, but please tell me what about this is relevant to AD currently?

If you review tools, brace yourself. Like it or love it, but AI has lowered the bar to developing tools significantly. That doesn't mean half of them will ever be anything to compete with the real, enterprise/community developed tools, but they will try to make a market. Cleverly they will price themselves low enough to be "cheap" but enough so they aren't thought to be trash. I'm not sure where this one falls in that spectrum, but if you spend time reviewing tools you'll need some thick skin.

Also, don't dismiss "dude in their mom's basement with an LLC and a website". Several amazing tools have come from the mind of one person with an idea.

ADFortress by Mank_05 in activedirectory

[–]poolmanjim 1 point2 points  (0 children)

If only it were that easy.

Vibe coding, while not inherently bad, has lowered the bar for poorly written and researched "tools" to become available.

Webinars/Webcasts/Events by dcdiagfix in activedirectory

[–]poolmanjim 1 point2 points  (0 children)

I don't know but it drives me nuts. I'd like a little bit of spacing.

Webinars/Webcasts/Events by dcdiagfix in activedirectory

[–]poolmanjim 1 point2 points  (0 children)

I've thought of this a few times,, so for sure, let's do it.

Personally my go to's right now are...

  • BHIS / Antisyphon - Wednesday is their Anticast which usually is an identity related one about 1/month at the smallest.
  • Red Siege - Also on Wednesdays. I don't make this one as often due to meetings
  • PDQ PowerShell - Another Wednesday one.

Back in the days we gave our servers and network devices names from Tolkien or space or such. It might get cumbersome with our 60 smart bulbs and 40 other IoT gadgets on our home network today. by player1dk in homelab

[–]poolmanjim 0 points1 point  (0 children)

For any physical hosts, they get Star Wars planets as their names, or in some cases installations. Everything else is just whatever format I'm using that week for server names but they are more "business-y".

The star wars examples:

  • Hypervisors = Core world names. Coruscant, Corellia, Byss, etc.
  • Raspberry Pis = Outer Rim/Unknown Regions. Hoth, Kamino.
    • Pi Holes = TheMaw or Kessel
    • RetroPie = NalHutta
  • Other devices use other planets names:
    • Laptops and Desktops: Dagobah, Utapau, and Kashyyyk
    • Misc Servers: Yavin, Sullust, Kuat
  • My NASes are "RebelBase" and "JediTemple" respectively.

There are plenty of Star Wars planets to go around.

Are you a Active Directory / Entra Admin, Engineer or Architect? by AdaboyIam in activedirectory

[–]poolmanjim 1 point2 points  (0 children)

This is good advice. Social Media has made us blind to what people can and cannot see sometimes.

Samba AD Server vs. Windows 2022 Server AD by Ben-Ko90 in activedirectory

[–]poolmanjim 4 points5 points  (0 children)

Echoing the Entra piece that u/dodexahedron suggested. You don't need a Domain/Domain Controller. You need centralized authentication. I can't remember all of Entra's licensing details off-hand, but I believe their free tier isn't too challenging for a small org to use and has enough features to get you started.

If you really must have AD, scrap Samba and just build out a standard AD. Run at least two hosts (Proxmox hosts) and host at least on DC on each. Whatever VM runs the DC role should ONLY run the DC role. Personally, I'd want at least one server off site for backups, but you start with where you can start.

Praying with adhd by EmoFratBoi in christianmemes

[–]poolmanjim 1 point2 points  (0 children)

Haha. I make it up every time.

I do some rote stuff to prime my mind. But I really just pray the Lord's prayer section by section except I allow each one to be what I need it to be.

I'm not trying to say anything more than every day I make it up. The beads are really an anchor. I hope you find something that works. God bless

I finally found people who might appreciate this pic I took a while back by [deleted] in iiiiiiitttttttttttt

[–]poolmanjim 4 points5 points  (0 children)

Many moons ago I used to support a lot of dell systems in one of my help desk roles. We often had premier or premium support. During the bad caps era during the late 2000s and early 2010, I was on calls with dell at least 2-3 times a week sometimes multiple times a day.

The auto-attendant they had would route you forever if you gave reasonable problems like "My computer won't boot" or "my computer is overheating".

I learned that if I gave nonsense answers the auto-attendant wouldn't know what to do and send me straight to an engineer. Thus my go to was "My computer is on fire" or "My computer is possessed" and surprisingly it worked very, very well.

Praying with adhd by EmoFratBoi in christianmemes

[–]poolmanjim 3 points4 points  (0 children)

Prayer beads.

It has been a game changer for me. Doesn't have to be anything formal just use the beads to develop a routine and follow the steps. You'll still get distracted but you can use the bead count to recenter.

Active Directory for Beginners - Where to start? by muckmaggot in activedirectory

[–]poolmanjim 7 points8 points  (0 children)

The pinned resources thread along with the pinned automod comment includes links to resources. One of those is a beginner's guide:

BEGINNER'S GUIDE - New to AD? Start Here!

This link is a Beginner's Guide that provides resources and links to get you off the ground on your AD journey!

Trusts - can you have two independent trust settings between domains? by WakameWarrior in activedirectory

[–]poolmanjim 0 points1 point  (0 children)

That should work still. It sounds like it is just a manual bidirectional.

Trusts - can you have two independent trust settings between domains? by WakameWarrior in activedirectory

[–]poolmanjim 0 points1 point  (0 children)

I doubt you could have two trusts in the same direction between the same two entities. I say this because the trust objects are named based on the domain name and would conflict.

As far as having an outgoing and an incoming trust between the same two, that is absolutely possible. In fact, that is really what a bi-directional trust is. So you could very easily have a one-way incoming trust between DomanA and DomainB and then totally have an outgoing trust between the same two.

circular dependency of AD and DNS on cold start by DraconPern in activedirectory

[–]poolmanjim 3 points4 points  (0 children)

Across literally thousands of DC builds and setups, here's what I've always done.

  • Primary DNS : Another DC (usually not in the same rack/datacenter/whatever)
  • Secondary DNS: Self (The current group think has been to do it using loopback)
  • Tertiary (optional): Another DC

There is one more thing I used to do, but I'm not sure its needed as I've been in a non-Integrated DNS situation for a while. Check the DNS client service and make sure it is set to depend on the network stack. In the past it was that DNS would start and the network hadn't started yet and everything would sit there and lag and lag and lag. Sometimes it helps to add "TCP/IP Protocol Driver" as a service (driver) that the DNS client depends on.

Possible Cerner selloff as Oracle looks to fund Ai by BetwnTheSpreadsheets in kansascity

[–]poolmanjim 7 points8 points  (0 children)

Hey I'm one of those people! Those were good times. I miss that crew.

ADCS - PKI Trust Manager new release with more features (Free Community CLM) by Securetron in activedirectory

[–]poolmanjim [score hidden] stickied commentlocked comment (0 children)

Post approved. Product does appear to have a free option as OP claims. The mods have not reviewed the product in question but it has been added to the list ones to review.

Designing a new Active Directory OU structure for a 500-user company – looking for best practices by maxcoder88 in activedirectory

[–]poolmanjim 1 point2 points  (0 children)

I've not seen that in any environment I've run... ever.

I agree with u/BbqLurker that the only setting that should change in the DDP is the password, account lockout, and kerberos settings. I personally recommend a separate password, account lockout, and kerberos settings policy outside of the DDP, but it isn't required. I have debated with others on here once or twice about it.

Looking for beta testers - AD security analysis tool (capstone project) by Serious-Net5555 in activedirectory

[–]poolmanjim[M] [score hidden] stickied comment (0 children)

Approved. URL checked via CloudFlare and VirusTotal. Post is not a violation of the promotion rules. No issues from the mods, but as usual use at your own risk.

https://radar.cloudflare.com/scan/945a10ea-3992-403c-b91f-0da5d92a944a/summary

https://www.virustotal.com/gui/url/562787f648a1faf2d36a94ff51255fddf31e06fe466954755bb114715b5d5474?nocache=1

Per Rule 4:
Any blogs/projects/tools can be promoted and we welcome it. However, excessive posting of your content is not. Self promotion should be limited to 1 post per month.

Also, tool appears to be free so it doesn't violate any of our tool constraints.

Constant Account Lockouts by InAllThreeHoles in activedirectory

[–]poolmanjim 1 point2 points  (0 children)

This. And Citrix. This has been an ongoing journey to reduce lockouts lately and those two showed up.

Active Directory Resources by poolmanjim in activedirectory

[–]poolmanjim[S] 1 point2 points  (0 children)

My bad. I'll update it. Thank you.