Skip to main content

Posts

Showing posts from December, 2012

SHA-1 checksums for files

To obtain the hash, you’ll need a utility that calculates SHA-1 checksums for files – fortunately Microsoft has a free download called the File Checksum Verifier Utility . Run fciv.exe from the command line on your reference PC to obtain the desired checksum:

SHA-1 checksums for files

To obtain the hash, you’ll need a utility that calculates SHA-1 checksums for files – fortunately Microsoft has a free download called the File Checksum Verifier Utility . Run fciv.exe from the command line on your reference PC to obtain the desired checksum:

SCCM "Closing the allow unknown computer support to take control"

Applies To: System Center Configuration Manager 2007 R2, System Center Configuration Manager 2007 R3 Unknown computer support is an operating system deployment feature in Configuration Manager 2007 R2 that allows unmanaged systems to be discovered and receive operating system deployment. http://technet.microsoft.com/en-us/library/cc161877.aspx ~But why is it showing up in my SCCM task sequence? ... This is not an error, it was an informational message just saying that the Task Sequence Availability Checker did not need to add the machine to a collection for task sequences to be available at the next step. This is because we have advertised the task sequences to the unknown computer collections. Any machines that boot up and request task sequences that do not have a record in SCCM will be able to start running one of those advertised task sequences. We are using non-integrated WDS which means we can’t use the unknown computer support on PXE service points. However, the issue here isn’t

SCCM "Closing the allow unknown computer support to take control"

Applies To: System Center Configuration Manager 2007 R2, System Center Configuration Manager 2007 R3 Unknown computer support is an operating system deployment feature in Configuration Manager 2007 R2 that allows unmanaged systems to be discovered and receive operating system deployment. http://technet.microsoft.com/en-us/library/cc161877.aspx ~But why is it showing up in my SCCM task sequence? ... This is not an error, it was an informational message just saying that the Task Sequence Availability Checker did not need to add the machine to a collection for task sequences to be available at the next step. This is because we have advertised the task sequences to the unknown computer collections. Any machines that boot up and request task sequences that do not have a record in SCCM will be able to start running one of those advertised task sequences. We are using non-integrated WDS which means we can’t use the unknown computer support on PXE service points. However, the issue here isn’t

SCCM DCM Creation and KPI

Microsoft Security Compliance manger Possible to import Backed up GPO's and then export as DCM baseline for compliance.  For computers not on the domain and able to receive a GPO can use teh local policy tool that is included with the SCM tool to import teh Group policy backup instead.     Verify that bitlokcer is enabled on the C drive Option Explicit On Error Resume Next Dim objWMI, obj, colTPM Set objWMI = GetObject("winmgmts:\\.\ROOT\CIMv2\Security\MicrosoftVolumeEncryption") If Err <> 0 Then Script.Quit End If Set colTPM = objWMI.ExecQuery ("Select * from Win32_EncryptableVolume") For Each obj in colTPM If ( UCase(obj.DriveLetter) = "C:" And obj.ProtectionStatus = 1 ) Then WScript.Echo "BitLocker Enabled on C Drive" WScript.Quit End If Next

SCCM DCM Creation and KPI

Microsoft Security Compliance manger Possible to import Backed up GPO's and then export as DCM baseline for compliance.  For computers not on the domain and able to receive a GPO can use teh local policy tool that is included with the SCM tool to import teh Group policy backup instead.     Verify that bitlokcer is enabled on the C drive Option Explicit On Error Resume Next Dim objWMI, obj, colTPM Set objWMI = GetObject("winmgmts:\\.\ROOT\CIMv2\Security\MicrosoftVolumeEncryption") If Err <> 0 Then Script.Quit End If Set colTPM = objWMI.ExecQuery ("Select * from Win32_EncryptableVolume") For Each obj in colTPM If ( UCase(obj.DriveLetter) = "C:" And obj.ProtectionStatus = 1 ) Then WScript.Echo "BitLocker Enabled on C Drive" WScript.Quit End If Next

SCCM DCM What is it?

What is Desired Configuration Management (DCM)? DCM is a feature in SCCM that will provide a framework for assisting organizations in both defining and enforcing corporate policies and standards for system configurations, whether related to the operating system or an application installed on the system. Feature include authoring and scheduling, model-based design leveraging Service Modeling Language (SML) (a component of Microsoft's Dynamic Systems Initiative) which makes the features we're about to discuss possible. Some of the key scenarios that drove the features Microsoft delivered in the final release of DCM include: Regulatory Compliance - demonstrating regulatory compliance in system configurations. Not only deploying a compliant standard system configuration, but being able to periodically prove adherence to these policies. Pre and post change configuration - Verify that no unplanned changes took place during the implementation of a planned change. Monitoring for "

SCCM DCM What is it?

What is Desired Configuration Management (DCM)? DCM is a feature in SCCM that will provide a framework for assisting organizations in both defining and enforcing corporate policies and standards for system configurations, whether related to the operating system or an application installed on the system. Feature include authoring and scheduling, model-based design leveraging Service Modeling Language (SML) (a component of Microsoft's Dynamic Systems Initiative) which makes the features we're about to discuss possible. Some of the key scenarios that drove the features Microsoft delivered in the final release of DCM include: Regulatory Compliance - demonstrating regulatory compliance in system configurations. Not only deploying a compliant standard system configuration, but being able to periodically prove adherence to these policies. Pre and post change configuration - Verify that no unplanned changes took place during the implementation of a planned change. Monitoring for "

Adobe Reader Error Opening a PDF

"Before proceeding you must first launch Adobe Acrobat and accept the End User License Agreement" To analyze, filter to only AcroRd32.exe process using Process monitor. Then exclude all “SUCCESS” results. Note the key: HKLM\SOFTWARE\Adobe\Adobe Acrobat\10.0\AdobeViewer\EULAAcceptedForBrowser NAME NOT FOUND Confirm the key is not present in Regedit; create a DWORD called “EULAAcceptedForBrowser” & set the Value Data to 1 NOTE: relating to a bug; if "CR" is in the folder or file name : http://forums.adobe.com/message/3791868

Adobe Reader Error Opening a PDF

"Before proceeding you must first launch Adobe Acrobat and accept the End User License Agreement" To analyze, filter to only AcroRd32.exe process using Process monitor. Then exclude all “SUCCESS” results. Note the key: HKLM\SOFTWARE\Adobe\Adobe Acrobat\10.0\AdobeViewer\EULAAcceptedForBrowser NAME NOT FOUND Confirm the key is not present in Regedit; create a DWORD called “EULAAcceptedForBrowser” & set the Value Data to 1 NOTE: relating to a bug; if "CR" is in the folder or file name : http://forums.adobe.com/message/3791868

1E NOMAD overview

What is Enterprise View? http://www.1e.com/helparchive/NightWatchman%20and%20WakeUp/v6.0/User_Guide/User-Guides/Enterprise%20View%20Users%20Guide.pdf Enterprise View is aimed at personnel who want a quick overview of their network and how the 1E products are working to bring them environmental and cost savings. Enterprise View is a management dashboard, providing at-a-glance overviews of the energy consumption and computer-related information that 1E is gathering on your network. How does Enterprise View operate? Enterprise View provides a web-based portal onto the 1E databases. The portal lets you choose from a number of pre-defined tiles to display significant PC and Server information in a handy, summarized format.

1E NOMAD overview

What is Enterprise View? http://www.1e.com/helparchive/NightWatchman%20and%20WakeUp/v6.0/User_Guide/User-Guides/Enterprise%20View%20Users%20Guide.pdf Enterprise View is aimed at personnel who want a quick overview of their network and how the 1E products are working to bring them environmental and cost savings. Enterprise View is a management dashboard, providing at-a-glance overviews of the energy consumption and computer-related information that 1E is gathering on your network. How does Enterprise View operate? Enterprise View provides a web-based portal onto the 1E databases. The portal lets you choose from a number of pre-defined tiles to display significant PC and Server information in a handy, summarized format.

NOMAD 1E not responding to a package status request

Overview : During a SCCM task sequence a specific application is to be installed.  The task sequence is designed to use a NOMAD cache to poll the source.  The sequence fails as no available cache is available. How to troubleshoot? On the NOMAD cacheing server Open regedit and check the package status details. Select the sub folder that corresponds to the cached item and review the details on the right.  You should check the following item are present and correct [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\1E\NomadBranch\PkgStatus\LDC002FE] "Percent"="100.000" "Version"="2" "CachePriority"="1" "CacheToFolder"="D:\\NomadBranchCache" "ReturnStatus"="Completed Successfully" "AlreadyCached"="0" Also check the logs for specific behaviour. C:\ProgramData\1E\NomadBranch\LogFiles The log should state "CacheStatus: (ELD)  pkgID="LDC002FE"(0) local=100.000% verified

NOMAD 1E not responding to a package status request

Overview : During a SCCM task sequence a specific application is to be installed.  The task sequence is designed to use a NOMAD cache to poll the source.  The sequence fails as no available cache is available. How to troubleshoot? On the NOMAD cacheing server Open regedit and check the package status details. Select the sub folder that corresponds to the cached item and review the details on the right.  You should check the following item are present and correct [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\1E\NomadBranch\PkgStatus\LDC002FE] "Percent"="100.000" "Version"="2" "CachePriority"="1" "CacheToFolder"="D:\\NomadBranchCache" "ReturnStatus"="Completed Successfully" "AlreadyCached"="0" Also check the logs for specific behaviour. C:\ProgramData\1E\NomadBranch\LogFiles The log should state "CacheStatus: (ELD)  pkgID="LDC002FE"(0) local=100.000% verified

PXE-E32: TFTP Open Timeout

SYMPTOM When the PXE client comes up with the PXE copyright message and completes the DHCP phase, but then displays: TFTP.... After a while, the following error message is displayed: PXE-E32: TFTP open timeout Depending on the PXE client's system setup boot device list configuration, the PC then either stops or tries to boot from the next boot device in the system setup boot device list. CAUSE 1 The "PXE-E32" error indicates that the PXE did not get a reply from the TFTP server when sending a request to download its boot file. Possible causes for this problem are: 1. There is no TFTP server 2. The TFTP server is not running 3. TFTP and DHCP/BOOTP services are running on different machines, but the next-server (066) option was not specified RESOLUTION 1 Make sure that a TFTP server is set up and running. When the TFTP service is running on a different machine than the DHCP or BOOTP service, you need to add option 066 (next-server) to the DHCP/BOOTP server configuration, an

PXE-E32: TFTP Open Timeout

SYMPTOM When the PXE client comes up with the PXE copyright message and completes the DHCP phase, but then displays: TFTP.... After a while, the following error message is displayed: PXE-E32: TFTP open timeout Depending on the PXE client's system setup boot device list configuration, the PC then either stops or tries to boot from the next boot device in the system setup boot device list. CAUSE 1 The "PXE-E32" error indicates that the PXE did not get a reply from the TFTP server when sending a request to download its boot file. Possible causes for this problem are: 1. There is no TFTP server 2. The TFTP server is not running 3. TFTP and DHCP/BOOTP services are running on different machines, but the next-server (066) option was not specified RESOLUTION 1 Make sure that a TFTP server is set up and running. When the TFTP service is running on a different machine than the DHCP or BOOTP service, you need to add option 066 (next-server) to the DHCP/BOOTP server configuration, an