<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Mind Of Root</title>
	<link>http://www.mindofroot.com</link>
	<description>Peering into the mind of a systems administrator</description>
	<pubDate>Tue, 09 Aug 2011 17:43:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<item>
		<title>Finally&#8230;an answer</title>
		<link>http://www.mindofroot.com/2011/08/09/finallyan-answer/</link>
		<comments>http://www.mindofroot.com/2011/08/09/finallyan-answer/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 17:43:44 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
		
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/08/09/finallyan-answer/</guid>
		<description><![CDATA[Hopefully there are a few of you that still check the site or feed and will see this.
If you are reading this, then you have been wondering where the show has gone and if it will return.  Our hiatus was fueled by many distractions, but it has led me to the point I had hoped to [...]]]></description>
			<content:encoded><![CDATA[<p>Hopefully there are a few of you that still check the site or feed and will see this.</p>
<p>If you are reading this, then you have been wondering where the show has gone and if it will return.  Our hiatus was fueled by many distractions, but it has led me to the point I had hoped to avoid; the show is done.  I finally had the chance to speak with Steve and let him know that I am bowing out of the show altogether.  Steve is battling his own constraints, but may decide to do something with the show.  Keep an eye out for a post from him letting you know if there are any plans.</p>
<p>We truly apologize for disappearing (again) without an explanation.  Between our jobs and families, we can&#8217;t seem to find a way to schedule a regular recording time.  I couldn&#8217;t find the time to put together content for the show; which led to aggravation for me as I wanted to bring something of substance to the show. The reason I/we didn&#8217;t post anything was that we kept hoping to delay the inevitable and find a way to get past this.  We&#8217;ve delayed long enough and it&#8217;s time to call it done.</p>
<p>I am hoping to schedule a &#8220;Final Episode&#8221; with Steve and Rich and will post a recording time should anyone want to join us.</p>
<p>Lastly, I want to thank all of the listeners we&#8217;ve had over the years.  You have all been very supportive and encouraging.  Knowing that someone was listening and enjoyed the show makes it all worth the effort.  I will truly miss the interaction and fun we&#8217;ve had along the way together.</p>
<p>Thank you again.</p>
<p>Keith</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/08/09/finallyan-answer/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Book Club Episode Delayed</title>
		<link>http://www.mindofroot.com/2011/04/24/book-club-episode-delayed/</link>
		<comments>http://www.mindofroot.com/2011/04/24/book-club-episode-delayed/#comments</comments>
		<pubDate>Sun, 24 Apr 2011 13:49:02 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Book Club]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/04/24/book-club-episode-delayed/</guid>
		<description><![CDATA[When I was planning the next book club show, I forgot that this weekend was Easter.&#160; Due to family commitments, I have to reschedule this review.
Stay tuned, because I know Keith is eager to talk Namespaces!
]]></description>
			<content:encoded><![CDATA[<p>When I was planning the next book club show, I forgot that this weekend was Easter.&#160; Due to family commitments, I have to reschedule this review.</p>
<p>Stay tuned, because I know Keith is eager to talk Namespaces!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/04/24/book-club-episode-delayed/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Scripting Games March On</title>
		<link>http://www.mindofroot.com/2011/04/13/the-scripting-games-march-on/</link>
		<comments>http://www.mindofroot.com/2011/04/13/the-scripting-games-march-on/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 03:43:04 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Scripting]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/04/13/the-scripting-games-march-on/</guid>
		<description><![CDATA[We are entering the final stretch of the Scripting Games.&#160; There are only two more events to be published and one more week of entries.
In my time judging for the Games, I&#8217;ve written a few blog posts about some of the common issues I&#8217;ve found in the entries.&#160; You can see all my Scripting Games [...]]]></description>
			<content:encoded><![CDATA[<p>We are entering the final stretch of the <a href="http://bit.ly/2011sgall" target="_blank">Scripting Games</a>.&#160; There are only two more events to be published and one more week of entries.</p>
<p>In my time judging for the Games, I&#8217;ve written a few blog posts about some of the common issues I&#8217;ve found in the entries.&#160; You can see all my <a href="http://blog.usepowershell.com/category/events/scripting-games/" target="_blank">Scripting Games related posts here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/04/13/the-scripting-games-march-on/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Taking a WinDump</title>
		<link>http://www.mindofroot.com/2011/04/04/taking-a-windump/</link>
		<comments>http://www.mindofroot.com/2011/04/04/taking-a-windump/#comments</comments>
		<pubDate>Mon, 04 Apr 2011 18:37:45 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Scripting]]></category>

		<category><![CDATA[Servers]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/04/04/taking-a-windump/</guid>
		<description><![CDATA[
I’ve had to troubleshoot a number of network related issues recently.  I love WireShark, but I don’t want to install it on every server.  I’m still a bit hesitant on installing the WinPcap drivers on servers as well, but when you need to grab network traffic on the Windows platform, it is one of the [...]]]></description>
			<content:encoded><![CDATA[<p>
I’ve had to troubleshoot a number of network related issues recently.  I love <a href="http://www.wireshark.org/" target="_blank">WireShark</a>, but I don’t want to install it on every server.  I’m still a bit hesitant on installing the <a href="http://www.winpcap.org/" target="_blank">WinPcap</a> drivers on servers as well, but when you need to grab network traffic on the Windows platform, it is one of the easier ways.
</p>
<p>(Yes.. I know I should have a monitoring box on a span port that I could do this off of, but it becomes a bit more complicated in a virtual environment.)
</p>
<p>So, I’ve compromised a bit.  I’ve been using the <a href="http://www.winpcap.org/" target="_blank">WinPcap</a> drivers and <a href="http://www.winpcap.org/windump/default.htm" target="_blank">WinDump</a> from the command line to create the network captures.  Then I can use <a href="http://www.wireshark.org/" target="_blank">WireShark</a> on my desktop to analyze the traffic.
</p>
<p>The command line I used for WinDump was something like:<br />
<blockquote>C:\WinDump.exe -n -s 0 -vvv -w mynetworkcapture.pcap</p></blockquote>
<p>The “–n” skips the DNS resolution (which makes it a bit more consistent to read through).The “–s 0” captures the full packet.  “-vvv” captures additional packet details.  And last, but not least, “-w mynetworkcapture.pcap” is the file name (and relative path) to where the capture could be saved.</p>
<p>There are many, many other options, but this got me a quick grab of traffic that let me isolate my problem in WireShark and get to the resolution I needed.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/04/04/taking-a-windump/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MOR 153 - Timebombs and T1&#8217;s</title>
		<link>http://www.mindofroot.com/2011/04/03/mor-153-timebombs-and-t1s/</link>
		<comments>http://www.mindofroot.com/2011/04/03/mor-153-timebombs-and-t1s/#comments</comments>
		<pubDate>Mon, 04 Apr 2011 02:52:06 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
		
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/04/03/mor-153-timebombs-and-t1s/</guid>
		<description><![CDATA[Recorded: April 3, 2011
Your Hosts: Keith Albright and Steve Murawski
Show Length: 1:06:11
Topics/Links:

System Center Betas
Problems with SP1
Verizon T1 outage

Read the full show notes here.
Website Picks
Sorry, none this week.

Listen Now:







Download Here
]]></description>
			<content:encoded><![CDATA[<p><strong>Recorded:</strong> April 3, 2011<br />
<strong>Your Hosts:</strong> Keith Albright and Steve Murawski<br />
<strong>Show Length: </strong>1:06:11</p>
<p><strong>Topics/Links:</strong></p>
<ul>
<li>System Center Betas</li>
<li>Problems with SP1</li>
<li>Verizon T1 outage</li>
</ul>
<p>Read the full show notes <a target="_blank" href="http://podcast.acoupleofadmins.com/pmwiki/pmwiki.php?n=Main.Episode153"><font color="#2175bc">here.</font></a></p>
<p><strong>Website Picks</strong></p>
<p>Sorry, none this week.</p>
<div class="podPress_content">
<div id="podPressPlayerSpace_2410" style="display: block">Listen Now:<br />
<object width="290" height="24" id="audioplayer235" data="http://podcast.acoupleofadmins.com/media/player.swf" type="application/x-shockwave-flash"></p>
<param value="http://podcast.acoupleofadmins.com/media/player.swf" name="movie" />
<param value="playerID=235&amp;bg=0xF8F8F8&amp;leftbg=0xEEEEEE&amp;text=0x666666&amp;lefticon=0x666666&amp;rightbg=0xCCCCCC&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xFFFFFF&amp;slider=0x666666&amp;track=0xFFFFFF&amp;loader=0x9FFFB8&amp;border=0x666666&amp;soundFile=http%3A%2F%2Fpodcast.acoupleofadmins.com%2Fmedia%2Fpodcast%2FMOR_153_20110403.mp3" name="FlashVars" />
<param value="high" name="quality" />
<param value="false" name="menu" />
<param value="transparent" name="wmode" /></object></div>
</div>
<p><a title="Episode 153 Download" target="_blank" href="http://podcast.acoupleofadmins.com/media/podcast/MOR_153_20110403.mp3">Download Here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/04/03/mor-153-timebombs-and-t1s/feed/</wfw:commentRss>
<enclosure url="http://podcast.acoupleofadmins.com/media/podcast/MOR_153_20110403.mp3" length="31776778" type="audio/mpeg" />
		</item>
		<item>
		<title>MOR 152 - Hellooooooo, Mr. Wilson!</title>
		<link>http://www.mindofroot.com/2011/03/27/mor-152-hellooooooo-mr-wilson/</link>
		<comments>http://www.mindofroot.com/2011/03/27/mor-152-hellooooooo-mr-wilson/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 02:36:40 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
		
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/03/27/mor-152-hellooooooo-mr-wilson/</guid>
		<description><![CDATA[Recorded: March 27, 2011
Your Hosts: Keith Albright and Steve Murawski
Show Length:1:13:33
Topics/Links:

Interview with Ed Wilson: The Microsoft Scripting Guy

Hey, Scripting Guy! Blog
Follow him on Twitter @ScriptingGuys
2011 Scripting Games


Upcoming Changes to Microsoft Core CAL&#8217;s
Making movies with YouTubeDownloader and CamStudio
Windows 7 &#38; 2008 R2 Service Pack 1 Trials and Tribulations
osTicket - Web-based help desk ticket management

Read the full show [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Recorded:</strong> March 27, 2011<br />
<strong>Your Hosts:</strong> Keith Albright and Steve Murawski</p>
<p><strong>Show Length:</strong>1:13:33</p>
<p><strong>Topics/Links:</strong></p>
<ul>
<li>Interview with Ed Wilson: The Microsoft Scripting Guy
<ul>
<li><a target="_blank" href="http://blogs.technet.com/b/heyscriptingguy/">Hey, Scripting Guy! Blog</a></li>
<li>Follow him on Twitter <a target="_blank" href="http://twitter.com/ScriptingGuys">@ScriptingGuys</a></li>
<li><a target="_blank" href="http://blogs.technet.com/b/heyscriptingguy/archive/2011/02/19/2011-scripting-games-all-links-on-one-page.aspx">2011 Scripting Games</a></li>
</ul>
</li>
<li><a target="_blank" href="http://blogs.softchoice.com/microsoftnavigator/2011/03/21/core-cal-updates/">Upcoming Changes to Microsoft Core CAL&#8217;s</a></li>
<li>Making movies with <a target="_blank" href="http://youtubedownload.altervista.org/">YouTubeDownloader</a> and <a target="_blank" href="http://camstudio.org/">CamStudio</a></li>
<li>Windows 7 &amp; 2008 R2 Service Pack 1 Trials and Tribulations</li>
<li><a target="_blank" href="http://www.osticket.com/">osTicket</a> - Web-based help desk ticket management</li>
</ul>
<p>Read the full show notes <a target="_blank" href="http://podcast.acoupleofadmins.com/pmwiki/pmwiki.php?n=Main.Episode152"><font color="#2175bc">here.</font></a></p>
<p><strong>Website Picks</strong></p>
<p>Sorry, none this week.</p>
<div class="podPress_content">
<div id="podPressPlayerSpace_2410" style="display: block">Listen Now:<br />
<object width="290" height="24" id="audioplayer235" data="http://podcast.acoupleofadmins.com/media/player.swf" type="application/x-shockwave-flash"></p>
<param value="http://podcast.acoupleofadmins.com/media/player.swf" name="movie" />
<param value="playerID=235&amp;bg=0xF8F8F8&amp;leftbg=0xEEEEEE&amp;text=0x666666&amp;lefticon=0x666666&amp;rightbg=0xCCCCCC&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xFFFFFF&amp;slider=0x666666&amp;track=0xFFFFFF&amp;loader=0x9FFFB8&amp;border=0x666666&amp;soundFile=http%3A%2F%2Fpodcast.acoupleofadmins.com%2Fmedia%2Fpodcast%2FMOR_152_20110327.mp3" name="FlashVars" />
<param value="high" name="quality" />
<param value="false" name="menu" />
<param value="transparent" name="wmode" /></object></div>
</div>
<p><a title="Episode 152 Download" target="_blank" href="http://podcast.acoupleofadmins.com/media/podcast/MOR_152_20110327.mp3">Download Here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/03/27/mor-152-hellooooooo-mr-wilson/feed/</wfw:commentRss>
<enclosure url="http://podcast.acoupleofadmins.com/media/podcast/MOR_152_20110327.mp3" length="31048453" type="audio/mpeg" />
		</item>
		<item>
		<title>MOR 151 - Author, Author!</title>
		<link>http://www.mindofroot.com/2011/03/26/mor-152-author-author/</link>
		<comments>http://www.mindofroot.com/2011/03/26/mor-152-author-author/#comments</comments>
		<pubDate>Sun, 27 Mar 2011 03:23:34 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
		
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/03/26/mor-152-author-author/</guid>
		<description><![CDATA[Recorded: March 20, 2011
Your Hosts: Keith Albright and Steve Murawski
Show Length:1:16:25
Topics/Links:

Interview with Tom Limoncelli, one of the authors of TPOSANA and presenter at the PICC Conference. 

Grab the book here: The Practice of System and Network Administration (2nd Ed.)
Check out his site at Everything Sysadmin


Steve is presenting on DirectAccess
DirectAccess &#38; Office Communicator configuration woes
Limiting your user account [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Recorded:</strong> March 20, 2011<br />
<strong>Your Hosts:</strong> Keith Albright and Steve Murawski</p>
<p><strong>Show Length:</strong>1:16:25</p>
<p><strong>Topics/Links:</strong></p>
<ul>
<li>Interview with Tom Limoncelli, one of the authors of TPOSANA and presenter at the <a target="_blank" href="http://www.picconf.org/">PICC Conference</a>. 
<ul>
<li>Grab the book here: <a target="_blank" href="http://www.amazon.com/Practice-System-Network-Administration-Second/dp/0321492668/ref=sr_1_1?ie=UTF8&amp;qid=1288287567&amp;sr=8-1"><font color="#2175bc">The Practice of System and Network Administration (2nd Ed.)</font></a></li>
<li>Check out his site at <a target="_blank" href="http://everythingsysadmin.com/">Everything Sysadmin</a></li>
</ul>
</li>
<li><a target="_blank" href="http://gmitpuc.com/">Steve is presenting on DirectAccess</a></li>
<li><a target="_blank" href="http://technet.microsoft.com/en-us/network/dd420463">DirectAccess &amp; Office Communicator configuration woes</a></li>
<li>Limiting your user account abilities</li>
</ul>
<p>Read the full show notes <a target="_blank" href="http://podcast.acoupleofadmins.com/pmwiki/pmwiki.php?n=Main.Episode151"><font color="#2175bc">here.</font></a></p>
<p><strong>Website Picks</strong></p>
<p>Sorry, none this week.</p>
<div class="podPress_content">
<div id="podPressPlayerSpace_2410" style="display: block">Listen Now:<br />
<object width="290" height="24" id="audioplayer235" data="http://podcast.acoupleofadmins.com/media/player.swf" type="application/x-shockwave-flash"></p>
<param value="http://podcast.acoupleofadmins.com/media/player.swf" name="movie" />
<param value="playerID=235&amp;bg=0xF8F8F8&amp;leftbg=0xEEEEEE&amp;text=0x666666&amp;lefticon=0x666666&amp;rightbg=0xCCCCCC&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xFFFFFF&amp;slider=0x666666&amp;track=0xFFFFFF&amp;loader=0x9FFFB8&amp;border=0x666666&amp;soundFile=http%3A%2F%2Fpodcast.acoupleofadmins.com%2Fmedia%2Fpodcast%2FMOR_151_20110320.mp3" name="FlashVars" />
<param value="high" name="quality" />
<param value="false" name="menu" />
<param value="transparent" name="wmode" /></object></div>
</div>
<p><a title="Episode 151 Download" target="_blank" href="http://podcast.acoupleofadmins.com/media/podcast/MOR_151_20110320.mp3">Download Here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/03/26/mor-152-author-author/feed/</wfw:commentRss>
<enclosure url="http://podcast.acoupleofadmins.com/media/podcast/MOR_151_20110320.mp3" length="36689930" type="audio/mpeg" />
		</item>
		<item>
		<title>SCCM 2012&#8211;Moving Backwards In Time</title>
		<link>http://www.mindofroot.com/2011/03/24/sccm-2012moving-backwards-in-time/</link>
		<comments>http://www.mindofroot.com/2011/03/24/sccm-2012moving-backwards-in-time/#comments</comments>
		<pubDate>Thu, 24 Mar 2011 19:37:50 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Servers]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/03/24/sccm-2012moving-backwards-in-time/</guid>
		<description><![CDATA[System Center Configuration Manager 2012’s 2nd Beta is out for download.. but don’t bother if you are running a patched or current SQL Server…
It appears that the Configuration Manager team decided to step back in their support of current database servers.&#160; Starting with Configuration Manager 2007 R2, the following were supported:

SQL Server 2005 with SP2 [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.microsoft.com/systemcenter/en/us/configuration-manager/cm-vnext-beta.aspx" target="_blank">System Center Configuration Manager 2012’s 2nd Beta</a> is out for download.. but don’t bother if you are running a patched or current SQL Server…</p>
<p>It appears that the Configuration Manager team decided to step back in their support of current database servers.&#160; <a href="http://technet.microsoft.com/en-us/library/ee344146.aspx" target="_blank">Starting with Configuration Manager 2007 R2, the following were supported</a>:</p>
<ul>
<li>SQL Server 2005 with SP2 or SP3</li>
<li>SQL Server 2008, SP1, or SP2 </li>
<li>SQL Server 2008 R2</li>
</ul>
<p>According to the beta <a href="http://go.microsoft.com/?linkid=9766556" target="_blank">System Requirements documentation</a> (remember this is beta, which in Microsoft parlance means bug fixes, not a lot of changes, etc..)</p>
<blockquote><p>Configuration Manager requires 64-bit SQL Server 2008 Standard Edition or SQL Server 2008 Enterprise Edition, running Service Pack 1 with at least Cumulative Update 10 . Other versions of SQL Server, such as SQL Server 2008 with Service Pack 2 or SQL Server 2008 R2, are not supported.</p>
</blockquote>
<p>If you are looking for something that is not so picky, but get’s you a good bit of the functionality, I’ve started to look at <a href="http://www.adminarsenal.com/" target="_blank">Admin Arsenal</a>.&#160; I’ve just downloaded one of their products and I’ll get a chance to look deeper later, but it seems to be a bit lower friction.</p>
<p>On a side note.. the guys at <a href="http://www.adminarsenal.com/" target="_blank">Admin Arsenal</a> are <a href="http://www.adminarsenal.com/admin-arsenal-blog/bid/55534/System-Admins-Take-Control-PICC-11-Conference" target="_blank">supporting this year’s</a> <a href="http://www.picconf.org" target="_blank">PICC event.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/03/24/sccm-2012moving-backwards-in-time/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OCS 2007 R2 Certificates</title>
		<link>http://www.mindofroot.com/2011/03/16/ocs-2007-r2-certificates/</link>
		<comments>http://www.mindofroot.com/2011/03/16/ocs-2007-r2-certificates/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 12:00:00 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Scripting]]></category>

		<category><![CDATA[Servers]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/03/16/ocs-2007-r2-certificates/</guid>
		<description><![CDATA[Situation:
Some of our internal certificates for OCS were coming due for replacement.&#160; I did a simple web search for “Find all certificates for Office Communication Server 2007 R2” and I got very little help.. 
And of course, OCS does not support wildcard certs  (but does take wildcards in Subject Alternative Names (SAN).. go figure..)
So [...]]]></description>
			<content:encoded><![CDATA[<h2>Situation:</h2>
<p>Some of our internal certificates for OCS were coming due for replacement.&#160; I did a simple web search for “Find all certificates for Office Communication Server 2007 R2” and I got very little help.. </p>
<p>And of course, OCS does not support wildcard certs <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-sadsmile" alt="Sad smile" src="http://www.mindofroot.com/wp-content/uploads/2011/03/wlemoticon-sadsmile.png" /> (but does take wildcards in Subject Alternative Names (SAN).. go figure..)</p>
<p>So for those who just want a reference of what certs are used where.. (Subject Name (SN) and Common Name (CN) are used somewhat interchangeably.. Common Name is the most import item to OCS)</p>
<h2>Outcome (it’s not pretty folks…):</h2>
<p>I give you (working from the outside in):</p>
<ol>
<li>
<h4>Edge Server</h4>
<ol>
<li>
<h5>Description:</h5>
<ol>
<li>The first cert needed is a Web Conferencing Edge Server.&#160; </li>
<li>SAN Required - No. </li>
<li>These are public facing certs, so you’ll likely want to get these from a cert provider. </li>
<li>Even if you are issuing them yoursefl, you’ll notice that these cert requests are generated offline, as the edge server is usually in a restricted portion of the DMZ without direct access to your internal CA. </li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: webconf.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>To create the cert request: LcsCmd /cert /action:request /friendlyname:”Web Conference Edge” /sn:webconf.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /fileName:”C:\CertHold\webedge.req” /L </li>
<li>To import the response: LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CAResponse.cer” /assign:true /Components:DP /L </li>
</ol>
</li>
<li>
<h5>Description:</h5>
<ol>
<li>The second cert required is for Audio/Video Authentication Edge Server. </li>
<li>SAN Required – No. </li>
<li>This is used for internal communication to the rest of the OCS infrastructure. </li>
<li>If you are using an internal cert, you will have to install the certs on the cert chain as well to make them trusted on this server. </li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: av.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /cert /action:request /friendlyname:”AV Edge” /sn:av.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /fileName:”C:\CertHold\avedge.req” /L </li>
<li>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CAResponse.cer” /assign:true /Components:MR /L </li>
</ol>
</li>
<li>
<h5>Description:</h5>
<ol>
<li>The third cert is required for the Internal Edge.&#160; </li>
<li>SAN Required – No. </li>
<li>This is for encrypting and decrypting traffic between external clients and the “next hop” server (usually the director or pool). </li>
<li>This can be an internally issued cert. </li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: internaledge.internal.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>
<p><font style="font-weight: normal">L</font>csCmd /cert /action:request /friendlyname:”Internal Edge” /sn:internaledge.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /fileName:”C:\CertHold\internaledge.req” /L</p>
</li>
<li>
<p>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CAResponse.cer” /assign:true /Components:INTERNAL /L</p>
</li>
</ol>
</li>
<li>
<h5>Description:</h5>
<ol>
<li>The fourth cert required covers the Access Edge. </li>
<li>SAN Required: Possible, if there are additional domains covered for external access. </li>
<li>This is for the default SIP.yourdomain.com address. </li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: sip.mindofroot.com </li>
<li>SAN: sip.acoupleofadmins.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /cert /action:request /friendlyname:”Access Edge” /sn:sip.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /san:sip.mindofroot.com, sip.acoupleofadmins.com /fileName:”C:\CertHold\accessedge.req” /L </li>
<li>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\accessedge.cer” /assign /Components:AP /L
<ol>
<p><!--EndFragment--></p>
</ol>
<ol>
<p><!--EndFragment--></p>
</ol>
</li>
</ol>
</li>
</ol>
</li>
<li>
<h4>Reverse Proxy</h4>
<ol>
<li>
<h5>Description:</h5>
<ol>
<li>The Reverse Proxy provides a way for external users to access content, expand address lists, and otherwise do things require more access. </li>
<li>SAN Required – Maybe. </li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: ocsweb.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /cert /action:request /friendlyname:”Web Proxy External” /sn:ocsweb.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /fileName:”C:\CertHold\webproxyext.req” /L </li>
<li>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CAResponse.cer” /L </li>
</ol>
</li>
</ol>
</li>
<li>
<h4>CWA Server</h4>
<ol>
<li>
<h5>Description:</h5>
<ol>
<li>The CWA certificate supports IM, PSTN call in, desktop sharing, etc.. </li>
<li>SAN Required – Yes. </li>
<li>Note – The DNS name cwa.yourdomain.com might be behind a reverse proxy.. in that case, you might need two certs (an internal and a public cert).</li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: cwa.mindofroot.com</li>
<li>SAN: im.mindofroot.com, cwa.acoupleofadmins.com, im.acoupleofadmins.com</li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /cert /action:request /online:false /friendlyname:”CWA” /sn:cwa.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /san: im.mindofroot.com, cwa.acoupleofadmins.com, im.acoupleofadmins.com /fileName:”C:\CertHold\CWAext.req” /L</li>
<li>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CWAResponse.cer” /assign:true /L</li>
</ol>
</li>
</ol>
</li>
<li>
<h4>Director</h4>
<ol>
<li>
<h5>Description:</h5>
<ol>
<li>SN set to the FQDN of the director. </li>
<li>SAN Required – Yes, set to the SIP DNS for each domain.&#160; </li>
</ol>
</li>
<li>
<h5>Example: </h5>
<ol>
<li>SN: director.internal.mindofroot.com </li>
<li>SAN: sip.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /Cert /Action:request /online:true /assign:true /ca:MOR-CA.internal.mindofroot.com\MOR-CA /caAccount:MOR\Admin /caPassword:P@ssword1 /friendlyname:”MOR-Director SIP”/sn:director.internal.mindofroot.com /OU: IT /org:MOR /city:SomeWhere /state:Else /country:US /san:*.mindofroot.com /L </li>
</ol>
</li>
</ol>
</li>
<li>
<h4>Mediation Server</h4>
<ol>
<li>
<h5>Description:</h5>
<ol>
<li>The Mediation Server coordinates enterprise voice traffic </li>
<li>SAN Required – No. </li>
</ol>
</li>
<li>
<h5>Example:</h5>
<ol>
<li>SN: mediation.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /cert /action:request /online:true /friendlyname:Mediation Server /sn:mediation.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /fileName:”C:\CertHold\mediation.req” /L </li>
<li>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CAResponse.cer” /assign:true /L </li>
</ol>
</li>
</ol>
</li>
<li>
<h4>Front End Server</h4>
</li>
<ol>
<li>
<h5>Description:</h5>
</li>
<ol>
<li>
<p>SN set to the FQDN of the enterprise pool name or server.&#160; </p>
</li>
<li>SAN Required – Yes, set to any alternative DNS names for the pool and server.&#160; </li>
</ol>
<li>
<h5>Example: </h5>
<ol>
<li>SN: pool1.intranet.mindofroot.com </li>
<li>SAN: pool1.mindofroot.com, sip.mindofroot.com, myfrontendserver.intranet.mindofroot.com </li>
</ol>
</li>
<li>
<h5>Command:</h5>
<ol>
<li>LcsCmd /Cert /Action:request /online:true /assign:true /ca:MOR-CA.internal.mindofroot.com\MOR-CA /caAccount:MOR\Admin /caPassword:P@ssword1 /friendlyname:“MOR-FE Front End SIP” /sn:pool01.internal.mindofroot.com /OU: IT /org:MOR /city:SomeWhere /state:Else /country:US /san:*.mindofroot.com, myfrontendserver.intranet.mindofroot.com /L </li>
</ol>
</li>
</ol>
<li>
<h4>Group Chat </h4>
</li>
<ol>
<li>
<h4>Description:</h4>
</li>
<ol>
<li>The Group Chat cert should reference the DNS for the Group Chat server. </li>
<li>SAN required – Maybe, if you have multiple DNS entries for group chat. </li>
</ol>
<li>
<h5>Example:</h5>
</li>
<ol>
<li>SN: groupchat.mindofroot.com </li>
<li>SAN: groupchat.acoupleofadmins.com </li>
</ol>
<li>
<h5>Command:</h5>
</li>
<ol>
<li>LcsCmd /cert /action:request /online:true /friendlyname:”Group Chat Server” /sn:groupchat.mindofroot.com /ou: IT /org:MOR /city:SomeWhere /state:Else /country:US /san:groupchat.mindofroot.com.com, groupchat.acoupleofadmins.com /enableClientEKU:TRUE /fileName:”C:\CertHold\groupchat.req” /L </li>
<li>LcsCmd /cert /action:ImportResponse /fileName:”C:\CertHold\CAResponse.cer” /assign:true /L</li>
</ol>
</ol>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/03/16/ocs-2007-r2-certificates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Licensing in Any World</title>
		<link>http://www.mindofroot.com/2011/03/14/licensing-in-any-world/</link>
		<comments>http://www.mindofroot.com/2011/03/14/licensing-in-any-world/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 19:53:03 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
		
		<category><![CDATA[Servers]]></category>

		<category><![CDATA[Vendors]]></category>

		<guid isPermaLink="false">http://www.mindofroot.com/2011/03/14/licensing-in-any-world/</guid>
		<description><![CDATA[Brian Lewis (IT Pro Evangelist for Microsoft) recently blogged about licensing in a virtual world.&#160; He made some interesting points about Datacenter edition licensing as VM density grows.
All that talk of licensing reminded me of a tool I’ve used to manage and license machines in my network – the Volume Activation Management Tool (VAMT) version [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://twitter.com/brianlewis_" target="_blank">Brian Lewis</a> (IT Pro Evangelist for Microsoft) <a href="http://mythoughtsonit.com/?p=303" target="_blank">recently blogged about licensing in a virtual world</a>.&#160; He made some interesting points about Datacenter edition licensing as VM density grows.</p>
<p>All that talk of licensing reminded me of a tool I’ve used to manage and license machines in my network – the <a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=ec7156d2-2864-49ee-bfcb-777b898ad582&amp;displaylang=en" target="_blank">Volume Activation Management Tool (VAMT) version 2.0</a>.&#160; Version 2.0 has some updated features, including managing Office 2010 licensing in addition to Server 2008 R2 and Windows 7.&#160; There is a <a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=12044dd8-1b2c-4da4-a530-80f26f0f9a99&amp;displaylang=en" target="_blank">version 1.1</a> of the tool that will manage licensing for Vista, Server 2008, Win 7, and Server 2008 R2.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mindofroot.com/2011/03/14/licensing-in-any-world/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

