Bart's Weblog

Just a blog…

Archive for the ‘Tech Stuff’ Category

Technical Stuff

Schemus Active Directory synchronisation tool

Posted by bartvdw on 2121/0505/2015

Recently had some questions in regards to the Schemus tool, which is a tool used to synchronize Active Directory information to cloud services, such as Symantec, Websense, etc. and I wanted to share that specific information.

Before you begin, it’s interesting to know:
& = AND
| = OR
! = NOT

If you use if to synchronize email addresses, you have the option to define the OU’s where to look for users if your AD is segmented accordingly, but the problem can be if both users and mail-enabled user reside in the same OU. To overcome that problem (as in: let’s exclude mail-enabled users), add this to the search filter: (!(msExchRecipientTypeDetails=128))

Full example: (|(&(objectCategory=person)(objectClass=user)(!(msExchRecipientTypeDetails=128)))(objectCategory=group))

(add objectCategory definitions if required, such as distribution groups, public folders, …)

Another thing that can cause troubles is that by default the tool uses %mail% variable to look up the primary email address, however that attribute is not maintained by Exchange, it’s an AD attribute and therefor it can have any value, even empty. That means that if the person who creates users must fill in that attribute correctly or you will have issues. To overcome that, change the Primary Mail attribute to following value: %proxyAddresses{s/(SMTP:|.*:.*)(.*)/$2/}%

By defining ‘SMTP’ (uppercase), we indicate we want the primary email address, the line Mail Aliases defines the same string, but with ‘smtp’ lowercase.

For Websense it can be difficult to synchronize users that have no mailbox or email address (ex. web filtering service, for authentication), in that case change the Primary Mail string to %userPrincipleName% as that should exist and filled in correctly.

msExchRecipientTypeDetails AD values: http://www.msexchange.org/kbase/ExchangeServerTips/MicrosoftOffice365/ExchangeOnline/msexchangerecipienttypedetails-active-directory-values.html

Posted in Active Directory, Schemus, Symantec, Websense | Leave a Comment »

VMware: Current known issues vCenter Server 5.5

Posted by bartvdw on 1414/1010/2013

These few issues I’ve encountered myself with VMware vCenter Server 5.5, and I think there are good to know/remember…

Active Directory authentication fails when vCenter Single Sign-On 5.5 runs on Windows Server 2012 and the AD Domain Controller is also on Windows Server 2012 (2060901)
http://kb.vmware.com/kb/2060901

vCenter Single Sign-On 5.5 Not Recognizing Nested Active Directory Groups
http://blogs.vmware.com/vsphere/2013/09/vcenter-single-sign-on-5-5-not-recognizing-nested-active-directory-groups.html

vCenter Server not listed in the inventory after installing or upgrading to vSphere 5.5 (2059528)
http://kb.vmware.com/kb/2059528

vCenter Server 5.5 displays a yellow warning in the Summary tab of hosts and reports the error: Quick stats on hostname is not up-to-date (2061008)
http://kb.vmware.com/kb/2061008

Posted in vCenter, vCenter 5.5, VMware, vSphere | Leave a Comment »

Symantec: General availability Backup Exec 2012 SP2 & Backup Exec 2010 SP3

Posted by bartvdw on 2626/0707/2013

Backup Exec 2010 R3 revision 5204 Service Pack 3 Release Notes
http://www.symantec.com/business/support/index?page=content&id=TECH208601

Backup Exec 2010 R3 revision 5204 Service Pack 3
http://www.symantec.com/business/support/index?page=content&id=TECH203157

Backup Exec 2012 revision 1798 Service Pack 2 Release Notes
http://www.symantec.com/business/support/index?page=content&id=TECH208600

Backup Exec 2012 revision 1798 Service Pack 2
http://www.symantec.com/business/support/index?page=content&id=TECH203155

Posted in Backup Exec 2010, Backup Exec 2012, Symantec | Leave a Comment »

IBM DS Storage and Windows MPIO

Posted by bartvdw on 2626/0707/2013

Don’t forget to install DSM !

Windows MPIO with IBM storage
http://niktips.wordpress.com/2012/09/17/windows-mpio-with-ibm-storage/

Posted in IBM Storage, Windows | Leave a Comment »

Best practices for DNS settings on DC and domain members

Posted by bartvdw on 1717/0707/2013

Very good and to the point summary!

http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/

Posted in Active Directory, DNS, Microsoft, Windows | Leave a Comment »

VMware: 101 Free Tools

Posted by bartvdw on 1010/0707/2013

101 FREE TOOLS FOR VMWARE ADMINISTRATORS
http://www.vmwarearena.com/2013/06/101-free-tools-for-vmware-administrators.html

Posted in ESX(i), VMware, vSphere | 1 Comment »

Symantec BE 2012 & VMware: Snapshot problems (unable to quiesce an application)

Posted by bartvdw on 1010/0707/2013

Backup Exec 2012 – An attempt to take a snapshot of a virtual machine failed because it was unable to quiesce an application

http://restingsysadmin.wordpress.com/2013/06/21/backup-exec-2012-an-attempt-to-take-a-snapshot-of-a-virtual-machine-failed-because-it-was-unable-to-quiesce-an-application/

Posted in Backup Exec, ESX(i), Tech Stuff, VMware, vSphere | Leave a Comment »

VMware: Cool Tool – VisualEsxtop

Posted by bartvdw on 1010/0707/2013

Cool Tool: VisualEsxtop
http://www.yellow-bricks.com/2013/07/08/cool-tool-visualesxtop/

Posted in ESX(i), VMware, vSphere | Leave a Comment »

VMware: Education Services

Posted by bartvdw on 1111/0606/2013

http://vmwarelearning.com

Posted in ESX(i), vCenter, VMware, vSA, vSphere | Leave a Comment »

WSUS: Automatically Declining Itanium Updates

Posted by bartvdw on 0606/0505/2013

This is quiet useful, and easier then using the GUI to filter them out…

Automatically Declining Itanium Updates in WSUS
http://gallery.technet.microsoft.com/scriptcenter/Automatically-Declining-a4fec7be

Adapt the code if you don’t want to have an email sent (ex. output to screen or dump in a text file).

Posted in PowerShell, WSUS | 5 Comments »