<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msforge.net/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Vlada&amp;#39;s Blog</title><subtitle type="html">Tips &amp;amp; Tricks from Real World Situations.</subtitle><id>http://msforge.net/blogs/vlada/atom.aspx</id><link rel="alternate" type="text/html" href="http://msforge.net/blogs/vlada/default.aspx" /><link rel="self" type="application/atom+xml" href="http://msforge.net/blogs/vlada/atom.aspx" /><generator uri="http://communityserver.org" version="4.0.30417.1769">Community Server</generator><updated>2008-03-12T18:30:00Z</updated><entry><title>WSS 3.0 0x8007005 Installation Error</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2009/09/15/wss-3-0-0x8007005-installation-error.aspx" /><id>/blogs/vlada/archive/2009/09/15/wss-3-0-0x8007005-installation-error.aspx</id><published>2009-09-15T15:10:00Z</published><updated>2009-09-15T15:10:00Z</updated><content type="html">&lt;p&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Scenario:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Working on a client site recently, I have installed Windows Sharepoint Services 3.0 in a stand-alone server mode. Everything worked fine until I&amp;#39;ve opened Central Administration Site and realized that the person who gave me access to the server logged me on as a local server administrator. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Since the server was member of a company domain, I decided to reinstall WSS in order to avoid future problems (actually I remember that I read somewhere that it is not a good practice doing WSS installation as a local server Administrator).&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;So, I uninstalled WSS 3.0, manually deleted Sharepoint Central Administration Site web site (have no idea why it wasn&amp;#39;t deleted automatically), restarted server, logged on as a domain user which was member of local Administrators group, and started setup again.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Everything worked fine, until step &lt;b&gt;8 of 10 &lt;/b&gt;of &amp;quot;&lt;i&gt;Sharepoint Products and Technologies Wizard&amp;quot;&lt;/i&gt;....In a blink of an eye I saw the status message &amp;quot;&lt;i&gt;Error creating Sample Site&lt;/i&gt;&amp;quot; or something similar, and then window with this message appeared:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;&lt;em&gt;HRESULT: 0x80070005 E_ACCESSDENIED&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Reason:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;I had no time and will to research further &amp;quot;why and where&amp;quot;....but even after complete remove and reinstall, WSS 3.0 was still keeping information that the Primary administrator of a first sample site collection is SERVER\Administrator, from the first installation, instead of the DOMAIN\WSSadmin who did the most recent installation.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Solution:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;A lot of Googling pointed me to problem with WMI DCOM configuration and lack of permission for the local ASPNET account....not in my case...;)&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Since the Central Administration Site was fully functional, I&amp;#39;ve accessed Application Management Section, removed SERVER\Administrator from Primary admin, added domain user account DOMAIN\WSSadmin as the Primary admin and re-run Sharepoint Technologies Wizard.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;This time everything worked fine.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:5pt 0cm;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Conclusions/Advices:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;"&gt;Create domain user account for WSS admin, make it member of server&amp;#39;s local Administrators group and use it for WSS installation and initial administration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=3739" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Sharepoint" scheme="http://msforge.net/blogs/vlada/archive/tags/Sharepoint/default.aspx" /></entry><entry><title>KERBEROS error 4 (Part II)</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2009/09/03/kerberos-error-4-part-ii.aspx" /><id>/blogs/vlada/archive/2009/09/03/kerberos-error-4-part-ii.aspx</id><published>2009-09-03T19:48:00Z</published><updated>2009-09-03T19:48:00Z</updated><content type="html">&lt;p&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;Scenario:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;For&amp;nbsp;an unknown reason Domain Controller in a branch office stopped to replicate Active Directory data with Domain Controllers in the main site.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;DCDIAG showed this:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;[DC1] DsBindWithSpnEx() failed with error -2146893022,&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;The target principal name is incorrect..&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;Warning: DC1 is the Schema Owner, but is not responding to DS RPC Bind.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;[DC1] LDAP bind failed with error 8341,&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;A directory service error has occurred..&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;Warning: DC1 is the Schema Owner, but is not responding to LDAP Bind.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;Warning: DC1 is the Domain Owner, but is not responding to DS RPC Bind.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;Warning: DC1 is the Domain Owner, but is not responding to LDAP Bind.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;DC1&amp;nbsp;is a Domain Controller in the main site with all FSMO roles.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;Event viewer kept logging Error from source Kerberos and EventID 4 :&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/.... The target name used was..... This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;Commonly, this is due to identically named machine account in the target realm (...), and the client realm. &lt;/span&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;And at the end my favorite sentence:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:&amp;#39;Courier New&amp;#39;;mso-ansi-language:EN-US;"&gt;Please contact your system administrator. &lt;/span&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;Have they ever considered a very small possibility that the one who is reading this message in the&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;System log of a Domain Controller might be actually &amp;quot;&lt;em&gt;our&lt;/em&gt; &lt;i style="mso-bidi-font-style:normal;"&gt;System Administrator&amp;quot; ...;))&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;strong&gt;Screenshot from Event Viewer:&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;img src="http://msforge.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/vlada/k4.JPG" alt="" /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;Reason:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;Yet another classic problem, solved many times never documented it before...have no idea why, it just happens from time to time.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Tahoma;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;Solution:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;If you want to solve this problem quickly run:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span&gt;&lt;em&gt;dcpromo /forceremoval &lt;/em&gt;on branch office DC&lt;em&gt;, &lt;/em&gt;restart server, and run &lt;i&gt;dcpromo&lt;/i&gt; again.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;Almost all Google results on this subjects points to NETDOM and reset computer account. Never worked for me.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;Conclusion/Advice:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:8pt;font-family:Verdana;mso-bidi-font-family:Verdana;mso-ansi-language:EN-US;"&gt;If you have branch offices connected with slow and unreliable links and a Domain Controller in it, bookmark this page.....this can happen to you too....;)&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=3643" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Active Directory" scheme="http://msforge.net/blogs/vlada/archive/tags/Active+Directory/default.aspx" /></entry><entry><title>File Server Migration Story</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2009/06/26/file-server-migration-story.aspx" /><id>/blogs/vlada/archive/2009/06/26/file-server-migration-story.aspx</id><published>2009-06-26T16:09:00Z</published><updated>2009-06-26T16:09:00Z</updated><content type="html">&lt;p&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Scenario:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;On of my clients have recently bought a new server box and an external storage system, and my task was to migrate all files and folders to the new system while interrupting users at least as possible (damn users&amp;hellip;;).&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Requirements:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;1) The old file server (&lt;b&gt;SERVER1&lt;/b&gt;) had 4 physical disks partitioned as &lt;b&gt;D&lt;/b&gt;,&lt;b&gt;E&lt;/b&gt;,&lt;b&gt;F&lt;/b&gt; and &lt;b&gt;G&lt;/b&gt; with lots of shared folders and defined NTFS permissions, and new storage system was visible as a single drive &lt;b&gt;S&lt;/b&gt; from the new server (&lt;b&gt;SERVER2&lt;/b&gt;). &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;2) The old server (&lt;b&gt;SERVER1&lt;/b&gt;)&amp;nbsp;must not be removed from production because it had hardware and software which was controlling external tape backup device system.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Steps:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 14.2pt;text-indent:-14.2pt;mso-layout-grid-align:none;tab-stops:14.2pt;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;1)&lt;span style="mso-tab-count:1;"&gt;&amp;nbsp; &lt;/span&gt;First step was to migrate files, folders, shares and NTFS permissions from multiple drives on &lt;b&gt;SERVER1&lt;/b&gt; to a single drive on &lt;b&gt;SERVER2&lt;/b&gt;. Tasks included:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 74pt;text-indent:-18pt;mso-layout-grid-align:none;tab-stops:72.0pt;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Stopped &lt;i&gt;Server&lt;/i&gt; service on &lt;b&gt;SERVER1&lt;/b&gt; so it was not anymore accessible for file sharing to clients.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 74pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Using software from the tape manufacturer backed up all folders onto tapes. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 74pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Joined the new server (&lt;b&gt;SERVER2&lt;/b&gt;) to domain and restored backup on a drive &lt;b&gt;S&lt;/b&gt; (RAID-5 on storage system), while preserving NTFS permissions.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 74pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Exported &lt;i&gt;HKEY_LOCAL_MACHINE\SYSTEM\Current Control Set\Services\LanmanServer\Shares&lt;/i&gt; from &lt;b&gt;SERVER1&lt;/b&gt; and imported it into the same place on &lt;b&gt;SERVER2&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 74pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Corrected manually all references for &lt;b&gt;D&lt;/b&gt;,&lt;b&gt;E&lt;/b&gt;, &lt;b&gt;F&lt;/b&gt; and &lt;b&gt;G&lt;/b&gt; drives to point to letter &lt;b&gt;S&lt;/b&gt; (actually I delegated this task to one of my junior squad member...;).&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 74pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Restarted &lt;i&gt;Server&lt;/i&gt; service on &lt;b&gt;SERVER2&lt;/b&gt; and checked that all shares are correctly recreated. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 22.7pt;text-indent:-22.7pt;mso-layout-grid-align:none;tab-stops:22.7pt;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;2) Second step was to redirect clients to &lt;b&gt;SERVER2&lt;/b&gt; without modifying paths in client&amp;#39;s mapped folders and shortcuts. Tasks included:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 68.35pt;text-indent:-18pt;mso-layout-grid-align:none;tab-stops:66.35pt;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Modified &lt;b&gt;SERVER1&lt;/b&gt; &amp;quot;&lt;i&gt;Local Area Connection&lt;/i&gt;&amp;quot; properties and cleared &amp;quot;&lt;i&gt;Register this connection&amp;#39;s address in DNS&lt;/i&gt;&amp;quot; and removed IP address of WINS server in TCP/IP properties.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 68.35pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Created DNS alias for &lt;b&gt;SERVER1&lt;/b&gt; name to point to the IP address of &lt;b&gt;SERVER2&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 68.35pt;text-indent:-18pt;mso-layout-grid-align:none;mso-list:l0 level1 lfo1;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Symbol;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&amp;middot;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Deleted WINS record for &lt;b&gt;SERVER1&lt;/b&gt; and created a new static unique mapping with the IP address of&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;b&gt;SERVER2&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Problems:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:9pt;color:#333333;font-family:Tahoma;"&gt;System error 52 has occurred.&lt;br /&gt;A duplicate name exists on the network.&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:9pt;color:#333333;font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;color:#333333;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Lucky me, I was already familiar with this one from one of my previous projects, and remembered that it has to do with something called &amp;quot;strict name checking&amp;quot; in Windows 2003 server. And so Google &lt;span style="color:#333333;"&gt;pointed me to Microsoft KB article:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&lt;a href="http://support.microsoft.com/kb/281308"&gt;http://support.microsoft.com/kb/281308&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;After adding &lt;i&gt;&lt;span style="color:black;"&gt;DisableStrictNameChecking &lt;/span&gt;&lt;/i&gt;&lt;span style="color:black;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;value under&lt;/span&gt; &lt;b&gt;&lt;span style="color:black;"&gt;HKEY_LOCAL_MACHINE\System\Current Control Set\Services\LanmanServer\Parameters&lt;/span&gt;&lt;/b&gt;&lt;span style="color:black;"&gt;, setting it to 1 and restarting the server .... new error appeared:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;color:red;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;System error 5&lt;br /&gt;Access is denied.&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:9pt;color:red;font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;color:#333333;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;color:#333333;font-family:Tahoma;"&gt;This was new, even to me....;))&lt;/span&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Reason:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;I guess that KB 281308 assumes that there is no other server in production called like given alias or that the old file server is permanently offline. In this scenario &lt;b&gt;SERVER1&lt;/b&gt; was still online and had account in Active Directory. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;Solution:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;After I renamed SERVER1 into something different, like SERVER1OLD and restarted it everything worked fine....:) &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:9pt;font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=3340" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Active Directory" scheme="http://msforge.net/blogs/vlada/archive/tags/Active+Directory/default.aspx" /><category term="Server" scheme="http://msforge.net/blogs/vlada/archive/tags/Server/default.aspx" /></entry><entry><title>Internet Explorer 8.0 Beta 2 and Exchange 2003 OWA Problem</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2008/10/21/internet-explorer-8-0-beta-2-and-exchange-2003-owa-problem.aspx" /><id>/blogs/vlada/archive/2008/10/21/internet-explorer-8-0-beta-2-and-exchange-2003-owa-problem.aspx</id><published>2008-10-21T19:45:00Z</published><updated>2008-10-21T19:45:00Z</updated><content type="html">&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Scenario:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;An advanced user from one of the company with which I have maintenance contract called me yesterday, asking for an advice. He was complaining that he cannot access OWA anymore since he has upgraded his Internet Explorer from version 7.0 to version 8.0 Beta 2. He was using Vista, and explained that he read in a local PC magazine that IE8 B2 is very stable version and listened to author&amp;rsquo;s advice to upgrade his &amp;ldquo;old&amp;rdquo; version of IE 7.0 to version 8.0 as soon as possible&amp;hellip;.;)&amp;hellip;nice&amp;hellip;.!&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Everything worked fine, except that he couldn&amp;rsquo;t access OWA anymore. Logon screen was appearing, but upon successful logon IE8 kept crashing.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Reason:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Have no idea&amp;hellip;but &lt;i style="mso-bidi-font-style:normal;"&gt;Google&lt;/i&gt; showed me that I am not the first one complaining, there were few users out there with similar problem.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Solution:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;So, I adviced him to uninstall IE 8.0. But&amp;hellip;not long after, he called me again saying that there is no Internet Explorer 8.0 or something similar under Vista&amp;rsquo;s Control Panel &amp;ldquo;Program and Features&amp;rdquo; ?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Well, of course...;), because Internet Explorer 8.0 is not a &amp;ldquo;Program&amp;rdquo; anymore, it is now &lt;i style="mso-bidi-font-style:normal;"&gt;update&lt;/i&gt; to Windows, so I told him to click on &amp;ldquo;&lt;i style="mso-bidi-font-style:normal;"&gt;View installed updates&lt;/i&gt;&amp;rdquo; on the top left corner of Vista&amp;rsquo;s Control Panel &amp;ldquo;Program and Features&amp;rdquo;, and uninstall it from there&amp;hellip;.:)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Conclusions/Advices:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt 36pt;text-indent:-18pt;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-fareast-font-family:Tahoma;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;span style="font-size:small;"&gt;1.&lt;/span&gt;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Wait for the final release of Internet Explorer 8.0, especially in production environments. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt 36pt;text-indent:-18pt;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-fareast-font-family:Tahoma;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;span style="font-size:small;"&gt;2.&lt;/span&gt;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;#39;Tahoma&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;Don&amp;rsquo;t believe in articles you read in local PC magazines...;)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=2540" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Exchange/Outlook" scheme="http://msforge.net/blogs/vlada/archive/tags/Exchange_2F00_Outlook/default.aspx" /></entry><entry><title>Exchange 2007 ‘Sender Reputation Filter’ Story</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2008/10/16/exchange-2007-sender-reputation-filter-story.aspx" /><id>/blogs/vlada/archive/2008/10/16/exchange-2007-sender-reputation-filter-story.aspx</id><published>2008-10-16T19:34:00Z</published><updated>2008-10-16T19:34:00Z</updated><content type="html">&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Prologue:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="vertical-align:top;line-height:140%;"&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;&lt;span style="font-size:8pt;color:black;line-height:140%;font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&amp;ldquo;Sender Reputation is anti-spam functionality that is enabled on computers that have the Microsoft&amp;nbsp;Exchange&amp;nbsp;Server&amp;nbsp;2007 Edge Transport server role installed to block messages according to many characteristics of the sender. Sender reputation relies on persisted data about the sender to determine what action, if any, to take on an inbound message. &amp;ldquo;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p align="right" style="vertical-align:top;line-height:140%;text-align:right;"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;&lt;span style="font-size:8pt;color:black;line-height:140%;font-family:&amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Microsoft , 2006.&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Scenario:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;One of my old clients called me recently, saying that they have bought some new server boxes and, beside other changes, asking for best advice how to improve their e-mail infrastructure from both, performance and security aspects. They were using &lt;b style="mso-bidi-font-weight:normal;"&gt;Exchange 2003&lt;/b&gt; with &lt;b style="mso-bidi-font-weight:normal;"&gt;GFI Mail Security &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;Antivirus and &lt;b style="mso-bidi-font-weight:normal;"&gt;GFI Mail Essentials &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;Antispam protection that I have installed some time ago. They also have dedicated &lt;b style="mso-bidi-font-weight:normal;"&gt;ISA&lt;/b&gt; server for proxy/firewall functionality:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Exchange 2003 (+GFI) &amp;lt;--------------------&amp;gt; ISA &amp;lt;----------------&amp;gt; &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;INTERNET&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;My advice to them was to migrate to &lt;b style="mso-bidi-font-weight:normal;"&gt;Exchange 2007&lt;/b&gt;, and also to implement a &lt;i style="mso-bidi-font-style:normal;"&gt;Windows 2003 Web Edition Server &lt;/i&gt;in DMZ to act as a SMTP relay server, with &lt;b style="mso-bidi-font-weight:normal;"&gt;GFI Mail Security&lt;/b&gt; and &lt;b style="mso-bidi-font-weight:normal;"&gt;GFI Mail Essentials&lt;/b&gt; installed on that server. Since they were already paying for Exchange Enterprise CALs in their licensing program I suggested &lt;b style="mso-bidi-font-weight:normal;"&gt;Forefront Security&lt;/b&gt; on internal Exchange (with 9 Antivirus and 2 Antispam engines they should be pretty safe&amp;hellip;.;)):&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Exchange 2007 (+Forefront) &amp;lt;-------&amp;gt; ISA &amp;lt;------&amp;gt; IIS SMTP relay (+GFI) &amp;lt;----&amp;gt; INTERNET&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;I&amp;rsquo;ve installed &lt;b style="mso-bidi-font-weight:normal;"&gt;GFI&lt;/b&gt; modules on Relay server and configured Antispam engine to append string &amp;ldquo;&lt;i style="mso-bidi-font-style:normal;"&gt;[SPAM]&lt;/i&gt;&amp;rdquo; in subject line for every message that is likely to be spam. Then, I created Transport Rule on Exchange server to increase &lt;b style="mso-bidi-font-weight:normal;"&gt;SCL&lt;/b&gt; level for this type of messages to &lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;9&lt;/i&gt;&lt;/b&gt; so that they always end in user&amp;rsquo;s Outlook &lt;i style="mso-bidi-font-style:normal;"&gt;Junk E-mail&lt;/i&gt; folder.&lt;br /&gt;I&amp;lsquo;ve tested this configuration by &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;sending a few legitimate mails and also few with &amp;ldquo;&lt;i style="mso-bidi-font-style:normal;"&gt;sex $$$ Viagra&lt;/i&gt;&amp;rdquo; in subject and/or body, and everything worked perfectly (not a good sign&amp;hellip;.;))&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Problem:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;Not very long after, some of the employees said that&amp;nbsp;their clients are complaining that all messages sent to&amp;nbsp;them are rejected by our mail server. &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;br /&gt;&lt;/span&gt;From Relay server, I&amp;#39;ve succesfuly telneted to port 25 on internal Exchange server, and&amp;nbsp;typed:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;HELO test.test.net&lt;br /&gt;Mail from:test@test.net&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;and got this response:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;" class="MsoPlainText"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;"&gt;&lt;span style="font-size:small;"&gt;550 5.7.1 External client with IP address 172.16.0.1 does not have permissions to submit to this server. Visit &lt;/span&gt;&lt;a href="http://support.microsoft.com/kb/928123"&gt;&lt;span style="font-size:small;color:#0000ff;"&gt;http://support.microsoft.com/kb/928123&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt; for more information.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;" class="MsoPlainText"&gt;&lt;span style="font-size:small;font-family:Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 0pt;" class="MsoPlainText"&gt;&lt;span style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:minor-latin;"&gt;&lt;span style="font-size:small;"&gt;172.16.0.1 was IP address of external interface on ISA server&amp;hellip;?!&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Reason:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;Sender reputation filter has characterized my own ISA server as a spammer, and added it to IP Block List for 24 hours..&amp;hellip;;))&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Solution:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin:0cm 0cm 10pt;" class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Calibri;"&gt;I&amp;rsquo;ve removed 172.16.0.1 from IP Block List on Exchange server, add it to IP allow list and disabled Sender Reputation filter..&amp;hellip;just in case&amp;hellip;;)&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=2480" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Exchange" scheme="http://msforge.net/blogs/vlada/archive/tags/Exchange/default.aspx" /></entry><entry><title>Outlook 2007 and Default Gateway problem</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2008/09/29/outlook-2007-and-default-gateway-problem.aspx" /><id>/blogs/vlada/archive/2008/09/29/outlook-2007-and-default-gateway-problem.aspx</id><published>2008-09-29T16:19:00Z</published><updated>2008-09-29T16:19:00Z</updated><content type="html">&lt;p&gt;Since it is very popular to use Office 2007 nowadays, I&amp;#39;ve recently received a call from IT manager of a mid-size company (with whitch I have regular maintenance contract) to upgrade few machines from Office 2003 to Office 2007. They use Exchange 2003 Server with Outlook MAPI clients.&lt;/p&gt;
&lt;p&gt;Great job for one of my junior squad members, I thought, and send one of them to do the job.&lt;/p&gt;
&lt;p&gt;Not a long after, he called me saying that everything goes smooth but Outlook 2007 is reporting the error:&lt;br /&gt;&amp;quot;&lt;em&gt;The action cannot be completed. The connection to the Microsoft Exchange Server is unavailable. Your network adapter does not have a default gateway.&lt;/em&gt;&amp;quot; &lt;/p&gt;
&lt;p&gt;That was, actually, true.&amp;nbsp;By design, the&amp;nbsp;only way the user can access Internet was&amp;nbsp;through proxy settings in their browsers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reason:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;It is documented in &lt;a href="http://support.microsoft.com/kb/913843"&gt;http://support.microsoft.com/kb/913843&lt;/a&gt; saying that&amp;nbsp; &amp;quot;&lt;em&gt;This problem may occur if the Outlook 2007 client computer does not have a default gateway configured.&lt;/em&gt;&amp;quot; !??&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution (part I):&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I found that KB article and told him to navigate to &amp;quot;&lt;em&gt;HKEY_CURRENT_USER\Software\Microsoft\Office\12.0\Outlook\RPC&lt;/em&gt;&amp;quot; and add DWORD value &lt;strong&gt;DefConnectOpts&lt;/strong&gt; vith value data of &lt;strong&gt;0&lt;/strong&gt;.&lt;br /&gt;The only problem was that there was no &amp;quot;&lt;em&gt;RPC&lt;/em&gt;&amp;quot; subkey above &amp;quot;&lt;em&gt;HKEY_CURRENT_USER\Software\Microsoft\Office\12.0\Outlook&lt;/em&gt;&amp;quot; key !?&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Solution (part II):&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If there is no subkey, maybe we should try to add it manually...and guess what...it worked...;)&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Conclusion:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;It is not a network if you don&amp;#39;t have Default Gateway....;))..?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=2419" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Exchange/Outlook" scheme="http://msforge.net/blogs/vlada/archive/tags/Exchange_2F00_Outlook/default.aspx" /></entry><entry><title>Certificate request problem - Error 0x00000046</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2008/04/19/certificate-request-problem-error-0x00000046.aspx" /><id>/blogs/vlada/archive/2008/04/19/certificate-request-problem-error-0x00000046.aspx</id><published>2008-04-19T12:43:00Z</published><updated>2008-04-19T12:43:00Z</updated><content type="html">&lt;p&gt;I&amp;#39;ve already resolved this one couple of times, but never document it before...;)&lt;/p&gt;
&lt;p&gt;Yesterday, one of my clients called explaining me that secure section (https) of the internal web site is &amp;quot;not working&amp;quot; anymore. They use combination of IE 6, IE 7 and Firefox browsers, and said that in IE 6 and Firefox browsers popup window asks from them to continue, and IE 7 displays the page where users are asked to click on Continue link.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reason:&lt;/strong&gt; &lt;br /&gt;It was obviously certificate problem, and after further investigation I found that certificate has expired.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution: &lt;br /&gt;&lt;/strong&gt;So, I&amp;#39;ve opened IIS Manager on the local Microsoft Windows 2003 Server and removed current certificate from secure portion of the web site. After that, I requested new certificate with the same parameters from online certification authority (Certificate Services running on the same server), completed the wizard successfully...and...nothing happened ?. Certificate was not generated...!?&lt;/p&gt;
&lt;p&gt;Restart of Certificate Services didn&amp;#39;t solve the problem.&lt;/p&gt;
&lt;p&gt;Then, I&amp;#39;ve tried the alternate method through &lt;em&gt;%servername%/certsrv&lt;/em&gt;, Advanced Certificate Request -&amp;gt; Web Server. After completing the form, and clicking on Submit button the following error appeared:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Advanced Certificate Request:&lt;/strong&gt; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;quot;An error occurred while creating the certificate request. Please verify that your CSP supports any settings you have made and that your input is valid.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Suggested cause:&lt;br /&gt;You do not have write permission to save the file to the path Error: 0x00000046 - Permission Denied &amp;quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;The problem was in permissions on local certificate store on CA server:&lt;br /&gt;&lt;em&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Administrators&lt;/strong&gt; and &lt;strong&gt;SYSTEM&lt;/strong&gt; group needs Full Control permissions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Advice:&lt;br /&gt;&lt;/strong&gt;Renew your certificates before expiration.....;)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=1662" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Active Directory" scheme="http://msforge.net/blogs/vlada/archive/tags/Active+Directory/default.aspx" /></entry><entry><title>OWA and PDF attachment problem</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2008/04/15/owa-and-pdf-attachments-problem.aspx" /><id>/blogs/vlada/archive/2008/04/15/owa-and-pdf-attachments-problem.aspx</id><published>2008-04-15T21:37:00Z</published><updated>2008-04-15T21:37:00Z</updated><content type="html">&lt;p&gt;A few days after successful implementation of Microsoft Small Business Server 2003 in a very small company, the Owner called me complaining that he cannot open PDF documents with a single click in OWA, while some of his employees can do that without any problems.&lt;/p&gt;
&lt;p&gt;Because I don&amp;#39;t believe end users (especially owners and managers), I logged with his credentials and tried to open the PDF attachment. This message appeared:&lt;br /&gt;&lt;em&gt;&amp;quot;To open this attachment, you must save it to your disk. Right-click the link, and then click Save. With a single-button mouse, hold the button down over the link, and then click Save.&amp;quot;&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;Logging into OWA with other user credentials (one of the employees) from the same computer opened pdf with no problem into Internet Explorer. They were both members of Domain Users and local Administrators groups.&lt;/p&gt;
&lt;p&gt;Huh ?&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve been already somewhat familiar with attachment blocking in OWA explained in:&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=555001"&gt;http://support.microsoft.com/?kbid=555001&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;They say that &lt;em&gt;&amp;quot;Level2 attachments have file extensions that can be accessed, but only if saved to the client&amp;#39;s file system first.&amp;quot;&lt;/em&gt;&lt;br /&gt;But there is no PDF extension defined in &lt;strong&gt;Level2FileTypes&lt;/strong&gt; registry key that could explain this behavior ?!&lt;/p&gt;
&lt;p&gt;Investigating further I found that Exchange server 2003 SP1 introduces two new registry values&lt;br /&gt;&lt;strong&gt;level1mimetypes&lt;/strong&gt; and &lt;strong&gt;level2mimetypes&lt;/strong&gt; but I couldn&amp;#39;t find application/pdf or&amp;nbsp;anything similar.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reason:&lt;br /&gt;&lt;/strong&gt;No idea...?&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Solution:&lt;br /&gt;&lt;/strong&gt;In the normal situation I would suggest the owner to follow that procedure because there are different security policies for the owner than from employees...or something similar...;)..but not with this one.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;So at the end, I&amp;nbsp;found the&amp;nbsp;solution ...after removing &amp;quot;&lt;strong&gt;application/octetstream&lt;/strong&gt;&amp;quot; from &amp;quot;&lt;strong&gt;HKLM\SYSTEM\Current Control Set\Services\MSExchangeWEB\level2mimetypes&lt;/strong&gt;&amp;quot; PDF files opened with a single click in OWA, everything worked fine, everybody was pleased and......I was paid for my job...;))&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Advice:&lt;br /&gt;&lt;/strong&gt;Install OWAADMIN.EXE tool from Microsoft site if you want to simplify/avoid registry editing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=1646" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Exchange/Outlook" scheme="http://msforge.net/blogs/vlada/archive/tags/Exchange_2F00_Outlook/default.aspx" /></entry><entry><title>KERBEROS error 4</title><link rel="alternate" type="text/html" href="/blogs/vlada/archive/2008/03/12/kerberos-error-4.aspx" /><id>/blogs/vlada/archive/2008/03/12/kerberos-error-4.aspx</id><published>2008-03-12T17:30:00Z</published><updated>2008-03-12T17:30:00Z</updated><content type="html">&lt;p&gt;A few days ago one of my clients asked me to migrate ISA services from his old hardware to a brand new HP server.&lt;/p&gt;
&lt;p&gt;Easy...;)&lt;/p&gt;
&lt;p&gt;I joined the new server to the domain, duplicated network configurations (while disconnected, of course), copied hosts file, XML export-import ISA settings, disabled unnecessary services...etc. &lt;br /&gt;At the end I removed the old box with the new one and connected it to the company network.&lt;br /&gt;We tested inbound and outbound rules and everything worked fine. &lt;/p&gt;
&lt;p&gt;Except...one of the domain controller (PDC emulator) started to report this event into its System log, every now and then:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/isa.company.com.&amp;nbsp; The target name used was HTTP/firewall.company.com. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named&amp;nbsp; machine accounts in the target realm (COMPANY.COM), and the client realm.&amp;nbsp;&amp;nbsp; Please contact your system administrator.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reason:&lt;br /&gt;&lt;/strong&gt;The new server had a different name (ISA) than the old one (FIREWALL).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution:&lt;br /&gt;&lt;/strong&gt;I deleted A record &amp;quot;firewall&amp;quot; from the company DNS zone and the error disappeared.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Advice:&lt;/strong&gt;&lt;br /&gt;I prefer to use DNS CNAME &amp;quot;proxy&amp;quot; that points to the real name of company&amp;#39;s ISA server. In the previous example nothing had to be changed on client machines, because they were already configured with &amp;quot;proxy.company.com&amp;quot; string in proxy settings on their&amp;nbsp;internet browers (through group policy).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msforge.net/aggbug.aspx?PostID=1115" width="1" height="1"&gt;</content><author><name>Vlada.Ilic</name><uri>http://msforge.net/members/Vlada.Ilic/default.aspx</uri></author><category term="Active Directory" scheme="http://msforge.net/blogs/vlada/archive/tags/Active+Directory/default.aspx" /></entry></feed>
