Showing posts with label Miscellaneous. Show all posts
Showing posts with label Miscellaneous. Show all posts

Thursday, March 15, 2012

HSPD-12 and Active Directory Domains -Documents Updated

Microsoft has updated their documentation regarding HSPD-12 Logical Access Authentication and Active Directory Domains

These documents are probably going to be more valuable to those that support federal customers in the US but they are a good read for anyone planning to deploy smart cards in their environment.

For those not familiar with HSPD-12 in a nut shell it is a mandate for federal organizations to issue common ID/Smart cards to their users.  This comes into play in the Active Directory arena as the cards are used for login using two-factor authentication/smart card login.  The two-factors in this case are:

  • Something the user has - the smart card
  • Something the user knows - PIN

Everyone has seen this referenced in the Account tab of a user in AD Users & Computers.



Those in the military or who have supported US Military customers will hear the term CAC Card used for their smart cards. Those supporting civilian agencies/.gov will hear the term PIV Card for their smart cards.

You can get the updated Microsoft documentation here:

Kurt Hudson has a good quote about the documents on the Windows PKI Blog

Included within this document are detailed steps to configure Windows Server 2008 R2 Active Directory Domain Services (AD DS), Active Directory Certificate Services (AD CS), Windows® 7, and Microsoft® Office 2010 to perform traditional UPN based smart card logon, explicit smart card logon (client authentication certificate mapped to multiple accounts), explicit cross-forest smart card logon and NIST SP800-78-3 compliant S/MIME email exchanges. 
Smart card/HSPD-12 adoption within agencies varies.  DoD has definitely been the leader in this space.  There are other agencies that I've been at that are also rolling but there are also those that haven't even started issuing smart cards to the majority of their users yet.   I'm not naming names here :)



Wednesday, March 9, 2011

Microsoft Premier Field Engineering Platform Reporting Tool

Microsoft has released an updated MPS Reports Tool.

Microsoft Premier Field Engineering Platform Reporting Tool

If you open a call with Microsoft you will often be told to upload the MPS reports. The reports can take a while to run to I always recommend running them before hand or as you are calling.

Friday, March 5, 2010

THANK YOU SECRET SERVICE - ID Theft Old School Style

I wanted to take a moment and dedicate an entry to thanking the US Secret Service.

Those that know me in “real life” know that my apartment was robbed in August of 2008. It sucked liked you can imagine. To come home after work and have every electronic device and other items gone and having the place totally trashed obviously sucks.

At the time the local police didn’t find the person that did it and closed the case. They let me know in a letter.

Fast forward to last month and I received a message from a secret service agent in the Washington D.C. field office telling me that I’m potentially a victim of ID theft. Like most people that come to this blog I’m fairly good at protecting private information on my computer. I run security measures and have anti-spyware/virus running. I use complex passwords, etc. So my first thought went back to the robbery.

When the agent called me back he told me that they had found some of my old military documents and student loan documents during a raid on a local house. It turns out the guy that robbed me had gone and stolen the master key from several apartment complexes and then broke in after that. I always thought it could have been inside job from someone that either worked or had worked for the apartment complex because there was no forced entry but now I found out why it was so clean.

In the immediate aftermath of the robbery I knew all my physical stuff was gone but I didn’t realize that he had taken my documents. There was crap all over the place and every drawer was dumped (like you see in a movie or TV show) so in terms of documents I didn’t know what was missing (mistake 1)

However that day I did remember all the lifelock commercials and signed up for their service within 30 minutes of the robbery. Some things I wish I would have done differently now looking back and hopefully lessons learned for people reading this.


  • Scan and backup all important documents and take those backups off site or backup to the cloud (many services available). I did backup to encrypted hard drives but those were all in my apartment. One of the things that saved me is that he didn’t take my external hard drives. All three he just unplugged and tossed to the ground but he may have not known what they were. (if he would have taken those it would have been a much harder thing to deal with)

  • Get renters insurance if you live in an apartment. My number 1 mistake in my opinion. I thought that because I lived in a decent neighborhood I didn’t need it and never got it. It was only around $125 a year once I got it after the robbery

  • Take an inventory of all your documents. I had documents in some file folders in different places and that is why I didn’t realize they were missing. I didn’t have good inventory control

  • If you can afford an alarm system get one; but what I’ve realized is just a siren is probably good enough. The local police don’t come to alarm calls with lights and sirens unless there is eminent danger. I once made it home in 20 minutes during a false alarm (I got an alarm system after the robbery). I beat the cops to the place. I understand why they don’t come with lights/sirens but the robber won’t know if the alarm system is armed or not.

  • If you can’t afford an alarm system or don’t want to pay just get the stickers and put them up. Easy enough to get them from eBay

  • Sign up for some sort of monitoring service. I went with lifelock because that is what I could remember the day I got robbed but there are a lot of good companies that do this.

  • Encrypt anything you don’t want seen if your computer gets stolen. I don’t encrypt everything (for instance my music); but documents and anything of real value gets encrypted

  • Get some sort of small safe for important documents (passports, birth certificates, etc). These are not super expensive. For an apartment you can get one fairly cheap. It may not bolt to the ground and he may have taken it but it would have been hard for this amateur to break into it.




The one thing I’m still torn on is a gun. I didn’t have one in the apartment because I thought anyone that broke in while I was there would get to me before I could go for the gun (small one bedroom). This guy also went through every nook and cranny of the place and would have found the gun if I had it out. What if I would have walked in on him during it and he had my gun…could have been ugly. If I would have had it in a safe then he would have taken the safe but that would have been much safer.

So far it looks like my ID hasn’t been stolen or used. I’m still monitoring the situation and have put out alerts to my creditors.

The secret service agent was very cool and is going to get my documents back to me. He also told me the local police are going after the guy on all the robbery charges but the secret service is going after him on Federal charges for the ID thefts. The agent said “we hope to put him in jail for a long time”. Again THANKS to this agent and the entire secret service!!

I hope no one that reads this ever has to go through a robbery but in the end the important thing is that people are safe and things can be replaced (I know that is a cliché but it is true)

...last but not least, if anyone knows how to get fingerprint dust out of a carpet please comment and let me know :)

Thursday, November 12, 2009

Great new Microsoft/AD Blog

My friend Rich and his brothers Jared and Chris have started a really great blog that deals with Active Directory and Microsoft technologies. I highly recommed adding this blog to your reading list or favorite RSS reader.

http://cbfive.com/blog/

They already have a good number of entries up so enjoy and I'm sure you will agree that Rich, Jared, and Chris have done a really great job.

Congrats CB5!!!

Wednesday, April 22, 2009

Lessons Learned from Eric Fleischman

As previously mentioned I attended the Philly.NET users group Code Camp on Saturday 4/18/2009.

I had the great privilege to sit through two sessions from Eric Fleischman.

Who is Eric Fleischman you ask?

Eric is currently the Dev Lead for Virtualization(cloud services) at Microsoft. Eric has also been a lead developer on the AD team for Microsoft. When it comes to those that know AD the best there is no debate...Eric makes that list.

One of Eric's best known projects in the AD community was creating the largest Active Directory known to date.

What I wanted to do is list some of the things I picked up.


    • Always make every DC a GC, assume you can do that unless you can prove that your bandwidth can't handle it. In most environments the DC/GC role will be fine. We already do this where I am but I was glad to hear Eric recommend it.
    • Leave Field Engineering Logging on everywhere. Turning it on won't hurt perf and the info you get from it is very valuable. It will let you know about inefficient and expensive queries in your environment. More info on field engineering can be found here We currently don't have this on but we soon will turn it on.
    • Eric considers Replication and Query Optimization the hardest part of AD. You also have to know that Eric works with very large implementations.
    • Don't ever user eseutil to repair your AD database. Never even tried that one in production and will never try it :)
    • Establish baselines: run SPA from time to time and run Perfmon a lot.
    • Collect Crash dumps and look at your own dumps before asking PSS.
    • The following commands will help with the crash dumps before calling PSS.

      • windbg –z foo.dmp
      • sympath SRV*http://msdl.microsoft.com/download/symbols
      • !analyze -v



That was just a taste of what Eric talked about. If you ever get a chance to go see Eric speak then do it!! Eric lived up to his reputation and in fact he exceeded all expectations.

He could have a great career after Microsoft as a college professor or high school teacher if he wanted to. Very smart but also good at conveying his thoughts and ideas to the audience. I can't imagine anyone not giving him a 5/5 on any evaluation.

Saturday, April 11, 2009

My Favorite Commercial of All-Time




Michael Jordan is my favorite athlete of all time. I really loved watching him play and watch that passion he had for the game.

What I really loved about this commercial is that Michael shows us all that even he has failed many many times…but in the end that is why he succeeded.

This is the same with Active Directory. We often try new things or maybe fail to solve the issue at hand in the first try or within the first few minutes….but that is why we succeed.

Odd Title For your Blog – Is AD really fun?

So why would I call my blog “ADisFUN”. There are a lot of things in this world that people consider fun and Active Directory is not often mentioned in that list.

What I really enjoy is that AD fits about any network. From those small businesses that run AD using SBS or to the large companies that span the globe with thousands and thousands of users across multiple continents. That means knowing AD and how it works is needed everywhere.

There is also always something to learn which is probably the most fun I have. If you ever hear anyone tell you that they have completely mastered AD and know everything about it then that person is lying. There are always new features and new versions coming out. Microsoft constantly strives to improve AD and now that they are releasing new features every two years there is always more to learn and know and try to master.

An analogy I use is that I compare Active Directory to the game of golf. Golf can be a humbling game and even someone as great as Tiger Woods knows that he will never truly “master” the game. Tiger comes close but he learns new things about his game and golf all the time. This is the same with Active Directory. There are those in the AD world that I consider the “Tiger Woods of AD” and the great thing is those people will readily admit that they still have things to learn and master.

There are new issues we encounter on a regular basis and solving those issues is what I consider Fun. Learning the new features is what I consider Fun. Working with great people in the AD community (see my blog list for some examples) is what I consider Fun. Helping answer questions in the community and receiving emails or comments from people is very fun and rewarding.

…and yes even going out and getting new certifications every few years is what I consider Fun :)

Hello World

My first post, yeah finally :)

This isn't my first attempt at a blog/website. Four years ago I purchased http://www.diggpodcast.com/

At the time podcasts were not really big and digg.com had just gotten started so I figured that would be a good podcast to start.

The problem there was when I actually recorded a few and heard my voice I really hated it. I know a lot of people hate their voice but I just didn't feel like it was a good podcast.

If you know what Active Directory is then you have come to the right place. I plan on posting Active Directory related topics and from time to time non-technical items too.

I'm active on experts-exchange in the AD forums (mkline71) and I'll try to pick a few questions from there a week and expand on them here in the blog.

I also plan on doing some step by step videos but that will come later.

I hope you all enjoy my blog and hopefully it can help someone out there.