<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://myitforum.com/cs2/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Chris Stauffer at myITForum.com</title><subtitle type="html">You want me to do What? 
</subtitle><id>http://myitforum.com/cs2/blogs/cstauffer/atom.aspx</id><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/default.aspx" /><link rel="self" type="application/atom+xml" href="http://myitforum.com/cs2/blogs/cstauffer/atom.aspx" /><generator uri="http://communityserver.org" version="3.1.31113.47">Community Server</generator><updated>2010-05-19T21:06:50Z</updated><entry><title>Windows Deployment Wizard 2.0 Released</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/10/16/windows-deployment-wizard-2-0-released.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/10/16/windows-deployment-wizard-2-0-released.aspx</id><published>2011-10-16T19:18:35Z</published><updated>2011-10-16T19:18:35Z</updated><content type="html">&lt;p&gt;I am happy to announce that version 2.0 of my deployment wizard is released. I also put out new directions and setup instructions. Hope this tool is as helpful to others as it has been for me. After releasing is tool at work about 3 weeks ago my call volume and email volume for windows 7 deployments and domain cleanup have drastically dropped.&lt;/p&gt;  &lt;p&gt;&lt;a title="http://osdeplymentwizard.codeplex.com/" href="http://osdeplymentwizard.codeplex.com/"&gt;http://osdeplymentwizard.codeplex.com/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Here is what the new site can do:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This site was created to allowing any system admin to deploy the Windows 7 image at their own speed.&lt;/p&gt;  &lt;p&gt;This website is still a work in progress so new features will be added as I has time. New features would be released with new version numbers.&lt;/p&gt;  &lt;p&gt;Windows Deployment Wizard 2.0 has the following features:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;strong&gt;Deploy Windows 7 to an existing SCCM Client&lt;/strong&gt;      &lt;ol&gt;       &lt;li&gt;Deploy X86 with data recovery (USMT) &lt;/li&gt;        &lt;li&gt;Deploy X64 with data recovery (USMT &lt;/li&gt;        &lt;li&gt;Deploy X84 without data recover &lt;/li&gt;        &lt;li&gt;Deploy X64 without data recovery &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Deploy Windows 7 to a bare Metal Machine or a machine that does NOT exist in SCCM&lt;/strong&gt;      &lt;ol&gt;       &lt;li&gt;Deploy X84 without data recovery &lt;/li&gt;        &lt;li&gt;Deploy X64 without data recovery &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Delete a Machine from AD and SCCM&lt;/strong&gt;&lt;/li&gt;    &lt;ol&gt;     &lt;li&gt;This will check AD and SCCM then let you know where it exists &lt;/li&gt;      &lt;li&gt;Once you click delete it will email you that the machine is deleted along with the Domain Cleanup exchange group of your choosing.&lt;/li&gt;      &lt;ol&gt;       &lt;li&gt;We use this as a way to let our other security teams know that a machine has been removed and they need to cleanup assets as well.&lt;/li&gt;     &lt;/ol&gt;   &lt;/ol&gt; &lt;/ol&gt;  &lt;p&gt;The whole site was recoded in VB.net. The website is considered ASP.NET 2.0 with HTML 4-5 and CSS3. This gives us the ability to use tracing and email for audit trails. It also allows for more code growth in the future. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note: I’ve also maintained version 1.0 for anybody that didn’t want all this new power &lt;img style="border-bottom-style:none;border-left-style:none;border-top-style:none;border-right-style:none;" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://myitforum.com/cs2/blogs/cstauffer/wlEmoticon-smile_04A68610.png" /&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=159798" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="OSD/MDT" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/OSD_2F00_MDT/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /><category term="ConfigMgr R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+R2/default.aspx" /><category term="Web Console Tweaks" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Web+Console+Tweaks/default.aspx" /><category term="ConfigMgr SP2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+SP2/default.aspx" /><category term="Windows 7" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Windows+7/default.aspx" /><category term="Windows Deployment tools" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Windows+Deployment+tools/default.aspx" /></entry><entry><title>Client install Error codes</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/09/11/client-install-error-codes.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/09/11/client-install-error-codes.aspx</id><published>2011-09-12T00:18:10Z</published><updated>2011-09-12T00:18:10Z</updated><content type="html">&lt;p&gt;I’ve been doing a lot of work with the client install lately. At MMS 2011 Mike Schultz did a presentation on MCS secrets and tips. During that presentation he released a spreadsheet and pivot table to parse the ccr.retry inbox. Below is a list of common error codes that he provided. I’ve updated and/or added about 8-10 errors that I was seeing.&lt;/p&gt;  &lt;p&gt;Hope this helps others. You can find the scripts that Mike uses on the MMS 2011 DVD’s.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note: Error 53 has lots of reasons. The reasons I provided below are based on the machine being turned on. You can also get an error 53 if you run an AD system discovery and a machine no longer exists but is still in AD and DNS. To remedy this turn on DNS scavenging.&lt;/p&gt;  &lt;h3&gt;Error Code Reason&lt;/h3&gt;  &lt;ul&gt;   &lt;li&gt;2 - The system cannot find the file specified.&lt;/li&gt;    &lt;li&gt;5 - Access denied.&lt;/li&gt;    &lt;li&gt;52 - You were not connected because a duplicate name exists on the network. Make sure there is not a duplicate name in DNS and that 2 machines don&amp;#39;t have the same IP in DNS.&lt;/li&gt;    &lt;li&gt;53 - Unable to locate - &lt;a href="http://support.microsoft.com/kb/920852"&gt;http://support.microsoft.com/kb/920852&lt;/a&gt; - cannot connect to admin$ - Computer Browser not started - add File/print sharing to Exceptions in Firewall – turn file and print on.&lt;/li&gt;    &lt;li&gt;58 - The specified server cannot perform The requested operation&lt;/li&gt;    &lt;li&gt;64 - The specified network name is no longer available. Source: Windows&lt;/li&gt;    &lt;li&gt;67 - network name cannot be found.     &lt;br /&gt;86 - network password is not correct? Machine Name &amp;lt;&amp;gt; resolved name.&lt;/li&gt;    &lt;li&gt;112 - Not enough disk space&lt;/li&gt;    &lt;li&gt;1003 - Cannot complete this function.&lt;/li&gt;    &lt;li&gt;1053 - The service did not respond to the start or control request in a timely fashion.&lt;/li&gt;    &lt;li&gt;1068 - The dependency service or group failed to start&lt;/li&gt;    &lt;li&gt;1130 - Not enough server storage is available to process this command. Source: Windows&lt;/li&gt;    &lt;li&gt;1203 - The network path was either typed incorrectly, does not exist, or the network provider is not currently available. Please try retyping the path or contact your network administrator.&lt;/li&gt;    &lt;li&gt;1208 - An extended error has occurred. Source: Windows&lt;/li&gt;    &lt;li&gt;1396 - Logon Failure: The target account name is incorrect. (NBTSTAT -a reverse lookup, duplicate IP address)&lt;/li&gt;    &lt;li&gt;1450 - Insufficient system resources exist to complete the requested service. Source: Windows&lt;/li&gt;    &lt;li&gt;2147749889 - Generic WMI failure (Broken WMI)&lt;/li&gt;    &lt;li&gt;2147749890 - not found - Source: Windows Management (WMI) - try repair WMI&lt;/li&gt;    &lt;li&gt;2147749904 - Invalid class - Source: Windows Management (WMI)&lt;/li&gt;    &lt;li&gt;2147749908 - Initialization failure - Source: Windows Management (WMI)&lt;/li&gt;    &lt;li&gt;2147942405 - Access is Denied (Firewall rule? / MacAfee-HIPS?)&lt;/li&gt;    &lt;li&gt;2147944122 - The RPC server is unavailable. (Dcom is miss-configured for security . &lt;a href="http://support.microsoft.com/kb/899965"&gt;http://support.microsoft.com/kb/899965&lt;/a&gt; )&lt;/li&gt;    &lt;li&gt;2148007941 - Server Execution Failed&lt;/li&gt; &lt;/ul&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=159286" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Client Health" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Client+Health/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /><category term="ConfigMgr R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+R2/default.aspx" /><category term="ConfigMgr SP2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+SP2/default.aspx" /></entry><entry><title>OS Deployment Wizard Webconsole</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/08/30/os-deployment-wizard-webconsole.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/08/30/os-deployment-wizard-webconsole.aspx</id><published>2011-08-31T00:39:32Z</published><updated>2011-08-31T00:39:32Z</updated><content type="html">  &lt;p&gt;I’ve been working on a way to deploy an OS with SCCM and Maik Koster’s webservices. I decided to Post it to CodePlex so that I could track it better. Please feel free to use this new tool and provide as much feedback as possible. I am not a Web developer so this code isn’t perfect but it is working &lt;img style="border-bottom-style:none;border-left-style:none;border-top-style:none;border-right-style:none;" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://myitforum.com/cs2/blogs/cstauffer/wlEmoticon-smile_125318B3.png" /&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Let me know what you think:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a title="http://osdeplymentwizard.codeplex.com/" href="http://osdeplymentwizard.codeplex.com/"&gt;http://osdeplymentwizard.codeplex.com/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://myitforum.com/cs2/blogs/cstauffer/image_242FAC80.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://myitforum.com/cs2/blogs/cstauffer/image_thumb_70F37316.png" width="658" height="409" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=159131" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Configuration Manager 2007" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Configuration+Manager+2007/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /><category term="ConfigMgr R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+R2/default.aspx" /><category term="Web Console Tweaks" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Web+Console+Tweaks/default.aspx" /><category term="ConfigMgr SP2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+SP2/default.aspx" /></entry><entry><title>What happens when you don’t reboot after patching</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/07/16/what-happens-when-you-don-t-reboot-after-patching.aspx" /><link rel="enclosure" type="application/x-zip-compressed" length="1141782" href="http://myitforum.com/cs2/blogs/cstauffer/attachment/158475.ashx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/07/16/what-happens-when-you-don-t-reboot-after-patching.aspx</id><published>2011-07-16T13:42:00Z</published><updated>2011-07-16T13:42:00Z</updated><content type="html">&lt;p&gt;I put this presentation together a few years ago and a topic of rebooting came up the other day so I thought I would post this presentation to better explain what happens when management decides “WE CANT REBOOT MACHINES”. I hope this helps others explain to management what happens when we patch and don’t reboot as needed.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;Thanks,&lt;/p&gt;  &lt;p&gt;Chris Stauffer &amp;lt;&amp;gt;&amp;lt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=158475" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Security Patches" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Security+Patches/default.aspx" /><category term="Configuration Manager 2007" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Configuration+Manager+2007/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /><category term="ConfigMgr R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+R2/default.aspx" /><category term="ITMU" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ITMU/default.aspx" /><category term="ConfigMgr SP2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+SP2/default.aspx" /></entry><entry><title>Updated ConfigMgr 2007 Patch Management Enterprise Compliancy Report</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/07/07/updated-configmgr-2007-patch-management-enterprise-compliancy-report.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/07/07/updated-configmgr-2007-patch-management-enterprise-compliancy-report.aspx</id><published>2011-07-08T01:07:22Z</published><updated>2011-07-08T01:07:22Z</updated><content type="html">&lt;p&gt;I’m finally getting back into ConfigMgr 2007 and Patch Management again so I wanted to update some of my existing reports and try to come up with some better ways to control my patches. Here is the fist updated report. Thanks Matt Broadstock for assisting with the code where I got stuck &lt;img style="border-bottom-style:none;border-left-style:none;border-top-style:none;border-right-style:none;" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://myitforum.com/cs2/blogs/cstauffer/wlEmoticon-smile_5AE3BECB.png" /&gt;&lt;/p&gt;  &lt;p&gt;Each report will have to be hard coded so I created several of them but basically you enter the &lt;font color="#ffc000"&gt;ScopeID&lt;/font&gt; and the &lt;font color="#00ff00"&gt;Collection&lt;/font&gt; for the machines you want a status on.     &lt;br /&gt;In this example I want to see all XP workstations and I want to compare it against the Patch list I created for XP Security patches.     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;This report is broken into 4 parts:&lt;/p&gt;  &lt;p&gt;Part 1 Show the title of the Scope ID&lt;/p&gt;  &lt;p&gt;Part 2 Show the Collection ID for an OS and give me the headcounts&lt;/p&gt;  &lt;p&gt;Part 3 Show the total Compliancy state for the machines in part 2&lt;/p&gt;  &lt;p&gt;Part 4 Show me the total compliancy state for each machines in each of the sub collections I want to know more about&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Presently I have to report on multiple office groups and each office group has its own IT staff, so I needed a report that would show management what things look like as a whole but at the same time tell us were issues are so we can address them separately. So I created a master collection and sub collections for each office group that contain only the machines from that office groups OU in AD.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;This could probably be automated further or even be setup with variables but it has been 18+ months since i worked on SQL like this so i need to get my head wet again :-)     &lt;br /&gt;Not as fancy as the new SRS but my Boss is just as happy with the ASP reports still :-P     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;##################################################################    &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;--The first two lines are just for quick reference so I know what Scopeid and collection I am using in the report&lt;/p&gt;  &lt;p&gt;-- AuthListID=&lt;font color="#ffc000"&gt;ScopeId_07303A0F-140E-4EB7-9D23-A333E0D085FC/AuthList_1BAE5B91-C218-4817-8CEC-13019EA83518&lt;/font&gt;     &lt;br /&gt;--CollID=&lt;font color="#00ff00"&gt;SMS000ES&lt;/font&gt;&lt;/p&gt; &lt;font color="#00ff00"&gt;&lt;/font&gt;  &lt;p&gt;   &lt;br /&gt;declare @CI_ID int; select @CI_ID=CI_ID from v_ConfigurationItems     &lt;br /&gt;where CIType_ID=9 and CI_UniqueID=&lt;font color="#ffc000"&gt;&amp;#39;ScopeId_07303A0F-140E-4EB7-9D23-A333E0D085FC/AuthList_1BAE5B91-C218-4817-8CEC-13019EA83518&amp;#39;&lt;/font&gt;     &lt;br /&gt;declare @CollCount int, @NumClients int; select @CollCount = count(*), @NumClients=isnull(sum(cast(IsClient as int)), 0)     &lt;br /&gt;from v_ClientCollectionMembers ccm     &lt;br /&gt;where ccm.CollectionID=&amp;#39;SMS000ES&amp;#39;     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#d16349"&gt;-- Part 1&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;select distinct Title as Title     &lt;br /&gt;--, CI_UniqueID as AuthListID     &lt;br /&gt;&amp;#160; from v_AuthListInfo     &lt;br /&gt;&amp;#160; where CI_UniqueID =&lt;font color="#ffc000"&gt;&amp;#39;ScopeId_07303A0F-140E-4EB7-9D23-A333E0D085FC/AuthList_1BAE5B91-C218-4817-8CEC-13019EA83518&amp;#39;      &lt;br /&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#d16349"&gt;-- Part 2&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Select     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; CollectionName=vc.Name,     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; NumberInCollection=@CollCount,     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; NonClients=@CollCount-@NumClients,     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; PComputers=convert(numeric(5,2), (@CollCount-@NumClients)*100.00 / isnull(nullif(@CollCount, 0), 1))     &lt;br /&gt;from v_Collection vc     &lt;br /&gt;where vc.CollectionID=&amp;#39;&lt;font color="#00ff00"&gt;SMS000ES&lt;/font&gt;&amp;#39;     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#d16349"&gt;-- Part 3&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;SELECT&amp;#160;&amp;#160; v_Collection.Name     &lt;br /&gt;, sn.StateName AS Status, COUNT(*) AS &amp;quot;Number Of Computers&amp;quot;     &lt;br /&gt;, CONVERT(numeric(5, 2)     &lt;br /&gt;, ISNULL(COUNT(*), 0)* 100.00 / ISNULL(NULLIF (@CollCount, 0), 1)) AS &amp;quot;Percentage of Computers&amp;quot;     &lt;br /&gt;FROM&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_ClientCollectionMembers AS cm INNER JOIN     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_UpdateListStatus_Live AS cs ON cs.CI_ID = @CI_ID AND cs.ResourceID = cm.ResourceID INNER JOIN     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_Collection ON cm.CollectionID = v_Collection.CollectionID LEFT OUTER JOIN     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_StateNames AS sn ON sn.TopicType = 300 AND sn.StateID = ISNULL(cs.Status, 0)     &lt;br /&gt;WHERE&amp;#160;&amp;#160;&amp;#160;&amp;#160; (cm.CollectionID = &amp;#39;&lt;font color="#00ff00"&gt;SMS000ES&lt;/font&gt;&amp;#39;)     &lt;br /&gt;GROUP BY sn.StateName, v_Collection.Name     &lt;br /&gt;ORDER BY &amp;quot;Number Of Computers&amp;quot; DESC     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#d16349"&gt;-- Part 4&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;SELECT&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_Collection.Name     &lt;br /&gt;, sn.StateName AS Status     &lt;br /&gt;, COUNT(*) AS &amp;quot;Number Of Computers&amp;quot;     &lt;br /&gt;, CONVERT(numeric(5, 2)     &lt;br /&gt;, ISNULL(COUNT(*), 0)* 100.00 / ISNULL(NULLIF (@CollCount, 0), 1)) AS &amp;quot;Percentage of Computers&amp;quot;     &lt;br /&gt;FROM&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_ClientCollectionMembers AS cm     &lt;br /&gt;INNER JOIN v_UpdateListStatus_Live AS cs ON cs.CI_ID = @CI_ID AND cs.ResourceID = cm.ResourceID     &lt;br /&gt;INNER JOIN v_Collection ON cm.CollectionID = v_Collection.CollectionID     &lt;br /&gt;INNER JOIN v_StateNames AS sn ON sn.TopicType = 300 AND sn.StateID = ISNULL(cs.Status, 0) AND cm.CollectionID IN     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (SELECT&amp;#160;&amp;#160;&amp;#160;&amp;#160; subCollectionID     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; FROM&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; v_CollectToSubCollect     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; WHERE&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (parentCollectionID = 00100030&amp;#39;) )     &lt;br /&gt;WHERE cm.ResourceID in     &lt;br /&gt;(select ResourceID from v_ClientCollectionMembers where CollectionID = &amp;#39;&lt;font color="#00ff00"&gt;SMS000ES&lt;/font&gt;&amp;#39;)&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;br /&gt;GROUP BY sn.StateName, v_Collection.Name     &lt;br /&gt;ORDER BY v_Collection.Name Asc, Status Desc&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;########################################################################&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;More to come as I get more into reports again.&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=158304" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="SMS Reports" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/SMS+Reports/default.aspx" /><category term="Security Patches" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Security+Patches/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /></entry><entry><title>Microsoft patch KB982018 (Solution)</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/04/28/microsoft-patch-kb982018-solution.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/04/28/microsoft-patch-kb982018-solution.aspx</id><published>2011-04-28T16:07:00Z</published><updated>2011-04-28T16:07:00Z</updated><content type="html">&lt;p&gt;Update: This also affects SP1 installs. MS actually published an article for it.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/2575082"&gt;http://support.microsoft.com/kb/2575082&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;*********************************************************************************&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;It was discovered this morning that KB982018 &lt;/font&gt;&lt;/font&gt;&lt;font size="3" face="Calibri"&gt;(&lt;/font&gt;&lt;a href="http://support.microsoft.com/kb/982018"&gt;&lt;font size="3" color="#0000ff" face="Calibri"&gt;http://support.microsoft.com/kb/982018&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;) is causing an issue and making &lt;/font&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;other patches installing with it fail to install.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;According to the KB this patch is only for Server 2008 R2 and Windows 7&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Apparently from what we are seeing the following patches are failing on&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;server 2008 R2 and windows 7.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;KB2492386&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;KB2515325&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;KB2522422&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;KB982018&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;The cause of the problem is KB982018. If you install the other 3 patches&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;individually they install fine.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;This is also causing SP1 to fail on install on Server 2008 R2 and Windows 7.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Solution:&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;KB982018 is updating the usbstor.inf and the&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;usbstor.PNF. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;If you locking down USB devices then these 2 files are explicitly denied &lt;/font&gt;&lt;/font&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;access for the following groups:&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Everyone&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Administrators&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;User&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;System&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;If you change all of these to Full control then the patch will install.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3" face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;The best solution is to apply a GPO to reverse the explicitly deny security&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;and give full control back to the above groups. Then apply the patch&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;then&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="MARGIN:0in 0in 0pt;" class="MsoPlainText"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;re-apply the original GPO to lock things back down.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hope this helps others&lt;/p&gt;
&lt;p&gt;Thanks &amp;lt;&amp;gt;&amp;lt;&lt;/p&gt;
&lt;p&gt;Chris Stauffer&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=157073" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Security Patches" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Security+Patches/default.aspx" /><category term="Windows 7" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Windows+7/default.aspx" /><category term="Server 2008 R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Server+2008+R2/default.aspx" /><category term="Server 2008 R2 SP1" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Server+2008+R2+SP1/default.aspx" /></entry><entry><title>MMS 2011</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/03/26/mms-2011.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/03/26/mms-2011.aspx</id><published>2011-03-26T16:28:00Z</published><updated>2011-03-26T16:28:00Z</updated><content type="html">&lt;p&gt;Wow what a week, I learn so much that my brain is tired. I picked up alot of new theories that I will be writing updated scripts and new automations for. Can&amp;#39;t wait to dive in.&lt;/p&gt;&lt;p&gt;One of the best session was by Mike Schultz from Microsoft. He gave some great hints and tips and some suggestions (wink wink) incase you are not ready to head to Configuration Manager 2012 just yet.&lt;/p&gt;&lt;p&gt;More to come from that session.&lt;/p&gt;&lt;p&gt;I was part of the Twitter Army and well lets just say that a Zune HD (even though i love my Zune HD and would never get an crap pod) it was almost impossible to stay connected to twitter so my account is now deleted. But is was nice to have to know what was happening during the conferance. Wish there was a way to just watch the twitter treads without actually having an account.&lt;/p&gt;&lt;p&gt;There were so moany great sessions by MyITForum members Like Sherry Kissinger, Paul Thomson, Steve Thomson and many others that i got alot out of. I am so glad that we have so many MVP&amp;#39;s in this community that are willing to share.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Anyway. Sitting the airport waiting to head home, bin a long week.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;To the Cloud..&lt;/p&gt;&lt;p&gt;No really I am almost ready to fly hehe..&lt;br /&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=155988" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="MMS 2011" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/MMS+2011/default.aspx" /></entry><entry><title>MyITForum MMS 2011 Party announced</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/03/07/myitforum-mms-2011-party-announced.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/03/07/myitforum-mms-2011-party-announced.aspx</id><published>2011-03-08T01:19:00Z</published><updated>2011-03-08T01:19:00Z</updated><content type="html">&lt;p&gt;Here are the party details&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://myitforum.com/cs2/blogs/rtrent/archive/2011/03/07/mms-news-annual-myitforum-party-at-mms-2011-mms2011.aspx"&gt;http://myitforum.com/cs2/blogs/rtrent/archive/2011/03/07/mms-news-annual-myitforum-party-at-mms-2011-mms2011.aspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Incidentally – if you are even a tad bit frightened of crowds you still have until the end of this week to “&lt;a target="_blank"&gt;donate&lt;/a&gt;” to myITforum.com to have a ticket reserved.&amp;nbsp; Donations for tickets will end March 11, 2011.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.myitforum.com/donations/donate.asp"&gt;http://www.myitforum.com/donations/donate.asp#&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=155198" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="MMS 2011" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/MMS+2011/default.aspx" /></entry><entry><title>Domain controller wont accept smart card logon **Updated**</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/02/09/domain-controller-wont-accept-smart-card-logon.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/02/09/domain-controller-wont-accept-smart-card-logon.aspx</id><published>2011-02-10T02:17:00Z</published><updated>2011-02-10T02:17:00Z</updated><content type="html">&lt;p&gt;I just spent the last 5 hours troubleshooting a new AD error, for me anyway…&lt;/p&gt;  &lt;p&gt;The problem was that when a user tried to log on they got the following error on Windows XP SP3:&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#ff0000"&gt;“The system could not log you on.&amp;nbsp; The server authenticating you reported an error (0xC00000BB).”&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;This error isn&amp;#39;t very helpful, it points to the Server 2008 R2 DC certificate having an issue but that is about it.&lt;/p&gt;  &lt;p&gt;I reviewed the certificate and it appeared to be fine. the interesting thing is that the certificate was fine when everybody came into work at 8am but by lunch time everybody was getting the above error as they returned from lunch.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;I spent 4 hours going over the DC and not finding anything wrong. Everything seemed to check out ok and anybody that logged in with a username and password was ok.&lt;/p&gt;  &lt;p&gt;But if you used a smart card and a pin you failed. with the above error code.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;I finally stumbled upon an event ID 19 for Kerberos on the DC. Interestingly enough this error was only showing up once an hour so we missed it the first few times it popped up.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;h3&gt;Event Details&lt;/h3&gt;  &lt;p&gt;&lt;b&gt;Product:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Windows Operating System&lt;/p&gt;  &lt;p&gt;&lt;b&gt;ID:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;19&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Source:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Microsoft-Windows-Kerberos-Key-Distribution-Center&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Version:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;6.1&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Symbolic Name:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;KDCEVENT_NO_KDC_CERTIFICATE&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Message:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;This event indicates an attempt was made to use smartcard logon, but the KDC is unable to use the PKINIT protocol because it is missing a suitable certificate.&lt;/p&gt;  &lt;h3&gt;&lt;/h3&gt;  &lt;p&gt;It turns out that something corrupted the certificate in such a way that it removed the smartcard portion of the cert but left the rest of it intact. The cert even passed a verification check when I ran this command: &lt;b&gt;certutil -dcinfo verify&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We finally found this Technet article and fixed the problem in about 2 minutes.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;&lt;a title="http://technet.microsoft.com/en-us/library/dd348640%28WS.10%29.aspx" href="http://technet.microsoft.com/en-us/library/dd348640%28WS.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/dd348640%28WS.10%29.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;Hope this helps someone else out.&lt;/p&gt;&lt;p&gt;** Update**&lt;/p&gt;&lt;p&gt;After further inspection we found an error code ID 29 &lt;/p&gt;&lt;p&gt;This points to the same process to fix the issue we had.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc734096%28WS.10%29.aspx%20"&gt;http://technet.microsoft.com/en-us/library/cc734096%28WS.10%29.aspx&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;** Update **&lt;/p&gt;&lt;p&gt;After a few weeks of this issue it was discovered that if we restart the &amp;quot;Kerberos Key Distribution Center&amp;quot; service that this fixes the issue without the need to replace the server certificate. this works 99% of the time.&lt;/p&gt;&lt;p&gt;simply run&lt;/p&gt;&lt;p&gt;########################&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Rem Certificate fix bat&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="posthilit"&gt;net&lt;/span&gt; stop kdc &amp;amp;&amp;amp; &lt;span class="posthilit"&gt;net&lt;/span&gt; start kdc&lt;/p&gt;&lt;p&gt;even better you can just create a shortcut on the desktop to do the same command line&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Still no cause of this issue but this will get you working again.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;Chris Stauffer &amp;lt;&amp;gt;&amp;lt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=154093" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Active Directory" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Active+Directory/default.aspx" /><category term="Server 2008 R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Server+2008+R2/default.aspx" /><category term="PKI" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/PKI/default.aspx" /></entry><entry><title>Fixing machines that will not install the client because they have been over secured</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/02/01/fixing-machines-that-will-not-install-the-client-because-they-have-been-over-stigged.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/02/01/fixing-machines-that-will-not-install-the-client-because-they-have-been-over-stigged.aspx</id><published>2011-02-01T16:09:00Z</published><updated>2011-02-01T16:09:00Z</updated><content type="html">&lt;p&gt;In order for systems to be accepted on our network it must be locked down very tight. This means that the security needs to be locked down to a certain level. This also means that sometimes things are set that should not be and a waiver should be submited because some setting actually break the OS.&lt;/p&gt;&lt;p&gt;Over the last 3 weeks i have been trying to get over 500 systems to install the client. These 500 have been real stuborn. In most cases what i have found is that someone (in good intent) attempted to make sure a system was up to the security standards and they over securied a system, the script below needs to be run on a system with Admin rights. At this point i am down to about 170 systems that still need fixed, but this script seems to be doing the trick. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Note: This should only be done if someone created good (FDCC Standards) gpo that will be reapplied once everything is cleared out.&lt;/b&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The problem I found is that I can not get it (the script) to run as a startup script and since the admin shares are missing in most cases PSexec does not work to get this script run remotely. I also found that because of how these machines have been secured I can not remote desktop or use dameware to reach these machines.&lt;/p&gt;&lt;p&gt;But direct access to the pc and then Running this script fixes about 90% of the issues. Then I reboot the system and let the Health Check Script I am running do the rest.&lt;/p&gt;&lt;p&gt;We still see some machines that are so messed up that they are better off being reimaged but this is worth a shot.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Hope this helps others out.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Fix_Client_Security_Issues.cmd&lt;br /&gt;&lt;/p&gt;&lt;p&gt;*******************************************************************************&lt;/p&gt;&lt;p&gt;@echo off&lt;br /&gt;Rem This Script will fix some common problems found on systems that have been over stigged.&lt;br /&gt;Echo Fix Admin Shares&lt;br /&gt;&lt;br /&gt;reg Delete hklm\System\CurrentControlSet\Services\LanmanServer\Parameters\ /v autoshareserver /f&lt;br /&gt;reg Delete hklm\System\CurrentControlSet\Services\LanmanServer\Parameters\ /v AutoShareWks /f&lt;br /&gt;net stop Server /y&lt;br /&gt;net start Server /y&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Echo Fix Firewalls&lt;br /&gt;&lt;br /&gt;SC sdset SharedAccess D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU) &lt;br /&gt;&lt;br /&gt;echo Fix Dcom&lt;br /&gt;&lt;br /&gt;Net stop msdtc&lt;br /&gt;Msdtc -resetlog&lt;br /&gt;Net start msdtc&lt;br /&gt;&lt;br /&gt;Echo Fix WMI&lt;br /&gt;&lt;br /&gt;net stop winmgmt /y&lt;br /&gt;if exist %windir%\system32\wbem\repository.001 rmdir /s /q %windir%\system32\wbem\repository.001&lt;br /&gt;rename %windir%\system32\wbem\repository repository.001&lt;br /&gt;%windir%\system32\wbem\winmgmt /clearadap&lt;br /&gt;%windir%\system32\wbem\winmgmt /kill&lt;br /&gt;%windir%\system32\wbem\winmgmt /unregserver&lt;br /&gt;%windir%\system32\wbem\winmgmt /reserver&lt;br /&gt;%windir%\system32\wbem\winmgmt /resyncperf&lt;br /&gt;regsvr32 /s %systemroot%\system32\scecli.dll&lt;br /&gt;regsvr32 /s %systemroot%\system32\userenv.dll&lt;br /&gt;mofcomp %windir%\system32\wbem\cimwin32.mof&lt;br /&gt;mofcomp %windir%\system32\wbem\cimwin32.mfl&lt;br /&gt;mofcomp %windir%\system32\wbem\rsop.mof&lt;br /&gt;mofcomp %windir%\system32\wbem\rsop.mfl&lt;br /&gt;cd \windows\system32\wbem&lt;br /&gt;for /f %%s in (&amp;#39;dir /b /s %windir%\system32\wbem\*.dll&amp;#39;) do regsvr32 /s %%s&lt;br /&gt;for /f %%s in (&amp;#39;dir /b /s %windir%\system32\wbem\*.mof&amp;#39;) do mofcomp %%s&lt;br /&gt;for /f %%s in (&amp;#39;dir /b %windir%\system32\wbem\*.mfl&amp;#39;) do mofcomp %%s&lt;br /&gt;net start winmgmt&lt;br /&gt;%windir%\system32\wbem\wmiprvse /regserver&lt;br /&gt;&lt;br /&gt;Echo Re-register the MSI service&lt;br /&gt;msiexec /regserver&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Echo Reset GPO&amp;#39;s&lt;br /&gt;secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;***************************************************************************************************&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Enjoy&lt;/p&gt;&lt;p&gt;Chris Stauffer &amp;lt;&amp;gt;&amp;lt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=153909" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Configuration Manager 2007" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Configuration+Manager+2007/default.aspx" /><category term="Client Health" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Client+Health/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /><category term="ConfigMgr R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+R2/default.aspx" /><category term="ConfigMgr SP2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+SP2/default.aspx" /></entry><entry><title>Increasing IIS 7 and 7.5 buffers for ConfigMgr 2007 on Server 2008 R2</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/02/01/increasing-iis-7-and-7-5-buffers-for-configmgr-2007-on-server-2008-r2.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/02/01/increasing-iis-7-and-7-5-buffers-for-configmgr-2007-on-server-2008-r2.aspx</id><published>2011-02-01T15:51:00Z</published><updated>2011-02-01T15:51:00Z</updated><content type="html">&lt;p&gt;In ConfigMgr 2007 you may get an error when you run web reports because the default values
are to small. You follow this &lt;a href="http://blogs.technet.com/b/smsandmom/archive/2006/07/10/441033.aspx"&gt;blog&lt;/a&gt;
to get them working, but if you are running Server 2008 (64bit) or Server 2008
R2 (64 bit) the locations have changed .&lt;br /&gt;&lt;br /&gt;

Yes I realize
that SSRS is better and removes the limitations but my brain can only hold so
much info at one time... (this is next on my list to learn)&lt;br /&gt;&lt;br /&gt;

Here are the
things that need edited for the ConfigMgr 2008 Webreports buffers when running
Server 2008 and Server 2008 R2&lt;br /&gt;&lt;br /&gt;

1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Change the Following Reg Key&lt;br /&gt;&lt;br /&gt;

a.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\SMS\Reporting&lt;br /&gt;&lt;br /&gt;

&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
i.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Add
a Dword called &lt;b&gt;Rowcount&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;

1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The maximum row count in decimal is
32767. &lt;br /&gt;&lt;br /&gt;

2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you need to return more than 32,767
records, you can set the row count to 0xffffffff hexadecimal, which will return
all rows. However, this significantly increases the workload on the SMS site
database.&lt;br /&gt;&lt;br /&gt;

2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open IIS manager, go to your site
under the ASP section, find the &lt;b&gt;Limit Properties.&amp;nbsp; Response Buffering
limit item.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;

a.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The &lt;i&gt;ASPBufferingLimit&lt;/i&gt; defaults
to 4mb&lt;br /&gt;&lt;br /&gt;

&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
i.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
So
that is 4 x 1024 x 1024 = 4194304&lt;br /&gt;&lt;br /&gt;

b.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; You want to have atleast 1 meg per
1000 entries&lt;br /&gt;&lt;br /&gt;

&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
i.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
To
increase it to say 20 megs &lt;br /&gt;&lt;br /&gt;

1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20x 1024 x1024 = 20971520&lt;br /&gt;&lt;br /&gt;

3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Finally you&amp;#39;ll likely need to adjust
the Timeout values for running ASP Scripts.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;

a.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open IIS manager, go to your site
under the ASP section, find the &lt;b&gt;Script
Timeout.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;

&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
i.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Default
is 90 Sec or 00:01:30&lt;br /&gt;&lt;br /&gt;

&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
ii.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Change
to a higher value maybe 00:03:00&lt;br /&gt;&lt;br /&gt;

Note make
sure you choose to apply your settings.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=153906" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="SMS Reports" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/SMS+Reports/default.aspx" /><category term="ConfigMgr" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr/default.aspx" /><category term="ConfigMgr R2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+R2/default.aspx" /><category term="SQL" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/SQL/default.aspx" /><category term="ConfigMgr SP2" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/ConfigMgr+SP2/default.aspx" /></entry><entry><title>MCITP: Server Administrator</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2011/01/14/mcitp-server-administrator.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2011/01/14/mcitp-server-administrator.aspx</id><published>2011-01-14T21:40:10Z</published><updated>2011-01-14T21:40:10Z</updated><content type="html">&lt;p&gt;What an tiring &lt;img style="border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;" class="wlEmoticon wlEmoticon-nerdsmile" alt="Nerd smile" src="http://myitforum.com/cs2/blogs/cstauffer/wlEmoticon-nerdsmile_677AD45D.png" /&gt; week. I just spent the last 8 days at &lt;a href="http://www.cedsolutions.com/"&gt;CED Solutions&lt;/a&gt; training for the MCITP: Server Administrator&lt;/p&gt;  &lt;p&gt;These guys do a great job getting you ready for an exam.&lt;/p&gt;  &lt;p&gt;After 2 days stuck in a hotel in Atlanta because they have no clue how to get ice off the roads and using brain cells I thought I killed off in the Army I sat 3 exams:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-640&amp;amp;locale=en-us"&gt;Exam 70-640&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-642&amp;amp;locale=en-us"&gt;Exam 70-642&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-646&amp;amp;locale=en-us"&gt;Exam 70-646&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Wow boot camps are a crazy way to spend a week or 2…&lt;/p&gt;  &lt;p&gt;But I am now certified as a MCITP: Server Administrator.&lt;/p&gt;  &lt;p&gt;What certs will be next, unknown…&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Glad to be going home Tomorrow.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Chris Stauffer &amp;lt;&amp;gt;&amp;lt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=153574" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="Tech notes" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/Tech+notes/default.aspx" /><category term="All About Me" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/All+About+Me/default.aspx" /></entry><entry><title>Happy Thanksgiving</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2010/11/28/happy-thanksgiving.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2010/11/28/happy-thanksgiving.aspx</id><published>2010-11-28T15:28:51Z</published><updated>2010-11-28T15:28:51Z</updated><content type="html">&lt;p&gt;I saw this video today and just had to share it. It speaks volumes to our men and women in the military.&lt;/p&gt;  &lt;p&gt;Be safe and stay strong.&lt;/p&gt;  &lt;p&gt;To thank a soldier click the “Soldiers Angels” link on the left side of my blog.&lt;/p&gt;  &lt;p&gt;Thank you,&lt;/p&gt;  &lt;p&gt;Chris Stauffer &amp;lt;&amp;gt;&amp;lt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;h3&gt;Joe Brucato - Thank You soldier &lt;/h3&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;div style="padding-bottom:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;float:none;padding-top:0px;" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:a6ad380d-5d83-4b76-81f1-234c495daf1e" class="wlWriterEditableSmartContent"&gt;&lt;div&gt;&lt;object width="480" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/92OCzvjokP8?hl=en&amp;amp;hd=1"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/92OCzvjokP8?hl=en&amp;amp;hd=1" type="application/x-shockwave-flash" width="480" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;/div&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=152868" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="All About Me" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/All+About+Me/default.aspx" /></entry><entry><title>CompTIA Security + Certified</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2010/11/05/comptia-security-certified.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2010/11/05/comptia-security-certified.aspx</id><published>2010-11-05T16:48:00Z</published><updated>2010-11-05T16:48:00Z</updated><content type="html">&lt;p&gt;Wow I just spend the last week at &lt;a href="http://www.cedsolutions.com/" target="_blank"&gt;CED Solutions&lt;/a&gt; training for the &lt;a href="http://www.comptia.org/certifications/listed/security.aspx" target="_blank"&gt;CompTIA Security + certification&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;My brain hurts &lt;img style="border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;" class="wlEmoticon wlEmoticon-nerdsmile" alt="Nerd smile" src="http://myitforum.com/cs2/blogs/cstauffer/wlEmoticon-nerdsmile_61E85B4A.png" /&gt; …&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;BUT I PASSED.&lt;img style="border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;" class="wlEmoticon wlEmoticon-smilewithtongueout" alt="Smile with tongue out" src="http://myitforum.com/cs2/blogs/cstauffer/wlEmoticon-smilewithtongueout_689B64CD.png" /&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Got in under the radar so one less exam to have to &lt;a href="http://myitforum.com/cs2/blogs/cstauffer/archive/2010/05/13/still-comptia-a-certified.aspx" target="_blank"&gt;repeat every 3 years&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Doing the happy Dance !!!&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=152379" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author><category term="All About Me" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/All+About+Me/default.aspx" /><category term="OT Ramblings" scheme="http://myitforum.com/cs2/blogs/cstauffer/archive/tags/OT+Ramblings/default.aspx" /></entry><entry><title>GPO Corruption caused an IPSec LOCKDOWN on a Domain Controller</title><link rel="alternate" type="text/html" href="http://myitforum.com/cs2/blogs/cstauffer/archive/2010/05/19/gpo-corruption-caused-an-ipsec-lockdown-on-a-domain-controller.aspx" /><id>http://myitforum.com/cs2/blogs/cstauffer/archive/2010/05/19/gpo-corruption-caused-an-ipsec-lockdown-on-a-domain-controller.aspx</id><published>2010-05-20T01:06:50Z</published><updated>2010-05-20T01:06:50Z</updated><content type="html">&lt;p&gt;Last week was a nightmare for me with problems. I have a major security inspection coming soon and we have certain standards that are required on our Domain controllers. So i spent the last month building a GPO for the Domain Controllers that was based on the security settings. The&amp;#160; old policy was not put together very well and wasn&amp;#39;t secure by any means.&lt;/p&gt;  &lt;p&gt;Anyway one May 1st 2010 I applied the policy to my first of many DC’s and everything went well. So 7 days later I added a few more DC’s. Everything was going well and i was about 10 days into the new policy without issues. We did a Retina scan and found a few patches and a few other security issues so i fixed them and rebooted the server. After rebooting the server i was not able to get to the network or the internet. My first though was that maybe something happened to the nic card or the port on the switch, so we did the following:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Replaced the network cable&lt;/li&gt;    &lt;li&gt;changed the nic card the server was using&lt;/li&gt;    &lt;li&gt;changed the switch port the server was using&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;We even checked the firewall logs and even tried pinging it from the switch. Nothing worked not response in or out of the server.&lt;/p&gt;  &lt;p&gt;Next i rolled back all of the patches and fixes that i had applied and still nothing.&lt;/p&gt;  &lt;p&gt;Next we disabled Mcafee AV and HIPS and still nothing. The weird thing was that we could ping the machine while it rebooted but as soon as it said applying policies the ping would stop. I reviewed the event logs and had several error codes 1085 and 8194 every 5 min but the error didn&amp;#39;t make any sense so i didn&amp;#39;t know what to do. I thought there was a policy issue but i had nothing to prove it, i even rolled the machine back to the old policy. There were NO IPSEC errors of any kind so i didn&amp;#39;t mess with that. As far as i knew it was still disabled.&lt;/p&gt;  &lt;p&gt;Nothing worked.&lt;/p&gt;  &lt;p&gt;Oh and the other DC’s with the new Policy are all still running with out issue. So i didn&amp;#39;t thing it was something in the new GPO but i rolled it back just in case.&lt;/p&gt;  &lt;p&gt; After 5 hours of troubleshooting i went home for the night because Daddy needed to watch the kids so my wife could go to work and came in bright and early the next morning. I did some research from home that evening but i couldn’t work on the DC because i couldn’t connect to it. I posted to the guys on the SMS and AD GPO lists to see if any of the awesome minds their had any clue as to what the heck i did. I got to work at 6am and started working again, by 8AM my boss was in so I asked if we could contact MS because I was clearly over my head and drowning fast. He approved the request so I put in the ticket and waited for the call back cue. But like any good tech I continued to try and figure out if I could fix the issue and noted every step that I took, in hopes that I could some how fix this mess before the 6 hour call back wait.&lt;/p&gt;  &lt;p&gt;Michael Hennessy on the SMS list suggested that he thought it sounded like an IPSEC issue and that I should have some error codes for the issues but I did not. He suggested several KB articles including this one &lt;a href="http://support.microsoft.com/kb/912023"&gt;http://support.microsoft.com/kb/912023&lt;/a&gt; . I reviewed it and though aw what the heck, I don&amp;#39;t have the error but at this point i have nothing to loose so I will give it a shot. First thing it says is to delete the reg keys associated with the policy, well the keys were missing. That made me suspicious so I continued on. It had me re-register the polstore.dll. As soon as I did the internet and network started to work again. (FYI I am now 10 hours into troubleshooting and 3 hours into an MS ticket call cue). So I am ecstatic that i got the network working again but i needed to fix my policies that were now corrupt but I could not get GPUPDATE /force to work. I just kept getting&amp;#160; error codes 1085 and 8194 every 5 min. So back to Google were I found an entry that stated to delete&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\History&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;So I backed it up and deleted it. Then ran GPUPDATE /force&amp;#160; again and the errors stopped.&lt;/p&gt;  &lt;p&gt;So now it is about 24 hours after the issue and I got all of my issues fixed but still don&amp;#39;t know what went wrong. I reapplied the patches and re enabled mcafee and hips. Everything is still working. Se we contacted MS who had not gotten to our call back yet (7 hours in to the cue) and asked for a root cause analysis.&lt;/p&gt;  &lt;p&gt;Well i finally got a call back yesterday (6 days after the issue) i would say that is bad CS but we just had a problem matching up with MS and frankly I was fixed so I wasn’t in a hurry at that point.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Anyway I spoke with an MS Tech yesterday and here is the conclusion:&lt;/p&gt;    &lt;p&gt;Something interrupted Server 2003 from writing the GPO settings to the registry during a GPO refresh (happens every 90 min), Our best guess would be HIPS protecting the registry, but we have no way to prove or disprove it. So i am not going to blame it but i still despise the product…&lt;/p&gt;    &lt;p&gt;&lt;font color="#e17100"&gt;Something i didn&amp;#39;t know was that every time your GPO is applied the system deletes all of the reg key&amp;#160; entries from the previous policies and re applies all the settings with fresh keys, but it happens so fast that you don&amp;#39;t see the keys being erased and re-written.&lt;/font&gt;&amp;#160;&lt;/p&gt;    &lt;p&gt;When this corruption occurred it caused the IPSec policy to be erased and put the server into a IPSec (built in firewall) LOCKDOWN (nothing in / nothing out). This is by Design and this is why KB912023 fixed the disconnection issue. &lt;/p&gt;    &lt;p&gt;Apparently this corruption is a know issue and the MS Tech provided a hotfix that we should apply to all the DC&amp;#39;s so it doesn&amp;#39;t happen again: &lt;a href="http://support.microsoft.com/kb/951059"&gt;http://support.microsoft.com/kb/951059&lt;/a&gt; . This is a POST Server 2003 SP2 hotfix. Installing hotfix 951059 will cause the system to back up the registry and replay it if MS is interrupted during the policy wipe / re-write process. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;So in conclusion i hope this blog entry helps someone else if they get locked out by IPSEC and have no clue what is happening.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Chris Stauffer &amp;lt;&amp;gt;&amp;lt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=146989" width="1" height="1"&gt;</content><author><name>cstauffer</name><uri>http://myitforum.com/cs2/members/cstauffer.aspx</uri></author></entry></feed>
