<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>My Fried Tech! - Windows 2008</title>
    <link>http://www.myfriedmind.com/techBlog/</link>
    <description>oddities from my work</description>
    <language>en-us</language>
    <copyright>Matt Mcknight</copyright>
    <lastBuildDate>Tue, 03 Aug 2010 20:50:12 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.3.9074.18820</generator>
    <managingEditor>matt@em.org</managingEditor>
    <webMaster>matt@em.org</webMaster>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=14097a04-1beb-43fd-b763-5f236ac8f58b</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,14097a04-1beb-43fd-b763-5f236ac8f58b.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,14097a04-1beb-43fd-b763-5f236ac8f58b.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=14097a04-1beb-43fd-b763-5f236ac8f58b</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I could not remote desktop to one of my servers so I actually had to get up and walk
over to it. 
<br /></p>
        <p>
Sheesh!
</p>
        <p>
I had the firewall already happy, had Remote Desktop enabled. Luckily, the solution
was fairly easy to fix. The server was part of a cluster and it had the network connection
listed as Public, not Work. If this happens to you, simply open up the Network and
Sharing Center, right click on the appropriate 'active network' and select Work.
</p>
        <p>
My favorite bit in the description for Work network is "Don't choose this for public
places such as coffee shops or airports." Hey, but what if I work there???<br /></p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/publicNetwork.jpg" border="0" />
        </p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=14097a04-1beb-43fd-b763-5f236ac8f58b" />
      </body>
      <title>Unable to connect via Remote Desktop to Windows 2008 server</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,14097a04-1beb-43fd-b763-5f236ac8f58b.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2010/08/03/UnableToConnectViaRemoteDesktopToWindows2008Server.aspx</link>
      <pubDate>Tue, 03 Aug 2010 20:50:12 GMT</pubDate>
      <description>&lt;p&gt;
I could not remote desktop to one of my servers so I actually had to get up and walk
over to it. 
&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
Sheesh!
&lt;/p&gt;
&lt;p&gt;
I had the firewall already happy, had Remote Desktop enabled. Luckily, the solution
was fairly easy to fix. The server was part of a cluster and it had the network connection
listed as Public, not Work. If this happens to you, simply open up the Network and
Sharing Center, right click on the appropriate 'active network' and select Work.
&lt;/p&gt;
&lt;p&gt;
My favorite bit in the description for Work network is "Don't choose this for public
places such as coffee shops or airports." Hey, but what if I work there???&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/publicNetwork.jpg" border="0"&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=14097a04-1beb-43fd-b763-5f236ac8f58b" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,14097a04-1beb-43fd-b763-5f236ac8f58b.aspx</comments>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=347682b4-62b3-42f5-bc5a-22ca806d3d99</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,347682b4-62b3-42f5-bc5a-22ca806d3d99.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,347682b4-62b3-42f5-bc5a-22ca806d3d99.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=347682b4-62b3-42f5-bc5a-22ca806d3d99</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
My Windows Update service on one a w08r2 x64 box told me that I had an update.
</p>
        <p>
          <img style="padding-left: 15px;" src="http://www.myfriedmind.com/techBlog/content/binary/wsus1Update.jpg" border="0" />
        </p>
        <p>
So I checked and discovered that it was KB967723.
</p>
        <p>
          <img style="padding-left: 15px;" src="http://www.myfriedmind.com/techBlog/content/binary/wsusKB937723.jpg" border="0" />
        </p>
        <p>
I ran the install but it failed with error code 80070490
</p>
        <p>
          <img style="padding-left: 15px;" src="http://www.myfriedmind.com/techBlog/content/binary/wsusKB937723Error.jpg" border="0" />
        </p>
        <p>
After trying various solutions (such as turning off the Windows Update service and
moving the log files) I finally manually downloaded the problematic file and installed
it. No more problems. I don't know what was the issue - was it snagging the x86 version?
was it getting the Vista one? Whatever triggered it, this resolved it.<br /></p>
        <p>
Download Locations:
</p>
        <ul>
          <li>
x64 - <a href="http://www.microsoft.com/downloads/details.aspx?familyid=6E46822E-F79D-492D-AD01-EE680AD324F5&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=6E46822E-F79D-492D-AD01-EE680AD324F5&amp;displaylang=en</a><br /></li>
          <li>
x86 - <a href="http://www.microsoft.com/downloads/details.aspx?familyid=35c1d5a9-a953-4fc6-90c0-d2358c7b89e6&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=35c1d5a9-a953-4fc6-90c0-d2358c7b89e6&amp;displaylang=en</a><br /></li>
        </ul>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=347682b4-62b3-42f5-bc5a-22ca806d3d99" />
      </body>
      <title>Wsus Windows 2008 R2 x64 giving Error Code 80070490 on KB937723 update</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,347682b4-62b3-42f5-bc5a-22ca806d3d99.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2010/04/21/WsusWindows2008R2X64GivingErrorCode80070490OnKB937723Update.aspx</link>
      <pubDate>Wed, 21 Apr 2010 15:34:16 GMT</pubDate>
      <description>&lt;p&gt;
My Windows Update service on one a w08r2 x64 box told me that I had an update.
&lt;/p&gt;
&lt;p&gt;
&lt;img style="padding-left: 15px;" src="http://www.myfriedmind.com/techBlog/content/binary/wsus1Update.jpg" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
So I checked and discovered that it was KB967723.
&lt;/p&gt;
&lt;p&gt;
&lt;img style="padding-left: 15px;" src="http://www.myfriedmind.com/techBlog/content/binary/wsusKB937723.jpg" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
I ran the install but it failed with error code 80070490
&lt;/p&gt;
&lt;p&gt;
&lt;img style="padding-left: 15px;" src="http://www.myfriedmind.com/techBlog/content/binary/wsusKB937723Error.jpg" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
After trying various solutions (such as turning off the Windows Update service and
moving the log files) I finally manually downloaded the problematic file and installed
it. No more problems. I don't know what was the issue - was it snagging the x86 version?
was it getting the Vista one? Whatever triggered it, this resolved it.&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
Download Locations:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
x64 - &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=6E46822E-F79D-492D-AD01-EE680AD324F5&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=6E46822E-F79D-492D-AD01-EE680AD324F5&amp;amp;displaylang=en&lt;/a&gt;
&lt;br&gt;
&lt;/li&gt;
&lt;li&gt;
x86 - &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=35c1d5a9-a953-4fc6-90c0-d2358c7b89e6&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=35c1d5a9-a953-4fc6-90c0-d2358c7b89e6&amp;amp;displaylang=en&lt;/a&gt;
&lt;br&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=347682b4-62b3-42f5-bc5a-22ca806d3d99" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,347682b4-62b3-42f5-bc5a-22ca806d3d99.aspx</comments>
      <category>Windows 2008</category>
      <category>WSUS</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=b27538d2-f0e4-4c80-b6b5-c39f87667c13</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,b27538d2-f0e4-4c80-b6b5-c39f87667c13.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,b27538d2-f0e4-4c80-b6b5-c39f87667c13.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=b27538d2-f0e4-4c80-b6b5-c39f87667c13</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
We recently had a case where a user moved a folder into another folder expecting that
the permissions in the parent folder would automatically roll on down. Of course they
did not, when you copy WITHIN a volume it maintains its original perms.
</p>
        <p>
What was really interesting is what happened when we tried to use the ole 'Replace
all child object permissions with inheritable permission from this object'. Although
the user was copied down, the perms were not. The user DID NOT get the inherited perms
on the sub objects.
</p>
        <p>
You have to dig to find the correct checkbox.
</p>
        <ul>
          <li>
Open up the properties for the parent folder</li>
          <li>
Selected "Advanced"</li>
          <li>
Select "Change Permissions"</li>
          <li>
Make sure "Replace all child object permissions with inheritable permissions from
this object" is checked.</li>
          <li>
Click on the user/group that you want to push the perms down for and select the "Edit"
button</li>
          <li>
Make sure that the "Apply these permissions to objects and/or containers within this
container only IS CHECKED (note it is not checked in my image)</li>
          <li>
Click 'OK' till you are done...</li>
        </ul>
        <br />
        <img src="http://www.myfriedmind.com/techBlog/content/binary/permRolldown.jpg" border="0" />
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=b27538d2-f0e4-4c80-b6b5-c39f87667c13" />
      </body>
      <title>Windows 2008 pushing inherited permissions down</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,b27538d2-f0e4-4c80-b6b5-c39f87667c13.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2010/04/09/Windows2008PushingInheritedPermissionsDown.aspx</link>
      <pubDate>Fri, 09 Apr 2010 15:17:48 GMT</pubDate>
      <description>&lt;p&gt;
We recently had a case where a user moved a folder into another folder expecting that
the permissions in the parent folder would automatically roll on down. Of course they
did not, when you copy WITHIN a volume it maintains its original perms.
&lt;/p&gt;
&lt;p&gt;
What was really interesting is what happened when we tried to use the ole 'Replace
all child object permissions with inheritable permission from this object'. Although
the user was copied down, the perms were not. The user DID NOT get the inherited perms
on the sub objects.
&lt;/p&gt;
&lt;p&gt;
You have to dig to find the correct checkbox.
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
Open up the properties for the parent folder&lt;/li&gt;
&lt;li&gt;
Selected "Advanced"&lt;/li&gt;
&lt;li&gt;
Select "Change Permissions"&lt;/li&gt;
&lt;li&gt;
Make sure "Replace all child object permissions with inheritable permissions from
this object" is checked.&lt;/li&gt;
&lt;li&gt;
Click on the user/group that you want to push the perms down for and select the "Edit"
button&lt;/li&gt;
&lt;li&gt;
Make sure that the "Apply these permissions to objects and/or containers within this
container only IS CHECKED (note it is not checked in my image)&lt;/li&gt;
&lt;li&gt;
Click 'OK' till you are done...&lt;/li&gt;
&lt;/ul&gt;
&lt;br&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/permRolldown.jpg" border="0"&gt;&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=b27538d2-f0e4-4c80-b6b5-c39f87667c13" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,b27538d2-f0e4-4c80-b6b5-c39f87667c13.aspx</comments>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=b34d9c25-df01-4292-bf34-8195bd0171f6</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,b34d9c25-df01-4292-bf34-8195bd0171f6.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,b34d9c25-df01-4292-bf34-8195bd0171f6.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=b34d9c25-df01-4292-bf34-8195bd0171f6</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">Working on the SP2010 beta I bumped into
an issue with search. I decided, after various attempts to fix it different ways,
to rerun the Sharepoint 2010 Products Configuration Wizard. But when I did I ran into
an error on Step #5 - namely a System.Security.Cryptography.CryptographicException
of "Object Already Exists".<br /><br /><img src="http://www.myfriedmind.com/techBlog/content/binary/rsaSP2010Error.jpg" border="0" /><br /><p>
This was verified by checking the logs. I tried many, many things to resolve it, including
making sure "Network Service" had full control over the 14-hive, per <a href="http://www.dev4side.com/community/blog/2010/3/1/principal-errors-during-sharepoint-2010-beta-2-installation.aspx">this
blog</a> and setting up Network Service using the aspnet_regiis -SampleKeys, etc.
I even disabled the UAC (<a href="http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx">see
my earlier post for an explanation</a>).
</p><p>
No dice.<br /></p><p>
The resolution lay, as you may be suspecting, in messed up perms on the RSA folder,
specifically C:\Program Data\Microsoft\Crypto\RSA\<font color="#ff0000">MachineKeys</font>.
I had checked to the RSA level and Administrators had full perms (I was logged on
as with an Administrative account) but I had not taken the next step and checked MachineKeys.
</p><p>
Turns out that that folder had removed all perms from Adminstrators. I ended up having
to take ownership of the folder and give Admins full perms again. Sure enough - it
worked...
</p><p>
As a bonus it DID fix my Search problem (I was getting "The search request was unable
to connect to the Search Service.").
</p><p>
Maybe.<br /></p><img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=b34d9c25-df01-4292-bf34-8195bd0171f6" /></body>
      <title>Sharepoint 2010 Configuration Wizard "Failed To Register Sharepoint Services" with System.Security.Cryptography.CryptographicException Object Already Exists</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,b34d9c25-df01-4292-bf34-8195bd0171f6.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2010/03/12/Sharepoint2010ConfigurationWizardFailedToRegisterSharepointServicesWithSystemSecurityCryptographyCryptographicExceptionObjectAlreadyExists.aspx</link>
      <pubDate>Fri, 12 Mar 2010 19:08:17 GMT</pubDate>
      <description>Working on the SP2010 beta I bumped into an issue with search. I decided, after various attempts to fix it different ways, to rerun the Sharepoint 2010 Products Configuration Wizard. But when I did I ran into an error on Step #5 - namely a System.Security.Cryptography.CryptographicException of "Object Already Exists".&lt;br&gt;
&lt;br&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/rsaSP2010Error.jpg" border="0"&gt;
&lt;br&gt;
&lt;p&gt;
This was verified by checking the logs. I tried many, many things to resolve it, including
making sure "Network Service" had full control over the 14-hive, per &lt;a href="http://www.dev4side.com/community/blog/2010/3/1/principal-errors-during-sharepoint-2010-beta-2-installation.aspx"&gt;this
blog&lt;/a&gt; and setting up Network Service using the aspnet_regiis -SampleKeys, etc.
I even disabled the UAC (&lt;a href="http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx"&gt;see
my earlier post for an explanation&lt;/a&gt;).
&lt;/p&gt;
&lt;p&gt;
No dice.&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
The resolution lay, as you may be suspecting, in messed up perms on the RSA folder,
specifically C:\Program Data\Microsoft\Crypto\RSA\&lt;font color="#ff0000"&gt;MachineKeys&lt;/font&gt;.
I had checked to the RSA level and Administrators had full perms (I was logged on
as with an Administrative account) but I had not taken the next step and checked MachineKeys.
&lt;/p&gt;
&lt;p&gt;
Turns out that that folder had removed all perms from Adminstrators. I ended up having
to take ownership of the folder and give Admins full perms again. Sure enough - it
worked...
&lt;/p&gt;
&lt;p&gt;
As a bonus it DID fix my Search problem (I was getting "The search request was unable
to connect to the Search Service.").
&lt;/p&gt;
&lt;p&gt;
Maybe.&lt;br&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=b34d9c25-df01-4292-bf34-8195bd0171f6" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,b34d9c25-df01-4292-bf34-8195bd0171f6.aspx</comments>
      <category>Sharepoint 2010</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=b9c0d0ba-743f-47f7-bc53-45106be9bbf2</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,b9c0d0ba-743f-47f7-bc53-45106be9bbf2.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,b9c0d0ba-743f-47f7-bc53-45106be9bbf2.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=b9c0d0ba-743f-47f7-bc53-45106be9bbf2</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
There appears to be an issue with w08r2 when it comes to using Hyper-V. When
attempting to launch your VM you might encounter the error: The application
encountered an error while attempting to change the state of %yourVM%.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsError.JPG" border="0" />
        </p>
        <p>
The solution seems very simple (thanks to this post) which is that you need
to give 'Authenticated Users' the 'List folder / read data' permission
at the root of the drive that contains the Virtual Machines (and you ONLY need
to do it at that level, not the ones below).
</p>
        <p>
Why this solves the problem I do not know, but here are the steps (with some pictures)
to walk you through the process:
</p>
        <p>
1 - Open up the root of the drive's properties and choose the Security tab. Click
on the Advanced button
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsAdv.JPG" border="0" />
        </p>
        <p>
2. Click on 'Change Permissions'
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsChange.JPG" border="0" />
        </p>
        <p>
3. Click on 'Add', Type in 'Authenticated Users' and hit the OK button, you should
see the screen below. Change the "Apply to:" to be "This folder only" and put a check
in to the "List folder / read data" check box. Click 'OK'
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsSettings.JPG" border="0" />
        </p>
        <p>
4. Make sure NOT to check the 'Replace all child objects...' checkbox. Check your
settings, and click OK. Click OK to close the Properties screen for the drive and
you should be good to go.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsNoCheck.JPG" border="0" />
        </p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=b9c0d0ba-743f-47f7-bc53-45106be9bbf2" />
      </body>
      <title>Hyper-V, Windows 2008 R2, and 'MyVM' could not initialize error</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,b9c0d0ba-743f-47f7-bc53-45106be9bbf2.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/10/29/HyperVWindows2008R2AndMyVMCouldNotInitializeError.aspx</link>
      <pubDate>Thu, 29 Oct 2009 15:18:14 GMT</pubDate>
      <description>&lt;p&gt;
There appears to be an issue with&amp;nbsp;w08r2 when it comes to using Hyper-V. When
attempting to&amp;nbsp;launch your VM you might encounter the error:&amp;nbsp;The&amp;nbsp;application
encountered an error while attempting to change the state of %yourVM%.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsError.JPG" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
The solution&amp;nbsp;seems very simple (thanks to this post) which&amp;nbsp;is that you need
to give&amp;nbsp;'Authenticated&amp;nbsp;Users' the&amp;nbsp;'List folder / read data'&amp;nbsp;permission
at the root of the drive that contains the Virtual Machines (and you&amp;nbsp;ONLY need
to do it at that level, not the ones below).
&lt;/p&gt;
&lt;p&gt;
Why this solves the problem I do not know, but here are the steps (with some pictures)
to walk you through the process:
&lt;/p&gt;
&lt;p&gt;
1 - Open up the root of the drive's properties and choose the Security tab. Click
on the Advanced button
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsAdv.JPG" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
2. Click on 'Change Permissions'
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsChange.JPG" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
3. Click on 'Add', Type in 'Authenticated Users' and hit the OK button, you should
see the screen below. Change the "Apply to:" to be "This folder only" and put a check
in to the "List folder / read data" check box. Click 'OK'
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsSettings.JPG" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
4. Make sure NOT to check the 'Replace all child objects...' checkbox. Check your
settings, and click OK. Click OK to close the Properties screen for the drive and
you should be good to go.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/vmRootPermsNoCheck.JPG" border=0&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=b9c0d0ba-743f-47f7-bc53-45106be9bbf2" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,b9c0d0ba-743f-47f7-bc53-45106be9bbf2.aspx</comments>
      <category>Virtual Server</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=36e36dd3-cbbb-41e1-9f19-d35f5b921f71</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,36e36dd3-cbbb-41e1-9f19-d35f5b921f71.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,36e36dd3-cbbb-41e1-9f19-d35f5b921f71.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=36e36dd3-cbbb-41e1-9f19-d35f5b921f71</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
When clustering two servers together you may still want to set up private network
connections. If you do hook a crossover cable and give it a different set of IPs from
your domain you may find that the private network does not working. Pinging will return
no responses. What you may have run into is that the Windows Firewall is interpreting
your little private network as being 'Public' and so is block all communications in.
</p>
        <p>
The solution depends on what flavor of w08 you are running. If you are running w08
you can go into the "Network and Sharing Center" and customize the network to be "Private"
which will allow communication through. If you are running w08r2 it is not so simple.
You have to go into Windows Firewall and explicitly tell it NOT to apply "Public"
rules to the adapter you are using for your private network. 
</p>
        <p>
Because a picture is worth a thousand words:
</p>
        <p>
Windows 2008 (non-R2)
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/w08ClusterNW0.gif" border="1" />
        </p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/w08ClusterNW1.gif" border="0" />
        </p>
        <p>
Windows 2008 R2
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/w08r2ClusterFW0.gif" border="1" />
        </p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/w08r2ClusterFW1.gif" border="0" />
        </p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/w08r2ClusterFW2.gif" border="0" />
        </p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=36e36dd3-cbbb-41e1-9f19-d35f5b921f71" />
      </body>
      <title>Windows 2008 Cluster and Getting the Private Network to Work</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,36e36dd3-cbbb-41e1-9f19-d35f5b921f71.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/10/22/Windows2008ClusterAndGettingThePrivateNetworkToWork.aspx</link>
      <pubDate>Thu, 22 Oct 2009 19:59:15 GMT</pubDate>
      <description>&lt;p&gt;
When clustering two servers together you may still want to set up private network
connections. If you do hook a crossover cable and give it a different set of IPs from
your domain you may find that the private network does not working. Pinging will return
no responses. What you may have run into is that the Windows Firewall is interpreting
your little private network as being 'Public' and so is block all communications in.
&lt;/p&gt;
&lt;p&gt;
The solution depends on what flavor of w08 you are running. If you are running w08
you can go into the "Network and Sharing Center" and customize the network to be "Private"
which will allow communication through. If you are running w08r2 it is not so simple.
You have to go into Windows Firewall and explicitly tell it NOT to apply "Public"
rules to the adapter you are using for your private network.&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
Because a picture is worth a thousand words:
&lt;/p&gt;
&lt;p&gt;
Windows 2008 (non-R2)
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/w08ClusterNW0.gif" border="1"&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/w08ClusterNW1.gif" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
Windows 2008 R2
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/w08r2ClusterFW0.gif" border="1"&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/w08r2ClusterFW1.gif" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/w08r2ClusterFW2.gif" border="0"&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=36e36dd3-cbbb-41e1-9f19-d35f5b921f71" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,36e36dd3-cbbb-41e1-9f19-d35f5b921f71.aspx</comments>
      <category>Clustering</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=a3987d9c-93f1-4926-8e93-7b6f148611ab</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,a3987d9c-93f1-4926-8e93-7b6f148611ab.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,a3987d9c-93f1-4926-8e93-7b6f148611ab.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=a3987d9c-93f1-4926-8e93-7b6f148611ab</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
When are Domain Admins NOT Domain Admins?<img src="http://www.myfriedmind.com/techBlog/content/binary/kryptonite.gif" align="right" border="0" /></p>
        <p>
I stumbled across some strange errors when using the UAC as a Non-Default Admin (NDA).
When logged in as an NDA and not the Built-In Administrator Account (BIAA) I ran into
permission issues with the User Access Control (UAC) turned on. It appeared as if
the w08 box (and w08r2) could not enumerate Domain Admins membership then the UAC
is turned on. Even when I gave Domain Admins Full Control of a folder (or a drive)
it would not recognize membership therein.
</p>
        <p>
More info (than you might want) on that at my entry here: <a href="http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx">http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx</a>. 
</p>
        <p>
This is the follow up to that, after I got a hold of MSoft. I called in and even though
it was the middle of the night for the gentleman on the other end of the line (he
was in India) he was very coherent and helpful. Or perhaps, helpful is not the right
word since I found the solution that Msoft suggests rather, ummm, absurd. This should
not reflect on him at all, he was great, it is just the, ummm, solution that is whacky.
</p>
        <p>
After some testing with me he did verify that I was right and that the issue was with
the Domain Admins membership enumeration. He then did some research and located this
article: <a href="http://technet.microsoft.com/en-us/library/cc772207(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc772207(WS.10).aspx</a>. 
</p>
        <p>
This lays out what is triggering the issue, how w08 (and Vista) handle Admin Approval
Mode (AAM). Again, you can read my earlier post for more background if you want. Basically,
Domain Admins, unlike ALL OTHER USERS, are given two tokens. They have the full access
token (like everyone else) and a second access token referred to as the filtered access
token. This filtered access token has the administrative powers removed. Explorer.exe
(ie the root of all) is started with the filtered access token, and thus everything
is started with it.
</p>
        <p>
Think of it is as RUNAS in reverse. Rather than being a Domain Admin you are reduced
to peon status. It is, in effect, kryptonite.
</p>
        <p>
The solution that MSoft gave was very simple – do not use the Domain Admins account.
At least for file and folder permissions. Create a TOTALLY NEW group and assign the
people that you would normally have as Domain Admins in there. Then give THAT group
the permissions that you want.
</p>
        <p>
You know, that answer still makes me chuckle. What a stupid, stupid solution. Here's
why
</p>
        <ol>
          <li>
It does not actually do the AAM thing. It does not ask me for consent, credentials,
whatever I have it set to. It just says NO when I try to access a folder. No discussion.
So UAC is not actually doing its job here. 
</li>
          <li>
I can access the share of the drive or the folder if I do it via shared drives. It
is only an issue if I am logged on directly to the box. I really get using UAC to
prevent malicious software install, but to stop me from opening a folder??? So now
I need to be the Domain Admins to log on to the server, but something completely different
to access a folder. 
</li>
          <li>
It has no affect on the Built-In Administrator Account. 
</li>
        </ol>
        <p>
I already have a group that I want to use for file and folder permissions or sensitive
areas. The Domain Admins. And with good reason, because they are the DOMAIN ADMINS!!!!!!!!
Now I have to track two groups. All because the UAC will not play well with others.
</p>
        <p>
Here is my solution –&gt; Hey UAC! Buh-bye!!!!!<br /></p>
        <img src="http://www.myfriedmind.com/techBlog/content/binary/buh-bye.gif" border="0" />
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=a3987d9c-93f1-4926-8e93-7b6f148611ab" />
      </body>
      <title>UAC and Domain Admins Permissions Issue or Pocket Full of Kryptonite</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,a3987d9c-93f1-4926-8e93-7b6f148611ab.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx</link>
      <pubDate>Tue, 20 Oct 2009 17:07:51 GMT</pubDate>
      <description>&lt;p&gt;
When are Domain Admins NOT Domain Admins?&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/kryptonite.gif" align=right border=0&gt;
&lt;/p&gt;
&lt;p&gt;
I stumbled across some strange errors when using the UAC as a Non-Default Admin (NDA).
When logged in as an NDA and not the Built-In Administrator Account (BIAA) I ran into
permission issues with the User Access Control (UAC) turned on. It appeared as if
the w08 box (and w08r2) could not enumerate Domain Admins membership then the UAC
is turned on. Even when I gave Domain Admins Full Control of a folder (or a drive)
it would not recognize membership therein.
&lt;/p&gt;
&lt;p&gt;
More info (than you might want) on that at my entry here: &lt;a href="http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx"&gt;http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx&lt;/a&gt;. 
&lt;/p&gt;
&lt;p&gt;
This is the follow up to that, after I got a hold of MSoft. I called in and even though
it was the middle of the night for the gentleman on the other end of the line (he
was in India) he was very coherent and helpful. Or perhaps, helpful is not the right
word since I found the solution that Msoft suggests rather, ummm, absurd. This should
not reflect on him at all, he was great, it is just the, ummm, solution that is whacky.
&lt;/p&gt;
&lt;p&gt;
After some testing with me he did verify that I was right and that the issue was with
the Domain Admins membership enumeration. He then did some research and located this
article: &lt;a href="http://technet.microsoft.com/en-us/library/cc772207(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc772207(WS.10).aspx&lt;/a&gt;. 
&lt;/p&gt;
&lt;p&gt;
This lays out what is triggering the issue, how w08 (and Vista) handle Admin Approval
Mode (AAM). Again, you can read my earlier post for more background if you want. Basically,
Domain Admins, unlike ALL OTHER USERS, are given two tokens. They have the full access
token (like everyone else) and a second access token referred to as the filtered access
token. This filtered access token has the administrative powers removed. Explorer.exe
(ie the root of all) is started with the filtered access token, and thus everything
is started with it.
&lt;/p&gt;
&lt;p&gt;
Think of it is as RUNAS in reverse. Rather than being a Domain Admin you are reduced
to peon status. It is, in effect, kryptonite.
&lt;/p&gt;
&lt;p&gt;
The solution that MSoft gave was very simple – do not use the Domain Admins account.
At least for file and folder permissions. Create a TOTALLY NEW group and assign the
people that you would normally have as Domain Admins in there. Then give THAT group
the permissions that you want.
&lt;/p&gt;
&lt;p&gt;
You know, that answer still makes me chuckle. What a stupid, stupid solution. Here's
why
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
It does not actually do the AAM thing. It does not ask me for consent, credentials,
whatever I have it set to. It just says NO when I try to access a folder. No discussion.
So UAC is not actually doing its job here. 
&lt;li&gt;
I can access the share of the drive or the folder if I do it via shared drives. It
is only an issue if I am logged on directly to the box. I really get using UAC to
prevent malicious software install, but to stop me from opening a folder??? So now
I need to be the Domain Admins to log on to the server, but something completely different
to access a folder. 
&lt;li&gt;
It has no affect on the Built-In Administrator Account. 
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
I already have a group that I want to use for file and folder permissions or sensitive
areas. The Domain Admins. And with good reason, because they are the DOMAIN ADMINS!!!!!!!!
Now I have to track two groups. All because the UAC will not play well with others.
&lt;/p&gt;
&lt;p&gt;
Here is my solution –&amp;gt; Hey UAC! Buh-bye!!!!!&lt;br&gt;
&lt;/p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/buh-bye.gif" border=0&gt;&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=a3987d9c-93f1-4926-8e93-7b6f148611ab" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,a3987d9c-93f1-4926-8e93-7b6f148611ab.aspx</comments>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=03d242c8-2226-432e-8547-cd2cb9d54ebe</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,03d242c8-2226-432e-8547-cd2cb9d54ebe.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,03d242c8-2226-432e-8547-cd2cb9d54ebe.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=03d242c8-2226-432e-8547-cd2cb9d54ebe</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Note - this is tested on a Windows 2003 R2 domain.
</p>
        <p>
Further note - I have corrected it a bit - specifically the problem applies ONLY to
Domain Admins - see <a href="http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx">http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx</a> for
more info.
</p>
        <p>
A while ago I noticed something odd on my Windows 2008 clustered file server. When
I tried to open the clustered drive that I was using to hold my shares  from
the box while logged in as a non-default admin (hereafter referred to as NDA) I got
a message stating “Access is denied”. 
</p>
        <img src="http://www.myfriedmind.com/techBlog/content/binary/UACDenialOnCluster.JPG" border="0" />
        <p>
This only happened if I was logged into the box itself in the server room or via Remote
Desktop. I could access the hidden share for that drive remotely with no problem.
Also, if I logged on with the built-it administrator account (hereafter referred to
as BIAA) I had no problem. Finally, if I disabled the User Access Control (UAC) I
could access the drive with the NDA.
</p>
        <p>
Originally I thought that this might be caused by it being clustered, but Symon Perriman
from MSoft assured me that he had not heard of this. Then I thought it might be because
storage we were using and the driver – EMC PowerPath. But I put off any further testing
until I had time to work on a non-production box and to wait for W08R2 to see if that
would make a difference.
</p>
        <p>
First the good news – it does not have to do with clustering. Now the bad news – it
might be a serious issue. 
</p>
        <p>
The basic issue is that the UAC, on both W08 and W08R2 appears to have issues enumerating
membership for certain groups. What is especially unfortunate is that Domain Admins
is one of those groups that it has trouble enumerating.
</p>
        <h2>My Discovery of the Issue
</h2>
        <p>
When I created the new box to test I was initially unable to replicate the problem.
It was not until I looked closer at the clustered drive on the original box that I
realized that the problem had to do with permissions. Since the clustered drive would
contain folders that would limit who would have access I had removed the “Users” group,
leaving “CREATOR OWNER”, “SYSTEM”, “Administrators” (for that box) untouched. I then
added “Domain Admins” with Full Control since this would be clustered and I did not
want to rely on the “Administrators” of one of the nodes for perms. My plan was to
create the shares, inherit from above, and add the appropriate security groups.
</p>
        <p>
Unfortunately, with the UAC turned on I could no longer access the drive even though
the account that I was using was a member of Domain Admins, albeit not the BIAA. I
got a very strongly worded “NO”.
</p>
        <img src="http://www.myfriedmind.com/techBlog/content/binary/UACDenialOnCluster.JPG" border="0" />
        <p>
I replicated the permissions on my test box and discovered the same issue. I then
added Everyone to the root of the drive with “Read” permissions and suddenly the NDA
could access the drive.
</p>
        <p>
By POE (process of elimination &lt;g&gt;) I determined that of the four permissions
included in “Read” – “Traverse Folder / execute file”, “List folder / read data”,
“Read attributes”, and “Read extended attributes” – I only needed the middle two –
“List folder / read data” and “Read attributes”.
</p>
        <p>
Hmm, I wondered if the issue could be that some special account was being used by
the UAC to check for the drive. So I removed the “Everyone” group and added the NDA
with those two specific perms. I could access the drive. So it appeared not to be
an issue with a unique account, but more likely that the Domain Admins membership
could not be enumerated. Maybe.
</p>
        <p>
So I added an old Global Security group that the NDA belonged to (after removing the
NDA) with the necessary perms. That worked. So I removed that, added an old Local
Security group that the old Global security group belonged to. That worked.
</p>
        <p>
I am stretching for possible causes. I can conceive of no reason why the Domain Admins
membership could not be enumerated when other older groups have no issue, even when
the NDA is a member of a member of a group. The only thing that strikes me is that
all the old accounts I have used do not have spaces. Stretching, I know, but there
has to be SOME reason.
</p>
        <p>
I create two new Global Security groups – “PermTest” and “Perm Test”, one with a space
one without. I add the NDA to each and try each of the, granting them the necessary
perms. Neither one worked. So that blows that theory. Just to put a nail in the coffin
I add “Domain Users” and that works. Further testing with Msoft and I catch that I
have to Log OFF and BACK ON for this. Ooops. Those new accounts work, but Domain Admins
still will not.
</p>
        <p>
So far (when the UAC is turned on and accessing with the NDA):
</p>
        <p>
Works
</p>
        <ul>
          <li>
Directly adding NDA 
</li>
          <li>
Adding Everyone 
</li>
          <li>
Adding Domain Users 
</li>
          <li>
Adding Old Global Security groups containing NDA 
</li>
          <li>
Adding Old Local Security groups containing old Global Security groups containing
NDA 
</li>
          <li>
Adding anny counter OTHER than Domain Admins</li>
        </ul>
        <p>
Does not work
</p>
        <ul>
          <li>
Domain Admins 
</li>
          <li>
?</li>
        </ul>
        <p>
I open up ADSIEdit to look at the properties of “Domain Admins” vs “Domain Users”,
I specifically want to see when it says the whenCreated and the whenChanged attributes
are. It turns out that although they both share the same whenCreated date, the “Domain
Admins” whenChanged is more recent. Except that the old Global Security group containing
the NDA has been changed more recently and that one works.
</p>
        <p>
So that is a dead end.
</p>
        <p>
And why does the default administrator account have no problem even with UAC turned
on?
</p>
        <h2>Verification by another forest
</h2>
        <p>
I want a totally isolated confirmation so I contact a buddy of mine down in Ohio (thanks
Stuart) who is also running a w03 network with a w08 member server on it. He runs
into the exact same problem. So the issue does not appear to be bad media or erroneous
implementation, unless we both made the exact same mistakes.
</p>
        <h2>Moving to subfolders
</h2>
        <p>
I move my study to subfolders. I create a subfolder on a local drive, remove Users,
add Domain Admins and test that. I get this message “You don’t currently have permission
to access this folder”. If I choose “Continue” it adds the NDA account with Full Control
and lets me in.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08NoPerms.gif" border="0" />
        </p>
        <h2>A closer look at the UAC
</h2>
        <p>
It is past time now that we delve into the UAC which seems to be giving us such problems.
</p>
        <p>
In the original w08 it was located in the Control Panel under “User Accounts” and
you had two options there – on or off. In w08r2 it is still located in the Control
Panel but it has now been moved to “System and Security” and now you have four options
(see image). 
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08UacSettings.gif" border="0" />
        </p>
        <p>
Quick testing on w08r2 soon reveals that the only time that the NDA can access the
drive via “Domain Admins” perms is when the UAC is all the way at the bottom (ie turned
completely off).
</p>
        <p>
What you may not know is that behind the scenes these apparently limited choices actually
control ten different settings in the Local Security Policy. You can access your Local
Security Policy by going to your “Administrative Tools”. Look under Local Policies,
Security Options and at the bottom you will find the entries I am talking about.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08R2DefaultAdminIssues.gif" border="0" />
        </p>
        <p>
First, let me draw your attention to the very top one – “Admin Approval Mode for the
Built-in Administrative account”. This is the source of that odd exception – that
the built-in administrative account can access the drive regardless of the UAC settings.
This is set to Disabled and is ALWAYS set to Disabled regardless of the changes you
make in the Control Panel. The only way to change it to Enabled is to change it here.
</p>
        <p>
What will happen if it gets changed from Disabled to Enabled? Basically the built-in
administrative account (BIAA) will be treated like any other administrative account
(such as the NDA). See the “Explain tab”.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08AdminApprovalExplain.gif" border="0" />
        </p>
        <p>
So, if your devious mind is like mine you instantly wonder if changing it to Enabled
means that since the NDA cannot access the drive and since the BIAA is being treated
like the NDA now, does that mean that the BIAA cannot access the drive? The answer
is that, sure enough, the BIAA account CANNOT access the drive when it is treated
like any other admin account and UAC is on. Yeah! I have succeeded in making things
worse!
</p>
        <p>
What does it mean that the BIAA is treated like any other administrator? How does
the UAC determine how they are treated? For that I draw your attention to the third
UAC entry in the Local Security Policy – named “Behavior of the elevation prompt for
administrators in Admin Approval Mode”. This is one of the areas where w08 and w08r2
differ in their implementation of UAC. W08r2 does not add any more entries into the
Local Security Policy, instead it adds three more options to this entry and adds one
more to the subsequent (“Behavior of the elevation prompt for standard users”). See
the image below.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08andW08r2AdminSettings.gif" border="0" />
        </p>
        <p>
So there are multiple ways that administrators can interact with the UAC when it is
turned on. But what if the UAC is turned off? That affects the eighth choice –“Run
all administrators in Admin Approval Mode”. Per the Explain below, disabling this
disables Admin Approval mode, and hence (I believe) the entire UAC.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08UACOffExplain.gif" border="0" />
        </p>
        <h2>W08 and W08r2 Admin Approval Mode settings results
</h2>
        <p>
Regardless of what level I set the Admin Approval Mode to (three in w08, six in w08r2),
including “Elevate without prompting”, I was unable to open a subfolder or a root
drive that had the perms I have been talking about using the NDA account when UAC
is on. The prompts where the same – denial on root drives, prompting to grant perms
to the NDA on subfolders.
</p>
        <p>
Only when the UAC is off w08 has no problem enumerating the NDA’s membership in Domain
Admins.
</p>
        <h2>What does this all mean?
</h2>
        <p>
It seems to me the simplest solutions are:
</p>
        <ol>
          <li>
turn off the UAC 
</li>
          <li>
do not use an NDA to access the server (the above is an issue with file/folder perms,
but it might affect other aspects as well) 
</li>
          <li>
do not rely on either Domain Admins for permissions. On second thought, do not rely
on Domain Admins for ANYTHING.</li>
        </ol>
        <p>
Until this gets addressed by Msoft you are probably safest (ironically) in turning
the UAC completely off on your w08 boxes. Not ideal, especially since the addition
of “Prompt for consent for non-Windows binaries” helps remove some of the Clippy aspects
of the UAC (<a href="http://www.myfriedmind.com/techBlog/2009/09/29/UACOrTheReturnOfClippy.aspx">see
my thoughts on that here</a>). Unfortunately the UAC has its tentacles in pretty much
everything and who knows when this issue might trigger something more serious?
</p>
        <p>
On a side note, some of you may be wondering why the UAC has that particular exception
for the BIAA, especially as it is never turned off unless you do it via the Local
Security policy. I cannot read the mind of the makers, but I suspect that it has to
do with protection against elevated privileges. If you can restrict all NDAs (but
not the BIAA) then if someone does hack your system on a regular user account and
elevates themselves to an NDA they could STILL be restricted. It seems to me a logical
way to guard against that.
</p>
        <p>
Let me know what you think….
</p>
        <p>
m
</p>
        <p>
followup - <a href="http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx">http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx</a></p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=03d242c8-2226-432e-8547-cd2cb9d54ebe" />
      </body>
      <title>UAC and Domain Admins permissions issue on Windows 2008</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,03d242c8-2226-432e-8547-cd2cb9d54ebe.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx</link>
      <pubDate>Wed, 14 Oct 2009 17:18:16 GMT</pubDate>
      <description>&lt;p&gt;
Note - this is tested on a Windows 2003 R2 domain.
&lt;/p&gt;
&lt;p&gt;
Further note - I have corrected it a bit - specifically the problem applies ONLY to
Domain Admins - see &lt;a href="http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx"&gt;http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx&lt;/a&gt;&amp;nbsp;for
more info.
&lt;/p&gt;
&lt;p&gt;
A while ago I noticed something odd on my Windows 2008 clustered file server. When
I tried to open the clustered drive that I was using to hold my shares&amp;nbsp; from
the box while logged in as a non-default admin (hereafter referred to as NDA) I got
a message stating “Access is denied”. 
&lt;/p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/UACDenialOnCluster.JPG" border=0&gt; 
&lt;p&gt;
This only happened if I was logged into the box itself in the server room or via Remote
Desktop. I could access the hidden share for that drive remotely with no problem.
Also, if I logged on with the built-it administrator account (hereafter referred to
as BIAA) I had no problem. Finally, if I disabled the User Access Control (UAC) I
could access the drive with the NDA.
&lt;/p&gt;
&lt;p&gt;
Originally I thought that this might be caused by it being clustered, but Symon Perriman
from MSoft assured me that he had not heard of this. Then I thought it might be because
storage we were using and the driver – EMC PowerPath. But I put off any further testing
until I had time to work on a non-production box and to wait for W08R2 to see if that
would make a difference.
&lt;/p&gt;
&lt;p&gt;
First the good news – it does not have to do with clustering. Now the bad news – it
might be a serious issue. 
&lt;/p&gt;
&lt;p&gt;
The basic issue is that the UAC, on both W08 and W08R2 appears to have issues enumerating
membership for certain groups. What is especially unfortunate is that Domain Admins
is one of those groups that it has trouble enumerating.
&lt;/p&gt;
&lt;h2&gt;My Discovery of the Issue
&lt;/h2&gt;
&lt;p&gt;
When I created the new box to test I was initially unable to replicate the problem.
It was not until I looked closer at the clustered drive on the original box that I
realized that the problem had to do with permissions. Since the clustered drive would
contain folders that would limit who would have access I had removed the “Users” group,
leaving “CREATOR OWNER”, “SYSTEM”, “Administrators” (for that box) untouched. I then
added “Domain Admins” with Full Control since this would be clustered and I did not
want to rely on the “Administrators” of one of the nodes for perms. My plan was to
create the shares, inherit from above, and add the appropriate security groups.
&lt;/p&gt;
&lt;p&gt;
Unfortunately, with the UAC turned on I could no longer access the drive even though
the account that I was using was a member of Domain Admins, albeit not the BIAA. I
got a very strongly worded “NO”.
&lt;/p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/UACDenialOnCluster.JPG" border=0&gt; 
&lt;p&gt;
I replicated the permissions on my test box and discovered the same issue. I then
added Everyone to the root of the drive with “Read” permissions and suddenly the NDA
could access the drive.
&lt;/p&gt;
&lt;p&gt;
By POE (process of elimination &amp;lt;g&amp;gt;) I determined that of the four permissions
included in “Read” – “Traverse Folder / execute file”, “List folder / read data”,
“Read attributes”, and “Read extended attributes” – I only needed the middle two –
“List folder / read data” and “Read attributes”.
&lt;/p&gt;
&lt;p&gt;
Hmm, I wondered if the issue could be that some special account was being used by
the UAC to check for the drive. So I removed the “Everyone” group and added the NDA
with those two specific perms. I could access the drive. So it appeared not to be
an issue with a unique account, but more likely that the Domain Admins membership
could not be enumerated. Maybe.
&lt;/p&gt;
&lt;p&gt;
So I added an old Global Security group that the NDA belonged to (after removing the
NDA) with the necessary perms. That worked. So I removed that, added an old Local
Security group that the old Global security group belonged to. That worked.
&lt;/p&gt;
&lt;p&gt;
I am stretching for possible causes. I can conceive of no reason why the Domain Admins
membership could not be enumerated when other older groups have no issue, even when
the NDA is a member of a member of a group. The only thing that strikes me is that
all the old accounts I have used do not have spaces. Stretching, I know, but there
has to be SOME reason.
&lt;/p&gt;
&lt;p&gt;
I create two new Global Security groups – “PermTest” and “Perm Test”, one with a space
one without. I add the NDA to each and try each of the, granting them the necessary
perms. Neither one worked. So that blows that theory. Just to put a nail in the coffin
I add “Domain Users” and that works. Further testing with Msoft and I catch that I
have to Log OFF and BACK ON for this. Ooops. Those new accounts work, but Domain Admins
still will not.
&lt;/p&gt;
&lt;p&gt;
So far (when the UAC is turned on and accessing with the NDA):
&lt;/p&gt;
&lt;p&gt;
Works
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
Directly adding NDA 
&lt;li&gt;
Adding Everyone 
&lt;li&gt;
Adding Domain Users 
&lt;li&gt;
Adding Old Global Security groups containing NDA 
&lt;li&gt;
Adding Old Local Security groups containing old Global Security groups containing
NDA 
&lt;li&gt;
Adding anny counter OTHER than Domain Admins&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Does not work
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
Domain Admins 
&lt;li&gt;
?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
I open up ADSIEdit to look at the properties of “Domain Admins” vs “Domain Users”,
I specifically want to see when it says the whenCreated and the whenChanged attributes
are. It turns out that although they both share the same whenCreated date, the “Domain
Admins” whenChanged is more recent. Except that the old Global Security group containing
the NDA has been changed more recently and that one works.
&lt;/p&gt;
&lt;p&gt;
So that is a dead end.
&lt;/p&gt;
&lt;p&gt;
And why does the default administrator account have no problem even with UAC turned
on?
&lt;/p&gt;
&lt;h2&gt;Verification by another forest
&lt;/h2&gt;
&lt;p&gt;
I want a totally isolated confirmation so I contact a buddy of mine down in Ohio (thanks
Stuart) who is also running a w03 network with a w08 member server on it. He runs
into the exact same problem. So the issue does not appear to be bad media or erroneous
implementation, unless we both made the exact same mistakes.
&lt;/p&gt;
&lt;h2&gt;Moving to subfolders
&lt;/h2&gt;
&lt;p&gt;
I move my study to subfolders. I create a subfolder on a local drive, remove Users,
add Domain Admins and test that. I get this message “You don’t currently have permission
to access this folder”. If I choose “Continue” it adds the NDA account with Full Control
and lets me in.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08NoPerms.gif" border=0&gt; 
&lt;/p&gt;
&lt;h2&gt;A closer look at the UAC
&lt;/h2&gt;
&lt;p&gt;
It is past time now that we delve into the UAC which seems to be giving us such problems.
&lt;/p&gt;
&lt;p&gt;
In the original w08 it was located in the Control Panel under “User Accounts” and
you had two options there – on or off. In w08r2 it is still located in the Control
Panel but it has now been moved to “System and Security” and now you have four options
(see image). 
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08UacSettings.gif" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
Quick testing on w08r2 soon reveals that the only time that the NDA can access the
drive via “Domain Admins” perms is when the UAC is all the way at the bottom (ie turned
completely off).
&lt;/p&gt;
&lt;p&gt;
What you may not know is that behind the scenes these apparently limited choices actually
control ten different settings in the Local Security Policy. You can access your Local
Security Policy by going to your “Administrative Tools”. Look under Local Policies,
Security Options and at the bottom you will find the entries I am talking about.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08R2DefaultAdminIssues.gif" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
First, let me draw your attention to the very top one – “Admin Approval Mode for the
Built-in Administrative account”. This is the source of that odd exception – that
the built-in administrative account can access the drive regardless of the UAC settings.
This is set to Disabled and is ALWAYS set to Disabled regardless of the changes you
make in the Control Panel. The only way to change it to Enabled is to change it here.
&lt;/p&gt;
&lt;p&gt;
What will happen if it gets changed from Disabled to Enabled? Basically the built-in
administrative account (BIAA) will be treated like any other administrative account
(such as the NDA). See the “Explain tab”.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08AdminApprovalExplain.gif" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
So, if your devious mind is like mine you instantly wonder if changing it to Enabled
means that since the NDA cannot access the drive and since the BIAA is being treated
like the NDA now, does that mean that the BIAA cannot access the drive? The answer
is that, sure enough, the BIAA account CANNOT access the drive when it is treated
like any other admin account and UAC is on. Yeah! I have succeeded in making things
worse!
&lt;/p&gt;
&lt;p&gt;
What does it mean that the BIAA is treated like any other administrator? How does
the UAC determine how they are treated? For that I draw your attention to the third
UAC entry in the Local Security Policy – named “Behavior of the elevation prompt for
administrators in Admin Approval Mode”. This is one of the areas where w08 and w08r2
differ in their implementation of UAC. W08r2 does not add any more entries into the
Local Security Policy, instead it adds three more options to this entry and adds one
more to the subsequent (“Behavior of the elevation prompt for standard users”). See
the image below.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08andW08r2AdminSettings.gif" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
So there are multiple ways that administrators can interact with the UAC when it is
turned on. But what if the UAC is turned off? That affects the eighth choice –“Run
all administrators in Admin Approval Mode”. Per the Explain below, disabling this
disables Admin Approval mode, and hence (I believe) the entire UAC.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/uacW08UACOffExplain.gif" border=0&gt;
&lt;/p&gt;
&lt;h2&gt;W08 and W08r2 Admin Approval Mode settings results
&lt;/h2&gt;
&lt;p&gt;
Regardless of what level I set the Admin Approval Mode to (three in w08, six in w08r2),
including “Elevate without prompting”, I was unable to open a subfolder or a root
drive that had the perms I have been talking about using the NDA account when UAC
is on. The prompts where the same – denial on root drives, prompting to grant perms
to the NDA on subfolders.
&lt;/p&gt;
&lt;p&gt;
Only when the UAC is off w08 has no problem enumerating the NDA’s membership in Domain
Admins.
&lt;/p&gt;
&lt;h2&gt;What does this all mean?
&lt;/h2&gt;
&lt;p&gt;
It seems to me the simplest solutions are:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
turn off the UAC 
&lt;li&gt;
do not use an NDA to access the server (the above is an issue with file/folder perms,
but it might affect other aspects as well) 
&lt;li&gt;
do not rely on either Domain Admins for permissions. On second thought, do not rely
on Domain Admins for ANYTHING.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
Until this gets addressed by Msoft you are probably safest (ironically) in turning
the UAC completely off on your w08 boxes. Not ideal, especially since the addition
of “Prompt for consent for non-Windows binaries” helps remove some of the Clippy aspects
of the UAC (&lt;a href="http://www.myfriedmind.com/techBlog/2009/09/29/UACOrTheReturnOfClippy.aspx"&gt;see
my thoughts on that here&lt;/a&gt;). Unfortunately the UAC has its tentacles in pretty much
everything and who knows when this issue might trigger something more serious?
&lt;/p&gt;
&lt;p&gt;
On a side note, some of you may be wondering why the UAC has that particular exception
for the BIAA, especially as it is never turned off unless you do it via the Local
Security policy. I cannot read the mind of the makers, but I suspect that it has to
do with protection against elevated privileges. If you can restrict all NDAs (but
not the BIAA) then if someone does hack your system on a regular user account and
elevates themselves to an NDA they could STILL be restricted. It seems to me a logical
way to guard against that.
&lt;/p&gt;
&lt;p&gt;
Let me know what you think….
&lt;/p&gt;
&lt;p&gt;
m
&lt;/p&gt;
&lt;p&gt;
followup - &lt;a href="http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx"&gt;http://www.myfriedmind.com/techBlog/2009/10/20/UACAndDomainAdminsPermissionsIssueOrPocketFullOfKryptonite.aspx&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=03d242c8-2226-432e-8547-cd2cb9d54ebe" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,03d242c8-2226-432e-8547-cd2cb9d54ebe.aspx</comments>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=de8d8c91-ee9b-4bc8-b23b-2d622661d103</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,de8d8c91-ee9b-4bc8-b23b-2d622661d103.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,de8d8c91-ee9b-4bc8-b23b-2d622661d103.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=de8d8c91-ee9b-4bc8-b23b-2d622661d103</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I checked the prerequisites for installing sp2 on w08 at this entry -&gt; <a href="http://technet.microsoft.com/en-us/library/dd335038(WS.10).aspx">http://technet.microsoft.com/en-us/library/dd335038(WS.10).aspx</a> and
there is no mention that Internet Explorer 8 needs to be installed in order for w08
sp2 to be installed. And perhaps this is a quirk with Windows Updates, but on identitical
w08 boxes (not r2) I am offered SP2 on one and not on the other.
</p>
        <p>
What I AM offered on the other is the installation of IE8 for x64. It has already
been installed on the first box. Note that it is simply called 'important' not 'critical'.
</p>
        <p>
So I install IE 8 on the 2nd box and voila! Now I can install sp2. 
</p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=de8d8c91-ee9b-4bc8-b23b-2d622661d103" />
      </body>
      <title>Internet Explorer 8 required for Windows 2008 SP2 Install</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,de8d8c91-ee9b-4bc8-b23b-2d622661d103.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/10/09/InternetExplorer8RequiredForWindows2008SP2Install.aspx</link>
      <pubDate>Fri, 09 Oct 2009 20:23:43 GMT</pubDate>
      <description>&lt;p&gt;
I checked the prerequisites for installing sp2 on w08 at this entry -&amp;gt; &lt;a href="http://technet.microsoft.com/en-us/library/dd335038(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd335038(WS.10).aspx&lt;/a&gt;&amp;nbsp;and
there is no mention that Internet Explorer 8 needs to be installed in order for w08
sp2 to be installed. And perhaps this is a quirk with Windows Updates, but on identitical
w08 boxes (not r2) I am offered SP2 on one and not on the other.
&lt;/p&gt;
&lt;p&gt;
What I AM offered on the other is the installation of IE8 for x64. It has already
been installed on the first box. Note that it is simply called 'important' not 'critical'.
&lt;/p&gt;
&lt;p&gt;
So I install IE 8 on the 2nd box and voila! Now I can install sp2. 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=de8d8c91-ee9b-4bc8-b23b-2d622661d103" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,de8d8c91-ee9b-4bc8-b23b-2d622661d103.aspx</comments>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=647c5ea5-463f-4846-ab3d-5a5ca1b9440c</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,647c5ea5-463f-4846-ab3d-5a5ca1b9440c.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,647c5ea5-463f-4846-ab3d-5a5ca1b9440c.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=647c5ea5-463f-4846-ab3d-5a5ca1b9440c</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
If you have tried installing the Windows 2008 Failover clustering one of the nice <img src="http://www.myfriedmind.com/techBlog/content/binary/toredoDupNodeInfo.JPG" align="right" border="0" />things
that MSoft provides out of the box is a Cluster Validator. Not merely does it allow
a more robust set of options for hardware, but it runs through a basic checklist of
necessary and suggested configurations so you do not have to.
</p>
        <p>
However, you may run into the following error under "Validate IP Configuration" -&gt;
Found duplicate IP address blahblahblah on node blahblah adapter Local Area Connection
*blah and node blahblah2 adapter Local Area Connection *blah.
</p>
        <p>
The reason for this is what is called the Teredo Tunneling Pseudo-Interface (TTPI).
Which, as you can intuitively tell from its name is used to tunnel IPv6 traffic over
an IPv4 interface. It turns out that the TTPI gives IDENTICAL IPv6 addresses to all
the servers. Since the IP address is going through a unique IPv4 already this is not
a problem (and prevents it from bumping against a different IPv6). When you apply
it to clustering, however, this is flagged as an issue.
</p>
        <p>
The basic solution is to disable the TTPI. The method I use is very simple:
</p>
        <p>
1. Open up Server Manager to get to your Device Manager and under View select "Show
hidden devices". (It is hidden, in case that was not obvious).
</p>
        <br />
        <img src="http://www.myfriedmind.com/techBlog/content/binary/toredoHiddenDevices[1].JPG" border="0" />
        <p>
2. The TTPI should magically appear. 
</p>
        <img src="http://www.myfriedmind.com/techBlog/content/binary/toredoDisplayed.JPG" border="0" />
        <br />
        <p>
3. Now right-click and select disabled. I suggest you do this on all nodes
</p>
        <img src="http://www.myfriedmind.com/techBlog/content/binary/toredoDisableCircled.JPG" border="0" />
        <br />
        <br />
        <p>
And you are good to go.
</p>
        <p>
If this STILL does not work, take a look at Symon Perriman's entry here -&gt; <a href="http://blogs.msdn.com/clustering/archive/2008/07/26/8773796.aspx">http://blogs.msdn.com/clustering/archive/2008/07/26/8773796.aspx</a></p>
        <p>
Have fun clustering!!!<br /></p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=647c5ea5-463f-4846-ab3d-5a5ca1b9440c" />
      </body>
      <title>W08 Cluster Validator Error: Found duplicate IP address</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,647c5ea5-463f-4846-ab3d-5a5ca1b9440c.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/10/06/W08ClusterValidatorErrorFoundDuplicateIPAddress.aspx</link>
      <pubDate>Tue, 06 Oct 2009 19:44:44 GMT</pubDate>
      <description>&lt;p&gt;
If you have tried installing the Windows 2008 Failover clustering one of the nice &lt;img src="http://www.myfriedmind.com/techBlog/content/binary/toredoDupNodeInfo.JPG" align="right" border="0"&gt;things
that MSoft provides out of the box is a Cluster Validator. Not merely does it allow
a more robust set of options for hardware, but it runs through a basic checklist of
necessary and suggested configurations so you do not have to.
&lt;/p&gt;
&lt;p&gt;
However, you may run into the following error under "Validate IP Configuration" -&amp;gt;
Found duplicate IP address blahblahblah on node blahblah adapter Local Area Connection
*blah and node blahblah2 adapter Local Area Connection *blah.
&lt;/p&gt;
&lt;p&gt;
The reason for this is what is called the Teredo Tunneling Pseudo-Interface (TTPI).
Which, as you can intuitively tell from its name is used to tunnel IPv6 traffic over
an IPv4 interface. It turns out that the TTPI gives IDENTICAL IPv6 addresses to all
the servers. Since the IP address is going through a unique IPv4 already this is not
a problem (and prevents it from bumping against a different IPv6). When you apply
it to clustering, however, this is flagged as an issue.
&lt;/p&gt;
&lt;p&gt;
The basic solution is to disable the TTPI. The method I use is very simple:
&lt;/p&gt;
&lt;p&gt;
1. Open up Server Manager to get to your Device Manager and under View select "Show
hidden devices". (It is hidden, in case that was not obvious).
&lt;/p&gt;
&lt;br&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/toredoHiddenDevices[1].JPG" border="0"&gt;
&lt;p&gt;
2. The TTPI should magically appear. 
&lt;/p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/toredoDisplayed.JPG" border="0"&gt;
&lt;br&gt;
&lt;p&gt;
3. Now right-click and select disabled. I suggest you do this on all nodes
&lt;/p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/toredoDisableCircled.JPG" border="0"&gt;
&lt;br&gt;
&lt;br&gt;
&lt;p&gt;
And you are good to go.
&lt;/p&gt;
&lt;p&gt;
If this STILL does not work, take a look at Symon Perriman's entry here -&amp;gt; &lt;a href="http://blogs.msdn.com/clustering/archive/2008/07/26/8773796.aspx"&gt;http://blogs.msdn.com/clustering/archive/2008/07/26/8773796.aspx&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Have fun clustering!!!&lt;br&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=647c5ea5-463f-4846-ab3d-5a5ca1b9440c" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,647c5ea5-463f-4846-ab3d-5a5ca1b9440c.aspx</comments>
      <category>Clustering</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I was pondering the <img src="http://www.myfriedmind.com/techBlog/content/binary/clippysucker.jpg" align="right" border="0" />UAC
(User Access Control) on Windows Server 2008 and Windows 7 (nobody talks about Vista
anymore) and it occurred to me that the experience of interacting with it reminded
me of another time. An annoying, apparently helpful attempt by Msoft that actually
prevents you from doing work (see <a href="http://www.myfriedmind.com/techBlog/2009/07/14/Windows2008AdministratorRemoteAccessVsWindows2003AdministratorRemoteAccess.aspx">here</a>).
Suddenly it struck me - the return of 'Clippy'!!!
</p>
        <p>
Now, first off, I can understand MSoft's implementing the UAC. After all, everyone
knows that MSoft is so full of holes that it should if it were a cheese it would be
swiss cheese. Everyone knows that, even if it is not necessarily true. So to convince
everyone that they were secure they had to prevent users (that would be us) from doing
stupid things. Like installing programs that should not be installed or changing setting
that would render their computer unbootable. Because, of course, if a user does those
things than the people REALLY at fault are not the users (heaven forfend) but MSoft!
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/eggwarninglabel.jpg" align="left" border="0" />To
quote on of my favorite sayings - "calling something foolproof fails to take into
account the ingenuity of fools."
</p>
        <p>
They have to do this because we are so stupid as a race that an entire industry has
sprung up to inform us of the obvious. Such as "do not put a gasoline can in a fire"
or "ax blades are sharp" or (as in this picture) "this egg product contains eggs".
</p>
        <p>
Still, there has to be <img src="http://www.myfriedmind.com/techBlog/content/binary/clippy1.jpg" align="right" border="0" />some
sort of happy medium. W08 only offers two options - on or off. W08R2 offers more (and
I will make some notes on that in another blog) but I fear that in general MSoft has
gone too far in the wrong direction. They are so concerned with protecting us that
they are annoying us. And if something becomes annoying we generally stop doing it.
</p>
        <p>
Goodbye Clippy. Goodbye UAC.
</p>
        <p>
Do I have a solution? Of course not. Except to suggest that the UAC could be tweaked
to be more specific. What I mean by that is simply that rather than trying to prevent
you from doing EVERYTHING, it should only prevent the main crucial things. Perhaps
it should not question you when you are installing programs but only when you are
not installing them from an executable from a DVD or from your local drive.
</p>
        <p>
Or perhaps the solution is that high-end users simply turn 'Clippy' off. He is annoying
and YES I DO KNOW WHAT I AM DOING AND I WANT TO DO THAT! 
</p>
        <p>
At least, most of the time...
</p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa" />
      </body>
      <title>UAC or the return of Clippy</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/09/29/UACOrTheReturnOfClippy.aspx</link>
      <pubDate>Tue, 29 Sep 2009 16:03:14 GMT</pubDate>
      <description>&lt;p&gt;
I was pondering the &lt;img src="http://www.myfriedmind.com/techBlog/content/binary/clippysucker.jpg" align=right border=0&gt;UAC
(User Access Control) on Windows Server 2008 and Windows 7 (nobody talks about Vista
anymore) and it occurred to me that the experience of interacting with it reminded
me of another time. An annoying, apparently helpful attempt by Msoft that actually
prevents you from doing work (see &lt;a href="http://www.myfriedmind.com/techBlog/2009/07/14/Windows2008AdministratorRemoteAccessVsWindows2003AdministratorRemoteAccess.aspx"&gt;here&lt;/a&gt;).
Suddenly it struck me - the return of 'Clippy'!!!
&lt;/p&gt;
&lt;p&gt;
Now, first off, I can understand MSoft's implementing the UAC. After all, everyone
knows that MSoft is so full of holes that it should if it were a cheese it would be
swiss cheese. Everyone knows that, even if it is not necessarily true. So to convince
everyone that they were secure they had to prevent users (that would be us) from doing
stupid things. Like installing programs that should not be installed or changing setting
that would render their computer unbootable. Because, of course, if a user does those
things than the people REALLY at fault are not the users (heaven forfend) but MSoft!
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/eggwarninglabel.jpg" align=left border=0&gt;To
quote on of my favorite sayings - "calling something foolproof fails to take into
account the ingenuity of fools."
&lt;/p&gt;
&lt;p&gt;
They have to do this because we are so stupid as a race that an entire industry has
sprung up to inform us of the obvious. Such as "do not put a gasoline can in a fire"
or "ax blades are sharp" or (as in this picture) "this egg product contains eggs".
&lt;/p&gt;
&lt;p&gt;
Still, there has to be &lt;img src="http://www.myfriedmind.com/techBlog/content/binary/clippy1.jpg" align=right border=0&gt;some
sort of happy medium. W08 only offers two options - on or off. W08R2 offers more (and
I will make some notes on that in another blog) but I fear that in general MSoft has
gone too far in the wrong direction. They are so concerned with protecting us that
they are annoying us. And if something becomes annoying we generally stop doing it.
&lt;/p&gt;
&lt;p&gt;
Goodbye Clippy. Goodbye UAC.
&lt;/p&gt;
&lt;p&gt;
Do I have a solution? Of course not. Except to suggest that the UAC could be tweaked
to be more specific. What I mean by that is simply that rather than trying to prevent
you from doing EVERYTHING, it should only prevent the main crucial things. Perhaps
it should not question you when you are installing programs but only when you are
not installing them from an executable from a DVD or from your local drive.
&lt;/p&gt;
&lt;p&gt;
Or perhaps the solution is that high-end users simply turn 'Clippy' off. He is annoying
and YES I DO KNOW WHAT I AM DOING AND I WANT TO DO THAT! 
&lt;/p&gt;
&lt;p&gt;
At least, most of the time...
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,2a3df7cb-c14c-4be2-829c-81ddb4b0c9fa.aspx</comments>
      <category>Windows 2008</category>
      <category>Windows 7</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=d126364d-b499-48ea-a590-ae5b95c92e06</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,d126364d-b499-48ea-a590-ae5b95c92e06.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,d126364d-b499-48ea-a590-ae5b95c92e06.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=d126364d-b499-48ea-a590-ae5b95c92e06</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
For those of you just enter the IT 'biz, let me assure you that Hewlett Packard was
once a great company. Good, reliable printers. Functional Drivers. Not the crap we
are handed today. It is always sad to see a reliable company start to tube and I can
only hope that this is a quirk, but I once again ran into an issue with their drivers.
</p>
        <p>
We are using their Universal Print Driver because they have not come out with the
necessary drivers for Windows 2008 for our printers (not to mention <a href="http://www.myfriedmind.com/techBlog/2009/08/05/Windows2008PrintServicesHPLaserJetPrintersAndSLOWPrinting.aspx">the
issue with their bidirectional channel component</a>) and came across a rather strange
bug. Let us say that we are trying to print the following document from
Word 2007 that has a watermark. It should look like this:
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/howitshouldlook[1].gif" border="0" />
        </p>
        <p>
However, when printed from an XP machine we only get half the letters. It looks
like this:
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/pcl6base.gif" border="0" />
        </p>
        <p>
I verify that there are no correct drivers from HP (nope!) and then I try changing
a setting - maybe "Send Truetype as Bitmap". Wow! Now we have the other letters, we
just dropped most of the original ones that were showing.
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/truetypeasbitmap.gif" border="0" />
        </p>
        <p>
So I roll back the driver from PCL6 (v 5.0) to PCL5 (v 5.0). And guess what. It works.
PCL 5 works where PCL 6 does not. 
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/pcl5.gif" border="0" />
        </p>
        <p>
A little (true) story. I was about to fly out of town so I took my wife's car into
an oil-change place just to get that task done. While there the tech pointed out that
the alternator belt was missing a tooth. Now I have changed more alternator belts
in my life than you can shake a stick at, and I should know better than to have an
oil-change place change my belts, but since I was in a hurry I figured to let them
do it for me this time. 
</p>
        <p>
Oops.
</p>
        <p>
When I get back I find out that it is squealing when you start the car. Hmm, maybe
they need to tighten it. I take it back and they can't repair it. It works on tensioning
pulleys in that car and they tell me they think that one of the pulleys is broken.
So I take it to the dealer to fix. The rep sits down next me after they have loaded
the car up and taken a look and says, "Well, it is kind of good news. The pulleys
aren't broken, they simply put on the wrong belt - it is too large."
</p>
        <p>
It seems to me that these "Universal" print drivers from HP fall into that category.
What use is a functional engine if the belts that you put on it do not fit.
</p>
        <p>
Come on, HP, spend some time on the belts. Please.
</p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=d126364d-b499-48ea-a590-ae5b95c92e06" />
      </body>
      <title>HP Universal Print Driver PCL 6, Windows 2008, and Watermarks</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,d126364d-b499-48ea-a590-ae5b95c92e06.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/08/26/HPUniversalPrintDriverPCL6Windows2008AndWatermarks.aspx</link>
      <pubDate>Wed, 26 Aug 2009 18:16:53 GMT</pubDate>
      <description>&lt;p&gt;
For those of you just enter the IT 'biz, let me assure you that Hewlett Packard was
once a great company. Good, reliable printers. Functional Drivers. Not the crap we
are handed today. It is always sad to see a reliable company start to tube and I can
only hope that this is a quirk, but I once again ran into an issue with their drivers.
&lt;/p&gt;
&lt;p&gt;
We are using their Universal Print Driver because they have not come out with the
necessary drivers for Windows 2008 for our printers (not to mention &lt;a href="http://www.myfriedmind.com/techBlog/2009/08/05/Windows2008PrintServicesHPLaserJetPrintersAndSLOWPrinting.aspx"&gt;the
issue with their bidirectional channel component&lt;/a&gt;) and came across a rather strange
bug.&amp;nbsp;Let us say that we are trying to print the following document&amp;nbsp;from
Word 2007 that has&amp;nbsp;a watermark. It&amp;nbsp;should look like this:
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/howitshouldlook[1].gif" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
However, when printed from an XP machine we&amp;nbsp;only get half the letters. It looks
like this:
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/pcl6base.gif" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
I verify that there are no correct drivers from HP (nope!) and then I try changing
a setting - maybe "Send Truetype as Bitmap". Wow! Now we have the other letters, we
just dropped most of the original ones that were showing.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/truetypeasbitmap.gif" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
So I roll back the driver from PCL6 (v 5.0) to PCL5 (v 5.0). And guess what. It works.
PCL 5 works where PCL 6 does not. 
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/pcl5.gif" border="0"&gt;
&lt;/p&gt;
&lt;p&gt;
A little (true) story. I was about to fly out of town so I took my wife's car into
an oil-change place just to get that task done. While there the tech pointed out that
the alternator belt was missing a tooth. Now I have changed more alternator belts
in my life than you can shake a stick at, and I should know better than to have an
oil-change place change my belts, but since I was in a hurry I figured to let them
do it for me this time. 
&lt;/p&gt;
&lt;p&gt;
Oops.
&lt;/p&gt;
&lt;p&gt;
When I get back I find out that it is squealing when you start the car. Hmm, maybe
they need to tighten it. I take it back and they can't repair it. It works on tensioning
pulleys in that car and they tell me they think that one of the pulleys is broken.
So I take it to the dealer to fix. The rep sits down next me after they have loaded
the car up and taken a look and says, "Well, it is kind of good news. The pulleys
aren't broken, they simply put on the wrong belt - it is too large."
&lt;/p&gt;
&lt;p&gt;
It seems to me that these "Universal" print drivers from HP fall into that category.
What use is a functional engine if the belts that you put on it do not fit.
&lt;/p&gt;
&lt;p&gt;
Come on, HP, spend some time on the belts. Please.
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=d126364d-b499-48ea-a590-ae5b95c92e06" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,d126364d-b499-48ea-a590-ae5b95c92e06.aspx</comments>
      <category>Printing</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=07f5f354-1a1a-43f2-902c-35b7bcde495f</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,07f5f354-1a1a-43f2-902c-35b7bcde495f.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,07f5f354-1a1a-43f2-902c-35b7bcde495f.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=07f5f354-1a1a-43f2-902c-35b7bcde495f</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">We moved to our w08 print server and as
noted in <a href="http://www.myfriedmind.com/techBlog/2009/08/05/Windows2008PrintServicesHPLaserJetPrintersAndSLOWPrinting.aspx">yesterday's
post </a>ran into issues with slooooooooooooooooow printing. These were resolved by
moving to the Universal Print Driver (UPD) which had an updated bidirectional channel
portion. There was one surprising result of the move - all of a sudden people were
being prompted to load a type of paper (recycled, heavy-weight, glossy) into the Manual
Feed tray on the 4250s. If they hit the continue button (the checkmark) it would print,
but they had to do it FOR EVERY PAGE.<br /><br />
Not something to make your end users happy.<br /><br />
The issue appears to be a rather odd interaction with the driver in which it sets
modifies the default settings of the printer. To fix:<br /><br />
1 - Open up the printer properties on the Print Server and go to the Advanced Tab.
Selecting "Printer Defaults"<br /><br /><img src="http://www.myfriedmind.com/techBlog/content/binary/hpCardstock1a.JPG" border="0" /><br /><br />
2 - Go to the Paper/Quality tab and look at the Paper type. It is probably set at
a specific (undesired) type.<br /><br /><img src="http://www.myfriedmind.com/techBlog/content/binary/hpCardstock2.JPG" border="0" /><br /><br />
3 - Click on the Paper type and select "Unspecified"<br /><br /><img src="http://www.myfriedmind.com/techBlog/content/binary/hpCardstock3.JPG" border="0" /><br /><br />
A couple of notes:<br /><ol><li>
Users may need to remove/add the printer back for this to get pushed down.</li><li>
This is NOT Printing Preferences. The same screens are there, but they will not fix
this, although they should be changed as well.<br /></li></ol><br /><img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=07f5f354-1a1a-43f2-902c-35b7bcde495f" /></body>
      <title>Hewlett Packer Printers asking for Cardstock (or Recycled, or Glossy) on Windows 2008 Print Server</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,07f5f354-1a1a-43f2-902c-35b7bcde495f.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/08/06/HewlettPackerPrintersAskingForCardstockOrRecycledOrGlossyOnWindows2008PrintServer.aspx</link>
      <pubDate>Thu, 06 Aug 2009 14:28:32 GMT</pubDate>
      <description>We moved to our w08 print server and as noted in &lt;a href="http://www.myfriedmind.com/techBlog/2009/08/05/Windows2008PrintServicesHPLaserJetPrintersAndSLOWPrinting.aspx"&gt;yesterday's
post &lt;/a&gt;ran into issues with slooooooooooooooooow printing. These were resolved by
moving to the Universal Print Driver (UPD) which had an updated bidirectional channel
portion. There was one surprising result of the move - all of a sudden people were
being prompted to load a type of paper (recycled, heavy-weight, glossy) into the Manual
Feed tray on the 4250s. If they hit the continue button (the checkmark) it would print,
but they had to do it FOR EVERY PAGE.&lt;br&gt;
&lt;br&gt;
Not something to make your end users happy.&lt;br&gt;
&lt;br&gt;
The issue appears to be a rather odd interaction with the driver in which it sets
modifies the default settings of the printer. To fix:&lt;br&gt;
&lt;br&gt;
1 - Open up the printer properties on the Print Server and go to the Advanced Tab.
Selecting "Printer Defaults"&lt;br&gt;
&lt;br&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/hpCardstock1a.JPG" border="0"&gt;
&lt;br&gt;
&lt;br&gt;
2 - Go to the Paper/Quality tab and look at the Paper type. It is probably set at
a specific (undesired) type.&lt;br&gt;
&lt;br&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/hpCardstock2.JPG" border="0"&gt;
&lt;br&gt;
&lt;br&gt;
3 - Click on the Paper type and select "Unspecified"&lt;br&gt;
&lt;br&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/hpCardstock3.JPG" border="0"&gt;
&lt;br&gt;
&lt;br&gt;
A couple of notes:&lt;br&gt;
&lt;ol&gt;
&lt;li&gt;
Users may need to remove/add the printer back for this to get pushed down.&lt;/li&gt;
&lt;li&gt;
This is NOT Printing Preferences. The same screens are there, but they will not fix
this, although they should be changed as well.&lt;br&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;br&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=07f5f354-1a1a-43f2-902c-35b7bcde495f" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,07f5f354-1a1a-43f2-902c-35b7bcde495f.aspx</comments>
      <category>Printing</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=87cd43a4-8334-408d-8a99-b0009027ae51</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,87cd43a4-8334-408d-8a99-b0009027ae51.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,87cd43a4-8334-408d-8a99-b0009027ae51.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=87cd43a4-8334-408d-8a99-b0009027ae51</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
If you have moved to Windows 2008 for your Print Server and have encountered slow
printing to your HP Laserjets, the issue may be the driver. 
</p>
        <p>
According to <a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01682861&amp;dimid=1001553288&amp;dicid=alr_mar09&amp;jumpid=em_alerts/us/mar09/all/xbu/emailsubid/mrm/mcc/loc/rbu_category/alerts">this
support document</a> by HP the issue lies in the HP Bidirectional Channel component
- namely hpzbid.dll and hpzbidXX.msi). You can read all about the symptoms/cause
there but to make a long story short it appears that this lies with issues where it
continually tries to reinstall the .dll and fails. 
</p>
        <p>
The solution, according to HP, is NOT to call up and get updated .dlls (they probably
will not give them to you) but to use their updated Universal Print Driver (UPD) version
5.0. This changes the .dll to cioum.dll for the bidirectional channel control rather
than hpzbid.dll. HP has no intention of updating hpzbid.dll so get used to it.
</p>
        <p>
The symptoms are hard to miss (for example it takes 30 seconds just to view the properties
of a printer on a client machine) so this one should not be hard to miss. Just remember
to use the 5.0 version of the UPD.
</p>
        <p>
Printers noted by HP:
</p>
        <ul>
          <li>
Laserjet 4250 series 
</li>
          <li>
Laserjet 4350 series 
</li>
          <li>
Laserjet 9040 series 
</li>
          <li>
Laserjet 9050 series 
</li>
          <li>
Laserjet 5200 series 
</li>
          <li>
Laserjet P3005 series<br /></li>
        </ul>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=87cd43a4-8334-408d-8a99-b0009027ae51" />
      </body>
      <title>Windows 2008 Print Services, HP LaserJet Printers and SLOW Printing</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,87cd43a4-8334-408d-8a99-b0009027ae51.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/08/05/Windows2008PrintServicesHPLaserJetPrintersAndSLOWPrinting.aspx</link>
      <pubDate>Wed, 05 Aug 2009 14:50:59 GMT</pubDate>
      <description>&lt;p&gt;
If you have moved to Windows 2008 for your Print Server and have encountered slow
printing to your HP Laserjets, the issue may be the driver. 
&lt;/p&gt;
&lt;p&gt;
According to &lt;a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01682861&amp;amp;dimid=1001553288&amp;amp;dicid=alr_mar09&amp;amp;jumpid=em_alerts/us/mar09/all/xbu/emailsubid/mrm/mcc/loc/rbu_category/alerts"&gt;this
support document&lt;/a&gt; by HP the issue lies in the HP Bidirectional Channel component
- namely hpzbid.dll and hpzbidXX.msi). You&amp;nbsp;can read all about the symptoms/cause
there but to make a long story short it appears that this lies with issues where it
continually tries to reinstall the .dll and fails. 
&lt;/p&gt;
&lt;p&gt;
The solution, according to HP, is NOT to call up and get updated .dlls (they probably
will not give them to you) but to use their updated Universal Print Driver (UPD) version
5.0. This changes the .dll to cioum.dll for the bidirectional channel control rather
than hpzbid.dll. HP has no intention of updating hpzbid.dll so get used to it.
&lt;/p&gt;
&lt;p&gt;
The symptoms are hard to miss (for example it takes 30 seconds just to view the properties
of a printer on a client machine) so this one should not be hard to miss. Just remember
to use the 5.0 version of the UPD.
&lt;/p&gt;
&lt;p&gt;
Printers noted by HP:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
Laserjet 4250 series 
&lt;li&gt;
Laserjet 4350 series 
&lt;li&gt;
Laserjet 9040 series 
&lt;li&gt;
Laserjet 9050 series 
&lt;li&gt;
Laserjet 5200 series 
&lt;li&gt;
Laserjet P3005 series&lt;br&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=87cd43a4-8334-408d-8a99-b0009027ae51" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,87cd43a4-8334-408d-8a99-b0009027ae51.aspx</comments>
      <category>Clustering</category>
      <category>Printing</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=fdcfe992-92c6-4955-b013-2829fec94c7a</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,fdcfe992-92c6-4955-b013-2829fec94c7a.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,fdcfe992-92c6-4955-b013-2829fec94c7a.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=fdcfe992-92c6-4955-b013-2829fec94c7a</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
After installing our clustered w08 Print Server I noticed that there was a particular
Warning in the System Log. Event ID 4 "The print spooler failed to reopen an existing
printer connection because it could not read the configuration information from the
registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry
key. This can occur if the registry key is corrupt or missing, or if the registry
recently became unavailable."
</p>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/spoolerEventId4.gif" border="0" />
        </p>
        <p>
I looked in the registry and, no surprise, that key was missing. I hunted around a
bit and found <a href="http://social.technet.microsoft.com/Forums/en-US/winserverprint/thread/b0bfd952-f7f6-4a06-9f85-8617b654174f">this</a> entry.
Basically to resolve this was fairly simple - add the key back in:
</p>
        <ol>
          <li>
Open up the registry on the computer (I did it on all nodes individually) 
</li>
          <li>
Go to HKEY_USERS/S-1-5-18/Printers 
</li>
          <li>
Add a new Key called "Connections" (no quotes) 
</li>
          <li>
Right-click and select Permissions on the new key to verify that System has "Full
Control"</li>
        </ol>
        <p>
          <img src="http://www.myfriedmind.com/techBlog/content/binary/eventIdRegConnectionsKey.gif" border="0" />
        </p>
        <p>
Now I am not sure if this is an issue with Clustering or just a strange whacky event
that happened. But if it happens to you, hopefully this will resolve it.
</p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=fdcfe992-92c6-4955-b013-2829fec94c7a" />
      </body>
      <title>Windows 2008 Spooler Warning on clustered print server - Event ID 4 -&gt; Missing S-1-5-18\Printers\Connections</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,fdcfe992-92c6-4955-b013-2829fec94c7a.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/07/29/Windows2008SpoolerWarningOnClusteredPrintServerEventID4MissingS1518PrintersConnections.aspx</link>
      <pubDate>Wed, 29 Jul 2009 13:15:44 GMT</pubDate>
      <description>&lt;p&gt;
After installing our clustered w08 Print Server I noticed that there was a particular
Warning in the System Log. Event ID 4 "The print spooler failed to reopen an existing
printer connection because it could not read the configuration information from the
registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry
key. This can occur if the registry key is corrupt or missing, or if the registry
recently became unavailable."
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/spoolerEventId4.gif" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
I looked in the registry and, no surprise, that key was missing. I hunted around a
bit and found &lt;a href="http://social.technet.microsoft.com/Forums/en-US/winserverprint/thread/b0bfd952-f7f6-4a06-9f85-8617b654174f"&gt;this&lt;/a&gt; entry.
Basically to resolve this was fairly simple - add the key back in:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
Open up the registry on the computer (I did it on all nodes individually) 
&lt;li&gt;
Go to HKEY_USERS/S-1-5-18/Printers 
&lt;li&gt;
Add a new Key called "Connections" (no quotes) 
&lt;li&gt;
Right-click and select Permissions on the new key to verify that System has "Full
Control"&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/eventIdRegConnectionsKey.gif" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
Now I am not sure if this is an issue with Clustering or just a strange whacky event
that happened. But if it happens to you, hopefully this will resolve it.
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=fdcfe992-92c6-4955-b013-2829fec94c7a" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,fdcfe992-92c6-4955-b013-2829fec94c7a.aspx</comments>
      <category>Clustering</category>
      <category>Windows 2008</category>
      <category>Printing</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=4fa18a00-4f76-4553-bffc-f06fe2547a65</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,4fa18a00-4f76-4553-bffc-f06fe2547a65.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,4fa18a00-4f76-4553-bffc-f06fe2547a65.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=4fa18a00-4f76-4553-bffc-f06fe2547a65</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <h1>NOTE: This is NOT an issue with clustering, but appears to be an issue with w08
(and w08r2) regardless of whether the drive is clustered or local. For more info look
here -&gt; <a href="http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx">http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx</a></h1>
        <p>
============ The information below is misleading - see the above link for correction
</p>
        <p>
 
</p>
        <p>
Another addition to w08 that might trip you up is the use of the User Account Control
(or UAC) to prevent Administrator accounts (other than the default created one) from
doing anything useful (unless prompted). Connect that with the fact that you can only
sign onto a machine once per account (see <a href="http://www.myfriedmind.com/techBlog/2009/07/14/Windows2008AdministratorRemoteAccessVsWindows2003AdministratorRemoteAccess.aspx">this</a>)
and you have a case where you have to log on as the non-default Administrator but
are hampered in doing your work.<br /><br />
Put aside the annoying popups (are you SURE you want to see the security permissions?
Really? Really?) there is are more serious issues. Case in point - we have a Cluster
server with the Role of File Services. Logged on as a lowly Domain Admin I can not
get to the actual drive that it is sharing. Let me state that again clearly<br /></p>
        <ol>
          <li>
I am working on a Clustered w08 server with the Role of File Services 
</li>
          <li>
I am logged on with a Domain Admin account (but not with the default Administrator
account) 
</li>
          <li>
UAC is turned on 
</li>
          <li>
I can NOT access the drive(s) (much less the shares) that the Cluster uses</li>
        </ol>
        <img src="http://www.myfriedmind.com/techBlog/content/binary/UACDenialOnCluster.JPG" border="0" />
        <br />
        <br />
I don't even get a chance to say that "YES, I WANT TO ACCESS THAT FOLDER" which you
normally get with UAC, just a big red X.<br /><br />
What are the possible choices? It seems that there are two: 
<br /><ol><li>
Always use the default Administrator account when logging on to a Clustered w08 account.
This always gives you access.<br /></li><li>
Turn off UAC ON ALL CLUSTERED SERVERS (since if it is not turned off on the host server,
whichever one that is, you are going to run into the same problem). 
<br /></li></ol>
I prefer #2 since (hopefully) the only people who will EVER be logging directly onto
your server are Administrators anyway. Once the UAC is turned off you will be able
to access all the appropriate folders, etc. Note that changing the UAC setting requires
a reboot (one of the few things that still does in Windows - yeah!) so I would suggest
you do it on the non-active nodes first so you are not constantly moving your active
node from one node to the next.<br /><br />
I am not sure firstly, why this happens; and secondly, why there is no prompt to override
it (I am, after all, a Domain Admin and therefore in the Administrators group of the
servers) but it does happen. There is no way that I am aware of to set UAC to allow
groups, or even to add more people. It is on (and only the default Administrator account
can do the work) or it is off.<br /><br />
Hope this helps...<br /><br />
Note: MSoft reports that this is unique (or at least they have never heard of it).
One interesting note - I can run the Cluster Configuration Validator even logged in
as a non-default Admin with UAC turned on. Go figure...<br /><br /><br /><img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=4fa18a00-4f76-4553-bffc-f06fe2547a65" /></body>
      <title>Windows 2008 and the User Account Control and Clustered drives...</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,4fa18a00-4f76-4553-bffc-f06fe2547a65.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/07/16/Windows2008AndTheUserAccountControlAndClusteredDrives.aspx</link>
      <pubDate>Thu, 16 Jul 2009 18:18:14 GMT</pubDate>
      <description>&lt;h1&gt;NOTE: This is NOT an issue with clustering, but appears to be an issue with w08
(and w08r2) regardless of whether the drive is clustered or local. For more info look
here -&amp;gt; &lt;a href="http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx"&gt;http://www.myfriedmind.com/techBlog/2009/10/14/UACAndDomainAdminsPermissionsIssueOnWindows2008.aspx&lt;/a&gt;
&lt;/h1&gt;
&lt;p&gt;
============ The information below is misleading - see the above link for correction
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
Another addition to w08 that might trip you up is the use of the User Account Control
(or UAC) to prevent Administrator accounts (other than the default created one) from
doing anything useful (unless prompted). Connect that with the fact that you can only
sign onto a machine once per account (see &lt;a href="http://www.myfriedmind.com/techBlog/2009/07/14/Windows2008AdministratorRemoteAccessVsWindows2003AdministratorRemoteAccess.aspx"&gt;this&lt;/a&gt;)
and you have a case where you have to log on as the non-default Administrator but
are hampered in doing your work.&lt;br&gt;
&lt;br&gt;
Put aside the annoying popups (are you SURE you want to see the security permissions?
Really? Really?) there is are more serious issues. Case in point - we have a Cluster
server with the Role of File Services. Logged on as a lowly Domain Admin I can not
get to the actual drive that it is sharing. Let me state that again clearly&lt;br&gt;
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
I am working on a Clustered w08 server with the Role of File Services 
&lt;li&gt;
I am logged on with a Domain Admin account (but not with the default Administrator
account) 
&lt;li&gt;
UAC is turned on 
&lt;li&gt;
I can NOT access the drive(s) (much less the shares) that the Cluster uses&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="http://www.myfriedmind.com/techBlog/content/binary/UACDenialOnCluster.JPG" border=0&gt;
&lt;br&gt;
&lt;br&gt;
I don't even get a chance to say that "YES, I WANT TO ACCESS THAT FOLDER" which you
normally get with UAC, just a big red X.&lt;br&gt;
&lt;br&gt;
What are the possible choices? It seems that there are two: 
&lt;br&gt;
&lt;ol&gt;
&lt;li&gt;
Always use the default Administrator account when logging on to a Clustered w08 account.
This always gives you access.&lt;br&gt;
&lt;li&gt;
Turn off UAC ON ALL CLUSTERED SERVERS (since if it is not turned off on the host server,
whichever one that is, you are going to run into the same problem). 
&lt;br&gt;
&lt;/li&gt;
&lt;/ol&gt;
I prefer #2 since (hopefully) the only people who will EVER be logging directly onto
your server are Administrators anyway. Once the UAC is turned off you will be able
to access all the appropriate folders, etc. Note that changing the UAC setting requires
a reboot (one of the few things that still does in Windows - yeah!) so I would suggest
you do it on the non-active nodes first so you are not constantly moving your active
node from one node to the next.&lt;br&gt;
&lt;br&gt;
I am not sure firstly, why this happens; and secondly, why there is no prompt to override
it (I am, after all, a Domain Admin and therefore in the Administrators group of the
servers) but it does happen. There is no way that I am aware of to set UAC to allow
groups, or even to add more people. It is on (and only the default Administrator account
can do the work) or it is off.&lt;br&gt;
&lt;br&gt;
Hope this helps...&lt;br&gt;
&lt;br&gt;
Note: MSoft reports that this is unique (or at least they have never heard of it).
One interesting note - I can run the Cluster Configuration Validator even logged in
as a non-default Admin with UAC turned on. Go figure...&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=4fa18a00-4f76-4553-bffc-f06fe2547a65" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,4fa18a00-4f76-4553-bffc-f06fe2547a65.aspx</comments>
      <category>Clustering</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=17246898-11bf-4f70-86ca-9e4f960c8b65</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,17246898-11bf-4f70-86ca-9e4f960c8b65.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,17246898-11bf-4f70-86ca-9e4f960c8b65.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=17246898-11bf-4f70-86ca-9e4f960c8b65</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">I am moving our old windows 2003 clustered
file share over to a brand, spanking new w08 clustered file share. There are things
to note about the differences (another name, another IP???) but the thing I want to
note about today had to do with one of our Multi-Function Printers, specifically the
HP 8060.<br /><br />
We have that beast setup so that staff can scan documents and it gets sent to our
public folder where they can get it. I guess when it was setup they were having trouble
with specifying the network share and so my cohorts were advised to use the IP address
of the share -&gt; 
<br />
\\10.10.10.10\public\scanner\folder. 
<br /><br />
This worked. 
<br /><br />
HOWEVER............<br /><br />
There always seems to be something that throws a wrench in the works and the wrench
in this case is that in w08 you CAN NOT get to a share via IP address, but only by
the name of the server. Let me state that again:<br /><br />
\\myserver\myshare\myfolder appears<br />
\\10.10.10.10\myshare\myfolder does not<br /><br />
It seems that in w08 clustered file shares do not share on IP addresses. I have not
mucked with this to see if there is a way around it, but out of the box there is no
way to get to a shared folder via IP address. This, of course, means that the HP 8060
is throwing a hissy fit.<br /><br />
I was poking around in the Networking settings for the printer when I noticed that
under the TCP/IP settings, in the Network Identification tab there was no entry for
the DNS Suffixes. So I added our domain extension (ourdomain.com) and it worked!<br /><br />
Just to note, I had previously tried mapping \\myserver.ourdomain.com\myshare\myfolder
on the printer and that did not work, but this did.<br /><br />
Hope that helps...<br />
m<br /><p></p><img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=17246898-11bf-4f70-86ca-9e4f960c8b65" /></body>
      <title>HP Laserjet 8060, Digital Sending, and Network Folder setup resolution (in Windows 2008)</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,17246898-11bf-4f70-86ca-9e4f960c8b65.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/07/15/HPLaserjet8060DigitalSendingAndNetworkFolderSetupResolutionInWindows2008.aspx</link>
      <pubDate>Wed, 15 Jul 2009 14:49:38 GMT</pubDate>
      <description>I am moving our old windows 2003 clustered file share over to a brand, spanking new w08 clustered file share. There are things to note about the differences (another name, another IP???) but the thing I want to note about today had to do with one of our Multi-Function Printers, specifically the HP 8060.&lt;br&gt;
&lt;br&gt;
We have that beast setup so that staff can scan documents and it gets sent to our
public folder where they can get it. I guess when it was setup they were having trouble
with specifying the network share and so my cohorts were advised to use the IP address
of the share -&amp;gt; 
&lt;br&gt;
\\10.10.10.10\public\scanner\folder. 
&lt;br&gt;
&lt;br&gt;
This worked. 
&lt;br&gt;
&lt;br&gt;
HOWEVER............&lt;br&gt;
&lt;br&gt;
There always seems to be something that throws a wrench in the works and the wrench
in this case is that in w08 you CAN NOT get to a share via IP address, but only by
the name of the server. Let me state that again:&lt;br&gt;
&lt;br&gt;
\\myserver\myshare\myfolder appears&lt;br&gt;
\\10.10.10.10\myshare\myfolder does not&lt;br&gt;
&lt;br&gt;
It seems that in w08 clustered file shares do not share on IP addresses. I have not
mucked with this to see if there is a way around it, but out of the box there is no
way to get to a shared folder via IP address. This, of course, means that the HP 8060
is throwing a hissy fit.&lt;br&gt;
&lt;br&gt;
I was poking around in the Networking settings for the printer when I noticed that
under the TCP/IP settings, in the Network Identification tab there was no entry for
the DNS Suffixes. So I added our domain extension (ourdomain.com) and it worked!&lt;br&gt;
&lt;br&gt;
Just to note, I had previously tried mapping \\myserver.ourdomain.com\myshare\myfolder
on the printer and that did not work, but this did.&lt;br&gt;
&lt;br&gt;
Hope that helps...&lt;br&gt;
m&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=17246898-11bf-4f70-86ca-9e4f960c8b65" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,17246898-11bf-4f70-86ca-9e4f960c8b65.aspx</comments>
      <category>Clustering</category>
      <category>Printing</category>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=564a1586-eaf2-47e0-ae29-5bd38c27f029</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,564a1586-eaf2-47e0-ae29-5bd38c27f029.aspx</pingback:target>
      <dc:creator>papabear</dc:creator>
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,564a1586-eaf2-47e0-ae29-5bd38c27f029.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=564a1586-eaf2-47e0-ae29-5bd38c27f029</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I funny thing happened to me this morning. I was remotely connected to one of our
w08 servers with our standard Administrator account when suddently my session came
to a sudden end. I knew what must have happened, and sure enough one of my cohorts
had signed on remotely to that server.
</p>
        <p>
At first I thought it might be a limitation in w08 that you could now only have a
single Remote Access connection, but I quickly realized that that was not the case.
Instead the new tweak in w08 is that you can only sign on ONCE per account. So, when
my cohort signed on with the same username it booted me off and handed my session
over to him. This is new to w08, in w03 you could have sign on more than once with
the same account and run different sessions.
</p>
        <p>
The takeaway seems to be that you are going to have to have multiple Domain Admin
accounts, probably assigning one per administrator. This will mean that you can have
better security auditing (hopefully) but it also means that you will have more accounts
that can do more damage.
</p>
        <p>
Note that with the addition of User Account Control turned on by default this may
restrict some critical tasks (see <a href="http://www.myfriedmind.com/techBlog/2009/07/16/Windows2008AndTheUserAccountControlAndClusteredDrives.aspx">here</a>).<br /></p>
        <p>
Not a bad thing to have added to w08, just something to be aware of...
</p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=564a1586-eaf2-47e0-ae29-5bd38c27f029" />
      </body>
      <title>Windows 2008 Administrator Remote Access vs Windows 2003 Administrator Remote Access</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,564a1586-eaf2-47e0-ae29-5bd38c27f029.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/07/14/Windows2008AdministratorRemoteAccessVsWindows2003AdministratorRemoteAccess.aspx</link>
      <pubDate>Tue, 14 Jul 2009 15:24:03 GMT</pubDate>
      <description>&lt;p&gt;
I funny thing happened to me this morning. I was remotely connected to one of our
w08 servers with our standard Administrator account when suddently my session came
to a sudden end. I knew what must have happened, and sure enough one of my cohorts
had signed on remotely to that server.
&lt;/p&gt;
&lt;p&gt;
At first I thought it might be a limitation in w08 that you could now only have a
single Remote Access connection, but I quickly realized that that was not the case.
Instead the new tweak in w08 is that you can only sign on ONCE per account. So, when
my cohort signed on with the same username it booted me off and handed my session
over to him. This is new to w08, in w03 you could have sign on more than once with
the same account and run different sessions.
&lt;/p&gt;
&lt;p&gt;
The takeaway seems to be that you are going to have to have multiple Domain Admin
accounts, probably assigning one per administrator. This will mean that you can have
better security auditing (hopefully) but it also means that you will have more accounts
that can do more damage.
&lt;/p&gt;
&lt;p&gt;
Note that with the addition of User Account Control turned on by default this may
restrict some critical tasks (see &lt;a href="http://www.myfriedmind.com/techBlog/2009/07/16/Windows2008AndTheUserAccountControlAndClusteredDrives.aspx"&gt;here&lt;/a&gt;).&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
Not a bad thing to have added to w08, just something to be aware of...
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=564a1586-eaf2-47e0-ae29-5bd38c27f029" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,564a1586-eaf2-47e0-ae29-5bd38c27f029.aspx</comments>
      <category>Windows 2008</category>
    </item>
    <item>
      <trackback:ping>http://www.myfriedmind.com/techBlog/Trackback.aspx?guid=7efcc636-3277-4738-8203-22fde44a79bc</trackback:ping>
      <pingback:server>http://www.myfriedmind.com/techBlog/pingback.aspx</pingback:server>
      <pingback:target>http://www.myfriedmind.com/techBlog/PermaLink,guid,7efcc636-3277-4738-8203-22fde44a79bc.aspx</pingback:target>
      <dc:creator />
      <wfw:comment>http://www.myfriedmind.com/techBlog/CommentView,guid,7efcc636-3277-4738-8203-22fde44a79bc.aspx</wfw:comment>
      <wfw:commentRss>http://www.myfriedmind.com/techBlog/SyndicationService.asmx/GetEntryCommentsRss?guid=7efcc636-3277-4738-8203-22fde44a79bc</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Can't be done. 
</p>
        <p>
Any attempt to install will be met with "This operating system in not supported..."
Supposedly the next version of ISA will be happy, happy, joy, joy, but not this one. 
</p>
        <p>
Could there be a hackaround? Probably. Should you do it? Probably not. Hacks can leave
doors open unless you are positive you know where all the moving parts are.
</p>
        <p>
So, buck up and used the old w03. At least for now...
</p>
        <img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=7efcc636-3277-4738-8203-22fde44a79bc" />
      </body>
      <title>Installing ISA 2006 on Windows 2008</title>
      <guid isPermaLink="false">http://www.myfriedmind.com/techBlog/PermaLink,guid,7efcc636-3277-4738-8203-22fde44a79bc.aspx</guid>
      <link>http://www.myfriedmind.com/techBlog/2009/04/30/InstallingISA2006OnWindows2008.aspx</link>
      <pubDate>Thu, 30 Apr 2009 19:26:07 GMT</pubDate>
      <description>&lt;p&gt;
Can't be done. 
&lt;/p&gt;
&lt;p&gt;
Any attempt to install will be met with "This operating system in not supported..."
Supposedly the next version of ISA will be happy, happy, joy, joy, but not this one. 
&lt;/p&gt;
&lt;p&gt;
Could there be a hackaround? Probably. Should you do it? Probably not. Hacks can leave
doors open unless you are positive you know where all the moving parts are.
&lt;/p&gt;
&lt;p&gt;
So, buck up and used the old w03. At least for now...
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.myfriedmind.com/techBlog/aggbug.ashx?id=7efcc636-3277-4738-8203-22fde44a79bc" /&gt;</description>
      <comments>http://www.myfriedmind.com/techBlog/CommentView,guid,7efcc636-3277-4738-8203-22fde44a79bc.aspx</comments>
      <category>Isa 2006</category>
      <category>Windows 2008</category>
    </item>
  </channel>
</rss>