<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Windows &#8211; Blog of Kliment Andreev &#8211; A place so I won&#039;t forget things</title>
	<atom:link href="https://blog.andreev.it/tag/windows/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.andreev.it</link>
	<description></description>
	<lastBuildDate>Mon, 02 Nov 2020 13:54:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Azure Arc &#8211; managing on-prem Windows and Linux servers</title>
		<link>https://blog.andreev.it/2020/03/azure-arc-managing-on-prem-windows-and-linux-servers/</link>
					<comments>https://blog.andreev.it/2020/03/azure-arc-managing-on-prem-windows-and-linux-servers/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Sun, 01 Mar 2020 16:06:38 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Azure Arc]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://blog.andreev.it/?p=6544</guid>

					<description><![CDATA[Azure Arc (some components still in beta at the time of writing) is a&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>Azure Arc (some components still in beta at the time of writing) is a new Azure service that allows you to manage your on-prem or &#8220;other&#8221; cloud resources with the familiar Azure interface.<br />
But, when I say manage, I don&#8217;t think of manage in terms of add disk, increase CPU on a VM &#8211; no, you can only certain aspects, like tagging your instances, get the logs so you can use Log Analitycs, assign RBAC controls etc. For more information go to this <a href="https://azure.microsoft.com/en-us/blog/azure-arc-extending-azure-management-to-any-infrastructure/" rel="noopener noreferrer" target="_blank">link</a>.<br />
So, it&#8217;s pretty much a governance across different environments as this diagram shows.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-01.png"><img fetchpriority="high" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-01.png" alt="" width="625" height="230" class="aligncenter size-full wp-image-6546" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-01.png 625w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-01-300x110.png 300w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-01-585x215.png 585w" sizes="(max-width: 625px) 100vw, 625px" /></a><br />
In this post, I&#8217;ll show you how that looks in practice. I have two VMs in my own vCenter, one Windows and one CentOS Linux. There is no VPN tunnel between the on-prem environment and Azure. We&#8217;ll install an agent on both of them and show how that looks like in Azure Arc. Let&#8217;s go to the Azure console first and they type Arc in the search bar on top.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-02.png"><img decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-02.png" alt="" width="1011" height="496" class="aligncenter size-full wp-image-6547" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-02.png 1011w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-02-300x147.png 300w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-02-768x377.png 768w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-02-585x287.png 585w" sizes="(max-width: 1011px) 100vw, 1011px" /></a><br />
As I said, the other components are not in public for everyone, so we&#8217;ll go with the <strong>Manage servers</strong> option. You&#8217;ll be presented with this screen. You&#8217;ll see your servers here lately. For now, just click <strong>Create machine &#8211; Azure Arc</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-03.png"><img decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-03.png" alt="" width="755" height="364" class="aligncenter size-full wp-image-6548" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-03.png 755w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-03-300x145.png 300w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-03-585x282.png 585w" sizes="(max-width: 755px) 100vw, 755px" /></a><br />
You have two options here. The first one is if you want to add a couple of servers manually and the second is if you want to automate the import with a SPN and a PowerShell script. If you click on <strong>Learn more</strong> link, you&#8217;ll see the instructions. It&#8217;s very simple and very straightforward. We&#8217;ll go with the first option so click on <strong>Generate script</strong>.<br />
Select your <strong>subscription </strong>and the <strong>resource group</strong> and choose the <strong>region</strong>. As you can see only 3 regions are supported so far. Specify the proxy if you use it on-prem and select the OS type. Click <strong>Review + Generate</strong> after.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-05.png" alt="" width="834" height="795" class="aligncenter size-full wp-image-6549" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-05.png 834w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-05-300x286.png 300w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-05-768x732.png 768w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-05-585x558.png 585w" sizes="(max-width: 834px) 100vw, 834px" /></a><br />
Before using it for the first time, you have to register first. Click <strong>Register </strong>and then copy the script below. If you click <strong>Download</strong>, you&#8217;ll get the same script in the file. Once you click <strong>Register</strong>, you&#8217;ll see on the screen that the registration is submitted and you have to wait couple of minutes.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-06.png" alt="" width="811" height="785" class="aligncenter size-full wp-image-6550" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-06.png 811w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-06-300x290.png 300w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-06-768x743.png 768w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-06-585x566.png 585w" sizes="(max-width: 811px) 100vw, 811px" /></a><br />
Download the script or copy and paste it in a Windows VM on-prem and run it from a Powershell console with Administrator rights. It pretty much downloads a MSI package and execute it in the background. But, as you can see you have to open a browser and register the VM.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-07.png" alt="" width="869" height="615" class="aligncenter size-full wp-image-6551" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-07.png 869w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-07-300x212.png 300w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-07-768x544.png 768w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-07-585x414.png 585w" sizes="(max-width: 869px) 100vw, 869px" /></a><br />
You will also have to enter your Azure credentials after you register your VM. Once you log in, you&#8217;ll receive a message that you can close the browser. DO NOT close the PowerShell console, wait for 5-6 seconds until you receive a message &#8211; <strong>&#8220;Successfully Onboarded Resource to Azure&#8221;</strong>. Now you can close the PS console window.<br />
If you go back to Azure Arc, you&#8217;ll see that your VM is there.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-08.png" alt="" width="1228" height="282" class="aligncenter size-full wp-image-6559" /></a><br />
For a Linux instance, we&#8217;ll use CentOS 7. Do the same as with Windows, add a machine, but this time choose Linux from the dropdown and generate a script. CentOS 7 doesn&#8217;t come with wget, so you have to install it first with <strong>sudo yum -y install wget</strong>. Same thing as with Windows, you&#8217;ll have to register the VM.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-09.png" alt="" width="569" height="136" class="aligncenter size-full wp-image-6554" srcset="https://blog.andreev.it/wp-content/uploads/2020/03/P146-09.png 569w, https://blog.andreev.it/wp-content/uploads/2020/03/P146-09-300x72.png 300w" sizes="(max-width: 569px) 100vw, 569px" /></a><br />
Again, wait for the confirmation message in the console that the VM is registered and then you can close the Linux session.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2020/03/P146-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2020/03/P146-10.png" alt="" width="1283" height="270" class="aligncenter size-full wp-image-6558" /></a><br />
Once you finish onboarding, you can go ahead and create the policies, assign rights, monitor the instance and check the logs.<br />
NOTE: The agents communicate over port 443 to a Microsoft site. I am not sure if you can redirect this traffic through a private link. You can check the log file on the Linux machine in <strong>/var/opt/azcmagent/log/himds.log</strong>. Looks like this in the logs.</p>
<pre class="brush: bash; title: ; notranslate">
{&quot;level&quot;:&quot;info&quot;,&quot;msg&quot;:&quot;Send HeartBeat to service via HTTP PATCH @ https://wus2.his.hybridcompute.azure-automation.net/machine/12345678-c3a2-6112-ab89-asdf343dcc307/metadata?api-version=1.0-preview\u0026location=westus2&quot;,&quot;time&quot;:&quot;2020-03-03T16:01:55-05:00&quot;}
</pre>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2020/03/azure-arc-managing-on-prem-windows-and-linux-servers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Windows, CentOS, FreeBSD: ssh, RDP &#8211; Bypass your corporate firewall</title>
		<link>https://blog.andreev.it/2018/03/125-ssh-rdp-bypass-your-corporate-firewall/</link>
					<comments>https://blog.andreev.it/2018/03/125-ssh-rdp-bypass-your-corporate-firewall/#comments</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Fri, 23 Mar 2018 17:04:18 +0000</pubDate>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freebsd]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=3765</guid>

					<description><![CDATA[If you are behind a firewall and want to access some resources over SSH&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>If you are behind a firewall and want to access some resources over SSH or RDP, most likely you won&#8217;t be able to do that. It&#8217;s because most of the corporate firewalls allow only ports 80 and 443 outbound. But you can still bypass that by tunneling everything over port 443. You will need a software called shellinabox to tunnel SSH over 443 and RDP gateway to tunnel the RDP traffic over 443. I&#8217;ll present the shellinabox solution for both CentOS 7 and FreeBSD 11. Both of these servers will be sitting somewhere in the cloud or behind your home firewall. The only requirement is to have port 443 opened and accessible on Internet. You might have a public IP or your home firewall will forward the traffic to 443, it doesn&#8217;t matter. Another option for connecting to any port is to use putty and a Linux/FreeBSD instance. I&#8217;ll describe that option last.</p>
<h1>CentOS 7</h1>
<p>shellinabox doesn&#8217;t come up with the default packages, so you have to install the EPEL release first. </p>
<pre class="brush: bash; title: ; notranslate">
yum install epel-release
yum install shellinabox
systemctl enable shellinaboxd
</pre>
<p>Edit the configuration file for shellinabox which is <strong>/etc/sysconfig/shellinaboxd</strong>. Make sure it looks like this. </p>
<pre class="brush: bash; title: ; notranslate">
# Shell in a box daemon configuration
# For details see shellinaboxd man page
# Basic options
USER=shellinabox
GROUP=shellinabox
CERTDIR=/var/lib/shellinabox
PORT=4200
OPTS=&quot;--css white-on-black.css -t -s /:SSH:localhost&quot;
#OPTS=&quot;--css color.css -t -s /:SSH:localhost&quot;
</pre>
<p>shellinabox runs on port 4200 by default. You can change it to run on 443, but you have to run as root. A better solution is to install Apache and use the mod_proxy so the Apache will listen on 443 and forward the traffic to 4200. </p>
<pre class="brush: bash; title: ; notranslate">
yum install httpd mod_ssl
systemctl enable httpd
</pre>
<p>Create the configuration file for the Apache server. In my case, I&#8217;ll access the SSH over HTTPS as sshtest.iandreev.com. Change the config below to suit your needs. </p>
<pre class="brush: bash; title: ; notranslate">
cd /etc/httpd/conf.d
touch httpd-vhosts.conf
</pre>
<p>Edit httpd-vhosts.conf and paste the following. </p>
<pre class="brush: bash; title: ; notranslate">
&lt;VirtualHost *:443&gt;
    SSLEngine On
    SSLCertificateFile /etc/pki/tls/certs/sshtest.iandreev.com.crt
    ServerAdmin klimenta@iandreev.com
    ServerName sshtest.iandreev.com
    ErrorLog &quot;/var/log/httpd/sshtest.iandreev.com-error_log&quot;
    CustomLog &quot;/var/log/httpd/sshtest.iandreev.com-access_log&quot; combined
    ProxyRequests On
    ProxyPreserveHost On
    &lt;Proxy *&gt;
        AuthUserFile /var/www/sshtest.iandreev.com/.htpasswd
        AuthName EnterPassword
        AuthType Basic
        require user ssh.admin
        Order deny,allow
        Allow from all
    &lt;/Proxy&gt;
    ProxyPass / http://localhost:4200/
    ProxyPassReverse / http://localhost:4200/
&lt;/VirtualHost&gt;
</pre>
<p>HTTPS requires a certificate, we&#8217;ll create a fake one. If you have a valid certificate, just put it under <strong>/etc/pki/tls/certs</strong> as <strong>sshtest.iandreev.com.crt</strong>.</p>
<pre class="brush: bash; title: ; notranslate">
cd /etc/pki/tls/certs
./make-dummy-cert sshtest.iandreev.com.crt
</pre>
<p>shellinabox when started will give you a SSH prompt so you can login to your server. A more secure solution is to protect the access even more with a username and password. Anytime you access your server, you&#8217;ll get prompted with a username and password and then you&#8217;ll get prompted with your SSH credentials.</p>
<pre class="brush: bash; title: ; notranslate">
cd /var/www
mkdir sshtest.iandreev.com
cd sshtest.iandreev.com
htpasswd -c .htpasswd ssh.admin
cd ..
chown -R apache:apache sshtest.iandreev.com
</pre>
<p>I&#8217;ve created a user called ssh.admin and the commands above will ask you for a password.<br />
Now, it&#8217;s time to start shellinabox.</p>
<pre class="brush: bash; title: ; notranslate">
systemctl start httpd
systemctl start shellinaboxd
</pre>
<p>On a laptop behind your comporate firewall, go to https://sshtest.yourdomain.com and you should get prompted for ssh.admin&#8217;s password. Once you pass that you&#8217;ll see the login prompt in your browser. From here you can SSH to any server that has port 22 opened.<br />
shellinabox comes with two styles. If you see above in it&#8217;s config, we provided these two lines.</p>
<pre class="brush: bash; title: ; notranslate">
OPTS=&quot;--css white-on-black.css -t -s /:SSH:localhost&quot;
#OPTS=&quot;--css color.css -t -s /:SSH:localhost&quot;
</pre>
<p>If you prefer black on white background, uncomment the last line, save the config file and restart shellinabox.<br />
Depending on your CentOS install, you might have firewall and SElinux enabled. If these are not configured, shellinabox won&#8217;t work. For the firewall, you&#8217;ll have to allow port 443 inbound. </p>
<pre class="brush: bash; title: ; notranslate">
firewall-cmd --add-service=https --permanent
firewall-cmd --reload
</pre>
<p>For SElinux, you&#8217;ll have to allow Apache to make outbound connections.</p>
<pre class="brush: bash; title: ; notranslate">
/usr/sbin/setsebool -P httpd_can_network_connect 1
</pre>
<p>At the end, it will look like this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-01.png" alt="" width="698" height="281" class="aligncenter size-full wp-image-8195" /></a><br />
&#8230;and this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-02.png" alt="" width="475" height="219" class="aligncenter size-full wp-image-8196" /></a></p>
<h1>FreeBSD 11</h1>
<p>We have to install Apache and shellinabox first. </p>
<pre class="brush: bash; title: ; notranslate">
pkg install shellinabox apache24
</pre>
<p>Make sure they start on boot. Add these two lines in <strong>/etc/rc.d</strong></p>
<pre class="brush: bash; title: ; notranslate">
apache24_enable=&quot;YES&quot;
shellinaboxd_enable=&quot;YES&quot;
shellinaboxd_flags=&quot;--disable-ssl --css=/usr/local/www/sshtest.iandreev.com/style.css&quot;
</pre>
<p>Go to the Apache config directory and edit the config file <strong>/usr/local/etc/apache24/httpd.conf</strong>. Make sure these lines are uncommented. </p>
<pre class="brush: bash; title: ; notranslate">
Include etc/apache24/extra/httpd-vhosts.conf
LoadModule authn_socache_module libexec/apache24/mod_authn_socache.so
LoadModule socache_shmcb_module libexec/apache24/mod_socache_shmcb.so
LoadModule ssl_module libexec/apache24/mod_ssl.so
Include etc/apache24/extra/httpd-ssl.conf
LoadModule proxy_module libexec/apache24/mod_proxy.so
LoadModule proxy_http_module libexec/apache24/mod_proxy_http.so
ServerName www.example.com:80
</pre>
<p>Go to <strong>/usr/local/etc/apache24/extra</strong> folder and make sure you have the definitiopn for the virtual host there. Change it to suit your needs. </p>
<pre class="brush: bash; title: ; notranslate">
&lt;VirtualHost *:443&gt;
    SSLEngine On
    SSLCertificateFile /usr/local/share/certs/sshtest.iandreev.com.crt
    SSLCertificateKeyFile /usr/local/share/certs/sshtest.iandreev.com.key
    ServerAdmin klimenta@iandreev.com
    ServerName sshtest.iandreev.com
    ErrorLog &quot;/var/log/sshtest.iandreev.com-error_log&quot;
    CustomLog &quot;/var/log/sshtest.iandreev.com-access_log&quot; combined
    ProxyRequests On
    ProxyPreserveHost On
    &lt;Proxy *&gt;
        AuthUserFile /usr/local/www/sshtest.iandreev.com/.htpasswd
        AuthName EnterPassword
        AuthType Basic
        require user ssh.admin
        Order deny,allow
        Allow from all
    &lt;/Proxy&gt;
    ProxyPass / http://localhost:4200/
    ProxyPassReverse / http://localhost:4200/
&lt;/VirtualHost&gt;
</pre>
<p>In the same directory, edit <strong>httpd-ssl.conf</strong> file and make sure it looks like this.</p>
<pre class="brush: bash; title: ; notranslate">
SSLRandomSeed startup file:/dev/urandom 512
Listen 443
SSLCipherSuite HIGH:MEDIUM:!MD5:!RC4
SSLProxyCipherSuite HIGH:MEDIUM:!MD5:!RC4
SSLHonorCipherOrder on
SSLProtocol all -SSLv3
SSLProxyProtocol all -SSLv3
SSLPassPhraseDialog  builtin
SSLSessionCache        &quot;shmcb:/var/run/ssl_scache(512000)&quot;
SSLSessionCacheTimeout  300
</pre>
<p>We&#8217;ll protect shellinabox with extra username (ssh.admin) and password. </p>
<pre class="brush: bash; title: ; notranslate">
cd /usr/local/www
mkdir sshtest.iandreev.com
cd sshtest.iandreev.com
htpasswd -c .htpasswd ssh.admin
</pre>
<p>We&#8217;ll need a certificate for the HTTPS site. Use your own or create a fake one. Hit ENTER for everything prompted. It&#8217;s a fake certificate.</p>
<pre class="brush: bash; title: ; notranslate">
cd /usr/local/share/certs
openssl genrsa -out sshtest.iandreev.com.key 2048
openssl req -new -key sshtest.iandreev.com.key -out sshtest.iandreev.com.csr
openssl x509 -req -days 3650 -in sshtest.iandreev.com.csr -signkey sshtest.iandreev.com.key -out sshtest.iandreev.com.crt
</pre>
<p>Unlike CentOS, FreeBSD shellinabox doesn&#8217;t come up with CSS files for the color, so we can use these two. Copy these files under <strong>/usr/local/www/sshtest.iandreev.com</strong> as <strong>blackonwhite.css</strong> and <strong>whiteonblack.css</strong>.<br />
This is <strong>blackonwhite.css</strong>. Click to expand. </p>
<pre class="brush: css; collapse: true; light: false; title: ; toolbar: true; notranslate">
#vt100 .ansiDefR {
  color:            #ffffff;
}

#vt100 .bgAnsiDefR {
  background-color: #123450;
}

#vt100 #scrollable.inverted .ansiDefR {
  color:            #000000;
}

#vt100 #scrollable.inverted .bgAnsiDefR {
  background-color: #ffffff;
}

#vt100 .ansiDefR {
  color:            #ffdfd0;
}

#vt100 .bgAnsiDefR {
  background-color: #010203;
}

#vt100 #scrollable.inverted .ansiDefR {
  color:            #002030;
}

#vt100 #scrollable.inverted .bgAnsiDefR {
  background-color: #1f1fff;
}
</pre>
<p>This is <strong>whiteonblack.css</strong>. Click to expand.</p>
<pre class="brush: css; collapse: true; light: false; title: ; toolbar: true; notranslate">
#vt100 #cursor.bright {
  background-color: white;
  color:            black;
}

#vt100 #cursor.dim {
  background-color: black;
  opacity:          0.2;
  -moz-opacity:     0.2;
  filter:           alpha(opacity=20);
}

#vt100 #scrollable {
  color:            #ffffff;
  background-color: #000000;
}

#vt100 #scrollable.inverted {
  color:            #000000;
  background-color: #ffffff;
}

#vt100 .ansiDef {
  color:            #ffffff;
}

#vt100 .ansiDefR {
  color:            #000000;
}

#vt100 .bgAnsiDef {
  background-color: #000000;
}

#vt100 .bgAnsiDefR {
  background-color: #ffffff;
}

#vt100 #scrollable.inverted .ansiDef {
  color:            #000000;
}

#vt100 #scrollable.inverted .ansiDefR {
  color:            #ffffff;
}

#vt100 #scrollable.inverted .bgAnsiDef {
  background-color: #ffffff;
}

#vt100 #scrollable.inverted .bgAnsiDefR {
  background-color: #000000;
}
</pre>
<p>Copy one of them to be your style. Anytime you change the style, restart shellinabox.</p>
<pre class="brush: bash; title: ; notranslate">
cd /usr/local/www/sshtest.iandreev.com
cp blackonwhite.css style.css
cd ..
chown -R www:www sshtest.iandreev.com
</pre>
<p>Finally, start Apache and shellinabox. </p>
<pre class="brush: bash; title: ; notranslate">
service shellinaboxd start
service apache24 start
</pre>
<p>Access your server from a laptop behind your corporate firewall as https://sshtest.domain.com.</p>
<h1>Windows 2016</h1>
<p>You will need a Windows 2016 server with a public IP and port 443 allowed or you can use a Windows server behind your home network as long as port 443 is allowed. In order to bypass the RDP restriction, we&#8217;ll tunnel the RDP traffic over HTTPS using Remote Desktop Gateway.<br />
From the Server Manager, go to Add Roles and Features. Select <strong>Remote Desktop Services</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-03.png" alt="" width="790" height="556" class="aligncenter size-full wp-image-8197" /></a><br />
Click <strong>Next </strong>2-3 times and then select <strong>Remote Desktop Gateway</strong>. Click Next again and accept all the defaults. Windows will install some other components for you.<br />
Once everything is installed, from the Server Manager&#8217;s menu click on <strong>Tools</strong>, <strong>Remote Desktop Services</strong> and then <strong>Remote Desktop Gateway Manager</strong>.<br />
Click on the server name and in the middle pane you&#8217;ll see what you have to do.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-04.png" alt="" width="972" height="456" class="aligncenter size-full wp-image-8198" /></a><br />
Click on the first link, <strong>View or modify certificate properties</strong>. Choose to create a fake certificate or you can import your own. It has to be in p12 format, not PEM.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-05.png" alt="" width="499" height="590" class="aligncenter size-full wp-image-8199" /></a><br />
If you decide to go with a fake certificate, enter the FQDN of the server, e.g sshtest.iandreev.com. You will have to make sure that sshtest.iandreev.com resolves to the public IP of the Windows box or if you have an internal server in your home lab, then the external IP of your cable/DSL modem. Then just click on the button <strong>Create and Import Certificate</strong>, enter the FQDN sshtest.iandreev.com and then click <strong>OK </strong>when prompted. Click <strong>Apply </strong>and <strong>OK </strong>to go back.<br />
At this point, you might want to create a user or a group that you can allow access to the Gateway.<br />
I created a user called RDP. Back in the RD Gateway Manager, select <strong>Policies </strong>under the server name, right-click on it and choose <strong>Create New Authorization Policies</strong>. Choose the option to create both RD CAP and RD RAP policies. Here is what I did in the wizard config.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-06.png" alt="" width="958" height="600" class="aligncenter size-full wp-image-8200" /></a><br />
I choose BUILTIN\Users to be able to use the Gateway. The generic user RDP that I created is by default a member of the users group.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-07.png" alt="" width="952" height="598" class="aligncenter size-full wp-image-8201" /></a><br />
Select the default <strong>Enable device redirection for all client devices</strong>.<br />
Check both checkmarks for <strong>Idle Timeout</strong> and <strong>Session Timeout</strong>. This is optional, but it&#8217;s good to have.<br />
Click Next and then create the <strong>Resource Authorization Policy</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-08.png" alt="" width="957" height="598" class="aligncenter size-full wp-image-8202" /></a><br />
Accept the same group (<strong>BUILTIN\Users</strong>).<br />
Choose the option at the bottom, <strong>Allow users to connect to any network resource (computer)</strong>.<br />
Choose the first option, <strong>Allow connections only to port 3389</strong>.<br />
Click <strong>Next </strong>and <strong>Finish</strong>.<br />
So, how do you use this solution now? Easy&#8230;<br />
All you have to do is go to your corporate laptop and create a new RDP connection. Under the General tab enter the IP address of the Windows box that you want to reach. This is the box that listens on 3389 and that you are not able to reach directly. Mind that the Windows server that we just built is a gateway, so the Windows RD Gateway server should be able to talk to the destination server over 3389 and your corporate laptop will talk to Windows RD Gateway server over 443.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-09.png" alt="" width="542" height="580" class="aligncenter size-full wp-image-8203" /></a><br />
Click on the <strong>Advanced </strong>tab and then the <strong>Settings </strong>button. Select to <strong>Use these RD Gateway server settings</strong> and enter the FQDN (sshtest.iandreev.com) of the RD Gateway server that we just built.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-10.png" alt="" width="539" height="535" class="aligncenter size-full wp-image-8204" /></a><br />
Once you are done, click <strong>Connect </strong>and you should get prompted to enter the credentials for the RD Gateway (in my case the username and password for the RDP user) and then you&#8217;ll have to enter the username and password for the destination server.<br />
NOTE: Make sure you use .\rdp for the username, not rdp. You can also get an error saying that the identity of the RD Gateway can&#8217;t be verified. This is most likely if you messed up the certificate and it doesn&#8217;t match the hostname. In that case, the RDP client will allow you to view the certificate. Then copy it to a file and import it on the local machine under the Trusted Root Cert Authorities. </p>
<h1>Tunnel over putty</h1>
<p>Let&#8217;s say that your corporate firewall allows only port 443 outbound. In this case, we&#8217;ll build a Linux/BSD server with a public IP and change the SSH listener port from 22 to 443. For this, edit <strong>sshd_config</strong> under <strong>/etc/ssh/sshd_config</strong> or <strong>/usr/local/etc/ssh/sshd_config</strong>. Look for the directive <strong>Port 22</strong> and change it to <strong>Port 443</strong>. Restart the ssh service.<br />
On your client machine behind the corporate firewall, open putty and under Session enter the public IP of your Linux/BSD server and port 443 so it looks like this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-11.png" alt="" width="453" height="197" class="aligncenter size-full wp-image-8205" /></a><br />
Now, expand the <strong>Connection </strong>on the left side, then <strong>SSH </strong>and select <strong>Tunnels</strong>. For the <strong>source port</strong> enter 3390 and for the <strong>destination </strong>enter the IP of your Windows box where you want to connect.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2018/03/P102-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2018/03/P102-12.png" alt="" width="448" height="200" class="aligncenter size-full wp-image-8206" /></a><br />
Finally, save this session, open it and login to the Linux server to establish the tunnel. You should be able to run the RDP client (mstsc) and RDP to 127.0.0.1:3390. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2018/03/125-ssh-rdp-bypass-your-corporate-firewall/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>CentOS, FreeBSD, Windows: rsyslog server and client</title>
		<link>https://blog.andreev.it/2017/12/118-linux-freebsd-windows-rsyslog-server-client/</link>
					<comments>https://blog.andreev.it/2017/12/118-linux-freebsd-windows-rsyslog-server-client/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Sun, 03 Dec 2017 23:56:22 +0000</pubDate>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[rsyslog]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=3480</guid>

					<description><![CDATA[In this post, I&#8217;ll explain how to configure a rsyslog server and client on&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>In this post, I&#8217;ll explain how to configure a <strong>rsyslog </strong>server and client on various operating systems. For the servers, I&#8217;ll chose 2 Red Hat 7 servers and the clients will be AWS Linux, FreeBSD and Windows 2016.<br />
<strong>rsyslog </strong>is an open-source utility for logging, a derivate of the original syslog. As defined by <a href="https://tools.ietf.org/html/rfc3164" rel="noopener noreferrer" target="_blank">RFC 3164</a>, each message includes the facility code and severity level. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-01.png" alt="" width="450" height="690" class="aligncenter size-full wp-image-7794" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-01.png 450w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-01-196x300.png 196w" sizes="(max-width: 450px) 100vw, 450px" /></a><br />
The severity levels are these. (Both screenshots are from <a href="https://en.wikipedia.org/wiki/Syslog" rel="noopener noreferrer" target="_blank">Wikipedia</a>).<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-02.png" alt="" width="958" height="399" class="aligncenter size-full wp-image-7795" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-02.png 958w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-02-300x125.png 300w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-02-768x320.png 768w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-02-585x244.png 585w" sizes="(max-width: 958px) 100vw, 958px" /></a></p>
<h1>RHEL 7 rsyslog servers</h1>
<p>RHEL 7 comes with <strong>rsyslog </strong>installed by default. Make sure it&#8217;s running.</p>
<pre class="brush: bash; title: ; notranslate">
systemctl status rsyslog
</pre>
<p>The configuration file is <strong>/etc/rsyslog.conf</strong>. Make sure that these lines are uncommented. They tell the <strong>rsyslog </strong>daemon to accept TCP and UDP connections.</p>
<pre class="brush: bash; title: ; notranslate">
# Provides UDP syslog reception
$ModLoad imudp
$UDPServerRun 514

# Provides TCP syslog reception
$ModLoad imtcp
$InputTCPServerRun 514
</pre>
<p>If you make changes in <strong>/etc/rsyslog.conf</strong>, make sure you verify the config.</p>
<pre class="brush: bash; title: ; notranslate">
rsyslogd -N 1
</pre>
<p>If you make a change, you&#8217;ll have to restart the <strong>rsyslog </strong>daemon.</p>
<pre class="brush: bash; title: ; notranslate">
systemctl restart rsyslog
</pre>
<p>To test if <strong>rsyslog </strong>works fine, try a test.</p>
<pre class="brush: bash; title: ; notranslate">
logger -p local0.notice -t from_cmd_line &quot;Test Message&quot;
</pre>
<p>If you check the <strong>/var/log/messages</strong>, a file where by default <strong>rsyslog </strong>writes the output, you&#8217;ll see the message.</p>
<pre class="brush: bash; title: ; notranslate">
tail /var/log/messages
</pre>
<p><a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-03.png" alt="" width="562" height="48" class="aligncenter size-full wp-image-7796" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-03.png 562w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-03-300x26.png 300w" sizes="(max-width: 562px) 100vw, 562px" /></a><br />
OK, so we didn&#8217;t have to make any changes on both RHEL servers. Let&#8217;s move to the clients.<br />
NOTE: If you have firewalld enabled, you&#8217;ll have to open the ports for the clients.</p>
<pre class="brush: bash; title: ; notranslate">
firewall-cmd --permanent --zone=public --add-port=514/tcp
firewall-cmd --permanent --zone=public --add-port=514/udp
firewall-cmd --reload
</pre>
<h1>AWS Linux, RHEL 6, CentOS 6</h1>
<p>AWS Linux is based on RHEL 6 so the instructions will apply for all of them. Check if <strong>rsyslog </strong>is running.</p>
<pre class="brush: bash; title: ; notranslate">
service rsyslog status
</pre>
<p>Edit <strong>/etc/rsyslog.conf</strong> and make sure these lines are commented. We don&#8217;t want a server, we want a client. </p>
<pre class="brush: bash; title: ; notranslate">
# Provides UDP syslog reception
#$ModLoad imudp
#$UDPServerRun 514

# Provides TCP syslog reception
#$ModLoad imtcp
#$InputTCPServerRun 514
</pre>
<p>Add these lines (11 to 14) somewhere at the end.</p>
<pre class="brush: bash; highlight: [11,12,13,14]; title: ; notranslate">
#$WorkDirectory /var/lib/rsyslog # where to place spool files
#$ActionQueueFileName fwdRule1 # unique name prefix for spool files
#$ActionQueueMaxDiskSpace 1g   # 1gb space limit (use as much as possible)
#$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
#$ActionQueueType LinkedList   # run asynchronously
#$ActionResumeRetryCount -1    # infinite retries if host is down
# remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional
#*.* @@remote-host:514
# ### end of the forwarding rule ###

*.*     @@10.0.0.170
$ActionExecOnlyWhenPreviousIsSuspended on
&amp; @@10.0.0.225
$ActionExecOnlyWhenPreviousIsSuspended off

# Finally include all config files in /etc/rsyslog.d. This allows overrides
# of the default configuration above.
$IncludeConfig /etc/rsyslog.d/*.conf
</pre>
<p>These four lines means that my primary <strong>rsyslog </strong>server has an IP of <strong>10.0.0.170</strong> and in case it&#8217;s not reachable, use the server <strong>10.0.0.225</strong>. Line 11 tells the <strong>rsyslog </strong>client to log everything to the server. If you want only certain messages logged, than you can change it, e.g. instead of <strong>*.* @@10.0.0.170</strong> you can use something like <strong>*.info @@10.0.0.170</strong> or <strong>*.info;auth.err @@10.0.0.170</strong>. Look at those two tables above. If you run this command on the client.</p>
<pre class="brush: bash; title: ; notranslate">
logger -p local0.notice -t from_aws_linux &quot;Test Message&quot;
</pre>
<p>and do</p>
<pre class="brush: bash; title: ; notranslate">
tail -f /var/log/messages
</pre>
<p>on the server, you&#8217;ll see the message on the server, not on the client.</p>
<h1>FreeBSD</h1>
<p>FreeBSD uses the old <strong>syslog</strong>, not <strong>rsyslog</strong>, but we can still redirect the logs to our RHEL servers. Edit <strong>/etc/syslog.conf</strong> and all the way at the end add this line.</p>
<pre class="brush: bash; title: ; notranslate">
*.* @10.0.0.170
</pre>
<p>As you can see, <strong>syslog </strong>uses one @, not two @@s. Restart the service and send a test message. You&#8217;ll see that the message goes to the RHEL server now.</p>
<pre class="brush: bash; title: ; notranslate">
service syslogd restart
logger -p local0.notice -t from_FreeBSD &quot;Test Message&quot;
</pre>
<h1>Windows</h1>
<p>Go to this <a href="http://www.rsyslog.com/windows-agent/" rel="noopener noreferrer" target="_blank">link </a>and download the rsyslog client. You can see the link for the download and also for the manual.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-04.png" alt="" width="724" height="290" class="aligncenter size-full wp-image-7797" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-04.png 724w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-04-300x120.png 300w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-04-585x234.png 585w" sizes="(max-width: 724px) 100vw, 724px" /></a><br />
The <strong>rsyslog </strong>agent for Windows is very detailed and requires some studying. Use the manual, there are some examples there. I&#8217;ll show you how to forward the <strong>event ID 7036</strong>. This event gets triggered when a service changes its state. So, download the client and open up the GUI. Expand the following and click on <strong>Rsyslog</strong>. Enter the primary and secondary rsyslog server&#8217;s IPs. Click <strong>Save </strong>in the upper left corner and then click <strong>Restart</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-05.png" alt="" width="990" height="646" class="aligncenter size-full wp-image-7798" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-05.png 990w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-05-300x196.png 300w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-05-768x501.png 768w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-05-585x382.png 585w" sizes="(max-width: 990px) 100vw, 990px" /></a><br />
If you check the logs on your rsyslog server, you&#8217;ll see a lot of logging going on. Pretty much everything that Windows does. We just want to filter all these logs to a single event ID.<br />
So, in the <strong>Default Rule Set</strong>, click <strong>Filters</strong>, then right-click <strong>AND</strong>, choose <strong>Add Filter, Event Log Monitor</strong> and then <strong>Event ID</strong>. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-06.png" alt="" width="910" height="556" class="aligncenter size-full wp-image-7799" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-06.png 910w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-06-300x183.png 300w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-06-768x469.png 768w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-06-585x357.png 585w" sizes="(max-width: 910px) 100vw, 910px" /></a><br />
Enter the Event ID <strong>7036</strong>, click <strong>Save </strong>and <strong>Restart</strong>. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-07.png" alt="" width="351" height="470" class="aligncenter size-full wp-image-7800" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-07.png 351w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-07-224x300.png 224w" sizes="(max-width: 351px) 100vw, 351px" /></a><br />
Now, go to <strong>Services </strong>(services.msc) and restart <strong>Windows Update </strong>service. You should see this on the rsyslog server.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2017/12/P095-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P095-08.png" alt="" width="565" height="75" class="aligncenter size-full wp-image-7801" srcset="https://blog.andreev.it/wp-content/uploads/2017/12/P095-08.png 565w, https://blog.andreev.it/wp-content/uploads/2017/12/P095-08-300x40.png 300w" sizes="(max-width: 565px) 100vw, 565px" /></a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2017/12/118-linux-freebsd-windows-rsyslog-server-client/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Windows: Enterprise PKI on Windows 2016</title>
		<link>https://blog.andreev.it/2017/12/117-windows-enterprise-pki-windows-2016/</link>
					<comments>https://blog.andreev.it/2017/12/117-windows-enterprise-pki-windows-2016/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Sat, 02 Dec 2017 23:44:23 +0000</pubDate>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[Enterprise PKI]]></category>
		<category><![CDATA[PKI]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=3334</guid>

					<description><![CDATA[A public key infrastructure (PKI) is a set of roles, policies, and procedures needed&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>A public key infrastructure (PKI) is a set of roles, policies, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates and manage public-key encryption. That&#8217;s what <a href="https://en.wikipedia.org/wiki/Public_key_infrastructure" rel="noopener noreferrer" target="_blank">Wikipedia </a>says.<br />
Today, using certificates is a must. Google search gives you better search scores if your web site is using certificates and if your site is mobile-friendly. So, in this post I’ll describe how to deploy an Enterprise PKI on Windows 2016 server. This post is mostly for on-prem deployments, but it will give you some insights on how PKI works. I will create one Windows IIS web server joined to the domain and one Linux server (not joined to the domain) running Apache. I&#8217;ll create SSL sites on both and deploy the certificates, so the clients (Windows machines on your corp domain) won&#8217;t get that certificate warning when browsing these site.<br />
In order to do what we planed, we’ll use Active Directory Certificate Services (AD CS). We’ll create a lab with a domain controller, an offline Certificate Authority, an Enterprise Certificate Authority and two web servers. These two web servers (one running IIS and the other running Apache) will host two web sites (test1 and test2) that will have SSL certificates issued by our CA.<br />
The hostnames are :</p>
<ul>
<li>dc01.empire.local</li>
<li>offCA</li>
<li>entCA.empire.local</li>
<li>iis.empire.local</li>
<li>apache</li>
</ul>
<div style="border:1px solid red; padding:16px;">
<p style="text-align:center;"><strong><span style="color:#800000;">NOTE</span> </strong></p>
<p style="text-align:center;"><em><strong>In this post, I&#8217;ll refer offline CA as Root CA and Enterprise CA as Subordinate CA.</strong></a></em><a href="http://paul-barford.blogspot.com/"> </a></p>
</div>
<h1>Domain Controller(s)</h1>
<p>I won’t explain how to create a domain controller. Just make sure you have a domain controller(s) in your environment. My domain is called <strong>empire.local</strong> with <strong>EMPIRE</strong> as a NetBIOS domain name.</p>
<h1>Offline Root Certificate Authority</h1>
<p>Why do we need an offline Certificate Authority and enterprise CA? It’s per MS best practices. The offline CA will be the one that holds the PKI, but once it’s configured it can be brought offline. The actual certificates will be signed by the enterprise CA. In case the enterprise CA gets compromised, you’ll have to bring the offlince CA on-line and revoke the certificate for the enterprise CA.<br />
So, let’s build the offline CA. This server shouldn’t be part of the domain. Leave it as a workgroup member. From the <strong>Server Manager</strong>, click on <strong>Add Roles and Features</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-01.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-3338" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-01.png" alt="" width="357" height="231" /></a><br />
Select <strong>Active Directory Certificate Services</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-02.png" alt="" width="787" height="558" class="aligncenter size-full wp-image-3344" /></a><br />
Under role services, select <strong>Certification Authority</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-03.png" alt="" width="780" height="563" class="aligncenter size-full wp-image-3345" /></a><br />
Once the installation is completed, click on the flag icon in the upper right corner to configure the CA.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-04.png" alt="" width="419" height="200" class="aligncenter size-full wp-image-3346" /></a><br />
Choose the defaults or if you want a separate local user, specify it here. You have to create that user first.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-05.png" alt="" width="757" height="557" class="aligncenter size-full wp-image-3347" /></a><br />
Choose to configure <strong>Certification Authority</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-06.png" alt="" width="763" height="560" class="aligncenter size-full wp-image-3348" /></a><br />
Choose <strong>Standalone CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-07.png" alt="" width="761" height="559" class="aligncenter size-full wp-image-3349" /></a><br />
Choose <strong>Root CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-08.png" alt="" width="749" height="557" class="aligncenter size-full wp-image-3350" /></a><br />
Select to <strong>Create a new private key</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-09.png" alt="" width="758" height="555" class="aligncenter size-full wp-image-3351" /></a><br />
Choose <strong>SHA256 </strong>and <strong>2048</strong>. Don’t use SHA1, it’s being deprecated.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-10.png" alt="" width="758" height="557" class="aligncenter size-full wp-image-3352" /></a><br />
Choose the common name for the CA. In my case it’s <strong>ROOT-CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-11.png" alt="" width="756" height="560" class="aligncenter size-full wp-image-3353" /></a><br />
Use validity for this CA. I used 10 instead of the default 5.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-12.png" alt="" width="758" height="559" class="aligncenter size-full wp-image-3354" /></a><br />
Choose where the database and the logs will be located. I used the defaults, best practice is to use a separate data drive.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-13.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-13.png" alt="" width="757" height="559" class="aligncenter size-full wp-image-3355" /></a><br />
Verify everything looks good and click <strong>Configure</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-14.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-14.png" alt="" width="764" height="554" class="aligncenter size-full wp-image-3356" /></a><br />
Once completed, go to <strong>C:\Windows\System32\CertSrv\CertEnroll</strong>. This is where you’ll have the root certificate (<strong>offCA_ROOT-CA.crt</strong>) and the Certificate Revocation List (<strong>ROOT-CA.crl</strong>).<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-15.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-15.png" alt="" width="718" height="203" class="aligncenter size-full wp-image-3357" /></a><br />
Go to the <strong>Administrative Tools</strong> under <strong>Control Panel</strong> and run the <strong>Certification Authority</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-16.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-16.png" alt="" width="544" height="198" class="aligncenter size-full wp-image-3358" /></a><br />
Now, we have to configure the Root (offline) CA so it is aware of the <strong>subordinate (enterprise) CA</strong>. Right click the name of the CA, choose <strong>Properties</strong> and then click on the <strong>Extensions</strong> tab. You’ll see something like this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-17.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-17.png" alt="" width="602" height="628" class="aligncenter size-full wp-image-3359" /></a><br />
Click <strong>Add </strong>and enter the following in the <strong>Location</strong> field. Then click <strong>OK</strong>. Don’t click <strong>Insert</strong>.</p>
<pre class="brush: bash; title: ; notranslate">
http://entCA.empire.local/certdata/&lt;CaName&gt;&lt;CRLNameSuffix&gt;&lt;DeltaCRLAllowed&gt;.crl
</pre>
<p>Replace <strong>entCA.empire.local</strong> with the name of your subordinate (enterprise) server.<br />
After you click <strong>OK</strong>, check these two checkmarks.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-18.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-18.png" alt="" width="397" height="535" class="aligncenter size-full wp-image-3369" /></a><br />
By default, they are not checked. Click <strong>Apply </strong>and you’ll be prompted to restart the CA service. Go back to the properties of the <strong>Root CA</strong>, click on the <strong>Extensions </strong>tab, but this time switch to <strong>Authority Information Access (AIA)</strong> instead of <strong>CRL Distribution Point (CDP)</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-19.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-19.png" alt="" width="414" height="541" class="aligncenter size-full wp-image-3362" /></a><br />
Same thing here. Click <strong>Add </strong>and enter the following in the <strong>Location </strong>field. </p>
<pre class="brush: bash; title: ; notranslate">
http://entCA.empire.local/certdata/&lt;ServerDNSName&gt;&lt;CaName&gt;&lt;CertificateName&gt;.crt
</pre>
<p>Replace <strong>entCA.empire.local</strong> with your enterprise CA server name.  Click <strong>OK</strong>, don’t click <strong>Insert</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-20.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-20.png" alt="" width="456" height="322" class="aligncenter size-full wp-image-3363" /></a><br />
Then check <strong>Include in the AIA extension of issues certificates</strong> which by default is not checked. Click <strong>OK </strong>and that will restart the CA service.<br />
Select <strong>Revoked Certiicates</strong>, right-click, choose <strong>All Tasks</strong> and then <strong>Publish</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-21.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-21.png" alt="" width="444" height="274" class="aligncenter size-full wp-image-3365" /></a><br />
Click <strong>OK</strong> for the <strong>New CRL</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-22.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-22.png" alt="" width="405" height="537" class="aligncenter size-full wp-image-3366" /></a><br />
If you go back to<strong> C:\Windows\System32\CertSrv\CertEnroll</strong>, you’ll see that the time stamp on <strong>ROOT-CA.crl</strong> file has changed.<br />
Now, we need the root certificate (without the private key) exported so we can copy it to the <strong>enterprise CA</strong>. Right-click the CA, choose <strong>Properties </strong>and from the <strong>General </strong>tab, choose <strong>View Certificate</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-23.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-23.png" alt="" width="442" height="619" class="aligncenter size-full wp-image-3367" /></a><br />
Click on <strong>Details </strong>tab and then <strong>Copy to File</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-24.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-24.png" alt="" width="442" height="619" class="aligncenter size-full wp-image-3373" /></a><br />
In the <strong>Certificate Export Wizard</strong>, choose the first option (<strong>DER</strong>).<br />
Click <strong>Next </strong>and save it under <strong>c:\windows\system32\certsrv\certenroll</strong> with a name something like this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-25.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-25.png" alt="" width="542" height="528" class="aligncenter size-full wp-image-3374" /></a><br />
Click <strong>Save </strong>then <strong>Finish</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-26.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-26.png" alt="" width="636" height="527" class="aligncenter size-full wp-image-3375" /></a><br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-27.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-27.png" alt="" width="531" height="518" class="aligncenter size-full wp-image-3378" /></a></p>
<h1>Enterprise (standalone) Certificate Authority</h1>
<p>Now, let’s move to the subordinate (enterprise) CA. This is the server that will actually issue and revoke certificates. Make sure this server is a member of the domain.<br />
From the server manager go to<strong> Add Roles and Features</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-28.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-28.png" alt="" width="357" height="231" class="aligncenter size-full wp-image-3377" /></a><br />
Choose <strong>Active Directory Certificate Services</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-29.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-29.png" alt="" width="780" height="558" class="aligncenter size-full wp-image-3379" /></a><br />
Choose both, <strong>Certification Authority</strong> and <strong>Certificate Authority Web Enrollment</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-30.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-30.png" alt="" width="775" height="557" class="aligncenter size-full wp-image-3380" /></a><br />
Web enrollment will require IIS. Choose defaults.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-31.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-31.png" alt="" width="788" height="559" class="aligncenter size-full wp-image-3381" /></a><br />
Once the installation is completed, click on the flag icon in the upper right corner to configure the CA.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-32.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-32.png" alt="" width="419" height="200" class="aligncenter size-full wp-image-3382" /></a><br />
Choose the Administrator or some other domain user if you want.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-33.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-33.png" alt="" width="766" height="556" class="aligncenter size-full wp-image-3383" /></a><br />
Select the <strong>Certification Authority</strong> and <strong>Certification Authority Web Enrollment</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-34.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-34.png" alt="" width="763" height="571" class="aligncenter size-full wp-image-3420" /></a><br />
Select <strong>Enterprise CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-35.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-35.png" alt="" width="752" height="555" class="aligncenter size-full wp-image-3385" /></a><br />
Select <strong>Subordinate CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-36.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-36.png" alt="" width="755" height="551" class="aligncenter size-full wp-image-3386" /></a><br />
<strong>Create a new Private key</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-37.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-37.png" alt="" width="749" height="554" class="aligncenter size-full wp-image-3387" /></a><br />
Choose <strong>SHA256 </strong>and <strong>2048</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-38.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-38.png" alt="" width="757" height="558" class="aligncenter size-full wp-image-3388" /></a><br />
Choose the common name. In my case it&#8217;s <strong>ENT-CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-39.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-39.png" alt="" width="754" height="555" class="aligncenter size-full wp-image-3389" /></a><br />
Choose where to save the request file. This will have to be signed by the <strong>Root CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-40.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-40.png" alt="" width="759" height="560" class="aligncenter size-full wp-image-3390" /></a><br />
Choose defaults. Again, best practice is to save it to a separate data drive.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-41.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-41.png" alt="" width="760" height="560" class="aligncenter size-full wp-image-3391" /></a><br />
Verify and click <strong>Configure</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-42.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-42.png" alt="" width="758" height="557" class="aligncenter size-full wp-image-3392" /></a><br />
You’ll see this warning. This means you have to sign the request file that we just saved under C:\<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-43.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-43.png" alt="" width="752" height="557" class="aligncenter size-full wp-image-3393" /></a><br />
Now, copy the files from the <strong>Root CA</strong> (the first server) to <strong>Enterprise CA</strong> (this server). You will need to copy those three files under <strong>C:\Windows\System32\CertSrv\CertEnroll</strong> to anywhere on the Enterprise CA server. Choose the desktop, we won’t need them after the configuration. Right click on the certificate file that we created (the one with <strong>NO-PVT-KEY</strong> in its name) in its name and a <strong>.cer</strong> as a file extenstion. Click on <strong>Install Certificate</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-44.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-44.png" alt="" width="529" height="275" class="aligncenter size-full wp-image-3394" /></a><br />
Choose <strong>Local Machine</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-45.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-45.png" alt="" width="530" height="523" class="aligncenter size-full wp-image-3395" /></a><br />
Choose <strong>Place all certificates in the following store</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-46.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-46.png" alt="" width="531" height="529" class="aligncenter size-full wp-image-3396" /></a><br />
Click <strong>Browse </strong>and select <strong>Trusted Root Certification Authority</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-47.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-47.png" alt="" width="537" height="527" class="aligncenter size-full wp-image-3397" /></a><br />
Click <strong>Next </strong>and <strong>Finish</strong>.<br />
Now, go to <strong>c:\inetpub\wwwroot\</strong> and create a folder <strong>certdata</strong>. Remember when we created the CDP and IAI extensions? We used something like <em>http://entCA.empire.local/certdata&#8230;</em> Well, we are creating that now. So, create that folder and move the other two files there.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-48.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-48.png" alt="" width="819" height="565" class="aligncenter size-full wp-image-3398" /></a><br />
OK, now go back to the offline <strong>Root CA</strong>. Copy the request file that was created when we installed CA on the <strong>Enterprise CA</strong>. That’s the file that’s on the C:\ drive of the <strong>Enterprise CA</strong>. Move it to the desktop of the <strong>offline Root CA</strong>.<br />
Launch the <strong>Certification Authority (Control Panel, Administrative Tools, Certification Authority) </strong>and select the name of the <strong>Root CA</strong>. Right-click, select <strong>All Tasks</strong> and then <strong>Submit New Request</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-49.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-49.png" alt="" width="451" height="289" class="aligncenter size-full wp-image-3399" /></a><br />
Browse to the file that we just copied on the desktop.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-50.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-50.png" alt="" width="661" height="558" class="aligncenter size-full wp-image-3400" /></a><br />
Click on <strong>Pending Requests</strong>. You’ll see our request is waiting for approval.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-51.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-51.png" alt="" width="774" height="306" class="aligncenter size-full wp-image-3401" /></a><br />
Select the requested item on the right and then right-click, <strong>All Tasks</strong> and <strong>Issue</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-52.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-52.png" alt="" width="752" height="320" class="aligncenter size-full wp-image-3402" /></a><br />
The request entry will be gone, but if you click on <strong>Issued Certificates</strong>, you’ll see the certificate there.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-53.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-53.png" alt="" width="783" height="239" class="aligncenter size-full wp-image-3403" /></a><br />
Double-click the certificate on the right and then click on <strong>Details </strong>tab.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-54.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-54.png" alt="" width="681" height="658" class="aligncenter size-full wp-image-3404" /></a><br />
Click <strong>Copy to File</strong>. In the export wizard choose this option.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-55.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-55.png" alt="" width="741" height="677" class="aligncenter size-full wp-image-3405" /></a><br />
Save it on the desktop. I named it as <strong>entCA-signed</strong>, which will remind me that this is a signed certificate for the Enterprise CA.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-56.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-56.png" alt="" width="741" height="683" class="aligncenter size-full wp-image-3406" /></a><br />
Go back to the <strong>Enterprise CA</strong> and copy this <strong>entCA-signed</strong> file to the desktop. Then start the <strong>Certification Authority (Control Panel, Administrative Tools, Certification Authority)</strong>. You will see that the CA service is stopped. Right click the enterprise CA name, choose <strong>All Tasks</strong> and then <strong>Install CA Certificate</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-57.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-57.png" alt="" width="537" height="339" class="aligncenter size-full wp-image-3407" /></a><br />
Browse to that file <strong>entCA-signed </strong>that we just copied from the <strong>offline Root CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-58.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-58.png" alt="" width="775" height="665" class="aligncenter size-full wp-image-3408" /></a><br />
Once imported, start the service from the toolbar (green triangle icon). The service should start successfully.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-59.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-59.png" alt="" width="604" height="291" class="aligncenter size-full wp-image-3409" /></a><br />
At this point we have to tell the domain controller that there is a new <strong>Enterprise CA</strong> in the environment. Log to the domain controller, and copy the file (ROOT-CERT-NO-PVT-KEY) from the <strong>Enterprise CA</strong>. I saved this file on the desktop on <strong>Enterprise CA</strong>, so do the same. Copy the file from the desktop of <strong>Enterprise CA</strong> to the desktop of the domain controller. On the domain controller, go to <strong>Control Panel</strong>, <strong>Administrative Tools</strong>, then <strong>Group Policy Management</strong>.<br />
Expand the GP to edit the default domain policy.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-60.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-60.png" alt="" width="747" height="549" class="aligncenter size-full wp-image-3410" /></a><br />
Right-click and <strong>Edit</strong>. Go to <strong>Computer Configuration</strong>, <strong>Policies</strong>, <strong>Windows Settings</strong>, <strong>Security Settings</strong>, <strong>Public Key Policies</strong> and <strong>Trusted Root Certification Authorities</strong>. Right click on it and choose <strong>Import</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-61.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-61.png" alt="" width="527" height="249" class="aligncenter size-full wp-image-3411" /></a><br />
Local machine is automatically selected.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-62.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-62.png" alt="" width="539" height="531" class="aligncenter size-full wp-image-3412" /></a><br />
Choose the certificate, the one without private key.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-63.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-63.png" alt="" width="625" height="508" class="aligncenter size-full wp-image-3413" /></a><br />
The <strong>Certificate Import Wizard</strong> will launch.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-64.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-64.png" alt="" width="540" height="524" class="aligncenter size-full wp-image-3414" /></a><br />
Make sure this is where the certificate will be stored.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-65.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-65.png" alt="" width="540" height="524" class="aligncenter size-full wp-image-3415" /></a><br />
Click <strong>Finish</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-66.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-66.png" alt="" width="537" height="519" class="aligncenter size-full wp-image-3416" /></a><br />
OK, what now? First, delete the files that you don’t need. The ones on the desktop of the <strong>Enterprise CA,</strong> the domain controller and the <strong>offline CA</strong>. and the request file on the c:\drive on the <strong>Enterprise CA</strong>. You can also shut down offline CA. it’s not needed for another 10 years.  </p>
<h1>IIS Windows Web Server</h1>
<p>OK, so we have the PKI in place, but let&#8217;s build an IIS web server that uses certificates, which means it will listen on port 443. This web server will be a member of a domain and the URL will be <strong>test1.empire.local</strong>. Users will access the site as https://site1.empire.local.<br />
Log in to the IIS server and install IIS. This server must be a member of the domain. From the <strong>Server Manager</strong> add the <strong>IIS </strong>role.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-67.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-67.png" alt="" width="771" height="563" class="aligncenter size-full wp-image-3430" /></a><br />
Create a folder called <strong>test1.empire.local</strong> under <strong>c:\inetpub\wwwroot</strong>. Create a text file called <strong>index.txt</strong> and type something.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-68.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-68.png" alt="" width="570" height="303" class="aligncenter size-full wp-image-3431" /></a><br />
Rename the <strong>index.txt</strong> as <strong>index.html</strong>.<br />
Start the <strong>Internet Information Services (IIS) Manager</strong> from <strong>Control Panel</strong>, <strong>Administrative Tools</strong> or click on Start then type <strong>inetmgr</strong>. Right-click on <strong>Sites </strong>and choose <strong>Add Website</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-69.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-69.png" alt="" width="355" height="314" class="aligncenter size-full wp-image-3432" /></a><br />
Configure it and click <strong>OK</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-70.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-70.png" alt="" width="589" height="572" class="aligncenter size-full wp-image-3433" /></a><br />
Once the site is started, make sure that you have the <strong>test1.empire.local</strong> in the DNS, so the client computers know that test1.empire.local resolves to an IP.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-71.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-71.png" alt="" width="1002" height="207" class="aligncenter size-full wp-image-3434" /></a><br />
From any machine that’s on the domain, go to http://test1.empire.local. Make sure it works.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-72.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-72.png" alt="" width="686" height="243" class="aligncenter size-full wp-image-3435" /></a><br />
Go back to the IIS server. Click on the IIS server name and double-click <strong>Server Certificates</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-73.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-73.png" alt="" width="563" height="440" class="aligncenter size-full wp-image-3436" /></a><br />
Click on <strong>Create Domain Certificate</strong> on the right side.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-79.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-79.png" alt="" width="296" height="279" class="aligncenter size-full wp-image-3438" /></a><br />
In the dialog box that shows up, fill out the values. The common name is the actual server name.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-74.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-74.png" alt="" width="668" height="515" class="aligncenter size-full wp-image-3439" /></a><br />
Click the <strong>Select </strong>button and specify our Enterprise CA. If you don&#8217;t see anything in the certification Authority box when you click Select, it means that the IIS server doesn&#8217;t know about the Enterprise CA because the default domain policy is not present. Try with <strong>gpforce /update</strong> first, to update the domain policy.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-75.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-75.png" alt="" width="667" height="520" class="aligncenter size-full wp-image-3442" /></a><br />
Click <strong>Finish</strong>.<br />
If everything goes according to the plan, you&#8217;ll see that you have your certificate issued.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-80.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-80.png" alt="" width="885" height="156" class="aligncenter size-full wp-image-3444" /></a><br />
Now, click on the actual web site that we created and click on <strong>Bindings </strong>on the right-side.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-76.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-76.png" alt="" width="908" height="422" class="aligncenter size-full wp-image-3445" /></a><br />
Click on <strong>Add </strong>button and fill out the values. Pretty much we are telling <strong>IIS </strong>that we want an SSL site that runs on port 443 with a certificate that we already got from the <strong>Enterprise CA</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-77.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-77.png" alt="" width="618" height="471" class="aligncenter size-full wp-image-3446" /></a><br />
Now, go back to any client on the network and browse to https://test1.empire.local. You&#8217;ll see this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-78.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-78.png" alt="" width="675" height="290" class="aligncenter size-full wp-image-3447" /></a><br />
If you click on the lock icon in the address bar, you&#8217;ll see that we got the certificates right.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-81.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-81.png" alt="" width="355" height="247" class="aligncenter size-full wp-image-3448" /></a></p>
<h1>Apache Web Server</h1>
<p>I&#8217;ll build a web server running Apache in the environment. I won&#8217;t go into details how to do that. Each flavor of Linux/*BSD has its own way of doing it. I&#8217;ll use AWS Linux which is based on Red Hat 6. It really doesn&#8217;t matter what you use, as long as you know how to configure Apache. Make sure you have the URL in the DNS, e.g. test2.empire.local to resolve to some IP.<br />
For instructions on how to configure Apache on AWS/RHEL6/CentOS 6, you can check my <a href="https://blog.andreev.it/?p=1010" rel="noopener noreferrer" target="_blank">post</a>. For RHEL 7/CentOS chek this <a href="https://blog.andreev.it/?p=1962" rel="noopener noreferrer" target="_blank">link </a>and for FreeBSD use this <a href="https://blog.andreev.it/?p=1309" rel="noopener noreferrer" target="_blank">one</a>.<br />
First, we have to generate the private key for the server. I&#8217;ll put it under <strong>/etc/certs</strong> directory.Do this by typing:</p>
<pre class="brush: bash; title: ; notranslate">
mkdir /etc/certs
cd /etc/certs
openssl genrsa -out test2.empire.local.key 2048
</pre>
<p>Then we&#8217;ll generate a request file that the Enterprise CA will have to sign. </p>
<pre class="brush: bash; title: ; notranslate">
openssl req -new -key test2.empire.local.key -out test2.empire.local.csr
</pre>
<p>You&#8217;ll be prompted to fill out the blanks, similarly with what we did with the IIS server.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-82.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-82.png" alt="" width="554" height="194" class="aligncenter size-full wp-image-7924" /></a><br />
Remember, common name is the name of your server URL.<br />
Once you execute these two commands, you&#8217;ll have two files under /etc/certs. The private key and the the certificate signing request (.csr extension means that).<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-83.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-83.png" alt="" width="475" height="75" class="aligncenter size-full wp-image-7925" /></a><br />
The<strong> Enterprise CA</strong> will have to sign the request file and issue a certificate.<br />
Issuing this certificate is a little bit different. Go to the <strong>Enterprise CA</strong> and using a browser go to http://localhost/certsrv.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-84.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-84.png" alt="" width="786" height="455" class="aligncenter size-full wp-image-7926" /></a><br />
Click on <strong>Request a certificate</strong>. Then click on <strong>advanced certificate request</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-85.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-85.png" alt="" width="773" height="242" class="aligncenter size-full wp-image-7927" /></a><br />
Click on the second line,<strong> Submit a certificate&#8230;</strong><br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-86.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-86.png" alt="" width="757" height="322" class="aligncenter size-full wp-image-7928" /></a><br />
On the Linux/BSD server, open up the csr file under <strong>/etc/certs</strong> with your favorite editor (vi, nano, vim). It&#8217;s just a text file.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-87.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-87.png" alt="" width="500" height="312" class="aligncenter size-full wp-image-7929" /></a><br />
Select the text, copy it to the clipboard and paste it under <strong>Saved Request</strong> field.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-88.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-88.png" alt="" width="877" height="703" class="aligncenter size-full wp-image-7930" /></a><br />
For the <strong>Certificate Template</strong>, choose the <strong>Subordinate Certification Authority</strong> and click <strong>Submit</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-89.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-89.png" alt="" width="541" height="297" class="aligncenter size-full wp-image-7931" /></a><br />
Select <strong>Base 64 encoded</strong> and then you can download the certificate or the certificate chain by clicking the link. In my case, I&#8217;ll download the certificate only.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-90.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-90.png" alt="" width="675" height="300" class="aligncenter size-full wp-image-7932" /></a><br />
Save the file somewhere on the desktop (delete after use), edit it with notepad, select all and copy. This is how it looks like.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-91.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-91.png" alt="" width="601" height="629" class="aligncenter size-full wp-image-7933" /></a><br />
Go back to your Linux/BSD server and edit a new file under <strong>/etc/certs</strong>. I&#8217;ll name my file test2.empire.local.crt, so I know that this is a server certificate. Paste the text from notepad and save it. Edit the httpd.conf or httpd-vhosts.conf or whatever file you have for your web server and create an entry for your web site. In my case it looks like this.</p>
<pre class="brush: bash; title: ; notranslate">
&lt;VirtualHost *:443&gt;
    SSLEngine on
    SSLCertificateFile /etc/certs/test2.empire.local.crt
    SSLCertificateKeyFile /etc/certs/test2.empire.local.key
    ServerAdmin darth.vader@empire.local
    DocumentRoot /var/www/test2.empire.local
    ServerName test2.empire.local
    ErrorLog logs/test2.empire.local-error_log
    CustomLog logs/test2.empire.local-access_log common
&lt;/VirtualHost&gt;
</pre>
<p>Go to the root of your web site, in my case it&#8217;s <strong>/var/www/test2.empire.local</strong> and create an <strong>index.html</strong> (not .htm) file with something in it.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-92.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-92.png" alt="" width="409" height="93" class="aligncenter size-full wp-image-7934" /></a><br />
Finally, go to https://test2.empire.local and you should see the site.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2017/12/P094-93.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2017/12/P094-93.png" alt="" width="586" height="153" class="aligncenter size-full wp-image-7935" /></a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2017/12/117-windows-enterprise-pki-windows-2016/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AWS: Install Command Line Interface (CLI)</title>
		<link>https://blog.andreev.it/2015/03/amazon-aws-command-line-interface/</link>
					<comments>https://blog.andreev.it/2015/03/amazon-aws-command-line-interface/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Tue, 10 Mar 2015 13:26:55 +0000</pubDate>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[AWS CLI]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=1905</guid>

					<description><![CDATA[In this post I&#8217;ll explain how to install and use AWS CLI. It will&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>In this post I&#8217;ll explain how to install and use AWS CLI. It will be a basic document that will be referred in the following posts. We&#8217;ll cover installation on Windows, FreeBSD 10.1 and CentOS 7.0. The installation and basic use is trivial.</p>
<h1>Windows</h1>
<p>Go to AWS CLI <a href="http://aws.amazon.com/cli/" target="_blank" rel="noopener noreferrer">home-page</a> and download your 64-bit or 32-bit version. Double-click the installer and follow up the prompts. I wanted to do some screenshots, but it&#8217;s not worth it. Three time click <strong>Next</strong>, once <strong>Install</strong>, <strong>Finish</strong> and you are done. Open a command prompt and type <strong>aws</strong>. If you see this, you are all set. </p>
<pre class="brush: bash; title: ; notranslate">
C:\windows\system32&gt;aws
usage: aws &#x5B;options] &lt;command&gt; &lt;subcommand&gt; &#x5B;parameters]
aws: error: too few arguments
</pre>
<h1>FreeBSD</h1>
<p>The aws cli relies on Python, so if you have Python 2.7 installed, do:</p>
<pre class="brush: bash; title: ; notranslate">
pkg install py27-pip
</pre>
<p>If you don&#8217;t have Python installed, use the same command. It will download and install Python 2.7 for you.<br />
If you have a different version, you might want to use the sources.<br />
Then, install aws cli.</p>
<pre class="brush: bash; title: ; notranslate">
pip install awscli
</pre>
<h1>CentOS</h1>
<p>Same thing, aws relies on Python. CentOS 7 comes with Python installed. Install <strong>pip</strong> first.</p>
<pre class="brush: bash; title: ; notranslate">
yum install wget
wget https://bootstrap.pypa.io/get-pip.py
python get-pip.py
pip install awscli
</pre>
<h1>AWS</h1>
<p>Log on to AWS Console and click on <strong>Identity &#038; Access Management.<br />
</strong><br />
<a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-01.png" alt="" width="572" height="235" class="aligncenter size-full wp-image-7271" /></a></p>
<p>Click on <strong>Users</strong> and then <strong>Create New Users</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-02.png" alt="" width="528" height="245" class="aligncenter size-full wp-image-7272" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-02.png 528w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-02-300x139.png 300w" sizes="(max-width: 528px) 100vw, 528px" /></a></p>
<p>Type the username of the first user and make sure that the check mark at the bottom is checked.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-03.png" alt="" width="1087" height="413" class="aligncenter size-full wp-image-7273" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-03.png 1087w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-03-300x114.png 300w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-03-1024x389.png 1024w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-03-768x292.png 768w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-03-585x222.png 585w" sizes="(max-width: 1087px) 100vw, 1087px" /></a></p>
<p>Click on <strong>Download Credentials</strong> and store them somewhere safe. If you lose this file or forget your credentials, you can regenerate the access keys, by selecting the user, clicking on <strong>User Actions</strong> and then <strong>Manage Access Keys</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-04.png" alt="" width="590" height="273" class="aligncenter size-full wp-image-7274" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-04.png 590w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-04-300x139.png 300w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-04-585x271.png 585w" sizes="(max-width: 590px) 100vw, 590px" /></a></p>
<p>Now that you have the credentials file downloaded, which is a simple text file, do the following.</p>
<pre class="brush: bash; title: ; notranslate">
aws configure
</pre>
<p>Enter your <strong>Access Key Id</strong>, <strong>Secret Access Key</strong>, <strong>Default Region Name</strong> and the <strong>Default output format</strong> (text, table, JSON).<br />
<a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-05.png" alt="" width="682" height="309" class="aligncenter size-full wp-image-7275" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-05.png 682w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-05-300x136.png 300w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-05-585x265.png 585w" sizes="(max-width: 682px) 100vw, 682px" /></a><br />
Don&#8217;t share these keys with anyone. The keys that I am using are for test use, they are gone by now. </p>
<p>Test the CLI.</p>
<pre class="brush: bash; title: ; notranslate">
c:\&gt;aws ec2 describe-instances
</pre>
<p>You should receive this.</p>
<pre class="brush: plain; title: ; notranslate">
A client error (UnauthorizedOperation) occurred when calling the DescribeInstances operation: 
You are not authorized to perform this operation.
</pre>
<p>Go back to the AWS console and back to <strong>IAM</strong> menu (Identity and Access Management). Create a new group called Admins or whatever you like.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-06.png" alt="" width="560" height="271" class="aligncenter size-full wp-image-7278" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-06.png 560w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-06-300x145.png 300w" sizes="(max-width: 560px) 100vw, 560px" /></a></p>
<p>Attach a Policy. In my case, I&#8217;ve selected the top option, thus giving the user full admin rights. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-07.png" alt="" width="1241" height="618" class="aligncenter size-full wp-image-7279" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-07.png 1241w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-07-300x149.png 300w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-07-1024x510.png 1024w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-07-768x382.png 768w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-07-1170x583.png 1170w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-07-585x291.png 585w" sizes="(max-width: 1241px) 100vw, 1241px" /></a></p>
<p>Go back to the <strong>Users</strong>, select the user, click on <strong>User Action</strong> and click <strong>Add User to Groups</strong>. Add the user to the group you&#8217;ve just created.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-08.png" alt="" width="613" height="345" class="aligncenter size-full wp-image-7276" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-08.png 613w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-08-300x169.png 300w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-08-585x329.png 585w" sizes="(max-width: 613px) 100vw, 613px" /></a></p>
<p>Test the CLI again.</p>
<pre class="brush: bash; title: ; notranslate">
c:\&gt;aws ec2 describe-instances
</pre>
<p>You should see all of your instances, if any.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2015/03/P052-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2015/03/P052-09.png" alt="" width="645" height="326" class="aligncenter size-full wp-image-7277" srcset="https://blog.andreev.it/wp-content/uploads/2015/03/P052-09.png 645w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-09-300x152.png 300w, https://blog.andreev.it/wp-content/uploads/2015/03/P052-09-585x296.png 585w" sizes="(max-width: 645px) 100vw, 645px" /></a></p>
<p>The default credentials are stored under <strong>%UserProfile%\.aws </strong>under Windows and <strong>~/.aws </strong>under Linux/FreeBSD.</p>
<h1>Proxy</h1>
<p>If you are behind a firewall and/or you are using proxy, make sure that port 443 (https) is opened. Amazon AWS CLI uses port 443 to execute API calls on the backend. See this <a href="http://docs.aws.amazon.com/cli/latest/userguide/cli-http-proxy.html" target="_blank" rel="noopener noreferrer">page </a>for more details and how to configure proxy.<br />
If you are using FreeBSD and csh/tcsh shell use <strong>setenv </strong>instead of <strong>export</strong>.</p>
<pre class="brush: bash; title: ; notranslate">
setenv HTTP_PROXY http://your-proxy-name-or-IP:your-proxy-port
</pre>
<p> or</p>
<pre class="brush: bash; title: ; notranslate">
setenv HTTPS_PROXY http://your-proxy-name-or-IP:your-proxy-port
</pre>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2015/03/amazon-aws-command-line-interface/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ESX/ESXi: Enable sound (audio) in a VM for use in a RDP session</title>
		<link>https://blog.andreev.it/2014/01/enable-sound-audio-in-a-vm-for-use-in-a-rdp-session/</link>
					<comments>https://blog.andreev.it/2014/01/enable-sound-audio-in-a-vm-for-use-in-a-rdp-session/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Sun, 19 Jan 2014 00:36:42 +0000</pubDate>
				<category><![CDATA[ESX/ESXi]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[audio]]></category>
		<category><![CDATA[RDP]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=1224</guid>

					<description><![CDATA[I manage a terminal server that Service Desk is using to access some applications&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>I manage a terminal server that Service Desk is using to access some applications using <strong>RDP</strong> client. Recently, they needed audio enabled. These steps will help accomplish that goal . </p>
<p>First, log to the server and make sure that <strong>Windows Audio</strong> service is set to start as <strong>Automatic</strong> instead of <strong>Manual</strong>. Then, start the service. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P039-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P039-01.png" alt="" width="520" height="86" class="aligncenter size-full wp-image-6982" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P039-01.png 520w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-01-300x50.png 300w" sizes="(max-width: 520px) 100vw, 520px" /></a><br />
Go to <strong>Administrative Tools</strong>, <strong>Remote Desktop</strong> and start the <strong>Remote Desktop Session Host Configuration</strong>.  Select the <strong>RDP</strong> connection, right-click and choose <strong>Properties</strong>. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P039-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P039-02.png" alt="" width="616" height="283" class="aligncenter size-full wp-image-6983" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P039-02.png 616w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-02-300x138.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-02-585x269.png 585w" sizes="(max-width: 616px) 100vw, 616px" /></a><br />
In the dialog box, select <strong>Client Settings</strong> and uncheck <strong>Audio and Video Playback</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P039-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P039-03.png" alt="" width="397" height="494" class="aligncenter size-full wp-image-6984" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P039-03.png 397w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-03-241x300.png 241w" sizes="(max-width: 397px) 100vw, 397px" /></a></p>
<p>You&#8217;ll get a message that you have to log off and log back on for these changes to take effect. </p>
<p>Also, make sure that you don&#8217;t inherit any domain policies that prevent the <strong>RDP</strong> audio settings. Click <strong>Start</strong>, <strong>Run</strong> and type:</p>
<pre class="brush: bash; title: ; notranslate">
gpedit.msc
</pre>
<p>Navigate to <strong>Computer Configuration | Administrative Templates | Windows Components | Remote Desktop Services | Remote Desktop Session Host | Device and Resource Configuration</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P039-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P039-04.png" alt="" width="715" height="255" class="aligncenter size-full wp-image-6985" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P039-04.png 715w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-04-300x107.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-04-585x209.png 585w" sizes="(max-width: 715px) 100vw, 715px" /></a></p>
<p>If it says <strong>Not Configured</strong> or <strong>Enabled</strong>, it&#8217;s fine. If it says <strong>Disabled</strong>, you&#8217;ll have to modify the domain <strong>GPO</strong>.</p>
<p>Finally, on the client computers, make sure that the <strong>RDP</strong> client is set to play the audio on the remote machine and not on the server.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P039-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P039-05.png" alt="" width="739" height="474" class="aligncenter size-full wp-image-6986" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P039-05.png 739w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-05-300x192.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P039-05-585x375.png 585w" sizes="(max-width: 739px) 100vw, 739px" /></a></p>
<p>Sources:</p>
<p><a href="http://technet.microsoft.com/en-us/library/cc770631.aspx" target="_blank" rel="noopener noreferrer">http://technet.microsoft.com/en-us/library/cc770631.aspx</a><br />
<a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&#038;cmd=displayKC&#038;externalId=1004839" target="_blank" rel="noopener noreferrer">http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&#038;cmd=displayKC&#038;externalId=1004839</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2014/01/enable-sound-audio-in-a-vm-for-use-in-a-rdp-session/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ESX/ESXi: Upgrade from vCenter 5.0 to 5.1</title>
		<link>https://blog.andreev.it/2014/01/vsphere-upgrade-from-5-0-to-5-1/</link>
					<comments>https://blog.andreev.it/2014/01/vsphere-upgrade-from-5-0-to-5-1/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Fri, 17 Jan 2014 21:35:43 +0000</pubDate>
				<category><![CDATA[ESX/ESXi]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[vCenter]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=1175</guid>

					<description><![CDATA[In my previous post, I&#8217;ve explained how to install vCenter 5.0. In this post,&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>In my <a href="http://blog.andreev.it/?p=1035" title="Install vCenter 5.0" target="_blank" rel="noopener noreferrer">previous post</a>, I&#8217;ve explained how to install vCenter 5.0. In this post, I&#8217;ll explain how to upgrade from 5.0 to 5.1. This version brings a new authentication <strong>Single Sign On</strong> mechanism and a new web client. Check the VMware web site for more information about these new products and features. </p>
<p>First, start <strong>SQL Server Management Studio </strong>and open the sql script that comes on the vCenter installation media. <strong>Single Sign On</strong> requires a separate database. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-01.png" alt="" width="406" height="220" class="aligncenter size-full wp-image-6930" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-01.png 406w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-01-300x163.png 300w" sizes="(max-width: 406px) 100vw, 406px" /></a></p>
<p>Open <strong>rsaIMSLiteMSSQLSetupTablespaces</strong> and change the file paths to suit your needs. There are three occurrences of this file path.  I used <strong>C:\DATA</strong> in my case. Click Execute and make sure you get a message that the commands completed successfully.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-02.png" alt="" width="614" height="393" class="aligncenter size-full wp-image-6931" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-02.png 614w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-02-300x192.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-02-585x374.png 585w" sizes="(max-width: 614px) 100vw, 614px" /></a><br />
Click on <strong>Security</strong>, then <strong>Logins</strong> and double-click the <strong>vpxuser</strong>. This is the same user that has full <strong>db_owner </strong>rights on the vCenter and Update Manager databases. Select <strong>User Mapping</strong>, <strong>RSA</strong> (<strong>Single Sign On</strong> database) and click <strong>db_owner</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-03.png" alt="" width="618" height="514" class="aligncenter size-full wp-image-6932" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-03.png 618w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-03-300x250.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-03-585x487.png 585w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<p>Now start the vCenter installer and select <strong>vCenter Single Sign On</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-04.png" alt="" width="507" height="225" class="aligncenter size-full wp-image-6933" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-04.png 507w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-04-300x133.png 300w" sizes="(max-width: 507px) 100vw, 507px" /></a></p>
<p>Click Next.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-05.png" alt="" width="504" height="378" class="aligncenter size-full wp-image-6934" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-05.png 504w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-05-300x225.png 300w" sizes="(max-width: 504px) 100vw, 504px" /></a></p>
<p>Create the <strong>primary node</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-06.png" alt="" width="502" height="369" class="aligncenter size-full wp-image-6935" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-06.png 502w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-06-300x221.png 300w" sizes="(max-width: 502px) 100vw, 502px" /></a></p>
<p>Select the first option.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-07.png" alt="" width="497" height="368" class="aligncenter size-full wp-image-6936" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-07.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-07-300x222.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>Enter a password for the <strong>admin@System-Domain</strong> user. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-08.png" alt="" width="498" height="369" class="aligncenter size-full wp-image-6937" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-08.png 498w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-08-300x222.png 300w" sizes="(max-width: 498px) 100vw, 498px" /></a></p>
<p>Select the second option.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-09.png" alt="" width="493" height="371" class="aligncenter size-full wp-image-6938" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-09.png 493w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-09-300x226.png 300w" sizes="(max-width: 493px) 100vw, 493px" /></a></p>
<p>Type <strong>RSA</strong> for the database name, the hostname of the SQL server, <strong>vpxuser</strong> for the database user and its password.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-10.png" alt="" width="499" height="370" class="aligncenter size-full wp-image-6939" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-10.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-10-300x222.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a></p>
<p>Confirm that your vCenter server is listed here.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-11.png" alt="" width="498" height="376" class="aligncenter size-full wp-image-6940" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-11.png 498w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-11-300x227.png 300w" sizes="(max-width: 498px) 100vw, 498px" /></a></p>
<p>Use the defaults.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-12.png" alt="" width="495" height="371" class="aligncenter size-full wp-image-6941" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-12.png 495w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-12-300x225.png 300w" sizes="(max-width: 495px) 100vw, 495px" /></a></p>
<p>Change or accept the defaults. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-13.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-13.png" alt="" width="507" height="371" class="aligncenter size-full wp-image-6942" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-13.png 507w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-13-300x220.png 300w" sizes="(max-width: 507px) 100vw, 507px" /></a></p>
<p>Change or accept the defaults. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-14.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-14.png" alt="" width="504" height="368" class="aligncenter size-full wp-image-6943" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-14.png 504w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-14-300x219.png 300w" sizes="(max-width: 504px) 100vw, 504px" /></a></p>
<p>Click <strong>Finish</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-15.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-15.png" alt="" width="497" height="369" class="aligncenter size-full wp-image-6944" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-15.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-15-300x223.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>Next, we&#8217;ll have to upgrade <strong>vCenter Inventory Service</strong>. From the same menu where we launched the <strong>Single Sign On </strong>install, click on <strong>vCenter Inventory Service</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-16.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-16.png" alt="" width="497" height="366" class="aligncenter size-full wp-image-6945" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-16.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-16-300x221.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>Choose the first option.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-17.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-17.png" alt="" width="494" height="378" class="aligncenter size-full wp-image-6946" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-17.png 494w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-17-300x230.png 300w" sizes="(max-width: 494px) 100vw, 494px" /></a><br />
Verify that you have the vCenter server name correct.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-18.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-18.png" alt="" width="511" height="372" class="aligncenter size-full wp-image-6947" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-18.png 511w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-18-300x218.png 300w" sizes="(max-width: 511px) 100vw, 511px" /></a><br />
Change or accept the defaults.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-19.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-19.png" alt="" width="499" height="371" class="aligncenter size-full wp-image-6948" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-19.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-19-300x223.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a></p>
<p>Change or accept the defaults.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-20.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-20.png" alt="" width="502" height="370" class="aligncenter size-full wp-image-6949" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-20.png 502w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-20-300x221.png 300w" sizes="(max-width: 502px) 100vw, 502px" /></a></p>
<p>Enter the password for the <strong>admin@System-Domain</strong> user. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-21.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-21.png" alt="" width="489" height="371" class="aligncenter size-full wp-image-6950" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-21.png 489w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-21-300x228.png 300w" sizes="(max-width: 489px) 100vw, 489px" /></a></p>
<p>Click <strong>Install certificates</strong>. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-22.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-22.png" alt="" width="492" height="373" class="aligncenter size-full wp-image-6951" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-22.png 492w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-22-300x227.png 300w" sizes="(max-width: 492px) 100vw, 492px" /></a><br />
Click <strong>Finish</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-23.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-23.png" alt="" width="491" height="370" class="aligncenter size-full wp-image-6952" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-23.png 491w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-23-300x226.png 300w" sizes="(max-width: 491px) 100vw, 491px" /></a></p>
<p>Next, upgrade vCenter. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-24.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-24.png" alt="" width="501" height="370" class="aligncenter size-full wp-image-6953" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-24.png 501w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-24-300x222.png 300w" sizes="(max-width: 501px) 100vw, 501px" /></a></p>
<p>Enter the password for the <strong>vpxuser</strong>. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-25.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-25.png" alt="" width="500" height="371" class="aligncenter size-full wp-image-6954" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-25.png 500w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-25-300x223.png 300w" sizes="(max-width: 500px) 100vw, 500px" /></a></p>
<p>Upgrade the database. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-26.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-26.png" alt="" width="497" height="368" class="aligncenter size-full wp-image-6955" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-26.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-26-300x222.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>Select the first option.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-27.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-27.png" alt="" width="495" height="375" class="aligncenter size-full wp-image-6956" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-27.png 495w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-27-300x227.png 300w" sizes="(max-width: 495px) 100vw, 495px" /></a></p>
<p>Choose if you want to use a domain account, local account or system account.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-28.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-28.png" alt="" width="494" height="366" class="aligncenter size-full wp-image-6957" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-28.png 494w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-28-300x222.png 300w" sizes="(max-width: 494px) 100vw, 494px" /></a></p>
<p>Change or accept the defaults.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-29.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-29.png" alt="" width="503" height="376" class="aligncenter size-full wp-image-6958" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-29.png 503w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-29-300x224.png 300w" sizes="(max-width: 503px) 100vw, 503px" /></a></p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-30.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-30.png" alt="" width="499" height="371" class="aligncenter size-full wp-image-6959" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-30.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-30-300x223.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a></p>
<p>Enter the password for the <strong>Single Sign On </strong>admin user. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-31.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-31.png" alt="" width="504" height="382" class="aligncenter size-full wp-image-6960" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-31.png 504w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-31-300x227.png 300w" sizes="(max-width: 504px) 100vw, 504px" /></a></p>
<p>Use this log file if you have any issues later. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-32.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-32.png" alt="" width="410" height="175" class="aligncenter size-full wp-image-6961" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-32.png 410w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-32-300x128.png 300w" sizes="(max-width: 410px) 100vw, 410px" /></a></p>
<p>Click <strong>Finish</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-33.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-33.png" alt="" width="490" height="371" class="aligncenter size-full wp-image-6962" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-33.png 490w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-33-300x227.png 300w" sizes="(max-width: 490px) 100vw, 490px" /></a></p>
<p>Next, we&#8217;ll upgrade the <strong>Update Manager</strong>. Start the installation.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-34.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-34.png" alt="" width="419" height="149" class="aligncenter size-full wp-image-6963" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-34.png 419w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-34-300x107.png 300w" sizes="(max-width: 419px) 100vw, 419px" /></a></p>
<p>Accept the default option.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-35.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-35.png" alt="" width="493" height="372" class="aligncenter size-full wp-image-6964" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-35.png 493w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-35-300x226.png 300w" sizes="(max-width: 493px) 100vw, 493px" /></a></p>
<p>Enter the credentials that were used to run the <strong>Update Manager </strong>service.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-36.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-36.png" alt="" width="498" height="372" class="aligncenter size-full wp-image-6965" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-36.png 498w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-36-300x224.png 300w" sizes="(max-width: 498px) 100vw, 498px" /></a></p>
<p>Enter the credentials for the <strong>vpxuser</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-37.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-37.png" alt="" width="499" height="378" class="aligncenter size-full wp-image-6966" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-37.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-37-300x227.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a><br />
Upgrade the dabase. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-38.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-38.png" alt="" width="499" height="374" class="aligncenter size-full wp-image-6967" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-38.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-38-300x225.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a></p>
<p>Change or accept the defaults. Make sure the vCenter server correctly appears. Click <strong>Finish</strong> at the end.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-39.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-39.png" alt="" width="501" height="374" class="aligncenter size-full wp-image-6968" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-39.png 501w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-39-300x224.png 300w" sizes="(max-width: 501px) 100vw, 501px" /></a><br />
Finally, let&#8217;s update the web client. You can run the installer from the media or you can just double-click the old client and this message will show up, prompting you to run or save the installer. Just click Run. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-40.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-40.png" alt="" width="389" height="172" class="aligncenter size-full wp-image-6969" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-40.png 389w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-40-300x133.png 300w" sizes="(max-width: 389px) 100vw, 389px" /></a></p>
<p>Change or accept the defaults.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-41.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-41.png" alt="" width="499" height="374" class="aligncenter size-full wp-image-6970" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-41.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-41-300x225.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a></p>
<p>Enter the password for the <strong>Single Sign On </strong>admin user.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-42.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-42.png" alt="" width="502" height="369" class="aligncenter size-full wp-image-6971" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-42.png 502w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-42-300x221.png 300w" sizes="(max-width: 502px) 100vw, 502px" /></a></p>
<p>If you try to use your Windows domain credentials, you&#8217;ll have to download the <strong>Client Integration Plug-In</strong> first. And, that&#8217;s it.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P38-43.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P38-43.png" alt="" width="489" height="433" class="aligncenter size-full wp-image-6972" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P38-43.png 489w, https://blog.andreev.it/wp-content/uploads/2014/01/P38-43-300x266.png 300w" sizes="(max-width: 489px) 100vw, 489px" /></a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2014/01/vsphere-upgrade-from-5-0-to-5-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ESX/ESXi: Install vCenter 5.0</title>
		<link>https://blog.andreev.it/2014/01/install-vcenter-5-0/</link>
					<comments>https://blog.andreev.it/2014/01/install-vcenter-5-0/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Sun, 12 Jan 2014 02:19:57 +0000</pubDate>
				<category><![CDATA[ESX/ESXi]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[vCenter]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=1035</guid>

					<description><![CDATA[In this post I&#8217;ll describe how I installed vCenter 5.0 on Windows 2008 R2&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>In this post I&#8217;ll describe how I installed <strong>vCenter 5.0</strong> on Windows 2008 R2 server using SQL 2008 R2 database. I&#8217;ve used two servers in my lab, one for the vCenter and the other one for the SQL. I won&#8217;t explain how to install SQL server, it&#8217;s fairly straightforward. </p>
<p>First thing to do is to create the SQL database. VMware provides a SQL script that you can execute to create the database. The script is on the vCenter installation DVD/ISO under <strong>source\vCenter-Server\dbschema</strong> folder where source is some drive letter (D:\ or E:\). This script does not work right, so we&#8217;ll use a modified version. By default, <strong>vCenter</strong> requires full <strong>db_owner</strong> rights so it can create some scheduled jobs. If your environment doesn’t allow this type of access, see the installation guide for vCenter. In this post, we’ll grant full <strong>db_owner</strong> rights for the sql user (<strong>vpxuser</strong>) to both vCenter database (<strong>VCDB</strong>) and the <strong>msdb</strong> system database. Once <strong>vCenter</strong> is up and running, you can remove the full <strong>db_owner</strong> rights from the msdb. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-01.png" alt="" width="561" height="305" class="aligncenter size-full wp-image-6872" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-01.png 561w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-01-300x163.png 300w" sizes="(max-width: 561px) 100vw, 561px" /></a></p>
<p>Start the <strong>SQL Server Management Studio</strong>, log as the <strong><em>sa</em></strong> user or some domain user with full SQL admin rights, and click <strong>New Query</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-02.png" alt="" width="525" height="251" class="aligncenter size-full wp-image-6873" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-02.png 525w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-02-300x143.png 300w" sizes="(max-width: 525px) 100vw, 525px" /></a></p>
<p>Copy and paste the following script, but change the file path where you want your database to reside. In my case it is <strong>C:\DATA</strong>. Also, change the password for the <strong>vpxuser</strong> that we will create. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-03.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-03.png" alt="" width="562" height="411" class="aligncenter size-full wp-image-6874" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-03.png 562w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-03-300x219.png 300w" sizes="(max-width: 562px) 100vw, 562px" /></a></p>
<pre class="brush: sql; title: ; notranslate">
use &#x5B;master]
go
CREATE DATABASE &#x5B;VCDB] ON PRIMARY
(NAME = N'vcdb', FILENAME = N'C:\DATA\VCDB.mdf', SIZE = 2000KB, FILEGROWTH = 10% )
LOG ON
(NAME = N'vcdb_log', FILENAME = N'C:\DATA\VCDB.ldf', SIZE = 1000KB, FILEGROWTH = 10%)
COLLATE SQL_Latin1_General_CP1_CI_AS
go
use VCDB
go
sp_addlogin @loginame=&#x5B;vpxuser], @passwd=N'vpxuserpassword', @defdb='VCDB',
@deflanguage='us_english'
go
ALTER LOGIN &#x5B;vpxuser] WITH CHECK_POLICY = OFF
go
CREATE USER &#x5B;vpxuser] for LOGIN &#x5B;vpxuser]
go
</pre>
<p>While in <strong>SQL Server Management Studio</strong>, expand the <strong>Security</strong>, then <strong>Logins</strong>. Double-click on the <strong>vpxuser</strong> and choose <strong>User Mapping</strong>. Select the <strong>VCDB</strong> database and put a check mark for <strong>db_owner</strong>. Put a check mark on the <strong>msdb</strong> database and do the same (check mark on <strong>db_owner</strong>).<br />
 <a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-04.png" alt="" width="874" height="470" class="aligncenter size-full wp-image-6875" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-04.png 874w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-04-300x161.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-04-768x413.png 768w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-04-585x315.png 585w" sizes="(max-width: 874px) 100vw, 874px" /></a></p>
<p>Next thing to do is to install the <strong>SQL Server Native Client</strong> on the vCenter server. It’s a free download from <a href="http://www.microsoft.com/en-us/download/details.aspx?id=16978" title="Click here to download SQL Native Client" target="_blank" rel="noopener noreferrer">Microsoft</a>. Once installed, go to <strong>Administrative Tools | Data Sources (ODBC)</strong>. Click on <strong>System DSN</strong> tab and then click <strong>Add</strong>. You should see a <strong>SQL Server Native Client 10.0</strong> driver there. Do not use <strong>SQL Server</strong> driver. It won&#8217;t work.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-05.png" alt="" width="575" height="462" class="aligncenter size-full wp-image-6876" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-05.png 575w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-05-300x241.png 300w" sizes="(max-width: 575px) 100vw, 575px" /></a></p>
<p>Enter the name for the <strong>ODBC</strong> connection, a description and type the hostname for the SQL server. In my case, I&#8217;ll use <strong>vCenter, vCenter Database</strong> and <strong>sql</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-06.png" alt="" width="497" height="379" class="aligncenter size-full wp-image-6877" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-06.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-06-300x229.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>Next, choose <strong>SQL authentication</strong> and type the SQL user that we just created with the script (<strong>vpxuser</strong> and its password).<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-07.png" alt="" width="505" height="380" class="aligncenter size-full wp-image-6878" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-07.png 505w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-07-300x226.png 300w" sizes="(max-width: 505px) 100vw, 505px" /></a></p>
<p>Click the first check mark and select the <strong>VCDB</strong> database.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-08.png" alt="" width="511" height="384" class="aligncenter size-full wp-image-6879" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-08.png 511w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-08-300x225.png 300w" sizes="(max-width: 511px) 100vw, 511px" /></a></p>
<p>Leave the defaults and click <strong>Finish</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-09.png" alt="" width="495" height="370" class="aligncenter size-full wp-image-6880" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-09.png 495w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-09-300x224.png 300w" sizes="(max-width: 495px) 100vw, 495px" /></a></p>
<p>Click the <strong>Test Data Source</strong> button and make sure that it says that the connection completed successfully.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-10.png" alt="" width="357" height="366" class="aligncenter size-full wp-image-6881" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-10.png 357w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-10-293x300.png 293w" sizes="(max-width: 357px) 100vw, 357px" /></a></p>
<p>Now, it&#8217;s time to install <strong>vCenter</strong>. Insert the DVD or mount the ISO image and the installer will start.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-11.png" alt="" width="686" height="502" class="aligncenter size-full wp-image-6882" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-11.png 686w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-11-300x220.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-11-585x428.png 585w" sizes="(max-width: 686px) 100vw, 686px" /></a></p>
<p>Click the first option <strong>vCenter server</strong> and go thru the Next, Accept cycle. Once you reach the <strong>Database Options</strong>, select the second radio button and choose the ODBC connection that we just created.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-12.png" alt="" width="499" height="370" class="aligncenter size-full wp-image-6883" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-12.png 499w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-12-300x222.png 300w" sizes="(max-width: 499px) 100vw, 499px" /></a></p>
<p>If you get this error, make sure you start the <strong>SQL Server Agent</strong> on the SQL server. By default this service is disabled. You can stop this service once the installation completes.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-13.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-13.png" alt="" width="381" height="154" class="aligncenter size-full wp-image-6884" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-13.png 381w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-13-300x121.png 300w" sizes="(max-width: 381px) 100vw, 381px" /></a></p>
<p>Enter the SQL username and password that we just created.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-14.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-14.png" alt="" width="497" height="366" class="aligncenter size-full wp-image-6885" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-14.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-14-300x221.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>If you receive the following error, it means that you are not a <strong>db_owner</strong> on the <strong>VCDB</strong> database.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-15.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-15.png" alt="" width="405" height="319" class="aligncenter size-full wp-image-6886" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-15.png 405w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-15-300x236.png 300w" sizes="(max-width: 405px) 100vw, 405px" /></a></p>
<p>You won&#8217;t be able to continue until you fix this. When you reach this screen <strong>vCenter Server Service</strong>, stop. You have an option to run the <strong>vCenter Server</strong> service as a local server account or you can choose a domain account. If you use a domain account, it should be a local admin on the server.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-16.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-16.png" alt="" width="497" height="371" class="aligncenter size-full wp-image-6887" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-16.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-16-300x224.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>Change or accept the defaults for the <strong>vCenter</strong> program.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-17.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-17.png" alt="" width="503" height="377" class="aligncenter size-full wp-image-6888" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-17.png 503w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-17-300x225.png 300w" sizes="(max-width: 503px) 100vw, 503px" /></a><br />
Select the first option.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-18.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-18.png" alt="" width="498" height="374" class="aligncenter size-full wp-image-6889" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-18.png 498w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-18-300x225.png 300w" sizes="(max-width: 498px) 100vw, 498px" /></a></p>
<p>Change or accept the default ports. If you install <strong>vCenter</strong> on a shared server with <strong>IIS</strong> installed, you&#8217;ll have port conflicts here.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-19.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-19.png" alt="" width="485" height="374" class="aligncenter size-full wp-image-6890" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-19.png 485w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-19-300x231.png 300w" sizes="(max-width: 485px) 100vw, 485px" /></a><br />
Change or accept the default ports for the <strong>Inventory Service</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-20.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-20.png" alt="" width="500" height="371" class="aligncenter size-full wp-image-6891" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-20.png 500w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-20-300x223.png 300w" sizes="(max-width: 500px) 100vw, 500px" /></a><br />
Estimate how many VMs you&#8217;ll have.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-21.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-21.png" alt="" width="501" height="374" class="aligncenter size-full wp-image-6892" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-21.png 501w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-21-300x224.png 300w" sizes="(max-width: 501px) 100vw, 501px" /></a></p>
<p>Click <strong>Install</strong>.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-22.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-22.png" alt="" width="497" height="377" class="aligncenter size-full wp-image-6893" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-22.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-22-300x228.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>After couple of minutes, click <strong>Finish</strong> to complete the install. Your <strong>vCenter Server</strong> should be up and running, but we are not over yet.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-23.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-23.png" alt="" width="495" height="371" class="aligncenter size-full wp-image-6894" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-23.png 495w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-23-300x225.png 300w" sizes="(max-width: 495px) 100vw, 495px" /></a></p>
<p>We will install the <strong>Update Manager</strong> now. This part of <strong>vCenter</strong> is used to patch the vCenter and ESXi hosts. Log back to the SQL server and in <strong>SQL Server Management Studio</strong>, execute this script that will create a new database for the <strong>Update Manager</strong>. Make sure you change the file path for the database. In my case is <strong>C:\DATA</strong>. We&#8217;ll use the same <strong>vpxuser</strong> user for the <strong>Update Manager</strong> database.</p>
<pre class="brush: sql; title: ; notranslate">
CREATE DATABASE &#x5B;VCUM] ON PRIMARY
(NAME = N'vcum', FILENAME = N'C:\DATA\VCUM.mdf', SIZE = 2000KB, FILEGROWTH = 10% )
LOG ON
(NAME = N'vcum_log', FILENAME = N'C:\DATA\VCUM.ldf', SIZE = 1000KB, FILEGROWTH = 10%)
COLLATE SQL_Latin1_General_CP1_CI_AS
go
use VCUM
go
</pre>
<p>On vCenter server, go to<strong> C:\Windows\SysWOW64</strong> folder and run <strong>odbcacd32.exe</strong>. The <strong>Update Manager</strong> is using a 32-bit ODBC and by default, if you go to <strong>Administrative Tools</strong> and start the <strong>ODBC manager</strong>, you&#8217;ll execute the 64-bit version.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-24.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-24.png" alt="" width="449" height="323" class="aligncenter size-full wp-image-6895" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-24.png 449w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-24-300x216.png 300w" sizes="(max-width: 449px) 100vw, 449px" /></a></p>
<p>Pick a name and description for this ODBC connection and specify your SQL server hostname.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-25.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-25.png" alt="" width="503" height="384" class="aligncenter size-full wp-image-6896" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-25.png 503w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-25-300x229.png 300w" sizes="(max-width: 503px) 100vw, 503px" /></a></p>
<p>Select the <strong>VCUM</strong> database that we just created and similarly to the previous ODBC creation, finish the rest of the steps.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-26.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-26.png" alt="" width="501" height="381" class="aligncenter size-full wp-image-6897" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-26.png 501w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-26-300x228.png 300w" sizes="(max-width: 501px) 100vw, 501px" /></a></p>
<p>Start the <strong>Update Manager</strong> install.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-27.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-27.png" alt="" width="655" height="452" class="aligncenter size-full wp-image-6898" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-27.png 655w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-27-300x207.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-27-585x404.png 585w" sizes="(max-width: 655px) 100vw, 655px" /></a></p>
<p>Accept the defaults.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-28.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-28.png" alt="" width="501" height="374" class="aligncenter size-full wp-image-6899" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-28.png 501w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-28-300x224.png 300w" sizes="(max-width: 501px) 100vw, 501px" /></a></p>
<p>Create a domain user that will run the <strong>Update Manager</strong> service. In my case I use <strong>svc_vcenter</strong>. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-29.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-29.png" alt="" width="491" height="371" class="aligncenter size-full wp-image-6900" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-29.png 491w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-29-300x227.png 300w" sizes="(max-width: 491px) 100vw, 491px" /></a></p>
<p>Specify the 32-bit ODBC connection that we just created.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-30.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-30.png" alt="" width="498" height="379" class="aligncenter size-full wp-image-6901" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-30.png 498w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-30-300x228.png 300w" sizes="(max-width: 498px) 100vw, 498px" /></a></p>
<p>Enter the same <strong>vpxuser</strong> and password.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-31.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-31.png" alt="" width="498" height="371" class="aligncenter size-full wp-image-6902" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-31.png 498w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-31-300x223.png 300w" sizes="(max-width: 498px) 100vw, 498px" /></a></p>
<p>Specify if any proxy servers need to be specified. <strong>Update Manager</strong> requires Internet connection.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-32.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-32.png" alt="" width="491" height="377" class="aligncenter size-full wp-image-6903" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-32.png 491w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-32-300x230.png 300w" sizes="(max-width: 491px) 100vw, 491px" /></a></p>
<p>Change or accept the defaults.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-33.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-33.png" alt="" width="497" height="378" class="aligncenter size-full wp-image-6904" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-33.png 497w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-33-300x228.png 300w" sizes="(max-width: 497px) 100vw, 497px" /></a></p>
<p>The rest of the steps a re just plain Next, Next, Finish.</p>
<p>Once installed, go back and install the <strong>vCenter</strong> client. I won&#8217;t explain how to do this. It&#8217;s trivial. Log to the <strong>vCenter</strong> with a local admin password or with a domain account (if you run vCenter service under a domain account).<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-34.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-34.png" alt="" width="416" height="373" class="aligncenter size-full wp-image-6905" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-34.png 416w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-34-300x269.png 300w" sizes="(max-width: 416px) 100vw, 416px" /></a></p>
<p>Select the top left <strong>vCenter</strong> server name and then click on <strong>Permissions</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-35.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-35.png" alt="" width="756" height="123" class="aligncenter size-full wp-image-6906" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-35.png 756w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-35-300x49.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-35-585x95.png 585w" sizes="(max-width: 756px) 100vw, 756px" /></a></p>
<p>Click <strong>Add</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-36.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-36.png" alt="" width="635" height="502" class="aligncenter size-full wp-image-6907" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-36.png 635w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-36-300x237.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-36-585x462.png 585w" sizes="(max-width: 635px) 100vw, 635px" /></a></p>
<p>Type your domain, enter a user that you want to grant full admin rights and click <strong>Check Names</strong>. If everything is OK, the dialog box will just blink.<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-37.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-37.png" alt="" width="500" height="468" class="aligncenter size-full wp-image-6908" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-37.png 500w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-37-300x281.png 300w" sizes="(max-width: 500px) 100vw, 500px" /></a></p>
<p>Back in the previous dialog, select <strong>Administrator</strong> and click OK. We made <strong>svc_vcenter</strong> an admin <strong>vCenter</strong> user. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-38.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-38.png" alt="" width="630" height="500" class="aligncenter size-full wp-image-6909" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-38.png 630w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-38-300x238.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-38-585x464.png 585w" sizes="(max-width: 630px) 100vw, 630px" /></a></p>
<p>From the <strong>vCenter</strong> client menu, select <strong>Plug-Ins</strong> and select the <strong>Update Manager</strong> plug-in.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-39.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-39.png" alt="" width="771" height="356" class="aligncenter size-full wp-image-6910" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-39.png 771w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-39-300x139.png 300w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-39-768x355.png 768w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-39-585x270.png 585w" sizes="(max-width: 771px) 100vw, 771px" /></a></p>
<p>Click <strong>Run</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-40.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-40.png" alt="" width="436" height="297" class="aligncenter size-full wp-image-6911" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-40.png 436w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-40-300x204.png 300w" sizes="(max-width: 436px) 100vw, 436px" /></a></p>
<p>Create a new datacenter, add the ESXi hosts and you are all set.</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2014/01/P037-41.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2014/01/P037-41.png" alt="" width="407" height="211" class="aligncenter size-full wp-image-6912" srcset="https://blog.andreev.it/wp-content/uploads/2014/01/P037-41.png 407w, https://blog.andreev.it/wp-content/uploads/2014/01/P037-41-300x156.png 300w" sizes="(max-width: 407px) 100vw, 407px" /></a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2014/01/install-vcenter-5-0/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Windows, PowerShell: PoshPAIG GUI tool for patching servers</title>
		<link>https://blog.andreev.it/2013/06/poshpaig-greate-powershell-gui-tool-for-patching-servers/</link>
					<comments>https://blog.andreev.it/2013/06/poshpaig-greate-powershell-gui-tool-for-patching-servers/#comments</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Thu, 13 Jun 2013 20:00:25 +0000</pubDate>
				<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[PoshPAIG]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=696</guid>

					<description><![CDATA[Recently, I was playing with PoshPAIG, a great GUI tool to audit and patch&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>Recently, I was playing with <a href="http://poshpaig.codeplex.com/" title="PoshPAIG Web Site" target="_blank" rel="noopener noreferrer">PoshPAIG</a>, a great GUI tool to audit and patch servers. This utility requires a WSUS server and a group policy to &#8220;Download updates and do not install&#8221; set for the servers. Unfortunately, at my company, our group policy is &#8220;Notify for download and notify for install&#8221;.<br />
Changing a group policy that will affect over 1000+ servers and not knowing the impact is impossible, so I had to modify the script a little bit to suit my needs. As a matter of fact, the script that PoshPAIG uses to install patches is a modified VBScript version that originates from <a href="http://www.akaplan.com/blog/wp-content/uploads/2011/04/InstallCriticalUpdates_vbs.txt" title="Original VBScript" target="_blank" rel="noopener noreferrer">this site</a>. </p>
<p>First, make a copy of the original Install-Patches.ps1 script that&#8217;s in <em>PoshPAIG_InstallFolder\Scripts</em> folder. Then look for the following piece of code:</p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2013/06/P030-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2013/06/P030-01.png" alt="" width="466" height="122" class="aligncenter size-full wp-image-6282" srcset="https://blog.andreev.it/wp-content/uploads/2013/06/P030-01.png 466w, https://blog.andreev.it/wp-content/uploads/2013/06/P030-01-300x79.png 300w" sizes="(max-width: 466px) 100vw, 466px" /></a></p>
<p>Insert the following code after &#8220;Else&#8221; and before &#8220;For I = 0&#8230;&#8221;</p>
<pre class="brush: vb; title: ; notranslate">
'Creating collection of updates to download
Set updatesToDownload = CreateObject(&quot;Microsoft.Update.UpdateColl&quot;)
For I = 0 to searchResult.Updates.Count-1
    Set update = searchResult.Updates.Item(I)
	Set objCategories = update.Categories
	strCatName = lcase(objCategories.Item(0).Name)
	updatesToDownload.Add(update) 
Next

'Downloading updates...
If updatestoDownload.count = 0 Then
	WScript.Quit
End If
Set downloader = updateSession.CreateUpdateDownloader() 

downloader.Updates = updatesToDownload
downloader.Download()

</pre>
<p>&#8230;or just use the attached file and replace <strong>Install-Patches.ps1</strong>. Now, when you do the audit, and then install patches, the script will first download the patches from WSUS (it takes a while) and then install them.</p>
<p><a href='http://blog.andreev.it/wp-content/uploads/2013/06/Install-Patches.zip'>Install-Patches</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2013/06/poshpaig-greate-powershell-gui-tool-for-patching-servers/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>Windows:  Migrating domain network printers to a different print server</title>
		<link>https://blog.andreev.it/2012/01/migrating-domain-users-network-printers-to-a-different-print-server/</link>
					<comments>https://blog.andreev.it/2012/01/migrating-domain-users-network-printers-to-a-different-print-server/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Wed, 18 Jan 2012 19:36:29 +0000</pubDate>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[print server]]></category>
		<guid isPermaLink="false">http://blog.iandreev.com/?p=239</guid>

					<description><![CDATA[Recently, I had a project to move about 70 printers from one domain member&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>Recently, I had a project to move about 70 printers from one domain member server to another. This was a very easy task, but I had a problem when I had to migrate the network printers on users computers. We don’t use login scripts or group policy to map the printers, so first thought was to visit each user and remap the network printers. But we have about 350+ users and visiting each one was out of the question. I was looking to script this problem and I found a couple of links (see below), that helped me to wrote my own script. After I tested it, we used MS SMS to push this script to every user. Still, there were some minor issues, but we fixed them manually.</p>
<p>This VBscript is very straightforward and it is well commented, so it is very easy to understand.<br />
Click below to download&#8230;<br />
<a href='https://blog.andreev.it/wp-content/uploads/2012/01/addremprtv2.zip'>addremprtv2</a></p>
<pre class="brush: vb; title: ; notranslate">
'=====================================================================
'
'
'   Program: AddRemPrt.vbs
'   Version: 2.0    
'    Author: Kliment Andreev
'      Date: 08/22/2008
'
'   Comment: This VBScript will list all network printers in a file
'            on \\LogShare\UserName+ComputerName.txt, then it will add the same printers
'            from a new print server and delete the old ones
'		
'    Note:   1. Printers defined on the new server must be with the same name
'	        or some suffix plus the same name
'	     2. Printers must exist on the new server
'	        e.g \\OldServer\PrinterName must exists 
'		as \\NewServer\PrinterName or as \\NewServer\Prefix+PrinterName
'	     3. Make sure \\LogShare is accessible by everyone for writing
'	     4. This script won't install network printers that are installed as local using TCP port
'		
' Copyright: Public Domain
'
'
'=====================================================================

Option Explicit

dim strOldServer					' Old printserver name, defined below
dim strNewServer					' New printserver name, defined below		
dim strLogShare						' Full path to a share where log files will be created
dim strOldPrinterPath					' Full path (\\servername\printername) of the old printer
dim strNewPrinterPath					' Full path (\\servername\printername) of the new printer + prefix
dim strPrinterName					' Name of the printer only
dim strComputerName					' String that contains the computername
dim strUserName						' String that contains the username
dim strPrefix						' Prefix that will be added to the new printer name
dim objFSO						' Object to work with Files
dim objNetwork						' Object to work with Network Printers
dim objShell						' Object to work with ENV variables
dim objFile						' Full path of the file that contains the printers
dim objOldPrinters					' Object that contains all printers (including local)
dim i, strTemp						' Helper varaibles

Set objFSO = CreateObject (&quot;Scripting.FileSystemObject&quot;)
Set objNetwork = CreateObject (&quot;Wscript.Network&quot;)
Set objShell = CreateObject (&quot;WScript.Shell&quot;)

strOldServer = &quot;USLCPDMGT02&quot;
strNewServer = &quot;USCORPRINTSRV01&quot;
strLogShare  = &quot;\\USCPDITCR01\PrtLogs&quot;
strPrefix    = &quot;CPD_CR_&quot;					

strComputerName = objShell.ExpandEnvironmentStrings(&quot;%ComputerName%&quot;)
strUserName = objShell.ExpandEnvironmentStrings(&quot;%UserName%&quot;)
Set objFile  = objFSO.CreateTextFile (strLogShare &amp; &quot;\&quot; &amp; strUsername &amp; &quot; - &quot; &amp; strComputerName &amp; &quot;.txt&quot;)
Set objOldPrinters = objNetwork.EnumPrinterConnections

For i = 0 to objOldPrinters.Count - 1
	
	strTemp = UCase(mid(objOldPrinters.Item(i), 1, 2 + len(strOldServer)))
	If strTemp = &quot;\\&quot; &amp; strOldServer  Then
		strOldPrinterPath = objOldPrinters.Item(i)
		strPrinterName = mid(strOldPrinterPath, 3 + 1 + len(strOldServer))
		objFile.Write(strOldPrinterPath &amp; vbCrLf)					' Write \\server\printer to a file
		strNewPrinterPath = &quot;\\&quot; &amp; strNewServer &amp; &quot;\&quot; &amp; strPrefix &amp; strPrinterName
		objNetwork.AddWindowsPrinterConnection strNewPrinterPath			' Add new printer
		objNetwork.RemovePrinterConnection strOldPrinterPath, True, True		' Remove the old one	
	End If

Next

objFile.Close
</pre>
<p>Useful links:<br />
<a href="http://www.hardforum.com/showthread.php?t=806407">http://www.hardforum.com/showthread.php?t=806407</a><br />
<a href="http://support.microsoft.com/kb/321025">http://support.microsoft.com/kb/321025</a><br />
<a href="http://www.tech-archive.net/Archive/Windows/microsoft.public.windows.server.migration/2008-01/msg00011.html">http://www.tech-archive.net/Archive/Windows/microsoft.public.windows.server.migration/2008-01/msg00011.html</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2012/01/migrating-domain-users-network-printers-to-a-different-print-server/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
