Hot and heavy

When we get servers into the shop to run up we normally have to install a number of additional components inside the beasts. This usually means that we rip off the cover and get everything installed and then power the sucker up to make sure that it all works. We also then generally leave the machine running so it can “burn in”, basically see if anything “burns out” and needs replacing before the customer takes delivery.

Recently, we left the side cover off the machine overnight and came back in the morning to discover a number of warnings being displayed in the server monitoring software. Turns out that the disks were running pretty damm hot. Why? Well, servers these days are specially crafted to ensure that they receive adequate air flow WITH the covers ON. Removing the cover completely destroyed the carefully crafted airflow designed to keep everything cool.

Once we returned the cover to the machine and switched it back on it was only a few minutes before everything was back operating at the correct temperature. So there you go, don’t run servers for extended periods of time with the covers removed or you risk overheating the internal components.

Computer Associates (CA) licensing

Something we have always found very mysterious is the way Computer Associates (CA) license their products. Generally, it is hard to locate exactly what product may be generating an out of license error. Hopefully the following information will make it easier for people to locate.

Computer Associates (CA) licensing information is usually held in
 
c:\program files\ca\shared components\ca_lic
 
in here you’ll find a file called lic98.log. This contains a log of all the license errors. Check this log to see what products aren’t licensed.
 
Also in this directory you’ll find a file calicnse.exe which when run will display the products that are licensed and their license count. Prior to selecting a product listed here you are able to enter additional licenses at the bottom of the window.
 
The license details are held in the register at hklm\software\computerassociates\license\products. Under this key you will find a number of subkeys that designate the products ( like 31AM, 3EPP ). A list of the corresponding product code can be found at :
 
http://supportconnectw.ca.com/public/reglic/infodocs/itcodes.asp
 
Under each product key should be a folder 011 and under that ( if the product is licensed ) you will find a key ( folder ) with the license code. If the product doesn’t have a license key ( folder ) under it then the product is not licensed.
 
To re-license the product simply delete the product key (folder) and return to the licensing options in the product ( usually under Help | About ) to re-license the product.

We can’t wait for these

Already have SharePoint 3.0 and love it. Next thing is a swag of SharePoint templates that are being released by Microsoft. You’ll find more information about what’s on offer here:

http://www.microsoft.com/technet/windowsserver/sharepoint/wssapps/v3templates.mspx

We have already see a few of these in operation and can’t wait. We are really keen to get our hands on the knowledge base template since we are currently building a new CIAOPS knowledge base in SharePoint 3.0. As soon as the templates are ready we are planning to release the site. At stage we are planning to offer it on subscriptions basis ( around the $ 40 per annum mark ). It will contact knowledge base articles on all the products we use and focus especially on SBS 2003. We are also planning to provide an amount of marketing material around SBS including things like logos, links to relevant web sites and what not. Hopefully, it will become a one stop shop for the SBS consultant who wants marketing as well as technical information to assist in their business.

If you have any ideas or suggestions we’d love to hear them as we go about designing our vision.

Try new filters first

We’ve been mucking around with ADSL2 lately and it has proved to be very frustrating. The problem is trying to locate the issues. Firstly, you change all the equipment at your end. Next you upgrade everything at your end. After that you blame the ISP and give their tech support a hard time and just when you think you are going to pull all your hair out you replace the ADSL filter on the phone line and viola, everything works.

From what we can work out ADSL, operating at higher frequencies, is much more sensitive to interference than normal ADSL. So using an older ADSL filter on an ADSL2 line may not provide enough “filtering” to allow adequate reliability. If you are having issues, the first thing that we would recommend you try is buying and installing a new line filter. It worked for us.

We have also seen some cases where ADSL filters have caused issues on lines so for what it is worth go out and buy a few filters and keep ’em handy and if problems develop try a new filter first. It may save you the hours that we wasted.

There are multiple accounts with name MSSQLSvc

Having nothing better to do over the Christmas / New Year break (yeah right) we thought we might enjoy a good swing. A swing migration that is. Firstly, all credit to Jeff Middleton for his excellent guide on how to get a new SBS server working without disrupting and old SBS server. It doesn’t even have to be an SBS server but we know that it works with SBS. For information about the process see www.sbsmigration.com.

Our only criticism of Jeff’s work is that although it is very through we found it a little disjoined. To overcome this we developed our set of custom migration notes that made it clear for dummies like us. During this process we have come across a few interesting tips and issues that aren’t mentioned in Jeff’s notes.

The first of these is the following error that started appearing in the logs :

There are multiple accounts with name MSSQLSvc/:1433 of type DS_SERVICE_PRINCIPAL_NAME.

Turns out what happens was that our initial SBS Premium server ( with SQL 2000 installed ) was set to run the SQL services under a specific user. However, when we installed the new SBS server we set up the new version of SQL to run under another account. This means that two different users in the Active Directory think that they in control the SQL service accounts generating the above error.

The fix is pretty simple. Use the setspn utility to check the accounts and then change the setting so only one is registered for SQL.

Use

setspn -l account1

&

setspn -l account2

to check that both accounts were registered for mssqlsvc. Now use

setspn -d mssqlsvc/:1433 account2

to remove the suplicate SPN from the second account (in this case account2).

So for all you SBS swingers out there keep this in mind if you are planning to change the service accounts logins for accounts during migration.

Windows updates fail to install

Having a problem installing Windows Updates from the Microsoft web site on your XP machine? Typically they download but when they actually go to install the message you get says “failed”. If so try this :

1. On the machine with issue, locate and stop the service “Automatic Updates” in Services under Administrative Tools from Control Panel.

2. Locate C:\WINDOWS\SoftwareDistribution and delete all the contents in this folder but do not delete the folder C:\WINDOWS\SoftwareDistribution, just all files and folders underneath it.

3. Return to Services and restart “Automatic Updates”

4. Re-run Microsoft Updates from the web site. You will need to reinstall the Microsoft Update ActiveX control but updates should now download and install.

Good security demo

Here’s a great video that demonstrates how “insecure” even the most the modern networks are. All you have to do is ignore one fundamental security principal ( which end users do all the time ) and then the flood gates are open.

http://www.microsoft.com/uk/technet/itsshowtime/sessionh.aspx?videoid=351

It’s only about 20 minutes in total time but we just wish we could download the file in total for later reference.

SBS2003 standard and VPN issues

We were recently trying to get VPN access to an SBS 2003 standard install. Everything we tried just didn’t work. We ran and re-ran the wizards, checked that the right ports on the hardware firewall were forwarded but still no luck. Typically, we would get the message that the VPN was connecting but during authentication it would simply timeout and we would receive a message that the VPN had been disconnected.

Turns out that the problem lay with the hardware firewall. What finally ended up resolving the problem was a simple upgrade of the firewall firmware. Once completed the VPN worked a treat. Initially you just never stop and consider that the hardware firewall ( external to SBS2003 ) could be the issue. It works and has always worked so why should it be a problem? Well, in this case it certainly was the problem.

Another handy tip we’d give is you is to always backup the configuration of the hardware firewall before you upgrade the firmware. Over time a lot of changes can be made to a hardware firewall that are note always documentated.