<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brad&#039;s Tech Blog &#187; OpsMgr</title>
	<atom:link href="http://bradstechblog.com/category/opsmgr/feed" rel="self" type="application/rss+xml" />
	<link>http://bradstechblog.com</link>
	<description>Microsoft technologies like: System Center Operations Manager, and whatever else comes up at the office.</description>
	<lastBuildDate>Wed, 09 Nov 2011 16:36:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SCOM &#8211; How to Create an override</title>
		<link>http://bradstechblog.com/scom/scom-how-to-create-an-override</link>
		<comments>http://bradstechblog.com/scom/scom-how-to-create-an-override#comments</comments>
		<pubDate>Wed, 16 Sep 2009 22:38:04 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[operationsmanger]]></category>
		<category><![CDATA[override]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=327</guid>
		<description><![CDATA[This article will show the basics of how to create an override
Never use the "Default Management Pack" it is selected by default]]></description>
			<content:encoded><![CDATA[<ul>
<li>
<div class="MsoNormal" style="margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 3;"> <span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Open the OpsMgrConsole, in the right pane select Monitoring and navigate to active alerts. </span></div>
</li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Right click on the alert you want to set an override for and select </span><strong><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 10.0pt;">Overrides\Override the Rule</span></strong>
<ul style="margin-top: 0in;" type="circle">
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level2 lfo2; tab-stops: list 1.0in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">You will have the choice of who or what the override is applied too.</span>
<ul style="margin-top: 0in;" type="square">
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">The current object as a whole. (For example, when you choose the Computer object, Operations Manager disables or overrides the rule for all computers).</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">A particular group.</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">A specific object of the current type (for Example, a specific computer on the network).</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">All objects of another type (such as Agent).</span></li>
</ul>
</li>
</ul>
</li>
</ul>
<p class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';"><span id="more-327"></span></span></p>
<ul>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">After you select the appropriate object you will see the override properties page. There may be as few as one rule to multiple rules that you can modify. Here you are going to need detailed knowledge about the technology that you are monitoring. </span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">At the bottom of this page you will need to select the management pack to save the override to. </span><strong><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 10.0pt;">DO NOT USE THE &#8220;DEFAULT MANAGMENT PACK&#8221;!</span></strong></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">If you don’t have a custom management pack to save it to you can create one from this window. Just follow the dialog boxes.</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">When you are done say ok and the changes will be saved. </span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">This article will show the basics of how to create an override</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">This will not show the values to use. For this product knowledge of the technology being monitored will be required as well as some research. </span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Never use the &#8220;Default Management Pack&#8221; it is selected by default, so be careful to change it to a custom management pack. This creates other potential problems later on. When installing OpsMgr service packs the &#8220;Default Management Pack&#8221; can be overwritten causing us to lose all changes.</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Never disable a monitor. This can be done as an override. When you disable a monitor it is automatically saved to the &#8220;Default Management Pack&#8221;.</span></li>
</ul>
<p> </p>
<p class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/scom-how-to-create-an-override/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to move the Operations Manager 2007 Reporting Server</title>
		<link>http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server</link>
		<comments>http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server#comments</comments>
		<pubDate>Thu, 30 Apr 2009 22:47:35 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[reporting]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server</guid>
		<description><![CDATA[The download able pdf has the complete steps that I took to perform a successful move of our opsmgr reporting server to a new server separate from the Data Warehouse. how-to-move-the-operations-manager-2007-reporting-server]]></description>
			<content:encoded><![CDATA[<p>The download able pdf has the complete steps that I took to perform a successful move of our opsmgr reporting server to a new server separate from the Data Warehouse.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/04/how-to-move-the-operations-manager-2007-reporting-server.pdf">how-to-move-the-operations-manager-2007-reporting-server</a></p>
<p><!--smartads--></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to move the OperationsManager Data Warehouse Database to a new SQL server</title>
		<link>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server</link>
		<comments>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server#comments</comments>
		<pubDate>Wed, 29 Apr 2009 18:36:19 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[move]]></category>
		<category><![CDATA[operationsmanger]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=303</guid>
		<description><![CDATA[I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers. the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all [...]]]></description>
			<content:encoded><![CDATA[<p>I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers.</p>
<p>the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all three manuals that I have created out of this here.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/04/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server.pdf">how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server</a></p>
<p><!--smartads--></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to move the OperationsManager DataBase to a new SQL server</title>
		<link>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-database-to-a-new-sql-server</link>
		<comments>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-database-to-a-new-sql-server#comments</comments>
		<pubDate>Wed, 29 Apr 2009 18:11:55 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[SQL Reporting Services]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[move]]></category>
		<category><![CDATA[operationsmanger]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=297</guid>
		<description><![CDATA[I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers. the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all [...]]]></description>
			<content:encoded><![CDATA[<p>I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers.</p>
<p>the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all three manuals that I have created out of this here.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/04/how-to-move-the-operationsmanager-database-to-a-new-sql-server.pdf">how-to-move-the-operationsmanager-database-to-a-new-sql-server</a></p>
<p><!-smartads-></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-database-to-a-new-sql-server/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to create a SCOM Windows Events Monitor and alert on the Description field</title>
		<link>http://bradstechblog.com/scom/how-to-create-a-scom-windows-events-monitor-and-alert-on-the-description-field</link>
		<comments>http://bradstechblog.com/scom/how-to-create-a-scom-windows-events-monitor-and-alert-on-the-description-field#comments</comments>
		<pubDate>Tue, 17 Feb 2009 21:01:34 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[monitor description]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=285</guid>
		<description><![CDATA[When creating a monitor that alerts on event logs you may want to be able to monitor based on key words in the description field. This is not a default parmater and needs a few extra steps. But is still very easy to accomplish once you now the steps. here are the two variables you [...]]]></description>
			<content:encoded><![CDATA[<p>When creating a monitor that alerts on event logs you may want to be able to monitor based on key words in the description field. This is not a default parmater and needs a few extra steps. But is still very easy to accomplish once you now the steps.</p>
<p>here are the two variables you will be adding to the monitor</p>
<p>parameter name: EventDescription</p>
<p>Alert description: $Data/EventDescription$<br />
<!--smartads--><br />
<span id="more-285"></span></p>
<p>1. When you are creating the Event Expression click on insert, then click on button &#8220;&#8230;: under parameter name</p>
<p>2. Select <strong>Use Parameter Name not specified above</strong> and enter <strong>EventDescription</strong></p>
<div id="attachment_287" class="wp-caption alignnone" style="width: 310px"><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0117.png"><img class="size-medium wp-image-287" title="image-0117" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0117-300x295.png" alt="Select an Event Property-EventDescription" width="300" height="295" />$Data/EventDescription$</a><p class="wp-caption-text">Select an Event Property-EventDescription</p></div>
<p>3. change your operator to <strong>Contains</strong><img src="file:///C:/Temp/moz-screenshot.jpg" alt="" /><strong> </strong></p>
<p>4. under the Value, enter the words you want to find in the desction field.</p>
<div id="attachment_288" class="wp-caption alignnone" style="width: 310px"><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0118.png"><img class="size-medium wp-image-288" title="image-0118" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0118-300x201.png" alt="Build Event Expresion - operator and value" width="300" height="201" /></a><p class="wp-caption-text">Build Event Expresion - operator and value</p></div>
<blockquote><p><strong>THIS IS NOT DONE!!!!</strong></p></blockquote>
<p>5. Continue to build your rule until you arrive at the Configure Alerts page. Enter the value <strong>$Data/EventDescription$</strong> in the <strong>Alert description</strong> window. If you do not you will receive errors.</p>
<blockquote><p><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0119.png"><img class="alignnone size-medium wp-image-289" title="Configure Alerts - $Data/EventDescription$" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0119-300x297.png" alt="" width="300" height="297" /></a></p></blockquote>
<p>6. Create the rule, and refresh how ever you like. When i am in a hurry i will restart the health service on the server that I am monitoring.</p>
<p>7. To test your rule the OpsMgr Event Creator tool is not going to work. It does not allow you to create custom descriptions. Log onto the server that you want to monitor and open a command window. Using the eventcreate command type the following</p>
<blockquote><p>eventcreate /t error /ID 1000/d &#8220;fieldxu.exe THIS IS JUST A TEST BY Brad Hearn&#8221;</p>
<p>/t sets as an error</p>
<p>/ID is the event id</p>
<p>/d is what will be placed into the description field. Remeber to place quotes around your text.</p></blockquote>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0120.png"><img class="alignnone size-medium wp-image-291" title="image-0120" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0120-300x61.png" alt="" width="300" height="61" /></a></p>
<p>The alerts will look something like this.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0121.png"><img class="alignnone size-medium wp-image-292" title="image-0121" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0121-267x300.png" alt="" width="267" height="300" /></a></p>
<p>Hope this helps out.</p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-create-a-scom-windows-events-monitor-and-alert-on-the-description-field/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Deploying SCOM Gateway server</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server</link>
		<comments>http://bradstechblog.com/scom/deploying-scom-gateway-server#comments</comments>
		<pubDate>Wed, 12 Nov 2008 21:17:23 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[netsh]]></category>
		<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[SCOM; Gateway]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=246</guid>
		<description><![CDATA[Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server Certificates need to be deployed (2 types of certificates) The root CA needs to be installed on all management servers A custom cert template needs to be created on the issuing CA [...]]]></description>
			<content:encoded><![CDATA[<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server</li>
<li class="MsoNormal">Certificates need to be deployed (2 types of certificates)</li>
<li class="MsoNormal">The root CA needs to be installed on all management servers</li>
<li class="MsoNormal">A custom cert template needs to be created on the issuing CA for OpsMGR</li>
<li class="MsoNormal">The Custom OpsMgr cert needs to be installed on all management servers</li>
<li class="MsoNormal">Run the momcertimport on all management server after the certs have been installed. This makes some specific registry changes for scom to help pick the correct cert.</li>
<li class="MsoNormal">Approve gateway server on RMS using a approval tool.</li>
<li class="MsoNormal">Manual install of agents on servers to be monitored</li>
<li class="MsoNormal">Approve agents in SCOM console</li>
</ol>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Download the PDF <a href="http://bradstechblog.com/wp-content/uploads/2008/11/deploying-scom-gateway-server2.pdf">deploying-scom-gateway-server2</a></p>
<p class="MsoNormal"> </p>
<p><!--martad--></p>
<p class="MsoNormal"><span id="more-246"></span></p>
<p class="MsoNormal"> </p>
<h3><a name="_Open_and_test"></a>Open and test ports</h3>
<p class="MsoNormal">Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">To test if the ports are open. Log on to gateway server. From a command prompt type</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><strong>telnet SRVNAME261 5723</strong></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">If you get a cursor at the top left corner then the port is open. Any other errors indicate that the port is still closed.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Do the same from the management server back to the gateway server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><a name="_Import_a_trusted"></a></p>
<p class="MsoNormal"> </p>
<h3><a name="_Certificates_need_to"></a>Certificates need to be deployed (2 types of certificates)</h3>
<p class="MsoNormal"> </p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Root_certificate"></a><!--if !supportLists--><span><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Root certificate</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the root certificate for the management servers on the same domain as the CA server</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Logon on the management server. Open a web Brower and navigate to <span style="color: #000000; text-decoration: none;">http://SRVNAME342/certsrv/</span></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Download a CA certificate, certificate chain, or CRL</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Download CA Certificate chain</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on save. And save to a location of your choice. The default file name is certnew.p7b. This is fine. (you can use this cert for all your management servers and gateway server to skip the initial download on this servers if you like.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->To import the downloaded cert open the certificate MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on “Trusted Root Certification Authorities”</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->When the wizard opens navigate to the downloaded cert is certnew.p7b . You will need to change the file type to PKCS #7</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Accept the defaults and finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Do this on all management servers inside the domain</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the root certificate for the Gateway server that is not attached to the domain as the CA server.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Perform step one above to save certnew.p7b. Or use the same cert that was downloaded above. And copy to the gateway server. Then perform step 2 above.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Create_the_Custom"></a><!--if !supportLists--><span><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Create the Custom OpsMgr Certificate</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->To create the cert. We will use two consoles to do this. Certification Authority mmc and certificate templates mmc</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificate Templates and Certification Authority, and click on add again. And finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select Certificate Templates</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->In the Certificate Templates Console right click <strong>IPSec (Offline request)</strong> and then select <strong>duplicate template</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->General Tab</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Type a name</p>
<p class="MsoNormal" style="margin-left: 99pt;">Request Handling</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select <strong>Allow private key to be exported</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>CSPs…</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select Microsoft RSA SChannel Cryptographic provider for windows 2003 and Microsoft Enhanced Cryptographic provider 1.0 for windows 2000</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Extensions Tab</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select the Applications Policies and click on edit</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->remove <strong>IP security IKE intermediate</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on add..</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>Client Authentication and Server Authentication</strong>, and clink on ok twice.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Security Tab</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Users should have read</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Say ok and close.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Add_the_new"></a><!--if !supportLists--><span><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Add the new custom cert to the certificate authority</h3>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open the Certification Authority mmc console</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand it and right click on certificate templates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select new, certificate template to issue</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Scroll through the list until you find the one you just created. Select it and say ok.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->It should now show in the right window.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Deploy_the_Custom"></a><!--if !supportLists--><span><span>4.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Deploy the Custom OpsMgr Certificate to the management servers on the same domain as the CA (need to do the full steps individually for each server)</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Logon on the management server. Open a web Brower and navigate to http://SRVNAME342/certsrv/</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Request a certificate</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Create and submit a request to this CA</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select the custom Template</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>e.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter a name for the template. This is the full unc name of the server that you are going to install the cert on.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>f.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter the rest of the identity info if you like.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>g.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Under Key options select the csp that fits your operating system. select Microsoft RSA SChannel Cryptographic provider for windows 2003 and Microsoft Enhanced Cryptographic provider 1.0 for windows 2000</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>h.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Key size 1024</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Mark keys as exportable</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>j.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Check off <strong>Store cert in local computer cert store…</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>k.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Use full unc path as friendly name.</p>
<p class="MsoNormal" style="margin-left: 0.75in;"> </p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>l.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on submit, say yes.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>m.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Install this certificate</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>n.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>o.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>p.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>q.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>r.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>s.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>t.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You should see the new cert here.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"> </p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"> </p>
<p><!--martad--></p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><!--if !supportLists--><span><span>5.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Deploy the custom Certificate to the Gateway sever in the DMZ.</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Because the gateway is not part of the same domain as the CA. We need to create the certificate on a different server and export it to a usb drive or other storage device. Then manually copy it to the gateway server and import it.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->First create the cert from a server on the same domain as the CA. <a href="#_Deploy_the_Custom">Follow the steps in step 4 first</a>.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Next we will export the cert</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You should see the new cert here.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Right click on the cert and select <strong>All tasks, export</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->The export wizard will open, say next</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>x.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>Yes, export private key</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>enable strong protection</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter a password for the import. You will need this password when you export the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xiii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Specify a location and name to save it too.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xiv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->And finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy the cert to the gateway server. It will have a .pfx extension.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>All tasks, Import</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Browse to the cert you coppied over. You will need to change the file type to PFX to see the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>x.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>open, say next, enter password. </strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Check off <strong>Mark this key as exportable. </strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Say next, make sure the certificate store is <strong>personal</strong> , click next and finish.</p>
<p class="MsoNormal" style="margin-left: 99pt;"> </p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Run_the_momcertimport"></a><!--if !supportLists--><span><span>6.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Run the momcertimport utility</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->In this step we are going to use the same pfx certificate (the custom personal cert) that we created in step 4.<span> </span>This tool writes the certificate serial number to the registry. This will help OpsMgr components find the the proper certificate for authenticatin easily.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You will find the momcertimport utility on the install cd under supporttools\i386.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy momcertimport.exe and the pfs certificate into the same folder.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open a command prompt, navigate to the folder with both files and type the following command</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->C:\&gt;MOMCertImport.exe certfilename.pfx</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->There is NO response after the command is successfully initiated.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>e.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->So this on all SCOM management servers. RMS, MS, and Gateway</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Approve_the_Gateway"></a><!--if !supportLists--><span><span>7.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Approve the Gateway Server</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->We will use the gateway approval tool to achieve this. This will setup the gateway server as a management server in SCOM. Once done you can confirm this by looking in the SCOM console under administration, Device Management, Management Servers.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->The tool has to be run from c:\program Files\System Center Operations Manager 2007</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy Microsoft.EnterpriseManagement.GatewayApprovalTool.exe from the support tools directory to c:\program Files\System Center Operations Manager 2007</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open the command prompt and type the following command</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->microsoft.enterprisemanagement.gatewayapprovaltool.exe /managementservername=SRVNAME261.domainName.com /gatewayname=domainNamedmz22.domainNamedmz.com /action=create</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Next_you_now"></a><!--if !supportLists--><span><span>8.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Next you now ready to manually install the agents on the servers in the DMZ</h3>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Approve_the_agents"></a><!--if !supportLists--><span><span>9.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Approve the agents in the SCOM console.</h3>
<p class="MsoNormal"> </p>
<p class="MsoNormal" style="margin-left: 0.25in;"> </p>
<div class="MsoNormal" style="margin-left: 0.25in  mce_tmp="> &lt;&#8211;&gt;</div>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/deploying-scom-gateway-server/feed</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>How to create a Recovery task in SCOM on a windows service.</title>
		<link>http://bradstechblog.com/scom/how-to-create-a-recovery-task-in-scom-on-a-windows-service</link>
		<comments>http://bradstechblog.com/scom/how-to-create-a-recovery-task-in-scom-on-a-windows-service#comments</comments>
		<pubDate>Wed, 01 Oct 2008 17:34:58 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[Monitors]]></category>
		<category><![CDATA[Recovery Task]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=205</guid>
		<description><![CDATA[When you have the requirement to monitor a windows service through Microsoft&#8217;s System Center Operations Manger and have it restarted automatically you can not use the management pack templates. The reason for this is that the templates are stored in locked MP&#8217;s that you do not have access too. Follow the following steps to monitor [...]]]></description>
			<content:encoded><![CDATA[<p>When you have the requirement to monitor a windows service through Microsoft&#8217;s System Center Operations Manger and have it restarted automatically you can not use the management pack templates. The reason for this is that the templates are stored in locked MP&#8217;s that you do not have access too.</p>
<p>Follow the following steps to monitor a service and have it restarted automatically by SCOM if it fails.<br />
<!--smartads--><br />
<span id="more-205"></span></p>
<p><strong>Steps</strong></p>
<ol>
<blockquote>
<li>Create a management pack to store the monitor in</li>
<li>Create a group that the monitor will be applied against</li>
<li>Create a monitor that watches the service</li>
<li>Create overrides (apply to group)</li>
<li>Create the recovery task</li>
</blockquote>
</ol>
<p><strong>Step 1: Create the Management Pack<br />
</strong></p>
<p>In the managment console under Administration right click on Management Packs and select &#8220;Create Management Pack&#8221;. Give this new MP a meaningfull name and continue.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1.png"><img class="alignnone size-medium wp-image-206" title="create_new_mp" src="http://bradstechblog.com/wp-content/uploads/2008/09/create_new_mp-300x199.png" alt="" width="300" height="199" /></a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1.png"> </a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1.png"><img class="alignnone size-medium wp-image-208" title="label_mp1" src="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1-300x264.png" alt="" width="300" height="264" /></a></p>
<p><strong>Step 2: Create the Group<br />
</strong></p>
<ul>
<li>In the Authoring Pane right click on &#8220;create new group&#8221; Give this new group a meaningful name. A description. And select the management pack that you created.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_group.png"> <img class="alignnone size-medium wp-image-209" title="create_new_group" src="http://bradstechblog.com/wp-content/uploads/2008/09/create_new_group-81x300.png" alt="" width="81" height="300" /></a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_group.png"> </a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_group.png"><img class="alignnone size-medium wp-image-210" title="label_group" src="http://bradstechblog.com/wp-content/uploads/2008/09/label_group-300x257.png" alt="" width="300" height="257" /></a></p>
<blockquote><p>Important: Do not use the default management pack. You can do it. But this will create problems when trying to remove MP in the future. Always use Custom MP&#8217;s.</p></blockquote>
<ul>
<li>Say next. Click on Add/remove objects on the Explicit Group Members. Enter a server name and search. Select your computer object and say ok. You can now add dynamic and exclusions. I am not going into that on this post so except all defaults.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/explicit_members.png"><img class="alignnone size-medium wp-image-211" title="explicit_members" src="http://bradstechblog.com/wp-content/uploads/2008/09/explicit_members-300x291.png" alt="" width="300" height="291" /></a><br />
<!--smartads--><br />
<strong>Step 3</strong>: <strong>Create the Monitor</strong></p>
<ul>
<li>In the Authoring Pane right click on monitors and select Create a monitor, then Unit Monitor.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/create_unitmonitor.png"><img class="alignnone size-medium wp-image-212" title="create_unitmonitor" src="http://bradstechblog.com/wp-content/uploads/2008/09/create_unitmonitor-300x171.png" alt="" width="300" height="171" /></a></p>
<ul>
<li>Expand Windows Services, and select &#8220;Basic Service Monitor&#8221;. Select the custom management pack.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/select_monitor_type.png"><img class="alignnone size-medium wp-image-213" title="select_monitor_type" src="http://bradstechblog.com/wp-content/uploads/2008/09/select_monitor_type-300x293.png" alt="" width="300" height="293" /></a></p>
<ul>
<li>Provide a name for the monitor. I am going to create this monitor to watch Windows Update services. Select the monitor target as windows Server Operating System. Select the Parent Monitor as Availability.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/monitor_general_properties.png"><img class="alignnone size-medium wp-image-214" title="monitor_general_properties" src="http://bradstechblog.com/wp-content/uploads/2008/09/monitor_general_properties-300x294.png" alt="" width="300" height="294" /></a><a href="http://bradstechblog.com/wp-content/uploads/2008/09/monitor-target.png"><img class="alignnone size-medium wp-image-216" title="monitor-target" src="http://bradstechblog.com/wp-content/uploads/2008/09/monitor-target-300x259.png" alt="" width="300" height="259" /></a></p>
<ul>
<li>Next Browse to the server, or any server with the service running. and select the service.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/select_service.png"><img class="alignnone size-medium wp-image-218" title="select_service" src="http://bradstechblog.com/wp-content/uploads/2008/09/select_service-300x248.png" alt="" width="300" height="248" /></a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/select_service2.png"><img class="alignnone size-medium wp-image-217" title="select_service2" src="http://bradstechblog.com/wp-content/uploads/2008/09/select_service2-300x294.png" alt="" width="300" height="294" /></a></p>
<ul>
<li>The next window shows how the monitor sees the health state. Accept the default.</li>
</ul>
<ul>
<li>The last window is how the alerts are configured.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/configure-alert.png"><img class="alignnone size-medium wp-image-219" title="configure-alert" src="http://bradstechblog.com/wp-content/uploads/2008/09/configure-alert-300x293.png" alt="" width="300" height="293" /></a></p>
<ul>
<li>uncheck the &#8220;Generate alerts for this monitor:&#8221; for now. This will prevent any unwanted alerts until we are ready.</li>
</ul>
<p><strong>Step 4: Apply to group</strong></p>
<p>Lets apply this MP against the group that we created earlier and disable it for all other servers.</p>
<p>Fist disable the rule for all servers</p>
<ul>
<li>Find the new rule under Authoring\monitors. The easiest way to do this is to change your scope. Click on the Change scope in the top right corner</li>
<li>Look for windows server operating System and select it and say ok.</li>
</ul>
<p><img src="file:///C:/Temp/moz-screenshot-4.jpg" alt="" /> <a href="http://bradstechblog.com/wp-content/uploads/2008/09/changescope.png"><img class="alignnone size-medium wp-image-220" title="changescope" src="http://bradstechblog.com/wp-content/uploads/2008/09/changescope-300x241.png" alt="" width="300" height="241" /><br />
</a></p>
<ul>
<li>Expand the monitor, right click on it and select properties.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/expandmonitor.png"><img class="alignnone size-medium wp-image-221" title="expandmonitor" src="http://bradstechblog.com/wp-content/uploads/2008/09/expandmonitor-300x132.png" alt="" width="300" height="132" /></a></p>
<ul>
<li>Select Disable and &#8220;For all objects of type: windows Server Operating System&#8221;</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/disable_monitor.png"><img class="alignnone size-medium wp-image-222" title="disable_monitor" src="http://bradstechblog.com/wp-content/uploads/2008/09/disable_monitor-300x206.png" alt="" width="300" height="206" /></a></p>
<ul>
<li>Next Right click on the same monitor and select override, Override the Monitor, for a group</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/override_for_group.png"><img class="alignnone size-medium wp-image-223" title="override_for_group" src="http://bradstechblog.com/wp-content/uploads/2008/09/override_for_group-300x123.png" alt="" width="300" height="123" /></a></p>
<ul>
<li>Start to type the name of the group you created and select it.<br />
<a href="http://bradstechblog.com/wp-content/uploads/2008/09/selectgroup.png"><img class="alignnone size-medium wp-image-225" title="selectgroup" src="http://bradstechblog.com/wp-content/uploads/2008/09/selectgroup-274x300.png" alt="" width="274" height="300" /></a></li>
<li>Place a check beside &#8220;Parameter name&#8221;. Change the override setting to True. This will enable the rule for the group.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/overrideproperties.png"><img class="alignnone size-medium wp-image-224" title="overrideproperties" src="http://bradstechblog.com/wp-content/uploads/2008/09/overrideproperties-289x300.png" alt="" width="289" height="300" /></a></p>
<ul>
<li>Say OK to save.</li>
</ul>
<p><strong>STEP 5: Create Recovery Task</strong></p>
<ul>
<li>In the Authoring Pane right click on monitors and select the monitor you created by right clicking on it and select properties.</li>
<li>Click on the Diagnostic and Recovery Tab</li>
<li>Under the configure recovery Tasks select Add&#8230; and choose &#8220;Recovery for Critical Health State&#8221;<br />
<a href="http://bradstechblog.com/wp-content/uploads/2008/09/select-task.png"><img class="alignnone size-medium wp-image-226" title="select-task" src="http://bradstechblog.com/wp-content/uploads/2008/09/select-task-300x290.png" alt="" width="300" height="290" /></a></li>
<li>Select Run command</li>
<li>Provide a meaningful name and description</li>
<li>Select the recovery target as Windows server operating system</li>
<li>Check run recovery automatically and recalculate monitor state.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0011.png"><img class="alignnone size-medium wp-image-227" title="task name and description" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0011-300x269.png" alt="" width="300" height="269" /></a></p>
<ul>
<li>Next, for the full path to the file type C:\WINDOWS\system32\net.exe This will spawn the net command</li>
<li>for the parameters type start service name. We are starting windows update service. Here is the best way to find the service name. Open services by opening the run box and type services.msc</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/services-window.png"><img class="alignnone size-medium wp-image-228" title="services-window" src="http://bradstechblog.com/wp-content/uploads/2008/09/services-window-300x238.png" alt="" width="300" height="238" /></a></p>
<ul>
<li>now that you have the actual service name lets enter it in the parameters field. so you would type &#8220;Start wuauserv&#8221;</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0013.png"><img class="alignnone size-medium wp-image-229" title="Task command line settngs" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0013-300x271.png" alt="" width="300" height="271" /></a></p>
<ul>
<li>Once you have clicked on create you are done.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-create-a-recovery-task-in-scom-on-a-windows-service/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>How to Remove Management Pack Dependencies</title>
		<link>http://bradstechblog.com/scom/how-to-remove-management-pack-dependencies</link>
		<comments>http://bradstechblog.com/scom/how-to-remove-management-pack-dependencies#comments</comments>
		<pubDate>Thu, 14 Aug 2008 07:46:57 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[dependencies]]></category>
		<category><![CDATA[Management Pack]]></category>
		<category><![CDATA[System Centre Operations Manager]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=102</guid>
		<description><![CDATA[When you create an override and don&#8217;t save it to a custom Management Pack it will by default save to the Microsoft.SystemCenter.OperationsManager.DefaultUser.xml management pack. This will later on bite you in the ass when you want to remove the effected management pack. To avoid this of coarse you should always save changes to a custom [...]]]></description>
			<content:encoded><![CDATA[<p>When you create an override and don&#8217;t save it to a custom Management Pack it will by default save to the Microsoft.SystemCenter.OperationsManager.DefaultUser.xml management pack. This will later on bite you in the ass when you want to remove the effected management pack. To avoid this of coarse you should always save changes to a custom management pack&#8230;..</p>
<p> <!-smartads-></p>
<p><span id="more-102"></span></p>
<p>But if you did not like all the rest of have done at least once, then here is how you can remove the dependencies. But first please backup you management packs.</p>
<ol>
<li>Download and install Microsoft&#8217;s <a title="XML Notepad" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=72D6AA49-787D-4118-BA5F-4F30FE913628&amp;displaylang=en" target="_blank">XML Notepad</a></li>
<li>Export the Default management pack to any folder you like. This will export it into an XML file. Back this file up before making changes to it.</li>
<li>Open the XML file in XML Notepad</li>
<li>Expand the management pack in the left window to \\managmentPack\Manifest\References </li>
</ol>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/08/image-0321.png"><img class="alignnone size-medium wp-image-103" title="XML Notepad" src="http://bradstechblog.com/wp-content/uploads/2008/08/image-0321-300x259.png" alt="" width="300" height="259" /></a></p>
<ol>
<li>Look in each sub-folder named Reference for the Management pack that you are trying to remove. Once you find it Delete the Reference folder.</li>
<li>Import the Default XML file back into the console.</li>
<li>Try to delete the management pack again.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-remove-management-pack-dependencies/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>ASP.net causes reporting services and prerequisite to fail</title>
		<link>http://bradstechblog.com/scom/aspnet-causes-reporting-services-and-pre-requisite-to-fail</link>
		<comments>http://bradstechblog.com/scom/aspnet-causes-reporting-services-and-pre-requisite-to-fail#comments</comments>
		<pubDate>Tue, 29 Jul 2008 14:28:32 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[SQL Reporting Services]]></category>
		<category><![CDATA[asp]]></category>
		<category><![CDATA[ASP.net]]></category>
		<category><![CDATA[aspnet_regiis]]></category>
		<category><![CDATA[prerequisite]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[System Centre Operations Manager]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=30</guid>
		<description><![CDATA[It appears that if IIS is installed before ASP then there are possible challenges with either the initial install of OpsMgr and/or the setup of reporting services. I have had two occasions where this has happened.  In both cases I performed the exact same fix to resolve this.      Symptom 1: During the pre-requisite [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">It appears that if IIS is installed before ASP then there are possible challenges with either the initial install of OpsMgr and/or the setup of reporting services. I have had two occasions where this has happened. <span style="mso-spacerun: yes"> </span>In both cases I performed the exact same fix to resolve this. <span style="mso-spacerun: yes"> </span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"> <span id="more-30"></span> </p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">Symptom 1: During the pre-requisite check you receive notification that ASP.net is not started but the service is running.</span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">Symptom 2: During setup you receive the “<strong><span style="color: #424242;">srs server validation” error </span></strong><span style="mso-spacerun: yes"> </span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">To fix this </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;"> </span></span></p>
<ul style="MARGIN-TOP: 0in" type="disc">
<li class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">Of course confirm that ASP is installed. If it is then do the following.</span></span></li>
<li class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">Open the command prompt go to </span></span></li>
</ul>
<blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">C:\windows\Microsoft.NET\Framework\v2.0.50727</span></span></p>
</blockquote>
<ul style="MARGIN-TOP: 0in" type="disc">
<li class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">Run the following command </span></span></li>
</ul>
<blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;">aspnet_regiis /i</span></span></p>
</blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"> </p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"> </p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;"><a href="http://bradstechblog.com"></a></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"><span style="FONT-SIZE: 12pt"><span style="FONT-SIZE: 12pt"><span style="font-family: Times New Roman;"><a href="http://bradstechblog.com"></a></span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/aspnet-causes-reporting-services-and-pre-requisite-to-fail/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Promoting MS to RMS : USE WITH CAUTION!!</title>
		<link>http://bradstechblog.com/scom/promoting-ms-to-rms-use-with-caution</link>
		<comments>http://bradstechblog.com/scom/promoting-ms-to-rms-use-with-caution#comments</comments>
		<pubDate>Mon, 28 Jul 2008 15:08:38 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Centre Operations Manager]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=13</guid>
		<description><![CDATA[If you haven&#8217;t had the pleasure of testing the promotion of a management server (MS)  to be a root management server (RMS) and then back again in the event of a RMS failure then this is  a must read. After I implementing Microsoft&#8217;s System Center Operation&#8217;s Manager 2007 (SCOM) into our environment I wanted to test [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> If you haven&#8217;t had the pleasure of testing the promotion of a management server (MS)  to be a root management server (RMS) and then back again in the event of a RMS failure then this is  a must read. </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">After I implementing Microsoft&#8217;s System Center Operation&#8217;s Manager 2007 (SCOM) into our environment I wanted to test the disaster recovery process. Our design is using an RMS and one MS. The test was meant to be simple and I of course didn&#8217;t think to create another test environment for this. *what an idiot*</span></p>
<p><!-smartads-></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">To prove that the steps provided by Microsoft worked I unplugged the RMS and prompted the MS server. Hey this worked like a charm. It was the next step that really got ugly, the next step of course was when I brought the RMS back on-line. Because that is the goal in the end right. To restore the original server. Somewhere </span><span style="font-size: small; font-family: Times New Roman;">I missed a step. And before you know it I was rebuilding the entire environment. I was fairly sure that I hadn&#8217;t really missed anything. But I screw up so often who really knows for sure? I then created that test environment that ignored the first time and tried it again. Hey what do you know I had the same results. Then for the third test I opened up a Microsoft support call and had them help me do it right, and again the same results. The Microsoft support tech confessed to me that in there training they only test the promotion . They didn&#8217;t actually try to go back to the original solid state. </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">After a couple of days he for-wards me an internal email from Microsoft that talks about the process and how to avoid this issue. </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">Read on to see the risk assessment and the detailed steps of how to demote and promote</span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span id="more-13"></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<h2 class="MsoNormal" style="MARGIN: 0in 0in 0pt">Risk assessment of promotion</h2>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">The Root management server (RMS) is the primary SCOM server that is responsible for sending alerts out to a pager. It is also the server that needs to be running in order to access the alerts window within SCOM.</span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">If the RMS fails, the Management Server (MS) will continue to accept the alerts from the agents (client servers that are being monitored). However, the MS will only collect alerts. It will not provide access to the Console to view alerts, nor will it send alerts to pager or email. The result of this is that all alerting will stop until there is a RMS in the environment again. </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;"><span style="font-family: Times New Roman;">Options</span></span></strong></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;">In our environment, we have three options to handle the RMS to MS fail-over. </span></p>
<ol>
<li>
<div class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span><span style="font-size: small; font-family: Times New Roman;"><strong>Don’t promote the MS server. Fix the RMS and bring it back on-line.</strong> </span></div>
</li>
</ol>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><span style="font-size: small; font-family: Times New Roman;">During the outage of the RMS server there will be no indication of other service failures in the environment. We would be relying on the business to notify us through the Service Desk.</span><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<ol style="MARGIN-TOP: 0in" type="1">
<li class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo2; tab-stops: list .5in"><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;"><span style="font-family: Times New Roman;">Promote the MS to RMS</span></span></strong></li>
</ol>
<blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes"> </span><span style="mso-tab-count: 1"> Benefit: </span>This will provide Alerting and console access.</span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span><span style="font-size: small; font-family: Times New Roman;">I have documented and tested the promotion and demotion of RMS servers in our environment. If the steps are followed exact then there should not be an issue. </span><a href="http://bradstechblog.com/Server%20Support/Microsoft/IOP/SCOM/SCOM%20-%20%20Disaster%20Recovery%20-%20Moving%20the%20Root%20Mgmt%20Server%20Role%20in%20Operations%20Manager%202007.doc"><span style="font-size: small; font-family: Times New Roman;"><strong></strong></span></a></p>
</blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><span style="font-size: small; font-family: Times New Roman;">However, if the procedure is not followed exactly it would mean <strong>a complete loss of the SCOM environment</strong>. The database may need to be rebuilt and the agents would need to be redeployed to all servers. The SCOM servers would need to be rebuilt from scratch. </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><span style="font-size: small; font-family: Times New Roman;">The following note is from an internal Microsoft memo that was provided to us during Microsoft support call. This is not included in the official MS documentation. There is the risk that an analyst that responds to this type of incident might consult the official documentation and not complete the fail-over properly.</span><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p><!-smartads-></p>
<blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><em style="mso-bidi-font-style: normal"><span style="font-size: 8pt; font-family: Arial;">NOTE: You do NOT want the previous RMS to still be an RMS when it comes back up or becomes reachable again (network back up), as both RMS&#8217;s will compete for the DB&#8217;s attention, which is not a healthy state.<span style="mso-spacerun: yes"> </span>If you do get in this state (old RMS not demoted, back in contact with DB), the correct fix is to demote that old/previous RMS first, as indicated above.</span></em></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><em style="mso-bidi-font-style: normal"><span style="font-size: 8pt; font-family: Arial;">Do not try to demote the new RMS, as you will end up with no RMS indicated in the DB, and would likely have no way to recover the Management Group.<span style="mso-spacerun: yes"> </span>If you want to set the previous RMS back to the current RMS, demote it first, then re-promote it, which will then automatically demote the existing RMS.</span></em><em style="mso-bidi-font-style: normal"><span style="font-size: 8pt; font-family: Arial;"> </span></em></p>
</blockquote>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><span style="font-size: small; font-family: Times New Roman;">The promotion should be used only as the last resort and only in the case where there is no other way to restore the original RMS.</span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<ol style="MARGIN-TOP: 0in" type="1">
<li class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo2; tab-stops: list .5in"><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;"><span style="font-family: Times New Roman;">Upgrade the SCOM environment to a Cluster. (The best option but the most costly)</span></span></strong><span style="font-size: small; font-family: Times New Roman;"> </span></li>
</ol>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"><span style="font-size: small; font-family: Times New Roman;">Clustered SCOM environment would ascertain stability of the SCOM environment and eliminate its single point of failure. It would also eliminate the need for the shaky promoting procedure described in item 2. </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">
<h2 class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">How to demote the Root Management Server so that you can promote it again later.</h2>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">
<h2 style="MARGIN: auto 0in"><span style="FONT-SIZE: 14pt; mso-bidi-font-size: 18.0pt"><span style="font-family: Times New Roman;">The following 3 steps need to happen to promote the Management server. </span></span></h2>
<h2 style="MARGIN: auto 0in"><span style="font-family: Times New Roman;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; mso-bidi-font-weight: bold"><span style="mso-list: Ignore">1.<span style="font-family: 'Times New Roman';"> </span></span></span><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; mso-bidi-font-weight: bold">Backup the key on the current RMS to a file share using SecureStorageBackup tool</span></span></h2>
<h2 style="MARGIN: auto 0in auto 0.25in; TEXT-INDENT: -0.25in; mso-list: l3 level1 lfo1; tab-stops: list .25in"><span style="font-family: Times New Roman;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; mso-bidi-font-weight: bold"><span style="mso-list: Ignore">2.<span style="font-family: 'Times New Roman';"> </span></span></span><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; mso-bidi-font-weight: bold">import the key to the MS to be promoted to RMS from the file share</span></span></h2>
<h2 style="MARGIN: auto 0in auto 0.25in; TEXT-INDENT: -0.25in; mso-list: l3 level1 lfo1; tab-stops: list .25in"><span style="font-family: Times New Roman;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; mso-bidi-font-weight: bold"><span style="mso-list: Ignore">3.<span style="font-family: 'Times New Roman';"> </span></span></span><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; mso-bidi-font-weight: bold">Run the management server config tool on the new RMS to promote it</span></span></h2>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list .25in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">1.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;">Backup the key on the current RMS to a file share</span></strong></span></p>
<p style="MARGIN-LEFT: 0.25in"><strong><span style="font-size: small; font-family: Times New Roman;">To run the SecureStorageBackup.exe Tool</span></strong></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">On the current Root Management Server</span></p>
<p style="MARGIN-LEFT: 0.75in; TEXT-INDENT: -0.25in; mso-list: l3 level2 lfo1; tab-stops: list .75in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">a.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal">Copy</strong><span style="mso-spacerun: yes"> </span></span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span class="UserInputNon-localizable"><strong>SecureStorageBackup.exe</strong></span> and <span class="UserInputNon-localizable"><strong>ManagementServerConfigTool.exe</strong></span> from</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">\ Ops_SP1Rc1\SupportTools.</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">To</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="TEXT-INDENT: 0.5in"><strong><span style="font-size: small; font-family: Times New Roman;"> b</span><span style="font-size: small;"><span style="font-family: Times New Roman;">. Open a command line and navigate to </span></span></strong></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"> <strong>c</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Run the following command:<br style="mso-special-character: line-break" /></strong><br style="mso-special-character: line-break" /></span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span class="UserInputNon-localizable"><strong>SecureStorageBackup Backup<span style="mso-spacerun: yes"> </span></strong></span>&#8220;Network Path\SCOM_Key_backup\SCOMKEY.bin&#8221;</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">This key must be available to the machine you want to promote.</span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"><strong> d</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Provide a password</strong> </span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;">to secure the key and retype the password. The password must be eight characters long. Once the key is exported, you will see a success message.</span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><strong style="mso-bidi-font-weight: normal"><span style="FONT-SIZE: 14pt; mso-bidi-font-size: 12.0pt"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list .25in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">2.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;">Import Key to the current MS</span></strong></span></p>
<p><strong><span style="font-size: small; font-family: Times New Roman;">On the Management Server you want to promote to become the Root Management Server</span></strong></p>
<p style="MARGIN-LEFT: 0.75in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo3; tab-stops: list .75in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">a.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><span style="font-size: small;"><strong style="mso-bidi-font-weight: normal">Copy</strong><span style="mso-spacerun: yes"> </span></span></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><span class="UserInputNon-localizable"><strong>SecureStorageBackup.exe</strong></span> and <span class="UserInputNon-localizable"><strong>ManagementServerConfigTool.exe</strong></span> from</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"> Ops_SP1Rc1\SupportTools.</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">To</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"><strong> b</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Open</strong> <strong>a command line and navigate to</strong> </span></span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"> <strong>c</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Run</strong> <strong>the following command:<br style="mso-special-character: line-break" /><br style="mso-special-character: line-break" /></strong></span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span class="UserInputNon-localizable"><strong>SecureStorageBackup Restore<span style="mso-spacerun: yes"> </span></strong></span>&#8220;Network Parch\SCOM_Key_backup\SCOMKEY.bin&#8221;</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"><strong>d. Provide password used</strong> to access the key and retype the password again. Once the key is exported, you see a success message.</span></p>
<p><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list .25in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">3.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong><span style="font-size: small;">On the Management Server you want to promote to become the Root Management Server</span></strong></span></p>
<p style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo4; tab-stops: list .5in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;"> a.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;">Copy</span></strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes"> </span><span class="UserInputNon-localizable"><strong>SecureStorageBackup.exe</strong></span> and <span class="UserInputNon-localizable"><strong>ManagementServerConfigTool.exe</strong></span> from</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">\Ops_SP1Rc1\SupportTools.</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">To</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p><span style="font-size: small; font-family: Times New Roman;"> </span><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;"><span style="font-family: Times New Roman;">b. Open a command line and navigate to </span></span></strong></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"><strong> c</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Run the following command:<br style="mso-special-character: line-break" /><br style="mso-special-character: line-break" /></strong></span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span class="UserInputNon-localizable"><span style="font-size: x-small; font-family: Arial;">ManagementServerConfigTool.exe PromoteRMS</span></span></p>
<blockquote>
<p style="MARGIN-LEFT: 0.5in"><span style="color: #ff0000;"><strong><span style="font-size: small;"><span style="font-family: Times New Roman;">If the Current RMS is currently on-line and reachable you are done. This will automatically update and demote the RMS to a MS. If not it is critical to complete ALL the following steps.</span></span></strong></span></p>
</blockquote>
<p style="MARGIN-LEFT: 0.5in"><strong style="mso-bidi-font-weight: normal"></strong></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal">d. </strong>Go to the promoted Root Management Server, open the services and stop the Ops HealthService.</span></span></p>
<p style="MARGIN-LEFT: 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo4; tab-stops: list 1.0in"><span style="font-family: Times New Roman;"><span style="mso-list: Ignore"><span style="font-size: small;">a.</span><span style="font-family: 'Times New Roman';"> </span></span><span style="font-size: small;">Go to the installation directory (default: %ProgramFiles%\System Center Operations Manager 2007) and delete the Health Service State folder.</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>e</strong>. Start the MOM Health Service.</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal">f.</strong> When you open the Operations Console the first time, specify the name of the new Root Management Server to connect to.</span></span></p>
<p style="margin-left: 0.25in; text-indent: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list .25in;"><strong><span style="font-family: Times New Roman;"><span style="mso-list: Ignore;"><span style="font-size: small;">4.</span><span style="font-family: 'Times New Roman';"> </span></span><span style="font-size: small;">Demote the Original RMS server when it is back on-line. This needs to be done before it can be promoted back to RMS.</span></span> </strong></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">a.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;">Copy</span></strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes"> </span><span class="UserInputNon-localizable"><strong>SecureStorageBackup.exe</strong></span> and <span class="UserInputNon-localizable"><strong>ManagementServerConfigTool.exe</strong></span> from</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">\ Ops_SP1Rc1\SupportTools.</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">To</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p><span style="font-size: small; font-family: Times New Roman;"> <strong>b</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Open a command line and navigate to </strong></span></span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"> </span><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;"><span style="font-family: Times New Roman;">c. Run the following command:<br style="mso-special-character: line-break" /><br style="mso-special-character: line-break" /></span></span></strong></p>
<p style="MARGIN-LEFT: 0.5in"><span class="UserInputNon-localizable"><strong><span style="font-size: x-small; font-family: Arial;"> ManagementServerConfigTool.exe UpdateDemotedRMS</span></strong></span></p>
<blockquote>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"> </span><span style="font-size: small; font-family: Times New Roman;">After the Original RMS is back online you will need to promote it again</span></p>
</blockquote>
<p style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list .25in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;">5.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong><span style="font-size: small;">On the Management Server you want to promote to become the Root Management Server</span></strong></span></p>
<p style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo4; tab-stops: list .5in"><span style="font-family: Times New Roman;"><strong style="mso-bidi-font-weight: normal"><span style="mso-list: Ignore"><span style="font-size: small;"> a.</span><span style="font-family: 'Times New Roman';"> </span></span></strong><strong style="mso-bidi-font-weight: normal"><span style="font-size: small;">Copy</span></strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes"> </span><span class="UserInputNon-localizable"><strong>SecureStorageBackup.exe</strong></span> and <span class="UserInputNon-localizable"><strong>ManagementServerConfigTool.exe</strong></span> from</span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">\ Ops_SP1Rc1\SupportTools.</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">To</span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p><span style="font-size: small; font-family: Times New Roman;"> <strong> b</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Open a command line and navigate to </strong></span></span></p>
<p style="TEXT-INDENT: 0.5in"><span style="font-size: small; font-family: Times New Roman;">C:\Program Files\System Center Operations Manager 2007</span></p>
<p style="MARGIN-LEFT: 0.5in"><span style="font-size: small; font-family: Times New Roman;"><strong> c</strong></span><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>. Run the following command:<br style="mso-special-character: line-break" /><br style="mso-special-character: line-break" /></strong></span></span></p>
<p style="MARGIN-LEFT: 0.5in"><span class="UserInputNon-localizable"><span style="font-size: x-small;"><strong><span style="font-family: Arial;">ManagementServerConfigTool.exe PromoteRMS</span></strong></span></span></p>
<p class="TextinList1" style="MARGIN: 3pt 0in 3pt 0.25in"><span class="UserInputNon-localizable"><strong><span style="font-size: x-small; font-family: Arial;"> </span></strong></span></p>
<h1 style="MARGIN-LEFT: 0.5in">Final Steps</h1>
<h1 style="MARGIN-LEFT: 0.5in"><span style="font-size: small;"><span style="font-family: Times New Roman;">Go to the promoted Root Management Server, open the services and stop the Ops HealthService.</span></span></h1>
<ol>
<li>
<div style="margin-left: 1in; text-indent: -0.25in; mso-list: l0 level2 lfo4; tab-stops: list 1.0in;"><span style="font-family: Times New Roman;"><span style="mso-list: Ignore"><span style="font-family: 'Times New Roman';"> </span></span><span style="font-size: small;">Go to the installation directory (default: %ProgramFiles%\System Center Operations Manager 2007) and delete the Health Service State folder.</span></span></div>
</li>
<li>
<div style="margin-left: 1in; text-indent: -0.25in; mso-list: l0 level2 lfo4; tab-stops: list 1.0in;"><span style="font-size: small;"><span style="font-family: Times New Roman;"> Start the MOM Health Service.</span></span></div>
</li>
<li style="margin-left: 1in; text-indent: -0.25in; mso-list: l0 level2 lfo4; tab-stops: list 1.0in;"><span style="font-size: small;"><span style="font-family: Times New Roman;">When you open the Operations Console the first time, specify the name of the new Root  Management Server to connect to.</span></span></li>
</ol>
<p class="TextinList1" style="MARGIN: 3pt 0in 3pt 0.25in"><span class="UserInputNon-localizable"><strong><span style="font-size: x-small; font-family: Arial;"> </span></strong></span></p>
<p class="TextinList1" style="MARGIN: 3pt 0in 3pt 0.25in"><span style="color: #ff0000;"><strong><span style="font-size: x-small; font-family: Arial;">If the Current RMS is currently on-line and reachable you are done. This will automatically update and demote the RMS to a MS.</span></strong></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt">
<p style="MARGIN: 0in 0in 0pt">
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><a href="http://bradstechblog.com/"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/promoting-ms-to-rms-use-with-caution/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

