<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brad&#039;s Tech Blog</title>
	<atom:link href="http://bradstechblog.com/feed" rel="self" type="application/rss+xml" />
	<link>http://bradstechblog.com</link>
	<description>Microsoft technologies like: System Center Operations Manager, and whatever else comes up at the office.</description>
	<lastBuildDate>Sat, 13 Feb 2010 01:59:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SCOM &#8211; How to Create an override</title>
		<link>http://bradstechblog.com/scom/scom-how-to-create-an-override</link>
		<comments>http://bradstechblog.com/scom/scom-how-to-create-an-override#comments</comments>
		<pubDate>Wed, 16 Sep 2009 22:38:04 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[operationsmanger]]></category>
		<category><![CDATA[override]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=327</guid>
		<description><![CDATA[This article will show the basics of how to create an override
Never use the "Default Management Pack" it is selected by default]]></description>
			<content:encoded><![CDATA[<ul>
<li>
<div class="MsoNormal" style="margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 3;"> <span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Open the OpsMgrConsole, in the right pane select Monitoring and navigate to active alerts. </span></div>
</li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Right click on the alert you want to set an override for and select </span><strong><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 10.0pt;">Overrides\Override the Rule</span></strong>
<ul style="margin-top: 0in;" type="circle">
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level2 lfo2; tab-stops: list 1.0in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">You will have the choice of who or what the override is applied too.</span>
<ul style="margin-top: 0in;" type="square">
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">The current object as a whole. (For example, when you choose the Computer object, Operations Manager disables or overrides the rule for all computers).</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">A particular group.</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">A specific object of the current type (for Example, a specific computer on the network).</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">All objects of another type (such as Agent).</span></li>
</ul>
</li>
</ul>
</li>
</ul>
<p class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level3 lfo2; tab-stops: list 1.5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';"><span id="more-327"></span></span></p>
<ul>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">After you select the appropriate object you will see the override properties page. There may be as few as one rule to multiple rules that you can modify. Here you are going to need detailed knowledge about the technology that you are monitoring. </span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">At the bottom of this page you will need to select the management pack to save the override to. </span><strong><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 10.0pt;">DO NOT USE THE &#8220;DEFAULT MANAGMENT PACK&#8221;!</span></strong></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">If you don’t have a custom management pack to save it to you can create one from this window. Just follow the dialog boxes.</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l1 level1 lfo2; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">When you are done say ok and the changes will be saved. </span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">This article will show the basics of how to create an override</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">This will not show the values to use. For this product knowledge of the technology being monitored will be required as well as some research. </span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Never use the &#8220;Default Management Pack&#8221; it is selected by default, so be careful to change it to a custom management pack. This creates other potential problems later on. When installing OpsMgr service packs the &#8220;Default Management Pack&#8221; can be overwritten causing us to lose all changes.</span></li>
<li class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"><span style="font-family: 'Arial','sans-serif'; font-size: 9pt; mso-fareast-font-family: 'Times New Roman';">Never disable a monitor. This can be done as an override. When you disable a monitor it is automatically saved to the &#8220;Default Management Pack&#8221;.</span></li>
</ul>
<p> </p>
<p class="MsoNormal" style="margin: 3pt 0in; mso-list: l2 level1 lfo1; tab-stops: list .5in;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/scom-how-to-create-an-override/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to move the Operations Manager 2007 Reporting Server</title>
		<link>http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server</link>
		<comments>http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server#comments</comments>
		<pubDate>Thu, 30 Apr 2009 22:47:35 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[reporting]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server</guid>
		<description><![CDATA[The download able pdf has the complete steps that I took to perform a successful move of our opsmgr reporting server to a new server separate from the Data Warehouse.
how-to-move-the-operations-manager-2007-reporting-server

]]></description>
			<content:encoded><![CDATA[<p>The download able pdf has the complete steps that I took to perform a successful move of our opsmgr reporting server to a new server separate from the Data Warehouse.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/04/how-to-move-the-operations-manager-2007-reporting-server.pdf">how-to-move-the-operations-manager-2007-reporting-server</a></p>
<p><!--smartads--></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-move-the-operations-manager-2007-reporting-server/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to move the OperationsManager Data Warehouse Database to a new SQL server</title>
		<link>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server</link>
		<comments>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server#comments</comments>
		<pubDate>Wed, 29 Apr 2009 18:36:19 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[move]]></category>
		<category><![CDATA[operationsmanger]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=303</guid>
		<description><![CDATA[I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers.
the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all three [...]]]></description>
			<content:encoded><![CDATA[<p>I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers.</p>
<p>the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all three manuals that I have created out of this here.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/04/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server.pdf">how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server</a></p>
<p><!--smartads--></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-data-warehouse-database-to-a-new-sql-server/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to move the OperationsManager DataBase to a new SQL server</title>
		<link>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-database-to-a-new-sql-server</link>
		<comments>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-database-to-a-new-sql-server#comments</comments>
		<pubDate>Wed, 29 Apr 2009 18:11:55 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[SQL Reporting Services]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[move]]></category>
		<category><![CDATA[operationsmanger]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=297</guid>
		<description><![CDATA[I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers.
the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all three [...]]]></description>
			<content:encoded><![CDATA[<p>I am currently testing with moving the OperationsManger database, OperationsMangerDW database, and the reporting services role to new servers.</p>
<p>the two databases will be moved to a new SQL server under a new name. And the reporting services role will be moved to its own server serperate from the SQL server. I will post all three manuals that I have created out of this here.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/04/how-to-move-the-operationsmanager-database-to-a-new-sql-server.pdf">how-to-move-the-operationsmanager-database-to-a-new-sql-server</a></p>
<p><!-smartads-></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-move-the-operationsmanager-database-to-a-new-sql-server/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to create a SCOM Windows Events Monitor and alert on the Description field</title>
		<link>http://bradstechblog.com/scom/how-to-create-a-scom-windows-events-monitor-and-alert-on-the-description-field</link>
		<comments>http://bradstechblog.com/scom/how-to-create-a-scom-windows-events-monitor-and-alert-on-the-description-field#comments</comments>
		<pubDate>Tue, 17 Feb 2009 21:01:34 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[monitor description]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=285</guid>
		<description><![CDATA[When creating a monitor that alerts on event logs you may want to be able to monitor based on key words in the description field. This is not a default parmater and needs a few extra steps. But is still very easy to accomplish once you now the steps.
here are the two variables you will [...]]]></description>
			<content:encoded><![CDATA[<p>When creating a monitor that alerts on event logs you may want to be able to monitor based on key words in the description field. This is not a default parmater and needs a few extra steps. But is still very easy to accomplish once you now the steps.</p>
<p>here are the two variables you will be adding to the monitor</p>
<p>parameter name: EventDescription</p>
<p>Alert description: $Data/EventDescription$<br />
<!--smartads--><br />
<span id="more-285"></span></p>
<p>1. When you are creating the Event Expression click on insert, then click on button &#8220;&#8230;: under parameter name</p>
<p>2. Select <strong>Use Parameter Name not specified above</strong> and enter <strong>EventDescription</strong></p>
<div id="attachment_287" class="wp-caption alignnone" style="width: 310px"><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0117.png"><img class="size-medium wp-image-287" title="image-0117" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0117-300x295.png" alt="Select an Event Property-EventDescription" width="300" height="295" />$Data/EventDescription$</a><p class="wp-caption-text">Select an Event Property-EventDescription</p></div>
<p>3. change your operator to <strong>Contains</strong><img src="file:///C:/Temp/moz-screenshot.jpg" alt="" /><strong> </strong></p>
<p>4. under the Value, enter the words you want to find in the desction field.</p>
<div id="attachment_288" class="wp-caption alignnone" style="width: 310px"><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0118.png"><img class="size-medium wp-image-288" title="image-0118" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0118-300x201.png" alt="Build Event Expresion - operator and value" width="300" height="201" /></a><p class="wp-caption-text">Build Event Expresion - operator and value</p></div>
<blockquote><p><strong>THIS IS NOT DONE!!!!</strong></p></blockquote>
<p>5. Continue to build your rule until you arrive at the Configure Alerts page. Enter the value <strong>$Data/EventDescription$</strong> in the <strong>Alert description</strong> window. If you do not you will receive errors.</p>
<blockquote><p><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0119.png"><img class="alignnone size-medium wp-image-289" title="Configure Alerts - $Data/EventDescription$" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0119-300x297.png" alt="" width="300" height="297" /></a></p></blockquote>
<p>6. Create the rule, and refresh how ever you like. When i am in a hurry i will restart the health service on the server that I am monitoring.</p>
<p>7. To test your rule the OpsMgr Event Creator tool is not going to work. It does not allow you to create custom descriptions. Log onto the server that you want to monitor and open a command window. Using the eventcreate command type the following</p>
<blockquote><p>eventcreate /t error /ID 1000/d &#8220;fieldxu.exe THIS IS JUST A TEST BY Brad Hearn&#8221;</p>
<p>/t sets as an error</p>
<p>/ID is the event id</p>
<p>/d is what will be placed into the description field. Remeber to place quotes around your text.</p></blockquote>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0120.png"><img class="alignnone size-medium wp-image-291" title="image-0120" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0120-300x61.png" alt="" width="300" height="61" /></a></p>
<p>The alerts will look something like this.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2009/02/image-0121.png"><img class="alignnone size-medium wp-image-292" title="image-0121" src="http://bradstechblog.com/wp-content/uploads/2009/02/image-0121-267x300.png" alt="" width="267" height="300" /></a></p>
<p>Hope this helps out.</p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-create-a-scom-windows-events-monitor-and-alert-on-the-description-field/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Deploying SCOM Gateway server</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server</link>
		<comments>http://bradstechblog.com/scom/deploying-scom-gateway-server#comments</comments>
		<pubDate>Wed, 12 Nov 2008 21:17:23 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[netsh]]></category>
		<category><![CDATA[SCOM; Gateway]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=246</guid>
		<description><![CDATA[
Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server
Certificates need to be deployed (2 types of certificates)
The root CA needs to be installed on all management servers
A custom cert template needs to be created on the issuing CA for OpsMGR
The Custom [...]]]></description>
			<content:encoded><![CDATA[<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server</li>
<li class="MsoNormal">Certificates need to be deployed (2 types of certificates)</li>
<li class="MsoNormal">The root CA needs to be installed on all management servers</li>
<li class="MsoNormal">A custom cert template needs to be created on the issuing CA for OpsMGR</li>
<li class="MsoNormal">The Custom OpsMgr cert needs to be installed on all management servers</li>
<li class="MsoNormal">Run the momcertimport on all management server after the certs have been installed. This makes some specific registry changes for scom to help pick the correct cert.</li>
<li class="MsoNormal">Approve gateway server on RMS using a approval tool.</li>
<li class="MsoNormal">Manual install of agents on servers to be monitored</li>
<li class="MsoNormal">Approve agents in SCOM console</li>
</ol>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Download the PDF <a href="http://bradstechblog.com/wp-content/uploads/2008/11/deploying-scom-gateway-server2.pdf">deploying-scom-gateway-server2</a></p>
<p class="MsoNormal"> </p>
<p><!--martad--></p>
<p class="MsoNormal"><span id="more-246"></span></p>
<p class="MsoNormal"> </p>
<h3><a name="_Open_and_test"></a>Open and test ports</h3>
<p class="MsoNormal">Put a change request into the Network group to open TCP port 5723 both ways from the Gateway server to the MS server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">To test if the ports are open. Log on to gateway server. From a command prompt type</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><strong>telnet SRVNAME261 5723</strong></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">If you get a cursor at the top left corner then the port is open. Any other errors indicate that the port is still closed.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Do the same from the management server back to the gateway server.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><a name="_Import_a_trusted"></a></p>
<p class="MsoNormal"> </p>
<h3><a name="_Certificates_need_to"></a>Certificates need to be deployed (2 types of certificates)</h3>
<p class="MsoNormal"> </p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Root_certificate"></a><!--if !supportLists--><span><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Root certificate</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the root certificate for the management servers on the same domain as the CA server</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Logon on the management server. Open a web Brower and navigate to <span style="color: #000000; text-decoration: none;">http://SRVNAME342/certsrv/</span></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Download a CA certificate, certificate chain, or CRL</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Download CA Certificate chain</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on save. And save to a location of your choice. The default file name is certnew.p7b. This is fine. (you can use this cert for all your management servers and gateway server to skip the initial download on this servers if you like.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->To import the downloaded cert open the certificate MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on “Trusted Root Certification Authorities”</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->When the wizard opens navigate to the downloaded cert is certnew.p7b . You will need to change the file type to PKCS #7</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Accept the defaults and finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Do this on all management servers inside the domain</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the root certificate for the Gateway server that is not attached to the domain as the CA server.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Perform step one above to save certnew.p7b. Or use the same cert that was downloaded above. And copy to the gateway server. Then perform step 2 above.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Create_the_Custom"></a><!--if !supportLists--><span><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Create the Custom OpsMgr Certificate</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->To create the cert. We will use two consoles to do this. Certification Authority mmc and certificate templates mmc</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificate Templates and Certification Authority, and click on add again. And finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select Certificate Templates</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->In the Certificate Templates Console right click <strong>IPSec (Offline request)</strong> and then select <strong>duplicate template</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->General Tab</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Type a name</p>
<p class="MsoNormal" style="margin-left: 99pt;">Request Handling</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select <strong>Allow private key to be exported</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>CSPs…</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select Microsoft RSA SChannel Cryptographic provider for windows 2003 and Microsoft Enhanced Cryptographic provider 1.0 for windows 2000</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Extensions Tab</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->select the Applications Policies and click on edit</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->remove <strong>IP security IKE intermediate</strong></p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on add..</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>Client Authentication and Server Authentication</strong>, and clink on ok twice.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Security Tab</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>1.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Users should have read</p>
<p class="MsoNormal" style="margin-left: 1.75in; text-indent: -0.25in;"><!--if !supportLists--><span>2.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Say ok and close.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Add_the_new"></a><!--if !supportLists--><span><span>3.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Add the new custom cert to the certificate authority</h3>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open the Certification Authority mmc console</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand it and right click on certificate templates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select new, certificate template to issue</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Scroll through the list until you find the one you just created. Select it and say ok.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->It should now show in the right window.</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Deploy_the_Custom"></a><!--if !supportLists--><span><span>4.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Deploy the Custom OpsMgr Certificate to the management servers on the same domain as the CA (need to do the full steps individually for each server)</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Logon on the management server. Open a web Brower and navigate to http://SRVNAME342/certsrv/</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Request a certificate</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Create and submit a request to this CA</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select the custom Template</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>e.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter a name for the template. This is the full unc name of the server that you are going to install the cert on.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>f.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter the rest of the identity info if you like.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>g.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Under Key options select the csp that fits your operating system. select Microsoft RSA SChannel Cryptographic provider for windows 2003 and Microsoft Enhanced Cryptographic provider 1.0 for windows 2000</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>h.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Key size 1024</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Mark keys as exportable</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>j.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Check off <strong>Store cert in local computer cert store…</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>k.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Use full unc path as friendly name.</p>
<p class="MsoNormal" style="margin-left: 0.75in;"> </p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>l.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on submit, say yes.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>m.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on <strong>Install this certificate</strong></p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>n.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>o.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>p.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>q.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>r.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>s.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>t.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You should see the new cert here.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"> </p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"> </p>
<p><!--martad--></p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><!--if !supportLists--><span><span>5.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Deploy the custom Certificate to the Gateway sever in the DMZ.</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Because the gateway is not part of the same domain as the CA. We need to create the certificate on a different server and export it to a usb drive or other storage device. Then manually copy it to the gateway server and import it.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->First create the cert from a server on the same domain as the CA. <a href="#_Deploy_the_Custom">Follow the steps in step 4 first</a>.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Next we will export the cert</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You should see the new cert here.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Right click on the cert and select <strong>All tasks, export</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->The export wizard will open, say next</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>x.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>Yes, export private key</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>enable strong protection</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Enter a password for the import. You will need this password when you export the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xiii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Specify a location and name to save it too.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xiv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->And finish</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Import the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy the cert to the gateway server. It will have a .pfx extension.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open run and type MMC</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on file, add/remove snap-in</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>iv.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Click on Add and select Certificates, and click on add again.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>v.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select computer account and say finish</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Close the window and say ok to the add remove window.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>vii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Expand certificates and right click on Personal certificates</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>viii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>All tasks, Import</strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ix.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Browse to the cert you coppied over. You will need to change the file type to PFX to see the cert.</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>x.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Select <strong>open, say next, enter password. </strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xi.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Check off <strong>Mark this key as exportable. </strong></p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>xii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Say next, make sure the certificate store is <strong>personal</strong> , click next and finish.</p>
<p class="MsoNormal" style="margin-left: 99pt;"> </p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Run_the_momcertimport"></a><!--if !supportLists--><span><span>6.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Run the momcertimport utility</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->In this step we are going to use the same pfx certificate (the custom personal cert) that we created in step 4.<span> </span>This tool writes the certificate serial number to the registry. This will help OpsMgr components find the the proper certificate for authenticatin easily.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->You will find the momcertimport utility on the install cd under supporttools\i386.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy momcertimport.exe and the pfs certificate into the same folder.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open a command prompt, navigate to the folder with both files and type the following command</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->C:\&gt;MOMCertImport.exe certfilename.pfx</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>ii.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->There is NO response after the command is successfully initiated.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>e.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->So this on all SCOM management servers. RMS, MS, and Gateway</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Approve_the_Gateway"></a><!--if !supportLists--><span><span>7.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Approve the Gateway Server</h3>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>a.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->We will use the gateway approval tool to achieve this. This will setup the gateway server as a management server in SCOM. Once done you can confirm this by looking in the SCOM console under administration, Device Management, Management Servers.</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>b.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->The tool has to be run from c:\program Files\System Center Operations Manager 2007</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>c.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Copy Microsoft.EnterpriseManagement.GatewayApprovalTool.exe from the support tools directory to c:\program Files\System Center Operations Manager 2007</p>
<p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"><!--if !supportLists--><span>d.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->Open the command prompt and type the following command</p>
<p class="MsoNormal" style="margin-left: 99pt; text-indent: -99pt;"><!--if !supportLists--><span>i.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span><!--endif-->microsoft.enterprisemanagement.gatewayapprovaltool.exe /managementservername=SRVNAME261.domainName.com /gatewayname=domainNamedmz22.domainNamedmz.com /action=create</p>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Next_you_now"></a><!--if !supportLists--><span><span>8.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Next you now ready to manually install the agents on the servers in the DMZ</h3>
<h3 style="margin-left: 0.25in; text-indent: -0.25in;"><a name="_Approve_the_agents"></a><!--if !supportLists--><span><span>9.<span style="font-family: &quot;Times New Roman&quot;; font-size-adjust: none; font-stretch: normal;"> </span></span></span><!--endif-->Approve the agents in the SCOM console.</h3>
<p class="MsoNormal"> </p>
<p class="MsoNormal" style="margin-left: 0.25in;"> </p>
<div class="MsoNormal" style="margin-left: 0.25in  mce_tmp="> &lt;&#8211;&gt;</div>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/deploying-scom-gateway-server/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Windows server 2000 and 2003: Time configuration for MaxPosPhaseCorrection and MaxNegPhaseCorrection</title>
		<link>http://bradstechblog.com/microsoft-windows-server/windows-server-2000-and-2003-time-configuration-for-maxposphasecorrection-and-maxnegphasecorrection</link>
		<comments>http://bradstechblog.com/microsoft-windows-server/windows-server-2000-and-2003-time-configuration-for-maxposphasecorrection-and-maxnegphasecorrection#comments</comments>
		<pubDate>Tue, 28 Oct 2008 19:20:08 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Microsoft windows server]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[MaxPosPhaseCorrection]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=239</guid>
		<description><![CDATA[The Windows Time service by default in Windows 2000 and 2003 allows for a positive or negative time correction of any amount for domain controllers. This can cause serious problems in a forest  should a dramatic time shift occur.]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">The Windows Time service by default in Windows 2000 and 2003 allows for a positive or negative time correction of any amount for domain controllers. This can cause serious problems in a forest  should a dramatic time shift occur. This can even occur when synchronizing with other authoritative sources as hardware problems, software problems or human error can cause them to provide the wrong time. Some of the problems that can occur from a dramatic time change are Windows Server 2003 based domain controllers may be quarantined, deleted objects may be prematurely purged before end-to-end replication of the deletion is fully replicated (causing lingering objects), user and computer passwords may expire unexpectedly, and trust passwords becoming out of sync. The amount of effort to recover from a dramatic time change can be significant. The registry key(s) are different depending upon the operating system version.</p>
<p style="text-align: left;">
<p><!-smartads-></p>
<p style="text-align: left;"><span id="more-239"></span></p>
<blockquote>
<p style="text-align: left;">Windows 2003/2008<br />
Path: HKLM\System\CurrentControlSet\Services\W32Time\Config<br />
Value: MaxPosPhaseCorrection<br />
Default data: 0xFFFFFFFF (4,294,967,295)<br />
(Note: there is an accompanying MaxNegPhaseCorrection value to control positive time changes.)</p></blockquote>
<p style="text-align: left;">
<blockquote>
<p style="text-align: left;">Windows 2000<br />
Path:<br />
HKLM\System\CurrentControlSet\Services\W32Time\Parameters<br />
Value: MaxAllowedClockErrInSecs<br />
Default data: 0xFFFFFFFF (4,294,967,295)<br />
(Note: Windows 2000 has a single value to control both positive and negative time changes.)</p></blockquote>
<p style="text-align: left;">The above values control the largest positive (and negative, for Windows 2000) time correction in seconds that the Windows Time service will allow. If a time change larger than these values is received the Windows Time service will reject it and log an error in the System event log. The default value for domain controllers is 0xFFFFFFFF, which effectively allows for any time change to be accepted.</p>
<p style="text-align: left;">The general recommendation is to use a lower value. The new default in Windows Server 2008 is a positive/negative value of 48 hours (0&#215;2A300 or 172,800 seconds). An even lower value can be used however the lower the value the more important operational processes and monitoring becomes since there is an increased chance of domain controllers rejecting time changes.</p>
<p style="text-align: left;">A GPO can also be used to manage the value. Windows 2003 and above natively include GPO settings to control the relevant Windows Time service values. A custom administrative template would be needed to manage Windows 2000 based domain controllers.</p>
<blockquote>
<p style="text-align: left;">For 2003 and above, the GPEditor exposes these settings under \Computer Configuration\Administrative Templates\System\Windows Time Service\Global Configuration Settings\.</p>
</blockquote>
<p style="text-align: left;">The values that should also be modified for Domain Controlers<br />
are below.</p>
<blockquote>
<p style="text-align: left;"><span style="text-decoration: underline;">Value name / Default value in GPEditor / Default for a DC</span></p>
<p style="text-align: left;">LargePhaseOffset / 1,280,000 / 50,000,000<br />
SpikeWatchPeriod / 90 / 900<br />
MaxPollInterval / 5 / 10<br />
MinPollInterval / 10 / 6<br />
UpdateInterval / 30,000 / 100<br />
PhaseCorrectRate / 1 / 7</p>
<p style="text-align: left;"><span style="text-decoration: underline;">Value name / Default value in GPEditor / New recomended value for a DC</span></p>
<p style="text-align: left;">MaxPosPhaseCorrection / 54000 / 172800</p>
<p style="text-align: left;">MaxNegPhaseCorrection / 54000 / 172800</p>
</blockquote>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">To veryify that the settings have been applied open your regisry editor and check the following Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\W32Time\Config</p>
<p style="text-align: left;">
<blockquote>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/microsoft-windows-server/windows-server-2000-and-2003-time-configuration-for-maxposphasecorrection-and-maxnegphasecorrection/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to create a Recovery task in SCOM on a windows service.</title>
		<link>http://bradstechblog.com/scom/how-to-create-a-recovery-task-in-scom-on-a-windows-service</link>
		<comments>http://bradstechblog.com/scom/how-to-create-a-recovery-task-in-scom-on-a-windows-service#comments</comments>
		<pubDate>Wed, 01 Oct 2008 17:34:58 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[OpsMgr]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[System Center Operations Manager]]></category>
		<category><![CDATA[Monitors]]></category>
		<category><![CDATA[Recovery Task]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=205</guid>
		<description><![CDATA[When you have the requirement to monitor a windows service through Microsoft&#8217;s System Center Operations Manger and have it restarted automatically you can not use the management pack templates. The reason for this is that the templates are stored in locked MP&#8217;s that you do not have access too.
Follow the following steps to monitor a [...]]]></description>
			<content:encoded><![CDATA[<p>When you have the requirement to monitor a windows service through Microsoft&#8217;s System Center Operations Manger and have it restarted automatically you can not use the management pack templates. The reason for this is that the templates are stored in locked MP&#8217;s that you do not have access too.</p>
<p>Follow the following steps to monitor a service and have it restarted automatically by SCOM if it fails.<br />
<!--smartads--><br />
<span id="more-205"></span></p>
<p><strong>Steps</strong></p>
<ol>
<blockquote>
<li>Create a management pack to store the monitor in</li>
<li>Create a group that the monitor will be applied against</li>
<li>Create a monitor that watches the service</li>
<li>Create overrides (apply to group)</li>
<li>Create the recovery task</li>
</blockquote>
</ol>
<p><strong>Step 1: Create the Management Pack<br />
</strong></p>
<p>In the managment console under Administration right click on Management Packs and select &#8220;Create Management Pack&#8221;. Give this new MP a meaningfull name and continue.</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1.png"><img class="alignnone size-medium wp-image-206" title="create_new_mp" src="http://bradstechblog.com/wp-content/uploads/2008/09/create_new_mp-300x199.png" alt="" width="300" height="199" /></a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1.png"> </a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1.png"><img class="alignnone size-medium wp-image-208" title="label_mp1" src="http://bradstechblog.com/wp-content/uploads/2008/09/label_mp1-300x264.png" alt="" width="300" height="264" /></a></p>
<p><strong>Step 2: Create the Group<br />
</strong></p>
<ul>
<li>In the Authoring Pane right click on &#8220;create new group&#8221; Give this new group a meaningful name. A description. And select the management pack that you created.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_group.png"> <img class="alignnone size-medium wp-image-209" title="create_new_group" src="http://bradstechblog.com/wp-content/uploads/2008/09/create_new_group-81x300.png" alt="" width="81" height="300" /></a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_group.png"> </a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/label_group.png"><img class="alignnone size-medium wp-image-210" title="label_group" src="http://bradstechblog.com/wp-content/uploads/2008/09/label_group-300x257.png" alt="" width="300" height="257" /></a></p>
<blockquote><p>Important: Do not use the default management pack. You can do it. But this will create problems when trying to remove MP in the future. Always use Custom MP&#8217;s.</p></blockquote>
<ul>
<li>Say next. Click on Add/remove objects on the Explicit Group Members. Enter a server name and search. Select your computer object and say ok. You can now add dynamic and exclusions. I am not going into that on this post so except all defaults.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/explicit_members.png"><img class="alignnone size-medium wp-image-211" title="explicit_members" src="http://bradstechblog.com/wp-content/uploads/2008/09/explicit_members-300x291.png" alt="" width="300" height="291" /></a><br />
<!--smartads--><br />
<strong>Step 3</strong>: <strong>Create the Monitor</strong></p>
<ul>
<li>In the Authoring Pane right click on monitors and select Create a monitor, then Unit Monitor.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/create_unitmonitor.png"><img class="alignnone size-medium wp-image-212" title="create_unitmonitor" src="http://bradstechblog.com/wp-content/uploads/2008/09/create_unitmonitor-300x171.png" alt="" width="300" height="171" /></a></p>
<ul>
<li>Expand Windows Services, and select &#8220;Basic Service Monitor&#8221;. Select the custom management pack.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/select_monitor_type.png"><img class="alignnone size-medium wp-image-213" title="select_monitor_type" src="http://bradstechblog.com/wp-content/uploads/2008/09/select_monitor_type-300x293.png" alt="" width="300" height="293" /></a></p>
<ul>
<li>Provide a name for the monitor. I am going to create this monitor to watch Windows Update services. Select the monitor target as windows Server Operating System. Select the Parent Monitor as Availability.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/monitor_general_properties.png"><img class="alignnone size-medium wp-image-214" title="monitor_general_properties" src="http://bradstechblog.com/wp-content/uploads/2008/09/monitor_general_properties-300x294.png" alt="" width="300" height="294" /></a><a href="http://bradstechblog.com/wp-content/uploads/2008/09/monitor-target.png"><img class="alignnone size-medium wp-image-216" title="monitor-target" src="http://bradstechblog.com/wp-content/uploads/2008/09/monitor-target-300x259.png" alt="" width="300" height="259" /></a></p>
<ul>
<li>Next Browse to the server, or any server with the service running. and select the service.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/select_service.png"><img class="alignnone size-medium wp-image-218" title="select_service" src="http://bradstechblog.com/wp-content/uploads/2008/09/select_service-300x248.png" alt="" width="300" height="248" /></a></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/select_service2.png"><img class="alignnone size-medium wp-image-217" title="select_service2" src="http://bradstechblog.com/wp-content/uploads/2008/09/select_service2-300x294.png" alt="" width="300" height="294" /></a></p>
<ul>
<li>The next window shows how the monitor sees the health state. Accept the default.</li>
</ul>
<ul>
<li>The last window is how the alerts are configured.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/configure-alert.png"><img class="alignnone size-medium wp-image-219" title="configure-alert" src="http://bradstechblog.com/wp-content/uploads/2008/09/configure-alert-300x293.png" alt="" width="300" height="293" /></a></p>
<ul>
<li>uncheck the &#8220;Generate alerts for this monitor:&#8221; for now. This will prevent any unwanted alerts until we are ready.</li>
</ul>
<p><strong>Step 4: Apply to group</strong></p>
<p>Lets apply this MP against the group that we created earlier and disable it for all other servers.</p>
<p>Fist disable the rule for all servers</p>
<ul>
<li>Find the new rule under Authoring\monitors. The easiest way to do this is to change your scope. Click on the Change scope in the top right corner</li>
<li>Look for windows server operating System and select it and say ok.</li>
</ul>
<p><img src="file:///C:/Temp/moz-screenshot-4.jpg" alt="" /> <a href="http://bradstechblog.com/wp-content/uploads/2008/09/changescope.png"><img class="alignnone size-medium wp-image-220" title="changescope" src="http://bradstechblog.com/wp-content/uploads/2008/09/changescope-300x241.png" alt="" width="300" height="241" /><br />
</a></p>
<ul>
<li>Expand the monitor, right click on it and select properties.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/expandmonitor.png"><img class="alignnone size-medium wp-image-221" title="expandmonitor" src="http://bradstechblog.com/wp-content/uploads/2008/09/expandmonitor-300x132.png" alt="" width="300" height="132" /></a></p>
<ul>
<li>Select Disable and &#8220;For all objects of type: windows Server Operating System&#8221;</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/disable_monitor.png"><img class="alignnone size-medium wp-image-222" title="disable_monitor" src="http://bradstechblog.com/wp-content/uploads/2008/09/disable_monitor-300x206.png" alt="" width="300" height="206" /></a></p>
<ul>
<li>Next Right click on the same monitor and select override, Override the Monitor, for a group</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/override_for_group.png"><img class="alignnone size-medium wp-image-223" title="override_for_group" src="http://bradstechblog.com/wp-content/uploads/2008/09/override_for_group-300x123.png" alt="" width="300" height="123" /></a></p>
<ul>
<li>Start to type the name of the group you created and select it.<br />
<a href="http://bradstechblog.com/wp-content/uploads/2008/09/selectgroup.png"><img class="alignnone size-medium wp-image-225" title="selectgroup" src="http://bradstechblog.com/wp-content/uploads/2008/09/selectgroup-274x300.png" alt="" width="274" height="300" /></a></li>
<li>Place a check beside &#8220;Parameter name&#8221;. Change the override setting to True. This will enable the rule for the group.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/overrideproperties.png"><img class="alignnone size-medium wp-image-224" title="overrideproperties" src="http://bradstechblog.com/wp-content/uploads/2008/09/overrideproperties-289x300.png" alt="" width="289" height="300" /></a></p>
<ul>
<li>Say OK to save.</li>
</ul>
<p><strong>STEP 5: Create Recovery Task</strong></p>
<ul>
<li>In the Authoring Pane right click on monitors and select the monitor you created by right clicking on it and select properties.</li>
<li>Click on the Diagnostic and Recovery Tab</li>
<li>Under the configure recovery Tasks select Add&#8230; and choose &#8220;Recovery for Critical Health State&#8221;<br />
<a href="http://bradstechblog.com/wp-content/uploads/2008/09/select-task.png"><img class="alignnone size-medium wp-image-226" title="select-task" src="http://bradstechblog.com/wp-content/uploads/2008/09/select-task-300x290.png" alt="" width="300" height="290" /></a></li>
<li>Select Run command</li>
<li>Provide a meaningful name and description</li>
<li>Select the recovery target as Windows server operating system</li>
<li>Check run recovery automatically and recalculate monitor state.</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0011.png"><img class="alignnone size-medium wp-image-227" title="task name and description" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0011-300x269.png" alt="" width="300" height="269" /></a></p>
<ul>
<li>Next, for the full path to the file type C:\WINDOWS\system32\net.exe This will spawn the net command</li>
<li>for the parameters type start service name. We are starting windows update service. Here is the best way to find the service name. Open services by opening the run box and type services.msc</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/services-window.png"><img class="alignnone size-medium wp-image-228" title="services-window" src="http://bradstechblog.com/wp-content/uploads/2008/09/services-window-300x238.png" alt="" width="300" height="238" /></a></p>
<ul>
<li>now that you have the actual service name lets enter it in the parameters field. so you would type &#8220;Start wuauserv&#8221;</li>
</ul>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0013.png"><img class="alignnone size-medium wp-image-229" title="Task command line settngs" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0013-300x271.png" alt="" width="300" height="271" /></a></p>
<ul>
<li>Once you have clicked on create you are done.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/scom/how-to-create-a-recovery-task-in-scom-on-a-windows-service/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>GPO &#8211; Change Event Viewer Log size and retention period</title>
		<link>http://bradstechblog.com/microsoft-windows-server/gpo-change-event-viewer-log-size-and-retention-period</link>
		<comments>http://bradstechblog.com/microsoft-windows-server/gpo-change-event-viewer-log-size-and-retention-period#comments</comments>
		<pubDate>Mon, 29 Sep 2008 15:52:07 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[GPO]]></category>
		<category><![CDATA[Microsoft windows server]]></category>
		<category><![CDATA[Event Viewer]]></category>
		<category><![CDATA[Size]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=200</guid>
		<description><![CDATA[The default of the event viewer log size is 512kb. As well to make this dangerous the logs will overwrite events older then 7 days only. So what happens when you logs fill up in two days from a critical error? You start loosing critical information to help trouble shoot the problem. With today&#8217;s availability [...]]]></description>
			<content:encoded><![CDATA[<p>The default of the event viewer log size is 512kb. As well to make this dangerous the logs will overwrite events older then 7 days only. So what happens when you logs fill up in two days from a critical error? You start loosing critical information to help trouble shoot the problem. With today&#8217;s availability of disk here is a better way to set these settings using a GPO to automate the process on all of your servers/desktops&#8230;</p>
<p><!-smartads-><br />
<span id="more-200"></span></p>
<p>On your server open up you Group Policy Object Editor</p>
<p>Navigate to Computer Configuration\Windows Settings\Security Settings\Event Log</p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0077.png"><img class="alignnone size-medium wp-image-201" title="image-0077" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0077-300x132.png" alt="" width="300" height="132" /></a></p>
<p>The following settings are to be done for each log separately.</p>
<blockquote><p>Set your Maximum values in increments of 64kb. I decided to go as close to 5mb so I am using 4992kb.</p></blockquote>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0078.png"><img class="alignnone size-medium wp-image-203" title="image-0078" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0078-251x300.png" alt="" width="251" height="300" /></a></p>
<blockquote><p>Set your retention method to &#8220;as needed&#8221;</p></blockquote>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0079.png"><img class="alignnone size-medium wp-image-202" title="image-0079" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0079-253x300.png" alt="" width="253" height="300" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/microsoft-windows-server/gpo-change-event-viewer-log-size-and-retention-period/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Force a user GPO on a computer OU in Microsoft Active Directory</title>
		<link>http://bradstechblog.com/microsoft-windows-server/force-a-user-gpo-on-a-computer-ou-in-microsoft-active-directory</link>
		<comments>http://bradstechblog.com/microsoft-windows-server/force-a-user-gpo-on-a-computer-ou-in-microsoft-active-directory#comments</comments>
		<pubDate>Fri, 26 Sep 2008 15:45:47 +0000</pubDate>
		<dc:creator>Brad Hearn</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Microsoft windows server]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Loopback]]></category>
		<category><![CDATA[Screen Saver]]></category>

		<guid isPermaLink="false">http://bradstechblog.com/?p=187</guid>
		<description><![CDATA[I needed to apply a blank screen saver to all of our servers. Of course I wanted this to be done based on Server and not the logged in user/administrator. The location in the GPO for setting a screen saver is located in&#8230; (Click below to read the rest)


the Group Policy snap-in under Local Computer [...]]]></description>
			<content:encoded><![CDATA[<p>I needed to apply a blank screen saver to all of our servers. Of course I wanted this to be done based on Server and not the logged in user/administrator. The location in the GPO for setting a screen saver is located in&#8230; (Click below to read the rest)</p>
<p><!-smartads-></p>
<p><span id="more-187"></span></p>
<p>the Group Policy snap-in under Local Computer Policy\User Configuration\Administrative Templates\Control Panel\Display</p>
<p><a rel="attachment wp-att-189" href="http://bradstechblog.com/microsoft-windows-server/force-a-user-gpo-on-a-computer-ou-in-microsoft-active-directory/attachment/image-0073"><img class="alignnone size-medium wp-image-189" title="image-0073" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0073-300x124.png" alt="" width="300" height="124" /></a></p>
<p>Select Screen Saver Executable name and enter the location of the screen saver you are going to enforce.</p>
<p><img src="file:///C:/Temp/moz-screenshot-1.jpg" alt="" /><img src="file:///C:/Temp/moz-screenshot-2.jpg" alt="" /> <img src="file:///C:/Temp/moz-screenshot.jpg" alt="" /></p>
<p><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0074.png"><img class="alignnone size-medium wp-image-190" title="image-0074" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0074-270x300.png" alt="" width="270" height="300" /></a></p>
<p>Here you can specify the screen saver you want. I am using the blank screen saver</p>
<p>Select ok.</p>
<p>Next you need to enable Loop Back so that the computer OU can use the Users GPO.</p>
<p>Navigate to Computer Configuration\Administrative Templates\System\Group Policy\User Group Policy Loopback processing mode\</p>
<div class="answerBody quoted"><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0075.png"><img class="alignnone size-medium wp-image-191" title="image-0075" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0075-300x181.png" alt="" width="300" height="181" /></a></div>
<div class="answerBody quoted">You have two choices in this policy. One is to merge the user settings into the computer GPO and the other is to replace. I am going to merge.</div>
<div class="answerBody quoted"><a href="http://bradstechblog.com/wp-content/uploads/2008/09/image-0076.png"><img class="alignnone size-medium wp-image-192" title="image-0076" src="http://bradstechblog.com/wp-content/uploads/2008/09/image-0076-270x300.png" alt="" width="270" height="300" /></a></div>
<div class="answerBody quoted">This is it. Refresh your GPO and test this.</div>
<div class="answerBody quoted">Remember You will want to create a new computer OU and move your computers or servers into it before you can apply the computer GPO to them.</div>
]]></content:encoded>
			<wfw:commentRss>http://bradstechblog.com/microsoft-windows-server/force-a-user-gpo-on-a-computer-ou-in-microsoft-active-directory/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
