I ran into this issue today while trying to run the Microsoft BPA (Best Practices Analyzer) 2.3 on a Windows Server 2012 R2 box with IIS 8.5 installed. Below is the full text of the error:
"Unable to scan IIS status - The IIS Common Files are not installed on the local computer. Refer to the system requirements list under the Microsoft Business Security Analyzer Help."
Here's the short fix:
Go back into Roles and under Web Server (IIS) and install IIS 6 Management Compatibility --> IIS 6 Metabase Compatibility.
Apparently from what I find this is a Windows Server 2003 item that hasn't been updated in the current server platform documentation on the MBSA to reflect the need for this additional set of files.
The longer explanation is that in order for the MBSA to be able to scan IIS properly it needs to have IIS 6 Management Compatibility turned on and more specifically the IIS 6 Metabase Compatibility.
I hope this one helps as it took me quite a bit of research to run this issue down.
Good luck.
Helping you with things I've found that should just work but don't. I hold several certifications from Cisco, VMware, and Microsoft.
Wednesday, May 13, 2015
Friday, April 24, 2015
Manually Applying Updates to Trend IMSVA
Whenever Trend issues an update for these virtual machines the GUI interface isn't always able to apply the patches to the VM.
This is where a bit of time and patience have to come in to get them updated. Below is how I get it done quickly without much headache to keep these VMs current.
1. Download the patch or hot fix to your computer (Ex: imsva_90_en_criticalpatch1560.zip).
2. Extract the file. You'll see a couple of files extracted such as readme_en.txt and imsva_90_en_criticalpatch1560.tar.gz listed.
3. Use a program to upload the files to the IMSVA virtual machine. I choose to use WinSCP. Upload the file to the /tmp folder.
4. Login to the IMSVA using root privilege using Putty or another program via SSH. NOTE: You have to use SCP on WinSCP as the protocol and the root account for the VM. If not it won't connect with the standard "admin" and password the web browser login uses.
5. Run the following commands:
# tar -zxvf /tmp/imsva_90_en_criticalpatch15160.tar.gz -C /tmp
# cd /tmp/imsva_90_en_criticalpatch15160
# ./imssinst
6. Allow the installation to run and when the install completes you'll see something similar to this:
Installation is complete and related services are started.
Just a note when you are done you can delete both the *.tar.gz file and the folder it created off of the IMSVA virtual machine to save space.
Login to the web interface and verify with the "About" option the new build version of your IMSVA.
I have found that not every hot fix or patch raises the build level in the web interface but if you try to apply it again to the IMSVA you'll find out it has already been installed.
For those of you that are not great in the Linux/Unix world I hope these instructions help you keep your critical infrastructure system patched and up to date.
It's Friday afternoon now so I hope you all have a great weekend.
This is where a bit of time and patience have to come in to get them updated. Below is how I get it done quickly without much headache to keep these VMs current.
1. Download the patch or hot fix to your computer (Ex: imsva_90_en_criticalpatch1560.zip).
2. Extract the file. You'll see a couple of files extracted such as readme_en.txt and imsva_90_en_criticalpatch1560.tar.gz listed.
3. Use a program to upload the files to the IMSVA virtual machine. I choose to use WinSCP. Upload the file to the /tmp folder.
4. Login to the IMSVA using root privilege using Putty or another program via SSH. NOTE: You have to use SCP on WinSCP as the protocol and the root account for the VM. If not it won't connect with the standard "admin" and password the web browser login uses.
5. Run the following commands:
# tar -zxvf /tmp/imsva_90_en_criticalpatch15160.tar.gz -C /tmp
# cd /tmp/imsva_90_en_criticalpatch15160
# ./imssinst
6. Allow the installation to run and when the install completes you'll see something similar to this:
Installation is complete and related services are started.
Just a note when you are done you can delete both the *.tar.gz file and the folder it created off of the IMSVA virtual machine to save space.
Login to the web interface and verify with the "About" option the new build version of your IMSVA.
I have found that not every hot fix or patch raises the build level in the web interface but if you try to apply it again to the IMSVA you'll find out it has already been installed.
For those of you that are not great in the Linux/Unix world I hope these instructions help you keep your critical infrastructure system patched and up to date.
It's Friday afternoon now so I hope you all have a great weekend.
Thursday, April 23, 2015
Managing FSMO roles with PowerShell in Server 2012 R2
Powershell was released some time ago but it feels to me like it was just yesterday. Part of that is because as time moves on Microsoft is adding more and more features. With Windows Server 2012 R2 now in full effect and quite stable, it's clear PowerShell is taking over as the primary Windows scripting language of choice.
I am a firm believer that everything in Windows Server 2012 R2 that can be done in the GUI can also be done in PowerShell. Case in point, I just upgraded one of our network Domain Controllers from Windows Server 2012 to Windows Server 2012 R2.
Since this server was a DC the first thing I needed to do before the upgrade was to ensure the server was not running any of the five FSMO roles on our network. To do this I ran the following command in PS on the server.
To transfer all five roles you can simply run this command in PS:
I don't find myself moving FSMO roles often but when I need to this is much easier than using the GUI. A great reference on PowerShell is Learn Windows PowerShell 3 in a Month of Lunches. It's a great read and has tons of great PowerShell information.
Good luck.
I am a firm believer that everything in Windows Server 2012 R2 that can be done in the GUI can also be done in PowerShell. Case in point, I just upgraded one of our network Domain Controllers from Windows Server 2012 to Windows Server 2012 R2.
Since this server was a DC the first thing I needed to do before the upgrade was to ensure the server was not running any of the five FSMO roles on our network. To do this I ran the following command in PS on the server.
netdom query FSMOThis will return which DC or DCs on your network contain the FSMO roles. Since the server I was upgrading had none then I had none to move before the upgrade. Once the upgrade had completed I now wanted to make sure the newest DC on the network had the roles while others were being upgraded.
To transfer all five roles you can simply run this command in PS:
Move-ADDirectoryServerOperationMasterRole -Identity “Target_DC_name” –OperationMasterRole 0,1,2,3,4For reference the command line syntax replaces the role number for the full name of the FSMO role.
- PDC Emulator = 0
- RID Master = 1
- Infrastructure Master = 2
- Schema Master = 3
- Domain Naming Master = 4
Move-ADDirectoryServerOperationMasterRole -Identity “Target_DC_name” –OperationMasterRole 0,1,2,3,4 - ForceFinally to transfer or seize just one role you would run the exact same command and just use the number of the role you need to move. These commands work on Server 2008 R2 and up or Windows 7 with the RSAT (Remote Server Administration Tools) installed.
I don't find myself moving FSMO roles often but when I need to this is much easier than using the GUI. A great reference on PowerShell is Learn Windows PowerShell 3 in a Month of Lunches. It's a great read and has tons of great PowerShell information.
Good luck.
Wednesday, March 04, 2015
RESOLVED: The WS-Management service cannot process the request.
RESOLVED: The WS-Management service cannot process the request. The user load quota of 1000 requests per 2 seconds has been exceeded. Send future requests at a slower rate or raise the quota for this user. The next request from this user will not be approved for at least X milliseconds.
This can happen if your Exchange server has recently received a new SSL (UCC) certificate.
What can happen is the remote PowerShell or the EMC will be using a certificate that is not trusted or valid anymore.
A simple "IISRESET" from PowerShell or the CMD prompt will correct the issue.
Good luck!
This can happen if your Exchange server has recently received a new SSL (UCC) certificate.
What can happen is the remote PowerShell or the EMC will be using a certificate that is not trusted or valid anymore.
A simple "IISRESET" from PowerShell or the CMD prompt will correct the issue.
Good luck!
Wednesday, February 11, 2015
Cisco AnyConnect "Failed to Initialize Connection Subsystem"
I run Windows 8.1 and run Cisco AnyConnect Secure Mobility Client version 3.1.03103 to access a VPN. After getting the error I updated to the latest AnyConnect Client version 4.0.00061 and got the same result.
Last night I install all of the updates from patch Tuesday (over 1.1G worth including Office 2013 patches). Today, after I hit connect, it stopped working out of the blue with the error:
Failed to initialize connection subsystem
I suspect a recent Windows update must be the cuplrit. Here's the steps you will find all over the web to fix it. THIS DOESN'T WORK! To fix just uninstall the KB3023607 published for install yesterday!
1. Close the Cisco AnyConnect Window and the taskbar mini-icon
2. Right click vpnui.exe in the “Cisco AnyConnect Secure Mobility Client” folder. (I have it in “C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\”
3. Click on the “Run compatibility troubleshooter” button
4. Choose “Try recommended settings”.
5. The wizard suggests Windows 8 compatibility.
6. Click “Test Program”. This will open the program.
7. Close
Cisco has escalated this issue to Microsoft for investigation from what I can find.
This issue was introduced by KB# 3023607: Secure Channel cumulative update changes TLS protocol renegotiation and fallback behavior (https://support.microsoft.com/kb/3023607) and included with Microsoft Security Bulletin MS15-009 – Critical Security Update for Internet Explorer (3034682)
This issue is rumored to affect Windows 7 with IE 11 as well. I have not experienced this myself as I no longer run Windows 7 on any of my machines.
Last night I install all of the updates from patch Tuesday (over 1.1G worth including Office 2013 patches). Today, after I hit connect, it stopped working out of the blue with the error:
Failed to initialize connection subsystem
I suspect a recent Windows update must be the cuplrit. Here's the steps you will find all over the web to fix it. THIS DOESN'T WORK! To fix just uninstall the KB3023607 published for install yesterday!
1. Close the Cisco AnyConnect Window and the taskbar mini-icon
2. Right click vpnui.exe in the “Cisco AnyConnect Secure Mobility Client” folder. (I have it in “C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\”
3. Click on the “Run compatibility troubleshooter” button
4. Choose “Try recommended settings”.
5. The wizard suggests Windows 8 compatibility.
6. Click “Test Program”. This will open the program.
7. Close
Cisco has escalated this issue to Microsoft for investigation from what I can find.
This issue was introduced by KB# 3023607: Secure Channel cumulative update changes TLS protocol renegotiation and fallback behavior (https://support.microsoft.com/kb/3023607) and included with Microsoft Security Bulletin MS15-009 – Critical Security Update for Internet Explorer (3034682)
This issue is rumored to affect Windows 7 with IE 11 as well. I have not experienced this myself as I no longer run Windows 7 on any of my machines.
Subscribe to:
Posts (Atom)