Exchange, SBS 2003, and Blackberry Enterprise Server

Last week I had a client who wanted the BES installed on his SBS 03 server.  No big deal, I’ve done it before…

Anyway, I had some problems with the “SendAs” permissions being revoked.  I wanted to detail some KB’s that helped me get everything straightened out.  Hopefully it will be good for someone else!

First, here is the install guide from Blackberry:  http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8067/645045/1382175/1404165/1382176/Getting_Started_Guide.pdf?nodeid=1382253&vernum=0

Here are the details on setting up the permissions for the Blackberry service account:  http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB02276&sliceId=SAL_Public&dialogID=6316111&stateId=0%200%203804961

Here is a KB from BB regarding the SendAs getting revoked:  http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB04707&sliceId=SAL_Public&dialogID=6306833&stateId=0%200%203804284

Here is a KB from Microsoft regarding the SendAs getting revoked:  http://support.microsoft.com/kb/912918/en-us

Keep in mind that Blackberry is VERY picky about permissions!!!  I can’t stress that enough.  I thought well, I can do what I want to and make it work.  No!  FOLLOW THE INSTRUCTIONS and save yourself some headache.  Also, keep in mind that permissions on the user account that you are syncing with (not the BES admin account) are important too.  They cannot be domain admins or power users or administrators.

UPDATE

Ok, all that I did and all my googling solved the problem.  I finally called BB tech support.  Here is the solution that they gave:

Go to Active Directory Users and Computers

Go to View->Advanced

Expand your domain.

Expand System.

Right click on AdminSDHolder, and click properties

Go to the Security tab, and click the Advanced button

Click “Allow inheritable permissions from the parent to propogate to this object……”

Click Apply and OK.

Now go to the User account that you are trying to use with the Blackberry server.

Right click and click properties and choose Security and Click advanced and check “allow inheritable….”

Apply, Ok, Done!  (Hopefully!!!)

Hopefully that saves someone else some pain!

All the best,

Luke

Vista Default Domain Profile

I’ve been working on deploying some Vista Business machines.  I was trying to figure out how in the world to create a default domain profile.

I finally found the answer.  In your Netlogon share, you create a folder called Default User.v2.

Login as a domain user and create the profile as you want it to be for everyone’s defaults.  Now logout and log back in as administrator.  Click “Windows Button (Start)” right click on “Computer,” and click on “Advanced system properties,” click on the advanced tab and then click on “Settings” under “User Profiles.”

You should see the user profile in the list that you just finished configuring.  Click on it and click “Copy To…”  Copy the user profile to \\YOUR SERVER\NETLOGON\Default User.v2.  Under “Permitted to use” make sure that everyone is permitted to use it.  Copy the profile and then you are done!

Hope it all works out!

Luke

Vista, Group Policy, and Server 2003

I was trying to figure out how in the world to manange Group Policy for Vista machines from a Vista Machine, but with a 03 domain controller.

It should have been simple, and I should have known, but here’s the trick:

Download the RSAT (Remote Server Administration Toolkit)

Now go to the control panel and go to Programs and Software.  Choose Enable or Disable Windows Components on the left hand pane.  Scroll through the list until you see Remote Server Administration Tools, and choos Group Policy Management in that list.  Apply the changes and then hit the Windows Key + R to bring up the run box.  Type GPMC.MSC and hit Enter and you should be in business!

This blog has some good details:  http://n3ilb.wordpress.com/2008/09/09/vista-group-policy-in-a-server-2003-active-directory/


Trixbox Changes

Well… According to my adventures this evening, this morning or whatever it is by now… You can take Trixbox from an old version to a new version complete with moving it to new hardware. It isn’t too big of a deal at all… It only took me about 6 hours.

I actually ended up deleting all the extensions in Trix and recreating them. Don’t ask me why it wouldn’t work, but I couldn’t get any of the phones to ring though they all rang out fine.

Another issue that I encountered was that some of the voicemail files that were transferred from the old system were transferred with the format of filename.WAV. For some reason, possibly due to the upgraded Trix core, it is now looking for filename.wav. So, of course, when it tries to find the file, it bombs out and hangs up your call.

Anyway, now I have triple the ram that I had before, so hopefully that will take care of some of the complaints I’ve been getting regarding my phone system.

Ok, going to bed!

Now, it’s my turn…

I buy new computers all the time…

But it seems like I just never break down and do it for myself.

Well, tonight, with my wife’s approval, I made the leap.

Here’s the specs:

Dell Precision T3400
Intel Core2Due E8500, 3.16GHz, 13336MB L2, 525W
4GB, 800MHz, DDR2 ECC SDRAM Memory, 4X1GB
USB Enhanced Multimedia English Keyboard
Dell UltraSharp 2009FP,Wide Flat Panel w/Height AdjustableStand,20.0 Inch
nVidia,Quadro FX 570,256MB dual DVI, Graphics Card
80GB SATA,10K RPM 3.0Gb/s 2.5 inch,SATA2 16MB Data Burst Cache
Windows XP 64 SP2 with WindowsVista Ultimate 64 Edition License
Internal USB Media card reader19:1
16X DVD+/-RW
3 Yr Warranty
Purchase is NOT intended for resell ;0)

Ok, now hurry and get here!

All the best,

Luke

Update….
For added effect, I thought I would mention that in the hundred’s of new computers that I’ve sold or hooked up this is my first new computer - excluding my laptop. I feel kind-of proud of that fact for some reason… :)

Internet Explorer 7 Using VERY HIGH Memory

Today I had a call from a guy who said… “My internet isn’t working on my main computer.” I said ok, expecting a virus, corrupt winsock, wrong tcp/ip settings, or a bad nic or something…

When I got there I found that none of the above was the case. Instead the deal was that IE was using a massive amount of memory when viewing certain websites. One of those websites was yahoo.com, and that was also set as their home page.

See the screen shots for the memory useage, and then following for the resolution:

I tried several things… Including removing and reinstalling IE7. I removed the only version of flash player that was on the system - an it was an old one. Finally, what seemed to actually fix the problem, was installing the latest flash player version - 9.something…

For your reference, here are links both to remove all Flash player versions and to install the latest:

Remove: http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_14157

Install Latest: http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash

So, there you go!

All the best,

Luke

Can you say “SpamBot?”


So today I was working on this lady’s virus laden computer.  I thought it was clean.  Until I suddenly realized that it was making a massive number of connections to port 25 on random IP addresses all over the globe.  Check out this nestat:

Spam Bots

Spam Bots

All of this to say…  this is why a “flatten and restore” aproach to virus removal is ALWAYS the best.  I thought it was clean.  It ran clean, it “felt” clean - anyone who has spent over 40 hours in their life removing computer viruses will know what that means.  BUT IT WASN’T CLEAN.  So, if in doubt, or even if not in doubt, reformat.

Best Wishes,

Luke

Rubber hits the Road

A Question…

To the random people who happen across this site. I have a question for you. You could do me a favor by leaving a comment or sending an email with an answer. Here it is:

I want to know, in all your years of purchasing services from vendors, what makes you the happiest? What would bring you back for more, and cause you to tell your friends and co-workers? What leaves a warm feeling in your heart that is a confirmation that, in spite of all the cold, in-humane numbers, bytes, and statistics overwhelming us every waking moment, you are still a real human, with real human needs, wants and desires. In short, what could a vendor provide, that would suddenly cause the reality of the fact that you want that vendor’s service, not necessarily his commodity?

Ok, sorry, that was more than one question… I meant one thought! :) Please, if you have thoughts, I want to hear them!

Because I’m changing this place where I work. And it’s going to take a new look and feel. For the better.

All the best,

Luke

Adobe Premier Elements won’t burn DVD - even though you have a burner!

So yesterday a friend who is a an amateur videographer said that even though he has a DVD burner, and even though Adobe Premier Elements has burnt DVD’s for him in the past… It is now saying that there is no DVD burner present with which to do the job.

After some troubleshooting, I decided that it was time to go online and see if anyone else was having the same problem. I found that they were. If you haveing this problem, do yourself a favor and visit this site: http://premierepro.wikia.com/wiki/FAQ:Why_can%E2%80%99t_I_burn_a_DVD%3F.

Just to help you out here is the solution in a nutshell:

1) Open regedit.

2) Navigate to this key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}

3) Go to the “LowerFilters” key

4) Add “PxHelp20″ and “PFC” to the list in lower filters. They should both be on separate lines and PxHelp20 should be at the very top of the list.

Hopefully that will get your friends wedding into her DVD player a bit sooner!

All the best,

Luke