Thursday, November 18, 2010
Wednesday, March 25, 2009
PowerShell 1.0 / WMI / IIS 6.0
write-host "### -----"renders
$t = get-wmiobject IISWebVirtualDir -namespace "root\MicrosoftIISv2"
$t | ft AppPackageID, AppPackageName, AppRoot, Name
# $t | ft AppIsolated, AppPackageID, AppPackageName, AppRoot, Caption, ' Description, InstallDate, Name, Status
$t = get-wmiobject IISWebVirtualDirSetting -namespace "root\MicrosoftIISv2"renders
$t | ft AppFriendlyName, Name, Path, Realm
# $t | ft AppIsolated, AppPackageID, AppPackageName, AppRoot, Caption, ' Description, InstallDate, Name, Status
Wednesday, May 14, 2008
Windows Update for Home Network
If you're using some version of Windows Server, it's pretty easy to set up your own Windows Server Update Service (WSUS). Visit http://technet.microsoft.com/en-us/wsus/ to download, install and configure WSUS.
Now, in order to have your PCs reference your WSUS rather than Windows Update, you need to change a couple of policy objects. Since I'm using a domain for my home network, I use the Group Policy Object Editor once and all the PCs pick it up. I believe the same changes will work by applying them to a PC's Local Policies.
Open the Policy Object Editor and navigate to Administrative Templates / Windows Components / Windows Update.
The pane to the right will show the applicable settings for Windows Update.
Your domain-connected PCs will pick up the change on their next policy load. You'll know that the client PCs are using your home WSUS when they appear in the Computers list of the WSUS admin application (Administrative Tools / Microsoft Windows Server Update Services 3.0)
Friday, November 30, 2007
Windows Policies and Settings for Virtual Machines
Clear Pagefile on Shutdown
This will help reduce the VM's disk space demands. Although many VM hosts may take of this directly, to make sure it's cleared out set the following Group Policy Object (GPO)
Local Computer Policy\Computer Configuration\Windows Settings\Security
Settings\Local Policies\Security Options\Shutdown: Clear virtual memory
pagefile
Allow Shutdown Prior to Logon (Non-Production)
It's valuable for personnel who can't log on to a VM (no access, forgot password, etc.) to be able to shutdown the OS w/o logging in. Enable the following GPO:
Local Computer Policy\Computer Configuration\Windows Settings\Security
Settings\Local Policies\Security Options\Shutdown: Allow system to be shutdown without having to log on
Allow Power Users to Shutdown the OS (Non-Production)
Add the local Power Users group to the following GPO:
Local Computer Policy\Computer Configuration\Windows Settings\Security
Settings\Local Policies\User Rights Assignment\Shutdown the system
Monday, November 26, 2007
Visual Studio 2008 Unattended Setup Fails on Longhorn
Root Cause: Unattended setup is not supported from DVD
Work-Around: Run unattended setup from a network share.
We had the bright idea for unattended Visual Studio 2008 setup. The theory was that we would create the unattend file using setup's CreateUnattend switch, copy it to the DVD and update autorun to trigger the unattended installation. All our devs would need to do is load the DVD, go get a cup of coffee and voilà! VS 2008 would be ready for action.
Unfortunately, it didn't work as expected. After several attempts with minor changes (full path, quoted path, etc.), I finally dug into the log files (in \Users
[11/26/07,15:45:23] vs70uimgr: [2] Admin deployment is not allowed from a
CD/DVD.[11/26/07,15:45:23] setup.exe: [0] InitializeUIManager(), Start
failure
That's pretty clear and straight-forward.
Wednesday, July 26, 2006
Windows Defender Update Error 0x8024402c
Searching for info on this lead me to instructions on using msiexec to uninstall the existing virus signatures, etc., but none of this worked.
Then I realized that I had recently switched to using my own Windows Update Server (WSUS). WD must have been seeking the updates from my WSUS rather than windowsupdate.com.
Resolution: Use WSUS Admin to turn on "Definition Updates" and set them to install automatically.
Tuesday, July 18, 2006
Using Enterprise Library Logging Securely with ASP.NET Applications
First, let's consider the security aspects. In order to keep ASPX apps locked down, I don't allow any users to write to the ASPX app's v-root hierarchy (except Admins & VS Devs groups of course). For example, an ASPX app may map to:
c:\inetpub\wwwroot\WebApp1with directory hierarchy (under WebApp1 dir) containing folders such as:
binThe WebApp1, WebApp1/SubFolder1 and WebApp1/SubFolder2 dirs may all contain .aspx or other script/executable files. I want the absolute minimum number of users to be able to write to this dir. Otherwise, the more people who have access (even via hacking), the more risk exposure to script injections, etc.
SubFolder1
SubFolder1
I frequently find that a developer's "solution" is to enable Write permissions on the v-root. This is a horrible mistake and practically unsecures the ASPX app. The correct (and secure) approach is to:
- Create a separate directory to store the log files
- Grant the (IIS 6.0) App Pool's Identity write permission to the new directory
- Configure the logging distributor to point to target the new directory
Simply use Windows Explorer, the Command Prompt or the Installer to create a dir for the log files. I typically create this as a sub-dir of the v-root (e.g., c:\inetpub\wwwroot\WebApp1\Logs)
Grant Write Permission
Again, use Windows Explorer, an Installer Custom Action, or other method to grant Write permission to the appropriate identity. I typically grant Write permission to IIS_WPG since all App Pool Identities must belong to this group. However, if you use multiple app pools with differing identities, then you should grant permission to that specific identity -- this will protect against other App Pool Identities from writing to the Log dir. (If your ASPX app uses end-user impersonation, see the Impersonation Issues section below)
Configure the Logging Distributor
Now that you have created the log dir and given the App Pool's Identity permission to Write to the dir, you need to instruct the Logging Application Block to use this dir for the output log files. Where the output file (typically "trace.log") is stored is controlled by fileName attribute of the sink element in the logging distributor configuration file (typically "loggingDistributorConfiguration.config"). Simply change the fileName attribute by prepending the relative path information.
<loggingDistributorConfiguration>
<xmlSerializerSection  >
<enterpriseLibrary.loggingDistributorSettings
defaultCategory="General" defaultFormatter="Text Formatter" ... >
<sinks>
<sink xsi:type="FlatFileSinkData" name="Flat File Sink" fileName=".\Logs\trace.log" ... />
</sinks>
...
</enterpriseLibrary.loggingDistributorSettings>
</xmlSerializerSection>
</loggingDistributorConfiguration>
Impersonation Issues
If your ASPX app employs end-user impersonation, then you'll need to make a choice.
- Unimpersonate -- more secure, but a little more difficult to get right
- Use custom group which holds Write Permission; add end-users to this group
- Stop using end-user impersonation (don't impersonate or impersonate specific identity rather than end-user)
Monday, May 15, 2006
SocketException on host over SmartPass VPN
Thursday, February 02, 2006
SQL 2K: User Defined Types are such a pain!
Friday, January 27, 2006
Don't use SQL Server 2000 Table Variables
- Table variables cannot be defined using User Defined Types. We use UDTs frequently to enforce consistency in even the smallest dbs. Table variables force you to break this best practice and reverse its benefits.
- Unclear that the variable is a table. The # (or ##) prefix of temp tables gives immediate indication that it is a table. Although good naming conventions could be used to reduce this, naming conventions aren't validated by the compiler.
Friday, January 06, 2006
Power Blogger?
MS Enterprise Library for GAC
Update App Config After GAC'ing Enterprise Library
The biggest gotcha I ran into is that using the E/L config tool for an application sets PublicKeyToken=null in the reference info. This will cause exceptions similar to "Logging.Configuration.ConfigurationException" to occur. To correct this problem, add the PublicKeyToken from the GAC for each E/L assembly to the appropriate location in the app's config files.
Wednesday, June 22, 2005
ASP.NET Apps within SharePoint
If your app needs to impersonate, the capabilities are limited. Setting impersonation in the identity element causes the Windows Identity to be IUSR_
ASP.NET Impersonation and Principals
Assumptions:
- VRoot requires authentication (anonymous disabled)
- VRoot's App Pool identity using NETWORK SERVICE
- "IEUser" is the end user
- "ImpersonatedUser" is the user config'd in the identity element
| Scenario | Page User | Thread CurrentPrincipal | WindowsIdentity |
| impersonate=false | IEUser | IEUser | NETWORK SERVICE |
| impersonate=true; userName not set | IEUser | IEUser | IEUser |
| impersonate=true; userName set | IEUser | IEUser | ImpersonatedUser |
So, the identity of System.Security.Principal.WindowsIdentity is the only one that changes. Page.User should typically be used for IsInRole checks.
Tuesday, March 08, 2005
SharePoint & WSS_Medium
Applications in SharePoint
WebParts are very similar to Server Controls in ASP.NET -- code in an assembly writes HTML to the output stream. No big deal from the output standpoint, but you don't get as much of the input benefits from ASP.NET controls (DataGrid is a good example).
Thursday, October 14, 2004
XSLT, XPath and GUID's
<xsl:template match="//Person[@PersonID='3'] >
...
</xsl:template>
But what if the unique identifier for Person nodes is a GUID?
<xsl:template match="//Person[@PersonID='
{4C22F4FA-0C4A-4FCF-85DF-F9B7A902244E}'] >
...
</xsl:template>
- What GUID format is used in the XML?
- Bracket notation?
- Hyphenated?
- Mixtures?
- With which casing are the alphabetic portion of the hex values stored in the XML?
- Upper case?
- Lower case?
- Mixture?
As you can see from just these two items, the matrix of problems expands rapidly. In the particular case I am dealing with, I am able to control format (bracketed, hyphenated), but not case. I have had to assume that case will be either upper or lower, but that mixed case will not occur (a fairly reasonable assumption since the GUIDs are not manually edited; for code to render mixed case it has to do extra work). So, my XSLT file finds the appropriate node by this method:
<xsl:param name='FindThisGuid'>
<xsl:variable name='UCaseGuid' select='translate($FindThisGuid, "abcdef", "ABCDEF")'>
<xsl:variable name='LCaseGuid' select='translate($FindThisGuid, "ABCDEF", "abcdef")'>
<xsl:template match='Person[@PersonID = $UCaseGuid) Person[@PersonID = ($LCaseGuid)]>
...
</xsl:template>
Now the Good News: XSLT 2.0 will hopefully resolve this issue by promoting GUID to a first class citizen (actual type).
Thursday, September 16, 2004
IE Gotcha! Do Not Use Self-Closing Script Tag
<script type='text/JavaScript' src='uitools.js' />
<script type='text/JavaScript'>
function DoSomething() {
//...
}
</script>
Seems harmless enough, right? For the longest time we could not determine why DoSomething was not accessible to page elements. We tried all kinds of things until we stumbled upon a surprising resolution. We began to drill in on the issue when I moved the DoSomething function into the upper script block (which required breaking open the self-closing script tag). Suddenly, page elements could use the function successfully. After we moved the function back to its rightful home, everything still worked. Then I realized that the only difference was that the upper script block was no longer self-closing. When I converted it back to self-closing, sure enough the page stopped working again.
For some reason IE (and possibly other browsers) does not handle self-closing script tags in an XML compliant manner. Go figure!
BP: 15 Minutes Isn't Enough
The person who does these builds seems to think that everyone receives the email instantaneously and that they will act on the information immediately. As is predictable, however, the builder frequently sends email along these lines, "Everybody stop checking in! I haven't been able to build." or "We will not have a build today because too many checkins occurred after the cut-off."
The problem is that people are not immediately in tune with email in some Borg-like fashion. We need consistent, dependable builds; but we're trying to deliver randomly.