<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" version="2.0">
  <channel>
    <title>ntldr - IT</title>
    <link>http://www.ntldr.com/</link>
    <description>Random thoughts from Jeffrey</description>
    <language>en-us</language>
    <copyright>Jeffrey Stults, Jr.</copyright>
    <lastBuildDate>Sun, 18 Apr 2010 23:36:08 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.3.9074.18820</generator>
    <managingEditor>stultsj@ntldr.net</managingEditor>
    <webMaster>stultsj@ntldr.net</webMaster>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=fe606f42-d422-4b5d-a666-c800bdfe226d</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,fe606f42-d422-4b5d-a666-c800bdfe226d.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,fe606f42-d422-4b5d-a666-c800bdfe226d.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=fe606f42-d422-4b5d-a666-c800bdfe226d</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Finally upgraded to Forefront TMG 2010 RTM last night. And screwed up the web listener
for this site. And didn’t know it. Ooops...
</p>
        <p>
It should all be good now though. At least the web publishing part. 
</p>
        <p>
I'm still having problems getting the VPN working. L2TP seems to be working fine,
but the SSTP endpoint is complaining about certificate problems and not working correctly.
Plus, web proxy clients are now trying to connect to one of the RAS demand dial interfaces
instead of the internal one they're supposed to. GRRRRR! (DNS looks correct, so no
idea how clients even <em>know</em> about the DHCP assigned address...but that's what
the logging is reporting...)
</p>
        <p>
Also, for some reason after applying the latest round of Windows Updates, system startup
has slowed to a crawl. It's now taking 15 minutes to go from POST to the login screen.
Nothing is being reported as being problematic, so no clue where to even start looking.
Even worse, sometimes services don't come back up, requiring manual intervention at
the console to start them. They've been different on each of the handful of reboots
I've done, so now I'm getting afraid to reboot...
</p>
        <p>
IPv6 support is also sorely missing. It's kind of there under the covers, and bleeds
through when configuring DirectAccess stuff. But without being supported &amp; without
a UI to configure rules, whatever underlying support there is is useless.
</p>
        <p>
On the bright side, recreating the old rules was a breeze. And the Best Practice Analyzer
is nice; it caught a couple things that I missed.
</p>
        <p>
I think the best approach is probably going to be to start over and reinstall everything.
Ouch. That'll have to wait a bit though...next week (+weekend) I'm down in the Bay
Area again, and two weeks later I'm in New Orleans...
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Vienna Teng – Warm Strangers – 04 <em>Shine</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=fe606f42-d422-4b5d-a666-c800bdfe226d" />
      </body>
      <title>Forefront TMG 2010 upgrade</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,fe606f42-d422-4b5d-a666-c800bdfe226d.aspx</guid>
      <link>http://www.ntldr.com/2010/04/18/ForefrontTMG2010Upgrade.aspx</link>
      <pubDate>Sun, 18 Apr 2010 23:36:08 GMT</pubDate>
      <description>&lt;p&gt;
Finally upgraded to Forefront TMG 2010 RTM last night. And screwed up the web listener
for this site. And didn’t know it. Ooops...
&lt;/p&gt;
&lt;p&gt;
It should all be good now though. At least the web publishing part. 
&lt;/p&gt;
&lt;p&gt;
I'm still having problems getting the VPN working. L2TP seems to be working fine,
but the SSTP endpoint is complaining about certificate problems and not working correctly.
Plus, web proxy clients are now trying to connect to one of the RAS demand dial interfaces
instead of the internal one they're supposed to. GRRRRR! (DNS looks correct, so no
idea how clients even &lt;em&gt;know&lt;/em&gt; about the DHCP assigned address...but that's what
the logging is reporting...)
&lt;/p&gt;
&lt;p&gt;
Also, for some reason after applying the latest round of Windows Updates, system startup
has slowed to a crawl. It's now taking 15 minutes to go from POST to the login screen.
Nothing is being reported as being problematic, so no clue where to even start looking.
Even worse, sometimes services don't come back up, requiring manual intervention at
the console to start them. They've been different on each of the handful of reboots
I've done, so now I'm getting afraid to reboot...
&lt;/p&gt;
&lt;p&gt;
IPv6 support is also sorely missing. It's kind of there under the covers, and bleeds
through when configuring DirectAccess stuff. But without being supported &amp;amp; without
a UI to configure rules, whatever underlying support there is is useless.
&lt;/p&gt;
&lt;p&gt;
On the bright side, recreating the old rules was a breeze. And the Best Practice Analyzer
is nice; it caught a couple things that I missed.
&lt;/p&gt;
&lt;p&gt;
I think the best approach is probably going to be to start over and reinstall everything.
Ouch. That'll have to wait a bit though...next week (+weekend) I'm down in the Bay
Area again, and two weeks later I'm in New Orleans...
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Vienna Teng – Warm Strangers – 04 &lt;em&gt;Shine&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=fe606f42-d422-4b5d-a666-c800bdfe226d" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,fe606f42-d422-4b5d-a666-c800bdfe226d.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=ac65eb5c-976e-4676-b9e8-412807455617</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,ac65eb5c-976e-4676-b9e8-412807455617.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,ac65eb5c-976e-4676-b9e8-412807455617.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=ac65eb5c-976e-4676-b9e8-412807455617</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I finally hopped on the solid state drive (SSD) bandwagon. Got an Intel X25-M G2 160GB
drive yesterday. And ended up spending all day trying to install it. Definitely should
have thought about how to go from the old drive to the new drive a bit more. But,
it's working now! Unfortunately, I haven't really noticed a performance boost at all...although
that might be because the only things I've done with it so far are resync my offline
file cache, create silly little drawings, and write blog posts. Nothing too disk intensive
there, and certainly nothing that would really benefit from the improved random access
times. So I'll see how this works out in the long run.
</p>
        <p>
In the mean time, this is how I migrated from the old drive to the new drive:
</p>
        <ol>
          <li>
Remove encrypted (EFS) files. It turns out that for some reason I had a random encrypted
file sitting around, which caused the backup procedure to fail. 
</li>
          <li>
Boot into WinPE. I used a USB drive that I've got laying around for installing Windows
Server 2008 R2. 
</li>
          <li>
Use imagex (from the Windows Automated Installation Kit (WAIK)) to capture an image
of the old drive's volumes. 
</li>
          <li>
Shutdown the system &amp; install the new drive. 
</li>
          <li>
Boot using the bootable USB drive and install Windows. I did this because I needed
to create the partition structure, file systems, and configure the new drive to be
bootable. Windows Setup does that all for me in a lot less time than it would take
me to document/chase down all that stuff and apply the changes manually. 
</li>
          <li>
Boot using the bootable USB drive again. Quick format the OS partition (or: delete
everything on it). 
</li>
          <li>
Use imagex to apply the captured image. 
</li>
          <li>
Reboot. Be happy that actually worked &amp; didn't result in weird errors from bootmgr
(or even worse, "ntldr not found"! (that would have been really bad because
Windows Vista, Server 2008, 7, &amp; Server 2008 R2 don't even *<strong>have/use</strong>*
ntldr anymore!). 
</li>
          <li>
(optional) Write blog post whining about how I didn't use dd, Ghost, TruImage, some
other disk cloning tool, or even just did something as simple as hooking both drives
up at the same time and doing a robocopy. (note that most of those would require having
both drives connected at the same time, which isn't possible for me because I don't
have a computer with 2 free SATA ports...yes, it's probably time I upgraded). 
</li>
        </ol>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Stars – In Our Bedroom After the War – 01 <em>The Beginning After the
End</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=ac65eb5c-976e-4676-b9e8-412807455617" />
      </body>
      <title>SSD</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,ac65eb5c-976e-4676-b9e8-412807455617.aspx</guid>
      <link>http://www.ntldr.com/2010/04/11/SSD.aspx</link>
      <pubDate>Sun, 11 Apr 2010 19:57:15 GMT</pubDate>
      <description>&lt;p&gt;
I finally hopped on the solid state drive (SSD) bandwagon. Got an Intel X25-M G2 160GB
drive yesterday. And ended up spending all day trying to install it. Definitely should
have thought about how to go from the old drive to the new drive a bit more. But,
it's working now! Unfortunately, I haven't really noticed a performance boost at all...although
that might be because the only things I've done with it so far are resync my offline
file cache, create silly little drawings, and write blog posts. Nothing too disk intensive
there, and certainly nothing that would really benefit from the improved random access
times. So I'll see how this works out in the long run.
&lt;/p&gt;
&lt;p&gt;
In the mean time, this is how I migrated from the old drive to the new drive:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
Remove encrypted (EFS) files. It turns out that for some reason I had a random encrypted
file sitting around, which caused the backup procedure to fail. 
&lt;/li&gt;
&lt;li&gt;
Boot into WinPE. I used a USB drive that I've got laying around for installing Windows
Server 2008 R2. 
&lt;/li&gt;
&lt;li&gt;
Use imagex (from the Windows Automated Installation Kit (WAIK)) to capture an image
of the old drive's volumes. 
&lt;/li&gt;
&lt;li&gt;
Shutdown the system &amp;amp; install the new drive. 
&lt;/li&gt;
&lt;li&gt;
Boot using the bootable USB drive and install Windows. I did this because I needed
to create the partition structure, file systems, and configure the new drive to be
bootable. Windows Setup does that all for me in a lot less time than it would take
me to document/chase down all that stuff and apply the changes manually. 
&lt;/li&gt;
&lt;li&gt;
Boot using the bootable USB drive again. Quick format the OS partition (or: delete
everything on it). 
&lt;/li&gt;
&lt;li&gt;
Use imagex to apply the captured image. 
&lt;/li&gt;
&lt;li&gt;
Reboot. Be happy that actually worked &amp;amp; didn't result in weird errors from bootmgr
(or even worse, &amp;quot;ntldr not found&amp;quot;! (that would have been really bad because
Windows Vista, Server 2008, 7, &amp;amp; Server 2008 R2 don't even *&lt;strong&gt;have/use&lt;/strong&gt;*
ntldr anymore!). 
&lt;/li&gt;
&lt;li&gt;
(optional) Write blog post whining about how I didn't use dd, Ghost, TruImage, some
other disk cloning tool, or even just did something as simple as hooking both drives
up at the same time and doing a robocopy. (note that most of those would require having
both drives connected at the same time, which isn't possible for me because I don't
have a computer with 2 free SATA ports...yes, it's probably time I upgraded). 
&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Stars – In Our Bedroom After the War – 01 &lt;em&gt;The Beginning After the
End&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=ac65eb5c-976e-4676-b9e8-412807455617" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,ac65eb5c-976e-4676-b9e8-412807455617.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=94969a72-a40a-495a-a71c-df578ac21eca</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,94969a72-a40a-495a-a71c-df578ac21eca.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,94969a72-a40a-495a-a71c-df578ac21eca.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=94969a72-a40a-495a-a71c-df578ac21eca</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
This weekend I got rid of the Digital AlphaServer 4000 5/300 that I've had for a number
of years. It ended up going a friend, so hopefully some good use will be made of it.
Honestly, getting rid of it is probably for the best: it's a pain to move (huge +
weighs a third of a ton), and I haven't used it for a while...in fact, it hasn't been
plugged in since moving out to Oregon a couple years ago.
</p>
        <p>
Still, I can't help but feel a little bit nostalgic &amp; miss it a little bit...
</p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Azure the AlphaServer" border="0" alt="Azure the AlphaServer" src="http://www.ntldr.com/attachments/WindowsLiveWriter/GoodbyeAlphaServer_14A66/IMG_0170_1.jpg" width="364" height="484" />
        </p>
        <p>
Between this &amp; the other stuff I've given away over the last 4 months, I'm now
down to the fewest number of computers I've owned since December 2002. Huh. Seems
odd to realize that.
</p>
        <p>
Anyway, bye Azure the AlphaServer!
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Lifehouse – Who We Are – 05 <em>Broken</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=94969a72-a40a-495a-a71c-df578ac21eca" />
      </body>
      <title>Goodbye AlphaServer</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,94969a72-a40a-495a-a71c-df578ac21eca.aspx</guid>
      <link>http://www.ntldr.com/2010/03/21/GoodbyeAlphaServer.aspx</link>
      <pubDate>Sun, 21 Mar 2010 23:29:43 GMT</pubDate>
      <description>&lt;p&gt;
This weekend I got rid of the Digital AlphaServer 4000 5/300 that I've had for a number
of years. It ended up going a friend, so hopefully some good use will be made of it.
Honestly, getting rid of it is probably for the best: it's a pain to move (huge +
weighs a third of a ton), and I haven't used it for a while...in fact, it hasn't been
plugged in since moving out to Oregon a couple years ago.
&lt;/p&gt;
&lt;p&gt;
Still, I can't help but feel a little bit nostalgic &amp;amp; miss it a little bit...
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Azure the AlphaServer" border="0" alt="Azure the AlphaServer" src="http://www.ntldr.com/attachments/WindowsLiveWriter/GoodbyeAlphaServer_14A66/IMG_0170_1.jpg" width="364" height="484" /&gt; 
&lt;/p&gt;
&lt;p&gt;
Between this &amp;amp; the other stuff I've given away over the last 4 months, I'm now
down to the fewest number of computers I've owned since December 2002. Huh. Seems
odd to realize that.
&lt;/p&gt;
&lt;p&gt;
Anyway, bye Azure the AlphaServer!
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Lifehouse – Who We Are – 05 &lt;em&gt;Broken&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=94969a72-a40a-495a-a71c-df578ac21eca" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,94969a72-a40a-495a-a71c-df578ac21eca.aspx</comments>
      <category>IT</category>
      <category>Personal</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=5cd76c89-692a-4a3c-b095-f756a781cd85</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,5cd76c89-692a-4a3c-b095-f756a781cd85.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,5cd76c89-692a-4a3c-b095-f756a781cd85.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=5cd76c89-692a-4a3c-b095-f756a781cd85</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Here's the workflow I used for analyzing the logs from this website:
</p>
        <ol>
          <li>
Wait until end of day. 
</li>
          <li>
Copy the day's log file to a temp directory. 
</li>
          <li>
Run the log loading utility (this also applies the geolocation lookups, so sometimes
the geoip databases need to be refreshed from <a href="http://www.maxmind.com">www.maxmind.com</a>) 
</li>
          <li>
After a bit (3-20 minutes usually; depends highly on the level of traffic), the log
entries are all in a SQL Server database. 
</li>
          <li>
The database has a View that filters out bots, crawlers, spammers, and internal traffic 
</li>
          <li>
I view the external user records by querying the view. 
</li>
        </ol>
        <p>
That view has a <em>horribly</em> complicated SELECT statement. Which I found out
this week had some bugs, so not all results were being correctly returned. And by
"horribly" complicated I mean that it has thousands of conditions that are
being evaluated.
</p>
        <p>
So after wasting a bunch of time trying to chase down where the problems were, I decided
to scrap that approach and come up with a better one. 
</p>
        <p>
What came to mind was developing some sort of "how-likely-is-it-that-this-record-should-be-hidden"
score. The more pieces of "evidence" that a particular request came from
a bot/crawler/spammer/etc., the higher the score.
</p>
        <p>
So now I've got a basic implementation going. It's written in C# 4.0 (hey, have to
play with the new stuff sometime!) and operates as a separate external utility that
persists the score as another field on each log entry's record. It took that massive
SELECT and refactored it down into 45 separate rule sets (classes)...much more manageable!
At the moment the scores from each rule are kind of arbitrary, and will probably need
to be redone/tweaked in the future. Right now I'm basically taking everything that
didn't match a rule (score = 0) and treating that as legitimate external traffic...which
seems to be working fairly well, but isn't really as fine grained as I originally
envisioned.
</p>
        <p>
Also, at some point (soon) I need to add more complex conditions. A couple of bots
operate in such a way that if you look at any one individual request to the web server,
that request is legitimate. But as soon as you see, say, 4 requests, repetitive patterns
start to emerge and it becomes obvious that some sort of crawling is going on. So
having an automated way to catch these would be nice...but also more complicated...probably
just haven't thought about it enough yet...
</p>
        <p>
Coolest parts of doing the new implementation: Linq to SQL, &amp; using Linq + reflection
to automatically discover all the rule sets. Just a couple lines of code to do such
complex things! And it's so much <em>simpler</em> with that syntax!
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: <a href="http://www.inflightsafety.ca/">In-Flight Safety</a> – We Are
An Empire, My Dear – 05 <em>Torches</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=5cd76c89-692a-4a3c-b095-f756a781cd85" />
      </body>
      <title>IIS Log Filtering – New approach</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,5cd76c89-692a-4a3c-b095-f756a781cd85.aspx</guid>
      <link>http://www.ntldr.com/2010/03/07/IISLogFilteringNewApproach.aspx</link>
      <pubDate>Sun, 07 Mar 2010 04:19:02 GMT</pubDate>
      <description>&lt;p&gt;
Here's the workflow I used for analyzing the logs from this website:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
Wait until end of day. 
&lt;/li&gt;
&lt;li&gt;
Copy the day's log file to a temp directory. 
&lt;/li&gt;
&lt;li&gt;
Run the log loading utility (this also applies the geolocation lookups, so sometimes
the geoip databases need to be refreshed from &lt;a href="http://www.maxmind.com"&gt;www.maxmind.com&lt;/a&gt;) 
&lt;/li&gt;
&lt;li&gt;
After a bit (3-20 minutes usually; depends highly on the level of traffic), the log
entries are all in a SQL Server database. 
&lt;/li&gt;
&lt;li&gt;
The database has a View that filters out bots, crawlers, spammers, and internal traffic 
&lt;/li&gt;
&lt;li&gt;
I view the external user records by querying the view. 
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
That view has a &lt;em&gt;horribly&lt;/em&gt; complicated SELECT statement. Which I found out
this week had some bugs, so not all results were being correctly returned. And by
&amp;quot;horribly&amp;quot; complicated I mean that it has thousands of conditions that are
being evaluated.
&lt;/p&gt;
&lt;p&gt;
So after wasting a bunch of time trying to chase down where the problems were, I decided
to scrap that approach and come up with a better one. 
&lt;/p&gt;
&lt;p&gt;
What came to mind was developing some sort of &amp;quot;how-likely-is-it-that-this-record-should-be-hidden&amp;quot;
score. The more pieces of &amp;quot;evidence&amp;quot; that a particular request came from
a bot/crawler/spammer/etc., the higher the score.
&lt;/p&gt;
&lt;p&gt;
So now I've got a basic implementation going. It's written in C# 4.0 (hey, have to
play with the new stuff sometime!) and operates as a separate external utility that
persists the score as another field on each log entry's record. It took that massive
SELECT and refactored it down into 45 separate rule sets (classes)...much more manageable!
At the moment the scores from each rule are kind of arbitrary, and will probably need
to be redone/tweaked in the future. Right now I'm basically taking everything that
didn't match a rule (score = 0) and treating that as legitimate external traffic...which
seems to be working fairly well, but isn't really as fine grained as I originally
envisioned.
&lt;/p&gt;
&lt;p&gt;
Also, at some point (soon) I need to add more complex conditions. A couple of bots
operate in such a way that if you look at any one individual request to the web server,
that request is legitimate. But as soon as you see, say, 4 requests, repetitive patterns
start to emerge and it becomes obvious that some sort of crawling is going on. So
having an automated way to catch these would be nice...but also more complicated...probably
just haven't thought about it enough yet...
&lt;/p&gt;
&lt;p&gt;
Coolest parts of doing the new implementation: Linq to SQL, &amp;amp; using Linq + reflection
to automatically discover all the rule sets. Just a couple lines of code to do such
complex things! And it's so much &lt;em&gt;simpler&lt;/em&gt; with that syntax!
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: &lt;a href="http://www.inflightsafety.ca/"&gt;In-Flight Safety&lt;/a&gt; – We Are
An Empire, My Dear – 05 &lt;em&gt;Torches&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=5cd76c89-692a-4a3c-b095-f756a781cd85" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,5cd76c89-692a-4a3c-b095-f756a781cd85.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=050ca564-7e16-456d-8159-680760db446e</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,050ca564-7e16-456d-8159-680760db446e.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,050ca564-7e16-456d-8159-680760db446e.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=050ca564-7e16-456d-8159-680760db446e</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Last Monday I applied a redirect rule to the site. And promptly watched (okay, so
it took me 4 hours to notice...) as things went crazy &amp; stuff broke. So, to help
avoid that in the future, here's what I did &amp; why I think it broke, and what was
done to fix it.
</p>
        <p>
Okay, so basically, there are 4 different domain names that can get visitors to this
site. That's nice and all, but it doesn't help the search engine rankings at all.
Also, it just seems kind of...repetitive (let's face it; this is probably the real
reason I bothered to mess with things; having 4 different paths isn't as <em>elegant</em> as
having just one). So I downloaded the URLRewrite add-on for IIS 7.5, installed it
and created a simple rule:
</p>
        <div class="csharpcode">
          <pre>
            <span class="lnum"> 1: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">rewrite</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 2: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">rules</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 3: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">rule</span>
            <span class="attr">name</span>
            <span class="kwrd">="Redirect
to www.ntldr.com"</span>
            <span class="attr">enabled</span>
            <span class="kwrd">="true"</span>
            <span class="attr">stopProcessing</span>
            <span class="kwrd">="true"</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 4: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">match</span>
            <span class="attr">url</span>
            <span class="kwrd">=".*"</span>
            <span class="kwrd">/&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 5: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">conditions</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 6: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">add</span>
            <span class="attr">input</span>
            <span class="kwrd">="{HTTP_HOST}"</span>
            <span class="attr">pattern</span>
            <span class="kwrd">="^(www.)ntldr.com$"</span>
            <span class="attr">negate</span>
            <span class="kwrd">="true"</span>
            <span class="kwrd">/&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 7: </span>
            <span class="kwrd">&lt;/</span>
            <span class="html">conditions</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 8: </span>
            <span class="kwrd">&lt;</span>
            <span class="html">action</span>
            <span class="attr">type</span>
            <span class="kwrd">="Redirect"</span>
            <span class="attr">url</span>
            <span class="kwrd">="http://www.ntldr.com/{R:0}"</span>
            <span class="kwrd">/&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 9: </span>
            <span class="kwrd">&lt;/</span>
            <span class="html">rule</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 10: </span>
            <span class="kwrd">&lt;/</span>
            <span class="html">rules</span>
            <span class="kwrd">&gt;</span>
          </pre>
          <pre>
            <span class="lnum"> 11: </span>
            <span class="kwrd">&lt;/</span>
            <span class="html">rewrite</span>
            <span class="kwrd">&gt;</span>
          </pre>
        </div>
        <style type="text/css">

.csharpcode, .csharpcode pre
{
	font-size: small;
	color: black;
	font-family: consolas, "Courier New", courier, monospace;
	background-color: #ffffff;
	/*white-space: pre;*/
}
.csharpcode pre { margin: 0em; }
.csharpcode .rem { color: #008000; }
.csharpcode .kwrd { color: #0000ff; }
.csharpcode .str { color: #006080; }
.csharpcode .op { color: #0000c0; }
.csharpcode .preproc { color: #cc6633; }
.csharpcode .asp { background-color: #ffff00; }
.csharpcode .html { color: #800000; }
.csharpcode .attr { color: #ff0000; }
.csharpcode .alt 
{
	background-color: #f4f4f4;
	width: 100%;
	margin: 0em;
}
.csharpcode .lnum { color: #606060; }</style>
        <p>
        </p>
        <p>
The rule looks at every URL used to get to the site, checks to see that the destination
server is <em>not</em> www.ntldr.com, and then redirects the request to http://www.ntldr.com/whatever-the-original-request-was.
Pretty simple, tested it internally, verified it was working, then applied it to the
site and went away for a few hours. 
</p>
        <p>
And came back to find that the logs had tens of thousands of entries. Mostly from
some computer in Kansas that kept going to / over and over and over and over again.
For almost 2 hours. The bots almost universally gave up after just 6 rounds. 
</p>
        <p>
Of course I immediately turned off the rewrite rule and frantically began looking
at logs &amp; network traces trying to figure out what the heck was going on and how
I managed to not catch it in testing. It quickly became apparent that the rule worked
internally, but not from outside the Forefront TMG 2010 firewall. Which narrowed down
the problem quite a bit, &amp; made me feel less incompetent (yay! the rule worked!),
but more stupid (doh! for not testing like an actual user would!). 
</p>
        <p>
However, examining the TMG logs didn't really yield anything useful. A request would
come in, it would go to the web server, a 301 Permanent Redirect would go back, and
then the client would seem to reissue the same request again. Out of desperation,
I decided to take a look at the rule and noticed this tab:
</p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web publishing rule: Link Translation tab" border="0" alt="Web publishing rule: Link Translation tab" src="http://www.ntldr.com/attachments/WindowsLiveWriter/URLRewritewhenbehindForefrontTMG_B35/image_3.png" width="404" height="484" />
        </p>
        <p>
At the time, "Apply link translation to this rule" was checked. And one
rule is used to make all 4 hosts accessible. Consequently, this is what the Link Translation
Mapping looked like:
</p>
        <p>
          <strong>Public name:</strong> ntldr.com
</p>
        <table border="1" cellspacing="0" cellpadding="0" width="450">
          <tbody>
            <tr>
              <td valign="top" width="133">
                <strong>Original URL</strong>
              </td>
              <td valign="top" width="133">
                <strong>Translated URL</strong>
              </td>
              <td valign="top" width="148">
                <strong>Mapping Details</strong>
              </td>
            </tr>
            <tr>
              <td valign="top" width="133">
http://ntldr.com</td>
              <td valign="top" width="133">
http://ntldr.com</td>
              <td valign="top" width="148">
Rule Defined: ntldr.com</td>
            </tr>
            <tr>
              <td valign="top" width="133">
http://www.ntldr.com</td>
              <td valign="top" width="133">
http://ntldr.com</td>
              <td valign="top" width="148">
Rule Defined: ntldr.com</td>
            </tr>
          </tbody>
        </table>
        <p>
 
</p>
        <p>
          <strong>Public name:</strong> ntldr.net
</p>
        <table border="1" cellspacing="0" cellpadding="0" width="450">
          <tbody>
            <tr>
              <td valign="top" width="150">
                <strong>Original URL</strong>
              </td>
              <td valign="top" width="150">
                <strong>Translated URL</strong>
              </td>
              <td valign="top" width="150">
                <strong>Mapping Details</strong>
              </td>
            </tr>
            <tr>
              <td valign="top" width="150">
http://ntldr.net</td>
              <td valign="top" width="150">
http://ntldr.net</td>
              <td valign="top" width="150">
Rule Defined: ntldr.com</td>
            </tr>
            <tr>
              <td valign="top" width="150">
http://www.ntldr.com</td>
              <td valign="top" width="150">
http://ntldr.net</td>
              <td valign="top" width="150">
Rule Defined: ntldr.com</td>
            </tr>
          </tbody>
        </table>
        <p>
 
</p>
        <p>
          <strong>Public name:</strong> www.ntldr.com
</p>
        <table border="1" cellspacing="0" cellpadding="0" width="450">
          <tbody>
            <tr>
              <td valign="top" width="150">
                <strong>Original URL</strong>
              </td>
              <td valign="top" width="150">
                <strong>Translated URL</strong>
              </td>
              <td valign="top" width="150">
                <strong>Mapping Details</strong>
              </td>
            </tr>
            <tr>
              <td valign="top" width="150">
http://www.ntldr.com</td>
              <td valign="top" width="150">
http://www.ntldr.com</td>
              <td valign="top" width="150">
Rule Defined: ntldr.com</td>
            </tr>
          </tbody>
        </table>
        <p>
 
</p>
        <p>
          <strong>Public name:</strong> www.ntldr.net
</p>
        <table border="1" cellspacing="0" cellpadding="0" width="450">
          <tbody>
            <tr>
              <td valign="top" width="150">
                <strong>Original URL</strong>
              </td>
              <td valign="top" width="150">
                <strong>Translated URL</strong>
              </td>
              <td valign="top" width="150">
                <strong>Mapping Details</strong>
              </td>
            </tr>
            <tr>
              <td valign="top" width="150">
http://www.ntldr.net</td>
              <td valign="top" width="150">
http://www.ntldr.net</td>
              <td valign="top" width="150">
Rule Defined: ntldr.com</td>
            </tr>
            <tr>
              <td valign="top" width="150">
http://www.ntldr.com</td>
              <td valign="top" width="150">
http://www.ntldr.net</td>
              <td valign="top" width="150">
Rule Defined: ntldr.com</td>
            </tr>
          </tbody>
        </table>
        <p>
 
</p>
        <p>
Oops. Fairly major, mind-numbingly stupid oops.
</p>
        <p>
See, this is what was happening:
</p>
        <ol>
          <li>
User visits http://ntldr.net.</li>
          <li>
Request for http://ntldr.net comes into Forefront TMG.</li>
          <li>
Forefront TMG processes the ntldr.com rule and forwards the request to www.ntldr.com
(at this point, an internal DNS alias for the actual server, tourmaline.global.ntldr.net).</li>
          <li>
IIS gets the request and applies rewrite rules.</li>
          <li>
Rewrite rules send a reply back saying "<strong>no, you really should go to http://www.ntldr.com</strong>".</li>
          <li>
Reply reaches Forefront TMG. Forefront TMG applies Link Translation mappings.</li>
          <li>
Link Translation mappings change that to "<strong>no, you really should go to
http://ntldr.net</strong>".</li>
          <li>
User dutifully goes to http://ntldr.net.</li>
          <li>
Repeat 1-8 until the user's browser either gives up (nice browsers), or the user gives
up (impatient users), or I disconnect them.</li>
        </ol>
        <p>
So, the solution: disable link translation in Forefront TMG. Note that I not only
had to do that on the rule itself, but also in the Web Filters. That <em>might</em> be
just because I was impatient and didn't wait for TMG to fully cycle and disable the
rule-level mappings. Not sure though, and haven't had a chance to find out yet.
</p>
        <p style="font-size: smaller; color: #7f7f7f;">
Now playing: <a href="http://radio3.cbc.ca/bands/New-Pornographers">The New Pornographers</a> –
Challengers – 07 <em>Unguided</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=050ca564-7e16-456d-8159-680760db446e" />
      </body>
      <title>URLRewrite when behind Forefront TMG</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,050ca564-7e16-456d-8159-680760db446e.aspx</guid>
      <link>http://www.ntldr.com/2010/02/21/URLRewriteWhenBehindForefrontTMG.aspx</link>
      <pubDate>Sun, 21 Feb 2010 23:59:00 GMT</pubDate>
      <description>&lt;p&gt;
Last Monday I applied a redirect rule to the site. And promptly watched (okay, so
it took me 4 hours to notice...) as things went crazy &amp;amp; stuff broke. So, to help
avoid that in the future, here's what I did &amp;amp; why I think it broke, and what was
done to fix it.
&lt;/p&gt;
&lt;p&gt;
Okay, so basically, there are 4 different domain names that can get visitors to this
site. That's nice and all, but it doesn't help the search engine rankings at all.
Also, it just seems kind of...repetitive (let's face it; this is probably the real
reason I bothered to mess with things; having 4 different paths isn't as &lt;em&gt;elegant&lt;/em&gt; as
having just one). So I downloaded the URLRewrite add-on for IIS 7.5, installed it
and created a simple rule:
&lt;/p&gt;
&lt;div class="csharpcode"&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 1: &lt;/span&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;rewrite&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 2: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;rules&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 3: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;rule&lt;/span&gt; &lt;span class="attr"&gt;name&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;Redirect
to www.ntldr.com&amp;quot;&lt;/span&gt; &lt;span class="attr"&gt;enabled&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;true&amp;quot;&lt;/span&gt; &lt;span class="attr"&gt;stopProcessing&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;true&amp;quot;&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 4: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;match&lt;/span&gt; &lt;span class="attr"&gt;url&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;.*&amp;quot;&lt;/span&gt; &lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 5: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;conditions&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 6: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;add&lt;/span&gt; &lt;span class="attr"&gt;input&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;{HTTP_HOST}&amp;quot;&lt;/span&gt; &lt;span class="attr"&gt;pattern&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;^(www.)ntldr.com$&amp;quot;&lt;/span&gt; &lt;span class="attr"&gt;negate&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;true&amp;quot;&lt;/span&gt; &lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 7: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;conditions&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 8: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;action&lt;/span&gt; &lt;span class="attr"&gt;type&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;Redirect&amp;quot;&lt;/span&gt; &lt;span class="attr"&gt;url&lt;/span&gt;&lt;span class="kwrd"&gt;=&amp;quot;http://www.ntldr.com/{R:0}&amp;quot;&lt;/span&gt; &lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 9: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;rule&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 10: &lt;/span&gt; &lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;rules&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span class="lnum"&gt; 11: &lt;/span&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;rewrite&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/div&gt;
&lt;style type="text/css"&gt;

.csharpcode, .csharpcode pre
{
	font-size: small;
	color: black;
	font-family: consolas, "Courier New", courier, monospace;
	background-color: #ffffff;
	/*white-space: pre;*/
}
.csharpcode pre { margin: 0em; }
.csharpcode .rem { color: #008000; }
.csharpcode .kwrd { color: #0000ff; }
.csharpcode .str { color: #006080; }
.csharpcode .op { color: #0000c0; }
.csharpcode .preproc { color: #cc6633; }
.csharpcode .asp { background-color: #ffff00; }
.csharpcode .html { color: #800000; }
.csharpcode .attr { color: #ff0000; }
.csharpcode .alt 
{
	background-color: #f4f4f4;
	width: 100%;
	margin: 0em;
}
.csharpcode .lnum { color: #606060; }&lt;/style&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;p&gt;
The rule looks at every URL used to get to the site, checks to see that the destination
server is &lt;em&gt;not&lt;/em&gt; www.ntldr.com, and then redirects the request to http://www.ntldr.com/whatever-the-original-request-was.
Pretty simple, tested it internally, verified it was working, then applied it to the
site and went away for a few hours. 
&lt;/p&gt;
&lt;p&gt;
And came back to find that the logs had tens of thousands of entries. Mostly from
some computer in Kansas that kept going to / over and over and over and over again.
For almost 2 hours. The bots almost universally gave up after just 6 rounds. 
&lt;/p&gt;
&lt;p&gt;
Of course I immediately turned off the rewrite rule and frantically began looking
at logs &amp;amp; network traces trying to figure out what the heck was going on and how
I managed to not catch it in testing. It quickly became apparent that the rule worked
internally, but not from outside the Forefront TMG 2010 firewall. Which narrowed down
the problem quite a bit, &amp;amp; made me feel less incompetent (yay! the rule worked!),
but more stupid (doh! for not testing like an actual user would!). 
&lt;/p&gt;
&lt;p&gt;
However, examining the TMG logs didn't really yield anything useful. A request would
come in, it would go to the web server, a 301 Permanent Redirect would go back, and
then the client would seem to reissue the same request again. Out of desperation,
I decided to take a look at the rule and noticed this tab:
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web publishing rule: Link Translation tab" border="0" alt="Web publishing rule: Link Translation tab" src="http://www.ntldr.com/attachments/WindowsLiveWriter/URLRewritewhenbehindForefrontTMG_B35/image_3.png" width="404" height="484" /&gt; 
&lt;/p&gt;
&lt;p&gt;
At the time, &amp;quot;Apply link translation to this rule&amp;quot; was checked. And one
rule is used to make all 4 hosts accessible. Consequently, this is what the Link Translation
Mapping looked like:
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Public name:&lt;/strong&gt; ntldr.com
&lt;/p&gt;
&lt;table border="1" cellspacing="0" cellpadding="0" width="450"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td valign="top" width="133"&gt;
&lt;strong&gt;Original URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="133"&gt;
&lt;strong&gt;Translated URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="148"&gt;
&lt;strong&gt;Mapping Details&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="133"&gt;
http://ntldr.com&lt;/td&gt;
&lt;td valign="top" width="133"&gt;
http://ntldr.com&lt;/td&gt;
&lt;td valign="top" width="148"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="133"&gt;
http://www.ntldr.com&lt;/td&gt;
&lt;td valign="top" width="133"&gt;
http://ntldr.com&lt;/td&gt;
&lt;td valign="top" width="148"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Public name:&lt;/strong&gt; ntldr.net
&lt;/p&gt;
&lt;table border="1" cellspacing="0" cellpadding="0" width="450"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Original URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Translated URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Mapping Details&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
http://ntldr.net&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
http://ntldr.net&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.com&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
http://ntldr.net&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Public name:&lt;/strong&gt; www.ntldr.com
&lt;/p&gt;
&lt;table border="1" cellspacing="0" cellpadding="0" width="450"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Original URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Translated URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Mapping Details&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.com&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.com&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Public name:&lt;/strong&gt; www.ntldr.net
&lt;/p&gt;
&lt;table border="1" cellspacing="0" cellpadding="0" width="450"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Original URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Translated URL&lt;/strong&gt;&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
&lt;strong&gt;Mapping Details&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.net&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.net&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.com&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
http://www.ntldr.net&lt;/td&gt;
&lt;td valign="top" width="150"&gt;
Rule Defined: ntldr.com&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
Oops. Fairly major, mind-numbingly stupid oops.
&lt;/p&gt;
&lt;p&gt;
See, this is what was happening:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
User visits http://ntldr.net.&lt;/li&gt;
&lt;li&gt;
Request for http://ntldr.net comes into Forefront TMG.&lt;/li&gt;
&lt;li&gt;
Forefront TMG processes the ntldr.com rule and forwards the request to www.ntldr.com
(at this point, an internal DNS alias for the actual server, tourmaline.global.ntldr.net).&lt;/li&gt;
&lt;li&gt;
IIS gets the request and applies rewrite rules.&lt;/li&gt;
&lt;li&gt;
Rewrite rules send a reply back saying &amp;quot;&lt;strong&gt;no, you really should go to http://www.ntldr.com&lt;/strong&gt;&amp;quot;.&lt;/li&gt;
&lt;li&gt;
Reply reaches Forefront TMG. Forefront TMG applies Link Translation mappings.&lt;/li&gt;
&lt;li&gt;
Link Translation mappings change that to &amp;quot;&lt;strong&gt;no, you really should go to
http://ntldr.net&lt;/strong&gt;&amp;quot;.&lt;/li&gt;
&lt;li&gt;
User dutifully goes to http://ntldr.net.&lt;/li&gt;
&lt;li&gt;
Repeat 1-8 until the user's browser either gives up (nice browsers), or the user gives
up (impatient users), or I disconnect them.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
So, the solution: disable link translation in Forefront TMG. Note that I not only
had to do that on the rule itself, but also in the Web Filters. That &lt;em&gt;might&lt;/em&gt; be
just because I was impatient and didn't wait for TMG to fully cycle and disable the
rule-level mappings. Not sure though, and haven't had a chance to find out yet.
&lt;/p&gt;
&lt;p style="font-size: smaller; color: #7f7f7f;"&gt;
Now playing: &lt;a href="http://radio3.cbc.ca/bands/New-Pornographers"&gt;The New Pornographers&lt;/a&gt; –
Challengers – 07 &lt;em&gt;Unguided&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=050ca564-7e16-456d-8159-680760db446e" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,050ca564-7e16-456d-8159-680760db446e.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=1724b0ca-6caf-4bbb-8217-2995213703fb</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,1724b0ca-6caf-4bbb-8217-2995213703fb.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,1724b0ca-6caf-4bbb-8217-2995213703fb.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=1724b0ca-6caf-4bbb-8217-2995213703fb</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Originally, this post was going to be a rant about how SQL Server Reporting Services
is useless, and how Excel was so much easier for creating graphs &amp; doing useful
analysis of data. Then I spent an hour and a half messing around writing queries,
executing queries, exporting &amp; importing result sets, and then manipulating the
data. So all the "oomph" has kind of gone out of that rant. 
</p>
        <p>
Besides, I shouldn't even be messing around with this data; there are a bunch of very
nice programs/scripts sitting around on the Internet to do the analysis &amp; reporting
for me. But doing things the easy way would be cheating. So instead I keep mucking
around with my own custom tools &amp; processes.
</p>
        <p>
In any case, here's a bunch of pretty graphs showing the human-like page views per
week broken out by country of origin. Data for other views is a bit...messy...right
now. The per-country stuff is fairly clean because I'm just using a geoip database
to map requesting IP address to source country.
</p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_3.png" width="485" height="365" />
        </p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_15.png" width="485" height="365" />
        </p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_14.png" width="485" height="364" />
        </p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_13.png" width="485" height="367" />
        </p>
        <p>
          <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_12.png" width="485" height="370" />
        </p>
        <p>
(yes, one would have probably been sufficient to show what I was doing, but hey, if
one is good, five is even better?)
</p>
        <p>
(also, in all honesty, I'm guessing I don't have enough consistent traffic to make
looking at a week-by-week view meaningful; better would probably be to focus on longer
time spans, like a month or so)
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: <a href="http://radio3.cbc.ca/bands/Matthew-Barber">Matthew Barber</a> –
Ghost Notes – 06 <em>One Little Piece of My Love</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=1724b0ca-6caf-4bbb-8217-2995213703fb" />
      </body>
      <title>Web site statistics</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,1724b0ca-6caf-4bbb-8217-2995213703fb.aspx</guid>
      <link>http://www.ntldr.com/2010/02/08/WebSiteStatistics.aspx</link>
      <pubDate>Mon, 08 Feb 2010 02:34:51 GMT</pubDate>
      <description>&lt;p&gt;
Originally, this post was going to be a rant about how SQL Server Reporting Services
is useless, and how Excel was so much easier for creating graphs &amp;amp; doing useful
analysis of data. Then I spent an hour and a half messing around writing queries,
executing queries, exporting &amp;amp; importing result sets, and then manipulating the
data. So all the &amp;quot;oomph&amp;quot; has kind of gone out of that rant. 
&lt;/p&gt;
&lt;p&gt;
Besides, I shouldn't even be messing around with this data; there are a bunch of very
nice programs/scripts sitting around on the Internet to do the analysis &amp;amp; reporting
for me. But doing things the easy way would be cheating. So instead I keep mucking
around with my own custom tools &amp;amp; processes.
&lt;/p&gt;
&lt;p&gt;
In any case, here's a bunch of pretty graphs showing the human-like page views per
week broken out by country of origin. Data for other views is a bit...messy...right
now. The per-country stuff is fairly clean because I'm just using a geoip database
to map requesting IP address to source country.
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_3.png" width="485" height="365" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_15.png" width="485" height="365" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_14.png" width="485" height="364" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_13.png" width="485" height="367" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.ntldr.com/attachments/WindowsLiveWriter/Websitestatistics_2448/image_12.png" width="485" height="370" /&gt; 
&lt;/p&gt;
&lt;p&gt;
(yes, one would have probably been sufficient to show what I was doing, but hey, if
one is good, five is even better?)
&lt;/p&gt;
&lt;p&gt;
(also, in all honesty, I'm guessing I don't have enough consistent traffic to make
looking at a week-by-week view meaningful; better would probably be to focus on longer
time spans, like a month or so)
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: &lt;a href="http://radio3.cbc.ca/bands/Matthew-Barber"&gt;Matthew Barber&lt;/a&gt; –
Ghost Notes – 06 &lt;em&gt;One Little Piece of My Love&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=1724b0ca-6caf-4bbb-8217-2995213703fb" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,1724b0ca-6caf-4bbb-8217-2995213703fb.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=a65eb988-f12d-49aa-93d4-075925aad68c</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,a65eb988-f12d-49aa-93d4-075925aad68c.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,a65eb988-f12d-49aa-93d4-075925aad68c.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=a65eb988-f12d-49aa-93d4-075925aad68c</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Hmm... can this get posted from Microsoft Office Word 2010 Beta? 
</p>
        <p>
Here, let's try a picture too: 
</p>
        <p>
          <img src="http://www.ntldr.com/attachments/111809_0045_TestPostWor1.jpg" alt="" />
        </p>
        <p>
&amp; how about a category too while I'm at it? 
</p>
        <p>
          <span style="color:#c0504d">
            <em>Update: okay, so can I update this too? </em>
          </span>
        </p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=a65eb988-f12d-49aa-93d4-075925aad68c" />
      </body>
      <title>Test Post (Word 2010)</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,a65eb988-f12d-49aa-93d4-075925aad68c.aspx</guid>
      <link>http://www.ntldr.com/2009/11/18/TestPostWord2010.aspx</link>
      <pubDate>Wed, 18 Nov 2009 00:45:29 GMT</pubDate>
      <description>&lt;p&gt;
Hmm... can this get posted from Microsoft Office Word 2010 Beta? 
&lt;/p&gt;
&lt;p&gt;
Here, let's try a picture too: 
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.ntldr.com/attachments/111809_0045_TestPostWor1.jpg" alt="" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&amp;amp; how about a category too while I'm at it? 
&lt;/p&gt;
&lt;p&gt;
&lt;span style="color:#c0504d"&gt;&lt;em&gt;Update: okay, so can I update this too? &lt;/em&gt;&lt;/span&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=a65eb988-f12d-49aa-93d4-075925aad68c" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,a65eb988-f12d-49aa-93d4-075925aad68c.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=f79f303b-93b1-48d2-9cba-b869802c1955</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,f79f303b-93b1-48d2-9cba-b869802c1955.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,f79f303b-93b1-48d2-9cba-b869802c1955.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=f79f303b-93b1-48d2-9cba-b869802c1955</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Okay, Hyper-V is cool. It's fast, easy to use, has a lot more features, &amp; generally
works very nicely. Much better than Virtual Server 2005 R2. Moved this website over
to a new VM (upgraded to 64-bit Windows Server 2008 R2 in the process...yeah!) on
my new server, and it's working great (I hope...guess I'll know for sure if any comments
get posted...:)). Tried moving another VM over just by coping the VHD file, but that
didn't work so well. Didn't really expect it to before trying, but then got hopeful
when first starting it up and trying to install the integration components, and now
have finally accepted that the two solutions (VS2005R2 &amp; Hyper-V) are just too
different for things to work.
</p>
        <p>
Not sure I care that much for Hyper-V's licensing model though...yes, the basic product
is free, but to get the "good" management tools you have to shell out the
big $$$'s for System Center Virtual Machine Manager. Guess I'm just greedy and want
everything for free... ;) (no, seriously, would it be too hard to have a management
interface that allows you to see, at a glance, how many resources have been allocated
to the VM's? kind of like the old VMRCplus view?)
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Stabbing Westward – Stabbing Westward – 07 <em>Angel</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=f79f303b-93b1-48d2-9cba-b869802c1955" />
      </body>
      <title>Hyper-V</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,f79f303b-93b1-48d2-9cba-b869802c1955.aspx</guid>
      <link>http://www.ntldr.com/2009/11/16/HyperV.aspx</link>
      <pubDate>Mon, 16 Nov 2009 04:39:05 GMT</pubDate>
      <description>&lt;p&gt;
Okay, Hyper-V is cool. It's fast, easy to use, has a lot more features, &amp;amp; generally
works very nicely. Much better than Virtual Server 2005 R2. Moved this website over
to a new VM (upgraded to 64-bit Windows Server 2008 R2 in the process...yeah!) on
my new server, and it's working great (I hope...guess I'll know for sure if any comments
get posted...:)). Tried moving another VM over just by coping the VHD file, but that
didn't work so well. Didn't really expect it to before trying, but then got hopeful
when first starting it up and trying to install the integration components, and now
have finally accepted that the two solutions (VS2005R2 &amp;amp; Hyper-V) are just too
different for things to work.
&lt;/p&gt;
&lt;p&gt;
Not sure I care that much for Hyper-V's licensing model though...yes, the basic product
is free, but to get the &amp;quot;good&amp;quot; management tools you have to shell out the
big $$$'s for System Center Virtual Machine Manager. Guess I'm just greedy and want
everything for free... ;) (no, seriously, would it be too hard to have a management
interface that allows you to see, at a glance, how many resources have been allocated
to the VM's? kind of like the old VMRCplus view?)
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Stabbing Westward – Stabbing Westward – 07 &lt;em&gt;Angel&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=f79f303b-93b1-48d2-9cba-b869802c1955" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,f79f303b-93b1-48d2-9cba-b869802c1955.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=937ea4fd-d294-41b9-9f04-8e2ac3deacda</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,937ea4fd-d294-41b9-9f04-8e2ac3deacda.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,937ea4fd-d294-41b9-9f04-8e2ac3deacda.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=937ea4fd-d294-41b9-9f04-8e2ac3deacda</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Looks like my nice new Intel SR1630HGP server, with its Intel Xeon X3460 processor
is affected by the <a href="http://msdn.microsoft.com/en-us/library/aa469194.aspx">CLOCK_WATCHDOG_TIMEOUT</a> STOP
error discussed in <a href="http://support.microsoft.com/kb/975530">KB975530</a>:
</p>
        <pre>0: kd&gt; !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CLOCK_WATCHDOG_TIMEOUT (101)
An expected clock interrupt was not received on a secondary processor in an
MP system within the allocated interval. This indicates that the specified
processor is hung and not processing interrupts.
Arguments:
Arg1: 0000000000000019, Clock interrupt time out interval in nominal clock ticks.
Arg2: 0000000000000000, 0.
Arg3: fffff880021e1180, The PRCB address of the hung processor.
Arg4: 0000000000000006, 0.</pre>
        <p>
(additional details follow that but don't really add anything)
</p>
        <p>
GRRRRR!!! Looks like, at the time of this writing, the KB article needs to be updated,
since the Xeon 3400 series aren't Xeon 5500's, nor Core i5's, nor Core i7's...
</p>
        <p style="font-size: smaller; color: #7f7f7f;">
Now playing: The Beatles – One – 26 <em>Let It Be</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=937ea4fd-d294-41b9-9f04-8e2ac3deacda" />
      </body>
      <title>Windows Server 2008 R2 with an Intel Xeon 3400 series needs KB975530</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,937ea4fd-d294-41b9-9f04-8e2ac3deacda.aspx</guid>
      <link>http://www.ntldr.com/2009/11/08/WindowsServer2008R2WithAnIntelXeon3400SeriesNeedsKB975530.aspx</link>
      <pubDate>Sun, 08 Nov 2009 02:48:13 GMT</pubDate>
      <description>&lt;p&gt;
Looks like my nice new Intel SR1630HGP server, with its Intel Xeon X3460 processor
is affected by the &lt;a href="http://msdn.microsoft.com/en-us/library/aa469194.aspx"&gt;CLOCK_WATCHDOG_TIMEOUT&lt;/a&gt; STOP
error discussed in &lt;a href="http://support.microsoft.com/kb/975530"&gt;KB975530&lt;/a&gt;:
&lt;/p&gt;
&lt;pre&gt;0: kd&amp;gt; !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CLOCK_WATCHDOG_TIMEOUT (101)
An expected clock interrupt was not received on a secondary processor in an
MP system within the allocated interval. This indicates that the specified
processor is hung and not processing interrupts.
Arguments:
Arg1: 0000000000000019, Clock interrupt time out interval in nominal clock ticks.
Arg2: 0000000000000000, 0.
Arg3: fffff880021e1180, The PRCB address of the hung processor.
Arg4: 0000000000000006, 0.&lt;/pre&gt;
&lt;p&gt;
(additional details follow that but don't really add anything)
&lt;/p&gt;
&lt;p&gt;
GRRRRR!!! Looks like, at the time of this writing, the KB article needs to be updated,
since the Xeon 3400 series aren't Xeon 5500's, nor Core i5's, nor Core i7's...
&lt;/p&gt;
&lt;p style="font-size: smaller; color: #7f7f7f;"&gt;
Now playing: The Beatles – One – 26 &lt;em&gt;Let It Be&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=937ea4fd-d294-41b9-9f04-8e2ac3deacda" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,937ea4fd-d294-41b9-9f04-8e2ac3deacda.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=f1791936-e6be-40ca-9dd1-02cd3f260e9f</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,f1791936-e6be-40ca-9dd1-02cd3f260e9f.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,f1791936-e6be-40ca-9dd1-02cd3f260e9f.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=f1791936-e6be-40ca-9dd1-02cd3f260e9f</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
0xc0000225 error when trying to boot into the Windows Server 2008 R2 installer? And
you're running on a Broadcom HT1000 based motherboard? Solution: hide/disable the
XIOAPIC functions of the HT1000.
</p>
        <p>
On the Supermicro H8SSL-i board this means going into the BIOS, Advanced tab, Advanced
Chipset Control menu, "HT1000 Southbridge Configuration" menu, and finally
changing the "Hide XIOAPIC PCI Functions" option to "Yes". Save
the changes and reboot. (Note that this applies to v1.2 of the BIOS...which based
on its age is probably going to be the last one ever released for that board...)
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Emm Gryner – Public – 08 <em>Your Sort of Human Being</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=f1791936-e6be-40ca-9dd1-02cd3f260e9f" />
      </body>
      <title>Windows Server 2008 R2 and Broadcom HT1000 chipset</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,f1791936-e6be-40ca-9dd1-02cd3f260e9f.aspx</guid>
      <link>http://www.ntldr.com/2009/11/04/WindowsServer2008R2AndBroadcomHT1000Chipset.aspx</link>
      <pubDate>Wed, 04 Nov 2009 04:33:53 GMT</pubDate>
      <description>&lt;p&gt;
0xc0000225 error when trying to boot into the Windows Server 2008 R2 installer? And
you're running on a Broadcom HT1000 based motherboard? Solution: hide/disable the
XIOAPIC functions of the HT1000.
&lt;/p&gt;
&lt;p&gt;
On the Supermicro H8SSL-i board this means going into the BIOS, Advanced tab, Advanced
Chipset Control menu, &amp;quot;HT1000 Southbridge Configuration&amp;quot; menu, and finally
changing the &amp;quot;Hide XIOAPIC PCI Functions&amp;quot; option to &amp;quot;Yes&amp;quot;. Save
the changes and reboot. (Note that this applies to v1.2 of the BIOS...which based
on its age is probably going to be the last one ever released for that board...)
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Emm Gryner – Public – 08 &lt;em&gt;Your Sort of Human Being&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=f1791936-e6be-40ca-9dd1-02cd3f260e9f" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,f1791936-e6be-40ca-9dd1-02cd3f260e9f.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=7b3f3df6-bb41-4217-8acc-bd529c12eecd</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,7b3f3df6-bb41-4217-8acc-bd529c12eecd.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,7b3f3df6-bb41-4217-8acc-bd529c12eecd.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=7b3f3df6-bb41-4217-8acc-bd529c12eecd</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Got a brand spanking new Intel Xeon X34xx (Nehalem based!) server recently (like within
the last month). It’s a barebones Intel Server System SR1630HGP, with an Intel S3420GP
motherboard. Which means...it supports EFI! So I'd finally be able to see what all
the hype &amp; excitement about the cool new BIOS replacement was! And I'd be able
to boot off a storage array &gt; 2TB in size! Or so I thought (insert thunderclaps,
lightning, and other ominous (or just drama enhancing) signs here).
</p>
        <p>
It turns out there's a bit more to getting EFI to work with Windows than just popping
the DVD in the drive and powering up the computer. A brief caveat here at the beginning:
these comments apply to the following firmware, so the settings may change as new
releases are made:
</p>
        <ul>
          <li>
BIOS: S3420GP.86B.01.00.0027 
</li>
          <li>
BMC: v01.14 
</li>
          <li>
FRUSDR: 15 
</li>
          <li>
Windows Server 2008 R2 (RTM) 
</li>
        </ul>
        <p>
So, first of all, the RAID functions of the chipset don't work with EFI. Period. Neither
the Intel Matrix RAID option ROM, nor the LSI/ESRT2 option ROM, appear to support
EFI. Sure, they're useable with the CSM enabled, and the system setup may make it
seem like they can be enabled, but as soon as EFI is used, things just stop working
and any arrays either wont be bootable or wont even be found.
</p>
        <p>
Actually, even with a standalone LSI MegaRAID SAS 9260-4i, things aren't that easy
to get working. The CSM has to be enabled in order to get into the controllers firmware
("WebBIOS" or something now). And there's only like half a second to press
the right keys to get into it the first time... But once the arrays and any settings
are configured, EFI does work with the controller and CSM can be disabled.
</p>
        <p>
Oh, and if using an internal SATA DVD drive, apparently it has to be plugged into
port 5, otherwise it doesn't always show up as a bootable device. This might just
be a legacy of leaving the Matrix RAID enabled when it shouldn't have been, but with
the drive on port 5 it always worked.
</p>
        <p>
Once the storage stuff is taken care of, the big tricky bit is that Windows apparently
requires a VGA BIOS to be present in order to work properly. This little nugget of
crucial information can be found by digging around the <a href="http://www.microsoft.com/whdc/system/platform/firmware/default.mspx">Windows
Hardware Design site</a> and reading up on firmware &amp; UEFI/EFI. In the system
setup, there's a setting for "Enable Use Legacy Video for EFI OS" that becomes
available when "Enable EFI Optimized Boot" is enabled. BOTH settings need
to be enabled for Windows to successfully run. I <em>think </em>I <em>may</em> have
been able to get WinPE to start off the DVD without the video setting enabled, but
it certainly wasn't stable &amp; reliable. <em>May</em> just have been that the setting
didn't actually get cleared, got temporarily turned back on again, or I'm just confused
by having tried too many different things.
</p>
        <p>
A final bit of trouble I ran into was getting Windows Setup to not encounter errors.
For some reason it kept saying that Windows couldn't be installed to the drive because
the system couldn't boot from the selected drive (although Setup would let you continue
with the installation, true to its word, Windows wouldn't boot after setup). To fix
this issue, I had to boot into WinPE (with CSM enabled/EFI boot disabled again! otherwise
you can't get a command prompt from the setup disks!), fire up diskpart, convert the
disk to GPT, then manually create the EFI System Partition (ESP) and Microsoft Reserved
Partition (MSR). The next time setup started from an EFI boot, the error was gone
and setup worked correctly.
</p>
        <p>
So, a summary of what needs to be done:
</p>
        <ol>
          <li>
Make sure the DVD drive is connected to SATA port 5! 
</li>
          <li>
Get a FAT32 EFI System Partition created on the disk somehow. 
</li>
          <li>
In the firmware setup: 
<ol><li>
Switch SATA controller to AHCI mode 
</li><li>
Disable AHCI Option ROM 
</li><li>
Enable EFI Optimized Boot 
</li><li>
Enable Use Legacy Video for EFI OS 
</li></ol></li>
          <li>
Save changes to firmware setup, then reenter it to double check that the settings
took (&amp; to verify the boot settings...those have an annoying habit of changing
all the time) 
</li>
          <li>
Start up Windows Setup and install 
</li>
        </ol>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Emm Gryner – Public – 05 <em>Phonecall 45</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7b3f3df6-bb41-4217-8acc-bd529c12eecd" />
      </body>
      <title>Windows, EFI, and an Intel S3420GP</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,7b3f3df6-bb41-4217-8acc-bd529c12eecd.aspx</guid>
      <link>http://www.ntldr.com/2009/11/04/WindowsEFIAndAnIntelS3420GP.aspx</link>
      <pubDate>Wed, 04 Nov 2009 04:24:46 GMT</pubDate>
      <description>&lt;p&gt;
Got a brand spanking new Intel Xeon X34xx (Nehalem based!) server recently (like within
the last month). It’s a barebones Intel Server System SR1630HGP, with an Intel S3420GP
motherboard. Which means...it supports EFI! So I'd finally be able to see what all
the hype &amp;amp; excitement about the cool new BIOS replacement was! And I'd be able
to boot off a storage array &amp;gt; 2TB in size! Or so I thought (insert thunderclaps,
lightning, and other ominous (or just drama enhancing) signs here).
&lt;/p&gt;
&lt;p&gt;
It turns out there's a bit more to getting EFI to work with Windows than just popping
the DVD in the drive and powering up the computer. A brief caveat here at the beginning:
these comments apply to the following firmware, so the settings may change as new
releases are made:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
BIOS: S3420GP.86B.01.00.0027 
&lt;/li&gt;
&lt;li&gt;
BMC: v01.14 
&lt;/li&gt;
&lt;li&gt;
FRUSDR: 15 
&lt;/li&gt;
&lt;li&gt;
Windows Server 2008 R2 (RTM) 
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
So, first of all, the RAID functions of the chipset don't work with EFI. Period. Neither
the Intel Matrix RAID option ROM, nor the LSI/ESRT2 option ROM, appear to support
EFI. Sure, they're useable with the CSM enabled, and the system setup may make it
seem like they can be enabled, but as soon as EFI is used, things just stop working
and any arrays either wont be bootable or wont even be found.
&lt;/p&gt;
&lt;p&gt;
Actually, even with a standalone LSI MegaRAID SAS 9260-4i, things aren't that easy
to get working. The CSM has to be enabled in order to get into the controllers firmware
(&amp;quot;WebBIOS&amp;quot; or something now). And there's only like half a second to press
the right keys to get into it the first time... But once the arrays and any settings
are configured, EFI does work with the controller and CSM can be disabled.
&lt;/p&gt;
&lt;p&gt;
Oh, and if using an internal SATA DVD drive, apparently it has to be plugged into
port 5, otherwise it doesn't always show up as a bootable device. This might just
be a legacy of leaving the Matrix RAID enabled when it shouldn't have been, but with
the drive on port 5 it always worked.
&lt;/p&gt;
&lt;p&gt;
Once the storage stuff is taken care of, the big tricky bit is that Windows apparently
requires a VGA BIOS to be present in order to work properly. This little nugget of
crucial information can be found by digging around the &lt;a href="http://www.microsoft.com/whdc/system/platform/firmware/default.mspx"&gt;Windows
Hardware Design site&lt;/a&gt; and reading up on firmware &amp;amp; UEFI/EFI. In the system
setup, there's a setting for &amp;quot;Enable Use Legacy Video for EFI OS&amp;quot; that becomes
available when &amp;quot;Enable EFI Optimized Boot&amp;quot; is enabled. BOTH settings need
to be enabled for Windows to successfully run. I &lt;em&gt;think &lt;/em&gt;I &lt;em&gt;may&lt;/em&gt; have
been able to get WinPE to start off the DVD without the video setting enabled, but
it certainly wasn't stable &amp;amp; reliable. &lt;em&gt;May&lt;/em&gt; just have been that the setting
didn't actually get cleared, got temporarily turned back on again, or I'm just confused
by having tried too many different things.
&lt;/p&gt;
&lt;p&gt;
A final bit of trouble I ran into was getting Windows Setup to not encounter errors.
For some reason it kept saying that Windows couldn't be installed to the drive because
the system couldn't boot from the selected drive (although Setup would let you continue
with the installation, true to its word, Windows wouldn't boot after setup). To fix
this issue, I had to boot into WinPE (with CSM enabled/EFI boot disabled again! otherwise
you can't get a command prompt from the setup disks!), fire up diskpart, convert the
disk to GPT, then manually create the EFI System Partition (ESP) and Microsoft Reserved
Partition (MSR). The next time setup started from an EFI boot, the error was gone
and setup worked correctly.
&lt;/p&gt;
&lt;p&gt;
So, a summary of what needs to be done:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
Make sure the DVD drive is connected to SATA port 5! 
&lt;/li&gt;
&lt;li&gt;
Get a FAT32 EFI System Partition created on the disk somehow. 
&lt;/li&gt;
&lt;li&gt;
In the firmware setup: 
&lt;ol&gt;
&lt;li&gt;
Switch SATA controller to AHCI mode 
&lt;/li&gt;
&lt;li&gt;
Disable AHCI Option ROM 
&lt;/li&gt;
&lt;li&gt;
Enable EFI Optimized Boot 
&lt;/li&gt;
&lt;li&gt;
Enable Use Legacy Video for EFI OS 
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;
Save changes to firmware setup, then reenter it to double check that the settings
took (&amp;amp; to verify the boot settings...those have an annoying habit of changing
all the time) 
&lt;/li&gt;
&lt;li&gt;
Start up Windows Setup and install 
&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Emm Gryner – Public – 05 &lt;em&gt;Phonecall 45&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7b3f3df6-bb41-4217-8acc-bd529c12eecd" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,7b3f3df6-bb41-4217-8acc-bd529c12eecd.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=5c04b94a-70f9-422c-b9a3-09e113434d93</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,5c04b94a-70f9-422c-b9a3-09e113434d93.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,5c04b94a-70f9-422c-b9a3-09e113434d93.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=5c04b94a-70f9-422c-b9a3-09e113434d93</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <em>Retracted. This scenario is not supported, and there are numerous additional issues
that need to be resolved that were not covered in the original post.</em>
        </p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Amy Millan – Masters of the Burial – 02 <em>Low Sail</em></p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=5c04b94a-70f9-422c-b9a3-09e113434d93" />
      </body>
      <title>How to get CGI Ratabase Product Builder v6 running in a Citrix environment</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,5c04b94a-70f9-422c-b9a3-09e113434d93.aspx</guid>
      <link>http://www.ntldr.com/2009/10/09/HowToGetCGIRatabaseProductBuilderV6RunningInACitrixEnvironment.aspx</link>
      <pubDate>Fri, 09 Oct 2009 05:32:52 GMT</pubDate>
      <description>&lt;p&gt;
&lt;em&gt;Retracted. This scenario is not supported, and there are numerous additional issues
that need to be resolved that were not covered in the original post.&lt;/em&gt;
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Amy Millan – Masters of the Burial – 02 &lt;em&gt;Low Sail&lt;/em&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=5c04b94a-70f9-422c-b9a3-09e113434d93" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,5c04b94a-70f9-422c-b9a3-09e113434d93.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=13f93399-066c-4c63-a8d2-edc3fccbac9e</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,13f93399-066c-4c63-a8d2-edc3fccbac9e.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,13f93399-066c-4c63-a8d2-edc3fccbac9e.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=13f93399-066c-4c63-a8d2-edc3fccbac9e</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Windows Live has this cool thing where it reminds you about your contact’s birthdays
(the “Birthday Calendar” I think…). And yes, I’ve come to rely on this feature. Unfortunately,
I can’t quite bring myself to trust the system completely, so whenever I get the alerts,
I also get this nagging doubt that it’s not really that person’s birthday and that
I’ve really just misentered their contact info…
</p>
        <p>
Wow Windows XP is showing it’s age…the RTM installation disc I have is reacting badly
to the &gt;127GB hard drive I’m trying to install on…(yes, I know the way to correct
this is to use SP1…which is why I’m slipstreaming SP3 onto a new installation disc
right now…)
</p>
        <p>
Hey! xcopy on Windows 7 seems to have a new option: /J (“Copies using unbuffered I/O.
Recommended for very large files.”) Cool!
</p>
        <p>
Command just used to build the Windows XP with SP3 disc: oscdimg -n -b"amd64\boot\ETFSBOOT.COM"
-lWXP_VOL_EN_SP3 -t04/14/2008,07:53:59 -g -h -maxsize:4096 "E:\CD Build\windows_xp_sp3"
"E:\CD build\windows_xp_sp3.iso". I’m probably a short DVD burn away from
finding out just how wrong that was…(much later)…hey, that actually worked!
</p>
        <p>
Oo…coool…Windows XP <em>does</em> have regional settings for Filipino…too bad the
timezone stuff doesn’t have one (instead I end up guessing…”it’s close enough to Singapore,
right?” note that this results in the timezone being "Malay Peninsula Standard
Time")
</p>
        <p>
Who makes &amp; sells a DVD drive <em>that can’t play DVD’s</em>?!?!?! I mean, I could
sort of understand a bare OEM drive…but these are boxed retail drives from HP! Grrr…
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: (nothing but the sound of computer fans)
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=13f93399-066c-4c63-a8d2-edc3fccbac9e" />
      </body>
      <title>Couple random thoughts…</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,13f93399-066c-4c63-a8d2-edc3fccbac9e.aspx</guid>
      <link>http://www.ntldr.com/2009/09/20/CoupleRandomThoughts.aspx</link>
      <pubDate>Sun, 20 Sep 2009 16:08:17 GMT</pubDate>
      <description>&lt;p&gt;
Windows Live has this cool thing where it reminds you about your contact’s birthdays
(the “Birthday Calendar” I think…). And yes, I’ve come to rely on this feature. Unfortunately,
I can’t quite bring myself to trust the system completely, so whenever I get the alerts,
I also get this nagging doubt that it’s not really that person’s birthday and that
I’ve really just misentered their contact info…
&lt;/p&gt;
&lt;p&gt;
Wow Windows XP is showing it’s age…the RTM installation disc I have is reacting badly
to the &amp;gt;127GB hard drive I’m trying to install on…(yes, I know the way to correct
this is to use SP1…which is why I’m slipstreaming SP3 onto a new installation disc
right now…)
&lt;/p&gt;
&lt;p&gt;
Hey! xcopy on Windows 7 seems to have a new option: /J (“Copies using unbuffered I/O.
Recommended for very large files.”) Cool!
&lt;/p&gt;
&lt;p&gt;
Command just used to build the Windows XP with SP3 disc: oscdimg -n -b&amp;quot;amd64\boot\ETFSBOOT.COM&amp;quot;
-lWXP_VOL_EN_SP3 -t04/14/2008,07:53:59 -g -h -maxsize:4096 &amp;quot;E:\CD Build\windows_xp_sp3&amp;quot;
&amp;quot;E:\CD build\windows_xp_sp3.iso&amp;quot;. I’m probably a short DVD burn away from
finding out just how wrong that was…(much later)…hey, that actually worked!
&lt;/p&gt;
&lt;p&gt;
Oo…coool…Windows XP &lt;em&gt;does&lt;/em&gt; have regional settings for Filipino…too bad the
timezone stuff doesn’t have one (instead I end up guessing…”it’s close enough to Singapore,
right?” note that this results in the timezone being &amp;quot;Malay Peninsula Standard
Time&amp;quot;)
&lt;/p&gt;
&lt;p&gt;
Who makes &amp;amp; sells a DVD drive &lt;em&gt;that can’t play DVD’s&lt;/em&gt;?!?!?! I mean, I could
sort of understand a bare OEM drive…but these are boxed retail drives from HP! Grrr…
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: (nothing but the sound of computer fans)
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=13f93399-066c-4c63-a8d2-edc3fccbac9e" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,13f93399-066c-4c63-a8d2-edc3fccbac9e.aspx</comments>
      <category>IT</category>
      <category>Personal</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=bfdf1ccf-d619-40ac-a2f6-37b1c432bbed</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,bfdf1ccf-d619-40ac-a2f6-37b1c432bbed.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,bfdf1ccf-d619-40ac-a2f6-37b1c432bbed.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=bfdf1ccf-d619-40ac-a2f6-37b1c432bbed</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
New! Improved! Now with inline hyperlinks!<sup>1</sup></p>
        <ul>
          <li>
            <a href="http://j-walkblog.com/index.php?/weblog/posts/squirrel_steals_flags/">Thieves!</a>
          </li>
          <li>
For some reason <a href="http://www.astrodigital.org/space/stshorse.html">this makes
me nervous about spec'ing out anything</a>... (via <a href="http://blogs.msdn.com/ericlippert/archive/2009/06/01/bug-psychology.aspx">http://blogs.msdn.com/ericlippert/archive/2009/06/01/bug-psychology.aspx</a>) 
</li>
          <li>
Some people might consider my apartment bad, but <a href="http://j-walkblog.com/index.php?/weblog/posts/not_wireless/">this
is ridiculous</a> (note: "some people" are wrong in this case; my apartment has its
electronic contents nicely organized). 
</li>
          <li>
Apparently all I need to do to shed the whole nerd/geek image &amp; become <a href="http://blogs.msdn.com/oldnewthing/archive/2009/06/04/9695344.aspx">"cool"
is go blow stuff up &amp; walk away</a>. Umm...sure... 
</li>
          <li>
            <a href="http://j-walkblog.com/index.php?/weblog/posts/national_doughnut_day/">Mmmmm...doughnuts...</a>
          </li>
          <li>
            <a href="http://www.wired.com/techbiz/people/magazine/17-06/ff_keymaster?currentPage=all">Fun
with locks!</a> (yes Emil, you have a long ways to go with your bump keys) (via <a href="http://j-walkblog.com/index.php?/weblog/posts/locks_arent_really_effective/">http://j-walkblog.com/index.php?/weblog/posts/locks_arent_really_effective/</a>) 
</li>
          <li>
            <a href="http://kfmonkey.blogspot.com/2009/06/suuuure-its-just-umbrella.html">-dsr-'s
comment is hilarious (read the post first of course)</a>
          </li>
          <li>
            <a href="http://j-walkblog.com/index.php?/weblog/posts/5555_email_accounts/">Having
this many email accounts actually isn't that impressive</a> if you <a href="http://technet.microsoft.com/en-us/library/aa997663.aspx">know
a little about Exchange 2007 &amp; Windows PowerShell</a>...such as: 
<br /><span style="font-family: monospace">for($i = 0; $i –lt 6000; $i += 1)<br />
{<br />
new-mailbox -UserPrincipalName "Me$i@ntldr.net" -alias "Me$i" -name "Me$i" -database
"Storage Group 1\Mailbox Database 1" -OrganizationalUnit 'examples' -DisplayName "Me
$i" -ResetPasswordOnNextLogon $true<br />
}</span><br />
(warning: for the kids following along at home, I don't actually have an Exchange
Server anymore, so I haven't tested that command. and even if it's error free, <em>why
would you want 6000 accounts?!</em>) 
</li>
          <li>
Interested in Bing? Wondering how good the results are? <a href="http://blindsearch.fejus.com/">Someone
set up an interesting comparison site</a>. (via <a title="http://www.istartedsomething.com/20090607/bing-vs-google-vs-yahoo-blind-search-engine-test/" href="http://www.istartedsomething.com/20090607/bing-vs-google-vs-yahoo-blind-search-engine-test/">http://www.istartedsomething.com/20090607/bing-vs-google-vs-yahoo-blind-search-engine-test/</a>)</li>
        </ul>
        <p>
 
</p>
        <h5>Extra special bonus feature:
</h5>
        <p>
So I got the following email message from my mom last week: 
</p>
        <blockquote style="font-family: monospace">See your Mom on YouTube!!</blockquote>and
was immediately filled with a weird curiosity and a sick terror wondering if this
was somehow going to be one of those horribly embarrassing videos where people just
do stupid things (&amp; (usually) get hurt). Fortunately it was just moderately embarrassing
and for work. :P So I'll share my link love (rofl! hahaha...like that's worth anything...I've
seen how many pages down into the search results some visitors have had to go to finally
stumble across this site!), and everyone can check it out: <a href="http://www.youtube.com/tcpllibrary">http://www.youtube.com/tcpllibrary</a><p></p><h5>Extra, extra special bonus feature:
</h5><p>
So, there's been a bit of speculation lately about why I blog (&amp; why it's increased
lately). The general consensus <em>amongst other people</em> seemed to be that it's
because I'm lonely &amp; am seeking attention. LOL! Duh, it's a <em>blog</em>. That's
like saying the sky is blue because of light's refraction through the atmosphere.
...err... maybe not quite that metaphor. Whatever...was going more for the whole "that's
the way it works because that's what it means to be that" thing... (actually, there
was a bunch of additional context around the whole question that makes it interesting,
but I'm trying to avoid the whole emo-teen-agnst-livejournal vibe because I'm a mature
technology professional maintaining a professional Internet self-marketing presence
(haha...okay, so really I'm just too lazy to create &amp; install a black-text-on-black-background
DasBlog theme :P)) 
</p><p style="font-size: smaller"><sup>1</sup> Rose Festival/Fleet Week 2009 pictures coming later this week...or next...hopefully
I'll be more punctual with this year's photos than I've been in previous years.
</p><p style="color: #7f7f7f; font-size: smaller">
Now playing: Sebastien Grainger &amp; the Mountains – Sebastien Grainger &amp; the
Mountains – 10 American Names
</p><img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=bfdf1ccf-d619-40ac-a2f6-37b1c432bbed" /></body>
      <title>Links</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,bfdf1ccf-d619-40ac-a2f6-37b1c432bbed.aspx</guid>
      <link>http://www.ntldr.com/2009/06/08/Links.aspx</link>
      <pubDate>Mon, 08 Jun 2009 04:04:31 GMT</pubDate>
      <description>&lt;p&gt;
New! Improved! Now with inline hyperlinks!&lt;sup&gt;1&lt;/sup&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a href="http://j-walkblog.com/index.php?/weblog/posts/squirrel_steals_flags/"&gt;Thieves!&lt;/a&gt; 
&lt;li&gt;
For some reason &lt;a href="http://www.astrodigital.org/space/stshorse.html"&gt;this makes
me nervous about spec'ing out anything&lt;/a&gt;... (via &lt;a href="http://blogs.msdn.com/ericlippert/archive/2009/06/01/bug-psychology.aspx"&gt;http://blogs.msdn.com/ericlippert/archive/2009/06/01/bug-psychology.aspx&lt;/a&gt;) 
&lt;li&gt;
Some people might consider my apartment bad, but &lt;a href="http://j-walkblog.com/index.php?/weblog/posts/not_wireless/"&gt;this
is ridiculous&lt;/a&gt; (note: "some people" are wrong in this case; my apartment has its
electronic contents nicely organized). 
&lt;li&gt;
Apparently all I need to do to shed the whole nerd/geek image &amp;amp; become &lt;a href="http://blogs.msdn.com/oldnewthing/archive/2009/06/04/9695344.aspx"&gt;"cool"
is go blow stuff up &amp;amp; walk away&lt;/a&gt;. Umm...sure... 
&lt;li&gt;
&lt;a href="http://j-walkblog.com/index.php?/weblog/posts/national_doughnut_day/"&gt;Mmmmm...doughnuts...&lt;/a&gt; 
&lt;li&gt;
&lt;a href="http://www.wired.com/techbiz/people/magazine/17-06/ff_keymaster?currentPage=all"&gt;Fun
with locks!&lt;/a&gt; (yes Emil, you have a long ways to go with your bump keys) (via &lt;a href="http://j-walkblog.com/index.php?/weblog/posts/locks_arent_really_effective/"&gt;http://j-walkblog.com/index.php?/weblog/posts/locks_arent_really_effective/&lt;/a&gt;) 
&lt;li&gt;
&lt;a href="http://kfmonkey.blogspot.com/2009/06/suuuure-its-just-umbrella.html"&gt;-dsr-'s
comment is hilarious (read the post first of course)&lt;/a&gt; 
&lt;li&gt;
&lt;a href="http://j-walkblog.com/index.php?/weblog/posts/5555_email_accounts/"&gt;Having
this many email accounts actually isn't that impressive&lt;/a&gt; if you &lt;a href="http://technet.microsoft.com/en-us/library/aa997663.aspx"&gt;know
a little about Exchange 2007 &amp;amp; Windows PowerShell&lt;/a&gt;...such as: 
&lt;br&gt;
&lt;span style="font-family: monospace"&gt;for($i = 0; $i –lt 6000; $i += 1)&lt;br&gt;
{&lt;br&gt;
new-mailbox -UserPrincipalName "Me$i@ntldr.net" -alias "Me$i" -name "Me$i" -database
"Storage Group 1\Mailbox Database 1" -OrganizationalUnit 'examples' -DisplayName "Me
$i" -ResetPasswordOnNextLogon $true&lt;br&gt;
}&lt;/span&gt;
&lt;br&gt;
(warning: for the kids following along at home, I don't actually have an Exchange
Server anymore, so I haven't tested that command. and even if it's error free, &lt;em&gt;why
would you want 6000 accounts?!&lt;/em&gt;) 
&lt;li&gt;
Interested in Bing? Wondering how good the results are? &lt;a href="http://blindsearch.fejus.com/"&gt;Someone
set up an interesting comparison site&lt;/a&gt;. (via &lt;a title="http://www.istartedsomething.com/20090607/bing-vs-google-vs-yahoo-blind-search-engine-test/" href="http://www.istartedsomething.com/20090607/bing-vs-google-vs-yahoo-blind-search-engine-test/"&gt;http://www.istartedsomething.com/20090607/bing-vs-google-vs-yahoo-blind-search-engine-test/&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;h5&gt;Extra special bonus feature:
&lt;/h5&gt;
&lt;p&gt;
So I got the following email message from my mom last week: &lt;blockquote style="font-family: monospace"&gt;See
your Mom on YouTube!!&lt;/blockquote&gt;and was immediately filled with a weird curiosity
and a sick terror wondering if this was somehow going to be one of those horribly
embarrassing videos where people just do stupid things (&amp;amp; (usually) get hurt).
Fortunately it was just moderately embarrassing and for work. :P So I'll share my
link love (rofl! hahaha...like that's worth anything...I've seen how many pages down
into the search results some visitors have had to go to finally stumble across this
site!), and everyone can check it out: &lt;a href="http://www.youtube.com/tcpllibrary"&gt;http://www.youtube.com/tcpllibrary&lt;/a&gt; 
&lt;p&gt;
&lt;/p&gt;
&lt;h5&gt;Extra, extra special bonus feature:
&lt;/h5&gt;
&lt;p&gt;
So, there's been a bit of speculation lately about why I blog (&amp;amp; why it's increased
lately). The general consensus &lt;em&gt;amongst other people&lt;/em&gt; seemed to be that it's
because I'm lonely &amp;amp; am seeking attention. LOL! Duh, it's a &lt;em&gt;blog&lt;/em&gt;. That's
like saying the sky is blue because of light's refraction through the atmosphere.
...err... maybe not quite that metaphor. Whatever...was going more for the whole "that's
the way it works because that's what it means to be that" thing... (actually, there
was a bunch of additional context around the whole question that makes it interesting,
but I'm trying to avoid the whole emo-teen-agnst-livejournal vibe because I'm a mature
technology professional maintaining a professional Internet self-marketing presence
(haha...okay, so really I'm just too lazy to create &amp;amp; install a black-text-on-black-background
DasBlog theme :P)) 
&lt;/p&gt;
&lt;p style="font-size: smaller"&gt;
&lt;sup&gt;1&lt;/sup&gt; Rose Festival/Fleet Week 2009 pictures coming later this week...or next...hopefully
I'll be more punctual with this year's photos than I've been in previous years.
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Sebastien Grainger &amp;amp; the Mountains – Sebastien Grainger &amp;amp; the
Mountains – 10 American Names
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=bfdf1ccf-d619-40ac-a2f6-37b1c432bbed" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,bfdf1ccf-d619-40ac-a2f6-37b1c432bbed.aspx</comments>
      <category>IT</category>
      <category>Personal</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=9e63e11f-a2be-4486-b01d-684112f61ee6</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,9e63e11f-a2be-4486-b01d-684112f61ee6.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,9e63e11f-a2be-4486-b01d-684112f61ee6.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=9e63e11f-a2be-4486-b01d-684112f61ee6</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
So for some reason you have a Lenovo X200T, a bootable USB hard drive running WinPE
(Vista SP1/Server 2008 based), ImageX, and the WIM files that were originally on the
recovery partition. For some reason you no longer have the recovery partition (probably
because it was deleted to free up space), you don’t have the recovery discs that you
burned like a conscientious computer owner, and your X200T wont start the OS (say,
because you didn’t think about all the implications of encrypting the entire drive
with BitLocker and then not having the recovery key…). Also, just to make it more
fun, you’re on a plane!
</p>
        <p>
Obviously the system needs to be restored. And because of the things you <em>do</em> have,
you’re in luck! It’s possible! And not that hard! (yeah, right…)
</p>
        <p>
First, backup everything you can off the X200T’s hard drive, because restoring things
is destructive and will involve wiping the drive. If you can’t back things up…umm…learn
to live with disappointment and loss? Since the system wont start the OS, you’ll probably
be doing this from within WinPE. Good luck copying everything with the command line
(xcopy can be useful here).
</p>
        <p>
If you aren’t in WinPE yet, adjust the bios settings to allow you to boot off the
bootable WinPE USB hard drive. Then boot into WinPE.
</p>
        <p>
The first real part of the recovery process is to wipe the X200T’s drive and repartition
it. Start diskpart and issue the following commands: 
</p>
        <pre style="padding-left: 0.25in">select disk 0
clean
create partition primary size=1499
active
assign letter=s
format fs=ntfs label="SERVICEV003" quick
create partition primary
assign letter=c
format fs=ntfs label="SW_Preload" quick</pre>
        <p>
        </p>
        <p>
Next, apply the WIM files to the disk (exact paths to the WIM files will probably
be different for you):
</p>
        <pre style="padding-left: 0.25in">imagex /apply E:\images\x200t\sdrivebackup.wim 0 S:\
imagex /apply E:\images\x200t\cdrivebackup.wim 0 C:\</pre>
        <p>
        </p>
        <p>
So, in a perfect world, everything would be all set to go now. Unfortunately, you
my run into problems with bootmgr not being able to find the OS, or the OS thinking
its on a different drive letter than it should be. To fix those issues, a little editing
of the boot configuration database will be required:
</p>
        <pre style="padding-left: 0.25in">bcdedit /store S:\boot\bcd /set {9dea862c-5cdd-4e70-acc1-f32b344d4795} device partition=S:

bcdedit /store S:\boot\bcd /set {3657ebe1-d4e6-11dc-88f0-ec9c0d1f1864} device partition=C:
bcdedit /store S:\boot\bcd /set {3657ebe1-d4e6-11dc-88f0-ec9c0d1f1864} osdevice partition=C:

bcdedit /store S:\boot\bcd /set {3657ebe2-d4e6-11dc-88f0-ec9c0d1f1864} device partition=C:

bcdedit /store S:\boot\bcd /set {b2721d73-1db4-4c62-bf78-c548a880142d} device partition=S:

bcdedit /store S:\boot\bcd /set {466f5a88-0af2-4f76-9038-095b170dc21c} device partition=S:

bcdedit /store S:\boot\bcd /set {ae5534e0-a924-466c-b836-758539a3ee3a} device partition=S:</pre>
        <p>
        </p>
        <p>
        </p>
        <p>
Note: bcdedit is kind of sensitive about the drive letter availability when it’s run.
Which is why S: was used back in the diskpart stage.
</p>
        <p>
In an almost perfect world, everything would <em>now</em> be all set to go. Too bad
things aren’t even almost perfect. One further step was required to swap get the drive
letter assignments correct: the registry of the restored OS needs to have its drive
letter mounts tweaked <em>BEFORE</em> the OS boots for the first time. This step is
probably the most complicated, since it's not scriptable. Basically, start up regedit.
Navigate to the HKLM\SYSTEM\MountedDevices key. Make note of the binary data for the
"\DosDevices\C:" and "\DosDevices\S:" values (in my case they
were something like "C4 78 A4 9C 00 00 C0 5D 00 00 00 00" &amp; "C4
78 A4 9C 00 00 10 00 00 00 00 00"). Now load System Hive from the restored OS
(it's "C:\windows\system32\config\system") in regedit. Navigate to the SYSTEM\MountedDevices
key in that hive. Change/create the SAME values with the SAME data that the WinPE
registry had.
</p>
        <p>
After rebooting the system (remember to either unplug the USB hard drive or adjust
the bios settings so its no longer the preferred boot device), everything should be
back to working.
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Neko Case – Middle Cyclone – 09 Magpie To The Morning
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9e63e11f-a2be-4486-b01d-684112f61ee6" />
      </body>
      <title>How to restore the OS on a Lenovo X200T from 33000 feet</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,9e63e11f-a2be-4486-b01d-684112f61ee6.aspx</guid>
      <link>http://www.ntldr.com/2009/04/29/HowToRestoreTheOSOnALenovoX200TFrom33000Feet.aspx</link>
      <pubDate>Wed, 29 Apr 2009 04:18:04 GMT</pubDate>
      <description>&lt;p&gt;
So for some reason you have a Lenovo X200T, a bootable USB hard drive running WinPE
(Vista SP1/Server 2008 based), ImageX, and the WIM files that were originally on the
recovery partition. For some reason you no longer have the recovery partition (probably
because it was deleted to free up space), you don’t have the recovery discs that you
burned like a conscientious computer owner, and your X200T wont start the OS (say,
because you didn’t think about all the implications of encrypting the entire drive
with BitLocker and then not having the recovery key…). Also, just to make it more
fun, you’re on a plane!
&lt;/p&gt;
&lt;p&gt;
Obviously the system needs to be restored. And because of the things you &lt;em&gt;do&lt;/em&gt; have,
you’re in luck! It’s possible! And not that hard! (yeah, right…)
&lt;/p&gt;
&lt;p&gt;
First, backup everything you can off the X200T’s hard drive, because restoring things
is destructive and will involve wiping the drive. If you can’t back things up…umm…learn
to live with disappointment and loss? Since the system wont start the OS, you’ll probably
be doing this from within WinPE. Good luck copying everything with the command line
(xcopy can be useful here).
&lt;/p&gt;
&lt;p&gt;
If you aren’t in WinPE yet, adjust the bios settings to allow you to boot off the
bootable WinPE USB hard drive. Then boot into WinPE.
&lt;/p&gt;
&lt;p&gt;
The first real part of the recovery process is to wipe the X200T’s drive and repartition
it. Start diskpart and issue the following commands: 
&lt;/p&gt;
&lt;pre style="padding-left: 0.25in"&gt;select disk 0
clean
create partition primary size=1499
active
assign letter=s
format fs=ntfs label=&amp;quot;SERVICEV003&amp;quot; quick
create partition primary
assign letter=c
format fs=ntfs label=&amp;quot;SW_Preload&amp;quot; quick&lt;/pre&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;p&gt;
Next, apply the WIM files to the disk (exact paths to the WIM files will probably
be different for you):
&lt;/p&gt;
&lt;pre style="padding-left: 0.25in"&gt;imagex /apply E:\images\x200t\sdrivebackup.wim 0 S:\
imagex /apply E:\images\x200t\cdrivebackup.wim 0 C:\&lt;/pre&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;p&gt;
So, in a perfect world, everything would be all set to go now. Unfortunately, you
my run into problems with bootmgr not being able to find the OS, or the OS thinking
its on a different drive letter than it should be. To fix those issues, a little editing
of the boot configuration database will be required:
&lt;/p&gt;
&lt;pre style="padding-left: 0.25in"&gt;bcdedit /store S:\boot\bcd /set {9dea862c-5cdd-4e70-acc1-f32b344d4795} device partition=S:

bcdedit /store S:\boot\bcd /set {3657ebe1-d4e6-11dc-88f0-ec9c0d1f1864} device partition=C:
bcdedit /store S:\boot\bcd /set {3657ebe1-d4e6-11dc-88f0-ec9c0d1f1864} osdevice partition=C:

bcdedit /store S:\boot\bcd /set {3657ebe2-d4e6-11dc-88f0-ec9c0d1f1864} device partition=C:

bcdedit /store S:\boot\bcd /set {b2721d73-1db4-4c62-bf78-c548a880142d} device partition=S:

bcdedit /store S:\boot\bcd /set {466f5a88-0af2-4f76-9038-095b170dc21c} device partition=S:

bcdedit /store S:\boot\bcd /set {ae5534e0-a924-466c-b836-758539a3ee3a} device partition=S:&lt;/pre&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;p&gt;
Note: bcdedit is kind of sensitive about the drive letter availability when it’s run.
Which is why S: was used back in the diskpart stage.
&lt;/p&gt;
&lt;p&gt;
In an almost perfect world, everything would &lt;em&gt;now&lt;/em&gt; be all set to go. Too bad
things aren’t even almost perfect. One further step was required to swap get the drive
letter assignments correct: the registry of the restored OS needs to have its drive
letter mounts tweaked &lt;em&gt;BEFORE&lt;/em&gt; the OS boots for the first time. This step is
probably the most complicated, since it's not scriptable. Basically, start up regedit.
Navigate to the HKLM\SYSTEM\MountedDevices key. Make note of the binary data for the
&amp;quot;\DosDevices\C:&amp;quot; and &amp;quot;\DosDevices\S:&amp;quot; values (in my case they
were something like &amp;quot;C4 78 A4 9C 00 00 C0 5D 00 00 00 00&amp;quot; &amp;amp; &amp;quot;C4
78 A4 9C 00 00 10 00 00 00 00 00&amp;quot;). Now load System Hive from the restored OS
(it's &amp;quot;C:\windows\system32\config\system&amp;quot;) in regedit. Navigate to the SYSTEM\MountedDevices
key in that hive. Change/create the SAME values with the SAME data that the WinPE
registry had.
&lt;/p&gt;
&lt;p&gt;
After rebooting the system (remember to either unplug the USB hard drive or adjust
the bios settings so its no longer the preferred boot device), everything should be
back to working.
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Neko Case – Middle Cyclone – 09 Magpie To The Morning
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9e63e11f-a2be-4486-b01d-684112f61ee6" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,9e63e11f-a2be-4486-b01d-684112f61ee6.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=3ec74375-53d5-4c06-b505-ed6db1be4485</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,3ec74375-53d5-4c06-b505-ed6db1be4485.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,3ec74375-53d5-4c06-b505-ed6db1be4485.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=3ec74375-53d5-4c06-b505-ed6db1be4485</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
So, from April 5th through the 8th I was in San Antonio, Texas on business for the
annual Ratabase conference. I’d been planning on live blogging it again like I did
last year (actually, I was planning on doing it <em>better</em> than last year), but
things didn’t quite work out that way. So, instead of the latest news on cool new
things you can do with an insurance rating calculator (stop laughing!), I’ve got a
cautionary tail about relying on new equipment, planning before doing things, and
generally about how I do stupid stuff with technology.
</p>
        <p>
Now for a bit of background. Windows Vista &amp; 7 have this cool feature called “BitLocker”.
Basically, it encrypts your hard drive so that if the computer/drive is stolen, an
attacker would have to go through the OS level security mechanisms (usernames/passwords/smartcards/ACL’s).
The attacker wouldn’t be able to circumvent the OS mechanisms by, say, editing the
password store to give change the passwords. Or they could go after the EFS keys and
just decrypt files that you had encrypted explicitly so that other people wouldn’t
be able to read them!
</p>
        <p>
One “mode” of Bitlocker relies on this cool hardware device called a TPM (trusted
platform module). The TPM is involved in the key management/access process, and basically
serves to ensure that the entire system, starting from the beginning of the boot process,
is “trusted”. After all, you wouldn’t want some nefarious person coming in, booting
to a different environment that can impersonate the BitLocker process, and then unlocking/decrypting
the BitLocker volume and thus bypassing all the security it was supposed to offer.
If the TPM/BitLocker (not sure which actually does the checks) detects that the system
is under attack (for example, the order of the devices that the system boots from
has changed), the system will require that a 56 digit recovery key be entered. Assuming
you created a recovery key initially…but everyone does that &amp; keeps that key safe,
right?
</p>
        <p>
A week before I was to head to San Antonio, my new Tablet PC (a Lenovo X200T) arrived.
Incidentally, it’s a very nice system…fast, light, long battery life, lots of accessories
(I bought most of the options…X-Base so I have an optical drive, webcam, fingerprint
reader, WiMAX, HSDPA/UMTS, GPS, etc.). And it has a TPM v1.2. Which was cool, because
it meant I could use BitLocker!
</p>
        <p>
So I put Windows 7 (beta) on the system, enabled BitLocker, created the recovery key,
and used the system successfully for a week. One time while rebooting the system I
had to enter the recovery key, which I thought was kind of funny at the time, but
didn’t really worry that much about it. So along came Sunday morning, it’s 5:00AM
and I need to head out to the airport, so I hibernate my tablet and pull it out of
the docking station (X Base). Figured I wouldn’t need the optical drive, and certainly
wouldn’t need the extra weight. Thought about putting the recovery key on a flash
drive or the external hard drive I was taking, but then thought “nah, I wouldn’t need
that”. Besides, the key would be a lot more exposed to compromise if I had it with
me and, say, my flash drive got lost/stolen.
</p>
        <p>
Remember how I said the boot order mattered to the TPM? And remember how 1) I installed
the OS shortly before this (from a DVD), &amp; 2) how I wasn’t taking the X-Base with
the DVD drive with me? And how I ignored the fact that when I’d last attached the
X-Base I had to enter the recovery key? And how I wasn’t taking the recovery key with
me? (this is where it should become apparent to most people that I am, in fact, an
idiot.)
</p>
        <p>
Of course I got all the way to the airport, through security, and was sitting at the
gate with 30 minutes until boarding started when I went to use my tablet. And of course
it saw that the DVD drive was no longer present and began going “oh noes! I’m under
attack!”. Which then caused me to first realize exactly what mistakes I’d made, then
freak out (it’s amazing what sorts of brief, complete clarity you can have when a
situation goes to crap).
</p>
        <p>
 
</p>
        <p>
Part of the freak out was calling up a trusted friend and giving him all the details
of connecting back to my network via VPN (including user names and <em>passwords</em>).
I figured “okay, get connected to the internal network, then the administrator account
can be used to login to the online CA and security server to retrieve the recovery
key”. Yes, it was a moment of weakness and complete stupidity. Fortunately, <a href="/2004/12/21/VPNServerWorking.aspx">years
ago when I got the VPN stuff working</a>, I had the foresight to use L2TP and require
certificates to connect <em>in addition</em> to passwords. So no VPN connection could
be established, giving the passwords did absolutely no good (but no harm either),
and the recovery key couldn’t be retrieved. Hurray for defense-in-depth.
</p>
        <p>
I was not totally without my tablet during the trip though. Remember how I brought
an external hard drive with me? Well, that drive is the bootable one that I use to
make OS recovery images. And I’d used it just a week before to backup the Lenovo factory
default config. So I spent the flight down to Texas doing restores until I got the
system working again.
</p>
        <p>
 
</p>
        <p>
Here are some pictures from the trip (more (and higher res ones) can be found on <a href="http://cid-348cb3ddffbdf313.skydrive.live.com/browse.aspx/CGI Alliance 2009, San Antonio, TX %7C52009-04%7C6?authkey=fBS3LqfJuNs%24&amp;ct=photos">my
Windows Live Photos album for the trip</a>):
</p>
        <p>
          <a title="Westin La Cantera Resort gulf course outbuilding" href="https://cid-348cb3ddffbdf313.skydrive.live.com/self.aspx/CGI%20Alliance%202009,%20San%20Antonio,%20TX%20%7C52009-04%7C6/IMG%7C_1777.JPG">
            <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Westin La Cantera Resort gulf course outbuilding" border="0" alt="Westin La Cantera Resort gulf course outbuilding" src="http://www.ntldr.com/attachments/WindowsLiveWriter/CGIAlliance2009Ratabaseconference_10DFA/IMG_1777_2.jpg" width="644" height="484" />
          </a>  
</p>
        <p>
Westin La Cantera Resort gulf course outbuilding
</p>
        <p>
          <a title="San Antonio, TX Riverwalk" href="https://cid-348cb3ddffbdf313.skydrive.live.com/self.aspx/CGI%20Alliance%202009,%20San%20Antonio,%20TX%20%7C52009-04%7C6/IMG%7C_1808.JPG">
            <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="San Antonio, TX Riverwalk" border="0" alt="San Antonio, TX Riverwalk" src="http://www.ntldr.com/attachments/WindowsLiveWriter/CGIAlliance2009Ratabaseconference_10DFA/IMG_1808_1.jpg" width="484" height="644" />
          </a>
        </p>
        <p>
San Antonio, TX Riverwalk. There’s a boat ride around it that’s kind of cool too (+).
Lots of people (-). On the whole, it was a cool area, and made for a good change of
pace from the conference.
</p>
        <p>
          <a title="The Alamo" href="https://cid-348cb3ddffbdf313.skydrive.live.com/self.aspx/CGI%20Alliance%202009,%20San%20Antonio,%20TX%20%7C52009-04%7C6/IMG%7C_1848.JPG">
            <img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="The Alamo" border="0" alt="The Alamo" src="http://www.ntldr.com/attachments/WindowsLiveWriter/CGIAlliance2009Ratabaseconference_10DFA/IMG_1848_1.jpg" width="644" height="484" />
          </a>
        </p>
        <p>
The Alamo (of course!).
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Greg Laswell – Three Flights From Alto Nido – 04 Comes &amp; Goes (In
Waves)
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=3ec74375-53d5-4c06-b505-ed6db1be4485" />
      </body>
      <title>CGI Alliance 2009 Ratabase conference</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,3ec74375-53d5-4c06-b505-ed6db1be4485.aspx</guid>
      <link>http://www.ntldr.com/2009/04/28/CGIAlliance2009RatabaseConference.aspx</link>
      <pubDate>Tue, 28 Apr 2009 02:21:19 GMT</pubDate>
      <description>&lt;p&gt;
So, from April 5th through the 8th I was in San Antonio, Texas on business for the
annual Ratabase conference. I’d been planning on live blogging it again like I did
last year (actually, I was planning on doing it &lt;em&gt;better&lt;/em&gt; than last year), but
things didn’t quite work out that way. So, instead of the latest news on cool new
things you can do with an insurance rating calculator (stop laughing!), I’ve got a
cautionary tail about relying on new equipment, planning before doing things, and
generally about how I do stupid stuff with technology.
&lt;/p&gt;
&lt;p&gt;
Now for a bit of background. Windows Vista &amp;amp; 7 have this cool feature called “BitLocker”.
Basically, it encrypts your hard drive so that if the computer/drive is stolen, an
attacker would have to go through the OS level security mechanisms (usernames/passwords/smartcards/ACL’s).
The attacker wouldn’t be able to circumvent the OS mechanisms by, say, editing the
password store to give change the passwords. Or they could go after the EFS keys and
just decrypt files that you had encrypted explicitly so that other people wouldn’t
be able to read them!
&lt;/p&gt;
&lt;p&gt;
One “mode” of Bitlocker relies on this cool hardware device called a TPM (trusted
platform module). The TPM is involved in the key management/access process, and basically
serves to ensure that the entire system, starting from the beginning of the boot process,
is “trusted”. After all, you wouldn’t want some nefarious person coming in, booting
to a different environment that can impersonate the BitLocker process, and then unlocking/decrypting
the BitLocker volume and thus bypassing all the security it was supposed to offer.
If the TPM/BitLocker (not sure which actually does the checks) detects that the system
is under attack (for example, the order of the devices that the system boots from
has changed), the system will require that a 56 digit recovery key be entered. Assuming
you created a recovery key initially…but everyone does that &amp;amp; keeps that key safe,
right?
&lt;/p&gt;
&lt;p&gt;
A week before I was to head to San Antonio, my new Tablet PC (a Lenovo X200T) arrived.
Incidentally, it’s a very nice system…fast, light, long battery life, lots of accessories
(I bought most of the options…X-Base so I have an optical drive, webcam, fingerprint
reader, WiMAX, HSDPA/UMTS, GPS, etc.). And it has a TPM v1.2. Which was cool, because
it meant I could use BitLocker!
&lt;/p&gt;
&lt;p&gt;
So I put Windows 7 (beta) on the system, enabled BitLocker, created the recovery key,
and used the system successfully for a week. One time while rebooting the system I
had to enter the recovery key, which I thought was kind of funny at the time, but
didn’t really worry that much about it. So along came Sunday morning, it’s 5:00AM
and I need to head out to the airport, so I hibernate my tablet and pull it out of
the docking station (X Base). Figured I wouldn’t need the optical drive, and certainly
wouldn’t need the extra weight. Thought about putting the recovery key on a flash
drive or the external hard drive I was taking, but then thought “nah, I wouldn’t need
that”. Besides, the key would be a lot more exposed to compromise if I had it with
me and, say, my flash drive got lost/stolen.
&lt;/p&gt;
&lt;p&gt;
Remember how I said the boot order mattered to the TPM? And remember how 1) I installed
the OS shortly before this (from a DVD), &amp;amp; 2) how I wasn’t taking the X-Base with
the DVD drive with me? And how I ignored the fact that when I’d last attached the
X-Base I had to enter the recovery key? And how I wasn’t taking the recovery key with
me? (this is where it should become apparent to most people that I am, in fact, an
idiot.)
&lt;/p&gt;
&lt;p&gt;
Of course I got all the way to the airport, through security, and was sitting at the
gate with 30 minutes until boarding started when I went to use my tablet. And of course
it saw that the DVD drive was no longer present and began going “oh noes! I’m under
attack!”. Which then caused me to first realize exactly what mistakes I’d made, then
freak out (it’s amazing what sorts of brief, complete clarity you can have when a
situation goes to crap).
&lt;/p&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
Part of the freak out was calling up a trusted friend and giving him all the details
of connecting back to my network via VPN (including user names and &lt;em&gt;passwords&lt;/em&gt;).
I figured “okay, get connected to the internal network, then the administrator account
can be used to login to the online CA and security server to retrieve the recovery
key”. Yes, it was a moment of weakness and complete stupidity. Fortunately, &lt;a href="/2004/12/21/VPNServerWorking.aspx"&gt;years
ago when I got the VPN stuff working&lt;/a&gt;, I had the foresight to use L2TP and require
certificates to connect &lt;em&gt;in addition&lt;/em&gt; to passwords. So no VPN connection could
be established, giving the passwords did absolutely no good (but no harm either),
and the recovery key couldn’t be retrieved. Hurray for defense-in-depth.
&lt;/p&gt;
&lt;p&gt;
I was not totally without my tablet during the trip though. Remember how I brought
an external hard drive with me? Well, that drive is the bootable one that I use to
make OS recovery images. And I’d used it just a week before to backup the Lenovo factory
default config. So I spent the flight down to Texas doing restores until I got the
system working again.
&lt;/p&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
Here are some pictures from the trip (more (and higher res ones) can be found on &lt;a href="http://cid-348cb3ddffbdf313.skydrive.live.com/browse.aspx/CGI Alliance 2009, San Antonio, TX %7C52009-04%7C6?authkey=fBS3LqfJuNs%24&amp;amp;ct=photos"&gt;my
Windows Live Photos album for the trip&lt;/a&gt;):
&lt;/p&gt;
&lt;p&gt;
&lt;a title="Westin La Cantera Resort gulf course outbuilding" href="https://cid-348cb3ddffbdf313.skydrive.live.com/self.aspx/CGI%20Alliance%202009,%20San%20Antonio,%20TX%20%7C52009-04%7C6/IMG%7C_1777.JPG"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Westin La Cantera Resort gulf course outbuilding" border="0" alt="Westin La Cantera Resort gulf course outbuilding" src="http://www.ntldr.com/attachments/WindowsLiveWriter/CGIAlliance2009Ratabaseconference_10DFA/IMG_1777_2.jpg" width="644" height="484" /&gt;&lt;/a&gt;&amp;#160; 
&lt;/p&gt;
&lt;p&gt;
Westin La Cantera Resort gulf course outbuilding
&lt;/p&gt;
&lt;p&gt;
&lt;a title="San Antonio, TX Riverwalk" href="https://cid-348cb3ddffbdf313.skydrive.live.com/self.aspx/CGI%20Alliance%202009,%20San%20Antonio,%20TX%20%7C52009-04%7C6/IMG%7C_1808.JPG"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="San Antonio, TX Riverwalk" border="0" alt="San Antonio, TX Riverwalk" src="http://www.ntldr.com/attachments/WindowsLiveWriter/CGIAlliance2009Ratabaseconference_10DFA/IMG_1808_1.jpg" width="484" height="644" /&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
San Antonio, TX Riverwalk. There’s a boat ride around it that’s kind of cool too (+).
Lots of people (-). On the whole, it was a cool area, and made for a good change of
pace from the conference.
&lt;/p&gt;
&lt;p&gt;
&lt;a title="The Alamo" href="https://cid-348cb3ddffbdf313.skydrive.live.com/self.aspx/CGI%20Alliance%202009,%20San%20Antonio,%20TX%20%7C52009-04%7C6/IMG%7C_1848.JPG"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="The Alamo" border="0" alt="The Alamo" src="http://www.ntldr.com/attachments/WindowsLiveWriter/CGIAlliance2009Ratabaseconference_10DFA/IMG_1848_1.jpg" width="644" height="484" /&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
The Alamo (of course!).
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Greg Laswell – Three Flights From Alto Nido – 04 Comes &amp;amp; Goes (In
Waves)
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=3ec74375-53d5-4c06-b505-ed6db1be4485" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,3ec74375-53d5-4c06-b505-ed6db1be4485.aspx</comments>
      <category>IT</category>
      <category>Personal</category>
      <category>Pictures</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=15600d9a-83df-47af-bcf0-ccb39b6fd395</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,15600d9a-83df-47af-bcf0-ccb39b6fd395.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,15600d9a-83df-47af-bcf0-ccb39b6fd395.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=15600d9a-83df-47af-bcf0-ccb39b6fd395</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
There have been entirely too few random bits posted here lately, so here's an IM conversation
from yesterday...
</p>
        <p>
          <span style="font-family: segoe ui; color: #545454;">Jeffrey says (05:34):</span>
          <br />
          <span style="padding-left: 0.125in; font-family: segoe ui;">you're up kind of late...</span>
          <br />
          <span style="font-family: segoe ui; color: #545454;">Jeffrey says (05:35):</span>
          <br />
          <span style="padding-left: 0.125in; font-family: segoe ui;">unless your computers
are LIEING</span>
          <br />
          <span style="font-family: segoe ui; color: #545454;">Matt says (13:31):</span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">or up early</span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">but more likely is
that my computer is full of lies</span>
          <br />
          <span style="font-family: segoe ui; color: #545454;">Matt says (14:10):</span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">but you </span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">are idle</span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">remember Jeffrey...</span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">idle messenger clients
are the Devil's beowulf cluster</span>
          <br />
          <span style="font-family: segoe ui; color: #545454;">Matt says (14:11):</span>
          <br />
          <span style="padding-left: 0.125in; font-family: ms sans serif;">Now the devil has
a better SETI@home score than Jesus, are you happy now Jeffrey?</span>
          <br />
        </p>
        <p style="color: #7f7f7f; text-size: smaller;">
Now playing: Stars – In Our Bedroom After the War – 10 Bitches in Tokyo 
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=15600d9a-83df-47af-bcf0-ccb39b6fd395" />
      </body>
      <title>Random IM conversation</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,15600d9a-83df-47af-bcf0-ccb39b6fd395.aspx</guid>
      <link>http://www.ntldr.com/2009/04/26/RandomIMConversation.aspx</link>
      <pubDate>Sun, 26 Apr 2009 04:38:17 GMT</pubDate>
      <description>&lt;p&gt;
There have been entirely too few random bits posted here lately, so here's an IM conversation
from yesterday...
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-family: segoe ui; color: #545454;"&gt;Jeffrey says (05:34):&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: segoe ui;"&gt;you're up kind of late...&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="font-family: segoe ui; color: #545454;"&gt;Jeffrey says (05:35):&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: segoe ui;"&gt;unless your computers
are LIEING&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="font-family: segoe ui; color: #545454;"&gt;Matt says (13:31):&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;or up early&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;but more likely is
that my computer is full of lies&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="font-family: segoe ui; color: #545454;"&gt;Matt says (14:10):&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;but you &lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;are idle&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;remember Jeffrey...&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;idle messenger clients
are the Devil's beowulf cluster&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="font-family: segoe ui; color: #545454;"&gt;Matt says (14:11):&lt;/span&gt; 
&lt;br /&gt;
&lt;span style="padding-left: 0.125in; font-family: ms sans serif;"&gt;Now the devil has
a better SETI@home score than Jesus, are you happy now Jeffrey?&lt;/span&gt; 
&lt;br /&gt;
&lt;/p&gt;
&lt;p style="color: #7f7f7f; text-size: smaller;"&gt;
Now playing: Stars – In Our Bedroom After the War – 10 Bitches in Tokyo 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=15600d9a-83df-47af-bcf0-ccb39b6fd395" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,15600d9a-83df-47af-bcf0-ccb39b6fd395.aspx</comments>
      <category>IT</category>
      <category>Personal</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=cf1e97b1-a152-4653-a7b5-955dc306f5b3</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,cf1e97b1-a152-4653-a7b5-955dc306f5b3.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,cf1e97b1-a152-4653-a7b5-955dc306f5b3.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=cf1e97b1-a152-4653-a7b5-955dc306f5b3</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
US Airways flight 1549 (the one that had the forced landing on the Hudson River back
in January): 
<br /><a href="http://feedproxy.google.com/~r/typepad/ZSjz/~3/SSL89J3Le2M/mallons-salvage-pictures-back-online.html">http://feedproxy.google.com/~r/typepad/ZSjz/~3/SSL89J3Le2M/mallons-salvage-pictures-back-online.html</a></p>
        <p>
Opting out of online advertising cookies &amp; their tracking behaviours: 
<br /><a href="http://feedproxy.google.com/~r/typepad/sethsmainblog/~3/4mvAgzlGUaI/how-to-opt-out-of-cookie-sniffing-and-trading.html">http://feedproxy.google.com/~r/typepad/sethsmainblog/~3/4mvAgzlGUaI/how-to-opt-out-of-cookie-sniffing-and-trading.html</a><br />
(not sure I entirely believe that opting out would really <em>do</em> anything) 
</p>
        <p>
Doctor Who humour: 
<br /><a href="http://roflrazzi.com/2009/01/08/celebrity-pictures-tennant-pop-up/">http://roflrazzi.com/2009/01/08/celebrity-pictures-tennant-pop-up/</a></p>
        <p>
Exception Driven Development (I actually added something along these lines to the
app at work that I used to work on…it was quite enlightening to be notified about
the crashes/errors and see 1) how alike your users think, &amp; 2) how different that
is from what you thought they’d think and the assumptions you implicitly made when
building the software) 
<br /><a title="http://www.codinghorror.com/blog/archives/001239.html" href="http://www.codinghorror.com/blog/archives/001239.html">http://www.codinghorror.com/blog/archives/001239.html</a></p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Holy F*ck – Holy F*ck EP – 04 Lovely Allen
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=cf1e97b1-a152-4653-a7b5-955dc306f5b3" />
      </body>
      <title>Links</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,cf1e97b1-a152-4653-a7b5-955dc306f5b3.aspx</guid>
      <link>http://www.ntldr.com/2009/04/21/Links.aspx</link>
      <pubDate>Tue, 21 Apr 2009 03:25:30 GMT</pubDate>
      <description>&lt;p&gt;
US Airways flight 1549 (the one that had the forced landing on the Hudson River back
in January): 
&lt;br /&gt;
&lt;a href="http://feedproxy.google.com/~r/typepad/ZSjz/~3/SSL89J3Le2M/mallons-salvage-pictures-back-online.html"&gt;http://feedproxy.google.com/~r/typepad/ZSjz/~3/SSL89J3Le2M/mallons-salvage-pictures-back-online.html&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Opting out of online advertising cookies &amp;amp; their tracking behaviours: 
&lt;br /&gt;
&lt;a href="http://feedproxy.google.com/~r/typepad/sethsmainblog/~3/4mvAgzlGUaI/how-to-opt-out-of-cookie-sniffing-and-trading.html"&gt;http://feedproxy.google.com/~r/typepad/sethsmainblog/~3/4mvAgzlGUaI/how-to-opt-out-of-cookie-sniffing-and-trading.html&lt;/a&gt; 
&lt;br /&gt;
(not sure I entirely believe that opting out would really &lt;em&gt;do&lt;/em&gt; anything) 
&lt;/p&gt;
&lt;p&gt;
Doctor Who humour: 
&lt;br /&gt;
&lt;a href="http://roflrazzi.com/2009/01/08/celebrity-pictures-tennant-pop-up/"&gt;http://roflrazzi.com/2009/01/08/celebrity-pictures-tennant-pop-up/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Exception Driven Development (I actually added something along these lines to the
app at work that I used to work on…it was quite enlightening to be notified about
the crashes/errors and see 1) how alike your users think, &amp;amp; 2) how different that
is from what you thought they’d think and the assumptions you implicitly made when
building the software) 
&lt;br /&gt;
&lt;a title="http://www.codinghorror.com/blog/archives/001239.html" href="http://www.codinghorror.com/blog/archives/001239.html"&gt;http://www.codinghorror.com/blog/archives/001239.html&lt;/a&gt;
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Holy F*ck – Holy F*ck EP – 04 Lovely Allen
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=cf1e97b1-a152-4653-a7b5-955dc306f5b3" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,cf1e97b1-a152-4653-a7b5-955dc306f5b3.aspx</comments>
      <category>IT</category>
      <category>Personal</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=03aab7b1-eaad-4e57-8fad-5437c1f79122</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,03aab7b1-eaad-4e57-8fad-5437c1f79122.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,03aab7b1-eaad-4e57-8fad-5437c1f79122.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=03aab7b1-eaad-4e57-8fad-5437c1f79122</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a title="http://www.wordplace.com/ap/index.shtml" href="http://www.wordplace.com/ap/index.shtml">http://www.wordplace.com/ap/index.shtml</a>
        </p>
        <p>
          <a title="http://www.qwantz.com/fanart/timetravelling.jpg" href="http://www.qwantz.com/fanart/timetravelling.jpg">http://www.qwantz.com/fanart/timetravelling.jpg</a>
        </p>
        <p>
          <a title="http://blogs.msdn.com/michkap/archive/2009/04/08/9537233.aspx" href="http://blogs.msdn.com/michkap/archive/2009/04/08/9537233.aspx">http://blogs.msdn.com/michkap/archive/2009/04/08/9537233.aspx</a>
        </p>
        <p>
          <a title="We need more Engineers" href="http://snowcrash751.blogspot.com/2009/04/we-need-more-engineers.html">We
need more Engineers</a>
        </p>
        <p>
And lastly, for anyone that reads the blog just via the RSS feed and never visits
the sites, my pictures are now hosted via Windows Live Photos. We’ll see how well
that works out in the long run… URL is <a title="http://cid-348cb3ddffbdf313.photos.live.com/" href="http://cid-348cb3ddffbdf313.photos.live.com/">http://cid-348cb3ddffbdf313.photos.live.com/</a></p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Emm Gryner — Get Brave
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=03aab7b1-eaad-4e57-8fad-5437c1f79122" />
      </body>
      <title>Links</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,03aab7b1-eaad-4e57-8fad-5437c1f79122.aspx</guid>
      <link>http://www.ntldr.com/2009/04/16/Links.aspx</link>
      <pubDate>Thu, 16 Apr 2009 03:15:34 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a title="http://www.wordplace.com/ap/index.shtml" href="http://www.wordplace.com/ap/index.shtml"&gt;http://www.wordplace.com/ap/index.shtml&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a title="http://www.qwantz.com/fanart/timetravelling.jpg" href="http://www.qwantz.com/fanart/timetravelling.jpg"&gt;http://www.qwantz.com/fanart/timetravelling.jpg&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a title="http://blogs.msdn.com/michkap/archive/2009/04/08/9537233.aspx" href="http://blogs.msdn.com/michkap/archive/2009/04/08/9537233.aspx"&gt;http://blogs.msdn.com/michkap/archive/2009/04/08/9537233.aspx&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a title="We need more Engineers" href="http://snowcrash751.blogspot.com/2009/04/we-need-more-engineers.html"&gt;We
need more Engineers&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
And lastly, for anyone that reads the blog just via the RSS feed and never visits
the sites, my pictures are now hosted via Windows Live Photos. We’ll see how well
that works out in the long run… URL is &lt;a title="http://cid-348cb3ddffbdf313.photos.live.com/" href="http://cid-348cb3ddffbdf313.photos.live.com/"&gt;http://cid-348cb3ddffbdf313.photos.live.com/&lt;/a&gt;
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Emm Gryner — Get Brave
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=03aab7b1-eaad-4e57-8fad-5437c1f79122" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,03aab7b1-eaad-4e57-8fad-5437c1f79122.aspx</comments>
      <category>IT</category>
      <category>Pictures</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=4453b8dc-0241-4454-bcd0-5b53c40efda5</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,4453b8dc-0241-4454-bcd0-5b53c40efda5.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,4453b8dc-0241-4454-bcd0-5b53c40efda5.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=4453b8dc-0241-4454-bcd0-5b53c40efda5</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
DasBlog 2.3 is <a href="http://dasblog.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24783">out</a>!
Upgrading took longer than it should have...probably because I did a bad job of separating
the application from my SharePoint migration customizations last year. But that’s
been fixed, and upgrading from my custom build of 2.1+ to 2.3 went pretty smoothly.
</p>
        <p>
In case I accidentally delete the files I saved these changes off into (again), here
are my customizations:
</p>
        <ul>
          <li>
~/web.config (I actually just copied &amp; reused my existing web.config file, but
this is the big change*): <pre>&lt;system.webServer&gt;
  ...
  &lt;security&gt;
    &lt;requestFiltering&gt;
      &lt;hiddenSegments applyToWebDAV="true"&gt;
        &lt;add segment="siteConfig" /&gt;
      &lt;/hiddenSegments&gt;
    &lt;/requestFiltering&gt;
  &lt;/security&gt;
  ...
&lt;/system.webServer&gt;</pre></li>
          <li>
~/siteConfig/site.config (these are in addition to the regular ones that have to be
performed, like site title, notification address, root url, etc.): <pre>&lt;!-- CUSTOMIZATIONS: --&gt;
  &lt;DisplayTimeZoneIndex&gt;90&lt;/DisplayTimeZoneIndex&gt;
  &lt;AdjustDisplayTimeZone&gt;false&lt;/AdjustDisplayTimeZone&gt;
  &lt;ContentDir&gt;~/App_Data/content/&lt;/ContentDir&gt;
  &lt;LogDir&gt;~/App_Data/logs/&lt;/LogDir&gt;
  &lt;BinariesDir&gt;~/attachments/&lt;/BinariesDir&gt;
  &lt;ProfilesDir&gt;~/App_Data/profiles/&lt;/ProfilesDir&gt;
  &lt;SmtpServer&gt;localhost&lt;/SmtpServer&gt;
  &lt;EnableSmtpAuthentication&gt;false&lt;/EnableSmtpAuthentication&gt;
  &lt;CommentsRequireApproval&gt;true&lt;/CommentsRequireApproval&gt;
&lt;!-- END OF CUSTOMIZATIONS—&gt;</pre></li>
        </ul>
        <p>
Other customizations:
</p>
        <ul>
          <li>
Backup from old installation and restore to new install: 
<ul><li>
~/siteConfig/blogroll.opml 
</li><li>
~/siteConfig/navigatorLinks.xml 
</li><li>
~/siteConfig/siteSecurity.config 
</li><li>
~/App_Data 
</li><li>
~/attachments 
</li></ul></li>
          <li>
Change ACL on ~/siteConfig to grant NETWORK SERVICE modify access (ACL's on App_Data
and attachments should be retained when backed up &amp; restored; if not, grant this
access to those directories too) 
</li>
        </ul>
        <p>
* I run dasBlog on IIS7, so my web.config file is actually quite a bit different than
the one that ships with dasBlog. But those differences (other than the one highlighted
above) were created by migrating the existing config file.
</p>
        <p style="color: #7f7f7f; font-size: smaller">
Now playing: Emm Gryner – Goddess – 07 Match
</p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=4453b8dc-0241-4454-bcd0-5b53c40efda5" />
      </body>
      <title>dasBlog 2.3 upgrade</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,4453b8dc-0241-4454-bcd0-5b53c40efda5.aspx</guid>
      <link>http://www.ntldr.com/2009/03/23/dasBlog23Upgrade.aspx</link>
      <pubDate>Mon, 23 Mar 2009 03:11:02 GMT</pubDate>
      <description>&lt;p&gt;
DasBlog 2.3 is &lt;a href="http://dasblog.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=24783"&gt;out&lt;/a&gt;!
Upgrading took longer than it should have...probably because I did a bad job of separating
the application from my SharePoint migration customizations last year. But that’s
been fixed, and upgrading from my custom build of 2.1+ to 2.3 went pretty smoothly.
&lt;/p&gt;
&lt;p&gt;
In case I accidentally delete the files I saved these changes off into (again), here
are my customizations:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
~/web.config (I actually just copied &amp;amp; reused my existing web.config file, but
this is the big change*): &lt;pre&gt;&amp;lt;system.webServer&amp;gt;
  ...
  &amp;lt;security&amp;gt;
    &amp;lt;requestFiltering&amp;gt;
      &amp;lt;hiddenSegments applyToWebDAV=&amp;quot;true&amp;quot;&amp;gt;
        &amp;lt;add segment=&amp;quot;siteConfig&amp;quot; /&amp;gt;
      &amp;lt;/hiddenSegments&amp;gt;
    &amp;lt;/requestFiltering&amp;gt;
  &amp;lt;/security&amp;gt;
  ...
&amp;lt;/system.webServer&amp;gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
~/siteConfig/site.config (these are in addition to the regular ones that have to be
performed, like site title, notification address, root url, etc.): &lt;pre&gt;&amp;lt;!-- CUSTOMIZATIONS: --&amp;gt;
  &amp;lt;DisplayTimeZoneIndex&amp;gt;90&amp;lt;/DisplayTimeZoneIndex&amp;gt;
  &amp;lt;AdjustDisplayTimeZone&amp;gt;false&amp;lt;/AdjustDisplayTimeZone&amp;gt;
  &amp;lt;ContentDir&amp;gt;~/App_Data/content/&amp;lt;/ContentDir&amp;gt;
  &amp;lt;LogDir&amp;gt;~/App_Data/logs/&amp;lt;/LogDir&amp;gt;
  &amp;lt;BinariesDir&amp;gt;~/attachments/&amp;lt;/BinariesDir&amp;gt;
  &amp;lt;ProfilesDir&amp;gt;~/App_Data/profiles/&amp;lt;/ProfilesDir&amp;gt;
  &amp;lt;SmtpServer&amp;gt;localhost&amp;lt;/SmtpServer&amp;gt;
  &amp;lt;EnableSmtpAuthentication&amp;gt;false&amp;lt;/EnableSmtpAuthentication&amp;gt;
  &amp;lt;CommentsRequireApproval&amp;gt;true&amp;lt;/CommentsRequireApproval&amp;gt;
&amp;lt;!-- END OF CUSTOMIZATIONS—&amp;gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Other customizations:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
Backup from old installation and restore to new install: 
&lt;ul&gt;
&lt;li&gt;
~/siteConfig/blogroll.opml 
&lt;/li&gt;
&lt;li&gt;
~/siteConfig/navigatorLinks.xml 
&lt;/li&gt;
&lt;li&gt;
~/siteConfig/siteSecurity.config 
&lt;/li&gt;
&lt;li&gt;
~/App_Data 
&lt;/li&gt;
&lt;li&gt;
~/attachments 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Change ACL on ~/siteConfig to grant NETWORK SERVICE modify access (ACL's on App_Data
and attachments should be retained when backed up &amp;amp; restored; if not, grant this
access to those directories too) 
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
* I run dasBlog on IIS7, so my web.config file is actually quite a bit different than
the one that ships with dasBlog. But those differences (other than the one highlighted
above) were created by migrating the existing config file.
&lt;/p&gt;
&lt;p style="color: #7f7f7f; font-size: smaller"&gt;
Now playing: Emm Gryner – Goddess – 07 Match
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=4453b8dc-0241-4454-bcd0-5b53c40efda5" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,4453b8dc-0241-4454-bcd0-5b53c40efda5.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=222db547-4d7d-44cc-aeed-65838b2532a8</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,222db547-4d7d-44cc-aeed-65838b2532a8.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,222db547-4d7d-44cc-aeed-65838b2532a8.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=222db547-4d7d-44cc-aeed-65838b2532a8</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
So...I switched over from SharePoint to dasBlog as the blog engine on the site. This
means that the RSS feed URL has changed. The old ones should all still work, courtesy
of the magic of 301 redirects, but still, everyone likes to be up-to-date, right?
</p>
        <p>
The new URL for the main site feed is: <a title="http://www.ntldr.com/SyndicationService.asmx/GetRss" href="http://www.ntldr.com/SyndicationService.asmx/GetRss">http://www.ntldr.com/SyndicationService.asmx/GetRss</a></p>
        <p>
          <span style="font-size: smaller; color: #7f7f7f">Now Playing: Lightning Dust – Lightning
Dust – 01 Listened On</span>
        </p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=222db547-4d7d-44cc-aeed-65838b2532a8" />
      </body>
      <title>dasBlog</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,222db547-4d7d-44cc-aeed-65838b2532a8.aspx</guid>
      <link>http://www.ntldr.com/2008/07/30/dasBlog.aspx</link>
      <pubDate>Wed, 30 Jul 2008 05:11:12 GMT</pubDate>
      <description>&lt;p&gt;
So...I switched over from SharePoint to dasBlog as the blog engine on the site. This
means that the RSS feed URL has changed. The old ones should all still work, courtesy
of the magic of 301 redirects, but still, everyone likes to be up-to-date, right?
&lt;/p&gt;
&lt;p&gt;
The new URL for the main site feed is: &lt;a title="http://www.ntldr.com/SyndicationService.asmx/GetRss" href="http://www.ntldr.com/SyndicationService.asmx/GetRss"&gt;http://www.ntldr.com/SyndicationService.asmx/GetRss&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size: smaller; color: #7f7f7f"&gt;Now Playing: Lightning Dust – Lightning
Dust – 01 Listened On&lt;/span&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=222db547-4d7d-44cc-aeed-65838b2532a8" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,222db547-4d7d-44cc-aeed-65838b2532a8.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=d4e16522-6576-4991-801d-27f77f6e0eef</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,d4e16522-6576-4991-801d-27f77f6e0eef.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,d4e16522-6576-4991-801d-27f77f6e0eef.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=d4e16522-6576-4991-801d-27f77f6e0eef</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
In response to <a href="http://tfl09.blogspot.com/2008/07/no-virginia-powershell-on-windows-2000.html">this
post</a>, yes, you actually can "run" PowerShell on Windows 2000. No, there is no
out of the box way for it to run. No, it's not supported in the slightest. I'm not
even sure it's technically legal (haven't read that Windows EULA in a long time).
And even when it is running, there are likely to be things that don't work.
</p>
        <p>
That said, here's how to get Windows PowerShell v1.0 to run on Windows 2000.
</p>
        <h3>What you will need
</h3>
        <ul>
          <li>
A computer running Windows XP</li>
          <li>
            <a href="http://support.microsoft.com/kb/926139">KB926139</a> for Windows XP</li>
          <li>
A hex/binary editor (like Visual Studio (or something simpler))</li>
          <li>
            <a href="http://www.microsoft.com/downloads/details.aspx?familyid=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5">.NET
Framework 2.0</a>
          </li>
          <li>
            <a href="http://www.microsoft.com/downloads/info.aspx?na=45&amp;p=1&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=0856eacb-4362-4b0d-8edd-aab15c5e04f5&amp;u=details.aspx%3ffamilyid%3dFE6F2099-B7B4-4F47-A244-C96D69C35DEC%26displaylang%3den">.NET
Framework 2.0 SDK</a>
          </li>
        </ul>
        <h3>Creating the installer (on Windows XP)
</h3>
        <ol>
          <li>
Install the .NET Framework 2.0 SDK. You'll need a specific tool from it, and it's
easier to just install the SDK and grab the tool than it is to try and extract it
somehow.</li>
          <li>
Extract KB926139 (run 'WindowsXP-KB926139-v2-x86-ENU.exe /extract').</li>
          <li>
Make a copy of the 'powershell.exe' file that was extracted from KB926139. Now break
out your hex editor, a copy of the <a href="http://download.microsoft.com/download/e/b/a/eba1050f-a31d-436b-9281-92cdfeae4b45/pecoff.doc">Portable
Executable Format Spec</a>, and modify the header so the Windows 2000 loader will
actually run the image. Or just use your hex editor to modify the byte beginning at
offset 0x00000132 in 'powershell.exe' so it is 0x00 instead of 0x01 (Windows 2000
is version 05.00, not 05.01).</li>
          <li>
Read the 'update\update.inf' file extracted from KB926139. This plain text file contains
the instructions on how to install PowerShell on Windows XP, so all that's needed
is for them to be duplicated on Windows 2000 (batch/reg files? windows scripting host?
whatever you want!).</li>
          <li>
'PSCustomSetupUtil.exe /install' doesn't seem to actually work on Windows 2000. So
use a combination of '<a href="http://msdn.microsoft.com/en-us/library/50614e95.aspx">InstallUtil.exe</a>'
from the .NET Framework and '<a href="http://msdn.microsoft.com/en-us/library/ex0ss12c(VS.80).aspx">GacUtil.exe</a>'
from the .NET Framework SDK (this tool is the entire reason the .NET Framework SDK
is needed).</li>
        </ol>
        <h3>Installation (on Windows 2000)
</h3>
        <ol>
          <li>
Install the .NET Framework 2.0</li>
          <li>
Follow the instructions in update.inf from the extracted KB926139 to install.</li>
          <li>
Remember to substitute 'installutil.exe' and 'gacutil.exe' for usages of 'pscustomsetuputil.exe
/install'.</li>
          <li>
Replace the official version of powershell.exe with the one containing a modified
header.</li>
          <li>
Maybe create a shortcut and define console window appearance settings.</li>
        </ol>
        <h3>For the lazy: all scripted up
</h3>
        <p>
I've gone ahead and deciphered the update.inf file, so if you're feeling lazy, just
download <a href="/attachments/d4e16522-6576-4991-801d-27f77f6e0eef/install package.zip">this
file</a> and follow these instructions. Note that the included scripts assume that
Windows is installed in C:\WINNT. If it's elsewhere, you'll have to modify all the
scripts &amp; registry files.
</p>
        <ol>
          <li>
Unzip the 'install package.zip' file you just downloaded.</li>
          <li>
Get 'gacutil.exe' and 'gacutil.exe.config' from the .NET Framework SDK. Place them
in the NETFXSDK subdirectory of the unzipped install package.</li>
          <li>
Get KB926139 and extract it to the KB926139 subdirectory of the unzipped install package.</li>
          <li>
Copy 'powershell.exe' from the KB926139 subdirectory into the bin directory. Modify
it as in step 3 of "Creating the installer".</li>
          <li>
Take the whole install package structure, now with the PowerShell binaries/installer
tools, to a Windows 2000 system and run the 'System Setup.cmd' batch file.</li>
          <li>
(optional) Run the 'User Setup.js' script to configure the PowerShell window's default
settings to match whatever I had on whatever system I was on when I figured all this
out (most useful because it enables tab completion, which isn't on by default in 2k,
unlike in XP and later).</li>
        </ol>
        <p>
          <span style="font-size: smaller; color: #7f7f7f">Now Playing: Basia Bulat – Oh, My
Darling – 07 In the Night</span>
        </p>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=d4e16522-6576-4991-801d-27f77f6e0eef" />
      </body>
      <title>Windows PowerShell on Windows 2000</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,d4e16522-6576-4991-801d-27f77f6e0eef.aspx</guid>
      <link>http://www.ntldr.com/2008/07/26/WindowsPowerShellOnWindows2000.aspx</link>
      <pubDate>Sat, 26 Jul 2008 05:07:47 GMT</pubDate>
      <description>&lt;p&gt;
In response to &lt;a href="http://tfl09.blogspot.com/2008/07/no-virginia-powershell-on-windows-2000.html"&gt;this
post&lt;/a&gt;, yes, you actually can "run" PowerShell on Windows 2000. No, there is no
out of the box way for it to run. No, it's not supported in the slightest. I'm not
even sure it's technically legal (haven't read that Windows EULA in a long time).
And even when it is running, there are likely to be things that don't work.
&lt;/p&gt;
&lt;p&gt;
That said, here's how to get Windows PowerShell v1.0 to run on Windows 2000.
&lt;/p&gt;
&lt;h3&gt;What you will need
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
A computer running Windows XP&lt;/li&gt;
&lt;li&gt;
&lt;a href="http://support.microsoft.com/kb/926139"&gt;KB926139&lt;/a&gt; for Windows XP&lt;/li&gt;
&lt;li&gt;
A hex/binary editor (like Visual Studio (or something simpler))&lt;/li&gt;
&lt;li&gt;
&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5"&gt;.NET
Framework 2.0&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=45&amp;amp;p=1&amp;amp;SrcDisplayLang=en&amp;amp;SrcCategoryId=&amp;amp;SrcFamilyId=0856eacb-4362-4b0d-8edd-aab15c5e04f5&amp;amp;u=details.aspx%3ffamilyid%3dFE6F2099-B7B4-4F47-A244-C96D69C35DEC%26displaylang%3den"&gt;.NET
Framework 2.0 SDK&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Creating the installer (on Windows XP)
&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
Install the .NET Framework 2.0 SDK. You'll need a specific tool from it, and it's
easier to just install the SDK and grab the tool than it is to try and extract it
somehow.&lt;/li&gt;
&lt;li&gt;
Extract KB926139 (run 'WindowsXP-KB926139-v2-x86-ENU.exe /extract').&lt;/li&gt;
&lt;li&gt;
Make a copy of the 'powershell.exe' file that was extracted from KB926139. Now break
out your hex editor, a copy of the &lt;a href="http://download.microsoft.com/download/e/b/a/eba1050f-a31d-436b-9281-92cdfeae4b45/pecoff.doc"&gt;Portable
Executable Format Spec&lt;/a&gt;, and modify the header so the Windows 2000 loader will
actually run the image. Or just use your hex editor to modify the byte beginning at
offset 0x00000132 in 'powershell.exe' so it is 0x00 instead of 0x01 (Windows 2000
is version 05.00, not 05.01).&lt;/li&gt;
&lt;li&gt;
Read the 'update\update.inf' file extracted from KB926139. This plain text file contains
the instructions on how to install PowerShell on Windows XP, so all that's needed
is for them to be duplicated on Windows 2000 (batch/reg files? windows scripting host?
whatever you want!).&lt;/li&gt;
&lt;li&gt;
'PSCustomSetupUtil.exe /install' doesn't seem to actually work on Windows 2000. So
use a combination of '&lt;a href="http://msdn.microsoft.com/en-us/library/50614e95.aspx"&gt;InstallUtil.exe&lt;/a&gt;'
from the .NET Framework and '&lt;a href="http://msdn.microsoft.com/en-us/library/ex0ss12c(VS.80).aspx"&gt;GacUtil.exe&lt;/a&gt;'
from the .NET Framework SDK (this tool is the entire reason the .NET Framework SDK
is needed).&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Installation (on Windows 2000)
&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
Install the .NET Framework 2.0&lt;/li&gt;
&lt;li&gt;
Follow the instructions in update.inf from the extracted KB926139 to install.&lt;/li&gt;
&lt;li&gt;
Remember to substitute 'installutil.exe' and 'gacutil.exe' for usages of 'pscustomsetuputil.exe
/install'.&lt;/li&gt;
&lt;li&gt;
Replace the official version of powershell.exe with the one containing a modified
header.&lt;/li&gt;
&lt;li&gt;
Maybe create a shortcut and define console window appearance settings.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;For the lazy: all scripted up
&lt;/h3&gt;
&lt;p&gt;
I've gone ahead and deciphered the update.inf file, so if you're feeling lazy, just
download &lt;a href="/attachments/d4e16522-6576-4991-801d-27f77f6e0eef/install package.zip"&gt;this
file&lt;/a&gt; and follow these instructions. Note that the included scripts assume that
Windows is installed in C:\WINNT. If it's elsewhere, you'll have to modify all the
scripts &amp;amp; registry files.
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
Unzip the 'install package.zip' file you just downloaded.&lt;/li&gt;
&lt;li&gt;
Get 'gacutil.exe' and 'gacutil.exe.config' from the .NET Framework SDK. Place them
in the NETFXSDK subdirectory of the unzipped install package.&lt;/li&gt;
&lt;li&gt;
Get KB926139 and extract it to the KB926139 subdirectory of the unzipped install package.&lt;/li&gt;
&lt;li&gt;
Copy 'powershell.exe' from the KB926139 subdirectory into the bin directory. Modify
it as in step 3 of "Creating the installer".&lt;/li&gt;
&lt;li&gt;
Take the whole install package structure, now with the PowerShell binaries/installer
tools, to a Windows 2000 system and run the 'System Setup.cmd' batch file.&lt;/li&gt;
&lt;li&gt;
(optional) Run the 'User Setup.js' script to configure the PowerShell window's default
settings to match whatever I had on whatever system I was on when I figured all this
out (most useful because it enables tab completion, which isn't on by default in 2k,
unlike in XP and later).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
&lt;span style="font-size: smaller; color: #7f7f7f"&gt;Now Playing: Basia Bulat – Oh, My
Darling – 07 In the Night&lt;/span&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=d4e16522-6576-4991-801d-27f77f6e0eef" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,d4e16522-6576-4991-801d-27f77f6e0eef.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=15d0c75c-42ef-4563-b859-eeab88311956</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,15d0c75c-42ef-4563-b859-eeab88311956.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,15d0c75c-42ef-4563-b859-eeab88311956.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=15d0c75c-42ef-4563-b859-eeab88311956</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
First it was the IIS box serving this site, but now it's going to be the whole network
that's moving to Windows Server 2008. I'm attempting to go with a complete new forest
installation, which will force migrating everything over from the old Server 2003
forest, so that should be interesting. And now, onto the first notes about that experience!
</p>
          <p>
So...here's what's happening: installing a "new" server using Windows Server
2008, making it the first DC in the domain, and then installing Virtual Server 2005
R2 SP1 Enterprise (okay, can that name <em>get </em>any longer?!) without installing
IIS. And it's the Core version of Server 2008, so everything is via the command line.
After having worked on it for the better part of today, I'm now sitting here wondering
why the heck anyone would use Core. I mean, if I wanted a command line only interface,
I'd just use BSD or Linux!
</p>
          <p>
For future reference here are a couple of things:
</p>
          <h4>Useful commands:
</h4>
          <p>
            <span style="font-family:consolas, lucida console, monospace">pnputil -i -a &lt;inf&gt;</span> (install
device drivers (I think...I haven't confirmed if this actually installed them yet))
</p>
          <p>
            <span style="font-family:consolas, lucida console, monospace">cscript %systemroot%\system32\scregedit.wsf
/au 4</span> (Enable automatic updates)
</p>
          <p>
            <span style="font-family:consolas, lucida console, monospace">cscript %systemroot%\system32\scregedit.wsf
/ar 0</span> (Enable Terminal Services)
</p>
          <p>
            <span style="font-family:consolas, lucida console, monospace">cscript %systemroot%\system32\scregedit.wsf
/im 1</span> (Enable remote IPSec management)
</p>
          <p>
            <span style="font-family:consolas, lucida console, monospace">netsh interface ipv4
show interface</span> (get the list of names for use in other netsh commands)
</p>
          <p>
            <em>Feldspar:</em>
          </p>
          <p style="font-family:consolas, lucida console, monospace">
netsh interface ipv4 set address name=2 source=static address=10.0.1.9 mask=255.0.0.0
gateway=10.0.0.1
</p>
          <p style="font-family:consolas, lucida console, monospace">
netsh interface ipv4 set address name=3 source=static address=10.0.1.10 mask=255.0.0.0
gateway=10.0.0.1
</p>
          <p style="font-family:consolas, lucida console, monospace">
netsh interface ipv4 add dnsserver name=2 address=10.0.1.9 index=1
</p>
          <p style="font-family:consolas, lucida console, monospace">
netsh interface ipv4 add dnsserver name=3 address=10.0.1.10 index=1
</p>
          <h4>Useful links:
</h4>
          <p>
            <a href="http://blogs.technet.com/shinsley/archive/2007/04/19/windows-server-longhorn-server-core.aspx">http://blogs.technet.com/shinsley/archive/2007/04/19/windows-server-longhorn-server-core.aspx</a>
          </p>
          <p>
            <a href="http://blogs.technet.com/server_core/archive/2008/04/16/reducing-the-server-core-disk-footprint.aspx">http://blogs.technet.com/server_core/archive/2008/04/16/reducing-the-server-core-disk-footprint.aspx</a>
          </p>
          <p>
            <a title="http://support.microsoft.com/kb/890893/en-us" href="http://support.microsoft.com/kb/890893/en-us">http://support.microsoft.com/kb/890893/en-us</a>
          </p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=15d0c75c-42ef-4563-b859-eeab88311956" />
      </body>
      <title>Windows Server 2008 upgrade, part 1</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,15d0c75c-42ef-4563-b859-eeab88311956.aspx</guid>
      <link>http://www.ntldr.com/2008/04/28/WindowsServer2008UpgradePart1.aspx</link>
      <pubDate>Mon, 28 Apr 2008 05:15:13 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
First it was the IIS box serving this site, but now it's going to be the whole network
that's moving to Windows Server 2008. I'm attempting to go with a complete new forest
installation, which will force migrating everything over from the old Server 2003
forest, so that should be interesting. And now, onto the first notes about that experience!
&lt;/p&gt;
&lt;p&gt;
So...here's what's happening: installing a &amp;quot;new&amp;quot; server using Windows Server
2008, making it the first DC in the domain, and then installing Virtual Server 2005
R2 SP1 Enterprise (okay, can that name &lt;em&gt;get &lt;/em&gt;any longer?!) without installing
IIS. And it's the Core version of Server 2008, so everything is via the command line.
After having worked on it for the better part of today, I'm now sitting here wondering
why the heck anyone would use Core. I mean, if I wanted a command line only interface,
I'd just use BSD or Linux!
&lt;/p&gt;
&lt;p&gt;
For future reference here are a couple of things:
&lt;/p&gt;
&lt;h4&gt;Useful commands:
&lt;/h4&gt;
&lt;p&gt;
&lt;span style="font-family:consolas, lucida console, monospace"&gt;pnputil -i -a &amp;lt;inf&amp;gt;&lt;/span&gt; (install
device drivers (I think...I haven't confirmed if this actually installed them yet))
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-family:consolas, lucida console, monospace"&gt;cscript %systemroot%\system32\scregedit.wsf
/au 4&lt;/span&gt; (Enable automatic updates)
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-family:consolas, lucida console, monospace"&gt;cscript %systemroot%\system32\scregedit.wsf
/ar 0&lt;/span&gt; (Enable Terminal Services)
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-family:consolas, lucida console, monospace"&gt;cscript %systemroot%\system32\scregedit.wsf
/im 1&lt;/span&gt; (Enable remote IPSec management)
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-family:consolas, lucida console, monospace"&gt;netsh interface ipv4
show interface&lt;/span&gt; (get the list of names for use in other netsh commands)
&lt;/p&gt;
&lt;p&gt;
&lt;em&gt;Feldspar:&lt;/em&gt; 
&lt;p style="font-family:consolas, lucida console, monospace"&gt;
netsh interface ipv4 set address name=2 source=static address=10.0.1.9 mask=255.0.0.0
gateway=10.0.0.1
&lt;/p&gt;
&lt;p style="font-family:consolas, lucida console, monospace"&gt;
netsh interface ipv4 set address name=3 source=static address=10.0.1.10 mask=255.0.0.0
gateway=10.0.0.1
&lt;/p&gt;
&lt;p style="font-family:consolas, lucida console, monospace"&gt;
netsh interface ipv4 add dnsserver name=2 address=10.0.1.9 index=1
&lt;/p&gt;
&lt;p style="font-family:consolas, lucida console, monospace"&gt;
netsh interface ipv4 add dnsserver name=3 address=10.0.1.10 index=1
&lt;/p&gt;
&lt;h4&gt;Useful links:
&lt;/h4&gt;
&lt;p&gt;
&lt;a href="http://blogs.technet.com/shinsley/archive/2007/04/19/windows-server-longhorn-server-core.aspx"&gt;http://blogs.technet.com/shinsley/archive/2007/04/19/windows-server-longhorn-server-core.aspx&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://blogs.technet.com/server_core/archive/2008/04/16/reducing-the-server-core-disk-footprint.aspx"&gt;http://blogs.technet.com/server_core/archive/2008/04/16/reducing-the-server-core-disk-footprint.aspx&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a title="http://support.microsoft.com/kb/890893/en-us" href="http://support.microsoft.com/kb/890893/en-us"&gt;http://support.microsoft.com/kb/890893/en-us&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=15d0c75c-42ef-4563-b859-eeab88311956" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,15d0c75c-42ef-4563-b859-eeab88311956.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <h3>Panel: To Share or Not to Share
</h3>
          <ul>
            <li>
Sharing is broken across regions (regions get approved/filed at different times, which
complicates implementing changes)</li>
            <li>
Some people apparently just don't use regions: they emulate it all with the formulas
and lots of tables</li>
            <li>
But sharing makes development faster (at the cost of more complex maintenance)</li>
            <li>
My thought: perhaps sharing would be more useful if really break down everything into
small components that wont change</li>
            <li>
What actually gets shared depends, as always, on business requirements</li>
          </ul>
          <h3>Break:
</h3>
          <p>
I thought I should take some pictures of the resort that the conference was at.
</p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0394.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Loews-Ventana Canyon Resort lobby entrance" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0394_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Loews-Ventana Canyon Resort lobby entrance.
</p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0395.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Loews-Ventana Canyon Resort pond" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0395_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Pond at the Loews-Ventana Canyon Resort. Yes, this is in the desert. It makes me wonder
what happens when there's a real drought...
</p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0398.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Loews-Ventana Canyon Resort golf course" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0398_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Golf course at the Loews-Ventana Canyon Resort. Plus a little bit of the pond they
have that spills over in a pretty water feature into a lower pond. Although that part
shows up more as the water just ending in a sharp edge.
</p>
          <h3>"X"ML Marks the Spot ~ Utilizing Ratabase XML
</h3>
          <ul>
            <li>
Presented by Serge Décoeur</li>
            <li>
Overview of XML (if you don't know this, umm...learn it?)</li>
            <li>
Ratabase XML schema: 'RBGeneric.xsd'</li>
            <li>
New with v.5.0</li>
            <li>
Fields: 
<ul><li>
General fields := input fields</li><li>
Accumulator, Parameter fields := output fields</li><li>
Global fields SHOULD NOT be passed in</li><li>
Optional FLD attributes MOSTLY used by test tool</li><li>
Arrays also handled differently</li></ul></li>
            <li>
We've coded formulas to handle NoMatch errors - we just keep on processing</li>
            <li>
Uppercasing everything "performs better"</li>
            <li>
Extension stuff sounds interesting 
<ul><li>
Not passed to calculator, so more efficient data pass through mechanism?</li></ul></li>
            <li>
Exclude attribute lets Nodes not be passed to the calculator</li>
            <li>
API doesn't drive calls at all 
<ul><li>
your "LobAdapter" would do it 
</li><li>
so we'd still have the web service, it just eliminates block specific stuff in it
(replace with the XML API)</li></ul></li>
          </ul>
          <h3>Wynsure Solution Overview
</h3>
          <ul>
            <li>
Platform portfolio of products</li>
            <li>
"Synergy Solutions" : partner with other solutions (non-CGI)</li>
            <li>
CGI implements, supports, does it ALL for these apps</li>
            <li>
Highly component based (good), but single sourced (bad) 
<ul><li>
.NET version is "a lot faster" than the Java version</li></ul></li>
            <li>
Actually written by Wyd (in Minneapolis)?!</li>
            <li>
Does Property &amp; Casualty and Life</li>
            <li>
Adding: 
<ul><li>
reflexive questioning</li><li>
acord support</li></ul></li>
          </ul>
          <h3>Finding the Proven Trail - Upgrading from Prior Versions
</h3>
          <ul>
            <li>
Summary: v4.0 → v4.2 → v5.01 
<ul><li>
Presented by John Barlow</li><li>
Upgrade Production before Product Builder</li><li>
Need Full distro to get to v5.01</li></ul></li>
            <li>
Product Builder 
<ul><li>
v4.0 → v4.2 
<ul><li>
Create Archive DB (.sql or DB2 script)</li><li>
Archive stuff is optional - can enable archive stuff AFTER 5.0 update</li><li>
Calculator doesn't really get updated with 4.2</li><li>
Note: Liberty firewall prevents us from getting FTP access</li></ul></li><li>
v4.2 → v5.0 
<ul><li>
SQL script (or DB2 batch file)</li><li>
Run security update</li><li>
Update Product Builder database ID</li></ul></li></ul></li>
            <li>
Production 
<ul><li>
Update DB's (further instructions)</li><li>
Install v5.01 following instructions</li><li>
(No complex upgrade steps)</li></ul></li>
            <li>
v5.0 
<ul><li>
Additional date validator changes</li><li>
adapter change</li></ul></li>
            <li>
"Feel free to contact help desk"</li>
          </ul>
          <h3>Exploring the Desert Landscape ~ Desert Jeep Tour 
</h3>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0402.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Arizona desert" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0402_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0407.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Desert plant" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0407_thumb.jpg" width="364px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0413.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Horse and donkey" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0413_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0419.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Desert plant" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0419_thumb.jpg" width="364px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0423.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Saguaro cacti on rocky hill" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0423_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0427.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Desert flower" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0427_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0434.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Old saguaro cactus" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0434_thumb.jpg" width="364px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0441.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Petroglyphs" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0441_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p style="font-size:smaller;color:#7f7f7f">
Now playing: Sam Roberts – Love at the End of the World – Them Kids
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936" />
      </body>
      <title>CGI Alliance 2008 Conference Live Blog: Day 2</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936.aspx</guid>
      <link>http://www.ntldr.com/2008/04/01/CGIAlliance2008ConferenceLiveBlogDay2.aspx</link>
      <pubDate>Tue, 01 Apr 2008 23:59:48 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;h3&gt;Panel: To Share or Not to Share
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
Sharing is broken across regions (regions get approved/filed at different times, which
complicates implementing changes)&lt;/li&gt;
&lt;li&gt;
Some people apparently just don't use regions: they emulate it all with the formulas
and lots of tables&lt;/li&gt;
&lt;li&gt;
But sharing makes development faster (at the cost of more complex maintenance)&lt;/li&gt;
&lt;li&gt;
My thought: perhaps sharing would be more useful if really break down everything into
small components that wont change&lt;/li&gt;
&lt;li&gt;
What actually gets shared depends, as always, on business requirements&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Break:
&lt;/h3&gt;
&lt;p&gt;
I thought I should take some pictures of the resort that the conference was at.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0394.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Loews-Ventana Canyon Resort lobby entrance" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0394_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Loews-Ventana Canyon Resort lobby entrance.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0395.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Loews-Ventana Canyon Resort pond" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0395_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Pond at the Loews-Ventana Canyon Resort. Yes, this is in the desert. It makes me wonder
what happens when there's a real drought...
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0398.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border="0" alt="Loews-Ventana Canyon Resort golf course" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0398_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Golf course at the Loews-Ventana Canyon Resort. Plus a little bit of the pond they
have that spills over in a pretty water feature into a lower pond. Although that part
shows up more as the water just ending in a sharp edge.
&lt;/p&gt;
&lt;h3&gt;"X"ML Marks the Spot ~ Utilizing Ratabase XML
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
Presented by Serge Décoeur&lt;/li&gt;
&lt;li&gt;
Overview of XML (if you don't know this, umm...learn it?)&lt;/li&gt;
&lt;li&gt;
Ratabase XML schema: 'RBGeneric.xsd'&lt;/li&gt;
&lt;li&gt;
New with v.5.0&lt;/li&gt;
&lt;li&gt;
Fields: 
&lt;ul&gt;
&lt;li&gt;
General fields := input fields&lt;/li&gt;
&lt;li&gt;
Accumulator, Parameter fields := output fields&lt;/li&gt;
&lt;li&gt;
Global fields SHOULD NOT be passed in&lt;/li&gt;
&lt;li&gt;
Optional FLD attributes MOSTLY used by test tool&lt;/li&gt;
&lt;li&gt;
Arrays also handled differently&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
We've coded formulas to handle NoMatch errors - we just keep on processing&lt;/li&gt;
&lt;li&gt;
Uppercasing everything &amp;quot;performs better&amp;quot;&lt;/li&gt;
&lt;li&gt;
Extension stuff sounds interesting 
&lt;ul&gt;
&lt;li&gt;
Not passed to calculator, so more efficient data pass through mechanism?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Exclude attribute lets Nodes not be passed to the calculator&lt;/li&gt;
&lt;li&gt;
API doesn't drive calls at all 
&lt;ul&gt;
&lt;li&gt;
your &amp;quot;LobAdapter&amp;quot; would do it 
&lt;li&gt;
so we'd still have the web service, it just eliminates block specific stuff in it
(replace with the XML API)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Wynsure Solution Overview
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
Platform portfolio of products&lt;/li&gt;
&lt;li&gt;
&amp;quot;Synergy Solutions&amp;quot; : partner with other solutions (non-CGI)&lt;/li&gt;
&lt;li&gt;
CGI implements, supports, does it ALL for these apps&lt;/li&gt;
&lt;li&gt;
Highly component based (good), but single sourced (bad) 
&lt;ul&gt;
&lt;li&gt;
.NET version is &amp;quot;a lot faster&amp;quot; than the Java version&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Actually written by Wyd (in Minneapolis)?!&lt;/li&gt;
&lt;li&gt;
Does Property &amp;amp; Casualty and Life&lt;/li&gt;
&lt;li&gt;
Adding: 
&lt;ul&gt;
&lt;li&gt;
reflexive questioning&lt;/li&gt;
&lt;li&gt;
acord support&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Finding the Proven Trail - Upgrading from Prior Versions
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
Summary: v4.0 → v4.2 → v5.01 
&lt;ul&gt;
&lt;li&gt;
Presented by John Barlow&lt;/li&gt;
&lt;li&gt;
Upgrade Production before Product Builder&lt;/li&gt;
&lt;li&gt;
Need Full distro to get to v5.01&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Product Builder 
&lt;ul&gt;
&lt;li&gt;
v4.0 → v4.2 
&lt;ul&gt;
&lt;li&gt;
Create Archive DB (.sql or DB2 script)&lt;/li&gt;
&lt;li&gt;
Archive stuff is optional - can enable archive stuff AFTER 5.0 update&lt;/li&gt;
&lt;li&gt;
Calculator doesn't really get updated with 4.2&lt;/li&gt;
&lt;li&gt;
Note: Liberty firewall prevents us from getting FTP access&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
v4.2 → v5.0 
&lt;ul&gt;
&lt;li&gt;
SQL script (or DB2 batch file)&lt;/li&gt;
&lt;li&gt;
Run security update&lt;/li&gt;
&lt;li&gt;
Update Product Builder database ID&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;
Production 
&lt;ul&gt;
&lt;li&gt;
Update DB's (further instructions)&lt;/li&gt;
&lt;li&gt;
Install v5.01 following instructions&lt;/li&gt;
&lt;li&gt;
(No complex upgrade steps)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
v5.0 
&lt;ul&gt;
&lt;li&gt;
Additional date validator changes&lt;/li&gt;
&lt;li&gt;
adapter change&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&amp;quot;Feel free to contact help desk&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Exploring the Desert Landscape ~ Desert Jeep Tour 
&lt;/h3&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0402.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Arizona desert" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0402_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0407.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Desert plant" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0407_thumb.jpg" width="364px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0413.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Horse and donkey" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0413_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0419.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Desert plant" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0419_thumb.jpg" width="364px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0423.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Saguaro cacti on rocky hill" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0423_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0427.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Desert flower" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0427_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0434.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt="Old saguaro cactus" src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0434_thumb.jpg" width="364px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0441.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" border=0 alt=Petroglyphs src="/Attachments/ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936/IMG_0441_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p style="font-size:smaller;color:#7f7f7f"&gt;
Now playing: Sam Roberts – Love at the End of the World – Them Kids
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,ad2e6e4a-8fe7-42eb-8ac2-1fd348bd4936.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=fc4c42eb-05d5-466d-ac01-7cee0c10c2df</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,fc4c42eb-05d5-466d-ac01-7cee0c10c2df.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,fc4c42eb-05d5-466d-ac01-7cee0c10c2df.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=fc4c42eb-05d5-466d-ac01-7cee0c10c2df</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <h3>Welcome event
</h3>
          <ul>
            <li>
CGI has a number of different apps - it's not just Ratabase!</li>
            <li>
CGI is BIG! ~26 000 employees and growing 
</li>
          </ul>
          <h4>Introduction:
</h4>
          <ul>
            <li>
Begins with Clients introducing themselves &amp; how they use Ratabase. We (LNW) run
the Ratabase calculator on Unix with a DB2 backend and IBM WebSphere app server interfacing
to the calculator via JNI</li>
            <li>
Some use Ratabase for Underwriting Rules (probably a bad idea, but meh...)</li>
            <li>
Mike (of Chubb) is interested in decoupling &amp; using SOA (so, might want to talk
to him, since we do that at LNW)</li>
            <li>
Geico people say they're on v5.0 (so, might want to talk to them about migration)</li>
            <li>
Liberty International uses it with Specialty Lines (there's other parts of Liberty
that use it? &lt;sarcasm&gt;who'd have guessed?&lt;/sarcasm&gt;)</li>
            <li>
&lt;something&gt; going to .NET</li>
            <li>
Traveller's looking for WC Anniversary Rating advice (sounds like they need to talk
to Deb...we've already dealt with this problem space)</li>
            <li>
Erie Insurance implies that the Report Tool can be used to verify the TRN files in
multiple environments (might prove useful if we have sync problems between any of
our 5 environments).</li>
            <li>
And ends with various awards being handed out 
</li>
          </ul>
          <h4>Panel discussion:
</h4>
          <ul>
            <li>
Notes taken but not really coherent. Mostly questions about the direction of rating
stuff in the insurance industry (so I didn't follow too well, and stopped even trying
to take notes half way through).</li>
          </ul>
          <h3>Distribution ("What to Pack"): Santa Rita room, 13:00
</h3>
          <ul>
            <li>
You need a Workflow!</li>
            <li>
Starts in Product Builder (sounds like distribution isn't such a big deal for us because
it's just Deb doing Ratabase right now)</li>
            <li>
SHOULD use Product Builder's data statuses</li>
            <li>
Can't (yet) do distribution by date</li>
            <li>
"Status is just a checklist" - it doesn't affect operations 
<ul><li>
'Ready to File' locks data down to read-only</li><li>
'Filed' is not reversible! (except when it is) 
</li></ul></li>
            <li>
Date changes can be done on 'User Filed' items (date change utility)</li>
            <li>
v5.0 allows more test distributions: distribute while recalled so can test recalled
changes</li>
            <li>
General Distribution: redistribute everything 
<ul><li>
Sounds like what I think we do now</li><li>
Maybe for fixes we could go with Specific Element 
</li></ul></li>
            <li>
What type of distribution are we doing? 
<ul><li>
Production or Test?<span color="#ff0000">(T*.trn == Test)</span></li><li>
Loader is stricter with Production target 
</li></ul></li>
            <li>
"Distribution Drawer" in Product Builder stores distribution definitions 
<ul><li>
We should keep a log of distributed data 
</li></ul></li>
            <li>
Production TRN distribution: <strong>D*.trn</strong></li>
            <li>
With general distribution, don't have to worry about missing file loads</li>
            <li>
Drawer allows recreation of a TRN 
<ul><li>
Unless filings have been shredded</li><li>
Or dates changed - GETADDR error</li><li>
Also, it creates a new sequence number (to allow rbdload to load the file) 
</li></ul></li>
            <li>
Owner-sharer relationships can be tricky 
<ul><li>
Don't want owner distributed? Out of luck if sharer used it &amp; gets distributed. 
</li></ul></li>
            <li>
              <strong>v5.0:</strong>
              <ul>
                <li>
Distribution files have changed 
<ul><li>
Can run reports on production databases to get build info</li><li>
Adds TRN file sequence/version number to database!</li><li>
We can read the sequence number &amp; output version automatically! 
</li></ul></li>
              </ul>
            </li>
            <li>
Filings shredded in Product Builder but distributed will only be removed by using
RBDelete – loading/reloading will not remove them.</li>
            <li>
Archive utility also exists to pull things off production databases too</li>
            <li>
When dealing with Owner-Sharer relationships, Product Builder actually does duplicate
the data, but it also keeps track of what the relationships WOULD BE 
<ul><li>
Sharing data doesn't actually exist in the production DB, it's just relationships
based on OID's</li></ul></li>
            <li>
Shredding may be needed to break sharing relationships (for us this "future"
is when we move to User Filing)</li>
            <li>
Date Changes need to be done after shredding &amp; recreation 
<ul><li>
because dates are used in the object mapping (if OID changes)</li><li>
dates are also used to pick filings</li><li>
TRN Loader matches on OID || all other fields</li></ul></li>
            <li>
If the table structure changes, Originators (owners) need to be put in first</li>
            <li>
Auditing is only done on user filed data 
<ul><li>
So we don't have any auditing support now?!</li></ul></li>
            <li>
Recall Distribution must be done after recall &amp; before any future distributions</li>
            <li>
Different regions wont get caught with sequence errors on load (sequence numbers don't
have to be increasing across regions, just within a region)</li>
          </ul>
          <h3>Interactive Discussion
</h3>
          <ul>
            <li>
Characteristics of good Ratabase programmer/analyst/whatever (people that work with
Ratabase/Product Builder) 
<ul><li>
Team Player: needs to bridge IT &amp; biz users</li><li>
Problem solver</li><li>
Analytical (LM PM VP said the economics majors worked out better than others)</li><li>
Attention to detail!</li><li>
Some use Actuarial to do Ratabase because they make the rate changes anyway (I think
we technically do this, at least if you look at the titles &amp; reporting structures)</li><li>
Some use Consumer Affairs because of their understanding of the regulations and mediation
of dealings with regulators</li><li>
But you don't need a CPCU 
<ul><li>
Need to understand the Product though</li><li>
Maybe only really need <em>some</em> biz knowledgeable users; not everyone needs to
know it to code it.</li><li><strong>Really</strong> need people who understand Formulas &amp; Math</li></ul></li><li>
Must play well with others ("Participants are all in Partnerships")</li><li>
Some projects helped by strong leads/PM</li><li>
Colocating can be very helpful too</li><li>
Can't separate IT &amp; Biz that much; Ratabase is in between both worlds</li></ul></li>
          </ul>
          <h3>Client Product Forum
</h3>
          <ul>
            <li>
Apparently they have this conference call every quarter to discuss how people feel
about Ratabase</li>
            <li>
Kind of a User Group for Ratabase</li>
            <li>
Gives CGI feedback for future plans/support options</li>
            <li>
v.5.0: Need to upgrade from v.4.2</li>
            <li>
v.5.01: Need to upgrade from v.5.0 
<ul><li>
Better Testing</li><li>
Added XML API</li><li>
Allows arbitrary NoMatch entries (indices in Item blocks don't need to be pre-allocated)</li><li>
FTP into site to get the Full distro (direct from v.4.2 to v.5.01)</li></ul></li>
            <li>
v.6.0 is in progress 
<ul><li>
.NET native app!</li><li>
can now sort columns of data by <em>clicking on the column</em></li><li>
Filing groups</li><li>
Can now view formulas graphically (WPF maybe?)</li><li>
Will be able to re-rate within calls (so we could conceivably do 1 call with multiple
passes)</li><li>
XML data API expanded to encompass Data Validation</li></ul></li>
            <li>
Listening to what other people say, it sounds like a lot of companies have bad practices: 
<ul><li>
Passing data through Ratabase</li><li>
Not tracking changes</li><li>
Making Ratabase take on roles it wasn't designed for: 
<ul><li>
workflow</li><li>
rules</li></ul></li><li>
Why would one have thousands &amp; thousands of tables!?</li></ul></li>
            <li>
Maybe we should adopt a naming practice for input fields 
<ul><li>
Assuming they're actually different than the ones marked as Input in the database
(no, you aren't supposed to be mucking around inside the database to figure things
out...)</li></ul></li>
            <li>
Liberty Mutual Personal Markets needs &gt;15 digit numbers (trillions)</li>
            <li>
XML test cases for testing tool might be good</li>
          </ul>
          <p style="font-size:smaller;color:#7f7f7f">
Now playing: Veda Hille – the riot life – lucklucky
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=fc4c42eb-05d5-466d-ac01-7cee0c10c2df" />
      </body>
      <title>CGI Alliance 2008 Conference Live Blog: Day 1</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,fc4c42eb-05d5-466d-ac01-7cee0c10c2df.aspx</guid>
      <link>http://www.ntldr.com/2008/03/31/CGIAlliance2008ConferenceLiveBlogDay1.aspx</link>
      <pubDate>Mon, 31 Mar 2008 23:59:23 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;h3&gt;Welcome event
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
CGI has a number of different apps - it's not just Ratabase!&lt;/li&gt;
&lt;li&gt;
CGI is BIG! ~26 000 employees and growing 
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Introduction:
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
Begins with Clients introducing themselves &amp;amp; how they use Ratabase. We (LNW) run
the Ratabase calculator on Unix with a DB2 backend and IBM WebSphere app server interfacing
to the calculator via JNI&lt;/li&gt;
&lt;li&gt;
Some use Ratabase for Underwriting Rules (probably a bad idea, but meh...)&lt;/li&gt;
&lt;li&gt;
Mike (of Chubb) is interested in decoupling &amp;amp; using SOA (so, might want to talk
to him, since we do that at LNW)&lt;/li&gt;
&lt;li&gt;
Geico people say they're on v5.0 (so, might want to talk to them about migration)&lt;/li&gt;
&lt;li&gt;
Liberty International uses it with Specialty Lines (there's other parts of Liberty
that use it? &amp;lt;sarcasm&amp;gt;who'd have guessed?&amp;lt;/sarcasm&amp;gt;)&lt;/li&gt;
&lt;li&gt;
&amp;lt;something&amp;gt; going to .NET&lt;/li&gt;
&lt;li&gt;
Traveller's looking for WC Anniversary Rating advice (sounds like they need to talk
to Deb...we've already dealt with this problem space)&lt;/li&gt;
&lt;li&gt;
Erie Insurance implies that the Report Tool can be used to verify the TRN files in
multiple environments (might prove useful if we have sync problems between any of
our 5 environments).&lt;/li&gt;
&lt;li&gt;
And ends with various awards being handed out 
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Panel discussion:
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
Notes taken but not really coherent. Mostly questions about the direction of rating
stuff in the insurance industry (so I didn't follow too well, and stopped even trying
to take notes half way through).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Distribution (&amp;quot;What to Pack&amp;quot;): Santa Rita room, 13:00
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
You need a Workflow!&lt;/li&gt;
&lt;li&gt;
Starts in Product Builder (sounds like distribution isn't such a big deal for us because
it's just Deb doing Ratabase right now)&lt;/li&gt;
&lt;li&gt;
SHOULD use Product Builder's data statuses&lt;/li&gt;
&lt;li&gt;
Can't (yet) do distribution by date&lt;/li&gt;
&lt;li&gt;
&amp;quot;Status is just a checklist&amp;quot; - it doesn't affect operations 
&lt;ul&gt;
&lt;li&gt;
'Ready to File' locks data down to read-only&lt;/li&gt;
&lt;li&gt;
'Filed' is not reversible! (except when it is) 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Date changes can be done on 'User Filed' items (date change utility)&lt;/li&gt;
&lt;li&gt;
v5.0 allows more test distributions: distribute while recalled so can test recalled
changes&lt;/li&gt;
&lt;li&gt;
General Distribution: redistribute everything 
&lt;ul&gt;
&lt;li&gt;
Sounds like what I think we do now&lt;/li&gt;
&lt;li&gt;
Maybe for fixes we could go with Specific Element 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
What type of distribution are we doing? 
&lt;ul&gt;
&lt;li&gt;
Production or Test?&lt;span color="#ff0000"&gt;(T*.trn == Test)&lt;/span&gt;
&lt;/li&gt;
&lt;li&gt;
Loader is stricter with Production target 
&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;
&amp;quot;Distribution Drawer&amp;quot; in Product Builder stores distribution definitions 
&lt;ul&gt;
&lt;li&gt;
We should keep a log of distributed data 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Production TRN distribution: &lt;strong&gt;D*.trn&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;
With general distribution, don't have to worry about missing file loads&lt;/li&gt;
&lt;li&gt;
Drawer allows recreation of a TRN 
&lt;ul&gt;
&lt;li&gt;
Unless filings have been shredded&lt;/li&gt;
&lt;li&gt;
Or dates changed - GETADDR error&lt;/li&gt;
&lt;li&gt;
Also, it creates a new sequence number (to allow rbdload to load the file) 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Owner-sharer relationships can be tricky 
&lt;ul&gt;
&lt;li&gt;
Don't want owner distributed? Out of luck if sharer used it &amp;amp; gets distributed. 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;v5.0:&lt;/strong&gt; 
&lt;ul&gt;
&lt;li&gt;
Distribution files have changed 
&lt;ul&gt;
&lt;li&gt;
Can run reports on production databases to get build info&lt;/li&gt;
&lt;li&gt;
Adds TRN file sequence/version number to database!&lt;/li&gt;
&lt;li&gt;
We can read the sequence number &amp;amp; output version automatically! 
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Filings shredded in Product Builder but distributed will only be removed by using
RBDelete – loading/reloading will not remove them.&lt;/li&gt;
&lt;li&gt;
Archive utility also exists to pull things off production databases too&lt;/li&gt;
&lt;li&gt;
When dealing with Owner-Sharer relationships, Product Builder actually does duplicate
the data, but it also keeps track of what the relationships WOULD BE 
&lt;ul&gt;
&lt;li&gt;
Sharing data doesn't actually exist in the production DB, it's just relationships
based on OID's&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Shredding may be needed to break sharing relationships (for us this &amp;quot;future&amp;quot;
is when we move to User Filing)&lt;/li&gt;
&lt;li&gt;
Date Changes need to be done after shredding &amp;amp; recreation 
&lt;ul&gt;
&lt;li&gt;
because dates are used in the object mapping (if OID changes)&lt;/li&gt;
&lt;li&gt;
dates are also used to pick filings&lt;/li&gt;
&lt;li&gt;
TRN Loader matches on OID || all other fields&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
If the table structure changes, Originators (owners) need to be put in first&lt;/li&gt;
&lt;li&gt;
Auditing is only done on user filed data 
&lt;ul&gt;
&lt;li&gt;
So we don't have any auditing support now?!&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Recall Distribution must be done after recall &amp;amp; before any future distributions&lt;/li&gt;
&lt;li&gt;
Different regions wont get caught with sequence errors on load (sequence numbers don't
have to be increasing across regions, just within a region)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Interactive Discussion
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
Characteristics of good Ratabase programmer/analyst/whatever (people that work with
Ratabase/Product Builder) 
&lt;ul&gt;
&lt;li&gt;
Team Player: needs to bridge IT &amp;amp; biz users&lt;/li&gt;
&lt;li&gt;
Problem solver&lt;/li&gt;
&lt;li&gt;
Analytical (LM PM VP said the economics majors worked out better than others)&lt;/li&gt;
&lt;li&gt;
Attention to detail!&lt;/li&gt;
&lt;li&gt;
Some use Actuarial to do Ratabase because they make the rate changes anyway (I think
we technically do this, at least if you look at the titles &amp;amp; reporting structures)&lt;/li&gt;
&lt;li&gt;
Some use Consumer Affairs because of their understanding of the regulations and mediation
of dealings with regulators&lt;/li&gt;
&lt;li&gt;
But you don't need a CPCU 
&lt;ul&gt;
&lt;li&gt;
Need to understand the Product though&lt;/li&gt;
&lt;li&gt;
Maybe only really need &lt;em&gt;some&lt;/em&gt; biz knowledgeable users; not everyone needs to
know it to code it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Really&lt;/strong&gt; need people who understand Formulas &amp;amp; Math&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Must play well with others (&amp;quot;Participants are all in Partnerships&amp;quot;)&lt;/li&gt;
&lt;li&gt;
Some projects helped by strong leads/PM&lt;/li&gt;
&lt;li&gt;
Colocating can be very helpful too&lt;/li&gt;
&lt;li&gt;
Can't separate IT &amp;amp; Biz that much; Ratabase is in between both worlds&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Client Product Forum
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
Apparently they have this conference call every quarter to discuss how people feel
about Ratabase&lt;/li&gt;
&lt;li&gt;
Kind of a User Group for Ratabase&lt;/li&gt;
&lt;li&gt;
Gives CGI feedback for future plans/support options&lt;/li&gt;
&lt;li&gt;
v.5.0: Need to upgrade from v.4.2&lt;/li&gt;
&lt;li&gt;
v.5.01: Need to upgrade from v.5.0 
&lt;ul&gt;
&lt;li&gt;
Better Testing&lt;/li&gt;
&lt;li&gt;
Added XML API&lt;/li&gt;
&lt;li&gt;
Allows arbitrary NoMatch entries (indices in Item blocks don't need to be pre-allocated)&lt;/li&gt;
&lt;li&gt;
FTP into site to get the Full distro (direct from v.4.2 to v.5.01)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
v.6.0 is in progress 
&lt;ul&gt;
&lt;li&gt;
.NET native app!&lt;/li&gt;
&lt;li&gt;
can now sort columns of data by &lt;em&gt;clicking on the column&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;
Filing groups&lt;/li&gt;
&lt;li&gt;
Can now view formulas graphically (WPF maybe?)&lt;/li&gt;
&lt;li&gt;
Will be able to re-rate within calls (so we could conceivably do 1 call with multiple
passes)&lt;/li&gt;
&lt;li&gt;
XML data API expanded to encompass Data Validation&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Listening to what other people say, it sounds like a lot of companies have bad practices: 
&lt;ul&gt;
&lt;li&gt;
Passing data through Ratabase&lt;/li&gt;
&lt;li&gt;
Not tracking changes&lt;/li&gt;
&lt;li&gt;
Making Ratabase take on roles it wasn't designed for: 
&lt;ul&gt;
&lt;li&gt;
workflow&lt;/li&gt;
&lt;li&gt;
rules&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Why would one have thousands &amp;amp; thousands of tables!?&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;
Maybe we should adopt a naming practice for input fields 
&lt;ul&gt;
&lt;li&gt;
Assuming they're actually different than the ones marked as Input in the database
(no, you aren't supposed to be mucking around inside the database to figure things
out...)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
Liberty Mutual Personal Markets needs &amp;gt;15 digit numbers (trillions)&lt;/li&gt;
&lt;li&gt;
XML test cases for testing tool might be good&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="font-size:smaller;color:#7f7f7f"&gt;
Now playing: Veda Hille – the riot life – lucklucky
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=fc4c42eb-05d5-466d-ac01-7cee0c10c2df" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,fc4c42eb-05d5-466d-ac01-7cee0c10c2df.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=9022fda0-cb27-45f8-88d3-a4a1f48e87c1</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,9022fda0-cb27-45f8-88d3-a4a1f48e87c1.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,9022fda0-cb27-45f8-88d3-a4a1f48e87c1.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=9022fda0-cb27-45f8-88d3-a4a1f48e87c1</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
I'd forgotten my SD card reader doesn't handle SDHC cards. So I have to copy the all
off my USB camera connection (thank you Ryan for that Belkin traveler's cable kit!).
Fortunately, that doesn't take that long if I put the files locally instead of uploading
them through a 100Kbps connection back to my file servers.
</p>
          <p>
Not much happened today except for checking into the room and picking up my name badge.
Didn't stay long at the reception (didn't know anyone there, so it was <em>a little</em> awkward).
Ended up driving out to the Tucson Airport just to get away &amp; relax/calm down
a bit. Plus, now I know how to get there if I need to take people when everyone leaves
on Wednesday.
</p>
          <p>
Anyway, to make up for the lack of real progress, there are pictures!
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0334.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Saguaro Lake" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0334_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Saguaro Lake (west end, looking east: NF-206 off N Bush Hwy (according to my map))
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0337.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Grandpa, grandma, &amp; me" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0337_thumb.jpg" width="364px" height="484px" />
            </a>
          </p>
          <p>
Grandpa (Bertil Peterson), Grandma (Joyce Peterson), &amp; Me (Jeffrey Stults, Jr.)
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0340.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Superstition Mountain" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0340_thumb.jpg" width="644px" height="364px" />
            </a>
          </p>
          <p>
Superstition Mountain (from US 60)
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0362.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Catalina Mountains?" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0362_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Catalina Mountains (I think), viewed from the north-ish on Arizona 77/79.
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0366.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Creek/river in Catalina State Park, AZ" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0366_thumb.jpg" width="364px" height="484px" />
            </a>
          </p>
          <p>
Some creek/river in Catalina State Park. Unfortunately, even the park map I got <em>at
the park</em> fails to mention what its name is.
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0380.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Romero Canyon floor" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0380_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
The same hydrological feature in Catalina Start Park. Only this time, from inside
Romero Canyon.
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0384.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Romero Canyon floor" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0384_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
And once again with the water...I mean, it is the desert after all, so water like
this is kind of rare. Looking up the "canyon" in this shot.
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0376.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Hills at Catalina State Park" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0376_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Hills/mountains at Catalina State Park. Apparently, there are trails if one wished
to hike all the way up to the top.
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0377.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Looking out across the Arizona desert" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0377_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Arizona desert (Catalina State Park again).
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0385.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Hill/mountain at Catalina State Park" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0385_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
Looking the other direction from the view out across the desert yields a site like
above.
</p>
          <p>
And some obligatory cactus photos:
</p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0367.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Barrel Cactus" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0367_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0368.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Prickly Pear Cactus" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0368_thumb.jpg" width="644px" height="484px" />
            </a>
          </p>
          <p>
            <a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0388.jpg">
              <img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border="0" alt="Saguaro Cactus" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0388_thumb.jpg" width="364px" height="484px" />
            </a>
          </p>
          <p style="font-size:smaller;color:#7f7f7f">
Now playing: Josh Ritter – The Animal Years – 09 Best for the Best
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9022fda0-cb27-45f8-88d3-a4a1f48e87c1" />
      </body>
      <title>CGI Alliance 2008 Conference Live Blog: Day 0</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,9022fda0-cb27-45f8-88d3-a4a1f48e87c1.aspx</guid>
      <link>http://www.ntldr.com/2008/03/30/CGIAlliance2008ConferenceLiveBlogDay0.aspx</link>
      <pubDate>Sun, 30 Mar 2008 23:59:51 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
I'd forgotten my SD card reader doesn't handle SDHC cards. So I have to copy the all
off my USB camera connection (thank you Ryan for that Belkin traveler's cable kit!).
Fortunately, that doesn't take that long if I put the files locally instead of uploading
them through a 100Kbps connection back to my file servers.
&lt;/p&gt;
&lt;p&gt;
Not much happened today except for checking into the room and picking up my name badge.
Didn't stay long at the reception (didn't know anyone there, so it was &lt;em&gt;a little&lt;/em&gt; awkward).
Ended up driving out to the Tucson Airport just to get away &amp;amp; relax/calm down
a bit. Plus, now I know how to get there if I need to take people when everyone leaves
on Wednesday.
&lt;/p&gt;
&lt;p&gt;
Anyway, to make up for the lack of real progress, there are pictures!
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0334.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Saguaro Lake" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0334_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Saguaro Lake (west end, looking east: NF-206 off N Bush Hwy (according to my map))
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0337.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Grandpa, grandma, &amp;amp; me" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0337_thumb.jpg" width="364px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Grandpa (Bertil Peterson), Grandma (Joyce Peterson), &amp;amp; Me (Jeffrey Stults, Jr.)
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0340.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Superstition Mountain" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0340_thumb.jpg" width="644px" height="364px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Superstition Mountain (from US 60)
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0362.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Catalina Mountains?" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0362_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Catalina Mountains (I think), viewed from the north-ish on Arizona 77/79.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0366.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Creek/river in Catalina State Park, AZ" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0366_thumb.jpg" width="364px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Some creek/river in Catalina State Park. Unfortunately, even the park map I got &lt;em&gt;at
the park&lt;/em&gt; fails to mention what its name is.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0380.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Romero Canyon floor" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0380_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
The same hydrological feature in Catalina Start Park. Only this time, from inside
Romero Canyon.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0384.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Romero Canyon floor" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0384_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
And once again with the water...I mean, it is the desert after all, so water like
this is kind of rare. Looking up the &amp;quot;canyon&amp;quot; in this shot.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0376.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Hills at Catalina State Park" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0376_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Hills/mountains at Catalina State Park. Apparently, there are trails if one wished
to hike all the way up to the top.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0377.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Looking out across the Arizona desert" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0377_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Arizona desert (Catalina State Park again).
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0385.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Hill/mountain at Catalina State Park" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0385_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Looking the other direction from the view out across the desert yields a site like
above.
&lt;/p&gt;
&lt;p&gt;
And some obligatory cactus photos:
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0367.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Barrel Cactus" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0367_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0368.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Prickly Pear Cactus" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0368_thumb.jpg" width="644px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0388.jpg"&gt;&lt;img style="border-top-width:0px;border-left-width:0px;border-bottom-width:0px;border-right-width:0px" border=0 alt="Saguaro Cactus" src="/Attachments/9022fda0-cb27-45f8-88d3-a4a1f48e87c1/IMG_0388_thumb.jpg" width="364px" height="484px"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p style="font-size:smaller;color:#7f7f7f"&gt;
Now playing: Josh Ritter – The Animal Years – 09 Best for the Best
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9022fda0-cb27-45f8-88d3-a4a1f48e87c1" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,9022fda0-cb27-45f8-88d3-a4a1f48e87c1.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=683644c8-b2be-443b-a6a8-3c42fad3b62a</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,683644c8-b2be-443b-a6a8-3c42fad3b62a.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,683644c8-b2be-443b-a6a8-3c42fad3b62a.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=683644c8-b2be-443b-a6a8-3c42fad3b62a</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <h3>9:45 : 
</h3>
          <p>
Finally made it through security at PDX. That has to be the longest it's taken me
to get through security here at PDX. It was shorter at Christmas &amp; Thanksgiving
even! Maybe it's just the flight time...
</p>
          <p>
Currently looks like the flight is on time, and everything has been confirmed. So,
all set to take off! (well, except the airplane isn't here yet, and isn't supposed
to be here for another hour and a half)
</p>
          <p>
Bit of background for those not-in-the-know: CGI makes software products for insurance
companies (they do other things too), specifically a product called <a>Ratabase</a>.
We use it at work to do, well, worker's compensation insurance rating. CGI is having
a conference on their rating &amp; other products in Tucson, AZ from March 30 - April
2. And I'm going to be there.
</p>
          <p>
But first I'm flying into Phoenix and visiting my grandparents in Apache Junction.
Which should now happen in ~1.5 hours.
</p>
          <h3>6:00 :
</h3>
          <p>
Plane landed fine, took wrong shuttle to rental cars &amp; ended up in the west parking
lot. Took shuttle back to terminal, got on correct shuttle to rental cars. Got rental
car, got talked into taking a full size car (hopefully that wont cause any problems
on the expense reporting). Picked a 2009 Nissan Altima because, well, it was brand
new. And I think the car looks good. After having driven it, don't really care for
it too much. I mean, it's not a terrible car, but I think there are definitely better
cars in its class available. Or at least, there were available 9 years ago when my
Stratus came out ;).
</p>
          <p>
Got to my grandparent's trailer in Apache Junction &amp; have had fun just hanging
out with them.
</p>
          <p>
(note: not actually posted at 4:00 Saturday because of no Internet connection).
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=683644c8-b2be-443b-a6a8-3c42fad3b62a" />
      </body>
      <title>CGI Alliance 2008 Conference Live Blog: Day -1</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,683644c8-b2be-443b-a6a8-3c42fad3b62a.aspx</guid>
      <link>http://www.ntldr.com/2008/03/29/CGIAlliance2008ConferenceLiveBlogDay1.aspx</link>
      <pubDate>Sat, 29 Mar 2008 17:08:04 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;h3&gt;9:45 : 
&lt;/h3&gt;
&lt;p&gt;
Finally made it through security at PDX. That has to be the longest it's taken me
to get through security here at PDX. It was shorter at Christmas &amp;amp; Thanksgiving
even! Maybe it's just the flight time...
&lt;/p&gt;
&lt;p&gt;
Currently looks like the flight is on time, and everything has been confirmed. So,
all set to take off! (well, except the airplane isn't here yet, and isn't supposed
to be here for another hour and a half)
&lt;/p&gt;
&lt;p&gt;
Bit of background for those not-in-the-know: CGI makes software products for insurance
companies (they do other things too), specifically a product called &lt;a&gt;Ratabase&lt;/a&gt;.
We use it at work to do, well, worker's compensation insurance rating. CGI is having
a conference on their rating &amp;amp; other products in Tucson, AZ from March 30 - April
2. And I'm going to be there.
&lt;/p&gt;
&lt;p&gt;
But first I'm flying into Phoenix and visiting my grandparents in Apache Junction.
Which should now happen in ~1.5 hours.
&lt;/p&gt;
&lt;h3&gt;6:00 :
&lt;/h3&gt;
&lt;p&gt;
Plane landed fine, took wrong shuttle to rental cars &amp;amp; ended up in the west parking
lot. Took shuttle back to terminal, got on correct shuttle to rental cars. Got rental
car, got talked into taking a full size car (hopefully that wont cause any problems
on the expense reporting). Picked a 2009 Nissan Altima because, well, it was brand
new. And I think the car looks good. After having driven it, don't really care for
it too much. I mean, it's not a terrible car, but I think there are definitely better
cars in its class available. Or at least, there were available 9 years ago when my
Stratus came out ;).
&lt;/p&gt;
&lt;p&gt;
Got to my grandparent's trailer in Apache Junction &amp;amp; have had fun just hanging
out with them.
&lt;/p&gt;
&lt;p&gt;
(note: not actually posted at 4:00 Saturday because of no Internet connection).
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=683644c8-b2be-443b-a6a8-3c42fad3b62a" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,683644c8-b2be-443b-a6a8-3c42fad3b62a.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
Sorry for a bit more downtime (well, 13 minutes to be more precise). Switched the
site over to the release version of Windows Server 2008 (Windows Web Server 2008 x86).
</p>
          <p>
Overall, pretty painless...just install Windows, install the Web Server role, enable
a bunch of Role Services, then add a few Features (like Windows PowerShell). Finally,
install Windows SharePoint Services 3.0 SP1 &amp; do a minimal amount of configuration
using the Central Admin tool. Create a dummy site, then go over to the existing standalone
server, change my internal DNS settings, kick off the site backup, and then kick off
the site restore on the new server. By the time the DNS changes had replicated, everything
was done.
</p>
          <p>
Except I forgot the HTTP SPN again, and so had to set that and change the ISA configuration
to point to sharepoint4 instead of sharepoint3. Oh, and I fixed the SSL stuff, so <a href="https://www.ntldr.com/">https://www.ntldr.com/</a> will
now work (assuming you've installed &amp; trust my root CA).
</p>
          <p style="color:#7f7f7f;font-size:smaller">
Now playing: Pete Samples – Yours Makes Mine – 04 Between Exhales
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd" />
      </body>
      <title>Uptime</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd.aspx</guid>
      <link>http://www.ntldr.com/2008/02/07/Uptime.aspx</link>
      <pubDate>Thu, 07 Feb 2008 07:30:10 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
Sorry for a bit more downtime (well, 13 minutes to be more precise). Switched the
site over to the release version of Windows Server 2008 (Windows Web Server 2008 x86).
&lt;/p&gt;
&lt;p&gt;
Overall, pretty painless...just install Windows, install the Web Server role, enable
a bunch of Role Services, then add a few Features (like Windows PowerShell). Finally,
install Windows SharePoint Services 3.0 SP1 &amp;amp; do a minimal amount of configuration
using the Central Admin tool. Create a dummy site, then go over to the existing standalone
server, change my internal DNS settings, kick off the site backup, and then kick off
the site restore on the new server. By the time the DNS changes had replicated, everything
was done.
&lt;/p&gt;
&lt;p&gt;
Except I forgot the HTTP SPN again, and so had to set that and change the ISA configuration
to point to sharepoint4 instead of sharepoint3. Oh, and I fixed the SSL stuff, so &lt;a href="https://www.ntldr.com/"&gt;https://www.ntldr.com/&lt;/a&gt; will
now work (assuming you've installed &amp;amp; trust my root CA).
&lt;/p&gt;
&lt;p style="color:#7f7f7f;font-size:smaller"&gt;
Now playing: Pete Samples – Yours Makes Mine – 04 Between Exhales
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,d0dca86a-b3b3-426d-bb8e-8a3ecee07bbd.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=20e10b43-57e4-422e-951c-0d4d2ad5c6a7</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,20e10b43-57e4-422e-951c-0d4d2ad5c6a7.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,20e10b43-57e4-422e-951c-0d4d2ad5c6a7.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=20e10b43-57e4-422e-951c-0d4d2ad5c6a7</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
Some amusing links… (at least, I found them amusing, even though I don't use Ruby.)
In particular, I liked the Java one, especially since I was dealing with a Spring
idiosyncrasy at the time my PM pointed me to these… 
</p>
          <p>
            <a href="http://www.railsenvy.com/2007/5/14/ruby-on-rails-commercial">Rails vs. Java</a>
          </p>
          <p>
            <a href="http://www.railsenvy.com/2007/5/15/hi-i-m-ruby-on-rails-part-2">Rails vs.
PHP</a>
          </p>
          <p>
            <a href="http://www.railsenvy.com/2007/5/16/hi-i-m-ruby-on-rails-part-3">Rails vs.
PHP</a>
          </p>
          <p>
            <a href="http://www.railsenvy.com/2007/5/21/hi-i-m-ruby-on-rails-part-4">Rails vs.
PHP</a>
          </p>
          <p>
            <a href="http://www.railsenvy.com/2007/8/23/Rails-vs-NET">Rails vs. .NET</a>
          </p>
          <p style="font-size:smaller;color:#7f7f7f">
Now playing: Terra Naomi – Say It's Possible (Single) – Say It's Possible
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=20e10b43-57e4-422e-951c-0d4d2ad5c6a7" />
      </body>
      <title>Ruby on Rails Humour</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,20e10b43-57e4-422e-951c-0d4d2ad5c6a7.aspx</guid>
      <link>http://www.ntldr.com/2007/09/05/RubyOnRailsHumour.aspx</link>
      <pubDate>Wed, 05 Sep 2007 00:46:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
Some amusing links… (at least, I found them amusing, even though I don't use Ruby.)
In particular, I liked the Java one, especially since I was dealing with a Spring
idiosyncrasy at the time my PM pointed me to these… 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.railsenvy.com/2007/5/14/ruby-on-rails-commercial"&gt;Rails vs. Java&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.railsenvy.com/2007/5/15/hi-i-m-ruby-on-rails-part-2"&gt;Rails vs.
PHP&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.railsenvy.com/2007/5/16/hi-i-m-ruby-on-rails-part-3"&gt;Rails vs.
PHP&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.railsenvy.com/2007/5/21/hi-i-m-ruby-on-rails-part-4"&gt;Rails vs.
PHP&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.railsenvy.com/2007/8/23/Rails-vs-NET"&gt;Rails vs. .NET&lt;/a&gt;
&lt;/p&gt;
&lt;p style="font-size:smaller;color:#7f7f7f"&gt;
Now playing: Terra Naomi – Say It's Possible (Single) – Say It's Possible
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=20e10b43-57e4-422e-951c-0d4d2ad5c6a7" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,20e10b43-57e4-422e-951c-0d4d2ad5c6a7.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=9979a879-7370-4b73-96f9-5a82744ed4e9</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,9979a879-7370-4b73-96f9-5a82744ed4e9.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,9979a879-7370-4b73-96f9-5a82744ed4e9.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=9979a879-7370-4b73-96f9-5a82744ed4e9</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
For some reason I can never actually find these sites when I need them, and that always
happens when I'm away from one of my computers. So here's a few links so that I can
actually find this stuff when I need it.
</p>
          <p>
            <a href="http://support.microsoft.com/default.aspx/kb/917021">KB917021: Description
of the Wireless Client Update for Windows XP with Service Pack 2</a>: Support article
pointing to the hotfix needed to add WPA2 support to Windows XP (I sometimes support
XP people (still), despite my vowing not to as soon as I switched over to Vista, okay?).
</p>
          <p>
            <a href="http://troels.arvin.dk/db/rdbms/">Comparison of different SQL implementations</a>:
REALLY useful article comparing SQL with PostgreSQL, DB2, SQL Server, MySQL, and Oracle
implementations. I find it mostly useful for figuring out the differences between
implementations so that I can get a basic operation to work on DB2 or Oracle (I'm
most familiar with SQL Server).
</p>
          <p>
            <a href="http://asktom.oracle.com/tkyte/ResultSets/index.html">Result Sets from Stored
Procedures In Oracle</a>: For some reason I can NEVER remember how to return query
results from SPROC's on Oracle. Go figure.
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9979a879-7370-4b73-96f9-5a82744ed4e9" />
      </body>
      <title>Some web links</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,9979a879-7370-4b73-96f9-5a82744ed4e9.aspx</guid>
      <link>http://www.ntldr.com/2007/08/01/SomeWebLinks.aspx</link>
      <pubDate>Wed, 01 Aug 2007 04:36:18 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
For some reason I can never actually find these sites when I need them, and that always
happens when I'm away from one of my computers. So here's a few links so that I can
actually find this stuff when I need it.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://support.microsoft.com/default.aspx/kb/917021"&gt;KB917021: Description
of the Wireless Client Update for Windows XP with Service Pack 2&lt;/a&gt;: Support article
pointing to the hotfix needed to add WPA2 support to Windows XP (I sometimes support
XP people (still), despite my vowing not to as soon as I switched over to Vista, okay?).
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://troels.arvin.dk/db/rdbms/"&gt;Comparison of different SQL implementations&lt;/a&gt;:
REALLY useful article comparing SQL with PostgreSQL, DB2, SQL Server, MySQL, and Oracle
implementations. I find it mostly useful for figuring out the differences between
implementations so that I can get a basic operation to work on DB2 or Oracle (I'm
most familiar with SQL Server).
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://asktom.oracle.com/tkyte/ResultSets/index.html"&gt;Result Sets from Stored
Procedures In Oracle&lt;/a&gt;: For some reason I can NEVER remember how to return query
results from SPROC's on Oracle. Go figure.
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9979a879-7370-4b73-96f9-5a82744ed4e9" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,9979a879-7370-4b73-96f9-5a82744ed4e9.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=2114d93f-7d2f-4ff3-af48-5e73c57da506</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,2114d93f-7d2f-4ff3-af48-5e73c57da506.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,2114d93f-7d2f-4ff3-af48-5e73c57da506.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=2114d93f-7d2f-4ff3-af48-5e73c57da506</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
Well, I think of it as old news by now, but apparently most of the people I know weren't
paying much attention to it, so here's a link to <a href="http://www.microsoft.com/surface">Microsoft
Surface</a>. Go check it out; it's seriously cool and neat and probably way too expensive
for me to even consider getting.
</p>
          <p>
New beta versions of <a href="http://get.live.com/betas/maildesktop_betas">Windows
Live Mail</a>, <a href="http://get.live.com/betas/messenger_betas">Windows Live Messenger</a>,
and <a href="http://get.live.com/betas/writer_betas">Windows Live Writer</a> were
released this week. This post has actually been written using WLW, so we'll see if
it actually shows up on the site... So far I like all the products, but don't really
notice any big functional advances in the WLM and WLM products (okay, so now I guess
I wont be able to refer to Windows Live Messenger as "WLM" anymore). WLW
added SharePoint support, and overall seems to be a bit nicer than using Word 2007
to blog with.
</p>
          <p>
I finally got the new <a href="http://usa.asus.com/products.aspx?l1=2&amp;l2=6&amp;l3=514&amp;l4=0&amp;model=1642&amp;modelmenu=1">video
card</a> yesterday. It's passively cooled, so no annoying fan noise, but it screwed
up airflow in the case. The temperatures here in Portland have been rather warm lately,
so heat + no more airflow = components overheating. Which meant I had to plug the
case fan back in, thus making the computer noisy again. It's still quieter than the
system + old video card were, and I've got DirectX 10 support now (even if the GeForce
8600GT is slower than the previous generation 7600GT I had in there before), so I'm
calling it a win.
</p>
          <p>
Just two more days until I start my new job...time to start getting nervous!
</p>
          <p>
            <a href="/Attachments/2114d93f-7d2f-4ff3-af48-5e73c57da506/IMG_1292p.jpg">
              <img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height="480px" alt="Mount St. Helens" src="/Attachments/2114d93f-7d2f-4ff3-af48-5e73c57da506/IMG_1292p_thumb.jpg" width="480px" border="0" />
            </a>
          </p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=2114d93f-7d2f-4ff3-af48-5e73c57da506" />
      </body>
      <title>Cool stuff this week</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,2114d93f-7d2f-4ff3-af48-5e73c57da506.aspx</guid>
      <link>http://www.ntldr.com/2007/06/01/CoolStuffThisWeek.aspx</link>
      <pubDate>Fri, 01 Jun 2007 22:23:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
Well, I think of it as old news by now, but apparently most of the people I know weren't
paying much attention to it, so here's a link to &lt;a href="http://www.microsoft.com/surface"&gt;Microsoft
Surface&lt;/a&gt;. Go check it out; it's seriously cool and neat and probably way too expensive
for me to even consider getting.
&lt;/p&gt;
&lt;p&gt;
New beta versions of &lt;a href="http://get.live.com/betas/maildesktop_betas"&gt;Windows
Live Mail&lt;/a&gt;, &lt;a href="http://get.live.com/betas/messenger_betas"&gt;Windows Live Messenger&lt;/a&gt;,
and &lt;a href="http://get.live.com/betas/writer_betas"&gt;Windows Live Writer&lt;/a&gt; were
released this week. This post has actually been written using WLW, so we'll see if
it actually shows up on the site... So far I like all the products, but don't really
notice any big functional advances in the WLM and WLM products (okay, so now I guess
I wont be able to refer to Windows Live Messenger as &amp;quot;WLM&amp;quot; anymore). WLW
added SharePoint support, and overall seems to be a bit nicer than using Word 2007
to blog with.
&lt;/p&gt;
&lt;p&gt;
I finally got the new &lt;a href="http://usa.asus.com/products.aspx?l1=2&amp;amp;l2=6&amp;amp;l3=514&amp;amp;l4=0&amp;amp;model=1642&amp;amp;modelmenu=1"&gt;video
card&lt;/a&gt; yesterday. It's passively cooled, so no annoying fan noise, but it screwed
up airflow in the case. The temperatures here in Portland have been rather warm lately,
so heat + no more airflow = components overheating. Which meant I had to plug the
case fan back in, thus making the computer noisy again. It's still quieter than the
system + old video card were, and I've got DirectX 10 support now (even if the GeForce
8600GT is slower than the previous generation 7600GT I had in there before), so I'm
calling it a win.
&lt;/p&gt;
&lt;p&gt;
Just two more days until I start my new job...time to start getting nervous!
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/2114d93f-7d2f-4ff3-af48-5e73c57da506/IMG_1292p.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height="480px" alt="Mount St. Helens" src="/Attachments/2114d93f-7d2f-4ff3-af48-5e73c57da506/IMG_1292p_thumb.jpg" width="480px" border="0"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=2114d93f-7d2f-4ff3-af48-5e73c57da506" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,2114d93f-7d2f-4ff3-af48-5e73c57da506.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=25990a62-e9d5-41d4-bd82-7d6791ee6ef3</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,25990a62-e9d5-41d4-bd82-7d6791ee6ef3.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,25990a62-e9d5-41d4-bd82-7d6791ee6ef3.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=25990a62-e9d5-41d4-bd82-7d6791ee6ef3</wfw:commentRss>
      <slash:comments>2</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
Tonight I installed Windows Vista Business Edition on my HP Compaq TC1000. I was surprised
at how good the install went; it didn't really take that much time at all (45 minutes
or so). The only difficult part of the whole process was getting the FinePoint digitizer
drivers installed. And the performance isn't that good (although it has been getting
better in the last few hours). 
</p>
          <p>
            <font color="#ff0000">Update 2007-02-23: It looks like this isn't really a permanent
way to get the digitizer working, since there's been a report of the procedure not
working for someone else, and it appears that even when it does work, it breaks after
a few reboots.</font>
          </p>
          <p>
So, to get the digitizer to work: 1) I can only seem to get it to work with the Standard
VGA Driver. 2) I have no idea if this works as a long term solution (for example,
changing display drivers seems to break it). 
</p>
          <ol>
            <li>
Download the FinePoint generic FPI2004 driver for Windows Vista (available from Gateway
as the driver for the digitizer in the CX210's). 
</li>
            <li>
Extract the install files (the Gateway driver was a self extracting zip file that
took care of this). 
</li>
            <li>
Start up Device Manager and identify the FinePoint digitizer. For me the PNP device
ID was "ACPI\FPI2002". 
</li>
            <li>
Force the generic driver for the newer digitizer to install, then reboot. 
</li>
            <li>
At this point the digitizer should be all screwed up. Download the digitizer driver
from HP. 
</li>
            <li>
Try and run the HP driver setup program. For me it failed, but got the drivers extracted.
Using the Windows XP SP2 compatibility mode should help. 
</li>
            <li>
After it fails, find the extracted files (should be C:\Compaq\FinePoint by default).
Run the setup.exe program that's there in Windows XP SP2 compatibility mode. 
</li>
            <li>
Press the install button that comes up. After a bit, that should fail with a "Service
could not start" error. 
</li>
            <li>
Reboot, and the digitizer should now work. It probably really needs to be calibrated
though. 
</li>
          </ol>
          <p>
The buttons were easier: I just grabbed the TC1100 button driver, extracted that,
then manually installed the drivers using Device Manager. I've heard there are problems
using the wireless, but for me that wasn't an issue because I've replaced the original
wireless with an Intel 2200BG card (built-in drivers! Yay!). The last thing I need
to get working is Rotation support, but everything I've tried either doesn't work
or breaks the digitizer hack <span style="font-family:Wingdings">L</span>.
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=25990a62-e9d5-41d4-bd82-7d6791ee6ef3" />
      </body>
      <title>HP TC1000 and Windows Vista</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,25990a62-e9d5-41d4-bd82-7d6791ee6ef3.aspx</guid>
      <link>http://www.ntldr.com/2007/02/11/HPTC1000AndWindowsVista.aspx</link>
      <pubDate>Sun, 11 Feb 2007 05:56:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
Tonight I installed Windows Vista Business Edition on my HP Compaq TC1000. I was surprised
at how good the install went; it didn't really take that much time at all (45 minutes
or so). The only difficult part of the whole process was getting the FinePoint digitizer
drivers installed. And the performance isn't that good (although it has been getting
better in the last few hours). 
&lt;/p&gt;
&lt;p&gt;
&lt;font color="#ff0000"&gt;Update 2007-02-23: It looks like this isn't really a permanent
way to get the digitizer working, since there's been a report of the procedure not
working for someone else, and it appears that even when it does work, it breaks after
a few reboots.&lt;/font&gt;
&lt;/p&gt;
&lt;p&gt;
So, to get the digitizer to work: 1) I can only seem to get it to work with the Standard
VGA Driver. 2) I have no idea if this works as a long term solution (for example,
changing display drivers seems to break it). 
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
Download the FinePoint generic FPI2004 driver for Windows Vista (available from Gateway
as the driver for the digitizer in the CX210's). 
&lt;/li&gt;
&lt;li&gt;
Extract the install files (the Gateway driver was a self extracting zip file that
took care of this). 
&lt;/li&gt;
&lt;li&gt;
Start up Device Manager and identify the FinePoint digitizer. For me the PNP device
ID was &amp;quot;ACPI\FPI2002&amp;quot;. 
&lt;/li&gt;
&lt;li&gt;
Force the generic driver for the newer digitizer to install, then reboot. 
&lt;/li&gt;
&lt;li&gt;
At this point the digitizer should be all screwed up. Download the digitizer driver
from HP. 
&lt;/li&gt;
&lt;li&gt;
Try and run the HP driver setup program. For me it failed, but got the drivers extracted.
Using the Windows XP SP2 compatibility mode should help. 
&lt;/li&gt;
&lt;li&gt;
After it fails, find the extracted files (should be C:\Compaq\FinePoint by default).
Run the setup.exe program that's there in Windows XP SP2 compatibility mode. 
&lt;/li&gt;
&lt;li&gt;
Press the install button that comes up. After a bit, that should fail with a &amp;quot;Service
could not start&amp;quot; error. 
&lt;/li&gt;
&lt;li&gt;
Reboot, and the digitizer should now work. It probably really needs to be calibrated
though. 
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
The buttons were easier: I just grabbed the TC1100 button driver, extracted that,
then manually installed the drivers using Device Manager. I've heard there are problems
using the wireless, but for me that wasn't an issue because I've replaced the original
wireless with an Intel 2200BG card (built-in drivers! Yay!). The last thing I need
to get working is Rotation support, but everything I've tried either doesn't work
or breaks the digitizer hack &lt;span style="font-family:Wingdings"&gt;L&lt;/span&gt;.
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=25990a62-e9d5-41d4-bd82-7d6791ee6ef3" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,25990a62-e9d5-41d4-bd82-7d6791ee6ef3.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=59e296d5-2854-4b2b-accb-9507ac6119f1</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,59e296d5-2854-4b2b-accb-9507ac6119f1.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,59e296d5-2854-4b2b-accb-9507ac6119f1.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=59e296d5-2854-4b2b-accb-9507ac6119f1</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Windows PowerShell is finally available for Windows Vista! Go grab it at <a href="http://support.microsoft.com/?kbid=928439">http://support.microsoft.com/?kbid=928439</a>.
</div>
          <div>
          </div>
          <div>I think I've begun to overuse it though... Today I ran into the problem of "how
do you spell that name again?" while trying to write an email. The obvious things
of "use the address book" and "remember it you idiot!" failed,
and the outlook for successful addressing of the message was bleak. But then I remembered
my trusty PSH! It was so simple!
</div>
          <div>
          </div>
          <div style="font-size: Consolas;">get-adusers | where-object {$_.sn -match ".*jack.*"}
| select-object givenName,distinguishedName
</div>
          <div>
          </div>
          <div>Gotta love PSH... (of course, it helped that I had the <span style="font-size: Consolas;">get-adusers</span> function,
which I wrote a while ago and have stashed in my profile).
</div>
          <div>
          </div>
          <div>Oh, and for those that are interested, the here's <span style="font-size: Consolas;">get-adusers</span> (along
with a few other AD functions that are very similar):
</div>
          <div>
          </div>
          <div style="font-size: Consolas;">function global:get-adusers<br />
{<br />
param( [string] $domain = (get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain
)<br /><br />
return (get-adobject -domain $domain -filter '(&amp;(objectClass=user)(!(objectClass=computer)))')<br />
}
</div>
          <div style="font-size: Consolas;">function global:get-adcomputers<br />
{<br />
param( [string] $domain = $((get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain)
)<br /><br />
return (get-adobject -domain $domain -filter '(objectClass=computer)')<br />
}
</div>
          <div style="font-size: Consolas;">function global:get-adprinters<br />
{<br />
param( [string] $domain = $((get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain)
)<br /><br />
return (get-adobject -domain $domain -filter '(objectClass=printQueue)')<br />
}
</div>
          <div style="font-size: Consolas;">function global:get-adobject<br />
{<br />
param( 
<br />
[string] $domain = (get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain,<br />
[string] $filter = '' 
<br />
)<br /><br />
$local:directory = new-object -TypeName 'System.DirectoryServices.DirectorySearcher'
-ArgumentList $domain<br />
$directory.PageSize = 500<br />
$directory.Filter = $filter<br />
$matches = $directory.FindAll()<br /><br />
$local:d = new-object -TypeName 'System.Collections.ArrayList'<br />
foreach($m in $matches)<br />
{<br />
$d.Add($m.GetDirectoryEntry()) | out-null<br />
}<br />
return $d.ToArray()<br />
}
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=59e296d5-2854-4b2b-accb-9507ac6119f1" />
      </body>
      <title>PowerShell</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,59e296d5-2854-4b2b-accb-9507ac6119f1.aspx</guid>
      <link>http://www.ntldr.com/2007/02/01/PowerShell.aspx</link>
      <pubDate>Thu, 01 Feb 2007 18:00:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Windows PowerShell is finally available for Windows Vista! Go grab it at &lt;a href="http://support.microsoft.com/?kbid=928439"&gt;http://support.microsoft.com/?kbid=928439&lt;/a&gt;.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;I think I've begun to overuse it though... Today I ran into the problem of &amp;quot;how
do you spell that name again?&amp;quot; while trying to write an email. The obvious things
of &amp;quot;use the address book&amp;quot; and &amp;quot;remember it you idiot!&amp;quot; failed,
and the outlook for successful addressing of the message was bleak. But then I remembered
my trusty PSH! It was so simple!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div style="font-size: Consolas;"&gt;get-adusers | where-object {$_.sn -match &amp;quot;.*jack.*&amp;quot;}
| select-object givenName,distinguishedName
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Gotta love PSH... (of course, it helped that I had the &lt;span style="font-size: Consolas;"&gt;get-adusers&lt;/span&gt; function,
which I wrote a while ago and have stashed in my profile).
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Oh, and for those that are interested, the here's &lt;span style="font-size: Consolas;"&gt;get-adusers&lt;/span&gt; (along
with a few other AD functions that are very similar):
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div style="font-size: Consolas;"&gt;function global:get-adusers&lt;br /&gt;
{&lt;br /&gt;
param( [string] $domain = (get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain
)&lt;br /&gt;
&lt;br /&gt;
return (get-adobject -domain $domain -filter '(&amp;amp;(objectClass=user)(!(objectClass=computer)))')&lt;br /&gt;
}
&lt;/div&gt;
&lt;div style="font-size: Consolas;"&gt;function global:get-adcomputers&lt;br /&gt;
{&lt;br /&gt;
param( [string] $domain = $((get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain)
)&lt;br /&gt;
&lt;br /&gt;
return (get-adobject -domain $domain -filter '(objectClass=computer)')&lt;br /&gt;
}
&lt;/div&gt;
&lt;div style="font-size: Consolas;"&gt;function global:get-adprinters&lt;br /&gt;
{&lt;br /&gt;
param( [string] $domain = $((get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain)
)&lt;br /&gt;
&lt;br /&gt;
return (get-adobject -domain $domain -filter '(objectClass=printQueue)')&lt;br /&gt;
}
&lt;/div&gt;
&lt;div style="font-size: Consolas;"&gt;function global:get-adobject&lt;br /&gt;
{&lt;br /&gt;
param( 
&lt;br /&gt;
[string] $domain = (get-wmiobject -namespace 'root\CIMV2' -class 'Win32_ComputerSystem').Domain,&lt;br /&gt;
[string] $filter = '' 
&lt;br /&gt;
)&lt;br /&gt;
&lt;br /&gt;
$local:directory = new-object -TypeName 'System.DirectoryServices.DirectorySearcher'
-ArgumentList $domain&lt;br /&gt;
$directory.PageSize = 500&lt;br /&gt;
$directory.Filter = $filter&lt;br /&gt;
$matches = $directory.FindAll()&lt;br /&gt;
&lt;br /&gt;
$local:d = new-object -TypeName 'System.Collections.ArrayList'&lt;br /&gt;
foreach($m in $matches)&lt;br /&gt;
{&lt;br /&gt;
$d.Add($m.GetDirectoryEntry()) | out-null&lt;br /&gt;
}&lt;br /&gt;
return $d.ToArray()&lt;br /&gt;
}
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=59e296d5-2854-4b2b-accb-9507ac6119f1" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,59e296d5-2854-4b2b-accb-9507ac6119f1.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=f687e141-0810-49c6-887f-8b5aed153cc1</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,f687e141-0810-49c6-887f-8b5aed153cc1.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,f687e141-0810-49c6-887f-8b5aed153cc1.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=f687e141-0810-49c6-887f-8b5aed153cc1</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <p>
In light of the recent Activation news for the Volume License versions of Vista, and
the news that Windows Vista will stop working if it suspects a licensing violation,
it looks like I probably wont be able to afford Windows Vista. At least, I wont be
able to if I follow my current process of reinstalling every few weeks. Oh well, it's
not like there's that many new features anyway…just updates to the kernel, the new
audio system, new video system, new networking system, the Desktop Window Manager,
full IPv6 support, Aero, search folders, UAC (a feature I LOVE, regardless of what
everyone says), the new Offline Files mechanism (now that it works, unlike all of
the pre-beta 2 builds), more granular power management controls, group policy control
of power settings (!), the Sidebar (fine, I admit it, the ability to have multiple
clocks and the weather constantly off to the side in a nice, subtle manner finally
won me over), updated take on the Media Center interface, pen flicks for Tablet PC's,
Mahjong and Chess as built-in games, the new, learning, recognizers for Ink on Tablet
PC's, and the cleaned up login screen with user icons that work even in domain environments.
Oh, and what really has me won over:
</p>
          <p>
            <a href="/Attachments/f687e141-0810-49c6-887f-8b5aed153cc1/Post104_1.jpg">
              <img src="/Attachments/f687e141-0810-49c6-887f-8b5aed153cc1/100506_0158_Why%20buy%20Win1.png" alt="" border="0" height="410px" width="512px" />
            </a>
          </p>
          <p>
Yes, that is my Windows Vista desktop with sidebar, glass, and <a href="http://www.istartedsomething.com/20061004/lazy-man-desktop-aurora"><strong>animated</strong></a> background.
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=f687e141-0810-49c6-887f-8b5aed153cc1" />
      </body>
      <title>Why buy Windows Vista</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,f687e141-0810-49c6-887f-8b5aed153cc1.aspx</guid>
      <link>http://www.ntldr.com/2006/10/05/WhyBuyWindowsVista.aspx</link>
      <pubDate>Thu, 05 Oct 2006 01:59:27 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;p&gt;
In light of the recent Activation news for the Volume License versions of Vista, and
the news that Windows Vista will stop working if it suspects a licensing violation,
it looks like I probably wont be able to afford Windows Vista. At least, I wont be
able to if I follow my current process of reinstalling every few weeks. Oh well, it's
not like there's that many new features anyway…just updates to the kernel, the new
audio system, new video system, new networking system, the Desktop Window Manager,
full IPv6 support, Aero, search folders, UAC (a feature I LOVE, regardless of what
everyone says), the new Offline Files mechanism (now that it works, unlike all of
the pre-beta 2 builds), more granular power management controls, group policy control
of power settings (!), the Sidebar (fine, I admit it, the ability to have multiple
clocks and the weather constantly off to the side in a nice, subtle manner finally
won me over), updated take on the Media Center interface, pen flicks for Tablet PC's,
Mahjong and Chess as built-in games, the new, learning, recognizers for Ink on Tablet
PC's, and the cleaned up login screen with user icons that work even in domain environments.
Oh, and what really has me won over:
&lt;/p&gt;
&lt;p&gt;
&lt;a href="/Attachments/f687e141-0810-49c6-887f-8b5aed153cc1/Post104_1.jpg"&gt;&lt;img src="/Attachments/f687e141-0810-49c6-887f-8b5aed153cc1/100506_0158_Why%20buy%20Win1.png" alt="" border="0" height="410px" width="512px"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Yes, that is my Windows Vista desktop with sidebar, glass, and &lt;a href="http://www.istartedsomething.com/20061004/lazy-man-desktop-aurora"&gt;&lt;strong&gt;animated&lt;/strong&gt;&lt;/a&gt; background.
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=f687e141-0810-49c6-887f-8b5aed153cc1" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,f687e141-0810-49c6-887f-8b5aed153cc1.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=7877a95a-c9f4-47a3-a109-d9623a685c6a</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,7877a95a-c9f4-47a3-a109-d9623a685c6a.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,7877a95a-c9f4-47a3-a109-d9623a685c6a.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=7877a95a-c9f4-47a3-a109-d9623a685c6a</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Well, it's done for a bit. You can check out <a href="/">www.ntldr.com</a> for
the final results. Cool eh?
</div>
          <div>
          </div>
          <div>Go check it out. NOW!
</div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>
          </div>
          <div>Ok, so maybe you aren't quite as sarcastic as I am: no, you aren't really meant
to see anything there. Because basically, WSS 3.0 isn't a smooth migration path. Sure,
it SEEMS like it will be when the installer first runs...but then things just didn't
work. The current state is actually the BEST I've been able to do so far.
</div>
          <div>
          </div>
          <div>So, I'm going to go back to the drawing board for a while and install a clean
server, put WSS 3.0 on it and poke, prod, slice, dice, hang, bang, and beat on it
until WSS 3.0 gives up every last one of its secrets of operation.
</div>
          <div>
          </div>
          <div>Needless to say, that much torture requires a bit of time as well, so don't expect
too many updates on that front.
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7877a95a-c9f4-47a3-a109-d9623a685c6a" />
      </body>
      <title>WSS 3.0 Status Update</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,7877a95a-c9f4-47a3-a109-d9623a685c6a.aspx</guid>
      <link>http://www.ntldr.com/2006/06/06/WSS30StatusUpdate.aspx</link>
      <pubDate>Tue, 06 Jun 2006 01:45:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Well, it's done for a bit. You can check out &lt;a href="/"&gt;www.ntldr.com&lt;/a&gt; for
the final results. Cool eh?
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Go check it out. NOW!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Ok, so maybe you aren't quite as sarcastic as I am: no, you aren't really meant
to see anything there. Because basically, WSS 3.0 isn't a smooth migration path. Sure,
it SEEMS like it will be when the installer first runs...but then things just didn't
work. The current state is actually the BEST I've been able to do so far.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;So, I'm going to go back to the drawing board for a while and install a clean
server, put WSS 3.0 on it and poke, prod, slice, dice, hang, bang, and beat on it
until WSS 3.0 gives up every last one of its secrets of operation.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Needless to say, that much torture requires a bit of time as well, so don't expect
too many updates on that front.
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7877a95a-c9f4-47a3-a109-d9623a685c6a" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,7877a95a-c9f4-47a3-a109-d9623a685c6a.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=2afd002a-ffa2-457a-88cf-ac47dbfb9f7a</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,2afd002a-ffa2-457a-88cf-ac47dbfb9f7a.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,2afd002a-ffa2-457a-88cf-ac47dbfb9f7a.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=2afd002a-ffa2-457a-88cf-ac47dbfb9f7a</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Today's lesson is How Not To (try and) Flash Your BIOS Using Your Digital Camera
Because You Loaned Your Universal Magic Disk With BIOS Flashing Capabilities To Someone
Who Then Left The Country.
</div>
          <div>
          </div>
          <div>The lesson title is the lesson. End of Field.
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=2afd002a-ffa2-457a-88cf-ac47dbfb9f7a" />
      </body>
      <title>HP tc4200 F.09</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,2afd002a-ffa2-457a-88cf-ac47dbfb9f7a.aspx</guid>
      <link>http://www.ntldr.com/2006/05/24/HPTc4200F09.aspx</link>
      <pubDate>Wed, 24 May 2006 02:25:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Today's lesson is How Not To (try and) Flash Your BIOS Using Your Digital Camera
Because You Loaned Your Universal Magic Disk With BIOS Flashing Capabilities To Someone
Who Then Left The Country.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;The lesson title is the lesson. End of Field.
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=2afd002a-ffa2-457a-88cf-ac47dbfb9f7a" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,2afd002a-ffa2-457a-88cf-ac47dbfb9f7a.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=9f23f500-55c3-4e89-8477-75e068b46616</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,9f23f500-55c3-4e89-8477-75e068b46616.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,9f23f500-55c3-4e89-8477-75e068b46616.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=9f23f500-55c3-4e89-8477-75e068b46616</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>My patience finally outweighed my ignorance of the process, so I got my wireless
working. And now everyone is laughing at me, because all they had to do was run down
to the local electronics store, grab a router, maybe pay for it too (hey, I wont ask
questions about how you got your gear...), and plug it in.
</div>
          <div>
          </div>
          <div>I've put in something like 14 hours getting my new wireless configuration to
work.
</div>
          <div>
          </div>
          <div>As I said, laugh away...because I shall have the last laugh!
</div>
          <div>
          </div>
          <div>Old wireless config:
</div>
          <div>Microsoft MN-500 with a patch cable running from one of the switch ports to the
"WLAN00" NIC in the ISA Server. ISA.WLAN00.IP = 192.168.2.254. AP.IP = 192.168.2.1,
with DHCP server stuff running on the AP, so clients got 192.168.2.x/24. To connect
to the wireless network, all the client had to have was the WEP key. And then they
could connect to the wonderful network...and do nothing. See, the ruleset for ISA.WLAN00
looked something like this: "Deny all". To actually <em>do</em> something
while on wireless, the client had to VPN into 192.168.2.254 (remember, no DNS working,
since the AP just forwarded requests to la-la land), at which point they were treated
like any other VPN client.
</div>
          <div>
          </div>
          <div>Secure? yeah, mostly. Terribly useable? no. Drags my TC1000 to a standstill for
hours at a time? you bet!
</div>
          <div>
          </div>
          <div>And now you're perhaps not laughing at me as hard as you were at the beginning.
Well, at least not for having spent so much time on it. You're still probably rolling
on the floor over my paranoia.
</div>
          <div>
          </div>
          <div>New wireless config:
</div>
          <div>DC running IAS (RADIUS server).
</div>
          <div>ISA with a route rule for Internal and Wireless, and a "Allow All"
firewall rule between Internal and Wireless (note that this will change now that I've
proved the damn thing can even <em>work</em>).
</div>
          <div>Linksys WRT54GL flashed with ewrt-0.4 (<a href="http://www.portless.net/menu/ewrt/">http://www.portless.net/menu/ewrt/</a>),
configured for WPA2, AES, and RADIUS back to the DC. Again, there's a patch cable
running from br0 back to ISA.WLAN00. IP's and subnets have changed, but that's no
big deal (okay, so it WAS a HUGE deal when I was sitting there bricking WRT54's, but
now it's mostly a moot point).
</div>
          <div>To connect, if the client is Windows Vista, I just turn the wireless on and BAM
it's like "I love you guy-who-turned-my-wireless-on! I know how to connect to
this network! You're connected!". If the client is Windows XP it sits there and
complains to me that the computer hasn't been connected into the domain for months,
and it's certificates have expired, and the autoenrollment agent can't find the certificate
authority, and just generally gives up and decides to go off into a corner and sulk.
But after you figure out how to get Windows XP to renew certificates, the same certificates
it needs for IPSec so it can communicate with the CA (hurray for chicken and egg problems),
and you actually somehow get those certificates renewed, everything works great!
</div>
          <div>
          </div>
          <div>Well, everything goes great until the wireless clients go to connect to the internet
and you find out how stupid these little router boxes really are. And you find out
how stupid you are for having forgotten that you need some ISA rules so that traffic
can go from Wireless to External.
</div>
          <div>
          </div>
          <div>But, at the moment, everything appears to be working nicely. And so I have my
last laugh! Haha! 
</div>
          <div>
          </div>
          <div>(If anyone wants me to do a more detailed write-up of this stuff, just leave
a few comments to that effect).
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9f23f500-55c3-4e89-8477-75e068b46616" />
      </body>
      <title>Wireless upgrade</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,9f23f500-55c3-4e89-8477-75e068b46616.aspx</guid>
      <link>http://www.ntldr.com/2006/05/17/WirelessUpgrade.aspx</link>
      <pubDate>Wed, 17 May 2006 04:05:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;My patience finally outweighed my ignorance of the process, so I got my wireless
working. And now everyone is laughing at me, because all they had to do was run down
to the local electronics store, grab a router, maybe pay for it too (hey, I wont ask
questions about how you got your gear...), and plug it in.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;I've put in something like 14 hours getting my new wireless configuration to
work.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;As I said, laugh away...because I shall have the last laugh!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Old wireless config:
&lt;/div&gt;
&lt;div&gt;Microsoft MN-500 with a patch cable running from one of the switch ports to the
&amp;quot;WLAN00&amp;quot; NIC in the ISA Server. ISA.WLAN00.IP = 192.168.2.254. AP.IP = 192.168.2.1,
with DHCP server stuff running on the AP, so clients got 192.168.2.x/24. To connect
to the wireless network, all the client had to have was the WEP key. And then they
could connect to the wonderful network...and do nothing. See, the ruleset for ISA.WLAN00
looked something like this: &amp;quot;Deny all&amp;quot;. To actually &lt;em&gt;do&lt;/em&gt; something
while on wireless, the client had to VPN into 192.168.2.254 (remember, no DNS working,
since the AP just forwarded requests to la-la land), at which point they were treated
like any other VPN client.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Secure? yeah, mostly. Terribly useable? no. Drags my TC1000 to a standstill for
hours at a time? you bet!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;And now you're perhaps not laughing at me as hard as you were at the beginning.
Well, at least not for having spent so much time on it. You're still probably rolling
on the floor over my paranoia.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;New wireless config:
&lt;/div&gt;
&lt;div&gt;DC running IAS (RADIUS server).
&lt;/div&gt;
&lt;div&gt;ISA with a route rule for Internal and Wireless, and a &amp;quot;Allow All&amp;quot;
firewall rule between Internal and Wireless (note that this will change now that I've
proved the damn thing can even &lt;em&gt;work&lt;/em&gt;).
&lt;/div&gt;
&lt;div&gt;Linksys WRT54GL flashed with ewrt-0.4 (&lt;a href="http://www.portless.net/menu/ewrt/"&gt;http://www.portless.net/menu/ewrt/&lt;/a&gt;),
configured for WPA2, AES, and RADIUS back to the DC. Again, there's a patch cable
running from br0 back to ISA.WLAN00. IP's and subnets have changed, but that's no
big deal (okay, so it WAS a HUGE deal when I was sitting there bricking WRT54's, but
now it's mostly a moot point).
&lt;/div&gt;
&lt;div&gt;To connect, if the client is Windows Vista, I just turn the wireless on and BAM
it's like &amp;quot;I love you guy-who-turned-my-wireless-on! I know how to connect to
this network! You're connected!&amp;quot;. If the client is Windows XP it sits there and
complains to me that the computer hasn't been connected into the domain for months,
and it's certificates have expired, and the autoenrollment agent can't find the certificate
authority, and just generally gives up and decides to go off into a corner and sulk.
But after you figure out how to get Windows XP to renew certificates, the same certificates
it needs for IPSec so it can communicate with the CA (hurray for chicken and egg problems),
and you actually somehow get those certificates renewed, everything works great!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Well, everything goes great until the wireless clients go to connect to the internet
and you find out how stupid these little router boxes really are. And you find out
how stupid you are for having forgotten that you need some ISA rules so that traffic
can go from Wireless to External.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;But, at the moment, everything appears to be working nicely. And so I have my
last laugh! Haha! 
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;(If anyone wants me to do a more detailed write-up of this stuff, just leave
a few comments to that effect).
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9f23f500-55c3-4e89-8477-75e068b46616" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,9f23f500-55c3-4e89-8477-75e068b46616.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=3601c12d-0779-49c7-949a-6ea651495b56</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,3601c12d-0779-49c7-949a-6ea651495b56.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,3601c12d-0779-49c7-949a-6ea651495b56.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=3601c12d-0779-49c7-949a-6ea651495b56</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>I recognize that spam is a big problem on the Internet. At work, I'm responsible
for manually reviewing all the messages that the server filters catch (propose idea
of filtering | boss paranoid about losing important messages | lowest cost employee
→ me). And I can tell you it's no fun going through thousands of drug, sex, phishing,
and pirated media messages each week (just to find that someone's subscription to
"Headline News" got caught this week…). Although, if you're feeling particularly
humane this week, and just really want to help those Nigerians get that cash out of
the country, just drop me a line and I can see about hooking you up with plenty of
addresses to contact… 
</div>
          <div>
          </div>
          <div>Anyway, I KNOW that spam is a problem. But I still think it's <em>kinda</em> extreme
to just block all DHCP addresses. Especially when there's no way for someone to get
off the list. Which is exactly what SORBS does. Oh, and to top it off they make you
go through one of those CAPTCHA things that's hard as hell for a human to read, but
trivially beatable using AI techniques, to even find that that's the reason you've
been getting NDR's for the last 2 days on all the messages from friends that you've
been replying to!
</div>
          <div>
          </div>
          <div>So I got to spent hours fiddling around with Smart Host settings &amp; DNS entries,
then another hour to confirm that things at least looked like they were working securely.
</div>
          <div>
          </div>
          <div>On the bright side, it does look like the ridiculously complicated and convoluted
method is actually working, so look forward to getting emails back from me in the
future instead of sitting in the dark for a couple of weeks.<br /></div>
          <div>
            <em>
              <font size="1">(sorry to everyone who emailed me and expected replies during
the last 1.5 months)</font>
            </em>
          </div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=3601c12d-0779-49c7-949a-6ea651495b56" />
      </body>
      <title>SORBS</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,3601c12d-0779-49c7-949a-6ea651495b56.aspx</guid>
      <link>http://www.ntldr.com/2006/02/20/SORBS.aspx</link>
      <pubDate>Mon, 20 Feb 2006 16:40:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;I recognize that spam is a big problem on the Internet. At work, I'm responsible
for manually reviewing all the messages that the server filters catch (propose idea
of filtering | boss paranoid about losing important messages | lowest cost employee
→ me). And I can tell you it's no fun going through thousands of drug, sex, phishing,
and pirated media messages each week (just to find that someone's subscription to
&amp;quot;Headline News&amp;quot; got caught this week…). Although, if you're feeling particularly
humane this week, and just really want to help those Nigerians get that cash out of
the country, just drop me a line and I can see about hooking you up with plenty of
addresses to contact… 
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Anyway, I KNOW that spam is a problem. But I still think it's &lt;em&gt;kinda&lt;/em&gt; extreme
to just block all DHCP addresses. Especially when there's no way for someone to get
off the list. Which is exactly what SORBS does. Oh, and to top it off they make you
go through one of those CAPTCHA things that's hard as hell for a human to read, but
trivially beatable using AI techniques, to even find that that's the reason you've
been getting NDR's for the last 2 days on all the messages from friends that you've
been replying to!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;So I got to spent hours fiddling around with Smart Host settings &amp;amp; DNS entries,
then another hour to confirm that things at least looked like they were working securely.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;On the bright side, it does look like the ridiculously complicated and convoluted
method is actually working, so look forward to getting emails back from me in the
future instead of sitting in the dark for a couple of weeks.&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;&lt;em&gt;&lt;font size=1&gt;(sorry to everyone who emailed me and expected replies during
the last 1.5 months)&lt;/font&gt;&lt;/em&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=3601c12d-0779-49c7-949a-6ea651495b56" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,3601c12d-0779-49c7-949a-6ea651495b56.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=270309f6-aa33-4352-8738-1b9d0462dce8</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,270309f6-aa33-4352-8738-1b9d0462dce8.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,270309f6-aa33-4352-8738-1b9d0462dce8.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=270309f6-aa33-4352-8738-1b9d0462dce8</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Today's "DUH! I'M AN IDIOT!" award goes to...me. Yay, I won something.
</div>
          <div>
          </div>
          <div>I get it for not putting the /* on the end of the path I was trying to publish
with ISA. The /extranet.aspx links should now work. The funny thing is I forgot it
despite there being other paths published in the same rule that correctly had the
/* at the end. So, basically, if I had just like, looked at the screen maybe, I should
have seen the problem immediately.
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=270309f6-aa33-4352-8738-1b9d0462dce8" />
      </body>
      <title>Wildcards are necessary (sometimes...and so is reading)</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,270309f6-aa33-4352-8738-1b9d0462dce8.aspx</guid>
      <link>http://www.ntldr.com/2006/02/13/WildcardsAreNecessarySometimesandSoIsReading.aspx</link>
      <pubDate>Mon, 13 Feb 2006 15:35:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Today's &amp;quot;DUH! I'M AN IDIOT!&amp;quot; award goes to...me. Yay, I won something.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;I get it for not putting the /* on the end of the path I was trying to publish
with ISA. The /extranet.aspx links should now work. The funny thing is I forgot it
despite there being other paths published in the same rule that correctly had the
/* at the end. So, basically, if I had just like, looked at the screen maybe, I should
have seen the problem immediately.
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=270309f6-aa33-4352-8738-1b9d0462dce8" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,270309f6-aa33-4352-8738-1b9d0462dce8.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Computer humor: <a href="http://www.computerworld.com/blogs/node/1688">http://www.computerworld.com/blogs/node/1688</a></div>
          <div>
          </div>
          <div>Follow the two links in the post...
</div>
          <div>
          </div>
          <div>Context update: this was one of the fun things I found during OS's today, thus
proving (again) that having PowerPoint slides available for a class leads to decreased
attention.
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12" />
      </body>
      <title>Humor for the day</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12.aspx</guid>
      <link>http://www.ntldr.com/2006/02/01/HumorForTheDay.aspx</link>
      <pubDate>Wed, 01 Feb 2006 18:05:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Computer humor: &lt;a href="http://www.computerworld.com/blogs/node/1688"&gt;http://www.computerworld.com/blogs/node/1688&lt;/a&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Follow the two links in the post...
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Context update: this was one of the fun things I found during OS's today, thus
proving (again) that having PowerPoint slides available for a class leads to decreased
attention.
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,3ba33fa7-a30d-4ba0-95f6-3ac0439ffa12.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=12b2e62a-7752-4ae4-86b7-259dfdf9afa6</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,12b2e62a-7752-4ae4-86b7-259dfdf9afa6.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,12b2e62a-7752-4ae4-86b7-259dfdf9afa6.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=12b2e62a-7752-4ae4-86b7-259dfdf9afa6</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>The PKI system I have on my computers has been upgraded: it now has 1 working
smart card that I'm using for testing &amp; evaluation!
</div>
          <div>
          </div>
          <div>The smart card is an Axalto Cryptoflex 32k e-gate. The certificate server is
Windows Server 2003 Certificate Services. The client is straight Windows XP SP2 (no
additional Axalto CSP, so I had to use their Personalization tool to format it for
Windows 2000 compatibility).
</div>
          <div>
          </div>
          <div>Now, there was one tiny problem I've run into. When trying to request a new certificate
using certmgr.msc, it would always generate the error "Certificate request could
not complete. The specified user was not found." (or something along those lines).
After combing the event logs, doing a number of web searches, and examining every
nook and cranny of the Certificate Process, I found the solution.
</div>
          <div>
          </div>
          <div>It turns out the user requesting the certificate can't be logged in using the
UPN (<a href="mailto:username@domain">username@domain</a>). You have to login using
the domain username, password, domain format.
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=12b2e62a-7752-4ae4-86b7-259dfdf9afa6" />
      </body>
      <title>Certificate Request could not complete.  The specified user was not found.</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,12b2e62a-7752-4ae4-86b7-259dfdf9afa6.aspx</guid>
      <link>http://www.ntldr.com/2006/01/25/CertificateRequestCouldNotCompleteTheSpecifiedUserWasNotFound.aspx</link>
      <pubDate>Wed, 25 Jan 2006 06:40:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;The PKI system I have on my computers has been upgraded: it now has 1 working
smart card that I'm using for testing &amp;amp; evaluation!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;The smart card is an Axalto Cryptoflex 32k e-gate. The certificate server is
Windows Server 2003 Certificate Services. The client is straight Windows XP SP2 (no
additional Axalto CSP, so I had to use their Personalization tool to format it for
Windows 2000 compatibility).
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Now, there was one tiny problem I've run into. When trying to request a new certificate
using certmgr.msc, it would always generate the error &amp;quot;Certificate request could
not complete. The specified user was not found.&amp;quot; (or something along those lines).
After combing the event logs, doing a number of web searches, and examining every
nook and cranny of the Certificate Process, I found the solution.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;It turns out the user requesting the certificate can't be logged in using the
UPN (&lt;a href="mailto:username@domain"&gt;username@domain&lt;/a&gt;). You have to login using
the domain username, password, domain format.
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=12b2e62a-7752-4ae4-86b7-259dfdf9afa6" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,12b2e62a-7752-4ae4-86b7-259dfdf9afa6.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=a2beef79-df1c-4be2-95b2-0b6204df34c0</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,a2beef79-df1c-4be2-95b2-0b6204df34c0.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,a2beef79-df1c-4be2-95b2-0b6204df34c0.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=a2beef79-df1c-4be2-95b2-0b6204df34c0</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>At work we bought two new servers to replace our 5-6 year old DC's. I got most
of the OS installed last weekend, and got the go ahead today to bring one of them
up as a DC in the domain.
</div>
          <div>
          </div>
          <div>So I ran dcpromo.exe, walked through the wizard, and let it do its thing. After
5 minutes or so, it failed, saying the schema was out of date and needed to be updated.
Which was funny, because its a Windows Server 2003 SP1 domain, and I thought that
Windows Server 2003 R2 was the same core OS as 2003 SP1. Well, it turns out that atleast
the AD components in R2 are newer (to support the Federation Services? or maybe the
Integrated Unix Authentication?).
</div>
          <div>
          </div>
          <div>However, running adprep.exe from Disc 1 didn't help, since it kept saying the
schema <strong>was</strong> up to date.
</div>
          <div>
          </div>
          <div>Well, it turns out there's <strong>ANOTHER</strong> adprep.exe that has to be
run. It's located on DISC 2 under the \CMPNTS\R2\ADPREP folder. So, "adprep.exe
/forestmode" (and, curiously, "adprep.exe /domainprep /gpprep", for
our domain) needs to be executed before dcpromo will work.
</div>
          <div>
          </div>
          <div>Next time, I'll try looking at the docs before doing something I've done dozens
of times before...
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=a2beef79-df1c-4be2-95b2-0b6204df34c0" />
      </body>
      <title>Windows Server 2003 R2 dcpromo requires adprep</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,a2beef79-df1c-4be2-95b2-0b6204df34c0.aspx</guid>
      <link>http://www.ntldr.com/2006/01/21/WindowsServer2003R2DcpromoRequiresAdprep.aspx</link>
      <pubDate>Sat, 21 Jan 2006 03:45:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;At work we bought two new servers to replace our 5-6 year old DC's. I got most
of the OS installed last weekend, and got the go ahead today to bring one of them
up as a DC in the domain.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;So I ran dcpromo.exe, walked through the wizard, and let it do its thing. After
5 minutes or so, it failed, saying the schema was out of date and needed to be updated.
Which was funny, because its a Windows Server 2003 SP1 domain, and I thought that
Windows Server 2003 R2 was the same core OS as 2003 SP1. Well, it turns out that atleast
the AD components in R2 are newer (to support the Federation Services? or maybe the
Integrated Unix Authentication?).
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;However, running adprep.exe from Disc 1 didn't help, since it kept saying the
schema &lt;strong&gt;was&lt;/strong&gt; up to date.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Well, it turns out there's &lt;strong&gt;ANOTHER&lt;/strong&gt; adprep.exe that has to be
run. It's located on DISC 2 under the \CMPNTS\R2\ADPREP folder. So, &amp;quot;adprep.exe
/forestmode&amp;quot; (and, curiously, &amp;quot;adprep.exe /domainprep /gpprep&amp;quot;, for
our domain) needs to be executed before dcpromo will work.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Next time, I'll try looking at the docs before doing something I've done dozens
of times before...
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=a2beef79-df1c-4be2-95b2-0b6204df34c0" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,a2beef79-df1c-4be2-95b2-0b6204df34c0.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=7284153f-eb48-4606-b2bd-336a8eed38c9</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,7284153f-eb48-4606-b2bd-336a8eed38c9.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,7284153f-eb48-4606-b2bd-336a8eed38c9.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=7284153f-eb48-4606-b2bd-336a8eed38c9</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Well, I got IPSEC to work. Finally. Actually, it only took about a week...there
just happened to be this thing called "winter break" and "classes start
again" immediately after I got everything working.
</div>
          <div>
          </div>
          <div>So, how did I manage to do it?
</div>
          <div>
          </div>
          <ol>
            <li>
Use certificate authentication, not Kerberos. 
</li>
            <li>
Disable the "map certificates to accounts" setting, otherwise it seems a
UNencrypted connection to a DC is needed, just like with Kerberos. 
</li>
            <li>
Somehow keep all the computers you're trying to configure from locking while you're
in the middle of setting everything up, because it's likely that if that happens,
and you have applied the MS Windows Server 2003 Security Guide recommendations, then
you'll be screwed and unable to access the server you're in the middle of configuring.
Yes, this happened to me, and no, I never want to go through that experience again. 
</li>
            <li>
Become familiar with "net stop policyagent", as it can save you when things
get screwed up. Basically, it turns off IPSEC enforcement/usage, allowing the computer
to communicate with the DC (maybe). 
</li>
            <li>
If you see someone like MS doing something with IPSEC, like exempt DC's &amp; DNS
servers from policy, PAY ATTENTION. THERE IS A REASON THEY DID THAT. Whatever you
do, don't think you're smarter than the people who wrote those papers, especially
since <em>their</em> implementation actually <em>works</em>.</li>
          </ol>
          <p>
So, those are my tips on how to get it working with Windows Server 2003 SP1 and Windows
XP SP2. Anyone else got any advice?
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7284153f-eb48-4606-b2bd-336a8eed38c9" />
      </body>
      <title>IPSEC (the conclusion)</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,7284153f-eb48-4606-b2bd-336a8eed38c9.aspx</guid>
      <link>http://www.ntldr.com/2006/01/21/IPSECTheConclusion.aspx</link>
      <pubDate>Sat, 21 Jan 2006 03:35:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Well, I got IPSEC to work. Finally. Actually, it only took about a week...there
just happened to be this thing called &amp;quot;winter break&amp;quot; and &amp;quot;classes start
again&amp;quot; immediately after I got everything working.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;So, how did I manage to do it?
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;
Use certificate authentication, not Kerberos. 
&lt;/li&gt;
&lt;li&gt;
Disable the &amp;quot;map certificates to accounts&amp;quot; setting, otherwise it seems a
UNencrypted connection to a DC is needed, just like with Kerberos. 
&lt;/li&gt;
&lt;li&gt;
Somehow keep all the computers you're trying to configure from locking while you're
in the middle of setting everything up, because it's likely that if that happens,
and you have applied the MS Windows Server 2003 Security Guide recommendations, then
you'll be screwed and unable to access the server you're in the middle of configuring.
Yes, this happened to me, and no, I never want to go through that experience again. 
&lt;/li&gt;
&lt;li&gt;
Become familiar with &amp;quot;net stop policyagent&amp;quot;, as it can save you when things
get screwed up. Basically, it turns off IPSEC enforcement/usage, allowing the computer
to communicate with the DC (maybe). 
&lt;/li&gt;
&lt;li&gt;
If you see someone like MS doing something with IPSEC, like exempt DC's &amp;amp; DNS
servers from policy, PAY ATTENTION. THERE IS A REASON THEY DID THAT. Whatever you
do, don't think you're smarter than the people who wrote those papers, especially
since &lt;em&gt;their&lt;/em&gt; implementation actually &lt;em&gt;works&lt;/em&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;
So, those are my tips on how to get it working with Windows Server 2003 SP1 and Windows
XP SP2. Anyone else got any advice?
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7284153f-eb48-4606-b2bd-336a8eed38c9" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,7284153f-eb48-4606-b2bd-336a8eed38c9.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=0684fc09-9b1f-4878-8f0f-9825d6687930</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,0684fc09-9b1f-4878-8f0f-9825d6687930.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,0684fc09-9b1f-4878-8f0f-9825d6687930.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=0684fc09-9b1f-4878-8f0f-9825d6687930</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>You may have noticed the site being up &amp; down (mostly down though) for the
last week and a half. Site performance has also decreased now that it's back up.
</div>
          <div>
          </div>
          <div>This is because IPSec is the worst thing EVER. And I mean that. Literally.
</div>
          <div>
          </div>
          <div>IPSec sits in the low level of the OSI stack and provides encryption and authentication
for IP. So it can do things like have every TCP packet from the Internet encrypted
using 3DES, with the sender and reciever authenticating to each other over Kerberos.
So far, so good. Sounds like a wonderful technology: all you have to worry about are
IP spoofing, hardware hacking, and Layer 1 (like ARP poisoning) attacks. Everything
above that stuff is always encrypted and always authenticated.
</div>
          <div>
          </div>
          <div>Except, it turns out to be incredibly hard to actually <em>use</em>. Sure, it
starts simple enough: assign one of the predefined policies that sounds like it's
the correct choice, like "Client" or "Require Security". But then
you apply that setting...and find out you can't log into the computer anymore, can't
get the computer to recognize that you've fixed the policy so that you could actually
login, and then find out you can't actually pull the broken policy off because the
IPSEC driver has now gone into BLOCK mode, and is denying every attempt to connect.
</div>
          <div>
          </div>
          <div>Even worse is what happened to me. It seemed to work fine for the servers for
a day or two. <em>Then</em> they started having those problems. Even more confusing,
they'd do this when configured to use Certificate based authentication.
</div>
          <div>
          </div>
          <div>Even more frustrating is that I have the PolicyAgent ("IPSec Services")
startup controlled via GPO's. So when I finally did manage to get the service stopped
and everything talking once again, the next GP application came around and fired it
right back up. While the console was locked. With the "Require Domain Controller
authorization to unlock workstation" setting enabled.
</div>
          <div>
          </div>
          <div>Oh, and this is all happening during finals week (well, actually, it started
the week before finals; it just took me a while to notice).
</div>
          <div>
          </div>
          <div>Understand why IPSec is the worst thing ever?
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=0684fc09-9b1f-4878-8f0f-9825d6687930" />
      </body>
      <title>IPSec is the worst thing ever</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,0684fc09-9b1f-4878-8f0f-9825d6687930.aspx</guid>
      <link>http://www.ntldr.com/2005/12/16/IPSecIsTheWorstThingEver.aspx</link>
      <pubDate>Fri, 16 Dec 2005 22:25:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;You may have noticed the site being up &amp;amp; down (mostly down though) for the
last week and a half. Site performance has also decreased now that it's back up.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;This is because IPSec is the worst thing EVER. And I mean that. Literally.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;IPSec sits in the low level of the OSI stack and provides encryption and authentication
for IP. So it can do things like have every TCP packet from the Internet encrypted
using 3DES, with the sender and reciever authenticating to each other over Kerberos.
So far, so good. Sounds like a wonderful technology: all you have to worry about are
IP spoofing, hardware hacking, and Layer 1 (like ARP poisoning) attacks. Everything
above that stuff is always encrypted and always authenticated.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Except, it turns out to be incredibly hard to actually &lt;em&gt;use&lt;/em&gt;. Sure, it
starts simple enough: assign one of the predefined policies that sounds like it's
the correct choice, like &amp;quot;Client&amp;quot; or &amp;quot;Require Security&amp;quot;. But then
you apply that setting...and find out you can't log into the computer anymore, can't
get the computer to recognize that you've fixed the policy so that you could actually
login, and then find out you can't actually pull the broken policy off because the
IPSEC driver has now gone into BLOCK mode, and is denying every attempt to connect.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Even worse is what happened to me. It seemed to work fine for the servers for
a day or two. &lt;em&gt;Then&lt;/em&gt; they started having those problems. Even more confusing,
they'd do this when configured to use Certificate based authentication.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Even more frustrating is that I have the PolicyAgent (&amp;quot;IPSec Services&amp;quot;)
startup controlled via GPO's. So when I finally did manage to get the service stopped
and everything talking once again, the next GP application came around and fired it
right back up. While the console was locked. With the &amp;quot;Require Domain Controller
authorization to unlock workstation&amp;quot; setting enabled.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Oh, and this is all happening during finals week (well, actually, it started
the week before finals; it just took me a while to notice).
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Understand why IPSec is the worst thing ever?
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=0684fc09-9b1f-4878-8f0f-9825d6687930" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,0684fc09-9b1f-4878-8f0f-9825d6687930.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=5b477c03-6008-4cd6-9f3d-417696b39106</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,5b477c03-6008-4cd6-9f3d-417696b39106.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,5b477c03-6008-4cd6-9f3d-417696b39106.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=5b477c03-6008-4cd6-9f3d-417696b39106</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Primarily, this is a post about RSS. You see, there's only one subscriber to
the RSS feeds that are in all those tabs to the right (on the v5 site...which is the
one that's available when this post is being written). And there should be more!\
</div>
          <div>
          </div>
          <div>But first, a digression into ECE: the lab practical today was just <em>meh</em>.
It was a simple enough task, but the infernal contraption just wouldn't work for me!
So I ran out of time, and the TA came over to grade what I had, and all of a sudden
it mostly started working (I had pulled out the Asynch Reset so I could debug it).
So I got a 9/10. Which is good, but the amount of frustration was...even more frustrating.
</div>
          <div>
          </div>
          <div>Back to RSS. It's just another XML format (kind of like most web pages are just
the XHTML XML format). However, there are these cool things called RSS Readers that
can Subscribe to an RSS Feed (the XML file containing RSS). When a feed (to use the
simplified parlance of <em>bloggers</em> - people who author a Web Log, like the one
that you're reading right now) is subscribed to, the RSS Reader will automatically
check the feed for updates and display those to the user in whatever manner. So subscribing
to one of the RSS feeds on this site would mean you'd never have to manually come
and visit it to see what's new: the Reader would take care of that for you.
</div>
          <div>
          </div>
          <div>I recommend that you check RSS out and see what it can do for you (like on this
site). I use RSS A LOT. I'm subscribed to a lot of RSS feeds (not just blogs - change
logs &amp; "new releases" are things I've found to be condusive to use as
RSS items). And now onto a little problem I have...
</div>
          <div>
          </div>
          <div>Now, there are a wide variety of RSS Readers. You have web based ones, like Start,
live.com, Google Reader (I know Google has one at least), and a wide variety of much
more popular sites. There are addons &amp; plugins for existing apps, like Newsgator:
Outlook. There are apps that have had Reader capabilities baked in (similar to the
plugins), like Mozilla Thunderbird, a couple of Jabber clients, and Microsoft IE7.
And then there are the dedicated desktop, rich client RSS Aggregators.
</div>
          <div>
          </div>
          <div>I use the later. Currently, this is RSS Bandit 1.2.117. I started out with SharpReader,
but that's waaay too memory intensive, and doesn't look that great in my opinion either.
But it lasted me a while. The next client I tried was SauceReader, which looked great,
but had even worse resource usage than SharpReader. Finally, I tried RSS Bandit 1.2.114.
And that had me hooked: it was specifically designed to not trash system resources.
RSS Bandit has served me well for almost a year and a half now.
</div>
          <div>
          </div>
          <div>Development has also continued, lead primarily by Dare Obasanjo (<a href="http://www.25hoursaday.com/">www.25hoursaday.com</a>).
They've had the 1.3 series of versions released for a bit now, and just rolled out
a new one. Unfortunately, I have never been able to get the 1.3 versions to work.
Between 1.2 and 1.3, they changed some of the UI components, and the new library just
does not seem to want to work. So whenever I go to use 1.3, all I get is a blank area
where it should be displaying the tree view of the feeds I'm subscribed to. Which
means that the program is completely useless, as none of the other sections of the
program (post contents &amp; post list for the currently selected feed) get populated.
I have seen this problem even on fresh installations of Windows, with just XP SP2
&amp; .NET 1.1 SP1 installed. Obviously everything is working fine for most people,
just not for me.
</div>
          <div>
          </div>
          <div>As stated before, I've been running the older version of RSS Bandit because of
that issue. However, that solution is becoming increasingly inadequite. A number of
the feeds I'm subscribed to use ATOM (as far as end users are concerned, it's the
same as RSS...just a different company's take on the whole feed idea), and have recently
moved from the 0.3 version to the 1.0 version of the spec. Which means RSS Bandit
1.2 can no longer view them.
</div>
          <div>
          </div>
          <div>So, any recommendations for a new RSS Aggregator? It needs to support ATOM 1.0,
podcasting support is not needed, I'd like it to look nice, preferably be a standalone
client (although something that acts as an addin to Outlook might also work for me),
and ideally be free/cheap.
</div>
          <div>
          </div>
          <div>Thanks!
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=5b477c03-6008-4cd6-9f3d-417696b39106" />
      </body>
      <title>RSS Client choice (&amp; introduction for newbies)</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,5b477c03-6008-4cd6-9f3d-417696b39106.aspx</guid>
      <link>http://www.ntldr.com/2005/12/09/RSSClientChoiceIntroductionForNewbies.aspx</link>
      <pubDate>Fri, 09 Dec 2005 02:05:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Primarily, this is a post about RSS. You see, there's only one subscriber to
the RSS feeds that are in all those tabs to the right (on the v5 site...which is the
one that's available when this post is being written). And there should be more!\
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;But first, a digression into ECE: the lab practical today was just &lt;em&gt;meh&lt;/em&gt;.
It was a simple enough task, but the infernal contraption just wouldn't work for me!
So I ran out of time, and the TA came over to grade what I had, and all of a sudden
it mostly started working (I had pulled out the Asynch Reset so I could debug it).
So I got a 9/10. Which is good, but the amount of frustration was...even more frustrating.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Back to RSS. It's just another XML format (kind of like most web pages are just
the XHTML XML format). However, there are these cool things called RSS Readers that
can Subscribe to an RSS Feed (the XML file containing RSS). When a feed (to use the
simplified parlance of &lt;em&gt;bloggers&lt;/em&gt; - people who author a Web Log, like the one
that you're reading right now) is subscribed to, the RSS Reader will automatically
check the feed for updates and display those to the user in whatever manner. So subscribing
to one of the RSS feeds on this site would mean you'd never have to manually come
and visit it to see what's new: the Reader would take care of that for you.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;I recommend that you check RSS out and see what it can do for you (like on this
site). I use RSS A LOT. I'm subscribed to a lot of RSS feeds (not just blogs - change
logs &amp;amp; &amp;quot;new releases&amp;quot; are things I've found to be condusive to use as
RSS items). And now onto a little problem I have...
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Now, there are a wide variety of RSS Readers. You have web based ones, like Start,
live.com, Google Reader (I know Google has one at least), and a wide variety of much
more popular sites. There are addons &amp;amp; plugins for existing apps, like Newsgator:
Outlook. There are apps that have had Reader capabilities baked in (similar to the
plugins), like Mozilla Thunderbird, a couple of Jabber clients, and Microsoft IE7.
And then there are the dedicated desktop, rich client RSS Aggregators.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;I use the later. Currently, this is RSS Bandit 1.2.117. I started out with SharpReader,
but that's waaay too memory intensive, and doesn't look that great in my opinion either.
But it lasted me a while. The next client I tried was SauceReader, which looked great,
but had even worse resource usage than SharpReader. Finally, I tried RSS Bandit 1.2.114.
And that had me hooked: it was specifically designed to not trash system resources.
RSS Bandit has served me well for almost a year and a half now.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Development has also continued, lead primarily by Dare Obasanjo (&lt;a href="http://www.25hoursaday.com/"&gt;www.25hoursaday.com&lt;/a&gt;).
They've had the 1.3 series of versions released for a bit now, and just rolled out
a new one. Unfortunately, I have never been able to get the 1.3 versions to work.
Between 1.2 and 1.3, they changed some of the UI components, and the new library just
does not seem to want to work. So whenever I go to use 1.3, all I get is a blank area
where it should be displaying the tree view of the feeds I'm subscribed to. Which
means that the program is completely useless, as none of the other sections of the
program (post contents &amp;amp; post list for the currently selected feed) get populated.
I have seen this problem even on fresh installations of Windows, with just XP SP2
&amp;amp; .NET 1.1 SP1 installed. Obviously everything is working fine for most people,
just not for me.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;As stated before, I've been running the older version of RSS Bandit because of
that issue. However, that solution is becoming increasingly inadequite. A number of
the feeds I'm subscribed to use ATOM (as far as end users are concerned, it's the
same as RSS...just a different company's take on the whole feed idea), and have recently
moved from the 0.3 version to the 1.0 version of the spec. Which means RSS Bandit
1.2 can no longer view them.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;So, any recommendations for a new RSS Aggregator? It needs to support ATOM 1.0,
podcasting support is not needed, I'd like it to look nice, preferably be a standalone
client (although something that acts as an addin to Outlook might also work for me),
and ideally be free/cheap.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Thanks!
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=5b477c03-6008-4cd6-9f3d-417696b39106" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,5b477c03-6008-4cd6-9f3d-417696b39106.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=88694b42-b0cd-4064-a994-6651793829ee</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,88694b42-b0cd-4064-a994-6651793829ee.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,88694b42-b0cd-4064-a994-6651793829ee.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=88694b42-b0cd-4064-a994-6651793829ee</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Taylor's website has comments now. He gets props for being the biggest poster
of comments to this site, and he's consistently been the 3rd most frequent user. So
go visit his site: <a href="http://www.metasyntax.net/">www.metasyntax.net</a></div>
          <div>
          </div>
          <div>As for this site, here's a summary of the current status of the New Design Project:
</div>
          <ul>
            <li>
Taylor ran a few perf tests against the test page, and pointed out that the header
renders fast, but not the &lt;sharepoint content&gt; area 
</li>
            <li>
I did my own investigating since my Remote Connections to work actually started working
(finally) 
</li>
            <li>
It looks like the Perf problem is the &lt;SharePoint:tag/&gt; stuff in the .aspx pages 
</li>
            <li>
Logging in removes all perf problems. So it's either pre-caching stuff for logged
in users (low possibility), or something is absolutely killing performance when the
Anonymous access maps to NT AUTHORITY\NETWORK SERVICE, and that goes over the wire
to SQL Server? Maybe?</li>
          </ul>
          <p>
I've got a gut feeling as to what's causing that security issue. Not happy with what
its telling me right now though.
</p>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=88694b42-b0cd-4064-a994-6651793829ee" />
      </body>
      <title>Misc. Web News</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,88694b42-b0cd-4064-a994-6651793829ee.aspx</guid>
      <link>http://www.ntldr.com/2005/12/08/MiscWebNews.aspx</link>
      <pubDate>Thu, 08 Dec 2005 04:55:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Taylor's website has comments now. He gets props for being the biggest poster
of comments to this site, and he's consistently been the 3rd most frequent user. So
go visit his site: &lt;a href="http://www.metasyntax.net/"&gt;www.metasyntax.net&lt;/a&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;As for this site, here's a summary of the current status of the New Design Project:
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;
Taylor ran a few perf tests against the test page, and pointed out that the header
renders fast, but not the &amp;lt;sharepoint content&amp;gt; area 
&lt;/li&gt;
&lt;li&gt;
I did my own investigating since my Remote Connections to work actually started working
(finally) 
&lt;/li&gt;
&lt;li&gt;
It looks like the Perf problem is the &amp;lt;SharePoint:tag/&amp;gt; stuff in the .aspx pages 
&lt;/li&gt;
&lt;li&gt;
Logging in removes all perf problems. So it's either pre-caching stuff for logged
in users (low possibility), or something is absolutely killing performance when the
Anonymous access maps to NT AUTHORITY\NETWORK SERVICE, and that goes over the wire
to SQL Server? Maybe?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
I've got a gut feeling as to what's causing that security issue. Not happy with what
its telling me right now though.
&lt;/p&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=88694b42-b0cd-4064-a994-6651793829ee" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,88694b42-b0cd-4064-a994-6651793829ee.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=9fbed3b1-3762-4f28-ab53-b4d47617e716</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,9fbed3b1-3762-4f28-ab53-b4d47617e716.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,9fbed3b1-3762-4f28-ab53-b4d47617e716.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=9fbed3b1-3762-4f28-ab53-b4d47617e716</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Oh, and Windows Server 2003 R2 RTM'd yesterday, which was a really cool (in an
IT'y sort of way) birthday present from the big M.
</div>
          <div>
          </div>
          <div>(expect more commentary in a few weeks...probably not downtime though, since
I don't think I'll be upgrading any existing servers)
</div>
          <div>
          </div>
          <div>Update: 2005-12-07 21:38: Unfortunately, it looks like they forgot to send me
the licenses &amp; media to go with this wonderful birthday present...come on MS!
You can do better!
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9fbed3b1-3762-4f28-ab53-b4d47617e716" />
      </body>
      <title>Birthday (amendum)</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,9fbed3b1-3762-4f28-ab53-b4d47617e716.aspx</guid>
      <link>http://www.ntldr.com/2005/12/07/BirthdayAmendum.aspx</link>
      <pubDate>Wed, 07 Dec 2005 04:25:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Oh, and Windows Server 2003 R2 RTM'd yesterday, which was a really cool (in an
IT'y sort of way) birthday present from the big M.
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;(expect more commentary in a few weeks...probably not downtime though, since
I don't think I'll be upgrading any existing servers)
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Update: 2005-12-07 21:38: Unfortunately, it looks like they forgot to send me
the licenses &amp;amp; media to go with this wonderful birthday present...come on MS!
You can do better!
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=9fbed3b1-3762-4f28-ab53-b4d47617e716" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,9fbed3b1-3762-4f28-ab53-b4d47617e716.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=7f9faedd-141b-4b26-8d60-d8b87a95d5d5</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,7f9faedd-141b-4b26-8d60-d8b87a95d5d5.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,7f9faedd-141b-4b26-8d60-d8b87a95d5d5.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=7f9faedd-141b-4b26-8d60-d8b87a95d5d5</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>Okay, I've put up my sketch and the first basic design work. Comments on the
new design idea, and the performance of the test page, would be appreciated. Please
note that I think the blue button on the test page is horrible, and needs a lot of
work that I don't (yet) know how to do, so if anyone could explain how the to make
things glossy &amp; how lighting works in Microsoft Expression codename 'Acrylic'
(October 2005 CTP)...
</div>
          <div>
          </div>
          <div>Sketch
</div>
          <div>
            <a href="#">https://www.ntldr.net/v60/idea/New%20Website.png</a>
          </div>
          <div>Sketch (original InkArt file)
</div>
          <div>
            <a href="#">https://www.ntldr.net/v60/idea/New%20design%20for%20Website.ptg</a>
          </div>
          <div>Test Page
</div>
          <div>
            <a href="#">https://www.ntldr.net/v60/Testing3.aspx</a>
          </div>
          <div>Test Page (version that doesn't work with SharePoint, grrrr)
</div>
          <div>
            <a href="#">https://www.ntldr.net/v60/Testing2.aspx</a>
          </div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7f9faedd-141b-4b26-8d60-d8b87a95d5d5" />
      </body>
      <title>New Site Design update</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,7f9faedd-141b-4b26-8d60-d8b87a95d5d5.aspx</guid>
      <link>http://www.ntldr.com/2005/12/06/NewSiteDesignUpdate.aspx</link>
      <pubDate>Tue, 06 Dec 2005 00:35:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;Okay, I've put up my sketch and the first basic design work. Comments on the
new design idea, and the performance of the test page, would be appreciated. Please
note that I think the blue button on the test page is horrible, and needs a lot of
work that I don't (yet) know how to do, so if anyone could explain how the to make
things glossy &amp;amp; how lighting works in Microsoft Expression codename 'Acrylic'
(October 2005 CTP)...
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Sketch
&lt;/div&gt;
&lt;div&gt;&lt;a href="#"&gt;https://www.ntldr.net/v60/idea/New%20Website.png&lt;/a&gt;
&lt;/div&gt;
&lt;div&gt;Sketch (original InkArt file)
&lt;/div&gt;
&lt;div&gt;&lt;a href="#"&gt;https://www.ntldr.net/v60/idea/New%20design%20for%20Website.ptg&lt;/a&gt;
&lt;/div&gt;
&lt;div&gt;Test Page
&lt;/div&gt;
&lt;div&gt;&lt;a href="#"&gt;https://www.ntldr.net/v60/Testing3.aspx&lt;/a&gt;
&lt;/div&gt;
&lt;div&gt;Test Page (version that doesn't work with SharePoint, grrrr)
&lt;/div&gt;
&lt;div&gt;&lt;a href="#"&gt;https://www.ntldr.net/v60/Testing2.aspx&lt;/a&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=7f9faedd-141b-4b26-8d60-d8b87a95d5d5" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,7f9faedd-141b-4b26-8d60-d8b87a95d5d5.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=2bec2cb3-5221-491c-adb8-6398a9b99021</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,2bec2cb3-5221-491c-adb8-6398a9b99021.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,2bec2cb3-5221-491c-adb8-6398a9b99021.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=2bec2cb3-5221-491c-adb8-6398a9b99021</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>There is a new site design coming soon!
</div>
          <div>
          </div>
          <div>Since break is almost upon us, I've begun to think about possible revisions to
the site...basically, I'm looking at scrapping the current design and going to something
that works better (faster load times, works in non-IE browsers better, is actually
finished, and looks cooler).<br /></div>
          <div>Some hints of this can be seen already. Like that ugly green bar that's now at
the tops of everything... Anyway, I'm going to need YOUR help to do this! So let's
get together and do some kick-ass web design! yeah!
</div>
          <div>
          </div>
          <div>Items that need helping:
</div>
          <ol>
            <li>
JavaScript debugger for IE (recommendations anyone? I'd like to get comments working
for everything, and part of that is understanding WHY they even work in IE) 
</li>
            <li>
Graphics/art: I suck at this. Although, by setting my standards low enough, relying
on the simple automations graphics packages provide, and doing TONS of stuff by hand
(okay, and blatant copying of other people's ideas), I've had results that don't look <em>that</em> bad. 
</li>
            <li>
Firefox testers. 
</li>
            <li>
External testers in general (perf for me is always great...but not so for most people
I guess). 
</li>
            <li>
CSS/JavaScript debugging expertise? Not sure if this will end up being a problem...it
hasn't been so far...but you never know... 
</li>
            <li>
Anything else I can think of when I get stopped by some hideous deficiency of my character
(like spelling).</li>
          </ol>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=2bec2cb3-5221-491c-adb8-6398a9b99021" />
      </body>
      <title>New Site Design</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,2bec2cb3-5221-491c-adb8-6398a9b99021.aspx</guid>
      <link>http://www.ntldr.com/2005/12/05/NewSiteDesign.aspx</link>
      <pubDate>Mon, 05 Dec 2005 04:45:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;There is a new site design coming soon!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Since break is almost upon us, I've begun to think about possible revisions to
the site...basically, I'm looking at scrapping the current design and going to something
that works better (faster load times, works in non-IE browsers better, is actually
finished, and looks cooler).&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;Some hints of this can be seen already. Like that ugly green bar that's now at
the tops of everything... Anyway, I'm going to need YOUR help to do this! So let's
get together and do some kick-ass web design! yeah!
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Items that need helping:
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;
JavaScript debugger for IE (recommendations anyone? I'd like to get comments working
for everything, and part of that is understanding WHY they even work in IE) 
&lt;/li&gt;
&lt;li&gt;
Graphics/art: I suck at this. Although, by setting my standards low enough, relying
on the simple automations graphics packages provide, and doing TONS of stuff by hand
(okay, and blatant copying of other people's ideas), I've had results that don't look &lt;em&gt;that&lt;/em&gt; bad. 
&lt;/li&gt;
&lt;li&gt;
Firefox testers. 
&lt;/li&gt;
&lt;li&gt;
External testers in general (perf for me is always great...but not so for most people
I guess). 
&lt;/li&gt;
&lt;li&gt;
CSS/JavaScript debugging expertise? Not sure if this will end up being a problem...it
hasn't been so far...but you never know... 
&lt;/li&gt;
&lt;li&gt;
Anything else I can think of when I get stopped by some hideous deficiency of my character
(like spelling).&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=2bec2cb3-5221-491c-adb8-6398a9b99021" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,2bec2cb3-5221-491c-adb8-6398a9b99021.aspx</comments>
      <category>IT</category>
    </item>
    <item>
      <trackback:ping>http://www.ntldr.com/Trackback.aspx?guid=31689f04-2101-463c-8aeb-5cb2b30ae7e6</trackback:ping>
      <pingback:server>http://www.ntldr.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.ntldr.com/PermaLink,guid,31689f04-2101-463c-8aeb-5cb2b30ae7e6.aspx</pingback:target>
      <dc:creator>Jeffrey Stults, Jr.</dc:creator>
      <wfw:comment>http://www.ntldr.com/CommentView,guid,31689f04-2101-463c-8aeb-5cb2b30ae7e6.aspx</wfw:comment>
      <wfw:commentRss>http://www.ntldr.com/SyndicationService.asmx/GetEntryCommentsRss?guid=31689f04-2101-463c-8aeb-5cb2b30ae7e6</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <div>
          <div>For those of you not subscribed to my Site News feed (or who never look at that
tab), here's the explanation for why the site was down for most of the last week:
</div>
          <div>
          </div>
          <div>
            <a href="#">https://www.ntldr.net/Lists/Site%20News/DispForm.aspx?ID=51</a>
          </div>
          <div>
          </div>
          <div>Importer's Note: 2006-10-03: That post has not been ported to the new system
yet. The link will probably not be updated, so this is basically a dead post.
</div>
        </div>
        <img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=31689f04-2101-463c-8aeb-5cb2b30ae7e6" />
      </body>
      <title>Site downtime Explanation</title>
      <guid isPermaLink="false">http://www.ntldr.com/PermaLink,guid,31689f04-2101-463c-8aeb-5cb2b30ae7e6.aspx</guid>
      <link>http://www.ntldr.com/2005/12/04/SiteDowntimeExplanation.aspx</link>
      <pubDate>Sun, 04 Dec 2005 03:35:00 GMT</pubDate>
      <description>
        &lt;div&gt;
&lt;div&gt;For those of you not subscribed to my Site News feed (or who never look at that
tab), here's the explanation for why the site was down for most of the last week:
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;&lt;a href="#"&gt;https://www.ntldr.net/Lists/Site%20News/DispForm.aspx?ID=51&lt;/a&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;Importer's Note: 2006-10-03: That post has not been ported to the new system
yet. The link will probably not be updated, so this is basically a dead post.
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://www.ntldr.com/aggbug.ashx?id=31689f04-2101-463c-8aeb-5cb2b30ae7e6" /&gt;</description>
      <comments>http://www.ntldr.com/CommentView,guid,31689f04-2101-463c-8aeb-5cb2b30ae7e6.aspx</comments>
      <category>IT</category>
    </item>
  </channel>
</rss>