<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lukas Beeler&#039;s IT Blog</title>
	<atom:link href="http://projectdream.org/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://projectdream.org/wordpress</link>
	<description>The experiences of an SMB IT technician</description>
	<lastBuildDate>Fri, 28 Jan 2011 19:57:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>In memory of Lukas Beeler</title>
		<link>http://projectdream.org/wordpress/2011/01/28/in-memory-of-lukas-beeler/</link>
		<comments>http://projectdream.org/wordpress/2011/01/28/in-memory-of-lukas-beeler/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 19:57:04 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=737</guid>
		<description><![CDATA[In memory of Lukas Beeler, who passed away on September 15, 2010. In silent mourning and loving memory, his family and friends keep Lukas’ website available. Everything changes depending on who walks with us on our journey and who is missing. WE LINGER ON THIS EARTH LIKE TRAVELERS WHO ARRIVE AT NIGHTFALL AT A SHELTER [...]]]></description>
			<content:encoded><![CDATA[<p>In memory of Lukas Beeler, who passed away on September 15, 2010.</p>
<p>In silent mourning and loving memory, his family and friends keep Lukas’ website available. </p>
<p><img alt="" src="http://ihsan.dogan.ch/files/lb/image002.jpg" title="image002.jpg" width="600" height="400" /></p>
<p>Everything changes depending on who walks with us on our journey and who is missing.</p>
<p>WE LINGER ON THIS EARTH LIKE TRAVELERS WHO ARRIVE AT NIGHTFALL AT A SHELTER AND CONTINUE THEIR JOURNEY AT DAWN. WE WALK TOWARDS A DESTINATION FROM SHELTER TO SHELTER, ONE STAGE AFTER THE OTHER.</p>
<p>For each one, the destination holds a different meaning, and each one will use different words to describe it.</p>
<p>We were privileged to walk a part of our journey with Lukas. He has passed the last stage; there we will follow him one day. His gift to each one of us, which he gave so generously, was the time he shared with us. This gift has become even more precious now that he has gone from us.</p>
<p>We hope that all users of this website may find a piece of an answer to their questions on IT related topics, bringing them one step closer to a solution. Save journey!</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2011/01/28/in-memory-of-lukas-beeler/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UEFI continues to haunt me</title>
		<link>http://projectdream.org/wordpress/2010/07/06/uefi-continues-to-haunt-me/</link>
		<comments>http://projectdream.org/wordpress/2010/07/06/uefi-continues-to-haunt-me/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 19:30:12 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=730</guid>
		<description><![CDATA[We have an IBM x3650 M2, that runs a specific business application, using Windows Server 2008 R2 installed in EFI mode. Now, requirements have changed and we need to virtualize this. Unfortunately, SCVMM 2008 R2&#8242;s P2V crashes when run on this machine. disk2vhd can produce a proper VHD from an EFI/UEFI install of Windows Server [...]]]></description>
			<content:encoded><![CDATA[<p>We have an IBM x3650 M2, that runs a specific business application, using Windows Server 2008 R2 installed in EFI mode. Now, requirements have changed and we need to virtualize this.</p>
<p>Unfortunately, SCVMM 2008 R2&#8242;s P2V crashes when run on this machine. <a href="http://technet.microsoft.com/en-us/sysinternals/ee656415.aspx">disk2vhd</a> can produce a proper VHD from an EFI/UEFI install of Windows Server 2008 R2, but there&#8217;s not way of getting it to boot in Hyper-V (i tried a myriad of ways, including several Linux tools that can convert GPT disks to MBR-style disks, got the Windows Boot Manager installed, but it still wouldn&#8217;t boot).</p>
<p>So. What now? I&#8217;m out of reasonable ideas. I have opened a Microsoft support case regarding the SCVMM 2008 R2 P2V crash on an EFI machine, but i&#8217;m not sure i&#8217;ll get a quick out of this. If anyone has any ideas on how to get this fixed, i&#8217;d be thankful for any replies.</p>
<p>If i ever get a solution that does not include reinstalling everything from scratch, i&#8217;ll of course post it.</p>
<p><strong>Update:</strong> Here&#8217;s the official statement:</p>
<blockquote><p>
There are no workarounds for moving a Windows system with an EFI partition to non-EFI architecture. EFI and Itanium are in lockstep. Classic x86 and x64 cannot boot EFI, and there and is no simple switch back to MBR boot.</p>
<p>Es tut mir Leid, das ich keine besseren Informationen für Sie habe aber das Feedback von unseren Development ist sehr eindeutig das keine Kombination von P2V / GPT bzw. EFI zur Zeit unterstützt wird. Mein Vorschlag wäre, unseren Service Request als &#8220;Dokumentations-Bug&#8221; für Sie kostenfrei zu schließen. Was halten Sie von meinen Vorschlag?
</p></blockquote>
<p>Bunch of idiots. Their agent shouldn&#8217;t crash in this scenario anyway and it should be documented that you can&#8217;t migrate machines installed in UEFI modes.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/07/06/uefi-continues-to-haunt-me/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>IBM i Access 7.1 installation hangs indefinitively with a Windows Installer Coordinator window</title>
		<link>http://projectdream.org/wordpress/2010/05/07/ibm-i-access-7-1-installation-hangs-indefinitively-with-a-windows-installer-coordinator-window/</link>
		<comments>http://projectdream.org/wordpress/2010/05/07/ibm-i-access-7-1-installation-hangs-indefinitively-with-a-windows-installer-coordinator-window/#comments</comments>
		<pubDate>Fri, 07 May 2010 13:43:27 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=725</guid>
		<description><![CDATA[If you&#8217;re trying to install IBM i Access 7.1 on a Windows Server 2008 R2 based Remote Desktop Session Host (RDS), formerly known as Terminal Server, you&#8217;ll most likely encounter this issue. A window titled &#8220;Windows Installer Coordinator&#8221; will pop up behind the IBM i Access 7.1 Installer (hidden until you click on it in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2010/05/IBMiaccess71.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2010/05/IBMiaccess71-150x98.png" alt="" title="IBMiaccess71" width="150" height="98" class="alignright size-thumbnail wp-image-726" /></a>If you&#8217;re trying to install <a href="http://www-03.ibm.com/systems/i/software/access/">IBM i Access 7.1</a> on a Windows Server 2008 R2 based Remote Desktop Session Host (RDS), formerly known as Terminal Server, you&#8217;ll most likely encounter this issue.</p>
<p>A window titled &#8220;Windows Installer Coordinator&#8221; will pop up behind the IBM i Access 7.1 Installer (hidden until you click on it in the task bar). This &#8220;Windows Installer Coordinator&#8221; will run indefinitively, without ever successfully installing the application.</p>
<p>Thanks to a helpful guy from IBM Software Support Austria, i now have a solution to this issue. It&#8217;s caused by a new feature in WS08R2 RDS.</p>
<p>It&#8217;s called <a href="http://technet.microsoft.com/en-us/library/dd560667%28WS.10%29.aspx#BKMK_3">Windows Installer RDS Compatibility</a>. If this feature is enabled, IBM i Access 7.1 will not install successfully, and hang at the &#8220;Windows Installer Coordinator&#8221; window.</p>
<p>To successfully install IBM i Access 7.1 on a Windows Server 2008 R2 Remote Desktop Session host, set the following DWORD registry key to 0:</p>
<p><tt>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Terminal Services\TSAppSrv\TSMSI\Enable</tt></p>
<p>It&#8217;s possible that not all keys exist &#8211; in my case, the TSAppSrv and TSMSI keys didn&#8217;t exist yet &#8211; you have to create them manually. After creating this key, you can rerun the installation &#8211; a reboot is not necessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/05/07/ibm-i-access-7-1-installation-hangs-indefinitively-with-a-windows-installer-coordinator-window/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>TMG 2010 seems to be still in Beta</title>
		<link>http://projectdream.org/wordpress/2010/04/27/tmg-2010-seems-to-be-still-in-beta/</link>
		<comments>http://projectdream.org/wordpress/2010/04/27/tmg-2010-seems-to-be-still-in-beta/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 17:35:16 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=720</guid>
		<description><![CDATA[Our apprentice is doing an a project for his final exams (IPA). For that, we&#8217;ve chosen to replace our current Exchange 2007 Edge with a Forefront TMG 2010 / Exchange 2010 Edge combination. As the project progressed, we&#8217;ve found a few extremely irritating and hard-to-debug issues, which needed my involvement to figure out the root [...]]]></description>
			<content:encoded><![CDATA[<p>Our apprentice is doing an a project for his final exams (IPA). For that, we&#8217;ve chosen to replace our current Exchange 2007 Edge with a Forefront TMG 2010 / Exchange 2010 Edge combination.</p>
<p>As the project progressed, we&#8217;ve found a few extremely irritating and hard-to-debug issues, which needed my involvement to figure out the root cause and get them resolved, without compromising the exam results.</p>
<p>Be aware that most of the debugging and research here was mostly done by our apprentice, not by myself.</p>
<p>There are several key issues with TMG, that we&#8217;ve noticed so far:</p>
<h3>IP Blocklist Entries</h3>
<p>If IP Blocklist Entries are present in Exchange 2010 Edge, enabling E-Mail Policy Integration will cause TMG to reject all further changes, with the following error message:</p>
<pre>
Windows Could not Start the "Microsoft Forefront TMG Managed Control" service on Local Computer
Error 0x80070057 : Parameter is incorrect
</pre>
<p>I&#8217;ve found <a href="http://social.technet.microsoft.com/Forums/en/Forefrontedgegeneral/thread/27318f8c-2802-465b-88f1-b1253c23ed30">this solution</a> in the TechNet forums. You need to remove all IP Blocklist and Allow List Entries.</p>
<h3>Extremely slow boot</h3>
<p>Forefront TMG 2010 with Exchange 2010 and FPE 2010 installed will boot extremely slowly, requiring up to 30 Minutes to boot. This issue is caused by the coexistence with Exchange 2010.</p>
<p>Again, i&#8217;ve found <a href="http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/33f6a377-1994-4fa8-af97-23608ffc61a4">a solution</a> in the TechNet forums.</p>
<p>You need to set the service Microsoft Exchange Transport and Microsoft Forefront TMG Managed Control to Automatic (Delayed Start). This will reduce the boot time to about 3 minutes.</p>
<h3>lsass.exe crashes when creating Edge subscriptions</h3>
<p>The next issue we&#8217;ve noticed is that while the initial edge subscription worked, the second one didn&#8217;t. It crashed lsass.exe, which subsequently caused a bluescreen. Not a very nice experience.</p>
<p>Again, we&#8217;ve found <a href="http://social.technet.microsoft.com/Forums/en-ZA/Forefrontedgesetup/thread/37eec54f-c653-401b-b4e7-3a9e0901d0e3">a solution</a> on the TechNet forums, and this is getting worse by the minute. The lsass.exe crash can be mitigated by removing all except one SSL certificate &#8211; not exactly a good approach since a TMG likely has multiple SSL certificates for publishing a variety of services. But it worked. Except that mailflow didn&#8217;t.</p>
<h3>Outgoing Mailflow doesn&#8217;t work with TMG 2010</h3>
<p>Of course, stuff wasn&#8217;t working yet. While incoming mailflow now worked flawlessly, outgoing mailflow didn&#8217;t &#8211; mails where stuck in the queue with &#8220;Primary Target IP Address responded with 421 Unable to establish connection&#8221;.</p>
<p>We&#8217;ve tried to look at this, but everything seemed alright &#8211; but we couldn&#8217;t modify any connectors on the Edge server &#8211; TMG prevented this, and thus we had no Verbose logging from the Receive Connectors. Changing the configuration in the Exchange Edge console resulted in the following error message:</p>
<pre>Forefront TMG detected changes in Microsoft Exchange Server or Microsoft Forefront Protection configuration, and reapplied the e-mail policy configuration on server</pre>
<p>So i&#8217;m not supposed to do that. The TMG console didn&#8217;t give me the option of enabling Verbose logging. We were stumped.</p>
<p>Luckily, further research showed that one could disable the integration between the Exchange Edge role and Forefront TMG &#8211; this was mentioned on <a href="http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/545f5d3d-4871-45b1-8592-8408ef8256d0">this TechNet forums post</a>.</p>
<p>After disabling this integration, i was able to allow Verbose logging. Which didn&#8217;t help at all, since the Exchange 2010 HT just wouldn&#8217;t show up in them, suspecting a deeper issue.</p>
<p>At that point, we&#8217;ve checked the receive connectors that were created by Forefront &#8211; and the internal Receive Connector didn&#8217;t allow Exchange Server Authentication. After setting that to enabled, we were finally able to send mail successfully using the Exchange Edge services.</p>
<h3>Final words</h3>
<p>Forefront TMG 2010 still seems to be in Beta. The integration with Exchange 2010 doesn&#8217;t work as nicely as it should. I hope these things get fixed soon with Hotfixes for TMG 2010. Until then, we&#8217;ve found workarounds for all of these issues.</p>
<p>I&#8217;m publishing this article as quickly as i can, because i&#8217;m most likely not the only one with these issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/04/27/tmg-2010-seems-to-be-still-in-beta/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>TechDays 2010 Basel will be the last that I have attended</title>
		<link>http://projectdream.org/wordpress/2010/04/07/techdays-2010-basel-will-be-the-last-that-i-have-attended/</link>
		<comments>http://projectdream.org/wordpress/2010/04/07/techdays-2010-basel-will-be-the-last-that-i-have-attended/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 17:30:00 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=716</guid>
		<description><![CDATA[Today marks the second and last day of TechDays 2010 in Basel. I have attended TechDays 05, 06, 07, 08 and 2010. While i&#8217;ve always had something complain about, there was always something to gain from attending. Not this time. When reading this, keep in mind that i&#8217;ve only attended IT Pro Sessions (with the [...]]]></description>
			<content:encoded><![CDATA[<p>Today marks the second and last day of <a href="http://www.techdays.ch">TechDays 2010</a> in Basel.</p>
<p>I have attended TechDays 05, 06, 07, 08 and 2010. While i&#8217;ve always had something <a href="http://projectdream.org/wordpress/?s=techdays">complain about</a>, there was always something to gain from attending. Not this time.</p>
<p>When reading this, keep in mind that i&#8217;ve only attended IT Pro Sessions (with the exception of the Windows Phone 7 Developer Briefing).</p>
<p>There were to many things that have gone wrong. </p>
<ul>
<li>The keynote was boring and it didn&#8217;t even remotely have anything to do with the job of an IT Pro or a Developer. The keynote speaker also used a MacBook with OS X/Keynote.app. Seriously.</li>
<li>The food was worse than what I got to eat at my Berufsschule (which wasn&#8217;t very good).</li>
<li>The long lines were still there &#8211; waiting 20 minutes in line for bad food isn&#8217;t my idea of spending the day. They should&#8217;ve solved this problem by now.</li>
<li>No more English talks. Why? I think we could use some experts.</li>
<li>All the talks were very basic. No In-Depth stuff. Nothing to learn.</li>
<li>I don&#8217;t want a basic talk about what OCS 2007 R2 can do. We&#8217;ve been using this for two years. It&#8217;s old news. Talk about Wave 14.</li>
<li>Giving a basic intro on what SCVMM and Hyper-V are is not an IT Pro track &#8211; these technologies have been out since years and everyone that&#8217;s interested will already know those basics</li>
<li>Make sure your stuff works. 75% of the demos did not work. Most of them because of bad internet connectivity. Yeah, i guess moving all the stuff to the &#8220;cloud&#8221; is a good idea.</li>
</ul>
<p>The location and the whole ship theme was okay though. The evening event was also nice, and they did have good food there (different catering organization). Not sure what some danish bloke was doing there yelling &#8220;in the cloud&#8221; about 50 times. I wanted to see some chair-throwing.</p>
<p>Another interesting tidbit: The number of iPhones at the event. I&#8217;ve seen more iPhones than WinMo phones.</p>
<p>So, did you attend TechDays? What did you think about it?</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/04/07/techdays-2010-basel-will-be-the-last-that-i-have-attended/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>My OCZ Vertex 120GB is dying</title>
		<link>http://projectdream.org/wordpress/2010/03/21/my-ocz-vertex-120gb-is-dying/</link>
		<comments>http://projectdream.org/wordpress/2010/03/21/my-ocz-vertex-120gb-is-dying/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 08:44:51 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=709</guid>
		<description><![CDATA[I currently have two SSDs &#8211; an OCZ Vertex 120GB bought before Intel priced it&#8217;s SSDs competitively (April 2009) and an Intel X25-M G2 160GB i bought at launch (September 2009). The OCZ Vertex is the one i use in my work laptop, and the Intel X25-M G2 is the one i use in my [...]]]></description>
			<content:encoded><![CDATA[<p>I currently have two SSDs &#8211; an OCZ Vertex 120GB bought before Intel priced it&#8217;s SSDs competitively (April 2009) and an Intel X25-M G2 160GB i bought at launch (September 2009). The OCZ Vertex is the one i use in my work laptop, and the Intel X25-M G2 is the one i use in my system at home. Both see extensive use, and both have always been used with Windows 7, which is TRIM-enabled.</p>
<p>The most important thing between the laptop and the desktop is that i&#8217;m using BitLocker on the laptop, which might have an influence on things. I&#8217;ve always been using BitLocker on the SSD, so it would seem strange that this is now suddenly an issue.</p>
<p>I&#8217;ve always been aggressive about SSD firmware updates, after a good backup. I&#8217;ve upgraded both the Vertex and the Intel drives to be TRIM capable as soon as the respective firmware was out.</p>
<p>Unfortunately, a few days after using the OCZ Vertex in my new laptop, it started to have serious hickups &#8211; during which no IO would take place (perfmon disk queue shooting up to 50). During this time, the HDD light on the laptop is not lit.</p>
<p>I&#8217;ve tried to make sure that this issue was related to the SSD, so i ran HDTune benchmark:</p>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2010/03/HDTune_Benchmark_.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2010/03/HDTune_Benchmark_.png" alt="" title="HDTune_Benchmark_&amp;#" width="570" height="460" class="alignnone size-full wp-image-711" /></a></p>
<p>This looked bad. Further investigation showed that there was a new Firmware out &#8211; 1.5. I&#8217;ve upgrade to Firmware 1.5, which supposedly had a Garbage Collection and TRIM support. After upgrading to 1.5, the hickups became much worse &#8211; the laptop needed about an hour just to boot up.</p>
<p>After looking at and posting on the OCZ support forum, i was told that i&#8217;d need to wait for Garbage collection to kick in. I let my laptop sit for a night, during which it crashed and the subsequent reboot was stuck on a &#8220;No harddisk found&#8221; message from the BIOS. Things looked bleak.</p>
<p>Further replies on the OCZ support forum requested that i do a <a href="http://www.ocztechnologyforum.com/forum/showthread.php?69503-How-to-use-OCZ-Sanitary-Erase">sanitary erase</a>, which would reset the disk to pristine performance levels (and delete all the data on it).</p>
<p>Unfortunately, the machine was too slow to run a Windows Complete PC Backup (wasn&#8217;t finished after 4 hours in). Fortunately, all the important data on my laptop is backed up using the <a href="http://scdpm.blogspot.com/2009/11/dpm-2010-client-based-protection.html">Client Protection of DPM 2010</a>, meaning all i had to do was reinstall my apps and i&#8217;d be good to go.</p>
<p>After reinstalling Windows 7, i installed the most important apps and then reenabled BitLocker protection &#8211; during which the hickups started happening again. The laptop would sometimes hang for 20-30 seconds, and then continue on on it&#8217;s merry way.</p>
<p>At this point, i went to sleep and let the laptop idle at the boot selection screen, so that the garbage collection could do it&#8217;s magic. </p>
<p>And now here we are, 8 hours later. While the read performance using HD Tune is nowwhere near as bad as it was before the sanitary erase, the write performance is stil abysmal.</p>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2010/03/HDTune_Benchmark_OCZ-VERTEX.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2010/03/HDTune_Benchmark_OCZ-VERTEX.png" alt="" title="HDTune_Benchmark_OCZ-VERTEX" width="570" height="460" class="alignnone size-full wp-image-712" /></a></p>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2010/03/as-ssd-bench-OCZ-VERTEX-ATA-D-21.03.2010-09-41-49.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2010/03/as-ssd-bench-OCZ-VERTEX-ATA-D-21.03.2010-09-41-49.png" alt="" title="as-ssd-bench OCZ-VERTEX ATA D 21.03.2010 09-41-49" width="503" height="490" class="alignnone size-full wp-image-713" /></a></p>
<p>For Comparison, here&#8217;s my Intel X25-M G2:</p>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2010/03/as-ssd-bench-INTEL-SSDSA2M160-21.03.2010-09-13-221.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2010/03/as-ssd-bench-INTEL-SSDSA2M160-21.03.2010-09-13-221.png" alt="" title="as-ssd-bench INTEL SSDSA2M160 21.03.2010 09-13-22" width="503" height="501" class="alignnone size-full wp-image-714" /></a></p>
<p>What now? I think i will RMA the drive. It&#8217;s the only choice i have left at this point.</p>
<p>If anyone has a better idea, give me a whirl.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/03/21/my-ocz-vertex-120gb-is-dying/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lenovo ThinkPad T510</title>
		<link>http://projectdream.org/wordpress/2010/03/16/lenovo-thinkpad-t510/</link>
		<comments>http://projectdream.org/wordpress/2010/03/16/lenovo-thinkpad-t510/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 15:43:57 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Hardware]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=707</guid>
		<description><![CDATA[Since December 2008, i&#8217;ve used my ThinkPad W500 as my work laptop. We&#8217;ve bought this as part of a promotion package. The W500 i had had a 15.4&#8243; 1920&#215;1200 Panel, which wasn&#8217;t too great. While the high fidelity was certainly nice, the screen was very, very dark. It could only be used indoors, and required [...]]]></description>
			<content:encoded><![CDATA[<p>Since December 2008, i&#8217;ve used my ThinkPad W500 as my work laptop. We&#8217;ve bought this as part of a promotion package.</p>
<p>The W500 i had had a 15.4&#8243; 1920&#215;1200 Panel, which wasn&#8217;t too great. While the high fidelity was certainly nice, the screen was very, very dark. It could only be used indoors, and required you to darken the room on sunny days.</p>
<p>Today i&#8217;ve had the chance to upgrade from the W500 to a T510, which i did. So far, i&#8217;m very much impressed with the changes Lenovo has do to this device. The W500 is running Windows 7 Enterprise x64.</p>
<ul>
<li>New controls for volume, microphone mute. Much easier to use than before</li>
<li>New bigger and multitouch capable touchpad. As i prefer the touchpad over the TrackPoint, this is something that helps me tremendously</li>
<li>Integrated Camera and eSATA connectivity</li>
<li>Improved connectivity layout</li>
</ul>
<p>There&#8217;s only one thing that i don&#8217;t like very much right now &#8211; the redesigned keyboard. As part of my job i deal with IBM&#8217;s IBM i platform, which still makes use the Function keys &#8211; which have all been shifted to the right for one key. So i regularly press F3 instead of F4, but chances are i will get used to it.</p>
<p>There&#8217;s one thing that worked very well &#8211; moving my Windows installation from the W500 to the T510. I&#8217;ve disabled Bitlocker protection, removed the OCZ Vertex SSD from the W500, placed it into the T510, booted it up, Windows installed several new drivers. Then, i installed the Intel LAN drivers from an USB stick, rebooted once more and installed the rest of the necessary drivers from Lenovo&#8217;s driver matrix. The whole process was done in less than half an hour, and reenabling Bitlocker protection was a breeze. </p>
<p>Windows 7 automatically reactivated by contacting our KMS servers, and i&#8217;ve had to reactivate my Office 2010 Beta manually, which also worked flawlessly.</p>
<p>While this portability is great (and also existed with Vista), it&#8217;s something I was able todo with Linux back in 2004 (assuming of course that the kernel had the storage drivers you required).</p>
<p>I&#8217;ve been using ThinkPads exclusively since 2004 &#8211; my first ThinkPad was an R51 and my first new laptop (my first laptop was a Compaq Armada i&#8217;ve bought used for 50.- CHF). When Lenovo took over the brand, i wasn&#8217;t to sure what to think of it, but having gone through several iterations of ThinkPad devices now (R51, T60, W500 and now the T510) i can see that Lenovo is commited to provide further well built, high performance devices. </p>
<p>Both the T60 and the W500 are still in service, neither of them are broken. The T60 is used by my apprentice and around 3 or 4 years old. We&#8217;ve replaced the Mouse and Keyboard to mitigate the wear and tear of several 40 hour work weeks on the device, but aside from that it stills works great.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/03/16/lenovo-thinkpad-t510/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Cablecom did it again</title>
		<link>http://projectdream.org/wordpress/2010/02/23/cablecom-did-it-again/</link>
		<comments>http://projectdream.org/wordpress/2010/02/23/cablecom-did-it-again/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 19:39:22 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=705</guid>
		<description><![CDATA[Another Cablecom outage &#8211; this time, it was nation wide and affected both Business and end user accounts. Interestingly, the Hotline wasn&#8217;t reachable either &#8211; busy signal, Swisscom text &#8220;Leitung gestört&#8221; or simply &#8220;Call Failed&#8221;. Lasted from 19:33 to 20:30, but it looks like everything is back online now.]]></description>
			<content:encoded><![CDATA[<p>Another Cablecom outage &#8211; this time, it was nation wide and affected both Business and end user accounts. </p>
<p>Interestingly, the Hotline wasn&#8217;t reachable either &#8211; busy signal, Swisscom text &#8220;Leitung gestört&#8221; or simply &#8220;Call Failed&#8221;.</p>
<p>Lasted from 19:33 to 20:30, but it looks like everything is back online now.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/02/23/cablecom-did-it-again/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Hyper-V 2008 R2 and Linux guests</title>
		<link>http://projectdream.org/wordpress/2010/02/17/hyper-v-2008-r2-and-linux-guests/</link>
		<comments>http://projectdream.org/wordpress/2010/02/17/hyper-v-2008-r2-and-linux-guests/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 21:14:46 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=703</guid>
		<description><![CDATA[I&#8217;m still running a Linux box to run a legacy business app that&#8217;s about to be replaced, and runs a few legacy VPNs. Setup ages ago, when i didn&#8217;t have the experience i have today, the setup on the machine was a mess &#8211; originally installed using testing of what was-to-be Debian 3.1 with several [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m still running a Linux box to run a legacy business app that&#8217;s about to be replaced, and runs a few legacy VPNs. Setup ages ago, when i didn&#8217;t have the experience i have today, the setup on the machine was a mess &#8211; originally installed using testing of what was-to-be Debian 3.1 with several custom packages (Postfix, Apache, OpenVPN, etc.), this has been overdue for some fixup work for quite some time.</p>
<p>As a disclaimer, i realize that Debian in any version isn&#8217;t a supported OS on Hyper-V R2 &#8211; i just want to tell of my experiences with this unsupported configuration.</p>
<p>The hardware, an aging IBM xSeries 306m with a Pentium 4 CPU wasn&#8217;t getting any younger and after a drive failure about half a year ago that lead to a system crash (No data loss though &#8211; it just crashed the machine, that&#8217;s Software RAID for you), it was finally time to modernize this.</p>
<p>The plan is to consolidate all our DMZ workloads (ISA, OCS Edge, XMPP Gateway, Exchange Edge) on Hyper-V 2008 R2 and doing the trickiest part first seemed like a good idea.</p>
<p>So i created a new VM using SCVMM 2008 R2, selected Other Linux 32bit as the guest OS, inserted a Debian 5.0 netboot CD and that&#8217;s where the problems already started. While the installation worked well in general, the Framebuffer used by the Debian installed is awfully slow. So it took me about half an hour just to get the install done (on a 5GB partition of the 80GB VHD).</p>
<p>After finishing the installation, i formatted the rest of the disk appropiately and then used rsync to transfer the machine contents over. A short bit after reconfiguring Grub, i could choose to boot either the transferred OS with it&#8217;s kernel, or the Debian 5 rescue system i installed alongside.</p>
<p>Booting the transferred system worked well enough, but the tulip driver wasn&#8217;t compiled into that (custom) kernel and building the module failed. So i read up a bit, and realized that the newest kernel (2.6.32.8) shipped with experimental Hyper-V VMbus drivers, that allowed synthetic NICs to be used.</p>
<p>I tried to compile the kernel after chrooting into the old installation, but it failed because gcc was too old. Not to worry, i compiled it in the rescue system, but couldn&#8217;t install the dpkg that make-kpkg created. So i installed it manually, which worked pretty well.</p>
<p>One reboot later, i was back in business with the extremely verbose Hyper-V drivers cluttering up dmesg, but the Synthetic NICs showed up as seth0 &#8211; seth2.  After quickly changing all the necessary configuration files, everything was working.</p>
<p>After a bit of more testing, i disconnected the physical machine from the network and plugged the VM into the production VLANs.</p>
<p>I tested everything thoroughly and didn&#8217;t find any issues. Sent out an information mail and continued on my merry way.</p>
<p>Half an hour later, i decided to do a quick systems check again &#8211; and i realized that the external interface (seth2 in this case) wasn&#8217;t working anymore. tcpdump showed no packets being received and other machines in the same VLANs didn&#8217;t see any answers to their ARP requests either. So i rebooted the VM, and everything was working again. No error messages of any kind, neither in dmesg nor in the system logs or on the Hyper-V host.</p>
<p>Hoping this was just a fluke, i waited until it happened again &#8211; which it did, roughly 10 minutes later. So i decided to skip on the synthetic devices and go with emulated NICs and the tulip driver.</p>
<p>Everything came back up, but i couldn&#8217;t ping any devices on the eth0 VLAN from the start, but the other two interfaces worked. </p>
<p>After a few more tries, i arrived at a configuration that has now been stable for 4 hours and 26 minutes, which sounds good so far. For this, i configured a single synthetic NIC that i used as a replacement for the non-working eth0 and three tulip NICs (of which the first was unused).</p>
<p>There are other things that also worry me:</p>
<p>Every reboot of the Linux machine created the following event log entry on the Hyper-V host:</p>
<p><tt><br />
'LINUX' was reset because an unrecoverable error occurred on a virtual processor that caused a triple fault. If the problem persists, contact Product Support. (Virtual machine ID [])</tt></p>
<p>Loading the synthetic NIC drivers logs the following in the event log on the Hyper-V host:</p>
<p><tt><br />
Networking driver on 'LINUX' loaded but has a different version from the server.  Server version 3.2  Client version 0.2 (Virtual machine ID []). The device will work, but this is an unsupported configuration. This means that technical support will not be provided until this problem is resolved. To fix this problem, upgrade the integration services. To upgrade, connect to the virtual machine and select Insert Integration Services Setup Disk from the Action menu.<br />
</tt></p>
<p>Loading the synthetic NIC drivers also logs all this on the Linux side of things:</p>
<p><tt><br />
VMBUS_DRV: Vmbus initializing.... current log level 0x1f1f0006 (1f1f,6)<br />
VMBUS: +++++++ Build Date=Feb 17 2010 12:37:00 +++++++<br />
VMBUS: +++++++ Build Description=Version 2.0 +++++++<br />
VMBUS: +++++++ Vmbus supported version = 13 +++++++<br />
VMBUS: +++++++ Vmbus using SINT 2 +++++++<br />
VMBUS: Windows hypervisor detected! Retrieving more info...<br />
VMBUS: Vendor ID: Microsoft Hv<br />
VMBUS: Interface ID: Hv#1<br />
VMBUS: OS Build:7600-6.1-16-0.16485<br />
VMBUS: Hypercall page VA=f80c9000, PA=0x36afe000<br />
VMBUS_DRV: irq 0x5 vector 0x35<br />
VMBUS: SynIC version: 1<br />
VMBUS: Vmbus connected!!<br />
VMBUS_DRV: generating uevent - VMBUS_DEVICE_CLASS_GUID={c5295816-f63a-4d5f-8d1a4daf999ca185}<br />
VMBUS: Channel offer notification - child relid 1 monitor id 0 allocated 1, type {32412632-86cb-44a2-9b5c50d1417354f5} instance {00000000-0000-8899-0000000000000000}<br />
hv_netvsc: module is from the staging directory, the quality is unknown, you have been warned.<br />
NETVSC_DRV: Netvsc initializing....<br />
VMBUS_DRV: child driver (f80dc570) registering - name netvsc<br />
VMBUS: Channel offer notification - child relid 2 monitor id 255 allocated 0, type {cfa8b69e-5b4a-4cc0-b98b8ba1a1f3f95a} instance {58f75a6d-d949-4320-99e1a2a2576d581c}<br />
VMBUS_DRV: generating uevent - VMBUS_DEVICE_CLASS_GUID={32412632-86cb-44a2-9b5c50d1417354f5}<br />
VMBUS_DRV: child device (f73a8634) registered<br />
VMBUS: Channel offer notification - child relid 9 monitor id 1 allocated 1, type {f8615163-df3e-46c5-913ff2d2f965ed0e} instance {9d44a66e-4b09-41d5-80d807ae24bf537d}<br />
VMBUS_DRV: generating uevent - VMBUS_DEVICE_CLASS_GUID={cfa8b69e-5b4a-4cc0-b98b8ba1a1f3f95a}<br />
VMBUS_DRV: child device (f73a5a34) registered<br />
VMBUS: Channel offer notification - child relid 1 monitor id 0 allocated 1, type {32412632-86cb-44a2-9b5c50d1417354f5} instance {00000000-0000-8899-0000000000000000}<br />
VMBUS_DRV: generating uevent - VMBUS_DEVICE_CLASS_GUID={f8615163-df3e-46c5-913ff2d2f965ed0e}<br />
VMBUS_DRV: device object (f73a5ee4) set to driver object (f80dc5c0)<br />
VMBUS: Channel offer notification - child relid 2 monitor id 255 allocated 0, type {cfa8b69e-5b4a-4cc0-b98b8ba1a1f3f95a} instance {58f75a6d-d949-4320-99e1a2a2576d581c}<br />
VMBUS: Channel offer notification - child relid 9 monitor id 1 allocated 1, type {f8615163-df3e-46c5-913ff2d2f965ed0e} instance {9d44a66e-4b09-41d5-80d807ae24bf537d}<br />
VMBUS: channel f73aac00 open success!!<br />
NETVSC: *** NetVSC channel opened successfully! ***<br />
NETVSC: Sending NvspMessageTypeInit...<br />
NETVSC: NvspMessageTypeInit status(1) max mdl chain (34)<br />
NETVSC: Sending NvspMessage1TypeSendNdisVersion...<br />
NETVSC: Establishing receive buffer's GPADL...<br />
NETVSC: Sending NvspMessage1TypeSendReceiveBuffer...<br />
NETVSC: Receive sections info (count 1, offset 0, endoffset 1048000, suballoc size 1600, num suballocs 655)<br />
NETVSC: Establishing send buffer's GPADL...<br />
NETVSC: Sending NvspMessage1TypeSendSendBuffer...<br />
NETVSC: *** NetVSC channel handshake result - 0 ***<br />
NETVSC: Device 0xf6552e80 mac addr 00155d031a09<br />
NETVSC: Device 0xf6552e80 link state up<br />
VMBUS_DRV: child device (f73a5e34) registered<br />
</tt></p>
<p>So, it works. But not without troubles. I&#8217;ve still got the physical machine to fall back on, but i sure hope Microsoft will get this to work better.</p>
<p>These issues are the reason why i decided to deploy my private server using ESXi instead of Hyper-V &#8211; because i need both Linux and Windows guests.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/02/17/hyper-v-2008-r2-and-linux-guests/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>DPM 2010 hangs at replica creation when backing up Hyper-V VMs</title>
		<link>http://projectdream.org/wordpress/2010/02/14/dpm-2010-hangs-at-replica-creation-when-backing-up-hyper-v-vms/</link>
		<comments>http://projectdream.org/wordpress/2010/02/14/dpm-2010-hangs-at-replica-creation-when-backing-up-hyper-v-vms/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 21:03:27 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=699</guid>
		<description><![CDATA[I&#8217;ve been playing with DPM 2010 and SCVMM 2008 R2, planning for our new development lab. I&#8217;ve setup a new Hyper-V server on a x3650 M2 (using server core) &#8211; i&#8217;ve also installed the latest Broadcom NetXtreme II drivers, all the firmware updates, all the best practices you do. Setting up the machine, transferring VMs [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been playing with DPM 2010 and SCVMM 2008 R2, planning for our new development lab.</p>
<p>I&#8217;ve setup a new Hyper-V server on a x3650 M2 (using server core) &#8211; i&#8217;ve also installed the latest Broadcom NetXtreme II drivers, all the firmware updates, all the best practices you do.</p>
<p>Setting up the machine, transferring VMs from another host (using BITS) worked well and fast, no issues.</p>
<p>And then i installed the DPM agent, started a backup. Two hours later, it was still stuck at &#8220;Replica creation in progress&#8221;.</p>
<p>I tried reading through the DPM agent logs, through the DPM server logs, looked if DPM created shadow copies (using <tt>vssadmin list shadows</tt>).</p>
<p>After two hours of fruitless searching (which included restarting everything), i wasn&#8217;t any further to a solution.</p>
<p>Well, backup wasn&#8217;t working right, but this was just a testing environment, so i decided to do other stuff. </p>
<p>A while later, i ran <tt>netstat -t</tt> to lookup connections &#8211; and also realized that TCP Chimney Offloading was still active. So i disabled it using <tt>netsh int tcp set global chimney=disabled</tt>. Just a few seconds later, the utilization of the management network adapter jumped to 100% and 5 minutes later, all the VMs were replicated to the DPM server.</p>
<p>So, if you&#8217;re having issues with DPM backups being stuck, check the status of your network offloading.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/02/14/dpm-2010-hangs-at-replica-creation-when-backing-up-hyper-v-vms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blog now moved to Windows Server 2008 R2</title>
		<link>http://projectdream.org/wordpress/2010/01/20/blog-now-hosted-on-windows-serve/</link>
		<comments>http://projectdream.org/wordpress/2010/01/20/blog-now-hosted-on-windows-serve/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 22:27:10 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=691</guid>
		<description><![CDATA[The old DL140 running Debian Linux finally died this Monday, due to a hard drive error which Linux software raid couldn&#8217;t deal with. Luckily, the second disk survived and i didn&#8217;t have to test my disaster recovery strategy. If you&#8217;re reading this, this blog is now hosted on Windows Server 2008 R2 Web Edition (Yay [...]]]></description>
			<content:encoded><![CDATA[<p>The old DL140 running Debian Linux finally died this Monday, due to a hard drive error which Linux software raid couldn&#8217;t deal with. Luckily, the second disk survived and i didn&#8217;t have to test my disaster recovery strategy.</p>
<p>If you&#8217;re reading this, this blog is now hosted on Windows Server 2008 R2 Web Edition (Yay NFR promotions!). There may still be some kinks that have to be worked out, because this was quite a rush job. Leave a comment if you find any issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/01/20/blog-now-hosted-on-windows-serve/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>cablecom hispeed business SLA and availability</title>
		<link>http://projectdream.org/wordpress/2010/01/11/cablecom-hispeed-business-sla-and-availability/</link>
		<comments>http://projectdream.org/wordpress/2010/01/11/cablecom-hispeed-business-sla-and-availability/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 15:45:24 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=684</guid>
		<description><![CDATA[After this weekends cablecom hispeed business fiasco, i talked with cablecom about offering us a more reliable service. Our current cablecom hispeed business line is ADSL2+ with 20/2 megabits. While the upstream is too low for my taste, i haven&#8217;t really seen better offers. I talked with a sales on the phone &#8211; for about [...]]]></description>
			<content:encoded><![CDATA[<p>After this weekends <a href="http://projectdream.org/wordpress/2010/01/08/cablecom-hispeed-business-sucks/">cablecom hispeed business fiasco</a>, i talked with cablecom about offering us a more reliable service.</p>
<p>Our current <a href="http://www.cablecom.biz/index/kleinunternehmen.htm">cablecom hispeed business</a> line is ADSL2+ with 20/2 megabits. While the upstream is too low for my taste, i haven&#8217;t really seen better offers.</p>
<p>I talked with a sales on the phone &#8211; for about 200 CHF more, we could get 20/2 SDSL (which sounded strange) and a 20/2 DOCSIS backup line, together with a &#8220;Bronze&#8221; level SLA. This sounded very attractive to me and i told the sales to send me the offer.</p>
<p>In the written offer, the ominous 20/2 SDSL was downgraded to 4/4 SDSL (which made much more sense). Of course, downgrading our internet connection from 20/2 to 4/4 seemed like a rather bad idea. We have about 30 people working here everyday, and almost all of them really use the internet to do their job. We&#8217;ve upgraded from 6/.6 ADSL to the current cablecom connection, because 6 megabit downstream wasn&#8217;t fast enough.</p>
<p>So i asked what else they could offer us &#8211; for 500 CHF more than we pay today, we could get 8/8 SDSL with a 20/2 DOCSIS backup. That still didn&#8217;t sound interesting to me.</p>
<p>I, personally, think 1000 CHF per month would be okay for a redundant 20/20 connection or something in this direction. My current connection at home is 25/2.5 &#8211; for 75 CHF a month. It works well enough, and the last failure i had was fixed in three days. Just like the failure we had on our 500 CHF per month 20/2 connection. This should be a telltale sign that something is very wrong with either the pricing or the service level.</p>
<p>The next question i asked if they could do a 20/2 ADSL with a 20/2 DOCSIS backup. Apparently, that&#8217;s not technically possible right now, but they might introduce this later this year. That sounds attractive to me.</p>
<p>All in all, i still think that <a href="http://www.cablecom.biz/index/kleinunternehmen.htm">cablecom hispeed business</a> sucks. They can&#8217;t be bothered to do a 5 minute fix in a 2 hour time window on Friday evening. Then, they make one ludicrous offer that noone can take serious after the other.</p>
<p>I&#8217;m pretty sure that cablecom doesn&#8217;t really understand what small businesses need.</p>
<p>As a side note, if you work for an ISP and think you can make us a better offer than cablecom, i&#8217;d be very much interested. Send your stuff to <tt>l dot beeler at acommit dot ch</tt>. We will be moving to Horgen/ZH at Seestrasse 202 in March 2010 and need 32 static IP addresses.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/01/11/cablecom-hispeed-business-sla-and-availability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>cablecom hispeed business sucks</title>
		<link>http://projectdream.org/wordpress/2010/01/08/cablecom-hispeed-business-sucks/</link>
		<comments>http://projectdream.org/wordpress/2010/01/08/cablecom-hispeed-business-sucks/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 22:03:52 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=670</guid>
		<description><![CDATA[Since about one and a half year, we&#8217;ve been using cablecom hispeed business for internet access. Shortly after installing the line back in 2008, we&#8217;ve ran into an issue where cablecom hispeed business blocks GRE packets. After almost three days and speaking with a variety of technicians, they were finally able to resolve the issue. [...]]]></description>
			<content:encoded><![CDATA[<p>Since about one and a half year, we&#8217;ve been using <a href="http://www.cablecom.biz/index/kleinunternehmen.htm">cablecom hispeed business</a> for internet access. </p>
<p>Shortly after installing the line back in 2008, we&#8217;ve ran into an issue  where <a href="http://projectdream.org/wordpress/2008/08/17/cablecom-hispeed-business-blocks-gre-packets/">cablecom hispeed business blocks GRE packets</a>. After almost three days and speaking with a variety of technicians, they were finally able to resolve the issue.</p>
<p>Now, we&#8217;ve run into another, much more grave problem. Since about 15:45, a variety of hosts on the Internet aren&#8217;t reachable and of course several other hosts can&#8217;t reach us.</p>
<p>Of course this isn&#8217;t a clear-cut &#8220;my DSL modem has no link&#8221; issue &#8211; so cablecom currently isn&#8217;t even trying to fix the problem. I&#8217;ve been on the phone twice, never get any callbacks and don&#8217;t get any updates on the state of the problem resolution.</p>
<p>Fact is, some hosts can reach our <a href="http://mail.acommit.ch">OWA 2010</a> and some can&#8217;t. Nasty thing is, Swisscom&#8217;s GPRS/UMTS IP addresses can&#8217;t &#8211; this means no push-email for all 35 of our employees. Since we&#8217;re working for a rather important project (ERP and POS implementation) this weekend, this is a big issue for us.</p>
<p>It also looks interesting in a tcpdump &#8211; some packets just get lost &#8211; and from other hosts it works without any issues.</p>
<p>The 77. addresses are cablecom hispeed business, the 217. are my cablecom residential connection. In the first part, we see a TCP connection to port 80. In the second part, we see a ping -t. As you can see, there are a lot of dropped packets.</p>
<pre>
23:12:12.629457 IP 217.162.252.98.18417 &gt; 77.59.216.227.80: S 4006182815:4006182815(0) win 8192 &lt;mss 1460,nop,wscale 2,nop,nop,sackOK&gt;
23:12:12.629479 IP 77.59.216.227.80 &gt; 217.162.252.98.18417: S 1280362581:1280362581(0) ack 4006182816 win 5840 &lt;mss 1460,nop,nop,sackOK,nop,wscale 6&gt;
23:12:15.826736 IP 77.59.216.227.80 &gt; 217.162.252.98.18417: S 1280362581:1280362581(0) ack 4006182816 win 5840 &lt;mss 1460,nop,nop,sackOK,nop,wscale 6&gt;
23:12:22.026734 IP 77.59.216.227.80 &gt; 217.162.252.98.18417: S 1280362581:1280362581(0) ack 4006182816 win 5840 &lt;mss 1460,nop,nop,sackOK,nop,wscale 6&gt;
23:12:34.026733 IP 77.59.216.227.80 &gt; 217.162.252.98.18417: S 1280362581:1280362581(0) ack 4006182816 win 5840 &lt;mss 1460,nop,nop,sackOK,nop,wscale 6&gt;

08:51:49.642995 IP 217.162.252.98 &gt; 77.59.216.227: icmp 40: echo request seq 65
08:51:49.643024 IP 77.59.216.227 &gt; 217.162.252.98: icmp 40: echo reply seq 65
08:52:00.641330 IP 217.162.252.98 &gt; 77.59.216.227: icmp 40: echo request seq 68
08:52:00.641345 IP 77.59.216.227 &gt; 217.162.252.98: icmp 40: echo reply seq 68
08:53:16.641813 IP 217.162.252.98 &gt; 77.59.216.227: icmp 40: echo request seq 84
08:53:16.641829 IP 77.59.216.227 &gt; 217.162.252.98: icmp 40: echo reply seq 84
</pre>
<p>Cablecom gets 180 CHF per month for 24/7 support. The case has now been open for 7 hours, with no resolution in sight. There&#8217;s no escalation path and there are no workarounds &#8211; we don&#8217;t have redundant connections.</p>
<p>Interestingly, one of our customers who also uses cablecom hispeed business had a similar issue, that lasted for roughly three weeks &#8211; one of their IP addresses wasn&#8217;t reachable externally, from one minute to the other. Unfortunately for us, all of our public IP addresses are affected by this issue, so we don&#8217;t have an easy workaround.</p>
<p>Of course, for some part we&#8217;re also to blame. Luckily i&#8217;m not one of the higher ups who gambled with non-redundant internet connections and lost.</p>
<p>Have you made negative experiences with cablecom hispeed business? Positive ones? Was support able to fix your issues quickly?</p>
<p><strong>Update:</strong> I&#8217;ve called cablecom again on Saturday at 09:00. Apparently, these sort of issues are supported on a best-effort base from 9 to 5, and not covered by our 24/7 support contract. We will have to wait until monday &#8211; they will not look at this issue further during the weekend.</p>
<p><strong>Update:</strong> Monday morning, 11:00. Problem is still unsolved.</p>
<pre>
--- hor-fw-01.acommit.ch ping statistics ---
20 packets transmitted, 3 received, 85% packet loss, time 19012ms
rtt min/avg/max/mdev = 20.490/21.360/22.585/0.891 ms
</pre>
<p><strong>Update:</strong> Monday morning, 11:36. Problem is now solved. According to the Tech i talked to, the he fixed the issue in 5 minutes. He could&#8217;ve done that on Friday, but apparently noone at cablecom felt like doing so. The issue was that cablecom configured our new line for the planned office move and configured load sharing between the new line for the new office and the old line. Since the new line didn&#8217;t physically exist yet, half of the packets were dropped. </p>
<p>Thanks to the Tech who fixed the issue, no thanks to cablecom in general for wasting an entire weekend on what could&#8217;ve been a five minute fix on Friday evening.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2010/01/08/cablecom-hispeed-business-sucks/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Acommit AG is hiring, Part 2</title>
		<link>http://projectdream.org/wordpress/2009/12/31/acommit-ag-is-hiring-part-2/</link>
		<comments>http://projectdream.org/wordpress/2009/12/31/acommit-ag-is-hiring-part-2/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 07:53:42 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=668</guid>
		<description><![CDATA[The company i&#8217;m working for, Acommit AG, is hiring again. Currently, we&#8217;re looking for: Project Manager (PDF) Sales (PDF)]]></description>
			<content:encoded><![CDATA[<p>The company i&#8217;m working for, <a href="http://www.acommit.ch">Acommit AG</a>, is hiring again.</p>
<p>Currently, we&#8217;re looking for:</p>
<p><a href="http://www.acommit.ch/Portals/0/Stelleninserat-Projektleiter__V2.pdf">Project Manager</a> (PDF)<br />
<a href="http://www.acommit.ch/Portals/0/Stelleninserat-Verkaufspers%C3%B6nlichkeit_V1.pdf">Sales</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/12/31/acommit-ag-is-hiring-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange 2010 Migration done</title>
		<link>http://projectdream.org/wordpress/2009/11/14/exchange-2010-migration-done/</link>
		<comments>http://projectdream.org/wordpress/2009/11/14/exchange-2010-migration-done/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 08:03:27 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Exchange]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=666</guid>
		<description><![CDATA[Exchange 2010 was released last Monday, the 9th. Today, we have Saturday the 14th &#8211; and i&#8217;m done with the Migration to Exchange 2010. Sure, there are loads of MVPs and TAP-Members that have migrated to Exchange 2010 a long time ago, but i&#8217;m still proud of this. At a starting point, i had a [...]]]></description>
			<content:encoded><![CDATA[<p>Exchange 2010 was released last Monday, the 9th. Today, we have Saturday the 14th &#8211; and i&#8217;m done with the Migration to Exchange 2010.</p>
<p>Sure, there are loads of MVPs and TAP-Members that have migrated to Exchange 2010 a long time ago, but i&#8217;m still proud of this.</p>
<p>At a starting point, i had a Exchange 2007 SP2 machine, with one Mailbox database, no public folders and 35 Mailboxes that used up 25GB of space. Moving this is simple enough, but the issue is that our Exchange isn&#8217;t virtualized, and i couldn&#8217;t get my hands on new hardware since the current box was only a year old.</p>
<p>Since in-place upgrades are not supported, i needed a temporary server for the migration. I used an HP ML110 from the Lab, which offered enough space to migrate.</p>
<p>Another issue was BackupExec 12.5, which did not support Exchange 2010 yet. Fortunately, Exchange 2010 (and 2007 SP2) can be backed up by using Windows Server Backup. So my goal was to just let WSB backup to a file server, and have BackupExec pickup the files from there. This way, i will get a reliable, clean and supported Exchange backup, and still have it on tape.</p>
<p>To Migration itself was straightforward and easy. There&#8217;s already _lots_ of content on the web about Exchange 2010, most of it from the RCs or Beta of course.</p>
<p>I followed the <a href="http://technet.microsoft.com/en-us/library/dd638158%28EXCHG.140%29.aspx">Migration Guide</a> from TechNet, which worked out well enough. Unfortunately, the <a href="http://projectdream.org/wordpress/2009/11/09/iphone-does-not-support-exchange-2010exchange-2007-coexistence/">iPhone does not support Exchange 2010/2007 coexistence</a>, which made it necessary for several people to manually reconfigure their phone.</p>
<p>Removing Exchange 2007 worked without issues, but after moving all the Exchange 2010 data back to the real hardware and removing the temporary server i ran into the issue of <a href="http://chrislehr.com/2009/10/exchange-2010-what-is-arbitration.htm">moving arbitration mailboxes</a>, which fortunately was already documented widely on the web.</p>
<p>In the end, upgrading from Exchange 2007 to 2010 while keeping the same hardware is not difficult, it just needs a bit more time.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/11/14/exchange-2010-migration-done/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>iPhone does not support Exchange 2010/Exchange 2007 Coexistence</title>
		<link>http://projectdream.org/wordpress/2009/11/09/iphone-does-not-support-exchange-2010exchange-2007-coexistence/</link>
		<comments>http://projectdream.org/wordpress/2009/11/09/iphone-does-not-support-exchange-2010exchange-2007-coexistence/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 17:15:52 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Exchange]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=659</guid>
		<description><![CDATA[The iPhone does not properly support coexistence between Exchange 2010/Exchange 2007. See this TechNet Posting. The error message in the IIS Log looks like this: RdirTo:https%3a%2f%2flegacy.contoso.com%2fMicrosoft-Server-ActiveSync_LdapC2_LdapL15_Error:MisconfiguredDevice_Budget]]></description>
			<content:encoded><![CDATA[<p>The iPhone does not properly support coexistence between Exchange 2010/Exchange 2007. See this <a href="http://social.technet.microsoft.com/Forums/en/exchange2010/thread/2cfe2729-77ea-44d7-9880-71d50127be35">TechNet Posting</a>.</p>
<p>The error message in the IIS Log looks like this:</p>
<blockquote><p>
RdirTo:https%3a%2f%2flegacy.contoso.com%2fMicrosoft-Server-ActiveSync_LdapC2_LdapL15_Error:MisconfiguredDevice_Budget
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/11/09/iphone-does-not-support-exchange-2010exchange-2007-coexistence/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>HP&#8217;s E200 controller really sucks</title>
		<link>http://projectdream.org/wordpress/2009/11/07/hps-e200-controller-really-sucks/</link>
		<comments>http://projectdream.org/wordpress/2009/11/07/hps-e200-controller-really-sucks/#comments</comments>
		<pubDate>Sat, 07 Nov 2009 22:10:52 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Hardware]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=645</guid>
		<description><![CDATA[A long time ago, i wrote a review of the HP ML110. In the comments, Paul indicated that the Performance of the E200 controllers was pretty bad, and i promised i would do benchmarks of that. Now we have a year later, and i indeed finally got the time and did those benchmarks. For the [...]]]></description>
			<content:encoded><![CDATA[<p>A long time ago, i wrote a review of the <a href="http://projectdream.org/wordpress/2008/10/14/hp-ml110-g5/">HP ML110</a>. In the comments, Paul indicated that the Performance of the E200 controllers was pretty bad, and i promised i would do benchmarks of that. Now we have a year later, and i indeed finally got the time and did those benchmarks.</p>
<p>For the benchmarks, i&#8217;ve used the free version of <a href="http://www.hdtune.com/">HDtune</a>. I&#8217;ve benchmarked four systems, and five different disk configurations. Note that the free version only does benchmarks for disk reads, and it&#8217;s a not a very pervasive test. None of these benchmarks are scientific. They should serve as a general indicator of performance, not as a final world on this topic. I don&#8217;t have that much clue about benchmarking.</p>
<p>The first system is my computer at home: It has an i7-920 CPU at stock speed, with 3x2GB RAM at 1333 Mhz (which is a slight overclock, but within the spec of the memory i purchased). Attached to it&#8217;s ICH10R controller are an Intel X25-M G2 160GB (Firmware 02HA) and a WD1001FALS (1TB, 7&#215;24), running Windows 7 x64.</p>
<p>The next system is my work laptop, which is a ThinkPad W500 with a 2.53 Ghz T9400 C2D CPU, with 4GB of RAM. Attached to it&#8217;s onboard controller is an OCZ Vertex 120GB (Firmware 1.40), running Windows 7 x64.</p>
<p>The third system is our Exchange Edge server, on which i dared to install a benchmark utility. It&#8217;s an IBM x3250 with two 70GB 15kRPM 2.5&#8243; SAS drives installed, attached to an onboard LSI1064E SAS controller. The system has a Xeon 3040 2.4Ghz Dualcore CPU and 5 GB RAM. It is running Windows Server 2008 x64 SP2.</p>
<p>And the final system is a HP ML110 G5 with a 2.33 Ghz Xeon 3065 CPU, 8GB of RAM and a E200 with the latest firmware (1.78). Attached to that are 4 WD1001FALS drives in a RAID10 configuration. The E200 has a backup battery and 128MB of cache installed. The system is running Windows Server 2008 R2.</p>
<p>Please note that none of these benchmarks are scientific. They were done on real systems, with workload minimized as much as possible, but virus scanners and other mandatory background applications active. Both the laptop and the desktop have not been formatted since Windows 7 RC was installed (i migrated to Windows 7 RTM using Windows.old), but the ML110 was freshly setup and the only application that&#8217;s been installed so far is the HP ACU and Forefront Client Security. The Exchange Edge server has been in use since May 2008. As such, the ML110 is the &#8220;cleanest&#8221; machine out of these four.</p>
<h3>Intel&#8217;s X25-M G2 160GB on an ICH10R (AHCI Mode)</h3>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2009/11/INTEL_X25MG2.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2009/11/INTEL_X25MG2.png" alt="Intel X25-M G2 on an ICH10R" title="Intel X25-M G2 on an ICH10R" width="573" height="462" class="alignnone size-full wp-image-647" /></a></p>
<p>This is how a graph should look. It&#8217;s nice, it&#8217;s clean, it&#8217;s fast. Intel&#8217;s X25-M G2 shows how a modern SSD and storage subsystem should behave. Clean, predictable performance.</p>
<h3>OCZ&#8217;s Vertex 160GB on an ICH7 (AHCI Mode)</h3>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2009/11/OCZ_VERTEX.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2009/11/OCZ_VERTEX.png" alt="OCZ Vertex 120GB on an ICH7" title="OCZ Vertex 120GB on an ICH7" width="580" height="472" class="alignnone size-full wp-image-650" /></a></p>
<p>Here&#8217;s the OCZ Vertex. It&#8217;s running on a machine that&#8217;s a lot slower than the one the X25-M is attached to, and it&#8217;s storage controller is also quite a bit older. It still shows remarkably good performance. It should also be considered that this Vertex is quite a bit older &#8211; it was bought in May 09. It&#8217;s still very fast and responsive and a good SSD.</p>
<h3>2x IBM&#8217;s 73GB 15kRPM 2.5&#8243; SAS Disks on an LSI Logic 1064E SAS Controller</h3>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2009/11/LSI_LOGIC_15kRPM_SAS_73GB.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2009/11/LSI_LOGIC_15kRPM_SAS_73GB.png" alt="LSI Logic 1064E SAS Controller with 2x IBM 73GB 15kRPM SAS Disks in RAID1" title="LSI Logic 1064E SAS Controller with 2x IBM 73GB 15kRPM SAS Disks in RAID1" width="575" height="459" class="alignnone size-full wp-image-651" /></a></p>
<p>As you can see, this is the performance you get from the server hard disks on an entry-level controller in an entry-level system. It&#8217;s not astonishing, but the performance is very well acceptable.</p>
<h3>Western Digital&#8217;s 1001FALS 1TB on an ICH10R (AHCI Mode)</h3>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2009/11/WD_1001FALS.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2009/11/WD_1001FALS.png" alt="WD 1001FALS on an ICH10R" title="WD 1001FALS on an ICH10R" width="579" height="463" class="alignnone size-full wp-image-648" /></a></p>
<p>Here&#8217;s how the Western Digital disk behaves on a proper controller. Please note that this is a single disk, not part of a RAID array. The performance is quite good.</p>
<h3>4x WD&#8217;s 1001FALS 1TB on an HP E200 in RAID10</h3>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2009/11/HP_E200_4xWD1001FALS.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2009/11/HP_E200_4xWD1001FALS.png" alt="HP E200 Controller with 4 WD1001FALS in RAID10" title="HP E200 Controller with 4 WD1001FALS in RAID10" width="571" height="458" class="alignnone size-full wp-image-646" /></a></p>
<p>And here&#8217;s how it shouldn&#8217;t look. Compare this to the stand-alone disks above, which exhibits better performance. HP fucked up bad on this one, and there&#8217;s no fix in sight. Stay away from the E200.</p>
<p>And as a final word: I really don&#8217;t have much of a clue about benchmarking. If you see an obvious error here, please state what you think. If possible, i will try to correct it.</p>
<p><strong>Update:</strong> As requested in the comments, i upgraded the E200 to Firmware 1.84 and redid the benchmark. It looks roughly the same.</p>
<p><a href="http://projectdream.org/wordpress/wp-content/uploads/2009/11/HDTune_Benchmark_HP______LOGICAL_VOLUME.png" rel="lightbox"><img src="http://projectdream.org/wordpress/wp-content/uploads/2009/11/HDTune_Benchmark_HP______LOGICAL_VOLUME.png" alt="HP E200 with Firmware 1.84" title="HP E200 with Firmware 1.84" width="570" height="457" class="alignnone size-full wp-image-664" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/11/07/hps-e200-controller-really-sucks/feed/</wfw:commentRss>
		<slash:comments>34</slash:comments>
		</item>
		<item>
		<title>Updating Subject Alternate Names in an Exchange certificate</title>
		<link>http://projectdream.org/wordpress/2009/11/02/updating-subject-alternate-names-in-an-exchange-certificate/</link>
		<comments>http://projectdream.org/wordpress/2009/11/02/updating-subject-alternate-names-in-an-exchange-certificate/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 16:02:25 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=639</guid>
		<description><![CDATA[Exchange 2010 will be out soon, and i&#8217;ve been preparing for the migration. One of the more important parts is that you will need to have both Exchange 2007 and Exchange 2010 client access servers accessible from the Internet. If you&#8217;re following the recommended deployment method for Exchange 2007, you&#8217;ll already be using a SAN [...]]]></description>
			<content:encoded><![CDATA[<p>Exchange 2010 will be out soon, and i&#8217;ve been preparing for the migration. One of the more important parts is that you will need to have both Exchange 2007 and Exchange 2010 client access servers accessible from the Internet.</p>
<p>If you&#8217;re following the recommended deployment method for Exchange 2007, you&#8217;ll already be using a SAN certificate in order to publish AutoDiscovery and OWA. For coexistence of Exchange 2007 and Exchange 2010, an additional name will need to be added to your SAN certificate.</p>
<p>With most CAs, this is a pretty straightforward process that can be done using their web interface, since the private key doesn&#8217;t need to be touched. After modifying this, you will get a new .crt file containing the certificate, but no private key (which is correct).</p>
<p>However, importing this into Exchange 2007 using <tt>Import-ExchangeCertificate</tt> doesn&#8217;t work &#8211; Windows won&#8217;t know which private key is associated with the newly imported certificate. When you try to use Enable-ExchangeCertificate, you will receive the following error message:</p>
<blockquote><p>
Enable-ExchangeCertificate : The certificate with thumbprint 1234 was found but is<br />
not valid for use with Exchange Server (reason: PrivateKeyMissing).
</p></blockquote>
<p>I searched high and low on how to replace a certificate without touching the private key, but i didn&#8217;t find anything. So i turned to the community for support &#8211; <a href="http://www.mcseboard.de/windows-forum-ms-backoffice-31/ws08-ex07-zertifikat-neue-san-namen-updaten-ohne-158514.html">MCSEBoard.de</a> is an excellent Windows community for those who speak German.</p>
<p>Unfortunately, noone knew an easy way either &#8211; the suggestion was to use OpenSSL to create a new keystore.</p>
<p>This was rather easy, but i didn&#8217;t find any guides on the net on how to do this, so i&#8217;m publishing this here in the hope that it will help others with the same issue.</p>
<ul>
<li>First, you need to export the key including the private key using the Windows certificate manager. Open an elevated MMC, add the Certificate snap-in and focus on the Computer certificate. Click &#8220;Personal&#8221;, and then export the certificate with the private key.</li>
<li>Download and Install <a href="http://www.slproweb.com/products/Win32OpenSSL.html">OpenSSL for Windows</a></li>
<li>Issue the following command: <tt>openssl pkcs12 -in mykey.pfx &gt; out.txt</tt></li>
<li>Open out.txt using an LF-aware text editor, such as <a href="http://notepad-plus.sourceforge.net/">Notepad++</a>. Save the PRIVATE KEY part to a textfile called key.pem.</li>
<li>Save the certificate to a file called cert.crt</li>
<li>Issue to the following command: <tt>openssl pkcs12 -export -in cert.crt -inkey key.pem -out newcert.p12</tt></li>
<li>Copy the newly created newcert.p12 to the Exchange server.</li>
<li>Open PowerShell and run the following command: <tt>$secureString = ConvertTo-SecureString "blubb" -AsPlainText -Force</tt> &#8211; Replace &#8220;blubb&#8221; with the Passphrase  you used in the step before</li>
<li>Run <tt>Import-ExchangeCertificate -path newcert.p12 -pass $secureString</tt> to import the certificate back into Exchange</li>
<li>The rest is as usual &#8211; use <tt>Enable-ExchangeCertificate</tt> to enable the certificate.</li>
</ul>
<p>And that&#8217;s it. It might be a bit cumbersome &#8211; and i really hope that there is an easier way to to this. If you know, let me know so i can update this page.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/11/02/updating-subject-alternate-names-in-an-exchange-certificate/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Microsoft finally fixes MS09-056 OCS issue</title>
		<link>http://projectdream.org/wordpress/2009/10/28/microsoft-finally-fixes-ms09-056-ocs-issue/</link>
		<comments>http://projectdream.org/wordpress/2009/10/28/microsoft-finally-fixes-ms09-056-ocs-issue/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 19:31:52 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Fillers]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=637</guid>
		<description><![CDATA[Microsoft has finally offered a fix to the OCS issue described here See here for the fix and it&#8217;s description KB974571 Click here to download the ocsasnfix.exe directly, which will fix the incorrect ASN License data &#8211; something which i already guessed about in my previous post about this issue.]]></description>
			<content:encoded><![CDATA[<p>Microsoft has finally offered a fix to the OCS issue described here</p>
<p>See here for the fix and it&#8217;s description <a href="http://support.microsoft.com/kb/974571">KB974571</a></p>
<p>Click <a href="http://go.microsoft.com/fwlink/?LinkId=168248">here</a> to download the ocsasnfix.exe directly, which will fix the incorrect ASN License data &#8211; something which i already guessed about in my <a href="http://projectdream.org/wordpress/2009/10/13/kb974571-crypto-api-update-may-break-office-communications-server-2007-r2-installations/">previous post</a> about this issue.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/10/28/microsoft-finally-fixes-ms09-056-ocs-issue/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>One year with SBS 2008</title>
		<link>http://projectdream.org/wordpress/2009/10/15/one-year-with-sbs-2008/</link>
		<comments>http://projectdream.org/wordpress/2009/10/15/one-year-with-sbs-2008/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 14:40:53 +0000</pubDate>
		<dc:creator>Lukas Beeler</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://projectdream.org/wordpress/?p=634</guid>
		<description><![CDATA[SBS 2008 is out for roughly a year. In this time, i did four deployments of SBS 2008, each with 15-30 users. During this time, i&#8217;ve gained valuable experience, which i&#8217;ll try to share here so that others can profit from it. Take all this with a grain of salt, as some observations may simply [...]]]></description>
			<content:encoded><![CDATA[<p>SBS 2008 is out for roughly a year. In this time, i did four deployments of SBS 2008, each with 15-30 users.</p>
<p>During this time, i&#8217;ve gained valuable experience, which i&#8217;ll try to share here so that others can profit from it. Take all this with a grain of salt, as some observations may simply be my fault. Also, as times changes these things might change too.</p>
<h3>Software</h3>
<ul>
<li>Make sure to install <a href="http://technet.microsoft.com/en-us/windows/dd262148.aspx">Windows Server 2008 SP2</a> after installing SBS 2008. Some media may come with SP2 already preloaded. You can use the normal SP2 package that&#8217;s also used for Vista and the normal Server 2008</li>
<li>Do not install SBS rollup updates before completing the configuration wizard. This is extremely counter-intuitive, but is described on the <a href="http://blogs.technet.com/sbs/archive/2009/09/08/sbs-2008-update-rollup-3-kb-969121-installation-failure.aspx">Official SBS blog</a></li>
<li>Installing Exchange 2007 SP2 requires you to follow special considerations <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;973862">Here</a></li>
<li>Installing WSUS 3.0 SP2, which is needed to support Windows 7, is currently not recommended. I was able to do this without issues on my lab machines, but others have reported issues doing this on machines that were in production. If you&#8217;re deploying a new SBS server, this should probably be safe to go. But make sure to test functionality afterward.</li>
<li>Always use the <a href="http://blogs.technet.com/sbs/archive/2009/01/02/introducing-the-windows-sbs-2008-answer-file.aspx">answer file</a> to deploy SBS 2008. This will make it possible to choose a custom domain name. Read my post about <a href="http://projectdream.org/wordpress/2007/06/07/choose-your-active-directory-dns-namespace-wisely/">choosing your AD DNS namespace</a></li>
<li>Do whatever tasks you can do using the SBS console. Resist of using the normal administration tools as much as possible, as you can break SBS with them easily.</li>
<li>Ensure that the AV software you install is compatible with WS08 x64. Symantec Endpoint Protection Manager works well &#8211; Forefront Client Security on the other hand requires a seperate server running 32bit Windows for management. You may consider deploying FCS unmanaged in smaller environments, and configure FCS using <a href="http://blog.tiensivu.com/aaron/archives/1766-Forefront-Client-Security-v1-standalone-GPO-.ADM-available-great-for-FCS-installations-without-a-management-server-backend.html">the FCS ADM File</a></li>
</ul>
<h3>Hardware</h3>
<ul>
<li>Use servers with the new Xeon 5500 CPUs. Read <a href="http://projectdream.org/wordpress/2009/04/01/ibm-x3650-m2-important-things/">my x3650 M2 tips</a> to find more about them. Consider using an E5530 or faster CPU. Using two CPUs (for a total of 16 virtual and 8 physical cores) makes little sense.</li>
<li>Buy enough memory. Lots of it. Really. I mean it. You&#8217;ll need lots and lots of memory. I would consider 12GB to bare minimum. In a 3x4GB configuration which makes the most sense for the Xeon 5500 setups, this is quite cheap. Consider more memory if you intend to run SQL Server as, consider bumping the memory to 24GB. Remember that you can only use the first 8 slots in a single socket machine.</li>
<li>Buy enough disks. A good starting layout is 8x147GB 2.5&#8243; disks. Use a RAID 1 for the OS, another RAID1 for Exchange and Sharepoint, and a RAID10 for Data and WSUS. This is all up for debate of course, and it might make sense to consider other disk layouts.</li>
</ul>
<p>If you have any additions, think i&#8217;m wrong somewhere just send in a comment.</p>
]]></content:encoded>
			<wfw:commentRss>http://projectdream.org/wordpress/2009/10/15/one-year-with-sbs-2008/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
	</channel>
</rss>

