<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>SMTP Port 25</title>
	<atom:link href="http://smtpport25.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://smtpport25.wordpress.com</link>
	<description>Anything and Everything Related to Messaging and Collaboration, Active Directory and Scripting.  It’s My Life!!!</description>
	<lastBuildDate>Mon, 20 May 2013 13:14:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='smtpport25.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/59f56e723b9bced7de772667204b6f88?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>SMTP Port 25</title>
		<link>http://smtpport25.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://smtpport25.wordpress.com/osd.xml" title="SMTP Port 25" />
	<atom:link rel='hub' href='http://smtpport25.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Netwrix Active Directory Change Reporter</title>
		<link>http://smtpport25.wordpress.com/2013/05/07/netwrix-active-directory-change-reporter/</link>
		<comments>http://smtpport25.wordpress.com/2013/05/07/netwrix-active-directory-change-reporter/#comments</comments>
		<pubDate>Tue, 07 May 2013 15:33:08 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Exchange 2013]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[netwrix]]></category>
		<category><![CDATA[reporter]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2251</guid>
		<description><![CDATA[Technorati Tags: Netwrix,Active Directory,Exchange,GPO,Report,Change auditing,Security auditing,Directory auditing,Systems Management,Compliance auditing,Configuration auditing Auditing is one of the most complex activities of the Windows Active Directory. Monitoring the changes and reporting immediately makes it very challenging for administrators. I would say that Netwrix Active Directory Change Reporter is one of the best tools available in the market with [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2251&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<div style="margin:0;display:inline;float:none;padding:0;" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:24d23222-187a-49c6-a6cc-102279dd0ed6" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Netwrix" rel="tag">Netwrix</a>,<a href="http://technorati.com/tags/Active+Directory" rel="tag">Active Directory</a>,<a href="http://technorati.com/tags/Exchange" rel="tag">Exchange</a>,<a href="http://technorati.com/tags/GPO" rel="tag">GPO</a>,<a href="http://technorati.com/tags/Report" rel="tag">Report</a>,<a href="http://technorati.com/tags/Change+auditing" rel="tag">Change auditing</a>,<a href="http://technorati.com/tags/Security+auditing" rel="tag">Security auditing</a>,<a href="http://technorati.com/tags/Directory+auditing" rel="tag">Directory auditing</a>,<a href="http://technorati.com/tags/Systems+Management" rel="tag">Systems Management</a>,<a href="http://technorati.com/tags/Compliance+auditing" rel="tag">Compliance auditing</a>,<a href="http://technorati.com/tags/Configuration+auditing" rel="tag">Configuration auditing</a></div>
<p>Auditing is one of the most complex activities of the Windows Active Directory. Monitoring the changes and reporting immediately makes it very challenging for administrators. I would say that Netwrix Active Directory Change Reporter is one of the best tools available in the market with comprehensive collection of features to audit changes in Active Directory and report on them. It has a very robust way of checking, if any modification/change was done to Active Directory objects. It uses both Active Directory event logs and also takes the Active Directory snapshot to compare the data and get a consolidated report on who made the changes, what was changed, when and where exactly. These changes are logged into a local database and are stored in the SQL server for reporting purposes. It is a unified solution for a complete Active Directory auditing, reporting and monitoring.</p>
<p>The Latest version of Netwrix Active Directory Change Reporter is 7.2.721 and it is available in two flavors, Freeware and the fully loaded Enterprise Edition. Free version has limited functionality features and can be used for an unlimited time period. Enterprise version has lots of auditing and reporting options which will make the life of an Active Directory administrator easier and allow him to get necessary data right in the finger tips. It can be evaluated free of charge for 20 days.</p>
<p>Netwrix Active Directory Change Reporter tool supports Active Directory starting from Windows 2000, Windows 2003, Windows 2008 and even the latest Windows 2012 Active Directory environment.</p>
<p>Requirements:</p>
<p>It has other basic technical requirements to function. </p>
<p>1. Intel or AMD Processor with Minimum of 2 GHz for 32 bit processor or 3 GHz for 64 bit&#160;&#160;&#160; processor is recommended</p>
<p>2. Memory 2 GB and above</p>
<p>3. Minimum of 50 GB disk for installation and an addition space for user, event and other necessary logs. </p>
<p>4. Active Directory permission to query an Active Directory</p>
<p>5. SQL server &#8211; SQL server 2005 Express Edition or above with an advanced service of SQL server, SQL server reporting tool and permission to generate reports. </p>
<p>6. Group policy management console to audit Active Directory Group Policy.</p>
<p>Required details of the tool can be found below link.</p>
<p><a href="http://www.netwrix.com/download/QuickStart/Active_Directory_Change_Reporter_Quick_Start.pdf">http://www.Netwrix.com/download/QuickStart/Active_Directory_Change_Reporter_Quick_Start.pdf</a></p>
<p>Native Active Directory tools do not provide a great flexibility to audit Active Directory changes and to report immediately. Raw data generated by the Windows native tools are always difficult to understand, analyze and it is an extremely time consuming process to analyze tons of logs. Most the times it is too late to analyze the logs as they would be overwritten. Netwrix solution for Active Directory Auditing overcomes these problems by saving the data in the SQL server. </p>
<p>There are also agents available for installing on the domain controller and these agents are optional. It helps to compress the data across the network and it is necessary if a change reporting tool is collecting data over the slow network but it should not make much of a difference if you are on a high speed network. Definitely it would be recommended to have agents installed in order to make the best utilization of all available networks. </p>
<p>Netwrix Active Directory Change Reporter also has some supporting tools like Group Policy Change reporter and Exchange Change Reporter. These two go very well with the Active Directory Change Reporter. Group Policy changes are critical and must be executed very carefully. Any mistake in Group Policy changes can have a big impact and not everyone in the organization has permission to modify the Group Policy. Netwrix Group Policy Change Reporter comes in handy to get complete details of the GPO with the details like who made the change, when was it made and also has details about “before and after” values more modified settings.</p>
<p>Exchange Change Reporter is another additional great component. Exchange is one of the business critical application and any downtime will have a major impact on an organization. Exchange Change Reporter keeps track of any addition, deletion, modification of the exchange attributes and generates reports on the changes. It also provides details about “before and after” values. The tool supports the earlier version of an exchange like the Exchange 2003, 2007 and 2010. The latest version of the Exchange Change Reporter supports Microsoft Exchange Server 2013 environment, which is one of the latest promising product of Microsoft.</p>
<p>­­­­­­Let’s understand some of the features of Netwrix Active Directory Change Reporter and what it can do for us. </p>
<blockquote><p>It provides in-depth change details about every Active Directory object, its attributes and also includes security changes. Changes can be addition, deletion or modification of Active Directory objects and It includes complete details like, who made the changed, what was changed and where.</p>
</blockquote>
<blockquote><p>It provides a real time reporting where an administrator or the security team can be notified with an email or SMS immediately after the change is detected. It also integrates with Microsoft SCOM using SCOM Management pack which captures Active Directory data and feeds into the SCOM for reporting and alerting. It also provides flexibility to integrate with other third party reporting tools available in your organization.</p>
</blockquote>
<blockquote><p>All reporting information is stored in SQL Server, where an administrator can manually query, generate custom and automated reports. Reporting is one of the key features and it can generate some predefined reports for the purpose of compliance regulations like SOX, HIPAA, GLBA, and FISMA. As these regulations require storing the data for later review the tool provides the long-term storage option. These long-term storages can be also at different servers other than the SQL server. By default, the long-term audit archiving is done for 24 months and these settings can be changed, if required. It can also generate daily reports with all the change details performed during the previous day. The product provides an administrator with a console view and gives a great flexibility to query and generate reports with ease. </p>
</blockquote>
<blockquote><p>Any kinds of accidental changes have to be rolled back immediately and this tool provides option to roll back all accidental or unwanted changes using roll back wizard. Performing this kind of roll back/restore operation using native windows tool is cumbersome and has many limitations. This tool performs a smooth, quick and an easy roll back from all kinds of accidental or unwanted changes. This overcomes any downtime, security risk or ill effects caused due to accidental changes. </p>
</blockquote>
<blockquote><p>It can be easily installed on any workstation with latest Windows OS like Windows 8 or on a server OS like windows 2012. It just has to be setup once and it runs forever. It can query and manage multiple domains from a single installed machine and can even manage multiple domains with its own unique settings. This gives lot of flexibility to manage and modify the settings based on the business requirement. </p>
</blockquote>
<blockquote><p>It provides an easy option to query and generate default and custom reports from the management console. It has got all necessary filters like timelines (from-date and to-date), types/kind of changes, where the changes were made and it also provides an option to specify an individual domain and individual forest. It has a great flexibility, which helps to get any data from any domain and any forest within no time. Finally, once you have all the data in the report then it can be easily exported into CSV, Excel, PDF, Word or even a Tiff format. </p>
</blockquote>
<blockquote><p>Reports come in an easy understandable format with color coding. Actions like adding, removing, modifying all highlighted with different colors. Most importantly, it gives clear information on who made these changes, when they were made and what was done. With this you can find all the necessary data/reports from one location and you really don’t have to depend on multiple logs or have in-depth knowledge to analyses and understand the logs from different locations. </p>
</blockquote>
<blockquote><p>Active Directory snapshot is one of the best features of this tool. It takes Active Directory snapshot at multiple points and keeps it in the database. It helps to look back at a specific AD object and what settings were in the past. These details can be viewed through reporting custom queries and these come under an advance reporting tool that requires some configuration before using it. </p>
</blockquote>
<blockquote><p>Real-time altering is one of the key components for any reporting tool to notify on any critical changes. By default Netwrix Active Directory Change Reporter provides the real-time alerts option for the below mentioned groups and you can also add more users or groups, if necessary. </p>
<p>· Changes to Admin Group </p>
<p>· Changes to Domain Configuration </p>
<p>· Changes to any Active Directory Object</p>
</blockquote>
<p>These real-time alerts can be sent via email or a text message right to the mobile device.</p>
<p>Netwrix Active Directory Change Reporter is very easy to install and configure. It needs some necessary configurations to function as required and these configurations can be made easily using wizards. Supported by other tools like Group Policy Change Reporter and Exchange Change Reporter it provides a great management option for IT administrators and security team. It will save a lot of time and energy of the administrator helping to avoid writing custom scripts or manual/LDAP queries to get the data for auditing or management purposes. </p>
<p>With this, I would like to finish my article saying <i>that “Netwrix Active Directory Change Reporter is a great tool which is helpful for IT administrators and security teams”.</i></p>
<p><i></i></p>
<p>Use this link download Netwrix Active Directory Change Reporter: <a href="http://www.netwrix.com/active_directory_change_reporting_freeware.html">http://www.netwrix.com/active_directory_change_reporting_freeware.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2251/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2251&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/05/07/netwrix-active-directory-change-reporter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Gal Sync between exchange 2003 and Exchange 2007 &#8211; Part 2</title>
		<link>http://smtpport25.wordpress.com/2013/04/17/gal-sync-between-exchange-2003-and-exchange-2007-part-2/</link>
		<comments>http://smtpport25.wordpress.com/2013/04/17/gal-sync-between-exchange-2003-and-exchange-2007-part-2/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 16:56:26 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2007]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2238</guid>
		<description><![CDATA[This article is continuation of part 1 to configure Gal Sync between Exchange 2003 and Exchange 2007.&#160; Please refer this link before coming to part 2 3. Creating and Configure IIFP Management Agents 3.1. Creating and Configuring Red.com – GAL MA 1. Login to IIFP Server, open Identity Manager. 2. From the Tools menu, click [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2238&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This article is continuation of <a href="http://wp.me/preb1-A3" target="_blank">part 1</a> to configure Gal Sync between Exchange 2003 and Exchange 2007.&#160; Please refer this <a href="http://wp.me/preb1-A3" target="_blank">link</a> before coming to part 2</p>
<h3><a name="_Toc345493883">3. Creating and Configure IIFP Management Agents</a></h3>
<blockquote><h4><a name="_Toc345493884">3.1. Creating and Configuring Red.com – GAL MA</a></h4>
<p>1. Login to IIFP Server, open Identity Manager. </p>
<p>2. From the Tools menu, click Management Agents. </p>
<p>3. From the Actions menu, click Create. </p>
<p>4. In Management Agent Designer, in Management agent for, click Active Directory global address list (GAL) (from the pull down).</p>
<p>5. In Name, type “Red GAL MA” and click Next.</p>
<p>6. On the “<b>Connect to an Active Directory forest”</b><b> </b>page, type the values for </p>
<p>7. Forest name = Red.com</p>
<p>8. User name = redgalsync</p>
<p>9. Password = xxxxx</p>
<p>10. Domain = Red.com</p>
<p>11. Click on options and clear the <b>Sign and encrypt LDAP traffic</b> check box and click Next </p>
<p>12. On the Configure Directory Partitions page, in Select directory partitions, select the only partition listed</p>
<p>13. Clear the <b>Sign and encrypt LDAP traffic</b> check box and select Containers</p>
<p>14. Clear the check box next to the directory partition to clear all organizational units under the directory partition</p>
<p>15. Select “Blue” and all other OU where users and DL accounts are based.</p>
<p>16. Click OK to and click Next</p>
<p>17. On the “Configure GAL” page click on Target container and select the “Contacts” OU which is under Blue OU and click on OK</p>
<p>18. Click on “Source” and select all the OUs where user’s mailbox and DLs are based and click on OK</p>
<p>19. Click on Edit under Exchange Configuration and add DNS suffix @blue.com and click on OK and click Next to continue</p>
<p>20. On the <b>Select Object Types page</b>, verify that the object types required for GAL synchronization are selected. Default settings are taken and Click Next.</p>
<p>21. On the <b>Select Attributes page</b>, verify that the attributes required for GAL synchronization are selected. Default settings are taken and Click Next.</p>
<p>22. On the <b>Configure Connector Filter page</b>, verify that the connector filters required for GAL synchronization are specified. Default settings are taken and Click Next.</p>
<p>23. On the <b>Configure Join and Projection Rules page</b>, verify that the four join and projection rules for GAL synchronization are specified. Default settings are taken and <b>Next</b></p>
<p>24. In <b>Configure Attribute Flow</b>, verify that the five attribute flow mappings for GAL synchronization are specified. Default settings are taken and click Next</p>
<p>25. On the <strong>Configure Deprovisioning </strong>page, in <strong>Deprovisioning Options</strong>, verify that the <strong>Determine with a rules extension </strong>option is selected and click on <b>Next</b></p>
<p>On the <strong>Configure Extensions </strong>page, in <strong>Assembly name</strong>, verify that the GALSync.dll file is specified and click on <b>Finish</b></p>
<p><strong></strong></p>
<h4><a name="_Toc345493885">3.2. Creating and Configuring Blue.com – GAL MA</a></h4>
<p>1. Login to IIFP Server, open Identity Manager. </p>
<p>2. From the Tools menu, click Management Agents. </p>
<p>3. From the Actions menu, click Create. </p>
<p>4. In Management Agent Designer, in Management agent for, click Active Directory global address list (GAL) (from the pull down).</p>
<p>5. In Name, type “<strong>Blue GAL MA</strong>” and click Next.</p>
<p>6. On the “<b>Connect to an Active Directory forest”</b><b> </b>page, type the values for </p>
<p>7. Forest name = Blue.com</p>
<p>8. User name = bluegalsync</p>
<p>9. Password = xxxxx</p>
<p>10. Domain = blue.com</p>
<p>11. Click on options and clear the Sign and encrypt LDAP traffic check box and click Next </p>
<p>12. On the Configure Directory Partitions page, in Select directory partitions, select the only partition listed</p>
<p>13. Clear the Sign and encrypt LDAP traffic check box and select Containers</p>
<p>14. Clear the check box next to the directory partition to clear all organizational units under the directory partition</p>
<p>15. Select “Red” and all other OU where users and DL accounts are based.</p>
<p>16. Click OK to and click Next</p>
<p>17. On the “Configure GAL” page click on Target container and select “Contacts” OU which is under <b>RED</b> OU and click on <b>OK</b></p>
<p>18. Click on “Source” and select all the OUs where red.com user’s mailbox and DLs are based and click on <b>OK</b></p>
<p>19. Click on Edit under Exchange Configuration and add DNS suffix <b>@red.com</b> and click on <b>OK</b> and click <b>Next</b> to continue</p>
<p>20. On the <b>Select Object Types page</b>, verify that the object types required for GAL synchronization are selected. Default settings are taken and Click Next.</p>
<p>21. On the <b>Select Attributes page</b>, verify that the attributes required for GAL synchronization are selected. Default settings are taken and Click Next.</p>
<p>22. On the <b>Configure Connector Filter page</b>, verify that the connector filters required for GAL synchronization are specified. Default settings are taken and Click Next.</p>
<p>23. On the <b>Configure Join and Projection Rules page</b>, verify that the four join and projection rules for GAL synchronization are specified. Default settings are taken and <b>Next</b></p>
<p>24. In <b>Configure Attribute Flow</b>, verify that the five attribute flow mappings for GAL synchronization are specified. Default settings are taken and click Next</p>
<p>25. On the <strong>Configure Deprovisioning </strong>page, in <strong>Deprovisioning Options</strong>, verify that the <strong>Determine with a rules extension </strong>option is selected and click on <b>Next</b></p>
<p>On the <strong>Configure Extensions </strong>page, in <strong>Assembly name</strong>, verify that the GALSync.dll file is specified and click on <b>Finish</b></p>
</blockquote>
<h4>
<p><b></b></p>
<p>   <a name="_Toc345493886">4. Enable Provisioning</a></h4>
<p>1. Open Identity Manager</p>
<p>2. From the <b>Tools</b> menu, click <b>Options</b>.</p>
<p>3. Under <b>Metaverse Rules Extensions</b>, ensure that the <b>Enable metaverse rules extensions</b> check box is selected.</p>
<p>4. In the box located next to <b>Rules extension name</b>, ensure <b>GALSync.dll</b> is present.</p>
<p>5. Select the check box next to <b>Enable Provisioning Rules Extensions</b> to enable provisioning rules extension to be used with the GAL synchronization management agent.</p>
<p>6. Click <b>OK</b>.</p>
<p>&#160;</p>
<p>Hope you like the article&#160; <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div style="margin:0;display:inline;float:none;padding:0;" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:d6aabdf0-e807-4771-b39d-7b13b4b03561" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/GAl+sync" rel="tag">GAl sync</a>,<a href="http://technorati.com/tags/IIPF" rel="tag">IIPF</a>,<a href="http://technorati.com/tags/Exchange+2007" rel="tag">Exchange 2007</a>,<a href="http://technorati.com/tags/exchange+2003" rel="tag">exchange 2003</a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2238/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2238&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/04/17/gal-sync-between-exchange-2003-and-exchange-2007-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Gal Sync between exchange 2003 and Exchange 2007 &#8211; Part 1</title>
		<link>http://smtpport25.wordpress.com/2013/04/17/gal-sync-between-exchange-2003-and-exchange-2007-part-1/</link>
		<comments>http://smtpport25.wordpress.com/2013/04/17/gal-sync-between-exchange-2003-and-exchange-2007-part-1/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 16:35:36 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2003]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Galsync]]></category>
		<category><![CDATA[IIPF]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2235</guid>
		<description><![CDATA[This document is to provide step by step instruction to GAL Sync between Red.com (Exchange 2003) and Blue.com (Exchange 2007 ) organization using IIFP SP2 This document is majorly divided into 4 parts 1. Installing and configuration IIFP 2. Preparing and configuring Active Directory on both Red.com and Blue.com 3. Creating and configuration MA Agents [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2235&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This document is to provide step by step instruction to GAL Sync between Red.com (Exchange 2003) and Blue.com (Exchange 2007 ) organization using IIFP SP2</p>
<p>This document is majorly divided into 4 parts</p>
<p>1. Installing and configuration IIFP</p>
<p>2. Preparing and configuring Active Directory on both Red.com and Blue.com</p>
<p>3. Creating and configuration MA Agents to create mail enabled contacts in both Active directory forest</p>
<p>4. Executing and scheduling MA profiles</p>
<p>Lets talk each of the parts in detail</p>
<h3><a name="_Toc345493883"></a>1. Installing and Configuration IIFP</h3>
<p>Follow these steps in order to build and setup IIFP on a Windows Server on any of the domain, either red.com or blue.com</p>
<p>1. Install Windows 2003 R2 enterprise edition and configure server as per best practice</p>
<p>2. Join the server to the domain</p>
<p>3. Install IIS, ASP.net 2.0</p>
<p>4. Install Microsoft SQL Server 2005 with SP1</p>
<p>5. Install Identity Integration Feature Pack SP2</p>
<p>6. Run Microsoft Updates to bring system up to latest patch levels.</p>
<h4><a name="_Toc345493884"></a>2. Creating and Configuring Blue.com – GAL MA</h4>
<blockquote><h4><a name="_Toc345493884"></a>2.1 Configuring Red.com Active Director</h4>
<p>1. Login to Red.com domain controller</p>
<p>2. From <strong>Start</strong>, click <strong>Administrative Tools</strong>; click <strong>Active Directory Users and Computers</strong>.</p>
<p>3. Select <b>View</b> from the top drop down menu and select <b>Advanced Features</b>.</p>
<p>4. Create new user “<b>RedGalsync”</b> with password and ensure that password is set not to expire and not to change the password for next logon</p>
<p>5. Select <strong>RED.COM</strong> and right-click, select <b>Delegate Control</b></p>
<p>6. On the <b>Welcome to the Delegation of Control Wizard</b> page click <b>Next</b>.</p>
<p>7. On the <b>Users or Groups</b> page click <b>Add</b>.</p>
<p>8. On the <b>Select Users, Computers, or Groups</b> dialog box type <b>“RedGalsync” </b>and click <b>OK</b>.</p>
<p>9. On the <b>Users or Groups</b> page click <b>Next</b>.</p>
<p>10. On the <b>Tasks to Delegate</b> page select <b>create a custom task to delegate</b>, and click <b>Next</b>.</p>
<p>11. On the <b>Active Directory Object Type </b>page except the defaults and click <b>Next</b>.</p>
<p>12. On the <b>Permissions</b> page select <b>General, Property-specific, </b>and <b>Creation/deletion of specific child objects</b>, under <b>permissions</b> select <b>Replicate Directory Changes</b> and <b>Replication Synchronization</b>, and click <b>Next</b>.</p>
<p>13. On the <b>Completing to the Delegation of Control Wizard</b> page click <b>Finish</b>.</p>
<p>14. Create new OU with the name <b>“Blue”</b> under root and create sub OU “<b>Contacts”</b></p>
<p>15. Right-click the <b>Contacts</b> OU and select <b>Properties</b>.</p>
<p>16. On the <b>Contacts Properties</b> dialog box click <b>Security.</b></p>
<p>17. On the <b>Contacts Properties</b> dialog box click <b>Add</b>.</p>
<p>18. On the <b>Select Users, Computers, or Groups</b> dialog box type “<b>REDGalsync” </b>and click <b>OK</b>.</p>
<p>19. On the <b>Contacts Properties</b> dialog box select <b>Read, Write, Create All Child Objects</b>, and <b>Delete All Child Objects</b>, and then click <b>OK</b>. Make sure to <b>Apply to this child and all objects</b>.</p>
<p>20. Open <b>ADSIEdit</b> and navigate to the container <b>“Blue”</b></p>
<p>21. Right-click on OU “<b>Contacts” </b>and select <b>Properties</b>.</p>
<p>22. Click on the <b>Security</b> tab, and click <b>Advanced</b>.</p>
<p>23. Choose to <b>Add</b> an ACE.</p>
<p>24. Specify <b>REDGalsync</b> to apply the permissions to. This will display the permissions dialog.</p>
<p>25. Click on <b>Properties</b>.</p>
<p>26. Drop down the Apply Onto dropdown box and select <b>Child Objects Only</b>.</p>
<p>27. Scroll down and mark <b>Write proxyAddresses</b> – <b>Allow</b>.</p>
<p>28. Choose to save the properties. This permission will be applied to every child object whose <b>Allow inheritable permissions from the parent to propagate to this object and all child objects</b> option is selected. This is located in the user&#8217;s Advanced Security property sheet. Any user that does not have this selected will not have the permissions granted to it</p>
</blockquote>
<p>&#160;</p>
<blockquote><h4>2.2 Configuring Blue.com Active Director</h4>
<p>1. Login to <strong>Blue.com</strong> domain controller</p>
<p>2. From <strong>Start</strong>, click <strong>Administrative Tools</strong>; click <strong>Active Directory Users and Computers</strong>.</p>
<p>3. Select <b>View</b> from the top drop down menu and select <b>Advanced Features</b>.</p>
<p>4. Create new user “<b>BlueGalsync”</b> with password and ensure that password is set not to expire and not to change the password for next logon</p>
<p>5. Select <strong>Blue.com</strong> and right-click, select <b>Delegate Control</b></p>
<p>6. On the <b>Welcome to the Delegation of Control Wizard</b> page click <b>Next</b>.</p>
<p>7. On the <b>Users or Groups</b> page click <b>Add</b>.</p>
<p>8. On the <b>Select Users, Computers, or Groups</b> dialog box type <b>“BlueGalsync” </b>and click <b>OK</b>.</p>
<p>9. On the <b>Users or Groups</b> page click <b>Next</b>.</p>
<p>10. On the <b>Tasks to Delegate</b> page select <b>create a custom task to delegate</b>, and click <b>Next</b>.</p>
<p>11. On the <b>Active Directory Object Type </b>page except the defaults and click <b>Next</b>.</p>
<p>12. On the <b>Permissions</b> page select <b>General, Property-specific, </b>and <b>Creation/deletion of specific child objects</b>, under <b>permissions</b> select <b>Replicate Directory Changes</b> and <b>Replication Synchronization</b>, and click <b>Next</b>.</p>
<p>13. On the <b>Completing to the Delegation of Control Wizard</b> page click <b>Finish</b>.</p>
<p>14. Create new OU with the name <b>“Red”</b> under root and create sub OU “<b>Contacts”</b></p>
<p>15. Right-click the <b>Contacts</b> OU and select <b>Properties</b>.</p>
<p>16. On the <b>Contacts Properties</b> dialog box click <b>Security.</b></p>
<p>17. On the <b>Contacts Properties</b> dialog box click <b>Add</b>.</p>
<p>18. On the <b>Select Users, Computers, or Groups</b> dialog box type <b>BlueGalsync </b>and click <b>OK</b>.</p>
<p>19. On the <b>Contacts Properties</b> dialog box select <b>Read, Write, Create All Child Objects</b>, and <b>Delete All Child Objects</b>, and then click <b>OK</b>. Make sure to <b>Apply to this child and all objects</b>.</p>
<p>20. Open <b>ADSIEdit</b> and navigate to the container name <b>“Red”</b></p>
<p>21. Right-click on OU “<b>Contacts” </b>and select <b>Properties</b>.</p>
<p>22. Click on the <b>Security</b> tab, and click <b>Advanced</b>.</p>
<p>23. Choose to <b>Add</b> an ACE.</p>
<p>24. Specify <b>BlueGalsync</b> to apply the permissions to. This will display the permissions dialog.</p>
<p>25. Click on <b>Properties</b>.</p>
<p>26. Drop down the Apply Onto dropdown box and select <b>Child Objects Only</b>.</p>
<p>27. Scroll down and mark <b>Write proxyAddresses</b> – <b>Allow</b>.</p>
<p>28. Choose to save the properties. This permission will be applied to every child object whose <b>Allow inheritable permissions from the parent to propagate to this object and all child objects</b> option is selected. This is located in the user&#8217;s Advanced Security property sheet. Any user that does not have this selected will not have the permissions granted to it</p>
</blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2235/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2235/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2235&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/04/17/gal-sync-between-exchange-2003-and-exchange-2007-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Exchange Autodiscover in a multi- forest environment</title>
		<link>http://smtpport25.wordpress.com/2013/04/07/exchange-autodiscover-in-a-multi-forest-environment/</link>
		<comments>http://smtpport25.wordpress.com/2013/04/07/exchange-autodiscover-in-a-multi-forest-environment/#comments</comments>
		<pubDate>Sun, 07 Apr 2013 11:04:43 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Exchange 2013]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2234</guid>
		<description><![CDATA[Most of the organization have Exchange multi-forest environment. Organization could be in multi forest environment because of the merger and acquisition or it could be because of security reason. Auto discover is the new feature introduced in Exchange 2007 and its been carried forward in all the subsequent version of exchange like Exchange 2010 and [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2234&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Most of the organization have Exchange multi-forest environment. Organization could be in multi forest environment because of the merger and acquisition or it could be because of security reason. Auto discover is the new feature introduced in Exchange 2007 and its been carried forward in all the subsequent version of exchange like Exchange 2010 and Exchange 2013. </p>
<p>Below link should give you good understanding on the information about</p>
<p><a href="http://4sysops.com/archives/exchange-autodiscover-in-a-multi-forest-environment-part-1-active-directory/" target="_blank">Exchange Autodiscover in a multi-forest environment&#160; 1</a></p>
<p><a href="http://4sysops.com/archives/exchange-autodiscover-in-a-multi-forest-environment-part-2-outlook/" target="_blank">Exchange Autodiscover in a multi-forest environment 2</a></p>
<p>&#160;</p>
<p>Hope you got some good understanding on Autodiscover in Exchange <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div style="margin:0;display:inline;float:none;padding:0;" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:4e771db7-872b-48f3-a857-8c45d0722b21" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/autodiscover" rel="tag">autodiscover</a>,<a href="http://technorati.com/tags/multi+forest" rel="tag">multi forest</a>,<a href="http://technorati.com/tags/cross+forest" rel="tag">cross forest</a>,<a href="http://technorati.com/tags/scp" rel="tag">scp</a>,<a href="http://technorati.com/tags/ldap" rel="tag">ldap</a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2234/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2234&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/04/07/exchange-autodiscover-in-a-multi-forest-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Exchange Jetstress &#8211; Determine maximum disk subsystem throughput</title>
		<link>http://smtpport25.wordpress.com/2013/04/07/exchange-jetstress-determine-maximum-disk-subsystem-throughput/</link>
		<comments>http://smtpport25.wordpress.com/2013/04/07/exchange-jetstress-determine-maximum-disk-subsystem-throughput/#comments</comments>
		<pubDate>Sun, 07 Apr 2013 10:54:16 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Exchange 2013]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2232</guid>
		<description><![CDATA[JetStress is a tool for Architects and administrator to test the storage if it can suites your requirement. Through understanding of the Jetstress is important. Proper desiging and right testing with Jetstress make your design a robust solution. &#160; Link: Determine throughput of disk subsystem using Jetstress Technorati Tags: Jetstress,throughput,disk,jbod,design,storage<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2232&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>JetStress is a tool for Architects and administrator to test the storage if it can suites your requirement. Through understanding of the Jetstress is important. Proper desiging and right testing with Jetstress make your design a robust solution.</p>
<p>&#160;</p>
<p>Link: <a href="http://4sysops.com/archives/exchange-jetstress-determine-maximum-disk-subsystem-throughput/">Determine throughput of disk subsystem using Jetstress</a></p>
<div style="margin:0;display:inline;float:none;padding:0;" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:95726981-2392-4767-ab8c-9d92ba53202e" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Jetstress" rel="tag">Jetstress</a>,<a href="http://technorati.com/tags/throughput" rel="tag">throughput</a>,<a href="http://technorati.com/tags/disk" rel="tag">disk</a>,<a href="http://technorati.com/tags/jbod" rel="tag">jbod</a>,<a href="http://technorati.com/tags/design" rel="tag">design</a>,<a href="http://technorati.com/tags/storage" rel="tag">storage</a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2232/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2232/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2232&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/04/07/exchange-jetstress-determine-maximum-disk-subsystem-throughput/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>How Outlook uses RPC and AB static ports to connect to Exchange</title>
		<link>http://smtpport25.wordpress.com/2013/04/07/how-outlook-uses-rpc-and-ab-static-ports-to-connect-to-exchange/</link>
		<comments>http://smtpport25.wordpress.com/2013/04/07/how-outlook-uses-rpc-and-ab-static-ports-to-connect-to-exchange/#comments</comments>
		<pubDate>Sun, 07 Apr 2013 09:34:00 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2230</guid>
		<description><![CDATA[Technorati Tags: Exchange 2010,Outlook,RPC,AB,Static port,connection Every one uses outlook and do you how outlook connect to the exchange server and how it access the emails from the server ? Here is one of the article to give you a better understanding&#160; on same. Link : How outlook connects to Exchange server &#160; Hope you like [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2230&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<div style="margin:0;display:inline;float:none;padding:0;" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:94fa996b-f767-4351-9de2-e82c95347424" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Exchange+2010" rel="tag">Exchange 2010</a>,<a href="http://technorati.com/tags/Outlook" rel="tag">Outlook</a>,<a href="http://technorati.com/tags/RPC" rel="tag">RPC</a>,<a href="http://technorati.com/tags/AB" rel="tag">AB</a>,<a href="http://technorati.com/tags/Static+port" rel="tag">Static port</a>,<a href="http://technorati.com/tags/connection" rel="tag">connection</a></div>
<p>Every one uses outlook and do you how outlook connect to the exchange server and how it access the emails from the server ?</p>
<p>Here is one of the article to give you a better understanding&#160; on same. </p>
<p>Link : <a href="http://4sysops.com/archives/how-outlook-uses-rpc-and-ab-static-ports-to-connect-to-exchange/">How outlook connects to Exchange server</a></p>
<p>&#160;</p>
<p>Hope you like this article <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2230/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2230&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/04/07/how-outlook-uses-rpc-and-ab-static-ports-to-connect-to-exchange/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Step by step Instructions for Subordinate CA Migration from Windows Server 2003 to Windows Server 2008 R2 &#8211; Part 3</title>
		<link>http://smtpport25.wordpress.com/2013/03/24/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-3/</link>
		<comments>http://smtpport25.wordpress.com/2013/03/24/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-3/#comments</comments>
		<pubDate>Sat, 23 Mar 2013 18:44:01 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[Windows 2008 R2]]></category>
		<category><![CDATA[authority]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[subordinate]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2221</guid>
		<description><![CDATA[This is the last and final part with back-out procedure of step by step instruction for subordinate CA migration from windows server 2003 to windows server 2008 R2 1. Back-Out Procedure In case of migration failure i.e. if the Certificate authority service fails to stop, auto enrollment failure or error/issue in any of the verifying [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2221&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This is the last and final part with back-out procedure of step by step instruction for subordinate CA migration from windows server 2003 to windows server 2008 R2</p>
<h3>1. Back-Out Procedure</h3>
<p>In case of migration failure i.e. if the Certificate authority service fails to stop, auto enrollment failure or error/issue in any of the verifying migration steps. Then the back-out procedure has to be executed to restore the CA service on the source server.</p>
<h4><a name="_Toc349230127"></a>a. Removing CA Role from Destination server</h4>
<p>Log on to the destination server, and start Server Manager.</p>
<p>In the console tree, click Roles.</p>
<p>On the Roles pane click, Remove Roles</p>
<p>If the Before you begin page appears click Next</p>
<p>On the Remove Server Roles, Uncheck ACTIVE Directory Certificate Services and click Next</p>
<p>Click Remove on the Confirm Removal Selection and restart the server once completes</p>
<p>Remove Destination server from domain</p>
<p>Rename the Destination server</p>
<h4><a name="_Toc349230128"></a>b. Adding CA Role on Source Server</h4>
<p>Rename the source server to the initial name</p>
<p>Add the source server to domain</p>
<p>Launch Add or Remove programs and select add/remove windows components and select Certificate Service and click, Next</p>
<p>Select Enterprise Subordinate CA as CA Type and select “Use custom settings to generate the key pair and CA Certificate”</p>
<p>On the Public and Private Key Pair click Import and select the backed up file .p12 and enter the password and click next</p>
<p>Click Next to proceed with the CA configuration and close</p>
<h4><a name="_Toc349230129"></a>c. Restoring CA DB on source server</h4>
<p>Launch Certificate Authority snap in</p>
<p>Select CA node and click on Actions, All Task and Restore CA</p>
<p>On the Items to Restore select Private key and CA Certificate and Certificate Database and Certificate Database Log</p>
<p>Browse the CA DB Location and Click Next</p>
<p>Enter the password set while backing up the CA</p>
<h4><a name="_Toc349230130"></a>d. Restore Certificate template list</h4>
<p>Open a command prompt window.</p>
<p>Type certutil -setcatemplates +&lt;templatelist1&gt;,&lt;templatelist2&gt;.. and press ENTER.</p>
<p>&nbsp;</p>
<p>Hope this article was informative and helpful to you .  This is based on test with real time scenario.</p>
<p>Below are the links of other part of the article</p>
<p><a href="http://wp.me/preb1-zN">Part 1 – Preparing Source CA and Target server</a><br />
<a href="http://wp.me/preb1-zO">Part 2 &#8211; Restoring the Source from backups and Verifying the migration</a></p>
<p>Please comment if you like this article <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2221/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2221&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/03/24/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Step by step Instructions for Subordinate CA Migration from Windows Server 2003 to Windows Server 2008 R2 &#8211; Part 2</title>
		<link>http://smtpport25.wordpress.com/2013/03/23/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-2/</link>
		<comments>http://smtpport25.wordpress.com/2013/03/23/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-2/#comments</comments>
		<pubDate>Sat, 23 Mar 2013 18:27:16 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Windows 2003]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[Windows 2008 R2]]></category>
		<category><![CDATA[authority]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[certificate authority]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[subordinate]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2220</guid>
		<description><![CDATA[Here is the next part of the article with the step by step Instruction for Subroutine CA Migration from Windows Server 2003 to Windows Server 2008 R2.  In this 2nd part we talk about restoring the source CA from backups on the new Windows Server 2008 R2 and Verifying the migration 1. Restore Source CA [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2220&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Here is the next part of the article with the step by step Instruction for Subroutine CA Migration from Windows Server 2003 to Windows Server 2008 R2.  In this 2nd part we talk about restoring the source CA from backups on the new Windows Server 2008 R2 and Verifying the migration</p>
<h4><a name="_Toc349230118"></a>1. Restore Source CA Server from backup</h4>
<h5><a name="_Toc349230119"></a>a. Restore CA DB</h5>
<p>Log on to the destination server by using an account that is a CA administrator.</p>
<p>Start the Certification Authority snap-in.</p>
<p>Right-click the node with the CA name, point to All Tasks, and then click Restore CA.</p>
<p>On the Welcome page, click Next.</p>
<p>On the Items to Restore page, select Certificate database and certificate database log.</p>
<p>Click Browse. Navigate to the parent folder that holds the Database folder (the folder that contains the CA database files created during the CA database backup).</p>
<p>Click Next and then click Finish.</p>
<h5><a name="_Toc349230120"></a>b. Restore CA Registry</h5>
<p>Create a backup of the current Registry setting</p>
<p>Open the exported registry file from source servers in notepad and verify the registry values</p>
<p>Open a Command Prompt window.</p>
<p>Type reg import &lt;Registry Settings Backup.reg&gt; and press ENTER.</p>
<p>Type net start certsvc and press ENTER.</p>
<h5><a name="_Toc349230121"></a>c. Restore Certificate template list</h5>
<p>Open a command prompt window.</p>
<p>Type certutil -setcatemplates +&lt;templatelist1&gt;,&lt;templatelist2&gt;.. and press ENTER.</p>
<h4><a name="_Toc349230122"></a>2. Verifying migration</h4>
<h5><a name="_Toc349230123"></a>a. Verify ACL’s on the AIA and CDP Containers</h5>
<p>Logging to DC and open Active Directory Sites in Services</p>
<p>On the Console click on Top Node</p>
<p>Click View and Show Services node you will find Services folder on the Left and expand to reach Public key Services</p>
<p>Expand Public Key Services</p>
<p>Click AIA folder and in the details pane, select the name of the source CA.</p>
<p>On the Action menu, click Properties.</p>
<p>Click the Security tab, and then click Add.</p>
<p>Click Object Types, click Computers, and then click OK.</p>
<p>Type the host name of the target CA, and click OK.</p>
<p>In the Allow column, select Full Control, and click OK.</p>
<p>If <b>Account unknown</b> with security identifier exist then select it and remove the object.</p>
<p>In the left pane, select CDP and the host name of the source CA.</p>
<p>In the details pane, select the first CRL object.</p>
<p>On the Action menu, click Properties, and then click the Security tab.</p>
<p>In the list of permitted group or user names, select the name of the source CA, click Remove, and then click Add.</p>
<p>Click Object Types, select Computers, and then click OK.</p>
<p>Type the host name of the target CA, and click OK.</p>
<p>In the Allow column, select Full Control, and then click OK.</p>
<p>If <b>Account unknown</b> with security identifier exist then select it and remove the object.</p>
<h5><a name="_Toc349230124"></a>b. Verify Registry</h5>
<p>Verify that CAServerName is a registry string value located under the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CAName\ registry key. It should be updated to represent the DNS or the host of the new CA host.</p>
<p>Verify that CACertPublicationURLs and CRLPublicationURLs are both registry multi-string values located under the same key as CAServerName.</p>
<h5><a name="_Toc349230125"></a>c. Verify Auto Enrollment</h5>
<p>Log on to a domain member computer by using an account that has Autoenroll, Enroll, and Read permissions for the certificate templates that are assigned to the destination CA.</p>
<p>Click Start, and then click Run.</p>
<p>Type certmgr.msc, and then click OK to open the Certificates snap-in.</p>
<p>In the console tree, right-click Certificates – Current User, click All Tasks, and then click Automatically Enroll and Retrieve Certificates to start the Certificate Enrollment wizard.</p>
<p>On the Before You Begin page, click Next.</p>
<p>On the Request Certificates page, a list of one or more certificate templates should be displayed. Select the check box next to each certificate template that you want to request, and then click Enroll.</p>
<p>Click Finish to complete the enrollment process.</p>
<p>In the console tree, double-click Personal, and then click Certificates to display a list of installed user certificates and to verify that the certificate that you requested is displayed.</p>
<p>Hope you liked this article and got some good understanding of migration process of CA server windows server 2003 to windows server 2008. Please continue with the last part with the backup process. You should know this part to revert back if necessary.</p>
<p>Below are the links for the other parts</p>
<p><a href="http://wp.me/preb1-zN">Part 1 – Preparing source and target CA  server for migration.</a></p>
<p><a href="http://wp.me/preb1-zP">Part 3 – Blackout procedure. </a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2220/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2220&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/03/23/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Step by step Instructions for Subordinate CA Migration from Windows Server 2003 to Windows Server 2008 R2 &#8211; Part 1</title>
		<link>http://smtpport25.wordpress.com/2013/03/23/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-1/</link>
		<comments>http://smtpport25.wordpress.com/2013/03/23/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-1/#comments</comments>
		<pubDate>Sat, 23 Mar 2013 18:13:54 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[Windows 2008 R2]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[certificate authority]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[subordinate]]></category>
		<category><![CDATA[windows 2003]]></category>

		<guid isPermaLink="false">https://smtpport25.wordpress.com/?p=2219</guid>
		<description><![CDATA[Below are the step by step comprehensive Instructions for subroutine CA migration from Windows Server 2003 to Windows Server 2008 R2. This article is published in three parts and in this part we will discuss more in details on about preparing of source and destination server for the migration 1. Preparing Source Server Map network [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2219&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Below are the step by step comprehensive Instructions for subroutine CA migration from Windows Server 2003 to Windows Server 2008 R2.<br />
This article is published in three parts and in this part we will discuss more in details on about preparing of source and destination server for the migration</p>
<h4>1. Preparing Source Server</h4>
<p>Map network share in source server to copy backup files</p>
<p>Perform/Verify System state backup of Source CA</p>
<h5><a name="_Toc349230109"></a>a. Verify and backup CA Template set</h5>
<p>Open Command prompt</p>
<p>Type certutil.exe – catemplates &gt; catemplates.txt</p>
<p>Verify the contents of catemplates.txt with the templates displayed in Certificate Authority snap-in</p>
<h5><a name="_Toc349230110"></a>b. Verify and backup CA’s CSP and signature algorithm</h5>
<p>Open Command prompt</p>
<p>Type certutil.exe –getreg ca\csp\* &gt; csp.txt</p>
<p>Verify that the csp.txt contains CSP detaill</p>
<h5><a name="_Toc349230111"></a>c. Publish CRL with extended validity period</h5>
<p>Open Certificate Authority snap in</p>
<p>In the console tree right click “Revoked Certificates” and click Properties</p>
<p>Record the current CRL Publishing Parameters</p>
<p>Set the CRL Delta publishing interval to 2 days</p>
<p>Click on “Revoked Certificates” -&gt; all task -&gt; publish -&gt; Delta CRL only</p>
<h5><a name="_Toc349230112"></a>d. Backup CA DB and Private Key</h5>
<p>Map shared network drive to take the backup</p>
<p>on Certificate authority snap-in right click point to All task and backup CA</p>
<p>On the Welcome page of the CA Backup wizard, click Next.</p>
<p>On the Items to Back Up page, select the Private key and CA certificate and Certificate database and certificate database log check boxes, specify the backup location, and then click Next.</p>
<p>On the Select a Password page, type a password to protect the CA private key, and click Next.</p>
<p>On the Completing the Backup Wizard page, click Finish.</p>
<p>After the backup completes, verify the following files in the location you specified CAName.p12 containing the CA certificate and private key Database folder containing files certbkxp.dat, edb#####.log, and CAName.edb</p>
<p>Open command prompt and type Net stop Certsvc to stop Certificate Service</p>
<h5><a name="_Toc349230113"></a>e. Backup CA Registry</h5>
<p>Click Start, point to Run, and type regedit to open the Registry Editor.</p>
<p>In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc, right-click Configuration, and then click Export.</p>
<p>Specify a location and file name, and then click Save. This creates a registry file containing CA configuration data from the source CA.</p>
<h5><a name="_Toc349230114"></a>f. Remove source server</h5>
<p>Launch Add or remove program</p>
<p>Click Add/Remove windows components and uncheck Certificate Services</p>
<p>Click next and finish</p>
<p>Remove source server from domain</p>
<p>Delete AD computer object</p>
<p>Rename source server to some temp name</p>
<h3>2. Preparing Destination Server</h3>
<p>Change destination server name to the initial source server name</p>
<p>Add destination server to domain</p>
<p>Map network share used in taking the backup on source server</p>
<h5><a name="_Toc349230116"></a>a. Import the CA certificate</h5>
<p>Start the Certificates snap-in for the local computer account.</p>
<p>In the console tree, double-click Certificates (Local Computer), and click Personal.</p>
<p>On the Action menu, click All Tasks, and then click Import to open the Certificate Import Wizard. Click Next.</p>
<p>Locate the &lt;CAName&gt;.p12 file created by the CA certificate and private key backup on the source CA, and click Open.</p>
<p>Type the password, and click OK.</p>
<p>Click Place all certificates in the following store.</p>
<p>Verify Personal is displayed in Certificate store. If it is not, click Browse, click Personal, and click OK.</p>
<h5><a name="_Toc349230117"></a>b. Add CA and IIS roles on destination server</h5>
<p>Log on to the destination server, and start Server Manager.</p>
<p>In the console tree, click Roles.</p>
<p>On the Action menu, click Add Roles.</p>
<p>If the Before you Begin page appears, click Next.</p>
<p>On the Select Server Roles page, select the Active Directory Certificate Services and Web Server (IIS) check box, and click Next.</p>
<p>On the Introduction to AD CS page, click Next.</p>
<p>On the Role Services page, click the Certification Authority check box, and Certification Authority Web Enrollment and click Next.</p>
<p>On the Specify Setup Type page, specify either Enterprise and click Next.</p>
<p>On the Specify CA Type page, select Subordinate CA, and click Next.</p>
<p>On the Set Up Private Key page, select Use existing private key and Select a certificate and use its associated private key.</p>
<p>In the Certificates list, click the imported CA certificate, and then click Next.</p>
<p>On the Configure Certificate Database page, specify the locations for the CA database and log files.</p>
<p>On the Confirm Installation Selections page, review the messages, and then click Install.</p>
<p>Hope you liked this article, please continue with the next part where we will discuss in details of the below</p>
<p><a href="http://wp.me/preb1-zO">Part 2 – Restoring the Source from backups and Verifying the migration</a><br />
<a href="http://wp.me/preb1-zP">Part 3 – Back Out procedure</a> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2219/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2219/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2219&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/03/23/step-by-step-instructions-for-subordinate-ca-migration-from-windows-server-2003-to-windows-server-2008-r2-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
		<item>
		<title>Exchange tools for Every Exchange Engineers</title>
		<link>http://smtpport25.wordpress.com/2013/01/10/exchange-tools-for-every-exchange-engineers/</link>
		<comments>http://smtpport25.wordpress.com/2013/01/10/exchange-tools-for-every-exchange-engineers/#comments</comments>
		<pubDate>Thu, 10 Jan 2013 11:02:22 +0000</pubDate>
		<dc:creator>Krishna - MVP</dc:creator>
				<category><![CDATA[Exchange 2003]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[Exchange 2013]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://smtpport25.wordpress.com/?p=2213</guid>
		<description><![CDATA[I found a nice link which has all the necessary tool for exchange available. I am sure i will be using this in the futur http://messagingschool.wordpress.com/2011/04/27/tools-for-exchange-server-200320072010/ Regards, Krishna<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2213&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I found a nice link which has all the necessary tool for exchange available. I am sure i will be using this in the futur</p>
<p><a href="http://messagingschool.wordpress.com/2011/04/27/tools-for-exchange-server-200320072010/">http://messagingschool.wordpress.com/2011/04/27/tools-for-exchange-server-200320072010/</a></p>
<p>Regards,</p>
<p>Krishna</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/smtpport25.wordpress.com/2213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/smtpport25.wordpress.com/2213/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=smtpport25.wordpress.com&#038;blog=6489355&#038;post=2213&#038;subd=smtpport25&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://smtpport25.wordpress.com/2013/01/10/exchange-tools-for-every-exchange-engineers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/38895e9ac4d54aceab379f586bb362d8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krishna</media:title>
		</media:content>
	</item>
	</channel>
</rss>
