tisdag 18 januari 2022

Certificate change on AD LDS (ADAM)

Last weekend I came across a problem to which I could not find a solution on Google.

The ldaps certificate on one of our AD LDS (ADAM) servers had expired. As we've had problems changing AD LDS certificates before I knew it could be tricky.

But after following all available instructions (for example https://www.dirwiz.com/kb/345 which explains how the private keys in C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys must have the correct permissions set for the AD LDS service to read the private key for the certificate we still could not get it working.

Finally I found a/the solution by chance:

First backup the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Services\ADAM_Lund01\SystemCertificates\My\Certificates

Then delete all keys there EXCEPT for the key matching the SHA1/Thumbprint of your new certificate.

Restart the AD LDS service and you're good to go.

If your new certificate is from a different CA than your old certificate you will most likely have to reboot your server and not just the service.

fredag 13 oktober 2017

Disabled administrator account on Windows 10

Having disabled my own account on Windows 10 twice(!) by mistake (with no other accounts available for login) there is a nice and easy tip for solving this. Google has lots of tips on how to solve it, with everything from reinstallation to entering the command prompt at shift-reboot but none of these tricks worked for me. Mostly because no accounts are available at the shift-reboot command prompt and a reinstallation seems a bit over the edge.

Instead, use the following trick:
https://4sysops.com/archives/reset-a-windows-10-password/

In short:
1) Boot from a Windows 10 CD
2) Start a command prompt
3) rename utilman.exe in c:\windows\system to utilman_old.exe
4) copy cmd.exe to utilman.exe
5) Reboot
6) Click the Easy-of-access icon at the Welcome screen and the Command Prompt should start
7) Type net user [your-user-name] /active:yes
8) Reboot.
9) ???
10) Profit!

tisdag 21 mars 2017

Removing Skype from Windows 7/10 autostart

While it's possible to remove Skype from Autostart by logging into Skype and the changing the settings, most people do not want to login to change this settings.

Instead, remove Skype.exe from the following key in the registry:

Computer\HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run

fredag 30 december 2016

Switching from RAID to AHCI on Windows 10

http://triplescomputers.com/blog/uncategorized/solution-switch-windows-10-from-raidide-to-ahci-operation/

  1. Right-click the Windows Start Menu. Choose Command Prompt (Admin).
  2. Type this command and press ENTER: bcdedit /set {current} safeboot minimal
  3. Restart the computer and enter BIOS Setup (the key to press varies between systems).
  4. Change the SATA Operation mode to AHCI from either IDE or RAID (again, the language varies).
  5. Save changes and exit Setup and Windows will automatically boot to Safe Mode.
  6. Right-click the Windows Start Menu once more. Choose Command Prompt (Admin).
  7. Type this command and press ENTER: bcdedit /deletevalue {current} safeboot
  8. Reboot once more and Windows will automatically start with AHCI drivers enabled.

fredag 29 oktober 2010

Epic log på geocaching.com


Ibland letar jag upp loggen och bara sitter och tittar på den. Den är fantastisk ur alla aspekter.