August 29, 2007

Modify AD object properties thru CLI

Modify AD object properties thru CLI

We can change AD object properties thru cli. It is necessary if we need to modify the properties of a multiple objects. If you use gui, you need to click the object, select the properties, select the respective tab etc. etc...

Anyway, windows has a command to make it easy. Some of the commands are listed below:

dsadd /? - help for adding objects.
dsget /? - help for displaying objects.
dsmod /? - help for modifying objects.
dsmove /? - help for moving objects.
dsquery /? - help for finding objects matching search criteria.
dsrm /? - help for deleting objects.

I would like to use one of it as an example. For the rest, you need to explore it yourself.

I want to change a password of ahmad to become "abcdef1234" and set it to be required to change at the next logon. ahmad is under OU: manager, and its domain is shazmi.blogspot.com.my

the syntax is:

dsmod user user_dn -pwd abcdef1234 -mustchpwd yes

the command is:


dsmod user "CN=ahmad,OU=manager,DC=shazmi,DC=blogspot,DC=com,DC=my" -pwd abcdef1234 -mustchpwd yes

please make sure that password never expires are not enable. Otherwise, it won't work. anyway you can add -pwdneverexpires no at the end of this command.

If you want to modify properties of multiple user (eg: ahmad under OU Manager and asamaliza under OU Engineer), you can issue this command:


dsmod user "CN=ahmad,OU=manager,DC=shazmi,DC=blogspot,DC=com,DC=my" "CN=asamaliza,OU=engineer,DC=shazmi,DC=blogspot,DC=com,DC=my"-pwd abcdef1234 -mustchpwd yes

But, how if you want to modify a properties of 100 users??

batch file can help you out....





August 21, 2007

hero

Hero

Apabila membaca akhbar harian pagi ini, antara peristiwa yang aku fikir agak menarik adalah kisah seorang pemandu awam yang bersama-sama dengan anggota polis mengejar penjenayah sehingga berjaya memberkas penjenayah terbabit.

Yang agak merbahaya pada pemikiran aku yang agak pesimis; rupa hensem Pakcik Zulkifli terpampang di akhbar dan television. Mungkinkah ada rakan-rakan penjenayah terbabit yang akan membalas dendam?? Tak siapa yang tahu kecuali mereka sendiri...

Ini antara kisah hero yang berjaya. Bagaimana dengan kisah hero2 sebelum ini yang gugur...?? Bagaimana keluarga mereka...??

Kisah ini juga mengingatkan aku pada diri aku sendiri yang cuba menjadi hero suatu ketika dahulu. Dah lebih sepuluh tahun. Tarikh pun tak ingat.. tapi aku rasa dalam tahun 1995 ke 1996 kot.

Malam tu macam biasa aku makan malam kat gerai Abang Amir kat hujung lorong tempat aku tinggal. Kalau tak silap Jalan 1/18 Taman Universiti Indah, Seri Kembangan. Ingat2 lupa...

Tengah aku menikmati mi sup, aku perasan kat simpang lebih kurang 100 meter dari gerai tu, ada satu motor panther dengan dua orang menunggangnya menghampiri seorang perempuan cina yang sedang berjalan sambil bertanyakan sesuatu. Tanya rumah la kot.. tak tau jalan...

Tiba-tiba aku tengok yang sorang tu turun, macam bergelut dengan pompuan tu. Tak berapa nampak apa yg jadi, maklumlah.. malam, lampu jalan je yang ada...pompuan tu pun jerit... aku tak paham butir bicaranya.. so, semua yang kat gerai tu pun tengok la situ... sambil menimbulkan pertanyaan sesama sendiri.. 'apahal tu?'.. 'gaduh kot...!'... 

Lepas tu, motor tu pun pecut... bedezup peginya... aku dengan spontan start moto aku (suzuki gamma 150 - power tak??).. terus gi kat makcik tu..."apahal? apahal?", aku tanya... "Itu olang jahat. Lia sula angkat saya punya lantai.. ala palang", jawab makcik tu. "manyak kuat aaa... kasi angkat lantai, ala palang pulak...!!", hehehe.. bukan aaa... dia kata "rantai sudah kena ragut, orang jahat tu ada parang". 

Aku dengan tak pakai helmet bedezup pi arah mat moto dua ekor tadi lari... semangat berkobar2 nak jadi hero. Sampai jalan turun bukit dari Taman U arah ke Seri Kembangan, aku rasa aku dah dapat moto tu. laju kan aku bawak moto?? Bukan aaa... diorang lari tak laju, mana diorang tau ada orang nak follow. Sambil aku follow tu, aku fikir strategi aku nak jadi hero; tahan diorang macam kaber hero kaber zero? aku takde power macam tu. tendang tayar depan? kalau termiss.. aku yang tergolek.. ikut sampai rumah diorang? lepas tu diorang ada parang.. aku ada apa?? pistol air je.... huhuhu.. last2 sampai je kilang artwright kat selekoh bawah tu, aku ingat2 nombo moto... patah balik naik atas... jumpa balik auntie tadi masih lagi trauma kat simpang tu (dengan harapan aku bawak balik rantai dia kot!! rantai moto aku ada la, rantai tembaga tu).. aku bagi je nombor moto tadi.. kata kat dia "tak dapat kejar la auntie.. diorang laju, dapat nombor ni je.. itupun kalau nak report polis le".

Aku pun pegi balik kat kedai abang amir, ngabihkan mi sup yang dah sejuk. Jadi la citer kejap kat gerai tu malam tu... 

Pakcik Zulkifli kejar sama-sama dengan polis, so dia tak payah fikir risiko kena lawan dengan penjenayah tu sorang2. Kalaupun pakcik ni ada isi, sekali penjahat tu keluar pistol betul... mau silat senteng ke, silat pulut ke.. kuntau ke... susah gak nak lawan...

Aku rasa, memikirkan risiko yang bakal ditanggung menyebabkan ramai orang tak mau jadi hero... melainkan kalu penjenayah tu mat pet yang memang dah tak larat, sekali jentik kat hidung terus jadik michael jackson. Pasal tu banyak kes mat pet mencurik, kantui.. kena belasah lebih kurang je dah padam... tak pasal2 jadi pembunuh tanpa niat... huhuhu..

ITIL

Ever heard of ITIL? If you are familiar with java, you may hear if often.... :) I mean if you are javanese.. or know javanese language... hehehe.. I don't know what does it means in javanese, but I've heard it when I was a child.

Anyway, here is the definition of ITIL which I digged from somewhere:

The ITIL (Information Technology Infrastructure Library) is a globally recognized collection of best practices for information technology (IT) service management (ITSM). The United Kingdom's Central Computer and Telecommunications Agency (CCTA) created the ITIL in response to growing dependence on information technology for meeting business needs and goals. The ITIL provides businesses with a customizable framework of best practices to achieve quality service and overcome difficulties associated with the growth of IT systems. Hewlett-Packard and Microsoft are two businesses that use ITIL as part of their own best practices frameworks.

The ITIL is organized into "sets" of texts which are defined by related functions: service support, service delivery, managerial, software support, computer operations, security management and environmental. In addition to texts, which can be purchased online, ITIL services and products include training, qualifications, software tools and user groups such as the IT Service Management Forum (itSMF).

While owned by the CCTA since the mid-1980s, the ITIL is currently maintained and developed by The National Exam Institute for Informatics (EXIN), a non-proprietary and non-profit organization based in the Netherlands.


You may get further information from this link: http://en.wikipedia.org/wiki/ITIL

August 17, 2007

Kesetiaan...

16 Ogos 2007. Genap 5 tahun aku berkhidmat dengan syarikat aku bekerja sekarang. Antara yang paling lama aku pernah bekerja. Sepanjang 5 tahun, macam-macam pengalaman dan pengajaran yang aku dapat. Antara ilmu yang aku dapat adalah dari aspek teknikal, politik, manusia, sahabat, lawan, emosi, stress, plan, pengurusan (manusia dan bukan manusia), kasih dan sayang (kuang.. kuang.. kuang..), benci, dan macam-macam lagi.

Berbagai jenis manusia juga yang aku jumpa masuk dan keluar dari tempat ini. Ada yang baik, ada yang kurang baik, ada yang tak berapa baik... dan aku juga jumpa yang sangat baik....

Lima tahun kira lama jugak kan...?? aku sekarang ni kalau tak silap no. 5 paling lama dalam kompeni ni. Kalau aku setia kat sini sampai taun depan, silap2 jadi no. 2 ke 3 ke, sebab yang lebih otai dari aku pun macam nak keluar je.... hmmmm...orang lama dan baru masuk dan keluar silih berganti.. ada gak yang dah keluar, masuk balik!! hebat kan... ada yang dikeluarkan, ada yang terkeluar dan ada yang keluar sendiri... aku....?? Kalau panjang jodoh, ada la lagi...

Anyway, aku akan cuba habiskan amanah yang diberikan pada aku at least satu site. Site aku skrg ni le, AMP.... heheheh.. aku start dari mula takde apa-apa sampai lah hand-over pada client nanti. Kalau boleh la.. kalau tak boleh.. nak buat macam mana.. takde rezeki kat sini... :)

huhuhu.. semalam kompeni isteri aku dah declare berapa bulan bonus diorang dapat taun ni... lazat.. lazat... kami di sini...?? nasib baik ada gaji...

August 16, 2007

Aku juga ada FAT







Separa MERDEKA.. dah lepas FAT, next week buleh cuti panjang... huhuhuh

FAT for 34 Intel Servers, 8 Fujitsu Servers, one EVA400 and One MSL6000 in less then 5 hours...

special thanks to cikeasy for assisting me to expedite all the processes... my Superior Superboss Mr. Zulazman (ada macam kipas tak??), and also my other team members Syed Edi, Nazri, Asri, Muin, Asamaliza, Norsalina, Normala, Al-Ghazali, Raznul Asri, Fazry, Imran, Solehin.. sapa lagi yang tertinggal..?? macam menang anugerah je...

I am impressed.... :))

Isu yang tinggal, workstations inventory... huhuhuhuhu... headache.. walaupun tiba2 ramai gadis2 datang membantu, aku takde plan untuk diorang...

tampi macam biasa.. for me... no plan is a part of the plan... ;)

August 13, 2007

Middle Ring Road - KL

If I say MRR2 or MIddle Ring Road 2, I beleive that most of Klang Valley road users will know where it is, or at least ever heard of it. 

How about Middle Ring Road 1? I beleive that most of us will blank a bit if somebody ask us of it. Is it exist?

I guess that MRR1 is a connection of most busiest road in KL. It is Jalan Tun Razak, Jalan Mahameru, Jalan Istana and back to Jalan Tun Razak. Am i right?? please correct me if I am wrong...

August 06, 2007

Fish-MO

What are the FSMO Roles in Active Directory?

Windows 2000/2003 Multi-Master Model
A multi-master enabled database, such as the Active Directory, provides the flexibility of allowing changes to occur at any DC in the enterprise, but it also introduces the possibility of conflicts that can potentially lead to problems once the data is replicated to the rest of the enterprise. One way Windows 2000/2003 deals with conflicting updates is by having a conflict resolution algorithm handle discrepancies in values by resolving to the DC to which changes were written last (that is, "the last writer wins"), while discarding the changes in all other DCs. Although this resolution method may be acceptable in some cases, there are times when conflicts are just too difficult to resolve using the "last writer wins" approach. In such cases, it is best to prevent the conflict from occurring rather than to try to resolve it after the fact. 

For certain types of changes, Windows 2000/2003 incorporates methods to prevent conflicting Active Directory updates from occurring. 

Windows 2000/2003 Single-Master Model
To prevent conflicting updates in Windows 2000/2003, the Active Directory performs updates to certain objects in a single-master fashion. 

In a single-master model, only one DC in the entire directory is allowed to process updates. This is similar to the role given to a primary domain controller (PDC) in earlier versions of Windows (such as Microsoft Windows NT 4.0), in which the PDC is responsible for processing all updates in a given domain. 

In a forest, there are five FSMO roles that are assigned to one or more domain controllers. The five FSMO roles are: 

Schema Master: 

The schema master domain controller controls all updates and modifications to the schema. Once the Schema update is complete, it is replicated from the schema master to all other DCs in the directory. To update the schema of a forest, you must have access to the schema master. There can be only one schema master in the whole forest. 

Domain naming master: 

The domain naming master domain controller controls the addition or removal of domains in the forest. This DC is the only one that can add or remove a domain from the directory. It can also add or remove cross references to domains in external directories. There can be only one domain naming master in the whole forest. 

Infrastructure Master: 

When an object in one domain is referenced by another object in another domain, it represents the reference by the GUID, the SID (for references to security principals), and the DN of the object being referenced. The infrastructure FSMO role holder is the DC responsible for updating an object's SID and distinguished name in a cross-domain object reference. At any one time, there can be only one domain controller acting as the infrastructure master in each domain. 

Note: The Infrastructure Master (IM) role should be held by a domain controller that is not a Global Catalog server (GC). If the Infrastructure Master runs on a Global Catalog server it will stop updating object information because it does not contain any references to objects that it does not hold. This is because a Global Catalog server holds a partial replica of every object in the forest. As a result, cross-domain object references in that domain will not be updated and a warning to that effect will be logged on that DC's event log. If all the domain controllers in a domain also host the global catalog, all the domain controllers have the current data, and it is not important which domain controller holds the infrastructure master role.

Relative ID (RID) Master: 

The RID master is responsible for processing RID pool requests from all domain controllers in a particular domain. When a DC creates a security principal object such as a user or group, it attaches a unique Security ID (SID) to the object. This SID consists of a domain SID (the same for all SIDs created in a domain), and a relative ID (RID) that is unique for each security principal SID created in a domain.  Each DC in a domain is allocated a pool of RIDs that it is allowed to assign to the security principals it creates. When a DC's allocated RID pool falls below a threshold, that DC issues a request for additional RIDs to the domain's RID master. The domain RID master responds to the request by retrieving RIDs from the domain's unallocated RID pool and assigns them to the pool of the requesting DC. At any one time, there can be only one domain controller acting as the RID master in the domain. 

PDC Emulator: 

The PDC emulator is necessary to synchronize time in an enterprise. Windows 2000/2003 includes the W32Time (Windows Time) time service that is required by the Kerberos authentication protocol. All Windows 2000/2003-based computers within an enterprise use a common time. The purpose of the time service is to ensure that the Windows Time service uses a hierarchical relationship that controls authority and does not permit loops to ensure appropriate common time usage.

The PDC emulator of a domain is authoritative for the domain. The PDC emulator at the root of the forest becomes authoritative for the enterprise, and should be configured to gather the time from an external source. All PDC FSMO role holders follow the hierarchy of domains in the selection of their in-bound time partner. 

In a Windows 2000/2003 domain, the PDC emulator role holder retains the following functions: 

Password changes performed by other DCs in the domain are replicated preferentially to the PDC emulator.

Authentication failures that occur at a given DC in a domain because of an incorrect password are forwarded to the PDC emulator before a bad password failure message is reported to the user. 

Account lockout is processed on the PDC emulator. 

Editing or creation of Group Policy Objects (GPO) is always done from the GPO copy found in the PDC Emulator's SYSVOL share, unless configured not to do so by the administrator.

The PDC emulator performs all of the functionality that a Microsoft Windows NT 4.0 Server-based PDC or earlier PDC performs for Windows NT 4.0-based or earlier clients. 

This part of the PDC emulator role becomes unnecessary when all workstations, member servers, and domain controllers that are running Windows NT 4.0 or earlier are all upgraded to Windows 2000/2003. The PDC emulator still performs the other functions as described in a Windows 2000/2003 environment. 

At any one time, there can be only one domain controller acting as the PDC emulator master in each domain in the forest. 

anyway.. FSMO stand for what??

Operasi Guru Bujang Boleh-berubah... :p

FAT vs NTFS

A file system is a method for storing and organizing computer files and the data they contain to make it easy to find and access them. FAT is the file system used in the earlier stage of Microsoft's OS (MS-Dos, Windows 3.11, Windows 95, 98) which was replaced by NTFS.

FAT(File Allocation Table) is a file system used by MS-DOS and other Windows Operating System. It is a system in which Windows stores information about each file in the File Allocation Table, so that it can retrieve later.

NTFS (New Teknologi File System) is an advanced file system that provides performance, security, reliability, and advanced features that are not found in any version of FAT.

The Benefits of NTFS:

Support for large hard drives
Support for large file sizes
Simple management of single disk partitions
Improved performance

Other Features of NTFS:

Security and access control
Distributed link tracking
Hard links for files
Symbolic links for directories
More efficient context indexing
File compression
File encryption
Volume shadow copy backup
Flexible metadata support for attributes, properties, and streams
Ability to mount a local drive to a folder on an NTFS volume

Considering the benefits and features of NTFS, it is wiser to consider NTFS.

So, How to Convert FAT to NTFS?

Note: This solution will not affect any data stored in the partition while converting but I advice you to have a backup. And after you convert to NTFS, you cannot convert back to FAT.

Go to Command prompt (Start -> All Programs -> Accessories -> Command Prompt)
Type the following in the command prompt
Convert x: /fs:ntfs
Where x€™ represents the drive which you want to covert.

In case if you want to convert the partition that is currently in use, you will not be able to convert and you can schedule the task when you restart the computer. This may be the scenario if you are trying to the convert the partition where your Windows is located.

Cerita BukuMuka

Cari dalam cerita ini