The T-qualiser

T-qualiser t-shirt with graphic equaliserEarlier this evening I won a t-shirt in a quiz (thanks to Phil Cross at Microsoft). I already have many Microsoft t-shirts, but this one is a little bit different… it has a battery pack sewn in and a graphic equaliser on the front that responds to the ambient noise. Cool huh? Now, where can I go clubbing in Reading on a Tuesday night? (On second thoughts I’ll wait a while as I need to lose a few pounds before I can squeeze into it!)

Groove, SharePoint or OCS Group Chat – which works for you?

Earlier today I was in an interesting session at the Microsoft UK user groups community day when Art Ho gave a presentation on group chat and discussion forums. What became apparent in Art’s presentation is that Microsoft has a number of products which, on the face of it, offer similar features and functionality, but each has its own strengths and weaknesses:

Groove Discussions SharePoint Discussions Groove Chat OCS Group Chat*
Persistent Yes Yes Yes Yes
Federation Yes Yes Yes Yes
Integrated Sort of Yes No no
Search Yes Yes (strong) No Yes
Realtime No No Yes Yes
Collaborative Yes Yes No No
Offline Yes No Yes No

* OCS Group Chat is still a beta product at this time and was formerly Parlano MindAlign (Parlano were acquired by Microsoft last year)

Basically, it breaks down like this. Think about the purpose of the collaboration and what end users need. Do they need search? If so, then SharePoint is the clear leader. Are you looking for one product, or can a mixture of products meet the requirements (e.g. collaborate using a Groove workspace and publish the final document to a SharePoint document library)? Finally, you can have real-time or collaborative working, but it seems you can’t have both (at least with this technology selection).

(Note that other solutions are available, this just compares three Microsoft products that all seem to compete in the same space.)

Publishing handouts from PowerPoint to Word

I’ve spent a lot of time over the last few weeks preparing a couple of presentions to deliver at the Microsoft UK user groups community day on Wednesday. Even though my slides will act as an aide mémoire, I’ve written full speaker notes, which are included in the slidedecks that I’ll be making available for download, as well as all the extra material that I chopped because it didn’t all fit into the hour-long presentation slots.

Publish handouts from PowerPoint to WordI wanted to print some notes pages from my presentation, but PowerPoint doesn’t allow multiple pages of notes for a single slide. What I discovered it can do though is publish notes pages to Word, where you have much more control over the formatting.

The help that I originally found on the Microsoft website was for PowerPoint 2003 but the image here shows the PowerPoint 2007 equivalent.

Removing phantom network adapters from virtual machines

Last night, I rebuilt my Windows Server 2008 machine at home to use the RTM build (it was running on an escrow build from a few days before it was finally released) and Hyper-V RC0. It was non-trivial because the virtual machines I had running on the server had to be recreated in order to move from the Hyper-V beta to the release candidate (which meant merging snapshots) and so it’s taken me a few weeks to get around to it.

The recreation of the virtual machine configuration (but using the existing virtual hard disk) meant that Windows detected new network adapters when I started up the VM. Where I previously had a NIC called Local Area Connection using Microsoft VMBus Network Adapter I now had a NIC called Local Area Connection 2 using Microsoft VMBus Network Adapter #2. The original adapter still configured but not visible. Ordinarily, that’s not a problem – the friendly name for the NIC can be edited but when I went to apply the correct TCP/IP settings, a warning was displayed that:

The IP address ipaddress you have entered for this network adapter is already assigned to another adapter Microsoft VMBus Network Adapter. Microsoft VMBus Network Adapter is hidden from the network and Dial-up Connections folder because it is not physically in the computer or is a legacy adapter that is not working. If the same address is assigned to both adapters and they become active, only one of them will use this address. This may result in incorrect system configuration. Do you want to enter a different IP address for this adapter in the list of IP addresses in the advanced dialog box?

That wasn’t a problem for my domain controller VM, but the ISA Server VM didn’t want to play ball – hardly surprising as I was messing around with the virtual network hardware in a firewall!

In a physical environment, I could have reinserted the original NIC, uninstalled the drivers, removed the NIC and then installed the new one, but that was less straightforward with my virtual hardware as the process had also involved upgrading the Hyper-V gues integration components. I tried getting Device Manager to show the original adapter using:

set devmgr_show_nonpresent_devices=1
start devmgmt.msc

but it was still not visible (even after enabling the option to show hidden devices). Time to break out the command line utilities.

As described in Microsoft knowledge base article 269155, I ran devcon to identify the phantom device and then remove it. Interestingly, running devcon findall =net produced more results than devcon listclass net and the additional entries were the original VMBus Network Adapters. After identifying their identifier for the NIC (e.g. VMBUS\{20AC6313-BD23-41C6-AE17-D1CA99DA4923}\5&37A0B134&0&{20AC6313-BD23-41C6-AE17-D1CA99DA4923}: Microsoft VMBus Network Adapter), I could use devcon to remove the device:

devcon -r remove "@VMBUS\{20AC6313-BD23-41C6-AE17-D1CA99DA4923}\5&37A0B134&0&{20AC6313-BD23-41C6-AE17-D1CA99DA4923}"

Result! devcon reported:

VMBUS\{20AC6313-BD23-41C6-AE17-D1CA99DA4923}\5&37A0B134&0&{20AC6313-BD23-41C6-AE17-D1CA99DA4923}: Removed
1 device(s) removed.

I repeated this for all phantom devices (and uninstalled the extra NICs that had been created but were visible, using Device Manager). I then refreshed Device Manager (scan for hardware changes), plug and play kicked in and I just had the NIC(s) that I wanted, with the original name(s). Finally, I configured TCP/IP as it had been before the Hyper-V upgrade and ISA Server jumped into life.

Just one extra point of note: the devcon package that Microsoft supplies in Microsoft knowledge base article 311272 includes versions for i386 and IA64 architectures but not x64. It worked for me on my ISA Server virtual machine, which is running 32-bit Windows Server 2003 R2, but was unable to remove the phantom device on my domain controller, which uses 64-bit Windows Server 2003 R2. I later found that devcon is one of the Support Tools on the Windows installation media (suptools.msi). After installing these, I was able to use devcon on x64 platforms too.

Xtremely Technical Seminars

If I was asked to name an industry expert on Active Directory, one of the names that would come to mind consultant is John Craddock of Kimberry Associates, who I have seen present with Sally Storey many times on behalf of Microsoft. John has formed a new company called XTSeminars (Xtremely Technical Seminars) and I’m pleased to see that John and Sally are working with another speaker whom I hold in high regard – Rafal Lukawiecki of Project Botticelli.

XTSeminars are a business venture – and as such the events are chargeable; however, based on previous events I’ve seen John and Sally present, I have absolutely no issue in recommending them – as they suggest:

Attend one of the seminars and not only will you rapidly get the real details but also an XTSeminars workbook packed with useful tips and techniques and a DVD with narrated videos of all the demos. Attend the seminars as a sponge and absorb the knowledge. All for a fraction of the cost of working with a lead consultant!

Definitely worth a slice of the training budget for anyone looking to improve their in-depth technical knowledge of key Microsoft technologies.

Free SharePoint enterprise search training

Last autumn, I attended some technical training on Microsoft Office SharePoint Server (MOSS) 2007 Enterprise Search, led by Martin Harwar. I just got an e-mail from Martin to say that he has recorded over 18 hours of free technical training about enterprise Search with SharePoint technologies. Based on my experiences of attending the course, it’s worth checking out for anyone looking to learn (or refresh) their MOSS knowledge.

So much for Apple’s legendary build quality

Readers of this blog may recall that I bitched about the time it took for Apple to deliver my new MacBook recently. It was ordered on 5 February, finally arrived on 14 February – and broken on 31 March. What did I do to break it? I rested my hands on the palm rest. Is that a user error?

Seriously, I was in the pub last night with Alex and Simon (from ascomi, who are helping me work on a new version of this site) and there was a fair degree of Mac vs. PC banter going on when all of a sudden there was a crack under my right palm and I saw that part of the top cover/keyboard assembly was split at the edge. I had only had the computer in my possession for 6 weeks and have really looked after it – to say that I was not happy is a bit of an understatement. So much for Apple’s legendary build quality.

Split top cover on nearly-new MacBook after 6 weeks of light (and careful) use

As it happens, some people regard the MacBook as the ugly step child of the Apple family – I disagree (hence the reason I bought one) but I do think that it is a little pricey and for that premium pricing I do expect premium build quality. It may not be as bad as the last Dell notebook I used but it is nowhere near as good as my IBM ThinkPad T40 and I have never had a case crack through normal use (drops and inadequate protection in transit maybe).

It seems that the MacBook case crack is a common defect and, whilst Apple refuses to acknowledge it as a design fault (it seems to occur next to the small bevel that keeps the screen and keyboard apart when the MacBook is closed, suggesting that may be causing undue pressure on that part of the top case) but Brian Ford wrote about the same problem four days ago and although getting picked up by John Gruber (Daring Fireball) will have helped, last night had 144 comments on his post. On that basis, this does not appear to be an isolated issue.

Furthermore, the problem has been around for a while now and whilst some reports suggest that Apple has changed the affected component and it does not occur on new models, I see no evidence of that as my computer is less than two months old – I call that pretty new.

I phoned AppleCare as soon as they were open this morning and spoke to a really helpful guy. He asked me if I had taken out AppleCare protection (no, but I have a warranty) and then proceeded to make an appointment with an Apple “Genius” at the Apple Store (I don’t know what’s worse – Apple’s idea that their tech support guys are all geniuses or Microsoft’s idea that there are IT departments full of heroes all across the world) . When there were no slots available, I asked which store he had tried and he said “Oh, most people ask for Regent Street in London”. I said “I’d like an appointment at my local store please” and suddenly there were lots of slots free and I just needed to pick my time!

So, I set off to the Milton Keynes Apple Store, arrived a couple of minutes early, booked in, and saw my name top of the Mac queue at the Genius Bar. Then I waited, and waited, and pestered the sales staff until a (very helpful) genius called Simon came over to help. It seems that the iPod queue and the Mac queue are actually one, and that there was only one genius, who was very very busy with a lot of people to see this morning, meanwhile the shop was littered with trainers and sales staff apparently doing very little.

Thankfully, Simon the genius noted that my MacBook was in “mint” condition (although the Genius Bar Work Authorisation will only allow it to be recorded as “As New”) and there was no argument that it had been mistreated in any way. Apple will be replacing the top cover/keyboard assembly and say that it will take 5 to 7 days but why so long? It should be a 1 hour job (maximum), plus the time to obtain parts and schedule the work – so, 2 to 3 days would be more reasonable. Doubtless I will hear from support technicians who say “you try our job for a day – we work really hard” (to which I say “I’ve been there – and so do lots of people”). In the meantime, I’ll be without my MacBook for a week.

I’ve posted my picture of the issue to the Flickr group that has been set up to highlight this issue. In the meantime, if you are having similar problems, I urge you to do the same and to leave a comment on Brian Ford’s Newsvine article so that he can build enough evidence to (hopefully) get Apple to actually do something about this issue.

The Windows runas command and the /netonly switch

Earlier today I needed to administer a Windows Server remotely, using a Microsoft Management Console (MMC) snap-in. Unfortunately, the computer I was using was in one domain and the remote server was in a workgroup, meaning that many of the MMC operations failed due to security issues. I tried running MMC as the administrator for the remote machine (using runas /user:remotecomputername\username mmc) but kept on getting a message that indicated an authentication failure:

RUNAS ERROR: Unable to run – mmc
1311: There are currently no logon servers available to service the logon request.

Then I found out about an obscure switch for the runas command – /netonly, used to indicate that the supplied credentials are for remote access only. By changing my command to:

runas /netonly /user:remotecomputername\username mmc

I was able to authenticate against the remote computer without needing the credentials to also be valid on the local computer, as described by Craig Andera.

Customising Windows Server 2008 server core

A few months back, I wrote a post with a few commands to get started with server core on Windows Server 2008. Since then, I’ve had some fun tweaking server core installations (including some cheekiness installing third party web servers and browsers).

Sander Berkouwer wrote a series of blog posts last summer that look at changing the look and feel of a server core installation:

  1. Changing regional and language options (international settings) as well as time and date options.
  2. Changing display settings such as screen resolution and color depth, screen saver, window and background colors, cleartype and windows dragging settings.
  3. Changing keyboard and mouse settings/cursors.
  4. Changing the splash screen, logon screen and tweaking the command prompt window.

Server core may be intended for core infrastructure servers in lights-out data centres but even so, some customisation can be useful. Sander’s notes should help most people get things started.

Surfing with server core

The whole point of the server core installation mode for Windows Server 2008 is a reduced attack surface – no Windows Explorer, no Internet Explorer, no .NET Framework. That’s all well and good but sometimes it’s useful to download a file over HTTP to a server core machine.

No problem – just download a version of GNU wget that has been compiled for Windows and use that to download the file. It needed a couple of configuration items to get past my corporate proxy server but worked flawlessly:

set http_proxy=http://proxyserver:portnumber
wget --proxy-user=domainname\username --proxy-passwd=password http://uri/

That’s probably as far as most people need to go – adding a simple command line utility to a command-line Windows installation – but I wanted to take things a step further (purely out of curiosity) and I installed Mozilla Firefox (v2.0.0.13). It worked, so I decided to try Apple Safari (v3.1) and Opera (v9.26). Safari installed (except the Bonjour component) but has a dependency on the Internet Options control panel applet (which is not present in server core) so I couldn’t define any proxy server settings. Meanwhile, Opera had no noticeable issues installing and loading a few test web pages. Next, I tried Internet Explorer 8 beta 1 and, as I expected, the installation failed. Bizarrely, it didn’t detect that I was trying to install it on server core but did attempt the installation, before failing and advising a restart followed by visit a web page (presumably using a competitor’s browser!) which redirects to Microsoft knowledge base article 949220.

Finally, I decided to go to the other extreme and try a text-mode browser. I found a version of Lynx that has been compiled for Windows but in order to get past my proxy server it needed the same environment variable as wget:

set http_proxy=http://proxyserver:portnumber

Even with this, it is incapable of performing authenticated proxy operations so I kept getting an HTTP 407 response. The workaround is to use the NTLM Authorization Proxy Server (NTLMAPS), which depends on Python (for which I found a 64-bit MSI package for Windows). Basically, NTLMAPS acts as a local proxy, configured to add the authentication headers and pass the request to the upstream server.

By editing the server.cfg file to include the following entries (all other configuration items were left at their defaults) and running the start runserver.bat command to launch the NTLMAPS server I was able to get NTLMAPS to prompt me for my password at startup and listen for HTTP requests (but not HTTPS) on port 5865:

[GENERAL]
PARENT_PROXY:proxyserver
PARENT_PROXY_PORT:portnumber

[NTLM_AUTH]
NT_DOMAIN:domainname
USER:username
PASSWORD:

Then, I ran the following:

set http_proxy=http://localhost:5865/
lynx

and was able to successfully browse the Internet through my corporate proxy server.

In all seriousness, I can’t really think of a good reason to install a full browser on server core but the wget command is probably useful. Even so, it’s still good to know that there are a few options for emergency surfing from a server core installation.