<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel xmlns:atom="http://www.w3.org/2005/Atom"><title>Daniel's IT Blog</title><link>http://daniels-it.blog.co.uk/</link><atom:link xmlns:atom="http://www.w3.org/2005/Atom" rel="self" href="http://daniels-it.blog.co.uk/feed/rss2/posts/"/><description>For Everything IT!</description><language>en-EU</language><generator>MokoFeed</generator><ttl>10</ttl><image><title>Daniel's IT Blog</title><link>http://daniels-it.blog.co.uk/</link><url>http://data5.blog.de/design/preview/87/dbac6d4a6c2d97e4188cfca386e853_160x200.jpg</url></image><item><title>New address for Daniel's IT Blog</title><link>http://daniels-it.blog.co.uk/2007/07/10/new_address_for_daniel_s_it_blog~2606004/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2007-07-10:/2007/07/10/new_address_for_daniel_s_it_blog~2606004/</guid><pubDate>Tue, 10 Jul 2007 02:53:53 +0200</pubDate><description>	&lt;p&gt;Hi Guys,&lt;br&gt;
            As per my previous blog,  my blog site has now moved... my new address is  &lt;a href="http://daniels-it.spaces.live.com/"&gt;http://daniels-it.spaces.live.com/&lt;/a&gt; &lt;/p&gt;
	&lt;p&gt;come back and visit often...&lt;/p&gt;
	&lt;p&gt;&lt;img src="/img/smilies/icon_wave.gif" alt=":wave:" class="middle" border="0"&gt;&lt;img src="/img/smilies/graybigeek.gif" alt="88|" class="middle" border="0"&gt;&lt;br&gt;
cheers
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2007/07/10/new_address_for_daniel_s_it_blog~2606004/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2007/07/10/new_address_for_daniel_s_it_blog~2606004/#comments</comments></item><item><title>My Departure from the UK</title><link>http://daniels-it.blog.co.uk/2007/07/09/my_departure_from_the_uk~2605448/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2007-07-09:/2007/07/09/my_departure_from_the_uk~2605448/</guid><pubDate>Mon, 09 Jul 2007 22:57:18 +0200</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;                    I have now left the UK and returned to my home in Melbourne, Australia, havign spent just over 2 and a half years worth of living &amp; working in London, it gave me the opportunity to learn a heap, get some great experience and of course travel!&lt;/p&gt;
	&lt;p&gt;I will be moving to a new .AU blog site soon when I decide upon which one takes my fancy.. As soon as I have decided on one, ill post the address for you guys..&lt;/p&gt;
	&lt;p&gt;in the meantime keep visiting this site for the latest and greatest info....&lt;/p&gt;
	&lt;p&gt;&lt;img class="smiley" src="http://www.blog.co.uk/srv/tinymce/jss/plugins/blogdeemotions/smilies/icon_wave.gif" border="0" alt="" width="26" height="22"&gt;&lt;/p&gt;
	&lt;p&gt;thanks&lt;/p&gt;
	&lt;p&gt;Dan
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2007/07/09/my_departure_from_the_uk~2605448/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2007/07/09/my_departure_from_the_uk~2605448/#comments</comments></item><item><title>Windows Server 2008 Cont'd:  Active Directory Federation Services</title><link>http://daniels-it.blog.co.uk/2007/06/29/windows_server_2008_cont_d_active_direct~2541427/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2007-06-29:/2007/06/29/windows_server_2008_cont_d_active_direct~2541427/</guid><pubDate>Fri, 29 Jun 2007 11:29:06 +0200</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;                  Part 3 of my Windows Server 2008 series is covering Active Directory Federation Services. &lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;So what is AD FS?&lt;/strong&gt;&lt;/p&gt;
	&lt;p&gt;Active Directory Federation Services (AD FS) is a feature in the Windows Server 2003 R2 and Windows Server 2008 OS's that provides Web single-sign-on (SSO) technologies to authenticate a user to multiple, related Web applications over the life of a single online session. AD FS accomplishes this by securely sharing digital identity and entitlement rights, or "claims," across security and enterprise boundaries. &lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;Features in AD FS&lt;br&gt;&lt;/strong&gt;&lt;br&gt;In Windows Server 2008, AD FS includes new features that were not available in Windows Server 2003 R2. &lt;br&gt;This new functionality is designed to ease administrative overhead and to further extend support for key applications:&lt;/p&gt;
	


&amp;bull;
	
&lt;p&gt;Improved installation: AD FS is included in Windows Server 2008 as a server role, and there are new server validation checks in the installation wizard.&lt;/p&gt;


	
&amp;bull;
	
&lt;p&gt;Improved application support: AD FS is more tightly integrated with Microsoft Office SharePoint Server 2007 and Active Directory Rights Management Services (AD RMS).&lt;/p&gt;


	
&amp;bull;
	
&lt;p&gt;A better administrative experience when you establish federated trusts: Improved trust policy import and export functionality helps to minimize partner-based configuration issues that are commonly associated with federated trust establishment.&lt;/p&gt;




	&lt;p&gt;The following are some of the key features of AD FS: 
&lt;p&gt;&lt;u&gt;Federation and Web SSO&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;When an organization uses Active Directory Domain Services (AD DS), it experiences the benefit of SSO functionality through Windows Integrated authentication within the organization's security or enterprise boundaries. AD FS extends this functionality to Internet-facing applications. This makes it possible for customers, partners, and suppliers to have a similar, streamlined, Web SSO user experience when they access the organization&amp;rsquo;s Web-based applications. Furthermore, federation servers can be deployed in multiple organisations to facilitate business-to-business (B2&lt;img src="/img/smilies/icon_cool.gif" alt="B)" class="middle" border="0"&gt; federated transactions between partner organizations. &lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Web Services (WS)-* interoperability&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;AD FS provides a federated identity management solution that interoperates with other security products that support the WS-* Web Services Architecture. AD FS does this by employing the federation specification of WS-*, called WS-Federation. The WS-Federation specification makes it possible for environments that do not use the Windows identity model to federate with Windows environments. &lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Extensible architecture&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;AD FS provides an extensible architecture that supports the Security Assertion Markup Language (SAML) 1.1 token type and Kerberos authentication (in the Federated Web SSO with Forest Trust design). AD FS can also perform claim mapping, for example, modifying claims using custom business logic as a variable in an access request. Organisations can use this extensibility to modify AD FS to coexist with their current security infrastructure and business policies. &lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Extending AD DS to the Internet&lt;/u&gt;&lt;br&gt;AD DS serves as a primary identity and authentication service in many organisations. With Windows Server 2003 Active Directory and Windows Server 2008 AD DS, forest trusts can be created between two or more Windows Server 2003 forests or Windows Server 2008 forests to provide access to resources that are located in different business units or organisations. &lt;/p&gt;
	&lt;p&gt;However, there are designs in which forest trusts are not a viable option. For example, access across organisations may have to be limited to only a small subset of individuals, not every member of a forest.&lt;/p&gt;
	&lt;p&gt;By employing AD FS, organisations can extend their existing Active Directory infrastructures to provide access to resources that are offered by trusted partners across the Internet. These trusted partners can include external third parties or other departments or subsidiaries in the same organization. &lt;/p&gt;
	&lt;p&gt;AD FS supports distributed authentication and authorisation over the Internet. AD FS can be integrated into an organisation's or department&amp;rsquo;s existing access management solution to translate the claims that are used in the organisation into claims that are agreed on as part of a federation. AD FS can create, secure, and verify the claims that move between organisations. It can also audit and monitor the communication activity between organisations and departments to help ensure secure transactions.&lt;/p&gt;
	&lt;p&gt;ok installing ADFS...&lt;/p&gt;
	&lt;p&gt;First up, install the role through server manager, &lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741048" title="adfs1"&gt;&lt;img src="http://data4.blog.de/media/048/1741048_b281a3c51b_m.jpg" alt="adfs1" hspace="5" vspace="5" width="500" height="362"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;you will then get the welcome screen, please ensure the Domain controller or member server is a member of the domain, and bear in mind when you install additiona features of ADFS you MUST seperate the ADFS proxy server and the ADFS feature foles.  You cannot run both on the one box.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741052" title="adfs2"&gt;&lt;img src="http://data4.blog.de/media/052/1741052_4a5075decf_m.jpg" alt="adfs2" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;br&gt;Note:  you will be required to install the additional IIS services as well.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741057" title="adfs3"&gt;&lt;img src="http://data4.blog.de/media/057/1741057_86f7b5acf2_m.jpg" alt="adfs3" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;In this demonstration i will be installing the ADFS service and the Web Agents. choose next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741059" title="adfs4"&gt;&lt;img src="http://data4.blog.de/media/059/1741059_64eff0433d_m.jpg" alt="adfs4" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;As I am installing the Web Agents Role, it is prompting me for an SSL certificate, I have some existing ADCS certificates which i could use, or if your organisation has its own set of SSL certificates for IIS, select them now, or alternatively create a new one.  For the purpose of this demo I will create a new certificate.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741061" title="adfs5"&gt;&lt;img src="http://data4.blog.de/media/061/1741061_e72bb77320_m.jpg" alt="adfs5" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741071" title="adfs6"&gt;&lt;img src="http://data4.blog.de/media/071/1741071_d4951ce13a_m.jpg" alt="adfs6" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;br&gt;Again because I am installing the Web Agent feature, one of its sub-requirements is token authentication, at this point it is asking me for a certificate for that.  I will create a self signed one, but in a production environment you would have a certificate signed by a External CA to issue. &lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741072" title="adfs7"&gt;&lt;img src="http://data4.blog.de/media/072/1741072_716e566eb9_m.jpg" alt="adfs7" hspace="5" vspace="5" width="496" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;It is now prompting me for my federation server for web agent communications.  In a production environment you should have this on a seperate federation server, but for this demo I am going to point it to the local DC.  Selecting Validate will confirm web agent communication with your desired federation server.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741079" title="adfs8"&gt;&lt;img src="http://data4.blog.de/media/079/1741079_b572c7a09b_m.jpg" alt="adfs8" hspace="5" vspace="5" width="497" height="375"&gt;&lt;/a&gt;&lt;br&gt;The next stage involves specifying the trustpolicy xml location.  If your organisation has its own policies for this please make the appropriate changes, but I will keep everything as default.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741092" title="adfs9"&gt;&lt;img src="http://data4.blog.de/media/092/1741092_a01b1ec253_m.jpg" alt="adfs9" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;The next part of the install involves configuring your IIS7 components, choose next to the welcome screen.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741097" title="adfs10"&gt;&lt;img src="http://data4.blog.de/media/097/1741097_92829d1e33_m.jpg" alt="adfs10" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Leave all IIS components selected as default unless you have specific requirements.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741099" title="adfs11"&gt;&lt;img src="http://data4.blog.de/media/099/1741099_93deb469c6_m.jpg" alt="adfs11" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Confirm your installation requirements and choose install.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741101" title="adfs12"&gt;&lt;img src="http://data4.blog.de/media/101/1741101_6f12432128_m.jpg" alt="adfs12" hspace="5" vspace="5" width="498" height="375"&gt;&lt;/a&gt;&lt;br&gt;installation proceding..&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741106" title="adfs13"&gt;&lt;img src="http://data4.blog.de/media/106/1741106_ac64f12fe7_m.jpg" alt="adfs13" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;installation finishes... choose close&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741111" title="adfs14"&gt;&lt;img src="http://data4.blog.de/media/111/1741111_a59ef1942c_m.jpg" alt="adfs14" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;note:  no restart is required.  you can access the AD FS snap in through mmc.  In the example below I have created an AD account store.  Also note you break up your policy for internal clients and external clients (partners).&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741113" title="adfs15"&gt;&lt;img src="http://data4.blog.de/media/113/1741113_43d3d475f2_m.jpg" alt="adfs15" hspace="5" vspace="5" width="492" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;I am now going to create a new application definition, to do this, right click on applications and select new and application...&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741117" title="adfs16"&gt;&lt;img src="http://data4.blog.de/media/117/1741117_f328181ff5_m.jpg" alt="adfs16" hspace="5" vspace="5" width="490" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;The wizard starts, choose next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741120" title="adfs17"&gt;&lt;img src="http://data4.blog.de/media/120/1741120_4ae4451026_m.jpg" alt="adfs17" hspace="5" vspace="5" width="490" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Now you need to specify whether your application will use token based authentication or claims-aware (.net), in this example I am going to use claims-aware.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741122" title="adfs18"&gt;&lt;img src="http://data4.blog.de/media/122/1741122_2e3d96f588_m.jpg" alt="adfs18" hspace="5" vspace="5" width="491" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;now enter your display name and URL path, in this case I will be using my HP SIM application.  &lt;/p&gt;
	&lt;p&gt;Please note:  Do NOT use ADFS with Sharepoint SSO, use either one or the other not both, although SSO works great, if your organisation has a policy to use ADFS only, ensure you remove the SSO option in your initial sharepoint installation configuration.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741123" title="adfs19"&gt;&lt;img src="http://data4.blog.de/media/123/1741123_c8cf8bc395_m.jpg" alt="adfs19" hspace="5" vspace="5" width="490" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Now you specify your identity claims, as HP SIM uses UPN, thats the option ill be selecting, however as you can see by the screen dump you have a few different options.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741134" title="adfs20"&gt;&lt;img src="http://data4.blog.de/media/134/1741134_2dc68bc5ff_m.jpg" alt="adfs20" hspace="5" vspace="5" width="490" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Now you choose whether to enable the application immediately or not. choose next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741137" title="adfs21"&gt;&lt;img src="http://data4.blog.de/media/137/1741137_1d40560a05_m.jpg" alt="adfs21" hspace="5" vspace="5" width="493" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Wizard is finished, hit Finish.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741140" title="adfs22"&gt;&lt;img src="http://data4.blog.de/media/140/1741140_8c5d6d5231_m.jpg" alt="adfs22" hspace="5" vspace="5" width="490" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;As you can see my application is initialised and is using UPN for its IC.&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1741142" title="adfs23"&gt;&lt;img src="http://data4.blog.de/media/142/1741142_558cf1e4ee_m.jpg" alt="adfs23" hspace="5" vspace="5" width="490" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2007/06/29/windows_server_2008_cont_d_active_direct~2541427/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2007/06/29/windows_server_2008_cont_d_active_direct~2541427/#comments</comments></item><item><title>Windows Server 2008 Cont'd:  Active Directory Certificate Services</title><link>http://daniels-it.blog.co.uk/2007/06/28/windows_server_2008_cont_d_active_direct~2535934/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2007-06-28:/2007/06/28/windows_server_2008_cont_d_active_direct~2535934/</guid><pubDate>Thu, 28 Jun 2007 13:50:06 +0200</pubDate><description>	&lt;p&gt;Hi guys,&lt;br&gt;           Following on from my last post about Active Directory Directory Services, now lets move into Windows Server 2008's other Active directory based services.&lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;&lt;u&gt;Active Directory Certificate Services&lt;/p&gt;
	&lt;p&gt;&lt;/u&gt;&lt;/strong&gt;Active Directory Certificate Services (AD CS) provides customisable services for creating and managing public key certificates used in software security systems that employ public key technologies.  ADCS Comprises of the following feature compnents, all configurable through Server Manager (I will run through the install procedure later on):&lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;Certification authorities (CAs)&lt;/strong&gt; Root and subordinate CAs are used to issue certificates to users, computers, and services, and to manage certificate validity.&lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;Web enrollment.&lt;/strong&gt; Web enrollment allows users to connect to a CA by means of a Web browser in order to request certificates, retrieve certificate revocation lists (CRLs), and perform smart card certificate enrollment.&lt;br&gt; &lt;br&gt;&lt;strong&gt;Online Responder&lt;/strong&gt; service. The Online Responder service decodes revocation status requests for specific certificates, evaluates the status of these certificates, and sends back a signed response containing the requested certificate status information. &lt;br&gt; &lt;br&gt;&lt;strong&gt;Network Device Enrollment Service (NDES).&lt;/strong&gt; NDES allows routers and other network devices that do not have network accounts to obtain certificates.&lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;&lt;u&gt;Benefits of AD CS&lt;br&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br&gt;Organisations can use AD CS to enhance security by binding the identity of a person, device, or service to a corresponding private key. AD CS gives organizations a cost-effective, efficient, and secure way to manage the distribution and use of certificates.&lt;/p&gt;
	&lt;p&gt;Applications supported by AD CS include Secure/Multipurpose Internet Mail Extensions (S/MIME), secure wireless networks, virtual private network (VPN), Internet Protocol security (IPsec), Encrypting File System (EFS), smart card logon, Secure Socket Layer/Transport Layer Security (SSL/TLS), and digital signatures.&lt;/p&gt;
	&lt;p&gt;Among the new features of AD CS in Microsoft Windows Server2008 are:&lt;/p&gt;
	&lt;p&gt;&amp;bull; Improved enrollment capabilities that enable delegated enrollment agents to be assigned on a per-template basis. &lt;br&gt; &lt;br&gt;&amp;bull; Integrated Simple Certificate Enrollment Protocol (SCEP) enrollment services for issuing certificates to network devices such as routers.&lt;br&gt; &lt;br&gt;&amp;bull; Scalable, high-speed revocation status response services combining both CRLs and integrated Online Responder services.&lt;/p&gt;
	&lt;p&gt;Hardware and software considerations&lt;/p&gt;
	&lt;p&gt;AD CS requires Windows Server 2008 and Active Directory Domain Services (AD DS). Although AD CS can be deployed on a single server, many deployments will involve multiple servers configured as CAs, other servers configured as Online Responders, and others serving as Web enrollment portals. &lt;/p&gt;
	&lt;p&gt;CAs can be set up on servers running a variety of operating systems, including Windows Server 2008, Windows Server 2003, and Windows 2000 Server. However, not all operating systems support all features or design requirements, and creating an optimal design will require careful planning and lab testing before you deploy AD CS in a production environment.&lt;/p&gt;
	&lt;p&gt;Ok lets go through the install Procedure..&lt;/p&gt;
	&lt;p&gt;As per usual you use Server Manager to install the role, Select Add Roles, and select Active Directory Certificate Services&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737932" title="cert1"&gt;&lt;img src="http://data4.blog.de/media/932/1737932_aa29fb9692_m.jpg" alt="cert1" hspace="5" vspace="5" width="497" height="375"&gt;&lt;/a&gt;&lt;br&gt;Welcome Page is below&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737928" title="cert1"&gt;&lt;/a&gt;&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737929" title="cert2"&gt;&lt;img src="http://data4.blog.de/media/929/1737929_29994975fc_m.jpg" alt="cert2" hspace="5" vspace="5" width="500" height="374"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;i'm going to add our primary role and the feature Certificate Authority Web Enrollment (see above for description on features) &lt;br&gt;Please note when you add CAWE you will be prompted to install the required IIS Services&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738053" title="cert3"&gt;&lt;img src="http://data4.blog.de/media/053/1738053_9673cc6dff_m.jpg" alt="cert3" hspace="5" vspace="5" width="495" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738065" title="cert4"&gt;&lt;img src="http://data4.blog.de/media/065/1738065_1479eaf0e9_m.jpg" alt="cert4" hspace="5" vspace="5" width="498" height="375"&gt;&lt;/a&gt;&lt;br&gt;If you plan to install Network Device Enrollment Services, please note you need to complete Certification Authority setup before you can install &amp; setup this service.&lt;/p&gt;
	&lt;p&gt;The next step involves involves selecting whether you use AD DS to simplify issuing of certificates or select standalone mode whereby you have a bunch of extra configuration steps.   Enterprise configuration is the recommended way of deploying certificates.  Choose next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738072" title="cert5"&gt;&lt;img src="http://data4.blog.de/media/072/1738072_5ce496f2eb_m.jpg" alt="cert5" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;br&gt;The next step involves configuring your CA.  You can select Root CA if this is your only certificate authority or if you have another CA provider (whether it be internal or external) you can select Subordinate CA.  In this example I will be setting this server up as a Root CA Authority.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738084" title="cert6"&gt;&lt;img src="http://data4.blog.de/media/084/1738084_be4a41aa60_m.jpg" alt="cert6" hspace="5" vspace="5" width="498" height="375"&gt;&lt;/a&gt;&lt;br&gt;The next step involves setting up your private key.  If you dont configure a private key or select an existing key, certificates will NOT be issued to clients.  As i do not have an existing key from another CA etc, i will choose to create a new one.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738102" title="cert7"&gt;&lt;img src="http://data4.blog.de/media/102/1738102_c2720456b3_m.jpg" alt="cert7" hspace="5" vspace="5" width="498" height="375"&gt;&lt;/a&gt;&lt;br&gt;Before you can issue Certificates, your Private key needs to be encrypted, this Cryptography section of the wizard involves selecting a CSP and a hash algorithm, there are a massive amount of different CSP's, so choose what is appropriate, depending on your organisation's Security policy.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738105" title="cert8"&gt;&lt;img src="http://data4.blog.de/media/105/1738105_6fc4ccca01_m.jpg" alt="cert8" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;br&gt;I will be using Microsoft Base Cryptographic Provider 1.0 with a sha1 algorithm for this example.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738107" title="cert9"&gt;&lt;img src="http://data4.blog.de/media/107/1738107_784a495c56_m.jpg" alt="cert9" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;The next step involves configuring your CA name, Generally you would leave all options as is, as it registers it against the server FQDN, but changing the common name is ok too.  Choose Next.&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738117" title="cert10"&gt;&lt;img src="http://data4.blog.de/media/117/1738117_5b8d77984b_m.jpg" alt="cert10" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;br&gt;Now you need to set the Certificate expiry the client/device will have before needing to get a certificate reissued.  The default is 5 Years, which is what I have left mine at.  However in regards to best practices it should be considerably less, but this depends on your internal organisation policies.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738120" title="cert11"&gt;&lt;img src="http://data4.blog.de/media/120/1738120_748ef03a29_m.jpg" alt="cert11" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Next you need to specify the install location of the database &amp; logs, I am going to leave it as default, however for performance or policy reasons you may choose to change this.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738141" title="cert12"&gt;&lt;img src="http://data4.blog.de/media/141/1738141_77202e64bf_m.jpg" alt="cert12" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Remember earlier on it asked if you wanted to install the required IIS services?  now here is where you configure the individual IIS components, choose next to the welcome page.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738142" title="cert13"&gt;&lt;img src="http://data4.blog.de/media/142/1738142_e23910b25b_m.jpg" alt="cert13" hspace="5" vspace="5" width="495" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Generally you can leave all the default selections, however I am installing the additiona IIS 6.0 components for my exchange install later on (blog will follow!)  then choose next&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738159" title="cert14"&gt;&lt;img src="http://data4.blog.de/media/159/1738159_63f75857f1_m.jpg" alt="cert14" hspace="5" vspace="5" width="498" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Finally we are at the confirmation page, confirm everything is OK and hit next.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738161" title="cert15"&gt;&lt;img src="http://data4.blog.de/media/161/1738161_ea9886a5a0_m.jpg" alt="cert15" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Installation starts.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738163" title="cert16"&gt;&lt;img src="http://data4.blog.de/media/163/1738163_d9b1fefc83_m.jpg" alt="cert16" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;br&gt;Once completed you will see a screen like the below.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738164" title="cert17"&gt;&lt;img src="http://data4.blog.de/media/164/1738164_e5187f051c_m.jpg" alt="cert17" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Now you will see the role under server manager (No restart is required for this role) however in my experience i have found it will not function correctly until a restart.  Additionally if you plan to install any other featured of ADCS you will need to restart prior.&lt;img class="smiley" src="http://www.blog.co.uk/srv/tinymce/jss/plugins/blogdeemotions/smilies/smileys60.gif" border="0" alt="" width="34" height="17"&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1738183" title="cert finish"&gt;&lt;img src="http://data4.blog.de/media/183/1738183_23ca1d4519_m.jpg" alt="cert finish" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Now you will see you have access to the new Certificate Server snap in under Admin Tools.  From here you can view issued certificates, revoked certificates, pending requests, failed requests &amp; templates.&lt;br&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740562" title="certserv"&gt;&lt;img src="http://data4.blog.de/media/562/1740562_ff84ae043f_m.jpg" alt="certserv" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Now, templates.... In Windows Server 2003 R3 you had the previous facilities but NOT templates, I think this is a fantastic feature that they have added, and its dead easy.  For example, I would like to setup a certificate template for Smart Card Authenticated users... EASY!  select Certificate Templates, you will see the preinstalled templates.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740570" title="cert2"&gt;&lt;img src="http://data4.blog.de/media/570/1740570_1887dc1c0e_m.jpg" alt="cert2" hspace="5" vspace="5" width="500" height="364"&gt;&lt;/a&gt;&lt;br&gt;Right Click on Certficate Templates and choose new template, and add your required certificate for clients.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740572" title="cert3"&gt;&lt;img src="http://data4.blog.de/media/572/1740572_5dfe6b5721_m.jpg" alt="cert3" hspace="5" vspace="5" width="500" height="272"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;As you can see there are heaps of templates available, what I like best about it, is that once you add them they are all preconfigured, there is no additional work required! &lt;/p&gt;
	&lt;p&gt;Now clients can connect to the servers iis web site and request new certificates if required.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740600" title="cert4"&gt;&lt;img src="http://data4.blog.de/media/600/1740600_c58cdd5418_m.jpg" alt="cert4" hspace="5" vspace="5" width="499" height="375"&gt;&lt;/a&gt;&lt;br&gt;All they select is 'Request a certificate, the below is displayed..&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740601" title="cert5"&gt;&lt;img src="http://data4.blog.de/media/601/1740601_2728274589_m.jpg" alt="cert5" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;br&gt;If any additional information is required it will prompt you here, but in this case i have left everything default, so the user chooses submit, therefore sending a request to the ADCS server for a new certificate, and of course it will appear under pending and or issued certificates under the certserv tool.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740605" title="cert6"&gt;&lt;img src="http://data4.blog.de/media/605/1740605_78bbd7a3a5_m.jpg" alt="cert6" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;br&gt;User gets a warning message, select YES&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740606" title="cert7"&gt;&lt;img src="http://data4.blog.de/media/606/1740606_b7751a68b9_m.jpg" alt="cert7" hspace="5" vspace="5" width="410" height="181"&gt;&lt;/a&gt;&lt;br&gt;Certificate has been issued, select install this certificate..&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740610" title="cert8"&gt;&lt;img src="http://data4.blog.de/media/610/1740610_7373f15cc7_m.jpg" alt="cert8" hspace="5" vspace="5" width="497" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;another prompt..select YES&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740612" title="cert9"&gt;&lt;img src="http://data4.blog.de/media/612/1740612_5c02d38091_m.jpg" alt="cert9" hspace="5" vspace="5" width="417" height="233"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Certificate Issuing Complete&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1740613" title="cert10"&gt;&lt;img src="http://data4.blog.de/media/613/1740613_c5dcb05188_m.jpg" alt="cert10" hspace="5" vspace="5" width="500" height="375"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt; COOL&lt;img class="smiley" src="http://www.blog.co.uk/srv/tinymce/jss/plugins/blogdeemotions/smilies/smiley-cool2.gif" border="0" alt="" width="18" height="18"&gt;&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2007/06/28/windows_server_2008_cont_d_active_direct~2535934/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2007/06/28/windows_server_2008_cont_d_active_direct~2535934/#comments</comments></item><item><title>Windows Server 2008 IDS3</title><link>http://daniels-it.blog.co.uk/2007/06/28/windows_server_2008_ids3~2534663/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2007-06-28:/2007/06/28/windows_server_2008_ids3~2534663/</guid><pubDate>Thu, 28 Jun 2007 10:11:28 +0200</pubDate><description>	&lt;p&gt;Hi Folks,&lt;br&gt;
          I have had a few requests from people out there about the Windows Server 2008 System, mainly in relation to release date, and items such as roles, features and step by step info.&lt;/p&gt;
	&lt;p&gt;Now, Microsoft released Windows Server 'Longhorn' Beta 3 about 6 weeks ago to Technet Plus subscribers, and now is readily available to everyone, microsoft's official release date on this product has yet to be determined, but all signs indicate that manufacturing will start at the end of this year, ready for early 2008 (as the name Suggests).&lt;/p&gt;
	&lt;p&gt;Tecnet Plus subscibers will notice that Windows Server 2008 IDS-3 is now available on technet in both standard, &amp; enterprise.&lt;br&gt;
So whats the difference?!  As far as I can see there are not too many, however I have come across a few differences thus far.&lt;br&gt;
First up, the installation was slightly different, everyone who has used Longhorn knows you have 2 install methods you can choose, a Windows Server Core install, or Windows Server server, i'm just going to take a moment to explain the differences....Essentially, Server Core is a slimmed-down, appliancelike version of Longhorn Server that functions in a couple of limited roles and does nothing else.&lt;/p&gt;
	&lt;p&gt;Server Core, as I see it, has three main advantages: it’s extremely focused, which means it does what it does very well, resulting in better performance, resilience and robustness than a full-fledged operating system. It also has limited dependencies on other pieces of the Windows puzzle, in that the Core is designed to work without a lot of other software installed; it can generally work by itself. In comparison, many of the previous Windows components aren’t really necessary -- like Windows Explorer or Internet Explorer, for example, which is something that can’t be said for Windows Server 2003.&lt;/p&gt;
	&lt;p&gt;All of this translates into a far smaller attack surface than the standard Windows Server product, given all of the material that's been stripped out. &lt;/p&gt;
	&lt;p&gt;ok back to the differences... during install mode I was not prompted to set an Administrator password, which i thought was a bit strange, but it did speed up the install process.. on my Vm machine it took about 15 Minutes to install the OS.&lt;br&gt;
Upon First load you now actually get prompted to set the Administrator password..&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737318" title="change password upon first log in"&gt;&lt;img src="http://data4.blog.de/media/318/1737318_3579074907_m.jpg" alt="change password upon first log in" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;now set your password&lt;/p&gt;
	&lt;p&gt; &lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737311" title="set password"&gt;&lt;img src="http://data4.blog.de/media/311/1737311_861a6c8b5e_m.jpg" alt="set password" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
You also now have the facility to create a password reset disk, handy, however so far I cannot see a USB key option, which i'm sure will come around prior to final release.&lt;br&gt;
Once your password is set and you log in, you will notice one little difference, nothing important, but in my opinion means they are finally getting closer to releasing the various RC's which is a good sign...In the bottom Right Hand Corner it has always stated Windows Server 'Longhorn' eval.....  It now states Windows Server 2008.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737328" title="bottom right hand corner - no longhorn"&gt;&lt;img src="http://data4.blog.de/media/328/1737328_bbda5290d6_m.jpg" alt="bottom right hand corner - no longhorn" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;I also noticed boot up time is incredibly quicker, os loaded in under 1 minute!&lt;br&gt;
ok, moving right along, naturally you you will get asked to fill in the usual info in the 'initial Configuration Tasks' wizard, i.e Time Zone, Networking, Computer name &amp; domain, automatic updating &amp; feedback, install updates, add roles and add features, enable remote desktop and customise windows firewall&lt;/p&gt;
	&lt;p&gt;Now lets run you through roles.  now server manager is still what you use to install roles and features, in this example we are going to install Active Directory but the screen dump lets you see what roles are available.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737352" title="roles, installing AD"&gt;&lt;img src="http://data4.blog.de/media/352/1737352_f956c62cdb_m.jpg" alt="roles, installing AD" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Best Practices:  Make sure prior to installing Active Directory that you have assigned the server a static IP, and that you have set its DNS primary pointing to its loopback address of 127.0.0.1.&lt;br&gt;
First up you will get your welcome screen&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737357" title="install1"&gt;&lt;img src="http://data4.blog.de/media/357/1737357_a421c0ef29_m.jpg" alt="install1" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
next comes the confirmation screen, notice taht in all prior server versions, once you install AD and restart it is up and running, but in Windows Server 2008 you need to run dcpromo AFTER initial install of AD to activate the role, which i will cover later.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737365" title="install2"&gt;&lt;img src="http://data4.blog.de/media/365/1737365_e1ccf33bb0_m.jpg" alt="install2" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
Active Directory starts to install and then finishes.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737382" title="install3"&gt;&lt;img src="http://data4.blog.de/media/382/1737382_4e4e1b2dba_m.jpg" alt="install3" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737383" title="install 4"&gt;&lt;img src="http://data4.blog.de/media/383/1737383_7268568ff1_m.jpg" alt="install 4" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
Now you need to run dcpromo, you access this via selecting the active directory services role in server manager and selecting the link selected in red below.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737397" title="selecting dc promo"&gt;&lt;img src="http://data4.blog.de/media/397/1737397_4438cac181_m.jpg" alt="selecting dc promo" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
now lets kick off the dcpromo config. you get the usual welcome screen&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737406" title="pre dc promo"&gt;&lt;img src="http://data4.blog.de/media/406/1737406_1205b9b6f5_m.jpg" alt="pre dc promo" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
go next, now you will hit Deployment Configuration page, please note in this example I am setting up the first dc in my forest.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737422" title="ad1"&gt;&lt;img src="http://data4.blog.de/media/422/1737422_aab4c158ba_m.jpg" alt="ad1" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
next comes your forest root domain name, in this example, my FQDN is XtremeIT.com&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737426" title="ad2"&gt;&lt;img src="http://data4.blog.de/media/426/1737426_38be9f822a_m.jpg" alt="ad2" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
next comes your AD firest level, in my example i'm going with 2008 and following that is your DNS.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737430" title="ad3"&gt;&lt;img src="http://data4.blog.de/media/430/1737430_1bb507bb69_m.jpg" alt="ad3" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737431" title="ad4"&gt;&lt;img src="http://data4.blog.de/media/431/1737431_56d8200a36_m.jpg" alt="ad4" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;now you will recieve the following warning message&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737433" title="ad5"&gt;&lt;img src="http://data4.blog.de/media/433/1737433_88367b898c_m.jpg" alt="ad5" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;this message is basically telling you it cannot contact another DNS zone, this is of course true, as I am doing a first Domain Controlller install and I am using this DC as my primary DNS If you are running a seperate delegated DNS (i.e you have another DNS Server and appropriate zone)you only need to manually create a connection to this on your other DNS Server and zone.&lt;br&gt;
The next warning message you get is quite lengthy, but all it is talking about here is that if this server will be your primary DNS, you need to ensure your primary DNS settings reflect the server.  This is what i was talking about earlier in the best practices section, by point it to 127.0.0.1, if you forgot to do that prior to install, selecting yes on this screen will make the appropriate changes&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737451" title="ad5-1"&gt;&lt;img src="http://data4.blog.de/media/451/1737451_86ea314ade_m.jpg" alt="ad5-1" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
the next part of the wizard will prompt you about installtion loactions for SYSVOL etc, now best practices on DC's is to segment these directory locations for performance, but in this example i'll leave it as default.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737470" title="ad6"&gt;&lt;img src="http://data4.blog.de/media/470/1737470_0bb271a8aa_m.jpg" alt="ad6" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
moving along, the next screen prompts you to set a restore password for Authoritive and Non-Authoritive and DS restores, as well as a review of all wizard steps.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737478" title="ad7"&gt;&lt;img src="http://data4.blog.de/media/478/1737478_8b76195d79_m.jpg" alt="ad7" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737479" title="ad8"&gt;&lt;img src="http://data4.blog.de/media/479/1737479_0835b354b4_m.jpg" alt="ad8" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;br&gt;
hitting next kicks off your install&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737481" title="ad9"&gt;&lt;img src="http://data4.blog.de/media/481/1737481_2da7ad1dc6_m.jpg" alt="ad9" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;you will then get a completed screen and naturally the prompt to restart.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737508" title="adfinish"&gt;&lt;img src="http://data4.blog.de/media/508/1737508_491fbb08a6_m.jpg" alt="adfinish" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=1737509" title="adfinish2"&gt;&lt;img src="http://data4.blog.de/media/509/1737509_669e10ae78_m.jpg" alt="adfinish2" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;once you restart, under server manager you will now see AD installed.&lt;br&gt;
Now please, please, please remember if you plan to install other Active Directory roles like Certificate Services or Federation Services, you MUST install this first and install ONLY this role, meaning although you have the option to install multiple AD roles at once, they will NOT work correctly until this role is installed and configured, so Install the Directory Services role first then move on to other roles.&lt;/p&gt;
	&lt;p&gt;Ok my next blogs in my Windows Server 2008 series, will cover the following.&lt;br&gt;
Active Directory Certificate Services&lt;br&gt;
Active Directory Federation Services&lt;br&gt;
Active Directory Rights Management Services&lt;br&gt;
Network Policy &amp; Access services&lt;br&gt;
Health Authority Services&lt;br&gt;
Windows Depoyment Services &amp; deploying Windows Server 2008 &amp; Vista&lt;br&gt;
Exchange 2007 Installation &amp; configuration.&lt;/p&gt;
	&lt;p&gt;Stay Tuned!&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2007/06/28/windows_server_2008_ids3~2534663/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2007/06/28/windows_server_2008_ids3~2534663/#comments</comments></item><item><title>I'm Back!!</title><link>http://daniels-it.blog.co.uk/2007/01/07/i_m_back~1524120/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2007-01-07:/2007/01/07/i_m_back~1524120/</guid><pubDate>Sun, 07 Jan 2007 10:23:20 +0100</pubDate><description>	&lt;p&gt;Hi Everyone,  Apologies for the long break since I have been blogging, all of december I was back home with Family in Australia for a great 4 week holiday in the sun, and before that was all preparing to go!  &lt;/p&gt;
	&lt;p&gt;Happy new year! to all my readers, its a new year and plenty of new blogs to come so should be back in full swing next week, please come back often!&lt;/p&gt;
	&lt;p&gt;Cheers&lt;/p&gt;
	&lt;p&gt;Dan
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2007/01/07/i_m_back~1524120/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2007/01/07/i_m_back~1524120/#comments</comments></item><item><title>Telnet In Windows Vista/Longhorn</title><link>http://daniels-it.blog.co.uk/2006/11/06/telnet_in_windows_vista_longhorn~1301934/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-11-06:/2006/11/06/telnet_in_windows_vista_longhorn~1301934/</guid><pubDate>Mon, 06 Nov 2006 16:31:05 +0100</pubDate><description>	&lt;p&gt;Where is Telnet in Vista/Longhorn beta builds? &lt;/p&gt;
	&lt;p&gt;Telnet is now made an optional component in Vista and Longhorn Servers. This means if you type telnet in command shell, you will be out of luck.&lt;/p&gt;
	&lt;p&gt;Why have microsoft done so?&lt;/p&gt;
	&lt;p&gt;As time has passed, fewer users use telnet. Thus, to decrease the foot print as well as the attack surface, they decided to make it an optional component.&lt;/p&gt;
	&lt;p&gt;Great, now how do I get telnet client/server working again?&lt;/p&gt;
	&lt;p&gt;Vista - &lt;/p&gt;
	&lt;p&gt;Use software explorer or Click Start, Control Panel, Programs, and then Turn Windows Features on or off. In the list, scroll down and select Telnet Client. Click OK to start the installation.&lt;/p&gt;
	&lt;p&gt;Longhorn - &lt;/p&gt;
	&lt;p&gt;Use RMT to install&lt;/p&gt;
	&lt;p&gt;If you want to use command line options - please use the following commands - &lt;/p&gt;
	&lt;p&gt;Command line to install telnet server:&lt;/p&gt;
	&lt;p&gt;start /w pkgmgr /iu:"TelnetServer"&lt;/p&gt;
	&lt;p&gt;Command line to install telnet server:&lt;/p&gt;
	&lt;p&gt;start /w pkgmgr /iu:"TelnetClient"&lt;/p&gt;
	&lt;p&gt;enjoy...&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/11/06/telnet_in_windows_vista_longhorn~1301934/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/11/06/telnet_in_windows_vista_longhorn~1301934/#comments</comments></item><item><title>Installing the Windows 2003 SP1 Admin Pack on Windows Vista Beta 2</title><link>http://daniels-it.blog.co.uk/2006/11/06/installing_the_windows_2003_sp1_admin_pa~1300931/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-11-06:/2006/11/06/installing_the_windows_2003_sp1_admin_pa~1300931/</guid><pubDate>Mon, 06 Nov 2006 11:37:25 +0100</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;            A lot of people have asked me whether Microsoft have released a version of the adminpak.msi for Windows Vista.  Unfortunately, in the current builds there is no version, and will not be until the final release.&lt;/p&gt;
	&lt;p&gt;If like me, you use the Windows Server 2003 Admin Tools very frequently this becomes a real pain, and, If you try to install the current  win server 2003 release adminpak in vista it will give you an error saying 'wrong version' which relates to the windows version check.  &lt;/p&gt;
	&lt;p&gt;However, you can create your own installer for the admin tools pak (win2k3) which WILL work on Windows Vista, and I am going to show you how!&lt;/p&gt;
	&lt;p&gt;As Mentioned above, The Windows 2003 SP 1 Admin Pack cannot be installed on a Windows Vista  machine due to a version check in the installer. Since there is also a bug with the compatibility mode for elevated processes, you must modify the MSI file to remove the version check. &lt;/p&gt;
	&lt;p&gt;Below are instructions for modifying the MSI. &lt;/p&gt;
	&lt;p&gt;Note that the same basic process may be used to correct version issues with other installers. &lt;/p&gt;
	&lt;p&gt;Download &amp; install Windows Server 2003 SP1 Platform SDK from &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=A55B6B43-E24F-4EA3-A93E-40C0EC4F68E5&amp;displaylang=en"&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=A55B6B43-E24F-4EA3-A93E-40C0EC4F68E5&amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=A55B6B43-E24F-4EA3-A93E-40C0EC4F68E5&amp;displaylang=en&lt;/a&gt;&lt;/a&gt; &lt;/p&gt;
	&lt;p&gt;Once installation has completed, install Orca.msi (Located in %Program Files%\Microsoft Platform SDK\Bin) &lt;/p&gt;
	&lt;p&gt;Unpack adminpak.exe&lt;br&gt; &lt;br&gt;Select adminpak.msi, Right-click and choose Edit with Orca &lt;/p&gt;
	&lt;p&gt;In the &amp;lsquo;Tables&amp;rsquo; view (left pane) select &amp;lsquo;LaunchCondition&amp;rsquo; &lt;/p&gt;
	&lt;p&gt;Select in the right pane:   &amp;lsquo;Condition&amp;rsquo; = (MsiNTSuitePersonal &lt;&gt; 1) AND ((VersionNT = 501 AND  (ServicePackLevel &gt;= 1 OR QFE_DSPROP = "Yes")) OR (VersionNT = 502 AND ServicePackLevel &lt;= AdminpakServicePackLevel ) ) &lt;/p&gt;
	&lt;p&gt;Select &amp;lsquo;Transform&amp;rsquo; à &amp;lsquo;New Transform&amp;rsquo; &lt;/p&gt;
	&lt;p&gt;Edit:   &amp;lsquo;Condition&amp;rsquo; = (MsiNTSuitePersonal &lt;&gt; 1) AND ((VersionNT = 501 AND  (ServicePackLevel &gt;= 1 OR QFE_DSPROP = "Yes")) OR (VersionNT = 502 AND ServicePackLevel &lt;= AdminpakServicePackLevel ) ) to &amp;lsquo;Condition&amp;rsquo; = (MsiNTSuitePersonal &lt;&gt; 1) AND ((VersionNT = 501 AND  (ServicePackLevel &gt;= 1 OR QFE_DSPROP = "Yes")) OR (VersionNT = &lt;strong&gt;600&lt;/strong&gt; AND ServicePackLevel &lt;= AdminpakServicePackLevel ) ) &lt;/p&gt;
	&lt;p&gt;Select &amp;lsquo;File&amp;rsquo; à &amp;lsquo;Save Transformed As&amp;hellip;&amp;rsquo; and save to AdminPak_Vista.msi &lt;/p&gt;
	&lt;p&gt;Close Orca &lt;/p&gt;
	&lt;p&gt;Install AdminPak_Vista.msi on computer running Windows Vista&lt;/p&gt;
	&lt;p&gt;Easy! hope this helps.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/11/06/installing_the_windows_2003_sp1_admin_pa~1300931/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/11/06/installing_the_windows_2003_sp1_admin_pa~1300931/#comments</comments></item><item><title>Longhorn Server Terminal Services Part II</title><link>http://daniels-it.blog.co.uk/2006/11/06/longhorn_server_terminal_services_part_i~1300750/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-11-06:/2006/11/06/longhorn_server_terminal_services_part_i~1300750/</guid><pubDate>Mon, 06 Nov 2006 10:39:43 +0100</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;
          in my last blog on terminal services in longhorn server, i discussed the installation and setup of remote programs.  Taking it one step this further in this post, we will discuss one of the other 2 major components of Terminal Services, TS Web Access (TS Gateway to follow in the next blog).&lt;/p&gt;
	&lt;p&gt;Ok let's jump straight into it:  TS Web Access&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;What is Terminal Services Web Access?&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;TS Web Access is a feature that makes Remote Programs available to users from a Web browser. With TS Web Access, a user can visit a Web site—either from the Internet or from an intranet—to access a list of available Remote Programs. When a user starts a Remote Program, a Terminal Services session is started on the terminal server that hosts the Remote Program.&lt;br&gt;
TS Web Access includes a default Web page that you can use to deploy Remote Programs over the Web. The Web page consists of a frame and a customizable Web Part, where the list of Remote Programs is displayed. Alternatively, you can incorporate the Web Part into a Microsoft Windows SharePoint Services site.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Deploying TS Web Access:&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;You must install the TS Web Access role service on the Windows Server "Longhorn"-based server that you want users to connect to over the Web to access Remote Programs. When you install TS Web Access, Microsoft Internet Information Services (IIS) 7.0 is also installed as a required component.&lt;br&gt;
After you install TS Web Access, you can specify the data source to use to populate the list of Remote Programs that appears in the Web Part. The Web server can populate the list from an external data source. Therefore, the Web server does not have to be a terminal server.&lt;br&gt;
If you want users to access the Web page from the Internet, you can use TS Gateway to help secure remote connections.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;TS Web Access Data Sources&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;TS Web Access can populate the list of Remote Programs that appear in the Web Part from either of the following data sources:&lt;br&gt;
•	Active Directory directory service&lt;br&gt;
•	A single terminal server&lt;br&gt;
By default, the list of Remote Programs is populated from Active Directory.&lt;br&gt;
If Active Directory is specified as the data source, the list of Remote Programs that appears in the Web Part is specific to the individual user. Only .msi packages (with an .rap.msi file name extension) that are published for that specific user by using Group Policy software distribution appear in the list.&lt;br&gt;
If a single terminal server is specified as the data source, the list of available Remote Programs that appears in the Web Part is not specific to the user. Instead, all Remote Programs that are configured for Web access on that server's Allow List appear on the page.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Install the TS Web Access Role Service&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;Install the TS Web Access role service on the server that you want users to connect to over the Web to access Remote Programs. When you install the TS Web Access role service, Microsoft IIS 7.0 is also installed.&lt;/p&gt;
	&lt;p&gt;To install TSWeb access role service it is pretty much the same procedure you would follow to install Terminal Services and setup Remote programs.&lt;/p&gt;
	&lt;p&gt;The server where you install TS Web Access acts as the Web server. The server does not have to be a terminal server. After you install TS Web Access, you can configure TS Web Access to populate the list of Remote Programs from Active Directory or you can designate a single terminal server as the data source.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;To install TS Web Access (if the Terminal Services role is already added)&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;First up, go to server manager (Start&gt; Server manager or servermanager.msc)&lt;/p&gt;
	&lt;p&gt;Under Roles Summary, click Terminal Services.  Under Role Services, click Add role services.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939518"&gt;&lt;img src="http://data2.blog.de/media/518/939518_2deea9561a_m.jpg" alt="add role" title="add role" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Then on the select components screen select TS Web Access, it will also prompt you to install additional supporting services (IIS7 etc) so choose 'Add Required Role Service'&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939523"&gt;&lt;img src="http://data2.blog.de/media/523/939523_70f54d5007_m.jpg" alt="add role2" title="add role2" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;then choose next.  &lt;/p&gt;
	&lt;p&gt;On the Intro screen, hit next.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939540"&gt;&lt;img src="http://data2.blog.de/media/540/939540_8a2ab909bb_m.jpg" alt="intro" title="intro" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;On the role services screen select next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939544"&gt;&lt;img src="http://data2.blog.de/media/544/939544_0f150330bb_m.jpg" alt="role services" title="role services" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;On the confirm installation Options screen, hit install.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939545"&gt;&lt;img src="http://data2.blog.de/media/545/939545_18387e7035_m.jpg" alt="confirm installation options" title="confirm installation options" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939549"&gt;&lt;img src="http://data2.blog.de/media/549/939549_51fac4bd41_m.jpg" alt="installing" title="installing" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;on the installation completed page, choose close.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939557"&gt;&lt;img src="http://data2.blog.de/media/557/939557_c0d776c32e_m.jpg" alt="finish" title="finish" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;you will now see the role in the list.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939558"&gt;&lt;img src="http://data2.blog.de/media/558/939558_9ac9b85fef_m.jpg" alt="verify installation" title="verify installation" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Use Active Directory as the Data Source&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;By default, TS Web Access populates its list of Remote Programs from Active Directory. When Active Directory is specified as the data source, the Terminal Services Remote Programs Web Part is populated by the Remote Program .rap.msi packages that are published to a user through Group Policy software distribution. The advantages to this deployment method are as follows:&lt;/p&gt;
	&lt;p&gt;•	TS Web Access will only display packages that are specific to the current user.&lt;br&gt;
•	Remote Program .msi packages that point to different terminal servers can all be consolidated into a single list in the Terminal Services Remote Programs Web Part.&lt;/p&gt;
	&lt;p&gt; To specify Active Directory as the data source&lt;/p&gt;
	&lt;p&gt;1.	Use Internet Explorer to connect to the default TS Web Access Web page. By default, the Web page is located at the following address (where server_name is the NetBIOS name or fully qualified domain name (FQDN) of your TS Web Access server): &lt;a href="http://server_name/ts"&gt;http://server_name/ts&lt;/a&gt;&lt;br&gt;
2.	Log on to the site by using an account that is a member of the local Administrators group or by using an account that is a member of the TS Web Access Administrators local group. (If you are already logged on to the computer as one of these accounts, you are not prompted for credentials.)&lt;/p&gt;
	&lt;p&gt;Note In Windows Server "Longhorn" Beta 2, the TS Web Access Administrators local group is added when you install TS Web Access. To open the Local Users and Groups snap-in, click Start, click Run, type lusrmgr.msc and then click OK.&lt;br&gt;
3.	In the upper-left corner, under Personalization Scope, click Shared.&lt;br&gt;
4.	In the Display Mode list, click Edit.&lt;br&gt;
5.	At the top of the Web part, click the drop-down arrow on the right side of the Terminal Services Remote Programs bar, and then click Edit.&lt;br&gt;
6.	Under Terminal Services Remote Programs Properties, click Active Directory.&lt;br&gt;
7.	Click OK to apply the changes and to close the Editor Zone dialog box.&lt;/p&gt;
	&lt;p&gt;Now as per my previous blog, web accessed applications are added/controlled via the remote programs screen.&lt;/p&gt;
	&lt;p&gt;The one field you need to worry about is the TS Web Access Column, as long as the application has a yes in there, you will see it displayed on the web access screen.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939562"&gt;&lt;img src="http://data2.blog.de/media/562/939562_8dc49f8862_m.jpg" alt="remote programs" title="remote programs" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;If you want to use Active Directory as the data source to populate the Terminal Services Remote Programs Web Part, you must do the following:&lt;/p&gt;
	&lt;p&gt;1.	On the terminal server where you added Remote Programs, create an .msi package for each Remote Program that you want to make available through TS Web Access.&lt;br&gt;
 Important&lt;/p&gt;
	&lt;p&gt;If Active Directory is specified as the data source, Remote Programs must have an .rap.msi file name extension to appear in the Web Part. When you create the .msi package from a Remote Program that is enabled for TS Web Access, the package is automatically created with an .rap.msi file name extension. If the Remote Program is not enabled for TS Web Access when you create the package, the package is created with an .rdp.msi extension. If you created an .rdp.msi package and you later want to make the package available for TS Web Access, you can rename the file name extension to .rap.msi.&lt;/p&gt;
	&lt;p&gt;2.	Make sure that the .rap.msi packages are saved to a shared network folder, and that users have access to the shared folder.&lt;/p&gt;
	&lt;p&gt;3.	Distribute the .rap.msi package to users by using the Software installation node in Active Directory Group Policy.&lt;br&gt;
 Note:  to locate the Software installation node in a Group Policy object (GPO), expand Software Settings under User Configuration, and then click Software installation. For more information about how to use Group Policy software distribution, see the Microsoft Knowledge Base article "How to use Group Policy to remotely install software in Windows Server 2003" (http://go.microsoft.com/fwlink/?LinkId=29166).&lt;/p&gt;
	&lt;p&gt;4.	Make sure that the computer account of the server that is running TS Web Access has Read access to the Remote Programs that you make available by using .rap.msi packages. To do this, make sure that the software distribution Group Policy settings are also applied to the computer account of the TS Web Access server.&lt;/p&gt;
	&lt;p&gt;•	If you applied the GPO at the domain level, and you do not use security filtering to filter the scope of the GPO, the TS Web Access server automatically has Read access.&lt;/p&gt;
	&lt;p&gt;•	If you applied the GPO at the domain level, and you use security filtering, or if you applied the GPO to an organizational unit (OU) that contains both the computer account of the TS Web Access server and the users who you want the policy to apply to, you must add the computer account of the TS Web Access server to the list of users and groups on the Security tab when you view the properties of the GPO. When you add the account, make sure it has both Read and Apply Group Policy permissions.&lt;/p&gt;
	&lt;p&gt;•	If you applied the GPO to an OU that contains the users who you want the policy to apply to, and the computer account of the TS Web Access server is in a separate OU, you must link the GPO to the OU that contains the computer account of the TS Web Access server. Additionally, you must add the computer account of the TS Web Access server to the list of users and groups on the Security tab when you view the properties of the GPO. When you add the account, make sure it has both Read and Apply Group Policy permissions.&lt;/p&gt;
	&lt;p&gt; Note:  Before you can add a computer account to the list of users and groups on the Security tab when you view the properties of the GPO, you must click Add, click Object Types in the Select Users, Computers, or Groups dialog box, select the Computers check box, and then click OK.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Use a Single Terminal Server as the Data Source&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;By default, TS Web Access populates its list of Remote Programs from Active Directory. However, you can configure the Terminal Services Remote Programs Web Part to populate its list of Remote Programs from a single terminal server instead. This is known as the Simple Publishing configuration. When a single server is specified as the data source, the Web Part is populated by all Remote Programs that are configured for Web access on that server's Allow List. When a single terminal server is used as the data source, the list of programs is not customized for the user.&lt;/p&gt;
	&lt;p&gt; To specify a single terminal server as the data source&lt;/p&gt;
	&lt;p&gt;1.	Use Internet Explorer to connect to the default TS Web Access Web page. By default, the Web page is located at the following address (where server_name is the NetBIOS name or FQDN of your TS Web Access server):  &lt;a href="http://server_name/ts"&gt;http://server_name/ts&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;2.	Log on to the site by using either an account that is a member of the local Administrators group or by using an account that is a member of the TS Web Access Administrators local group. (If you are already logged on to the computer as one of these accounts, you are not prompted for credentials.)&lt;/p&gt;
	&lt;p&gt; Note:  In Windows Server "Longhorn" Beta 2, the TS Web Access Administrators local group is added when you install TS Web Access. To open the Local Users and Groups snap-in, click Start, click Run, type lusrmgr.msc and then click OK.&lt;/p&gt;
	&lt;p&gt;3.	In the upper-left corner, under Personalization Scope, click Shared.&lt;br&gt;
4.	In the Display Mode list, click Edit.&lt;br&gt;
5.	At the top of the Web Part, click the drop-down arrow on the right side of the Terminal Services Remote Programs bar, and then click Edit. &lt;/p&gt;
	&lt;p&gt;6.	Under Terminal Services Remote Programs Properties, click Terminal Server.&lt;br&gt;
7.	In the Terminal Server Name box, type the name of the terminal server that you want to use as the data source.&lt;br&gt;
8.	If you want to configure access to the Remote Programs on the terminal server through TS Gateway, select the Use TS Gateway check box. Additionally, you must do the following:&lt;/p&gt;
	&lt;p&gt;a.	In the TS Gateway Name box, type the name of the TS Gateway server.&lt;br&gt;
 Important&lt;br&gt;
The server name must match what is specified in the SSL certificate for the TS Gateway server.&lt;br&gt;
b.	Under Gateway Authentication Method, click either Smart Card or Password depending on your environment.&lt;br&gt;
9.	Click OK to apply the changes and to close the Editor Zone dialog box.&lt;br&gt;
10.	If the TS Web Access server and the terminal server that you specified as the data source in Step 7 are separate servers, you must add the computer account of the TS Web Access server to the Terminal Server Publishing Access group on the terminal server. To do this, follow these steps on the terminal server:&lt;/p&gt;
	&lt;p&gt;a.	Open the Local Users and Groups snap-in. To do this, click Start, click Run, type lusrmgr.msc and then click OK.&lt;br&gt;
b.	In the left pane, click Groups.&lt;br&gt;
c.	In the right pane, double-click Terminal Server Publishing Access.&lt;br&gt;
d.	In the Terminal Server Publishing Access Properties dialog box, click Add.&lt;br&gt;
e.	In the Select Users, Computers, or Groups dialog box, click Object Types.&lt;br&gt;
f.	In the Object Types dialog box, select the Computers check box, and then click OK.&lt;br&gt;
g.	In the Enter the object names to select box, specify the computer account of the TS Web Access server, and then click OK.&lt;br&gt;
h.	Click OK to close the Terminal Server Publishing Access Properties dialog box.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;To Access TS Web Access from the client&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;By default, you can access the TS Web Access Web page at the following location (where server_name is the NetBIOS name or FQDN of the Web server where you installed TS Web Access):&lt;br&gt;
     &lt;a href="http://server_name/ts"&gt;http://server_name/ts&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt; Important:&lt;/p&gt;
	&lt;p&gt;If you specified Active Directory as the data source, and you want to test TS Web Access while logged on locally to the TS Web Access server or while connected to the server's desktop over a Remote Desktop connection, you must turn off protected mode for the local intranet zone.&lt;/p&gt;
	&lt;p&gt; To turn off protected mode&lt;br&gt;
1.	Start Internet Explorer.&lt;br&gt;
2.	On the Tools menu, click Internet Options.&lt;br&gt;
3.	On the Security tab, in the Select a zone to view or change security settings box, click Local intranet.&lt;br&gt;
4.	Clear the Enable Protected Mode check box, and then click OK.&lt;br&gt;
5.	Click the Refresh Current Page button (green button with arrows) to refresh the Internet Explorer page.&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Client Requirements and Configuration&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;To connect to TS Web Access, the client computer must be running any one of the following operating systems:&lt;br&gt;
•	Microsoft Windows Server "Longhorn" Beta 2&lt;br&gt;
•	Microsoft Windows Server 2003 with SP1&lt;br&gt;
•	Microsoft Windows Vista&lt;br&gt;
•	Microsoft Windows XP with SP2&lt;/p&gt;
	&lt;p&gt;Additionally, the client computer must be configured as follows:&lt;/p&gt;
	&lt;p&gt;•	The client computer must be running Remote Desktop Connection (RDC) client 6.0. If you are running an earlier version of the RDC client, you are prompted to upgrade the client when you visit the TS Web Access Web page.&lt;/p&gt;
	&lt;p&gt; Note:  RDC client 6.0 is not yet available on the Microsoft Windows Update site. For the Windows Server "Longhorn" Beta 2 release, you can download the RDC client 6.0 installer package from the Microsoft Connect Web site (http://go.microsoft.com/fwlink/?LinkId=49779).&lt;/p&gt;
	&lt;p&gt;•	The Terminal Services ActiveX Client control must be enabled. If you are prompted to run the Terminal Services ActiveX Client control when you access TS Web Access, click the message line, click Run ActiveX Control, and then click Run.&lt;/p&gt;
	&lt;p&gt;Note:  If you are running Windows Server "Longhorn" Beta 2 or Windows Vista click the bubble at the lower-right corner of the screen (if it appears) to enable the ActiveX control.&lt;/p&gt;
	&lt;p&gt;•	The TS Web Access server must be added to the Trusted sites zone or the Local intranet zone in Internet Explorer. To do this, use the following method:&lt;/p&gt;
	&lt;p&gt; Note:  If you are running Windows Server 2003, you may be automatically prompted to add the URL of the TS Web Access server to the Trusted sites zone when you visit the TS Web Access Web site. To add the site to the Trusted sites zone, click Add, make sure that the Require server verification (https&lt;img src="/img/smilies/icon_smile.gif" alt=":)" class="middle" border="0"&gt; for all sites in this zone box is cleared if the site does not require server verification, click Add, and then click Close. To manually add the site to the Trusted sites zone or to the Local intranet zone, use the method described in the following procedure.&lt;/p&gt;
	&lt;p&gt; Add site to Local intranet or Trusted sites zone by using Internet Options&lt;br&gt;
1.	Start Internet Explorer.&lt;br&gt;
2.	On the Tools menu, click Internet Options.&lt;br&gt;
3.	Click the Security tab.&lt;br&gt;
4.	If the TS Web Access server is on your intranet, click Local intranet. Otherwise, click Trusted sites.&lt;br&gt;
5.	Click Sites.&lt;br&gt;
6.	Use one of the following procedures, depending on the zone that you selected:&lt;/p&gt;
	&lt;p&gt;•	If you are adding the site to the Local intranet zone, click Advanced. In the Add this website to the zone box, type the URL of the Web server (for example, type &lt;a href="http://server_name),"&gt;http://server_name),&lt;/a&gt; and then click Add. If the site does not require server verification, clear the Require server verification (https&lt;img src="/img/smilies/icon_smile.gif" alt=":)" class="middle" border="0"&gt; for all sites in this zone box. Click Close to apply the settings. (In Windows XP, click OK to apply the settings.)&lt;/p&gt;
	&lt;p&gt;•	If you are adding the site to the Trusted sites zone, in the Add this website to the zone box, type the URL of the Web server (for example, type &lt;a href="http://server_name),"&gt;http://server_name),&lt;/a&gt; and then click Add. If the site does not require server verification, clear the Require server verification (https&lt;img src="/img/smilies/icon_smile.gif" alt=":)" class="middle" border="0"&gt; for all sites in this zone box. Click Close to apply the settings. (In Windows XP, click OK to apply the settings.)&lt;/p&gt;
	&lt;p&gt;If you remember from my previous example, I published Remote Calculator.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939565"&gt;&lt;img src="http://data2.blog.de/media/565/939565_4ba6b79e1f_m.jpg" alt="install active x" title="install active x" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;So here it is under my TS Web Access (after saying yes to activex)&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939598"&gt;&lt;img src="http://data2.blog.de/media/598/939598_2578af014b_m.jpg" alt="remote calculator" title="remote calculator" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Once you click on the icon, it will start your rdc to the published application and will open exactly the same as any other remote program (see previous blog)&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939607"&gt;&lt;img src="http://data2.blog.de/media/607/939607_0ba640fe5d_m.jpg" alt="starting" title="starting" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939618"&gt;&lt;img src="http://data2.blog.de/media/618/939618_bf5b609966_m.jpg" alt="starting1" title="starting1" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=939619"&gt;&lt;img src="http://data2.blog.de/media/619/939619_d94f106d48_m.jpg" alt="calculator" title="calculator" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Easy as that!&lt;/p&gt;
	&lt;p&gt;I will be covering TS gateway in my next blog, but if you have any questions at all regarding the above, shoot me an email!
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/11/06/longhorn_server_terminal_services_part_i~1300750/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/11/06/longhorn_server_terminal_services_part_i~1300750/#comments</comments></item><item><title>Longhorn Server Terminal Services - Citrix Eat your heart out!!!</title><link>http://daniels-it.blog.co.uk/2006/10/31/longhorn_server_terminal_services_citrix~1281450/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-10-31:/2006/10/31/longhorn_server_terminal_services_citrix~1281450/</guid><pubDate>Tue, 31 Oct 2006 15:39:33 +0100</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;
	Longhorn server has been out for quite some time now, with the latest build being CTP August 06.&lt;br&gt;
One of the huge let down’s I found from Microsoft’s server operating systems was the ability to have What we in the citrix world would call Published Applications.&lt;br&gt;
There has always been a great debate in the Terminal Services World as to what is better, Terminal Services or Citrix, and of course Citrix has the majority of the market due to its published applications ability.. well not anymore!&lt;br&gt;
Well finally Microsoft have developed 2 new components of their longhorn server family, Remote Programs and Terminal Services Gateway.&lt;/p&gt;
	&lt;p&gt;Additionally a new version of TS Web Access is also included but has many improvements over Windows Server 2003 and R2 TS Web Access&lt;/p&gt;
	&lt;p&gt;What is Remote Programs?&lt;br&gt;
Remote Programs are programs that are accessed remotely through Terminal Services and appear as if they are running on a user’s local computer.  Users can run Remote Programs Side-by-side with their local programs.  If a user starts more than one Remote Program on the same terminal server, the Remote Programs will share the same Terminal Services Session.&lt;/p&gt;
	&lt;p&gt;To use Remote programs please be aware the client must be running on either Longhorn Server Beta2, Windows Server 2003 SP1 or higher, Windows Vista, or Windows XP SP2.&lt;br&gt;
If you plan to use it on Server 2003 or XP, you must install Remote Desktop Connection (RDC) 6.0&lt;br&gt;
You can download the installer from &lt;a href="http://go.microsoft.com/fwlink/?LinkId=49779"&gt;http://go.microsoft.com/fwlink/?LinkId=49779&lt;/a&gt; &lt;/p&gt;
	&lt;p&gt;One of things I love about the new terminal services/remote programs, is that administrators can deploy them via an RDP file, or via an MSI, which is fantastic, especially the MSI, as it can be deployed through group policy!!!&lt;/p&gt;
	&lt;p&gt;My Lab Environment consists of the following:  1 Longhorn Server Beta 2 Domain Controller (I find Beta2 to be a bit more stable in VM’s than CTP August 06 Release), then 1 Longhorn Terminal Server, and of course 1 vista RC2 Client all joined in a single Domain.&lt;/p&gt;
	&lt;p&gt;Now I bet you are thinking, ‘well its all well and good talking about how good it is, but how do I set this up for myself to see?!’  It’s a breeze, and I am going to step you through it right now..&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Install Terminal Server Role Service&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;To install the Terminal Server role Service&lt;br&gt;
1.	 Start Server Manager.  To start Server Manager, use any one of the following methods:&lt;br&gt;
•	Start, then click Server Manager&lt;br&gt;
•	Start, point to Administrative Tools, and then click server manager&lt;br&gt;
•	Start, then Run, then type servermanager.msc then ok.&lt;br&gt;
The following screen then appears&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925253"&gt;&lt;img src="http://data2.blog.de/media/253/925253_2c46f9f542_m.jpg" alt="server manager" title="server manager" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Under Roles Summary, click Add Roles&lt;br&gt;
On the before you begin page, click next.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925255"&gt;&lt;img src="http://data2.blog.de/media/255/925255_ce040596f3_m.jpg" alt="before you begin" title="before you begin" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;On the Select Server Roles page, Select the Terminal Services role , then next&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925256"&gt;&lt;img src="http://data2.blog.de/media/256/925256_faf577b231_m.jpg" alt="select roles" title="select roles" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;On the Uninstall &amp; Reinstall Applications page, click next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925257"&gt;&lt;img src="http://data2.blog.de/media/257/925257_8995674729_m.jpg" alt="reinstall application" title="reinstall application" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;On the specify licencing mode page, select the most appropriate option and hit next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925259"&gt;&lt;img src="http://data2.blog.de/media/259/925259_374a99ce4e_m.jpg" alt="licencing mode" title="licencing mode" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;On the confirm installation option choose Install&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925261"&gt;&lt;img src="http://data2.blog.de/media/261/925261_fa138950be_m.jpg" alt="confirm installation options" title="confirm installation options" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;When completed hit restart.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925263"&gt;&lt;img src="http://data2.blog.de/media/263/925263_3ca21c7847_m.jpg" alt="install complete" title="install complete" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Once restarted, under server manager,  in roles, select terminal services and ensure it is all running aok.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925272"&gt;&lt;img src="http://data2.blog.de/media/272/925272_1c69bf804b_m.jpg" alt="running ok?" title="running ok?" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Next Step, Install programs, for the purpose of this example I have only installed the 2007 office suite, It is strongly recommended that you do NOT install separate components on separate servers for example, don’t just install word, install the whole office suite.&lt;/p&gt;
	&lt;p&gt;Next, Ensure that under Remote settings, under system in the control panel that you have allowed for your users.&lt;br&gt;
Now under server manager, under Terminal Services you will now see the Remote Programs tool.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925277"&gt;&lt;img src="http://data2.blog.de/media/277/925277_02788a3a42_m.jpg" alt="remote programs tool" title="remote programs tool" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Configure Remote Programs&lt;/u&gt;&lt;/p&gt;
	&lt;p&gt;Go to the remote programs tool, right click and choose&lt;br&gt;
Add Remote Programs...&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925327"&gt;&lt;img src="http://data2.blog.de/media/327/925327_684332a098_m.jpg" alt="right click and choose add remote program" title="right click and choose add remote program" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;on the welcome screen click next then point to your previously installed application, in this case I am going to choose Microsoft Powerpoint.  Then click Next&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925331"&gt;&lt;img src="http://data2.blog.de/media/331/925331_7735e52b84_m.jpg" alt="choose program" title="choose program" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;on the review settings page, click finish.&lt;br&gt;
You will now see your app in the list (I have a few already there)&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925337"&gt;&lt;img src="http://data2.blog.de/media/337/925337_9e868771d5_m.jpg" alt="list" title="list" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;u&gt;Creating an msi or rdp file for you application&lt;/u&gt; &lt;/p&gt;
	&lt;p&gt;Now, there is a new snap in for mmc called remote programs, so go to start, then run and type in remoteprograms.msc&lt;/p&gt;
	&lt;p&gt;From the right hand side actions pane, select create msi or rdp as applicable, in this case I will choose msi&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925360"&gt;&lt;img src="http://data2.blog.de/media/360/925360_c079d1b95a_m.jpg" alt="remoteprograms.jpg" title="remoteprograms.jpg" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;now click next on the wizard welcome screen.&lt;/p&gt;
	&lt;p&gt;The next step is to tell it where to save the msi.  Note if you plan to deploy through group policy, ensure the right permissions are on the directory where you save the msi to.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925367"&gt;&lt;img src="http://data2.blog.de/media/367/925367_bc353c86c9_m.jpg" alt="remoteprogramssave" title="remoteprogramssave" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;click next, now the next screen you need to tell it whether you want a desktop icon, a start menu icon or both and the extension, and hit next.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925368"&gt;&lt;img src="http://data2.blog.de/media/368/925368_45b8cd3734_m.jpg" alt="icons" title="icons" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;then hit finish.&lt;/p&gt;
	&lt;p&gt;Now you can deploy the msi from the location via group policy or via a file share etc..  The extension it will call these files is .rap, meaaning remote access program, but works the same as an msi.&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925370"&gt;&lt;img src="http://data2.blog.de/media/370/925370_9153616139_m.jpg" alt="msi created" title="msi created" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;now on your client, this is how it works..&lt;/p&gt;
	&lt;p&gt;In this case I am just going to double click the msi, and do a standard install (non group policy, however it works exactly the same)&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925374"&gt;&lt;img src="http://data2.blog.de/media/374/925374_2c25e3959a_m.jpg" alt="install" title="install" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;you will now see an icon on the desktop, and if you selected it, an icon under start&gt;programs&gt;Remote Programs&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925376"&gt;&lt;img src="http://data2.blog.de/media/376/925376_9e35e0e39c_m.jpg" alt="icon" title="icon" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;double click and launch the application, it will ask you to provide your login credentials but, bar that, thats it!&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925377"&gt;&lt;img src="http://data2.blog.de/media/377/925377_16504e1408_m.jpg" alt="starting" title="starting" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;and behold, there it is, it appears exactly as if it was running on the clients workstation!&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=925388"&gt;&lt;img src="http://data2.blog.de/media/388/925388_64e9188ea1_m.jpg" alt="powerpoint" title="powerpoint" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;One thing I love about it, is that it acts the same as a normal application whereby you can minimise it, move it around the screen etc.. Citrix Published applications could never do that, they only provided you with a single box in the middle of the screen and you couldnt move it around, so thumbs up microsoft &lt;img src="/img/smilies/icon_smile.gif" alt=":)" class="middle" border="0"&gt;&lt;/p&gt;
	&lt;p&gt;I will continue the remainder of this  setup in regards to Terminal Services Web Access (TSWEB ) and TsGateway in the next upcoming blogs... stay tuned!&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/10/31/longhorn_server_terminal_services_citrix~1281450/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/10/31/longhorn_server_terminal_services_citrix~1281450/#comments</comments></item><item><title>Running Vista or Longhorn Server on Vmware Workstation 5</title><link>http://daniels-it.blog.co.uk/2006/10/30/running_vista_or_longhorn_server_on_vmwa~1277741/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-10-30:/2006/10/30/running_vista_or_longhorn_server_on_vmwa~1277741/</guid><pubDate>Mon, 30 Oct 2006 15:15:05 +0100</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;
           I have recently been asked about Installing Longhorn Server and/or Windows Vista on VMWare Workstation.  There are a few tricks to getting it to work on VMWare workstation.&lt;/p&gt;
	&lt;p&gt;First up, make sure you are running the latest version, I am running VMWare 5.5.2 Build 29772 which works well on Windows Vista RC2.  The catch is during the Virtual Machine setup phase...&lt;/p&gt;
	&lt;p&gt;First up, create your virtual machine using a typical setup..&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923083"&gt;&lt;img src="http://data2.blog.de/media/083/923083_75fab5c7d2_m.jpg" alt="typical configuration" title="typical configuration" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Then Ensure you choose &lt;u&gt;'Windows XP Professional' &lt;/u&gt;as the OS&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923085"&gt;&lt;img src="http://data2.blog.de/media/085/923085_675fb77fab_m.jpg" alt="os version" title="os version" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Then Setup the rest as per usual.&lt;/p&gt;
	&lt;p&gt;Windows Vista and Longhorn Server have a slight compatibility issue with vmware, whereby until the VMware tools are installed, it gets slightly confused with the drivers and displays nothing but a blank screen.  So.. before running windows setup, edit the .vmx file for your virtual machine in notepad, and add the following lines:&lt;/p&gt;
	&lt;p&gt;Svga.maxWidth = "640"&lt;br&gt;
Svga.maxHeight = "480"&lt;/p&gt;
	&lt;p&gt;and change the following line:&lt;br&gt;
usb.present = "TRUE"&lt;br&gt;
to&lt;br&gt;
usb.present = "FALSE"&lt;/p&gt;
	&lt;p&gt;your vmx file should look like the below:&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923109"&gt;&lt;img src="http://data2.blog.de/media/109/923109_db5916f19f_m.jpg" alt=".vmx file" title=".vmx file" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;The reason you should set usb.Present = "FALSE" is because the OS will hang when shutting down if you dont (vmware to Vista/Longhorn driver issue)&lt;/p&gt;
	&lt;p&gt;Once you have done this, fire up your machine, install your OS and away you go...&lt;/p&gt;
	&lt;p&gt;Once you have Installed VMWare Tools on your virtual machine, Shutdown the VM, and take the Svga.maxWidth = "640" and Svga.maxHeight = "480"&lt;/p&gt;
	&lt;p&gt;out of your vmx file.  Save and Close and Happy VM'ing!!!&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/10/30/running_vista_or_longhorn_server_on_vmwa~1277741/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/10/30/running_vista_or_longhorn_server_on_vmwa~1277741/#comments</comments></item><item><title>Vista RC2 Rocks!</title><link>http://daniels-it.blog.co.uk/2006/10/30/vista_rc2_rocks~1277488/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-10-30:/2006/10/30/vista_rc2_rocks~1277488/</guid><pubDate>Mon, 30 Oct 2006 13:56:12 +0100</pubDate><description>	&lt;p&gt;On the 06/10/2006 Microsoft released Windows Vista Release Candidate 2 (RC2) build 5744 to a select number of Customer Preview Program (CPP) participants, as well as to members of itsTechBeta, TechNet, TAP, and MSDN community.&lt;br&gt;
Being the Technet Plus member that I am, I downloaded it the second it was released!  Following the release of Windows Vista RC1 on September 1, Microsoft continued to receive feedback that warranted a second release candidate release. That said, Microsoft hopes this is the last interim build before Windows Vista is released to manufacturing. As for whether Microsoft will meet its shipping goals for Windows Vista, a press release stated, "Microsoft continues to target Windows Vista availability for volume license customers in November 2006 and general availability in January 2007, although the final delivery will be based on quality." &lt;/p&gt;
	&lt;p&gt;I must say from my experience, Vista RC2 has been fantastic, I have noticed a huge number of differences from RC1, first up more drivers!  A lot of devices on my laptop did not pick up at all in RC1, but with RC2 everything got picked up with the exception of my display adapter, it seems a lot faster and more reliable.&lt;/p&gt;
	&lt;p&gt;They have also added Smart Card support in the new build, I found previously there was no option to use smart card, but now it appears they have upped their game... Also application compatibility, a lot more of my applications are smooth on vista, especially VMWare workstation.&lt;/p&gt;
	&lt;p&gt;It took ages to find the solution to the following 4 applications that vista has trouble with...&lt;br&gt;
Symantec Antivirus, Cisco VPN Client, Nero and Lotus Notes&lt;/p&gt;
	&lt;p&gt;The solutions... First up Symantec Antivirus, the following version is available via the symantec website:  Corporate Edition V10.0.1.628, this works a treat in Vista RC2.  In RC1, all the services used to fail, but this new version from symantec is fine.  But please note, you will need to install the following MS update prior to installation:  Windows6.0-KB920143-v1-x86.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923040"&gt;&lt;img src="http://data2.blog.de/media/040/923040_828b22f2ea_m.jpg" alt="symantec antivirus" title="symantec antivirus" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Cisco VPN Client, due to the enhanced security and User Account Control restrictions in vista it was impossible to get any version to install under vista, it would fail at the point in setup stating 'Installing Network Enhancer' i.e the network connection.. It would hang for an extensive amount of time, then crash.  Glad to say cisco are ahead of their game and released version 4.8.01.0410.  This is 100% Compatible with vista, just install it, import your existing pcf files and away you go..&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923045"&gt;&lt;img src="http://data2.blog.de/media/045/923045_1a59f7934c_m.jpg" alt="cisco" title="cisco" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Nero:  Nero has advised that they are not creating a 100% working version of Nero until Vista is released, but after trial and error I can advise that the following version works fine:&lt;br&gt;
Version 6.6.012, but keep in mind the SmartStart  does not work, but who needs that anyways?  We are IT Pro's right? as long as you use it via nero.exe it works fine.  Vista will alert you that it is not compatible, but you can ignore those messages because I assure you it does!&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923046"&gt;&lt;img src="http://data2.blog.de/media/046/923046_0401285cfb_m.jpg" alt="nero" title="nero" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Last and least, Lotus Notes/Domino.  If you are one fo the unfortunate people who are currently stuck with a Lotus Notes Infrastructure as apposed to an Exchange environment, not all hope is lost with Vista.  The only version of Lotus Notes/Domino Administrator that work with Vista are Notes R7.0.1, any version of Notes 6 (which most notes users run) is not compatible and will crash as soon as you try to open it.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=923049"&gt;&lt;img src="http://data2.blog.de/media/049/923049_f4ed1ec1c1_m.jpg" alt="notes" title="notes" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Can you upgrade from a previous version of Vista to Vista RC2?? YES YOU CAN, you can upgrade from Vista Beta 2 or RC1 without any issues at all! which was impossible under RC1.&lt;/p&gt;
	&lt;p&gt;One thing I have found strange though, is when my screen saver kicks in (the default vista one) it comes up saying Windows XP Media Edition!  OOPS Microsoft... I have informed them of this.. quite embarassing...&lt;/p&gt;
	&lt;p&gt;there are also a huge mound of new Gadgets available for the Vista Sidebar.. some useful ones I have found are the ping gadget and the Remote Desktop Connection.. &lt;/p&gt;
	&lt;p&gt;get your gadgets here:&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://gallery.microsoft.com/Results.aspxvista=landing&amp;rdm=797722&amp;l=1&amp;ti=2"&gt;http://gallery.microsoft.com/Results.aspxvista=landing&amp;rdm=797722&amp;l=1&amp;ti=2&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;To get Vista go to the follwing:  &lt;a href="http://www.microsoft.com/windowsvista/"&gt;http://www.microsoft.com/windowsvista/&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;All I can say is, vista kicks ass!&lt;br&gt;
&lt;a href="http://www.blog.co.uk/srv/media/media_item.php?item_ID=922945"&gt;&lt;img src="http://data2.blog.de/media/945/922945_3aa2967409_m.jpg" alt="vista desktop" title="vista desktop" vspace="5" hspace="5"&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;I highly recommend giving it a go, i'll be blogging more and more on vista in upcoming days...&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/10/30/vista_rc2_rocks~1277488/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/10/30/vista_rc2_rocks~1277488/#comments</comments></item><item><title>Daniel's IT Blog - Grand Opening!</title><link>http://daniels-it.blog.co.uk/2006/10/30/daniel_s_it_blog_grand_opening~1277097/</link><guid isPermaLink="false">tag:daniels-it.blog.co.uk,2006-10-30:/2006/10/30/daniel_s_it_blog_grand_opening~1277097/</guid><pubDate>Mon, 30 Oct 2006 11:56:14 +0100</pubDate><description>	&lt;p&gt;Hi Everyone,&lt;br&gt;
              Welcome to the first ever entry on Daniel's IT blog!  This Blog site is a resource for all IT professionals out there, wanting to get their hands dirty in the latest Products from Microsoft, there will be posts on everything from ISA Server 2005 to Windows Vista, Longhorn and Exchaneg 2007 as well as any hints, tips and problems I find along the way with any products!&lt;/p&gt;
	&lt;p&gt;One thing you dont have to worry about is, 'Is this guy full of crap?'  The answer to that will be NOOOOOO!!!&lt;br&gt;
My qualifications are as follows...A+, CTT+, Linux+, IEUST, CCNA, havent bothered doing the exams but I will sit my MCSE next year, I have had that much experience with all MS Products I figure hey! there's no rush! and I have 7 years active duty in the field providing consulting and Support (2/3/4)on everything from Security to Active Directory and Large Scale Implementations &amp; Migrations, My specialty being Active Directory.&lt;br&gt;
I Have worked with all sorts, ranging from Small Business/Personal to government of 50,000 people and above...&lt;/p&gt;
	&lt;p&gt;I will blog whenever I have the chance!&lt;/p&gt;
	&lt;p&gt;Enjoy and come back often!&lt;img src="/img/smilies/icon_biggrin.gif" alt=":D" class="middle" border="0"&gt;
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://daniels-it.blog.co.uk/2006/10/30/daniel_s_it_blog_grand_opening~1277097/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</description><comments>http://daniels-it.blog.co.uk/2006/10/30/daniel_s_it_blog_grand_opening~1277097/#comments</comments></item></channel></rss>
