miércoles, 11 de mayo de 2011

SSL services in exchange 2007

On exchange 2007 there are many client protocols as 2003 as well, when import a cert on the CAS or HUB server, we are able to co consolidate or associate those with all services (pop3, imap4,smtp,owa).

For a clients outlook express and SMTP we must take care with the configuration, by default there is a receive connector for a clients:





On the client:





We are using an internal PKI and in order to request a new SMTP certificate using the Exchange Management Shell use the following cmdlet:

New-ExchangeCertificate –GenerateRequest –Path c:\cert.req –SubjectName “cn=relay.apatricio.local” –FriendlyName “Internal Relay Certificate” –PrivateKeyExportable:$True

Now, let’s request the certificate created using the Certification Authority webpage:

  1. Logged on Exchange Server open the http:///certsrv, where is your server which hosts the Certification Authority.
  2. Click on Request a Certificate link.
  3. Click on advanced certificate request.
  4. Click on the second link which is Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
  5. Open the file C:\cert.req which was created by New-ExchangeCertificate cmdlet and copy the content.
  6. Paste the content of that file into the Base-64-encoded certificate request field in the webpage.
  7. On the same page, select Web Server in the Certificate Template field and then click the Submit button.
  8. On the new page, click on the Download Certificate link and save it in the C:\ root of the Exchange Server.

Let’s import the new certificate, to do that use this cmdlet:

Import-ExchangeCertificate –Path:C:\certnew.cer

Note:
The file name and path is just an example, you have to use the file name and path that you have used in the previous step.

Time to enable the new imported certificate to be used by the SMTP service using the Exchange Management Shell. To enable it we just need to copy the Thumbprint that was shown when we imported the request in the previous step and use this cmdlet:

Enable-ExchangeCertificate –Thumbprint -Services SMTP

You will be prompted to change the default SMTP certificate, just type in N and hit enter.

Use get-excgangecertificates | fl PS to see the current services attached on the cert:

More information:

http://technet.microsoft.com/en-us/library/aa997231%28EXCHG.80%29.aspx

For enable logging:



martes, 10 de mayo de 2011

Information Store and Log sequence numbers

Event 514 on our exchange server means that the logs sequence is consume and when is completed, all Exchange databases will dismounted.

Information Store (6768) XXX: Log sequence numbers for this instance have almost been completely consumed. The current log generation is 933000 (0x000E3C88) which is approaching the maximum log generation of 1048559 (0x000FFFEF), there are 115559 (0x0001C367) log generations.

So the maximum log generation is 1048559 (0x000FFFEF) and remains 115559 logs to consume, so ig we find on the APP eventvwr the event number 214, we can estimate how many logs our Exchange use by day and we can estimate how many days we have until to have this problem.

Exchange 2007 supports 2 billion log files (2147483628) which is 7fffffec in hexadecimal.

Notice that if you miss the ESE 514 warning your databases will dismount and generate the following events:

Event ID: 1159
Event Type: Error
Event Source: MSExchangeIS
Event Category: General
Description: Database error 0xfffffdf9 occurred in function JTAB_BASE::EcEscrowUpdate while accessing the database "First Storage Group\Mailbox Store (SERVER)".

Event ID: 9518
Event Type: Error
Event Source: MSExchangeIS
Event Category: General
Description: Error 0xfffffddc starting Storage Group Path_of_Storage_Group on the Microsoft Exchange Information Store. Storage Group - Initialization of Jet failed.

More info.
http://support.microsoft.com/kb/830408

Solution:

One of the common solution is dismount all database that are part of storage group, move out all logs and CHK file, mount all databases, CHK file and transaction logs will create starting in 0.

1--


2--


3--


4--


After that, all incremental backup are unusable, so run a full backup after this procedure.

jueves, 5 de mayo de 2011

Connection broken between ISA FW and ISA Storage conf.

The only case that I see this issue is when the cert on ADAM instance was expire, but I have the same issue with a intermediate Verising cert for an application.

Verising has two new cert for SLL apps, so take care with those because there is one that has problem with ISA server:

1.

2.

Those certs has a different serial number version, on one of those there is something wrong because when we paste it on the server, isa server stop to work:

VeriSign Class 3 Public Primary Certification Authority - G5 (serial number)

1b 09 3b 78 60 96 da 37 bb a4 51 94 46 c8 96 78 --- wrong cert

18 da d1 9e 26 7d e8 bb 4a 21 58 cd cc 6b 3b 4a--- wrong cert

25 0c e8 e0 30 61 2e 9f 2b 89 f7 05 4d 7c f8 fd --- correct cert

Solution:

Just replace the cert for the correct one and the problem will be solved.

3.

4.

On this document there is information about How to Securely Publish a Configuration Storage Server in ISA Server 2006 and also how to change an expiate certificate:

http://technet.microsoft.com/en-us/library/bb794830.aspx

How to Back Up and Restore an ISA Server Enterprise Configuration (Enterprise Edition)

http://technet.microsoft.com/en-us/library/bb794757.aspx

In ISA Server 2006 EE the configuration is stored in ADAM (Active Directory Application Mode)
Connect to you ADAM ADSI Edit
Server Name: localhost and port: 2171
Connect to the following node:
Distinguished name (DN) or namingContext: CN=FPC2
Navigate to CN=Array-Root
CN=Arrays
CN={ID of your Array}
CN=ArrayPolicy
CN=PolicyRules
CN={ID of the bad rule}

5.

How to delete Logs in a Exchange 2007 CCR

Here is the process to manually remove log files. As a reminder once this is done you will NOT be able to perform an incremental backup until a FULL backup is completed.


1. Suspend replication on the server
a. Get-StorageGroup -Server | Suspend-StorageGroupCopy
2. On the passive node check the database header to find out the logs required.
a. Eseuil /mh (the ‘State’ will be Dirty Shutdown, this is expected and not an issue).
b. Look for ‘Log Required’. This will tell you which logs CANNOT be removed. Anything before those logs are safe to remove.
i. Looking at the sample below, Logs Exx00004A42-Exx00004A45 cannot be removed. Logs Exx00004A41 and earlier can be removed. (Exx will depend on the SG…can be E00, E01, E02, etc.)
3. Resume replication on the server
a. Get-StorageGroup -Server | Resume-StorageGroupCopy
4. Run Get-StorageGroupCopyStatus and check that CopyQueueLength and ReplayQueueLength are 0
5. Perform a switchover using Move-ClusteredMailboxServer and repeast the process on the former active (now newly passive) node.
6. Perform a FULL Backup. All previous backups are now invalid.

[PS] C:\>eseutil /mh F:\CCRMBX1\CCR-SG4.edb
Extensible Storage Engine Utilities for Microsoft(R) Exchange Server
Version 08.02
Copyright (C) Microsoft Corporation. All Rights Reserved.
Initiating FILE DUMP mode...
File Type: Database
Format ulMagic: 0x89abcdef
Engine ulMagic: 0x89abcdef
Format ulVersion: 0x620,12
Engine ulVersion: 0x620,12
Created ulVersion: 0x620,12
DB Signature: Create time:11/25/2008 16:50:25 Rand:102284345 Computer:
cbDbPage: 8192
dbtime: 165542 (0x286a6)
State: Dirty Shutdown
Log Required: 19010-19013 (0x4a42-0x4a45)

Also here there is a procedure to run a backup with windows 2008:

http://technet.microsoft.com/en-us/library/ee221177(EXCHG.80).aspx


viernes, 22 de abril de 2011

Siii robocopy en w2008

Esta fue una tool muy utilizada por los administradores de file server, muy poderosa y de mucha auyuda, la buena noticia es q viene incluida en esta version de windows.

Para los administradores de Echnage, con los nuevos logs de 1mb en 2007, es muy util para mover logs por falta de espacio en disco:

robocopy x:\LG09 z:\temp e09002b*.log /R:1 /W:1 /mov /LOG:c:\ROBOLOGexch5.txt
comando--origen----destino--criterio-------reintentos-espera--move--log

http://technet.microsoft.com/en-us/library/cc733145%28WS.10%29.aspx

OCS y grupos en la GAL

Managing the Address Book Server from the Command Line

You can manage the Address Book Server by running ABServer.exe from a command prompt. You can modify the environment path system variable to include the location of ABServer.exe (%programfiles%\Microsoft Office Communications Server 2007\Server\Core), or you can run the tool directly from the Office Communications Server Address Book directory.

Table 6 shows valid command switches and arguments.

http://technet.microsoft.com/en-us/library/bb936631%28office.12%29.aspx

Este blog es muy interesante, esta todo el deploy de ocs:

Office Communications Server 2007 Enterprise Deployment

http://www.shudnow.net/2008/06/08/office-communications-server-2007-enterprise-deployment-part-1/



miércoles, 13 de abril de 2011

Routing en modo misxto

Como funciona:

When only one routing group connector is established between Exchange 2003 and Exchange 2007, you do not have to make any changes to link state, and routing loops will not occur. However, if more than one routing group connector is configured between Exchange 2003 and Exchange 2007, the minor link state updates that are transmitted between Exchange 2003 servers can introduce problems. When Exchange 2003 detects that a connector is unavailable, link state updates are communicated throughout the Exchange organization to notify them of the connector down state. The Exchange 2003 bridgehead server also tries to determine an alternative route for message transfer to the destination server. However, Exchange 2007 does not use link state to determine a routing path. The Exchange 2007 Hub Transport server will be unaware of the down connector state and may decide to route a message back through a routing path that Exchange 2003 is trying to route around.


Q es liknk state?? Disabel en 2003 para evitar problemas de looping:

To avoid routing loops, you must suppress minor link state updates before introducing additional routing group connectors. Minor link state updates are sent between Exchange 2003 servers to update the link state routing table to indicate that a connector is down. When the SuppressStateChanges registry key is set, you are turning off the ability for a connector to be marked as down. Link state messages are also used to notify Exchange 2003 servers of configuration changes to the Exchange organization, such as the addition or removal of a connector or a server. When you suppress minor link state updates, it does not prevent these major link state update messages from being communicated.

When minor link state updates are suppressed, Exchange 2003 also only uses least cost routing. This eliminates the chance for routing loops to occur. We recommend that you suppress link state updates on every Exchange 2003 server in the organization to maintain a consistent configuration.

Lo mas importante q me llamo mucho la atención:

mportant: If configuration changes are made in Exchange Routing Group (DWBGZMFD01QNBJR) some latency may occur before those changes are received by Exchange Server 2003 servers and propagated by the Exchange 2003 routing group masters. The delay will depend on how frequently the routing group masters poll for configuration changes in other routing groups. By default, the polling interval is set to one hour. To immediately register all changes in Exchange Routing Group (DWBGZMFD01QNBJR) on Exchange 2003 servers, you must restart the routing group masters.



Articulo:

http://technet.microsoft.com/en-us/library/bb125223%28EXCHG.80%29.aspx