Saturday, July 8, 2023

Ikea Trådfri Bulbs On Philips Hue Bridge

 My husband and I have been dabbling in smart home pursuits for a few years.

One of my initial forays has been into Philips Hue smart lights.  They have been amazing for decorating and home automation.  But not cheap!

This has led me to try out cheaper alternatives.  I've had some nice luck that Innr lights can be added to the Hue bridge.

I wanted some Ikea Vidja lamps and wanted to add smart bulbs to them.  Innr doesn't sell E12 bulbs.

But Ikea has their automation line of Trådfri bulbs.  Reading online seemed to indicate that bulbs with new firmware could be added to Hue.

Other sources I read said that you might need to update the firmware.  That would take the Ikea bridge, which I didn't have. 

I tried adding a Trådfri bulb to Hue by discovery.  It wasn't working.  You can add items to items to the Hue bridge by discovery or with a 6 digit serial number.  I could find no sign of serial number on the bulb.

What helped me be successful was Hue Tips Lamp Finder app. 

I did have to add the bulbs one at a time, and I needed them extremely close to the bridge.  When I tried originally, I was quite close in the next room, but it only worked when I plugged the lights in a very short distance from the bridge.

But I have the smart control, warm to cool color adjustment of the Trådfri bulb for $8.99 each as compared to $27.99 for the Hue counterpart (costs as of writing July 2023).

Sunday, February 7, 2021

Certificates and External Dynamic Lists - Challenges on Palo Alto NG Firewall

I manage a Palo Alto firewall and have been using External Dynamic Lists to find outside sources listing malicious IPs and domain names and blocking them from our network.

My starting problem - if I didn't take the time to properly configure the certificates, commits would come with a warning for each EDL: External Dynamic List <name> is configured with no certificate profile. Please select a certificate profile for performing server certificate validation.

At one point, I had things done wrong, which led to different errors in the logs: EDL server certificate authentication failed. The associated external dynamic list has been removed, which might impact your policy. EDL Name: <name> All, EDL Source URL: <url>, CN: <cn>, Reason: unable to get local issuer certificate

There are three pieces to this.  Uploading the full certificate chain into your firewall, correctly building a certificate profile, and associating the certificate profile with the EDL.

I was having difficulties understanding how to get the certificates.  At one point, I didn't understand how to do it in Chrome and I was doing it on Firefox.  

In Firefox, you browse to the site in question, and click the padlock in the left of the address bar. A site information box appears, and click the arrow to the right of Connection Secure.  Then click More Information at the bottom. A page info window appears - use the View Certificate button.

You get an about:certificate tab to open, and there's a tab for each part of the chain.  I was using the Download PEM (cert) link for each certificate.

However...once I learned how to work with certificates in Chrome, I was surprised to see Firefox was showing me 3 certificates in the chain of the site in question, yet Chrome showed me 4!  That fourth certificate was obviously a necessary piece of the puzzle.



Working with certificates in Chrome: click the padlock in the left of the address bar. Click Certificate (Valid). Go to the Certification Path tab. 

For each certificate in the chain, highlight it and hit the View Certificate button. Go to the Details tab and use the Copy to File... button. You will enter a Certificate Export Wizard. I used the default format, DER encoded binary X.509 (.CER). Name each file so you know the correct order for how they enter in the chain - adding them to your Palo Alto in the correct order, top down, is important.

Once you have all your files, now they need to be added into the firewall.  This is done on Device, in Certificates under the Certificate Management section.  Import each certificate, starting at the top of your chain.

Once all are imported, let's handle the certificate profile.  That is done from the Certificate Profile area in Device, Certificate Management.

Name your Certificate Profile, and add the top 2 certificates that you just imported in the previous set.

Now head to Objects and External Dynamic Lists. Apply your new Certificate Profile to the EDL in question.

You should now commit error free!

Sunday, February 2, 2020

Apple Watch Workouts - Complete List in WatchOS 6

This is a little different from my normal post.

But being a technology person, I am all about my gadgets.  I also enjoy fitness pursuits, so I love having an Apple Watch.

I enjoy the Workouts app for tracking, and enjoy the social aspect with several friends and family.

I recently attended a qi gong seminar, and was eager to track it.

Apple Watch is great at certain basic activity tracking like running or walking (indoors or outdoors) and swimming.

But there are a lot of other activities!  I will say that the watch does its best to calculate calories based on your heart rate and movement, but my educated guess says that it can be off by a lot.  It warns you that it will assume a brisk walk - and I have found times that I think the calories for my workout is way too high because it did exactly that.

So, understand that all these activities are likely for your record tracking and won't give you tons of interesting metrics.  And if you can't find anything you like, you can always use "Other."

P.S. I tracked my qi gong class as "Tai Chi" - the icon even matches one of the moves from our class!

Here's the complete list:

  • American Football
  • Archery
  • Australian Football
  • Badminton
  • Barre
  • Baseball
  • Basketball
  • Bowling
  • Boxing
  • Climbing
  • Core Training
  • Cricket
  • Cross Country Skiing
  • Cross Training
  • Curling
  • Dance
  • Disc Sports
  • Downhill Skiing
  • Elliptical
  • Equestrian Sports
  • Fencing
  • Fishing
  • Fitness Gaming
  • Flexibility
  • Functional Training
  • Golf
  • Gymnastics
  • Hand Cycling
  • Handball
  • High Intensity Interval Training (HIIT)
  • Hiking
  • Hockey
  • Hunting
  • Indoor Cycle
  • Indoor Run
  • Indoor Walk
  • Jump Rope
  • Kickboxing
  • Lacrosse
  • Martial Arts
  • Mind & Body
  • Mixed Cardio
  • Open Water Swim
  • Other
  • Outdoor Cycle
  • Outdoor Run
  • Outdoor Walk
  • Paddling
  • Pilates
  • Play
  • Pool Swim
  • Racquetball
  • Rolling
  • Rower
  • Rugby
  • Sailing
  • Skating
  • Snow Sports
  • Snowboarding
  • Soccer
  • Softball
  • Squash
  • Stair Stepper
  • Stairs
  • Step Training
  • Strength Training
  • Surfing
  • Table Tennis
  • Tai Chi
  • Tennis
  • Track & Field
  • Volleyball
  • Water Fitness
  • Water Polo
  • Water Sports
  • Wrestling
  • Yoga

Thursday, November 1, 2018

Skype for Business Retention in Office 365

Much as I needed to configure a retention policy for Microsoft Teams, I also needed retention for Skype for Business conversations.  

The Data Governance area at https://protection.office.com has a Retention section, but a Skype for Business policy was giving me difficulty.  

When you build a retention policy, you specify the locations to apply it to, and Skype for Business is an option.  Other policies allow you to include all users or all areas by default.  SfB is not like that.

The added challenge was when I used the GUI to attempt to choose users, it shows 100 users.  My organization contains well over 100 users.  There were no ways to navigate between screens.  And there's no way I was checking hundreds of checkboxes to pick my users!

I wound up opening a support ticket to get some guidance.  

What we need can be accomplished by PowerShell.  Once I have established a retention policy that suits my needs, a single PowerShell command can add them to the existing policy:

Set-RetentionCompliancePolicy -Identity "MyPolicy" -AddSkypeLocation janedoe@mycompany.com

But what if I want everyone in my policy?  My basic strategy (and forgive me, as I am sure there are easier solutions, but my PowerShell skills are rudimentary at best) is as follows:


Get-MsolUser -All | where {$_.isLicensed -eq $true} | select userprincipalname | out-file AllLicensedO365Usersyyyymmdd.csv

I would then manipulate the list in a text editor (such as Notepad++).  I need to remove excess spaces.  The CSV needs to have a heading of User.  

Then:

Import-Csv AllLicensedO365Usersyyyymmdd.csv | ForEach {Set-RetentionCompliancePolicy -Identity "Keep Everything (Skype)" -AddSkypeLocation $_.User}

Voila, all my users have the policy of choice.

Wednesday, September 26, 2018

Teams Retention in Office 365

My organization is working on deploying Office 365.  It's been a slow process as our Exchange environment has lots of room for improvement.  Our users are drowning in PST files, so moving that data to Exchange Online is tedious.

We've recently enabled Teams for our organization and are currently piloting it, with possible plans for expansion.  Retention is a big deal for our organization, so configuring those settings quickly became important.  

I headed over to https://protection.office.com and went to Data Governance | Retention.  I edited our existing policy.  But, wait, there were no options for Teams.  The Teams retention settings are missing.  What was going on?

I ultimately found the answer... a Teams retention policy cannot contain any other products.  So, when you want to configure Teams retention, make a new policy that contains no other products.

Lots more helpful on retention for Office 365 here: https://docs.microsoft.com/en-us/office365/securitycompliance/retention-policies?redirectSourcePath=%252fen-us%252farticle%252fOverview-of-retention-policies-5e377752-700d-4870-9b6d-12bfc12d2423

Saturday, August 11, 2018

"This app is no longer shared with you" on iOS

I stumbled across a new problem today.

I'm very much a part of the Apple ecosystem.  On my iPhone, an app that had been purchased by my husband (AutoSleep) with Family Sharing would not open for me.

"This app is no longer shared with you.  To use it, you must buy it from the App Store." I had options to View in App Store or Cancel.  To further my confusion, viewing it in the app store only gave me an Open button.  Restarting my phone didn't help.

I found a quick answer that worked great here:
https://discussions.apple.com/thread/8273516

On iOS11, there's a new feature called Offloading Unused Apps.  If you're low on disk space, it lets you remove apps from your phone without deleting data.  If you delete an app in the traditional sense, it discards the data along with it.

So to fix my broken app, I went to Settings | General | iPhone Storage.  I selected the app in question.  I then selected Offload App.  Once that was finished, I then picked Reinstall App.

Lo and behold, the app is working again for me. 

Wednesday, June 27, 2018

Azure Active Directory Connect, High CPU Usage After June 2018 Patching

I did the latest Microsoft security updates for some servers, and was noticing my server running Azure Active Directory Connect for Office 365 was running at very high CPU.  I wasn't successful at restarting it from within the guest (or, wasn't patient enough, take your pick) and reset the VM.  The issue persisted.

My Microsoft.Identity.Health.AadSync.MonitoringAgent.Startup.exe was running at 99%.

Some research quickly tipped me off to the culprit.  (https://social.msdn.microsoft.com/Forums/azure/en-US/e9b621f6-f38c-488e-8fcb-ff85d406f256/azure-ad-connect-health-sync-monitor-high-cpu-usage?forum=WindowsAzureAD) .NET Framework 4.7.2 was the culprit.  Uninstalling the right KB depends on your OS.

  • Server 2008 R2 - "Microsoft .NET Framework 4.7.2"
  • Server 2012 - KB4054542
  • Server 2012 R2 - KB4054566
  • Server 2016 - KB4054590
I was dealing with Server 2016, so I uninstalled KB4054590, restarted, and the server seems fine.


I'll be sure to monitor the version history to see if when I go to patch next month, if Azure Active Directory Connect has been updated to address this.


Monday, June 11, 2018

Resolving Crashing Skype for Business

Today, I found myself unable to open Skype for Business.  I would load the application and it would crash.

Examining my Event Viewer, I found the following:

Level: Error
Source: Application Error
Event ID: 1000
Faulting application name: lync.exe, version: 16.0.4690.1000, time stamp: 0x5acd052e
Faulting module name: KERNELBASE.dll, version: 10.0.15063.1029, time stamp: 0x99b50546
Exception code: 0xc06d007e
Fault offset: 0x000f0132
Faulting process id: 0x3364
Faulting application start time: 0x01d40178ed74b119
Faulting application path: C:\Program Files (x86)\Microsoft Office\Office16\lync.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: fde33f51-913a-4302-9674-3a5370420999
Faulting package full name: 
Faulting package-relative application ID: 

I was a bit perplexed as I had run successfully last week after receiving updates.

I found the resolution here (thanks to Brian):
https://community.spiceworks.com/topic/2126287-skype-for-business-2016-problems-after-kb4018323

  • Open your Playback devices menu by right-clicking on the volume icon on your taskbar (or your preferred method)
  • Highlight your current playback device and select the Properties button.
  • Select the Advanced tab on the resulting window.
  • Under the heading ,"Exclusive Mode", ensure that both checkboxes are unchecked. Really, you can deselect the first checkbox and it will gray out the second for you.


Monday, January 22, 2018

Exchange, Trend ScanMail, SQL Server Express, and SQL Server 2012 Native Client

I have an older Exchange environment to manage in my environment.  I have hopes to migrate to Exchange Online, but in the meantime, Exchange on premise needs maintenance.

We protect our Exchange with Trend Micro ScanMail (among other products).

Recently, when calling support, I discovered I had let our version of ScanMail fall behind and was out of support.  It was time to update to ScanMail 12.5.

I read the documentation, and the process looked fairly straight forward.  I was very concerned about the risks involved (email is probably our most visible service to our end users) but the work needed to happen.

In the first few screens of the ScanMail upgrade, it pointed out that if your version was being back-ended by SQL Express, you should upgrade off SQL Server 2008 Express to SQL Server 2014 Express.  A little investigation on my part reveals, yes, I need to do this.

OK, so I cancel the ScanMail upgrade and proceed onto downloading SQL Server 2014 Express.

And unfortunately, there things stopped going smoothly.

Some way into the upgrade, it stopped.  It was attempting to do something with the Microsoft SQL Server 2012 Native Client.  It was telling me that it couldn't find SQLNCLI.MSI.  OK, fair enough, I go download it.  I point it to my download.  Nope:

"The file '<path>SQLNCLI.MSI' is not a valid installation package for the product Microsoft SQL Server 2012 Native Client.  Try to find the installation package 'sqlncli.msi' in a folder from which you can install the Microsoft SQL Server 2012 Native Client."


Uh oh.

I tried other downloads, and even scoured the server for every copy of SQLNCLI.MSI I could find.  Despite finding a variety of versions, every file returned that same error message.

Finally, out of ideas, I hit cancel on the prompt for the SQLNCLI.MSI.  The installation continued on.

But, unsurprisingly, it failed, telling me that several components had been unsuccessful.

At this point, I took inventory of the server, and could see I was in rough shape.  I could see signs of SQL Server 2008 Express and 2014 Express both on the system.  But the 2008 version was what was still running.

Some quick Googling didn't yield any results.  Given the criticality of this server, I felt a call to Microsoft Support was my best option.

When I got my support technician on the phone, he had me try one interesting avenue (that didn't help my situation but could be helpful in general).   This utility checks for missing SQL MSI files and can remediate.  My server yielded no results.  The link to that utility is here: 
FixSQLMSI Version1.3.zip

Once that didn't yield any solution, his suggestion then became the right one.  Uninstall the SQL Server 2012 Native Client, and rerun the SQL Server 2014 Express upgrade.

That finished successfully.  I then had healthy SQL Server 2014 Express.  And I was able to successfully complete my ScanMail 11.0 SP1 to 12.5 upgrade.

Monday, April 17, 2017

Exchange Server 2010 to Exchange Online Message Tracking Does Not Work


My organization is currently working on moving from on premise Exchange to hosted Exchange from Microsoft via Office 365 and Exchange Online.

Prior to moving any mailboxes to our tenant, we have been testing from on premise mailboxes to test cloud mailboxes.  

We were tracking messages from Outlook Web Access.  Under Manage My Organization, Mail Control, we'd run Delivery Reports.

I would search from an on premise mailbox to a cloud mailbox for messages I had sent.  The search would work well and return results.






 













Once I double clicked one of the results to see detail, however, that wasn't successful.  It would not be successful and would fail after a timeout.


 








I opened a ticket with Microsoft Support.

It wound up being fairly involved and we did quite a bit for troubleshooting.  But the ultimate solution was to close the ticket as a known bug.



I consulted about the results of our last troubleshooting to get Message tracking report using EMS and we got the error related to “WARNING: The log search service was unavailable on server 'mwhpr09mb2047.namprd09.prod.outlook.com'.”

It’s a known issue on O365 which possibly might not be addressed any time soon, the alternate option would is to use the Messaging Tracing if they can in our  scenario. Message Tracing is available to admins only, can't directly search on Subject (but can search on recipient, sender, date/time then sort to locate specific subject).



As an administrator, you can find out what happened to an email message by running a message trace in the Exchange admin center (EAC). After running the message trace, you can view the results in a list, and then view the details about a specific message. Message trace data is available for the past 90 days. If a message is more than 7 days old, the results can only be viewed in a downloadable .CSV file.



Reference:




Since this a known issue in product, you will not be charged for the incident. 

So, I can track messages from the Office 365 administrator center, and can do nothing to correct the issue impacting my on premise message tracking