As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/
Options

[Sysadmin] Routing to null

1919294969799

Posts

  • Options
    CogCog What'd you expect? Registered User regular
    To be fair, "nobody remembers the admin password" is also a problem.

    But still, changing a name shouldn't be so god damned hard.

  • Options
    wunderbarwunderbar What Have I Done? Registered User regular
    I'm also impressed you were able to convince them to change the account names.

    the last 3 places I've worked have all had firstinitial.lastname and no amount of begging could get anyone to change it, including my current employer which is still small enough to do it without so much pain before we get big enough where it does become a pain in the ass.

    XBL: thewunderbar PSN: thewunderbar NNID: thewunderbar Steam: wunderbar87 Twitter: wunderbar
  • Options
    CogCog What'd you expect? Registered User regular
    wunderbar wrote: »
    I'm also impressed you were able to convince them to change the account names.

    the last 3 places I've worked have all had firstinitial.lastname and no amount of begging could get anyone to change it, including my current employer which is still small enough to do it without so much pain before we get big enough where it does become a pain in the ass.

    The secret is to tell and not ask.

  • Options
    CogCog What'd you expect? Registered User regular
    I just ran into a user who's been using a local account on their Mac this whole time, so now I get to learn how to convert that into a.... mobile?... account? I believe that is the term? And get them authenticating to AD.

    I feel like a broken record asking why everything in Mac world is so hard.

  • Options
    FeralFeral MEMETICHARIZARD interior crocodile alligator ⇔ ǝɹʇɐǝɥʇ ǝᴉʌoɯ ʇǝloɹʌǝɥɔ ɐ ǝʌᴉɹp ᴉRegistered User regular
    Thawmus wrote: »
    Thawmus wrote: »
    Step one, find and cage Feral.

    Step two, let Feral loose inside local CenturyLink office.

    Step three, ???

    Step four, profit!

    I just realized this morning that this joke is incomplete without one small addition:

    When I release him inside the local CenturyLink office, I say, "Look out."

    Then I put on my shades.

    "He's Feral."

    I'm game for this plan.

    every person who doesn't like an acquired taste always seems to think everyone who likes it is faking it. it should be an official fallacy.

    the "no true scotch man" fallacy.
  • Options
    FeralFeral MEMETICHARIZARD interior crocodile alligator ⇔ ǝɹʇɐǝɥʇ ǝᴉʌoɯ ʇǝloɹʌǝɥɔ ɐ ǝʌᴉɹp ᴉRegistered User regular
    edited July 2021
    Thawmus wrote: »
    Cog wrote: »
    Thawmus wrote: »
    "Hey maybe just, like, fuck faxing."

    Correct.

    Fun fact: Our fax server is running on CentOS 8, which will no longer be getting updates at the end of the year and when I went to upper management and said hey I gotta replace the OS before the end of the year they were like, "But what if you didn't and we just turned it off at the end of the year instead because fuck faxing?"

    Look I don't like to swoon about management very often but they have their moments.

    yessssssssssssssssss

    Feral on
    every person who doesn't like an acquired taste always seems to think everyone who likes it is faking it. it should be an official fallacy.

    the "no true scotch man" fallacy.
  • Options
    NosfNosf Registered User regular
    I fuckin' hate me some faxing, and deal with hospitals, pharmacies and doctors all of whom thing fax is just the most secure thing ever, because like, we put the fax behind a counter!

    We posted for some jobs. So far I have applicants from Tehran, Ghana, someplace in S. America, etc. Thaaaaaaanks indeed and linkedin, you pieces of shit.

  • Options
    CogCog What'd you expect? Registered User regular
    Nosf wrote: »
    I fuckin' hate me some faxing, and deal with hospitals, pharmacies and doctors all of whom thing fax is just the most secure thing ever, because like, we put the fax behind a counter!

    We posted for some jobs. So far I have applicants from Tehran, Ghana, someplace in S. America, etc. Thaaaaaaanks indeed and linkedin, you pieces of shit.

    I've been at this new job for a month now even after shutting off my "looking for a job" options on those sites I'm getting job offers from Tehran, Ghana, and S. America.

  • Options
    bowenbowen How you doin'? Registered User regular
    Nosf wrote: »
    I fuckin' hate me some faxing, and deal with hospitals, pharmacies and doctors all of whom thing fax is just the most secure thing ever, because like, we put the fax behind a counter!

    We posted for some jobs. So far I have applicants from Tehran, Ghana, someplace in S. America, etc. Thaaaaaaanks indeed and linkedin, you pieces of shit.

    Lawyers and Doctors still operate under the assumption they're POTS copper lines that need a warrant to wire tap instead of being fed off a fiber backbone that they have been for the past like decade at this point. I don't think you can get POTS without paying like $200 a month now.

    not a doctor, not a lawyer, examples I use may not be fully researched so don't take out of context plz, don't @ me
  • Options
    FeralFeral MEMETICHARIZARD interior crocodile alligator ⇔ ǝɹʇɐǝɥʇ ǝᴉʌoɯ ʇǝloɹʌǝɥɔ ɐ ǝʌᴉɹp ᴉRegistered User regular
    It's all metadata?
    *cocks handgun*
    It always was.

    every person who doesn't like an acquired taste always seems to think everyone who likes it is faking it. it should be an official fallacy.

    the "no true scotch man" fallacy.
  • Options
    MyiagrosMyiagros Registered User regular
    What have you guys been using for spam filters in tandem with Office 365?

    We were using ZeroSpam which worked and was straight forward to set up. Now they have merged with a service called Hornet Security and it is turning out to be a nightmare.
    - email accounts have to be listed in the system, otherwise they are rejected by the spam filter (this works the same as Message Labs or whatever it is called now)
    - each address requires a licensing fee, just perfect when it comes to shared mailboxes and distribution groups /s
    - they don't have a simple way to integrate with O365, their only method is using LDAPS through Azure AD - an extra $8/month per user :o
    - they have an import option using CSV, but of course that is a whole load of manual data entry for the clients on the service
    - the new servers are also hosted in Europe instead of Canada which is fantastic for data governance.

    Luckily I only have a half dozen clients using the service at this time, unluckily, they combine for almost 250+ addresses that will have to be manually reviewed, added to a CSV, then imported into the system.

    iRevert wrote: »
    Because if you're going to attempt to squeeze that big black monster into your slot you will need to be able to take at least 12 inches or else you're going to have a bad time...
    Steam: MyiagrosX27
  • Options
    That_GuyThat_Guy I don't wanna be that guy Registered User regular
    We've been using SpamTitan at our office for the last 10ish years. It works pretty well and has a good web interface.

  • Options
    CogCog What'd you expect? Registered User regular
    The first of the ~250 Macbook transfers started today and it became abundantly clear that we don't have time to both transfer all their shit and rename their accounts when we're hoping to maintain a pace of ~30 devices per day. Looks like renaming accounts will get put off for winter break.

  • Options
    FeldornFeldorn Mediocre Registered User regular
    We went back to IronPort... I mean Cisco Cloud Email Security.

    It's alright, works pretty well. I think licensing is per mailbox so a group wouldn't count but a Shared mailbox probably does.

  • Options
    NosfNosf Registered User regular
    Spamhero atm, seems ok. Doing shared quarantine which is bullshit, but haven't had time to set up individual.

  • Options
    FeralFeral MEMETICHARIZARD interior crocodile alligator ⇔ ǝɹʇɐǝɥʇ ǝᴉʌoɯ ʇǝloɹʌǝɥɔ ɐ ǝʌᴉɹp ᴉRegistered User regular
    I've had good luck with Barracuda's cloud spam filter in the past. Their on-prem appliances were on cheap unreliable hardware but the software was A+.

    Mimecast is good, too.

    every person who doesn't like an acquired taste always seems to think everyone who likes it is faking it. it should be an official fallacy.

    the "no true scotch man" fallacy.
  • Options
    FeralFeral MEMETICHARIZARD interior crocodile alligator ⇔ ǝɹʇɐǝɥʇ ǝᴉʌoɯ ʇǝloɹʌǝɥɔ ɐ ǝʌᴉɹp ᴉRegistered User regular
    Avoid MessageLabs. The service works great but their human tech support is slow and bad.

    every person who doesn't like an acquired taste always seems to think everyone who likes it is faking it. it should be an official fallacy.

    the "no true scotch man" fallacy.
  • Options
    RandomHajileRandomHajile Not actually a Snatcher The New KremlinRegistered User regular
    Feral wrote: »
    I've had good luck with Barracuda's cloud spam filter in the past. Their on-prem appliances were on cheap unreliable hardware but the software was A+.

    Mimecast is good, too.
    We had pretty good luck with the Barracuda on prem hardware but they’re pretty much all virtual now.

    With that being said, we got a FireEye EX a couple years ago as a second layer of protection and that thing is basically magic how it does detonation. (It’s quite expensive though!)

  • Options
    CogCog What'd you expect? Registered User regular
    I fucking hate fumbling my way through SSL certificate/CA shit. Why does this never make sense to me?

  • Options
    RandomHajileRandomHajile Not actually a Snatcher The New KremlinRegistered User regular
    Cog wrote: »
    I fucking hate fumbling my way through SSL certificate/CA shit. Why does this never make sense to me?
    My experience is that you’ll only kinda half understand it after you accidentally set up a CA for your entire domain because you needed a trusted CA for your dumb WiFi, and then five years later you’ll realize that you already have a CA set up for the entire domain, and then get disgusted with yourself and spend a month doing it right, and then another year decommissioning the old one.

  • Options
    LD50LD50 Registered User regular
    And there will be a random service that is mission critical that you didn't know about that used the original CA that breaks horribly when you decom the old one. You spend hours figuring out what the thing that broke actually even is and when you finally update the cert it is using it doesn't work because the original cert is still cached somewhere.

  • Options
    ThawmusThawmus +Jackface Registered User regular
    Feral wrote: »
    Avoid MessageLabs. The service works great but their human tech support is slow and bad.

    MessageLabs was really good way back in the day and then, IIRC, Symantec bought them out, and they became complete shit overnight. (This is from like 10 years ago)

    Twitch: Thawmus83
  • Options
    Dizzy DDizzy D NetherlandsRegistered User regular
    My favourite CA bit is from technet (copied and pasted it back when I replaced the CAs at a customer):
    During the migration procedure, you are asked to turn off your existing CA (either the computer or at least the CA service). You are asked to name the destination CA with the same name that you used for the original CA. The computer name, (hostname or NetBIOS name), does not have to match that of the original CA. However, the destination CA name must match that of the source CA. Further, the destination CA name must not be identical to the destination computer name.

    This is completely correct. It's also written to be nearly incomprehensible if you don't know what they mean.

    Steam/Origin: davydizzy
  • Options
    CogCog What'd you expect? Registered User regular
    Dizzy D wrote: »
    My favourite CA bit is from technet (copied and pasted it back when I replaced the CAs at a customer):
    During the migration procedure, you are asked to turn off your existing CA (either the computer or at least the CA service). You are asked to name the destination CA with the same name that you used for the original CA. The computer name, (hostname or NetBIOS name), does not have to match that of the original CA. However, the destination CA name must match that of the source CA. Further, the destination CA name must not be identical to the destination computer name.

    This is completely correct. It's also written to be nearly incomprehensible if you don't know what they mean.

    Certified insane.

  • Options
    mcpmcp Registered User regular
    Server 2019 has an extremely annoying habit of not applying all the host firewall rules when it reboots.

    A reboot, sometimes two, will fix it.

    It would be really rad if Microsoft would fix that.

  • Options
    wunderbarwunderbar What Have I Done? Registered User regular
    mcp wrote: »
    Server 2019 has an extremely annoying habit of not applying all the host firewall rules when it reboots.

    A reboot, sometimes two, will fix it.

    It would be really rad if Microsoft would fix that.

    If you never reboot your servers, you'll never encounter that!

    XBL: thewunderbar PSN: thewunderbar NNID: thewunderbar Steam: wunderbar87 Twitter: wunderbar
  • Options
    That_GuyThat_Guy I don't wanna be that guy Registered User regular
    mcp wrote: »
    Server 2019 has an extremely annoying habit of not applying all the host firewall rules when it reboots.

    A reboot, sometimes two, will fix it.

    It would be really rad if Microsoft would fix that.

    9c7xqwi819cm.jpg

  • Options
    FeralFeral MEMETICHARIZARD interior crocodile alligator ⇔ ǝɹʇɐǝɥʇ ǝᴉʌoɯ ʇǝloɹʌǝɥɔ ɐ ǝʌᴉɹp ᴉRegistered User regular
    Thawmus wrote: »
    Feral wrote: »
    Avoid MessageLabs. The service works great but their human tech support is slow and bad.

    MessageLabs was really good way back in the day and then, IIRC, Symantec bought them out, and they became complete shit overnight. (This is from like 10 years ago)

    Broadcom owns them now. They still suck.

    every person who doesn't like an acquired taste always seems to think everyone who likes it is faking it. it should be an official fallacy.

    the "no true scotch man" fallacy.
  • Options
    Dizzy DDizzy D NetherlandsRegistered User regular
    Cog wrote: »
    Dizzy D wrote: »
    My favourite CA bit is from technet (copied and pasted it back when I replaced the CAs at a customer):
    During the migration procedure, you are asked to turn off your existing CA (either the computer or at least the CA service). You are asked to name the destination CA with the same name that you used for the original CA. The computer name, (hostname or NetBIOS name), does not have to match that of the original CA. However, the destination CA name must match that of the source CA. Further, the destination CA name must not be identical to the destination computer name.

    This is completely correct. It's also written to be nearly incomprehensible if you don't know what they mean.

    Certified insane.

    Honestly, I'm ok with AD, Exchange and Certificate Authorities. SCCM/MEMCM is the bane of my existence.

    Steam/Origin: davydizzy
  • Options
    wunderbarwunderbar What Have I Done? Registered User regular
    Even a mention of SCCM makes me want to vomit.

    XBL: thewunderbar PSN: thewunderbar NNID: thewunderbar Steam: wunderbar87 Twitter: wunderbar
  • Options
    Bendery It Like BeckhamBendery It Like Beckham Hopeless Registered User regular
    I like sccm, fight me.

  • Options
    wunderbarwunderbar What Have I Done? Registered User regular
    I like sccm, fight me.

    consider yourself fought.

    XBL: thewunderbar PSN: thewunderbar NNID: thewunderbar Steam: wunderbar87 Twitter: wunderbar
  • Options
    FeldornFeldorn Mediocre Registered User regular
    edited August 2021
    I’ve explained certificates quite a few times. PKI doesn’t need to be complicated. It helps if you make the private key exportable so you can migrate off that 32-bit 2008 server.

    SCCM needs a lot of attention… We don’t have to time to take care of it as well as it deserves, but it works alright. That said, it did break spectacularly while initially being built and was scrapped and rebuilt. I think it was a certificate problem…

    Feldorn on
  • Options
    Bendery It Like BeckhamBendery It Like Beckham Hopeless Registered User regular
    I think my enjoyment of sccm is being part of a dedicated sccm team. We do a lot of other shit but we have 4 people working on various aspects.

  • Options
    DarkewolfeDarkewolfe Registered User regular
    SCCM is a great idea and I don't hate what it does but I hate that Microsoft basically invests the bare minimum in it because you're captive anyway. The market of tools that are like SCCM but better is proof it w should get more love from MS.

    What is this I don't even.
  • Options
    SiliconStewSiliconStew Registered User regular
    Darkewolfe wrote: »
    SCCM is a great idea and I don't hate what it does but I hate that Microsoft basically invests the bare minimum in it because you're captive anyway. The market of tools that are like SCCM but better is proof it w should get more love from MS.

    MS's direction seems to focusing on doing all that stuff via cloud with O365/Azure/Endpoint Manager/Autopilot etc. It wouldn't be the first thing they've let languish without development but refuse to officially kill due to enterprise use inertia.

    Just remember that half the people you meet are below average intelligence.
  • Options
    DarkewolfeDarkewolfe Registered User regular
    Darkewolfe wrote: »
    SCCM is a great idea and I don't hate what it does but I hate that Microsoft basically invests the bare minimum in it because you're captive anyway. The market of tools that are like SCCM but better is proof it w should get more love from MS.

    MS's direction seems to focusing on doing all that stuff via cloud with O365/Azure/Endpoint Manager/Autopilot etc. It wouldn't be the first thing they've let languish without development but refuse to officially kill due to enterprise use inertia.

    They never invested in it though. Like everything, they do the bare minimum if you're stuck in their ecosystem.

    What is this I don't even.
  • Options
    electricitylikesmeelectricitylikesme Registered User regular
    SCCM when I encountered it seemed like hot garbage. It sort of kind of sometimes did things you'd want to do.

  • Options
    DarkewolfeDarkewolfe Registered User regular
    Alright someone defend SCOM next.

    What is this I don't even.
  • Options
    SeidkonaSeidkona Had an upgrade Registered User regular
    Darkewolfe wrote: »
    Alright someone defend SCOM next.

    I turning this thread around and we are going home right now.

    Mostly just huntin' monsters.
    XBL:Phenyhelm - 3DS:Phenyhelm
This discussion has been closed.