หน้าเว็บ

แสดงบทความที่มีป้ายกำกับ Windows Server แสดงบทความทั้งหมด
แสดงบทความที่มีป้ายกำกับ Windows Server แสดงบทความทั้งหมด

วันเสาร์ที่ 7 ธันวาคม พ.ศ. 2562

Windows Server 2003 : Windows Server 2003 Update To R2

Windows Server 2003 : Windows Server 2003 Update To R2
DC04 ที่ Copy VMware มาจากเครื่อง Intranet Local Join และ ทำ Domain เสร็จแล้ว แต่ตัว Version ไม่ใช่ Windows Server 2003 R2
ซึ่งต้อง Update ในหนังสือหน้า 23-24
ทำดังนี้
- Backup Snapshots ก่อนทำ
- หาแผ่นที่ใช้ลง ถ้าของแท้ให้เอาแผ่น 2 ใส่ แต่ตัวนี้เป็น skz ให้ mout แผ่น windows server 2003 skz เข้าไปเลย
ในแผ่นจะมี Folder Update R2
พบปัญหาเวลากดที่ Link Update แล้ว Error
Windows 2003 Wizard Another
Application requires a restart of this computer. Before Setup can run, you must restart the computer.
วิธีแก้ต้องลบ registry เข้าไปที่
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
แล้วลบ PendingFileRenameOperations ออก ถึงจะลงได้
- ติดตั้งตามขึ้นตอน เสร็จแล้ว Reboot
จะเป็น Windows Server 2003 R2

- ต้องดู Active Directory schema version ต้องเป็น Version เดียวกัน กับตัว Master
WINDOWS EDITION SCHEMA VERSION
Windows 2000 Server : 13
Windows Server 2003 : 30
Windows Server 2003 R2 : 31
Windows Server 2008 : 44
Windows Server 2008 R2 : 47
Windows Server 2012 : 56
Windows Server 2012 R2 - Preview : 69

โดยใช้คำสั่ง
dsquery * cn=schema,cn=configuration,dc=domain,dc=com -scope base -attr objectVersion"

เปลี่ยนชื่อ Domain และ dc ที่ใช้ จะต้องได้ Version เดียวกัน กับตัว Master

31 เป็นตัว Windows Server 2003 R2 ถ้าไม่ได้เป็นคนตัวตัวต้อง Update Active Directory schema version (ในหนังสือหน้า 24)

https://nolabnoparty.com/en/finding-active-directory-schema-version/

วันพฤหัสบดีที่ 22 สิงหาคม พ.ศ. 2562

การลบ Domain Controller Windows server 2003

การลบ Domain Controller Windows server 2003  กรณีทำผ่าน dcpromo ไม่ได้
1.ntdsutil
2.metada cleanup
3.connections
4.connect to server <servername>
5.quit
6.select operation target
7.list domains
8.select domain <number>
9.list sites
10.select site <number>
11.list servers in site
12.select server <number>
13.quit
14.remove selected server
15.quit
16.quit

จากนั้นลบ Domain Controller ออกจาก Active Directory Sites and Services และ Active Directory Users and Computers

เพิ่มเติม กรณี Server Master เสีย จะใช้ผ่าน GUI ไม่ได้ ERROR

เพิ่มเติม กรณี Server Master เสีย จะใช้ผ่าน GUI ไม่ได้ ERROR
เช่น DC01 เสีย ข้อมูลหายหมด
แก้ Config Server ต่าง ๆ ไปใช้ DC02 แทน
https://intranet.sci.com/blog.php?u=3&b=993

** สำคัญต้องลบ Master ที่เสียทิ้งก่อนไม่อย่างนั้นจะยึด RID ไม่ผ่าน **
ลบ Domain
https://intranet.sci.com/blog.php?u=3&b=67

ต้องยึดโดยใช้คำสั่ง NTDSUTIL
1. Start --> Run --> cmd เข้า Command Prompt
2. พิมพ์ ntdsutil แล้ว Enter
3. พิมพ์ roles แล้ว Enter เพื่อเข้าโหมด fsmo maintenance
4. พิมพ์ connect to server <ชื่อ Server เครื่องที่ยังเปิดอยู่ ที่เราจะยึด roles มาจากเครื่องต้นทาง>
  1. connect to server dc02.sci.com
แล้ว Enter
5. พิมพ์ quit แล้ว Enter
6. พิมพ์ seize <fsmo> master แล้วกด Enter
โดย fsmo เป็นชื่อของ Role ที่ต้องการจะยึด ซึ่งประกอบด้วย RID, Domain Naming , Schema
7. ตอบ Yes
ทำทีละ fsmo ทำต่อกันได้เลย
seize Schema master
seize Domain Naming master
seize RID master

ต้องไม่มี Error fail

Operations Masters ต้องผ่านทั้งหมด RID, PDC, Infrastructiure ต้องผ่าน เป็นชื่อ Server ตัวใหม่ที่ทำขึ้น


8. ทำผ่าน GUI ได้ ได้แก่ PDC Emulator และ Infrastructure Master (ตามข้อ 6. Blog บน)
เสร็จแล้ว Reboot เสร้จขั้นตอนการ ยึด Domain แบบ Command

ในหนังสือหน้า 293

ปัญหาที่พบ
1. proxy ติด ๆ หลุด ๆ ถามและใส่รหัสผ่านเดิม ๆ บ่อยครับ
2. Windows 10 อาการคล้ายหลุด Domain
เข้าเครื่อง datacenter จะถามให้ใส่รหัสผ่าน
เข้าเครื่องอื่น ที่ Join domain shared printer ไม่ได้ทำให้ print ไม่ออก
เข้า เปิด Drawing จาก Axapta ไม่ได้ เพราะยังไม่ได้ใส่รหัสเข้า ที่มี box ขึ้นมาถามก่อน
3. Join domain ใหม่ใช้งานได้ทั้งวันแต่ถ้ามีการ reboot หรือ login ใหม่ก็จะเข้าไม่ได้อีก

แก้ให้ใข้ชั่วคราว

เข้า datacenter หรือ axapta ให้ถามรหัส แล้วใส่รหัส เลือก Remember ไว้ จะได้ใช้ได้ทั้งวันจนกว่าจะ reboot หรือ login ใหม่

วิธีแก้ ต้องทำที่ Domain

https://blogs.msdn.microsoft.com/servergeeks/2014/07/12/dns-records-that-are-required-for-proper-functionality-of-active-directory/

โดยเข้าไปลบค่าที่ DNS ของ Domain

ที่เป็น Server เก่าเช่น server3 server4 DC01 ลบทิ้งให้หมด ไล่ดูทีละ Directory แตกเครื่องหมาย + ออกให้หมด
ลบให้เหลือ เฉพาะ Domain ที่ใช้งานจริง


proxy ติด ๆ หลุด ๆ ถามรหัสบ่อย ๆ ทั้งที่ใช้ตัวเติม
- ตรวจสอบ ไฟล์ hosts ที่ Fix ไว้
- Pi-hole ลอง ping ไป ชื่อ dc ตัวเดิมดูถ้า ping ติดแสดงว่า cash
แก้ hosts แก้ resoft.conf dns ให้ไปใช้ ip fireware เดิมใช้ 127.0.0.1

วันจันทร์ที่ 7 พฤศจิกายน พ.ศ. 2559

Windows 7 login เข้า Samba Server ไม่ได้

Windows 7 login เข้า Samba Server ไม่ได้
วิธีแก้ไขกรณี Win7 login เข้า Samba Server ไม่ได้ โดยถาม password อยู่เรื่อย ๆ

วิธีที่ 1 : ทำที่ Server
1.Run: gpedit.msc
2.Find:
Console Root -> Local Computer Policy -> Computer Configuration -> Windows Settings -> -> Security Settings -> Local Policies ->Security Options
3.When you're there change the following policies
- Microsoft network client: Send unencrypted password to third-party SMB server: Switch it to "Enabled".
- Network security: LAN Manager authentication level: Select the option: Send LM & NTLM - use NTLMv2 session security if negotiated.

วิธีที่ 2 : ทำที่เครื่อง Client
1.ถ้าทำที่ Server แล้ว ที่เครื่อง Client สามารถ run คำสั่ง gpupdate /force หรือ reboot เครื่องได้เลย
2.กรณีต้องการทำเอง Run: secpol.msc แล้วตั้งค่าเหมือนวิธีที่ 1 ดังรูป

http://superuser.com/questions/115337/windows-7-connecting-to-samba-shares

Dataserver : กำหนดสิทธิ์ให้กับ Ubuntu ผ่าน Windows server

Dataserver : กำหนดสิทธิ์ให้กับ Ubuntu ผ่าน Windows server
Dataserver : กำหนดสิทธิ์ให้กับ Ubuntu ผ่าน Windows server กำหนดสิทธิ์แบบพิเศษ ทำผ่าน Windows server
1. RDP ไปที่ Server Domain DC01 หรือ DC02 Log on to a Windows machine, using an account that is a member of the "Domain Admins" group
2. Open the Start Menu, search for "Computer Management" and open the program
3. In the menu bar go to "Action" / "Connect to another computer"
4. Enter the name of the Samba host on which you want to edit the share permissions
5. Navigate to "System Tools" / "Shared Folders" / "Shares" and select the desired share
6.Right-click to the share name and choose "Properties"
7.Go to the "Share Permissions" tab and define who is allowed to connect to the share


** ถ้าทำไม่ได้ต้อง Task Owner สิทธิ์ก่อน เข้าที่ Advanced Tab Owner แล้วคลิกที่ชื่อที่มีสิทธิ์เป็น Admin เช่น it_suwit OK ปิดหน้า Properties แล้วเข้า Properties ใหม่จึงจะมีสิทธิ์กำหนดได้ ซึ่งจะทำให้ Owner ของ Folder นั้นเป็นของ Admin
หรือใช้คำสั่ง ใน Terminal
  1. chown it_suwit:Group /Folder/


8. Subfolders of a share ทำโดยคลิ๊กขวาที่ Folder ที่ Shared คลิกขวาเลือก All Tasks ---> Open แล้วคลิกขวาเลือก Properties แล้วกำหนด Security ถ้าทำไม่ได้ก็ต้อง Task Owner สิทธิ์ก่อน
9. สิทธ์จะมี + ต่อท้าย คือสิทธิ์ special สิทธิ์ที่กำหนดมากว่า chmod ธรรมดา จะเป็น
  1. drwxrws---+

https://wiki.samba.org/index.php/Shares_with_Windows_ACLs

Domain : Domain AC Time Server ไม่ตรง

SCI ใช้ Pfsense เป็น Time Server และใช้ Domain Server เป็นตัว Sync Time สู่เครื่องลูก

1. ดูเครื่องลูก ว่าตอนนี้ Time Server เป็นเครื่องไหน ด้วยคำสั่ง ใน cmd
  1. w32tm /query /peers

ข้อมูลแสดงประมาณนี้
Peer: dc02.SCI.COM
State: Active
Time Remaining: 555.4386918s
Mode: 3 (Client)
Stratum: 4 (secondary reference - syncd by (S)NTP)
PeerPoll Interval: 10 (1024s)
HostPoll Interval: 10 (1024s)

2.ไปดูที่เครื่อง Server เครื่องนั่น
  1. net stop w32time

  1. w32tm /config /manualpeerlist:192.168.0.2 /syncfromflags:MANUAL /reliable:yes /update

  1. net start w32time

  1. w32tm /resync


3. Sync ข้อมูลไปยังเครื่องลูก
Next you need to sync all of your client PC's to the domain controller. You can do the following from the command line.
  1. net stop w32time

  1. w32tm /config /manualpeerlist:peers /syncfromflags:DOMHIER /update

  1. net start w32time

  1. w32tm /resync


http://www.ozzu.com/mswindows-forum/how-configure-ntp-server-windows-2003-server-t91197.html

วันเสาร์ที่ 5 พฤศจิกายน พ.ศ. 2559

Domain : Export ชื่อออกจาก Domain ตาม Group ที่ต้องการ

Domain : Export ชื่อออกจาก Domain ตาม Group ที่ต้องการ
1. ติดตั้งโปรแกรม Softerra LDAP Browser 2.6 ที่ Server \\datacenter\Software\#Freeware\Admin\ldapbrowser26.msi
2. เปิดโปรแกรมแล้ว Connect ไปที่ Domain Server 192.168.0.253 Port 389 ใส่ User Name และ Password ที่มีสิทธิ์เป็น Admin
3. เลือก Group ที่เราต้องการดู แล้วคลิกขวาที่ Group นั้นเลือก Properties ตามรูป เพื่อดู {LDAP Path}

ทำที่เครื่อง Windows Server Domain
4. ใช้คำสั่งใน cmd
  1. csvde -d {LDAP Path} -f c:\filename.csv -u

เช่น
  1. csvde -d "CN=DC-Assembly,OU=DataCenter,OU=SCI,DC=SCI,DC=COM" -f c:\assembly.csv -u

5. ได้ไฟล์ .csv เปิดด้วย Notepad++ จัดข้อมูล เช่น ลบแถวแรกออก Ctrl+H แทนที่ค่าที่เราไม่ต้องการ เหลือเฉพาะชื่อใน Group นั้น ๆ เพื่อนำไปใช้งานต่อ

Domain : กำหนดเกี่ยวกับ Password ของ User

Domain : กำหนดเกี่ยวกับ Password ของ User ใน Domain
Password Policy
- Enforce password history : กำหนดจำนวนครั้งของการเปลี่ยนรหัสผ่าน ก่อนที่จะนำรหัสเก่ามาใช้ ค่าเริ่มต้นจะไม่ยังคับใช้
- Maximum password age : กำหนดอายุสูงสุดของรหัสผ่านที่ใช้งานได้ก่อนที่จะต้องทำการเปลี่ยนรหัสใหม่ค่าเริ่มต้นเป็น 42 วัน
- Minimum password age : กำหนดอายุต่ำสุดของรหัสผ่านก่อนที่จะอนุญาตให้เปลี่ยน ค่าเริ่มต้นจะไม่ยังคับใช้
- Minimum password length : กำหนดความยาวต่ำสุดของรหัสผ่านที่อนุญาตให้ใช้ได้ ค่าเริ่มต้นจะไม่บังคับใช้
- Password must meet complexity requirement : กำหนดให้รหัสผ่านต้องประกอบด้วย อักษรตัวเล็ก (a , b, c, …y, z) อักษรตัวใหญ่ (A, B, C, …Y, Z) อักษรพิเศษ (!, @, # , $, %, ^, &, *, (, ), _,+ และ ตัวเลข (1, 2, 3, ..9, 0) ค่าเริ่มต้นจะไม่บังคับใช้
- Store password using reversible encryption for all user in domain : กำหนดให้เก็บรหัสผ่านที่สามารถถอดรหัสแบบย้อนกับได้ ค่าเริ่มต้นจะไม่บังคับใช้

http://thaiwinadmin.blogspot.com/2008/04/kb2008174.html

Menu สำหรับเข้าตั้งค่า ที่
Start --> Administrative Tools --> Default Domain Security Setting เลือก Account Policies --> Password Policy

Workshop : Windows SERVER2003

Workshop : Windows SERVER2003
1. ติดตั้ง Windows Server2003 ใน VirtualBox
2. เปลี่ยนชื่อเครื่องตามที่เราต้องการก่อน
3. Start > Run... พิมพ์ dcpromo แล้วเลือก OK แล้วทำ Next ตามขั้นตอนไปเรื่อย ๆ ตั้งชื่อ Domain ไม่ให้ซ้ำกับ SCI
ตามรูป
เลือก Next
เลือก Next

เลือก Domain controller for new domain แล้วเลือก Next

เลือก Domain in a new forest แล้วเลือก Next
ใส่ชื่อ Domain (เช่น thaivmadmin.dom) แล้วเลือก Next
ในส่วนของ Domain bios name กำหนดให้เป็น default แล้วเลือก Next
กำหนด Database และ Log โฟล์เดอร์ แล้วเลือก Next
กำหนด SYSVOL โฟล์เดอร์ แล้วเลือก Next
เลือก Permission compatible only with Windows 200 or Windows Server 2003 operating systems แล้วเลือก Next

กำหนด Password เพื่อใช้สำหรับ Restore Mode แล้วเลือก Next

หน้า Summary เลือก Next
ให้รอจนกว่าจะเสร็จ
เมื่อเสร็จแล้ว เลือก Finish
เลือก Restart Now เพื่อ Reboot Server เป็นอันเสร็จขั้นตอนการติดตั้ง

การตรวจสอบความสมบูรณ์ของ Domain Controller

· ตรวจสอบแชร์ไฟล์ โดยใช้ Command "net share" แล้วดูว่ามี แชร์ชื่อ SYSVOL และ NETLOGON
· ตรวจสอบใน Adminitrative Tools ว่ามี AD management tools ติดตั้งอยู่หรือเปล่า
· รัน Active Directory Sites and Services. จะเห็น Default-First-Site-Name และ ในนั้นจะมีชื่อ Server อยู่
· ตรวจสอบ ว่ามี Zone ชื่อของ Domain Name บน DNS

· ตรวจสอบภายใต้ SYSVOL แชร์ว่ามี Subfolder อยู่
4. เสร็จแล้ว Test โดยการ Join domain เข้า ชื่อ Domain ที่เราตั้งแล้วเข้าไปดู DNS ว่ามีเครื่องที่ Join Domain เข้าใช้งานได้หรือปล่าว
- โดย Set Ip ให้อยู่ใน ยานเดียวกัน และ DNS เป็นตัวเดียวกัน กับ SERVER
- ทดลอง Ping หากัน ผ่านชื่อและผ่าน IP ว่าได้หรือปล่าว
- ลอง Join domain ใช้สิทธ์ admin ของ Domain
- ถ้าสำเร็จ ลอง Login โดยเลือก Domain ข้างล่างเป็นชื่อที่เราตั้ง และใส่ ชื่อที่มี ใน Domain เข้าไป ถ้า เข้าได้แสดงว่า ทำ Domain Controller สำเร็จ


http://www.thaiadmin.org/article/setup_domain_controller_on_windows_server_2003_r2.htm

Windows Server 2003 : ย้าย ยึด Domain จากเครื่องหลัก


Windows Server 2003 : ย้าย ยึด Domain จากเครื่องหลัก Transfer and Seize (ในหนังสือ Windows Server 2003 หน้า288-293)
1. ติดตั้ง Windows Server 2003 2 เครื่อง เพื่อทดลอง Set IP ให้เรียบร้อย
2. Set up Domain (DNS ด้วยต้องมีถ้าไม่มีจะ Join Domain ไม่ได้)
*** ถ้าในของจริงให้ทำ DNS เลือกเอามาจากเครื่องอื่น เช่น 192.168.0.252 หรือ 192.168.0.254 ใหม่มีข้อมูล DNS เหมือนกับ Server Master
http://porpramarn.blogspot.com/2016/11/workshop-windows-server2003.html

3. Create an additional domain controller.
3.1. Join Server To Domain Master In Number 2.
3.2. Click Start, click Run, and then type dcpromo /adv to open the Active Directory Installation Wizard with the option to create an additional domain controller from restored backup files.
3.3. On the Operating System Compatibility page, read the information and then click Next.
If this is the first time you have installed Active Directory on a server running Windows Server 2003, click Compatibility Help for more information.
3.4. On the Domain Controller Type page, click Additional domain controller for an existing domain, and then click Next.
3.5. On the Copying Domain Information page, do one of the following:
- Click Over the network, and then click Next.
- Click From these restored backup files, and type the location of the restored backup files, or click Browse to locate the restored files, and then click Next.
3.6. On the Network Credentials page, type the user name, password, and user domain of the user account you want to use for this operation, and then click Next.
The user account must be a member of the Domain Admins group for the target domain.
3.7. On the Database and Log Folders page, type the location in which you want to install the database and log folders, or click Browse to choose a location, and then click Next.
3.8. On the Shared System Volume page, type the location in which you want to install the Sysvol folder, or click Browse to choose a location, and then click Next.
3.9. On the Directory Services Restore Mode Administrator Password page, type and confirm the password that you want to assign to the Administrator account for this server, and then click Next.
Use this password when starting the computer in Directory Services Restore Mode.
3.10. Review the Summary page, and then click Next to begin the installation.
3.11. Restart the computer.
Link : https://technet.microsoft.com/en-us/lib ... 10%29.aspx

สิ่งที่ต้องยึดจาก Domain หลัก
1. Schema Master
2. Domain Naming Master
3. RID Master
4. PDC Emulator
5. Infrastructure Master


4. ที่เครื่อง Additional ย้าย Schema Master
4.1. เปิดหน้าจอ Command Prompt เข้าไปที่ C:\Windows\System32 พิมพ์คำสั่ง regsvr32 schmmgmt.dll แล้ว Enter เพื่อ Register Schmmgmt.dll แล้วกด OK ตามรูป

4.2. Start --> Run แล้วพิมพ์คำสั่ง mmc /a แล้ว enter
4.3. คลิกเมนู File --> Add/Remove Snap-In
4.4. ในหน้า Snap-in ให้ Add Active Directory Schema เข้า Console Root

4.5. เปลี่ยน Domain Schema โดย คลิกขวาที่ Active Directory Schema เลือก Change Domain Controller.. ตามรูป
4.6. ติ๊ก Specify Name : แล้วใส่ชื่อเครื่องใหม่ที่จะทำเป็น Domain Controller แล้วกด OK

4.7. คลิกขวาที่ Active Directory Schema เลือก Opertion Master... แล้วกด Change กด Yes แล้วกด OK


5. ที่เครื่อง Additional Domain Naming Master
เข้าเปิดโปรแกรม Active Directory Domains and Trusts ที่ Administrative Tools
5.1. คลิกขวาที่ Active Directory Domains and Trusts เลือก Connect to Domain Controller... ตามรูป


5.2. เลือก Domain ที่จะทำเป็น Master แล้วกด OK

5.3. คลิกขวาที่ Active Directory Domains and Trusts เลือก Operation Master ...

5.4. กด Change

5.5. กด Yes แล้วกด OK ตามลำดับ

6. ย้าย RID Master, PDC Emulator และ Infrastructure Master
เข้าเปิดโปรแกรม Active Directory Users and Computers (ADUC) ที่ Administrative Tools
6.1. คลิกขวาที่ ADUC เลือก Connet to Domain Controller...

6.2. เลือก Server ที่จะทำเป็น Domain Master

6.3. คลิกขวาที่ ADUC เลือก All Tasks เลือก Operations Master...


6.4. ที่ Tab RID, RDC, Infrastructure ทำเหมือนกันทั้ง 3 Tab กด Change กด Yes แล้วกด OK ตามลำดับ




จบขั้นตอนการยึด Domain ตรวจสอบ ว่า Computer , User , Group ต่าง ๆ ที่เคยมีใน Domain Master ใน Active Directory ย้ายมาที่ Domain ใหม่หรือไม่ต้องมีข้อมูลเหมือนกับ Server เดิม ทดลอง Login เครื่อง ที่ Join Domain ไว้ใน Domain Master เก่า ต้อง Login ได้

วันเสาร์ที่ 23 กรกฎาคม พ.ศ. 2559

Windows Server 2003: Group Policy Auto Set Proxy.

Windows Server 2003 : Group Policy Auto Set Proxy.
1. Remote to Server domain example Server4
2. Oprogram Group Policy Management by enter to Start ---> AdministrativeTools --> Group Policy Management
Expand by step Forest : SCI.COM ---> Domains ---> SCI.COM --> Group Policy Objects ---> Default Domain Policy see image

3. Click right in Default Domain Policy select Edit follow image

4. Enter to User Configuration ---> Windows Settings ---> Internet Explore Main ---> Connection Expand follow step see image.

5. Click right in Proxy Settings and select Properties follow image.

6. Set Proxy and Exceptions by you want. example see image.


**Wanning : After set auto proxy in step finish. On machine client not update now you mush logoff computer or reboot machine client.