2020 LDAP channel binding and LDAP signing requirement for Windows
This is definitely gonna break some things, but will protect against NTLM relay attacks against LDAP. The problem is many third party software doesn't accept signed plaintext LDAP messages though, so the actual default will end up being LDAP over TLS. Which is another problem...
windows  AD  LDAP  signed  message  channel  binding  sysadmin  tips  tricks  TLS  security 
2 days ago by asteroza
UniFi Cloud Hosting - HostiFi
Free minimal cloud hosting of the Ubiquiti UniFi cloud controller software, if you can't install on a PC and don't want to buy their cloud controller hardware...
Ubiquiti  cloud  controller  hosting  service  wifi  wireless  network  sysadmin  tips  tricks 
24 days ago by asteroza
alex's coding playground » Download
Apparently a proper windows based tool for full image cloning of a USB or SD storage device, useful for backs like for ESXi
USB  SD  card  cloning  backup  tools  utilities  software  sysadmin  tips  tricks  VMware  ESXi 
24 days ago by asteroza
Download Intel® Virtual RAID on CPU (Intel® VROC) and Intel® Rapid Storage Technology Enterprise (Intel® RSTe) Driver for Windows*
Intel VROC F6 driver for installing the driver during Windows 10 installation so it can see a bootable VROC RAID drive
intel  VROC  F6  RAID  driver  windows  10  installation  install  sysadmin  tips  tricks 
24 days ago by asteroza
VMware High Performance Plug-In
VMware ESXi HPP plugin as an alternative for the inbox native NVMe driver for fast single path access to local NVMe storage
VMware  ESXi  NVMe  driver  high  performance  sysadmin  tips  tricks 
26 days ago by asteroza
Solved: Windows 2000 VM on ESXi 6.7 showing 100... |VMware Communities
So, it looks like the consensus is, where possible, use the uniprocessor HAL and a single vCPU with a single core, but if you really need it, switch to the multiprocessor HAL and stay unisocket with multicore. Multisocket seems to be a world of hurt if you have a problematic situation. The problem here is a lot of documentation is spread out and recommending uniprocessor, but what they really mean is single socket.
VMware  ESXi  windows  2000  high  CPU  usage  sysadmin  tips  tricks 
29 days ago by asteroza
Dism | New Windows Utility
Oh wow, apparently can carve away unused SxS asemblies too?
windows  package  management  DISM  GUI  sysadmin  tools  utilities  software  free 
7 weeks ago by asteroza
Deploy Software with PDQ Deploy -
Third party software patching. The free version isn't total garbage
remote  patch  update  install  software  server  installer  windows  sysadmin  tips  tricks 
7 weeks ago by asteroza
"VMware Workstation and Device/Credential Guard are not compatible" error in VMware Workstation on Windows 10 host (2146361)
Because VMware are jerks and still haven't fixed hyper-v VHP support, you have to STILL disable credential guard
VMware  workstation  windows  10  hyper-v  credential  guard  sysadmin  tips  tricks 
8 weeks ago by asteroza
Linux 5.0 compat: SIMD compatibility · zfsonlinux/zfs@e5db313
So the linux kernel effectively outlawed userland FPU (wasn't the kernel NOT supposed to screw up userland?!?), so skeezy bypasses needed. This might kneecap ZFS Send ops...
linux  ZFS  kernel  filesystem  FPU  userland  access  restriction  sysadmin  tips  tricks  reference  information 
8 weeks ago by asteroza
Plan for deploying devices using Discrete Device Assignment | Microsoft Docs
Powershell script to check if a system can do GPU PCIe passthru for Hyper-V VM's. Works better with AMD, Nvidia does their own driver limitation to quadro GPU's
sysadmin  tips  tricks  hypervisor  Hyper-V  test  check  powershell  script  GPU  PCIe  passthru 
9 weeks ago by asteroza
Download Intel® Network Adapter Driver for Windows® 10
Apparently windows 10 VLAN support is half broken again, needs to use powershell to set VLAN's
windows  10  intel  network  card  driver  bug  VLAN  sysadmin  tips  tricks  powershell 
9 weeks ago by asteroza
Fixing Antivirus Errors | Mozilla Security Blog
Not liking this auto-import of OS certificate store CA's becoming the default setting. One of the hallmarks of Firefox has been Mozilla's instance on their own private and controlled cert store. A popup on start showing newly detected OS CA certs that are available for import sounds safer to me...
mozilla  firefox  OS  certificate  store  CA  automatic  import  security  sysadmin  tips  tricks 
10 weeks ago by asteroza
A heavily fragmented file in an NTFS volume may not grow beyond a certain size
Windows has an internal NTFS extent limit of 1.5 million roughly, can extend to 6 million
windows  NTFS  file  extent  limit  sysadmin  tipstricks 
10 weeks ago by asteroza
ReFS integrity streams | Microsoft Docs
So filesystem checksumming, the ostensible reason to even try ReFS, is off by default...
windows  filesystem  ReFS  checksum  integrity  sysadmin  tips  tricks 
10 weeks ago by asteroza
