IT.TheLibrarie.Com Ramblings Of An IT Person

March 2, 2020

Remove Hidden KACE Agent

Filed under: Microsoft,Miscellaneous — bsdman @ 10:19 am

We utilize KACE (SMA K1000) for our helpdesk/ticketing, and inventory management. Part of our deployment packages include the KACE agent – this agent is required to send back data about the system it is installed upon (username, OS specs, hardware specs, etc).

Unfortunately, there are some times that the KACE agent doesn’t play nicely and it needs to be reinstalled. Or, in my case (pun intended), I needed to make a new GM image for deployment and it is recommended to NOT have the KACE agent installed prior to sysprep.

Open an administrator command prompt:

wmic product where "name like %kace%" call uninstall /nointeractive

This will find and remove any “KACE” related software currently residing on your system. You should see the messages “Method execution successful” and “ReturnValue = 0” if this runs successfully.

Note: This does not remove any existing firewall rules or files created outside of the standard install/uninstall configuration.

January 14, 2020

Stuff I Use

Filed under: Miscellaneous — bsdman @ 9:08 pm

After recently chatting with some friends about various technologies I utilize, I figured it would be a good idea to just document all of the various products with a brief overview/review of each.

Networking

Cisco Switching
Cisco Catalyst 3560G 24 port Layer 3 Switch (my old core).
Unifi Switching
I switched (pun intended) to Unifi equipment a while back due to the price, ease of configuration, and the “underdog appeal”.
I have a US-24-250W, and 2x US-8-60W
Unifi Access Points
I’ve used Unifi AP’s ever since my free Meraki bricked itself due to lack of support contracts. Currently using Unifi UAC-AP-PRO’s (quantity 2).
All of the Unifi equipment is controlled by a Cloud Key Gen 2 Plus.
Untangle UTM
I’ve used Untangle over PFSense for a while now. I like the ability to alter everything within PFSense, and the wicked speed of it, but overall the ease-of-setup and the “it just works” of Untangle won me over. Well worth the $50 annual home license fees.
Protectli Firewall J3160 with 4GB RAM, 32GB MSATA.
Although if I had an opportunity to do it again, I’d get the upgraded model instead with its J3160, 8GB RAM, 120GB SSD.
Powerline
After trying 2 different netgear models, trendnet, and 2 different linksys models, I learned of a rather unknown manufacturer called Extollo. I use Powerline LANSocket 1500 for my hard-to-reach-network-places in the house.

Systems

I have too many systems and may eventually list them here. Currently typing on an MacBook Air while watching a movie streamed from my Plex server that’s running on a proxmox hypervisor on a supermicro server. Collectively we have 5 laptops, a gaming desktop, and 4 servers (only 1 is currently powered on to save some money). That plex box also uses a NAS from QNAP TS-228 and nas4free/ubuntu/debian/etc.

Security

I’ve used cameras both as a hobby (home use) as well as at several employers on a professional basis. These include cameras from Axis, HikVision, SuperCircuits, Unifi, Nest, Ring, and Blink.
In the house I have a Nest camera (with no storage plan) and a single Unifi UVC-G3-Micro. Outside I run the Blink XT2’s, a UVC‑G3, and a UVC‑G3‑DOME.
I also use the Nest Protects on each level of the house.

Home Automation

Honeywell Wi-Fi Smart Color Thermostat
Caseta Wireless Lighting Controls
Chamberlain MyQ Garage Door
Alexa – 2 Echo’s, an Echo Dot, and an Echo Show (5″ display)
Wink2
Panicky Solar Motion lights 3 in the backyard for the dog and 1 on the side for the garbage cans.

Power

After a 30+ hour power outage, we decided to get a standby generator. A ton of research later, we got a Kohler 14RESA Generator with service-entrance ATS. I have OnCue monitoring enabled so I can get alerts on the usage.
After a bit of a windfall of stock options, I moved forward with 15x 285w solar panels and an 5000w inverter.
Driving an electric car, we needed to enable some faster-than-120v-charging at home. Enter 50AMP 240v circuit! Ended up getting an GoPlug ESVE Car Charger.
Rechargable batteries from Fuvaly have been pretty awesome in our various remote controls.
We’ve signed up for the hourly pricing from our provider, so I also have a Rainforest EMU 2 to monitor our current power usage.

Telecom and Internet

Wowway
Tmobile
Yealink on voip.ms SIP
Apple

Other

I’m a flashlight collector.
Car, Flashlight, toilets, humidifer, ac/heat, sumppumps zoeller TV, audio equipment, roku

January 29, 2018

Reset WordPress Password

Filed under: Linux,Miscellaneous — bsdman @ 1:55 pm

Taking over the IT department when the previous IT regime had zero plans on how to integrate the series of businesses they had taken over in the past several years makes for some fun times. I have 4 different godaddy accounts, a couple DH accounts, and even one from a German company I had never heard of. And I had to fight, beg, talk, email, reverse engineer, and guess on several logins. Something something “no documentation”.

That being said, I’ve also had the responsibility of migrating and managing some of our wordpress sites and was SOL when it came to logins. Luckily GD, DH, and even the German cpanel host company all allowed for some sort of mysql access – whether that was shell access or phpmyadmin – so I could “easily” reset the credentials.

On Dreamhost using SSH:
mysql -h MYSQL.DOMAINNAME.TLD -u MYDBUSERPASSWORDFROMTHEPANEL -p
Enter your DB User password
show databases;
use DATABASENAMEHERE;
show tables;
Look for one with “users” at the end (eg wp_users)
List the Users Table along with the ID you’ll need later (First Column)
select id, user_login, user_pass from NAMEOFUSERTABLE;
update NAMEOFUSERTABLE set user_pass = MD5('YOURNEWPASSWORDHERE') where ID = NUMBERFOUNDABOVE

Through PHPMYADMIN
Open PHPMyAdmin and click on the WP database
Find the “Users” table (eg wp_users)
Click on Browse
Click on edit by the user for which you desire to change the password
Where it says “user_pass” change the function drop down to MD5 and then type in a plain text password.
Hit save/submit

Unifi Linux and Windows Certificates

Filed under: Linux,Miscellaneous,Networking — bsdman @ 9:49 am

I thought I knew it all about certificates, but then I was humbled once again.

I needed to “secure” an internal linux webserver using our Windows 2016 CA as to remove the “this is an unverified site” messages that liked to pop up when browsing the various sites.

The process I had done in the past was to create the CSR using openssl, then copy the encryption data, open up my trusty http://certserverhere/certsrv/ site and go through the process of making a webserver certificate. Then, when finished, just download the certificate and the CA + chain, import on linux, and profit.

Well, the new versions of the templates (V3 and V4 specifically) no longer allowed the web enrollment using my trusty http://certserverhere/certsrv site. Booo.

I could probably get it to work by just requesting my own certificates using the MMC, but I’m still leaning towards the whole CLI phase of life. I should also note that I find the performance and management of Unifi on Linux to be significantly better and easier than that on Windows. YMMV.

By the way, this is technically how I published a certificate on our Unifi wireless controller. The CA Certificate Authority is a 2016 Windows Server that’s been published in AD. The unifi machine is running Ubuntu 17.10 and unifi version 5.6.29. I also used WinSCP, Putty, and my base machine is Win10 (not super applicable).

SSH to the Unifi Machine
(I did this as root, so add “sudo” before commands if you’re not the root god)
cd /usr/lib/unifi
java -jar lib/ace.jar new_cert unifi.domain.tld CompanyName Town State Country
This creates unifi_certificate.csr.der and unifi_certificate.csr.pem – the DER is encrypted and the PEM is what we need.

Get the PEM over to your CA Server
I just used nano to view all the data and then copy pasted, but feel free to WinSCP it over as well
nano unifi_certificate.csr.pem
Copy this text, then on the CA create a new text file and paste the data there. Save.

Certreq
Open an administrative Command Prompt on your CA server
certreq -submit -attrib "SAN:dns=unifi.yourdomain.tld&dns=unifi" -attrib "CertificateTemplate:WebServer2018" unifi_certificate.csr.pem
By default your Certificate Template will be “WebServer” instead of the one I listed above – I created my own template with the year it’s valid for the sake of record keeping.

Save the Certificate
Assuming the request went through, you’ll be able to name and save your signed certificate. In my case I named it unifi_withSAN.domain.tld.cer. I also navigated to the http://certserverhere/certsrv site and downloaded the CA certificate, Certificate chain, or CRL (I just downloaded the CA Certificate as it’s a single host with no subs).

Copy it back to Unifi
I used WinSCP to copy both the signed certificate as well as the CA Certificate I downloaded back to my /home directory on the Unifi server.

Final Touches
Back on your Unifi SSH session (in the /usr/lib/unifi directory)
java -jar lib/ace.jar import_cert /home/unifi_withSAN.domain.local.cer /home/srv-cert01-ca.cer
Replace srv-cert01-ca with the name of your CA certificate.
If successful, restart the unifi services
service unifi restart

Close your browser and open back up to https://unifi:8443 and no more error!

October 20, 2017

Solarwinds Syslog Database Cleanup

Filed under: Microsoft,Miscellaneous — bsdman @ 2:36 pm

So my last senior systems administrator decided to install solarwinds on a virtual machine as a standalone package (solarwinds, licensing, sql express). He came to me a day or two later saying that he needed to migrate the database from SQL express to our production SQL server as the instance was at the maximum allowed by SQL Express. He said it was eating up almost 20GB of space – which means he filled up the first database and created a secondary and then filled that one up too (SQL Express has a 10GB per database limit).

After being unable to migrate the database from Express to Standard for 2 days, he just starts it over on the production SQL instance. Long story short we were chewing through about 18GB of database disk space every day. The admin had, for some reason, enabled syslog with Debugging on all network equipment. Damn.

So I needed to delete about 180GB worth of syslogs and, knowing my previous experiences between delete and truncate, decided to just drop the entire table:

Truncate all syslog:
Open SQL Studio Manager
Run a new query
Truncate Table Syslog

Delete Old Syslogs:
Open SQL Studio Manager
Delete from Syslog Where datetime <= '4/24/2016'

September 13, 2017

Tmobile Band 12

Filed under: Miscellaneous,Networking — bsdman @ 11:22 am

Tmobile bought up quite a bit of the 700MHz spectrum, but I wanted to see where it was being deployed.

Map of Deployments and other Information
http://maps.spectrumgateway.com/t-mobile-700-mhz-spectrum.html

How to find current band on iPhone
Open the Dialer
*3001#12345#*
Press Dial/Talk
This enables Field Test Mode
Navigate to LTE > Service Cell Info
Where it says Freq_band_ind that’s the band you’re currently utilizing. In my case it’s Band 2

http://www.radio-electronics.com/info/cellulartelecomms/lte-long-term-evolution/lte-frequency-spectrum.php

LTE BAND
NUMBER DOWNLINK UPLINK WIDTH_OF_BAND DUPLEX_SPACING BAND_GAP
1 1920 – 1980 2110 – 2170 60 190 130
2 1850 – 1910 1930 – 1990 60 80 20
3 1710 – 1785 1805 -1880 75 95 20
4 1710 – 1755 2110 – 2155 45 400 355
5 824 – 849 869 – 894 25 45 20
6 830 – 840 875 – 885 10 35 25
7 2500 – 2570 2620 – 2690 70 120 50
8 880 – 915 925 – 960 35 45 10
9 1749.9 – 1784.9 1844.9 – 1879.9 35 95 60
10 1710 – 1770 2110 – 2170 60 400 340
11 1427.9 – 1452.9 1475.9 – 1500.9 20 48 28
12 698 – 716 728 – 746 18 30 12
13 777 – 787 746 – 756 10 -31 41
14 788 – 798 758 – 768 10 -30 40
15 1900 – 1920 2600 – 2620 20 700 680
16 2010 – 2025 2585 – 2600 15 575 560
17 704 – 716 734 – 746 12 30 18
18 815 – 830 860 – 875 15 45 30
19 830 – 845 875 – 890 15 45 30
20 832 – 862 791 – 821 30 -41 71
21 1447.9 – 1462.9 1495.5 – 1510.9 15 48 33
22 3410 – 3500 3510 – 3600 90 100 10
23 2000 – 2020 2180 – 2200 20 180 160
24 1625.5 – 1660.5 1525 – 1559 34 -101.5 135.5
25 1850 – 1915 1930 – 1995 65 80 15
26 814 – 849 859 – 894 30 / 40 10
27 807 – 824 852 – 869 17 45 28
28 703 – 748 758 – 803 45 55 10
29 n/a 717 – 728 11
30 2305 – 2315 2350 – 2360 10 45 35
31 452.5 – 457.5 462.5 – 467.5 5 10 5

March 25, 2017

Updated to HTTPS

Filed under: Miscellaneous — admin @ 1:12 pm

I decided to join the future and encrypt the communications to/from this server. Not that it’s a big deal, but I do like privacy.

If you notice any problems please let me know.

Also, it’s a certificate through Letsencrypt!

Older Posts »

Powered by WordPress