Wednesday, July 12, 2017

What to do if the HomePlug has been reset (CURB)

    NOTES

    The HomePlug device is a TP-Link AV500 Nano Powerline Adapter (TL-PA4010).
    These instructions were written for a TP-Link AV500 Nano Powerline Adapter (TL-PA4010) configured through the TP-Link Powerline Communication (PLC) Utility version 2.2.2660.4.

    IMPORTANT Secure Powerline Network name MUST match Basic setting device name. Once this is done, the Home LED will light up.

    If the HomePlug has been reset:

    1. Download and install the HomePlug utility at: http://www.tp-link.com/en/download/TL-PA4010.html#Utility
      NOTE There will be different links for different operating systems.
    2. Plug the HomePlug into the designated power outlet.
    3. Connect the RJ45 connector of the HomePlug to the local area network (LAN) using an ethernet cable.
    4. Open the HomePlug utility.
    5. In the left pane, click Secure.
    1. On the Secure Powerline Network screen,
      1. For Enter a new powerline network name, enter: CurbPowerHub 
      2. Click Save
    1. In the right pane, hover over the HomePlug device for the side options to become available.
    2. Choose Basic (the single gear icon)
    1. In the left pane, click on Rename.
    2. For Enter a new device name, enter: CurbPowerHub
       

    NOTES
    (1) It is possible that for a few early versions, the device name could be: CurbPower Hub, but most will be CurbPowerHub(2) The values are case sensitive.

Thursday, January 5, 2017

We couldn't get your latest saved data

Issue

We couldn't get your latest saved data

Cause

Unknown

Root Cause

Unknown

Scope

Microsoft Xbox

Workaround
  1. Scroll left on the Home screen to open the guide.
  2. Select Settings.
  3. Select All Settings.
  4. Select Network.
  5. Select Network settings
  6. Select Go offline.
  7. Scroll left on the Home screen to open the guide.
  8. Select Settings.
  9. Select Restart console.
  10. Select Yes to confirm.
  11. Sign out of any profiles (if instant sign-in is on)
  12. Scroll left on the Home screen to open the guide.
  13. Select Settings.
  14. Select All Settings.
  15. Select Network.
  16. Select Network settings
  17. Select Go online.
  18. Open a game and let it request and complete the profile login
Resolution

None

Reference

Xbox couldn't get your latest saved date?
http://www.xboxoneforums.net/forum/5-xbox-one-chat/10836-xbox-couldn-t-get-your-latest-saved-date.html#post81352

More Information

Some online forums suggest that this is caused by corruption after an update is installed.


Thursday, November 3, 2016

Nest Cam Outdoor video is stuck loading with a spinning circle.

Issue

Nest Cam Outdoor video is stuck loading with a spinning circle.

Cause

Network ports required to stream video from Nest to the playback device are not open on the firewall.

Root Cause

Unknown

Scope

Nest Cam Outdoor

Workaround

None

Resolution

Open network ports on the firewall that are required to stream video from Nest to the playback device.

More Information

Method
Firewall Port Requirement
Web Browser (home.nest.com)
Any Source IP, Any Source Port to AWS, 1935/tcp
Android App (Nest)
Any Source IP, Any Source Port to AWS, 1443/tcp
AWS = Amazon Web Service

Saturday, August 16, 2014

Adobe ARM - Time elapsed is less than time limit - returning 0

Issue


The AdobeARM.log file contains similar entries:

[YYYY-MM-DD HH:MM:SS] IsTimeElapsed...
[YYYY-MM-DD HH:MM:SS] Minutes elapsed: MMM
[YYYY-MM-DD HH:MM:SS] Time elapsed is less than time limit - returning 0

Cause


By default, the Updater performs an update check every 3 days. The Updater adds the update check interval (3 days) to the value of tLasT_Acrobat. If the current date/time is less than this value, the Updater will exit without checking for updates and log the message.

Solution


Removing the tLastT_Acrobat entry will allow the Updater to perform the check.

Run the following via a Command Prompt.

REG DELETE "HKEY_USERS\.DEFAULT\Software\Adobe\Adobe ARM\1.0\ARM" /V "tLastT_Acrobat" /F

Tuesday, May 27, 2014

UAC, Administrators and Logon Scripts...

Logon script implementations prior to User Account Control (UAC) were fairly simple. Apply a logon script to user and the script did what it was supposed to. Post-UAC is a much different experience. There are things to take into account that, hopefully, this post will help explain.

Logon scripts can be applied to user accounts using
  • The Active Directory Logon script defined in the user account properties
    NOTE: Only one can be specified. Therefore, it would need to call others.
  •  A GPO Logon script

When a user is not part of the local Administrators group, scripts execute under the standard user access token. But when the user is part of the local Administrators group, scripts execute differently.

In the following scenarios, two logon scripts were applied at each login. Either both batch (CMD) or both VBScript (VBS).

Red = Bad, Yellow = OK, Green = Good

In conclusion, we found that using the Active Directory Logon script defined in the user account properties in conjunction with a VBScript file provided the most reliable results. This provided accurate drive mappings for the standard user account and no drive mapping for the administrative user account (or elevation). Conversely, the use of a batch file did allow accurate drive mappings for the standard user account, it also provided unavailable drive mappings to the administrative user account.

NOTE: This post does not apply to mapping drives using Group Policy Preferences.

Monday, May 26, 2014

Oracle Java Deployment Rule Set still broken

When Oracle began building in stronger security measures in their Java products in December 2012 with version 7 Update 10, IT departments discovered that the product could no longer work correctly. End users found that the product could no longer access Java applets or applications without error messages being presented. Enterprises found that the additional security did not include measures to bypass it, even for their own internally owned sites.

In September of 2013, Oracle released Deployment Rule Set (DRS) with Java 7 Update 40. DRS introduced the use of an XML file that allowed for defining a site and whether it was allowed to run. An extension to allowing the site to run, the XML could also define which version of Java to run the site with.

These versions do not support the feature to use a specific version of Java for a specified site.

Java 7 ReleasesRelease Date
Java 7 Update 60 Limited UpdateMay 28, 2014
Java 7 Update 55 CPUApril 15, 2014
Java 7 Update 51 CPUJanuary 14, 2014
Java 7 Update 45 CPUOctober 15, 2013
Java 7 Update 40 Limited UpdateSeptember 10, 2013

If you've been stressing-out attempting to get this functionality working, waiting until a version that works is released would alleviate that stress.

REFERENCE

Deployment Rule Set
http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/security/deployment_rules.html

Monday, May 12, 2014

The cache disk on a Citrix PVS target fills and a server that is attached to it crashes.

Symptoms

Above normal CPU utilitization by the DAgentUI.exe process(es).
The per-user log, DAgentUI{USERNAME}{PID}.log, contains the following entries, repeatedly:

[MM/DD/YYYY hh:mm:s.ms TID #] DAgentProxy.cpp:518 CDAgentProxy::WaitForDAgentService() Waiting 15000 ms for DAgent service
[MM/DD/YYYY hh:mm:s.ms TID #] DAgentProxy.cpp:546 CDAgentProxy::WaitForDAgentService() Wait returned - -1
[MM/DD/YYYY hh:mm:s.ms TID #] DAgentProxy.cpp:362 CDAgentProxy::WaitForDAgentData() entered
[MM/DD/YYYY hh:mm:s.ms TID #] HideTrayIconThread.cpp:37 CHideTrayIconThread::HideClientTrayIcon() entered
[MM/DD/YYYY hh:mm:s.ms TID #] HideTrayIconThread.cpp:51 Destroying tray icon

Cause

The Altiris Deployment Agent service is not running or has been disabled. This causes the per-user log to fill with events and subsequently fill the cache disk. 

Solution

If the service MUST be disabled, delete the DAgentUI registry value in the registry that starts the per-user process (DAgentUI.exe).

Otherwise, start the Altiris Deployment Agent service.

Tuesday, December 3, 2013

When multiple versions of Java are installed, what version wins?

The flow is, latest version > 64-bit > 32-bitWhile the flow is understandable, different flows are used and present the following experiences.

Java Web Start


The installer registers the JNLP file association. This is a per-system registration and does not have corresponding 32-bit/64-bit entries.

A problem arises when both 32-bit and 64-bit of the same version are installed. The 64-bit version is registered and causes calls that require the 32-bit version to fail. For example, opening a JNLP file within the 32-bit version of Internet Explorer.

Control Panel


The installer uses the same GUID for Java 1.5, 1.6, 1.6 (x64), 1.7 and 1.7 (x64) when registering the Control Panel applet. This GUID is placed in both the 32-bit and 64-bit sections of the registry. When both 32-bit and 64-bit versions are installed, Windows uses the 64-bit registry section entry and discards the 32-bit section entry.

A problem arises when both 32-bit and 64-bit of the same version are installed. The the 64-bit version is available in the Control Panel allowing 64-bit versions to be managed. Conversely, the 32-bit version is not available in the Control Panel which does not allow 32-bit versions to be managed. For example, when using the 32-bit version of Internet Explorer users can manage which versions are available. This cannot be done if the user cannot manage the 32-bit versions.

Saturday, November 23, 2013

Windows 8 0xC0000001

Error 0xC0000001 was encountered when a Windows 8 system was booted from a drive image that was restored using Active@ Disk Image. The drive utilized Unified Extensible Firmware Interface (UEFI) and a GUID Partition Table (GPT).

Booting the system using Microsoft Diagnostic and Repair Tool (DaRT) and enumerating the Boot Configuration Data (BCD) showed that both the device and osdevice settings on the {default} entry were unknown.

To resolve this issue, the following was done:
  1. Locate the partition drive letter for the drive containing the OS. (In this instance, drive C.)
  2. Set device setting on the {default} entry to Partition={DriveLetter}:. (in this instance, Partition=C:)
  3. Set osdevice setting on the {default} entry to Partition={DriveLetter}:. (in this instance, Partition=C:)
GUID
Globally Unique Identifier
0xC0000001
STATUS_UNSUCCESSFUL
{Operation Failed} The requested operation was unsuccessful.

Symantec Management Platform Agent and Package Server Vulnerability

The Symantec Management Platform Symantec Management Agent and/or Package Server Agent Disk Space Check and Drive Overflow features can potentially cause the space of it's system drive to be fully consumed. When this occurs, no additional data can be written to the drive, such as security patches or antivirus definitions.

As an example, a system where the Package Server Agent is installed on drive D. The Package Server was assigned more packages than the D drive had space for. The only drive with enough space for the download was the system drive, drive C. This drive was promptly consumed of drive space. After this it was noticed that antivirus definitions for Thursday, November 21, 2013 are for Wednesday, November 20, 2013 r25, but a system having this issue is nearly a month old.


Drive Space Check will check whether there is free space available on the drive containing the Package Server Agent installation. The amount of free space on a drive must be, at least, the value of the Min Disk Free Space (Mbytes) registry key in addition to 120% of the download size. If there is enough drive space, it will download it to this drive. If there is not enough drive space, the Drive Overflow feature is implemented.

Drive Overflow will check whether a drive, other than the drive containing the Package Server Agent installation, has available disk space for the download. If space is available on the drive, a folder will be created using the Package Server Agent installation path, replacing the drive letter with the drive letter of the using a path as the  has the space and download there, if no other drive has this space then it will not download the package.

Thursday, November 14, 2013

Silent Upgrade with In-Use Files Leaves Java Uninstalled (In-Progress)

This has been submitted to Oracle and entered as a bug into their bug tracking system under Bug Id: 9009448. This bug is not publicly available.

This issue is active. This page may be updated with additional information as it becomes available.

This issue was experienced when:
  • Java 7 Update 11 to Java 7 Update 25 Upgrade on Windows x64
  • Java 7 Update 25 to Java 7 Update 45 Upgrade on Windows x64
  • Java 7 Update 45 to Java 7 Update 51 Upgrade on Windows x64
    This document focuses on the Java 7 Update 25 to Java 7 Update 45 Upgrade on Windows x64.

Issue

When Java is upgraded using the silent switch (/s) with the installer executable and Java files are in-use, the following is experienced:
  • Java web sites and applets no longer work
  • Java version verification site showed no version installed
  • The previous version of Java was partially uninstalled from the file system
  • The previous version of Java was removed from Programs and Features (aka Add/Remove Programs)
  • The new version of Java was not installed on the file system
    * Java 7 Update 51: Files were installed in the Program Files folder, but missing from SysWOW64
  • The new version of Java was added to Programs and Features (aka Add/Remove Programs)
  • Java Control Panel applet is missing

What does this mean?

Most companies inventory a system using Programs and Features (aka Add/Remove Program) data. Moreover, most companies use patch software that detects installed versions that require patching. Both of these processes break when Java's installer causes this issue. The program shows as installed when the product is definitely not which will throw off installed totals, etc. Patching solutions will show the system as not requiring a patch or as even having the software.

Cause

The versions of Java were not packaged correctly to work when installations are performed silently. They neither take advantage of Windows Installer functionality nor address errors encountered. When an in-use file is encountered, the installation silently continues instead of rolling back.

This is different from installations that are not silent; during those installations the user is prompted to close the programs identified as having files in-use.

Additional Information

The executable is a wrapper that extracts a Windows Installer package. The Windows Installer package does not install the software, but instead places the installation files on the file system and runs Custom Actions to install Java.

When installing software on a given platform, a company must hire persons with the skill set to properly package software using technologies for that platform; in this case Windows Installer.

This issue is different, almost the exact opposite, of that described in JDK-7042296 : Silent Installations Break Java Installation, http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=7042296, that was opened on 05/05/2011 and still has the status of Open and is Unresolved. This shows how much the vendor cares about their product and the persons/companies using it.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\JavaSoft is populated with Java 7 Update 45 data.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall is populated with Java 7 Update 45 data.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations is populated with Java 7 Update 45 data. This makes it impossible to install Java until the system is rebooted or the data for the value is modified to remove Java-specific entries.

Neither a repair nor an installation over the currently broken version can be performed. A full uninstall/install will be required.

Steps to Reproduce

Note: Java 7 Update 25 / Java 7 Update 45
  1. Install Java 7 Update 25
    (jre-7u25-windows-i586.exe /s /norestart /L %windir%\system32\LogFiles\jre-7u25-windows-i586_inst.log)
  2. Verify the installed Java web browser version
    1. Open https://www.java.com/en/download/installed.jsp?detect=jre
    2. Click Run when asked "Do you want to run this application?"
      Do not check the checkbox to "not show again"
    3. Version shows as Java 7 Update 25
    4. Close the web page.
  3. Verify the installed Java system version
    1. Open Java Control Panel (32-bit)
      (
      "%ProgramFiles% (x86)\Java\jre7\bin\javacpl.exe")
    2. Select the Java tab
    3. Select the User tab; version is 1.7.0_25
    4. Select the System tab; version is 1.7.0_25
    5. Close Java Conrol Panel (32-bit)
  4. Verify the installed Java executables
    1. Open a Command Prompt
    2. Type: DIR %WINDIR%\SysWOW64\java*
    3. Returns a list of Java executables
    4. Close Command Prompt
  5. Verify the installed Java in Programs and Features
    1. Open/Refresh Programs and Features in Control Panel
    2. Java 7 Update 25 is shown
    3. Close Programs and Features
  6. Verify the installed Java web browser version
    1. Open https://www.java.com/en/download/installed.jsp?detect=jre
    2. Do nothing when asked "Do you want to run this application?"
  7. Install Java 7 Update 45
    (
    jre-7u45-windows-i586.exe /s /norestart /L %windir%\system32\LogFiles\jre-7u45-windows-i586_inst.log)
  8. Review the installation log.
    (%windir%\system32\LogFiles\jre-7u45-windows-i586_inst.log)
    1. The log showed 1603 errors
      1. Must reboot to complete operation.
      2. Close that application and retry.
    2. The log showed the installation was successful.
      1. Windows Installer installed the product. Product Name: Java 7 Update 45. Product Version: 7.0.450. Product Language: 1033. Manufacturer: Oracle. Installation success or error status: 0.
  9. Close the web browser.
  10. Verify the installed Java web browser version
    1. Open https://www.java.com/en/download/installed.jsp?detect=jre
    2. Click Run when asked "Do you want to run this application?"
      Do not check the checkbox to "not show again"
    3. Version check errors
    4. Close the web page.
  11. Verify the installed Java system version
    1. Open Java Control Panel (32-bit)
      (
      "%ProgramFiles% (x86)\Java\jre7\bin\javacpl.exe")
    2. Select the Java tab
    3. Select the User tab; version is 1.7.0_25
    4. Select the System tab; version is 1.7.0_25
    5. Close Java Conrol Panel (32-bit)
  12. Verify the installed Java executables
    1. Open a Command Prompt
    2. Type: DIR %WINDIR%\SysWOW64\java*
    3. Returns File not found
    4. Close Command Prompt
  13. Verify the installed Java in Programs and Features
    1. Open/Refresh Programs and Features in Control Panel
    2. Java 7 Update 45 is shown
    3. Close Programs and Features

Thursday, August 1, 2013

Disabling IPv6 causes 389/UDP to fail on domain controllers

Issue

When querying UDP port 389 locally on, or remotely to, a domain controller it fails with "LDAP query to port 389 failed Server did not respond to LDAP query"

Cause

One or more IPv6 components were disabled.


On the domain controller used in this example, the following command was used to disable IPv6:


The following commands will also cause this failure:



The following spreadsheet shows a breakdown of how the DisableComponents registry value affects 389/udp.


Resolution

Use any or all of the following commands to re-enable IPv6.

NOTE A reboot of the system is required when disabling or enabling IPv6 components.

Result

After re-enabling IPv6, querying 389/UDP completes successfully.


Conclusion

An environment that utilizes IPv4 and wishes to remove complexity by removing IPv6 may be surprised to find that its not so easily removed. Microsoft's Article, How to disable IP version 6 or its specific components in Windows, explains that the DisabledComponents registry key method is the correct way to disable IPv6. This article also states, "We do not recommend disabling IPv6. However, if you must disable IPv6 or components of IPv6, follow the steps in this article." Unfortunately, disabling IPv6 causes this known failure and may cause other unknown failures.

Friday, January 25, 2013


The Problem

iMessage is a feature for messaging between iOS devices. A problem arises when a user switches to another operating system, such as Google Android, but keeps the same phone number.

An Example

Kate and Henry both have iPhones and both of them use iMessage. Kate decides to trade-in her iPhone for a Samsung Galaxy. That night, Henry texts Kate some information. (Seems simple enough)

Neither Kate nor Henry are aware there is an issue. To Henry, the text went through because iMessage said it did. Kate never got the message because iMessage doesn't work with non-iOS devices.

How to disable iMessage for a device that is no longer needed
  1. Go to https://supportprofile.apple.com
  2. Sign in with the Apple ID the device was registered under.

  3. Click on Edit Products
  4. Click on the X to the right of the device.

  5. Click Unregister


Saturday, November 17, 2012

"This webpage has a redirect loop."

Using Google Chrome.

Gibson Research Corporation Cookie Forensics states to disable 3rd party cookies.

After disabling 3rd party cookies, entering credentials into accounts.google.com reloads the page allowing for the credentials to be entered again. Odd, but after this second time, the page loads correctly.

Attempts to correct #1

ACTION

In Settings, Show advanced settings..., Content Settings (under Privacy), Manage Exceptions (under Cookies); Add the following:

Hostname pattern: [*.]accounts.google.com
Behavior: Allow

RESULT

The address bar began a noticeable loop, finally ending with a message stating "This webpage has a redirect loop."
Attempts to correct #2

ACTION

In Settings, Show advanced settings..., Content Settings (under Privacy), Manage Exceptions (under Cookies); Modify the following:

Hostname pattern (Existing): [*.]accounts.google.com
Hostname pattern (Change to): [*.]google.com
Behavior: Allow

RESULT

The web page loaded successfully with only one login attempt.

CONCLUSION

When 3rd party cookies are disabled, websites may fail to load. In the case of Google, 3rd party cookies are used (and my guess, heavily) throughout their sites. Because of this, when 3rd party cookies are disable, their pages do not load. Initially, the issue appears to be with just the accounts.google.com site. When the accounts.google.com sites are allowed and the page starts looping, it happens so fast that the other google.com sites are unknown. Adding all google.com sites resolves the issue.

MORE INFORMATION

After making these changes, the page will load but additional blocking may show in the address bar. This could be due to Google's acquisition of YouTube. To correct for this, add the following:

Hostname pattern: [*.]youtube.com
Behavior: Allow

Wednesday, October 3, 2012

Logitech TV Cam HD (PN 960-000921)

After spending some time at Best Buy today, I thought I would create this page so that others would know the specifications for the Logitech TV Cam HD.

Skype Options

Calling

  • Skype-to-Skype
  • Phones and mobiles1
  • Conference Calls
  • Voicemail (aka Voice Messaging)
  • Caller ID
  • Call Forwarding
  • Call Transfer

Video

  • Video calling
  • Group video calling
  • Screen Sharing

Messaging

  • Instant Messaging
  • Send Files
  • Text Messaging
  • Facebook News Feed
  • SMS

Other

  • Skype WiFi
  • Online Number
  • Skype To Go

Logitech Device Options

  • Skype app built-in *
  • Skype Certified
  • HDMI connection to TV
  • Widescreen HD 720p video **
  • Wi-Fi (802.11 g/n) or Ethernet connection
  • Built-in ringer (rings if TV is on or off)
  • Carl Zeiss optics
  • Logitech Fluid Crystal™ Technology
  • Digital zoom, pan & tilt
  • 4 noise cancelling microphones
  • No computer required
  • Width: 9-19/32"
  • Depth: 2-51/64"
  • Height: 2-5/64"

1 Requires Skype Credit or a subscription.

The version of Skype included does not support group calling.
** 1 1.2 Mbps upload/download for 720p video calling.

Monday, September 17, 2012

Windows 64-bit uses MSHTA.EXE 32-bit

By default, Windows 2008 R2 uses the 32-bit version of MSHTA.EXE even if the parent process is 64-bit, such as double-clicking an HTA from the Explorer process. This is due to the htafile association pointing to the 32-bit version.


While it seems that this should be corrected by updating the registry with the 64-bit path, there are sites on the Internet the state this might not be a good idea; though no reason was given. A quick guess is that the server-based HTA's used for server configuration may break.

An issue that was encountered due to this configuration is the calling of 32-bit programs when only the 64-bit version actually works.

For example, calling the NBTSTAT.EXE command from a 32-bit Command Prompt will result in the following error:


'nbtstat' is not recognized as an internal or external command, operable program or batch file.

The same error is encountered when using WScript.Shell.Exec to call NBTSTAT.EXE from a 32-bit MSHTA.EXE on a 64-bit operating system.

As a workaround, call the 64-bit/32-bit version directly by using a CMD or BAT file that uses a similar command (this command will call the 32-bit version on a 32-bit OS and the 64-bit version on a 64-bit OS):

START %windir%\system32\mshta.exe "<PathToHTA>"

Thursday, May 10, 2012

Package Servers are not able to download Symantec Deployment Solution 7.1 packages

Issue

Package servers show a number of invalid packages when the packages are valid.

Cause

The manually defined Package Destination Location (\\%COMPUTERNAME%\Deployment\...), does not exist because the Task Server role has not been assigned to the Package Server.

NOTE: The manually defined Package Destination Location was set by Symantec.

Workarounds

  • Assign the Task Server role to the Package Server. (Preferred)
  • Remove the manually defined Package Destination Location. This may cause issues with Symantec Deployment Solution, but will allow the package to download to the Package Server.
  • Create the share on the Package Server using a similar command line:

More Information

A review of the Symantec Management Platform, Site Servers page shows that one or more Package Servers have invalid packages.






A review of the Symantec Management Agent, Package Server tab shows that the packages are related to Symantec Deployment Solution.


A review of the package on the Symantec Management Platform server shows that the package is set to download to All Package Servers, but to a manually defined Package Destination Location.


The manually defined Package Destination Location is associated with Task Server.

Thursday, April 12, 2012

Where Symantec Management Platform Will Fail Your Company

The short...

Fixes for versions of Symantec Management Platform are not provided; Instead their solution is either to uninstall and re-install the current version or upgrade to a newer version.

The not-so short...

Symantec (formerly Altiris) produces a software product called Symantec Management Platform (formerly Altiris Notification Server). This product has been around for many years and has many excellent features such as inventory, reporting and software delivery (including patches). The use of this product in any environment is a valuable asset.

Once this product is installed and collecting data, the potential for problems increases. This may be exampled by having a slow web-based console or the inability to manage data within pages in the console (such as workstations, servers or patches). In my experience, this is mostly due to poor management of the data entering and leaving their SQL database.

When contacting Symantec support, the most common answer provided is either to uninstall and reinstall the product (if an upgrade is not available) or upgrade to the latest version (if an upgrade is available). The problem with this is that both options have the potential to, and have been known to, revert user-specified options back to default.

To have agents rolling out or policy schedules change after an uninstall/re-install is frustrating to say the least. And this is only for items a customer can see changed.
Upgrading to a newer version is more involved than fixing the current version. Every upgrade requires a push of new agents, policies, etc. This requires time to plan and implement which is not realistic when the customer only wants to fix a current version issue.

An example...

A customer calls Symantec support after having Symantec Management Platform 7.1 SP1 installed and running for over 9 months. They are complaining of slowness in the console and are unable to download patch data.

After hours of troubleshooting the issue, the Symantec support technician suggests repairing the current installation.

The repair fails with Symantec Installation Manager stating it cannot repair Symantec Management Platform 7.1 SP1 because it could not install Symantec Management Platform 7.1 SP2.

What started as a repair of the current version progressed into an upgrade without understanding or notification from Symantec support. What state would the environment been in if it had succeeded?!

Conclusion

Symantec support is a great resource for discovering what is causing issues with the product. The problem arises when support is unable to determine the cause. It seems they default to the standard "Reboot, rinse and repeat" method; This is great for simple issues, but this product is anything but simple and requires more attention to detail.

The idea that any vendor considers either an uninstall and re-install of the current version or upgrade to a newer version as a way to fix a version is unacceptable.

A good company should want to partner with the customer to fix the issue; Not just because the customer requires the product to be working, but also because the company should want the same for all of their customers. They would be able to create a fix that could be provided to other customers experiencing the same issue. And possibly, if necessary, include the same fix in the newer version.

Monday, February 6, 2012

Removing Items from Apple Software Update

A challenge of Apple Software Update is that it attempts to install Updates and New Software that may not wanted by the end user or company. The following are instructions on a way to remove items from the list.

This article applies to Apple Software Update 2.1.3 for Windows, but may apply to other versions.


When Apple Software Update is executed, a window similar to the one below is shown.



Ignoring Update Manually

  1. Open Apple Software Update
  2. Select the Update or New Software item(s)
  3. Select the Tools menu item
  4. Select Ignore Selected Updates

Ignoring Update via Automation


Ignoring updates can be implemented using different methods, such a Group Policy Preference or logon script. Visibility of items in the Updates and New Software lists above is controlled by entering update keys into a registry key in the current user registry hive. Update keys for an Update or New Software can be found by viewing an Apple Software Update catalog.

Apple Software Update catalog for Mac URL
http://swscan.apple.com/content/catalogs/index.sucatalog

Apple Software Update catalog for Windows URL
http://swscan.apple.com/content/catalogs/others/index-windows-1.sucatalog

NOTE: These links only contain current update keys.

To export a full list of update keys using PowerShell (to block all updates) (Windows)
  1. Download the sucatalog
  2. In PowerShell, run the following:

    NOTE: The list of update keys will be in the clipboard.
This is what the Safari 5 item looks like in the index-windows-1.sucatalog; showing update key (041-3083) and MSI (Safari.msi).

These update keys can be entered into the following registry key:

Key: HKEY_CURRENT_USER\SOFTWARE\Apple Inc.\Apple Software Update
ValueType: REG_MULTI_SZ
Value: Update_Ignore_List
Data: <AppleSoftwareUpdateKeys>

NOTE: This key cannot be transposed to a per-system entry in HKEY_LOCAL_MACHINE.

Update keys can be entered manually into the registry or via a form of automation, such as the following:

Once the registry value is present and Apple Software Update is executed, a window similar to the one below is shown: