Monday, August 17, 2020

Certificate Signing Request (CSR) through Microsoft Management Console

 

Wednesday, August 5, 2020

How to enable e-mail as a two-factor authentication for a user and increase token timeout on FortiGate

I would say absolutely that FortiToken (be it a mobile app or a physical token) is the most secure and preferable way today for multi-factor authentication. The other two - SMS message and e-mail message are vulnerable to many attacks, including not so technically sophisticated SMS swapping. But sometimes a less secure method is better than none. Two catches with using an e-mail as MFA on Fortigate though:

  • It is not available in the GUI until you turn it on at the CLI.

 



  • e-mails tend to get delayed sometimes, and the default validity time for any Fortigate produced token code (SMS, e-mail, FortiToken) is 60 seconds. If the user doesn't enter the token code within 60 seconds of issuing - code becomes invalid. It is usually not a problem, but recently I had to enable e-mail MFA for our branch location with substantial e-mail delays being a norm. So optionally below you can find how to increase the default timeout.

  • Enable e-mail option as MFA for a user:

config user local

    edit "karthi"

        set type password

        set two-factor email

        set email-to "karthi@abc.com"

    next

end

Now the option for e-mail as 2-factor authentication appears in GUI: 


(Optional) Increase token code validity from 1 to 2 minutes:


 config system global

(global) # set two-factor-email-expiry   ?

two-factor-email-expiry    Enter an integer value from <30> to <300> (default = <60>).

(global) # set two-factor-email-expiry 120


Thanks for reading my blog.


Thursday, December 13, 2018

How to Disable HTTP Method OPTIONS for the web applications in IIS 7.5 and above



ABOUT OPTIONS METHOD

OPTIONS is a diagnostic method which is mainly used for debugging purpose. This HTTP method basically reports which HTTP Methods that are allowed on the web server. In reality, this is rarely used for legitimate purposes, but it does grant a potential attacker a little bit of help and it can be considered a shortcut to find another hole.

How to fix it

OPTIONS method should be disabled.

Way to do it
Methods to disable OPTION method may vary depending upon the type, version of the web server.

Here i am describing IIS Version 7.5 and above.
  • Open IIS Manager.
  • Select the name of the machine to configure this globally (or change to the specific web site for which you need to configure this).
  • Double click on "Request Filtering".
  • Change to the HTTP Verbs tab.
  • From the Actions pane, select "Deny Verb".
  • Insert 'OPTIONS' in the Verb, and press OK to save changes.

Regards
R.Karthikeyan

Tuesday, July 3, 2018

list of Windows PowerShell commands Useful for administrators

Add a DLL to the GAC


1. Run the Power Shell console as Administrator.
2. Enter the following PowerShell

Set-location "c:\Folder Path"            
[System.Reflection.Assembly]::Load("System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a")            
$publish = New-Object System.EnterpriseServices.Internal.Publish            
$publish.GacInstall("c:\Folder Path\DLL.dll")            
iisreset

Remove a DLL from the GAC

1. Run the PowerShell console as Administrator.
2. Enter the following Power Shell

Set-location "c:\Folder Path"            
[System.Reflection.Assembly]::Load("System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a")            
$publish = New-Object System.EnterpriseServices.Internal.Publish            
$publish.GacRemove("c:\Folder Path\DLL.dll")            
iisreset

Regards
R Karthikeyan

Monday, March 26, 2018

users temp profile deleting without restart


Delete their profile along with the corresponding registry key which can be found in,
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
In the profile list tree are a list of folders that start with "S-1-5-21-000-2323-" and so on, each one of these folders corresponds to a profile. Click each one, and in the right hand pane you will see something similar to "ProfileImagePath" where the patch shown will show the users logon ID at the very end. Find the folder with that users logon ID and delete it. Have the user now try and logon again which should force a new profile to be built.

Tuesday, October 10, 2017

MCSA 2016 Prepartion and practice Exam

This practice test consists of 15 questions, with correct answers and comments following each submission. They prefer to provide answers and comments after every question so you can see where you’re going wrong and to learn from your mistakes. There’s no point getting to the end of an exam only to realist that 10 out of 20 questions were wrong but with no idea which ones they were. 

The test is free and you can retake it as often as you like: on desktop, tablet or mobile. The questions were handwritten and I do not approve of PDF braindumps - you won’t find any copied material here. 

Braindumps - It’s worth asking yourself if you’re ok with braindumps. These barely legal documents essentially equate to cheating your way through life. Where’s the self satisfaction or even the challenge in cheating? You’ll get greater pleasure and reward for actually learning the material and passing the exam legitimately. Stick to official training material and do yourself justice in passing the exam yourself - you know you can! 

Practice Exam Free

http://www.accelerated-ideas.com/exams/practice-exam.aspx?group=70-740&fq=1&qmax=30



Reference Book:

MCSA 70-740 : http://amzn.to/2g8bhR8

MCSA 70-741 : http://amzn.to/2wKkYbw

MCSA 70-742 : http://amzn.to/2g8CTpi


Regards
R.Karthikeyan

Thursday, October 5, 2017

Friday, September 22, 2017

Adding NANO Server to Domain controller 2016

Adding NANO Server to Domain controller
After Creating Success Full Nano Server. We need to do some initial configuration to communicate from Domain controller.
    1. We need set IP Address
    2. We need to enable ALL file share and printer sharing session from the inbound firewall rule
Once finished above task. We can move to Domain controller and follow the steps for join nano server to domain.
You will receive file on c:odjblob and you need move same file into your Nano server.
From DC in the file explorer
2.  Need to add Nano Server as trusted host on DC

3.  You can view the trusted hosts from the below Command
4. You can add Nano server to domain through following command (Offline)

5. To confirm domain join we have to restart the Nano server.



6. We can login through you domain administrator credential.


7. You can see the Domain Column it’s showing my Domain name MYLAB.COM

I just create one html file and pasted into Nano server IIS root folder to confirm my Nano IIS server is working fine. Here we go…..
Regards
R.Karthikeyan

Monday, September 11, 2017

Direct download .bak files through IIS Windows 2012 R2


Hi,

Some time  for some reason we avoid using FTP Server and we wold like to have alternate for dwolading huge size files.

In My Case almost 20 GB file i need to transfer from one location to another location.
 I can use FTP  but some of speed restriction policy applied in my FTP server during the peak hours.
we do have alternate ISP in this we are not configure any FTP. 

In this i just used IIS Server.(note: Source server I am having public IP access).

I just Followed these   three steps and Stared Donwload.

1. Host the test Application.
2.  Enable Directory Browsing Give Permisiion to IIS_IUser and IUSR 
3. Adding MIME Type.
























Add additional MIME types for PKGs:
a. Select Default Web Site in the left sidebar.
b. Double-click MIME Types.
c. Click Add from the right sidebar and type ".bak" in the File name extension field and "application/octet-stream" in the MIME type field. Then, click OK.


Not everything has a custom mime type. For generic binary files 





Friday, May 19, 2017

Moving Temp DB to Different Folder / Location



---Determine the logical file names of the tempdb database and their current location on the disk.

SELECT name, physical_name AS CurrentLocation
FROM sys.master_files
WHERE database_id = DB_ID(N'tempdb');
GO

----Change the location of each file by using ALTER DATABASE.

USE master;
GO
ALTER DATABASE tempdb
MODIFY FILE (NAME = tempdev, FILENAME = 'F:\TEMPDB\tempdb.mdf');
GO
ALTER DATABASE tempdb
MODIFY FILE (NAME = templog, FILENAME = 'F:\TEMPLOG\templog.ldf');
GO

--Stop and restart the instance of SQL Server.
--Verify the file change.

SELECT name, physical_name AS CurrentLocation, state_desc
FROM sys.master_files
WHERE database_id = DB_ID(N'tempdb');


--Delete the tempdb.mdf and templog.ldf files from the original location.

Share this

Labels

WINDOWS SERVER (22) Windows (20) IIS (15) Interview questions (10) TFS (9) Troubleshooting Tips (9) Fortigate Firewall (8) SQL (8) Backup (6) Team Foundation Server (6) Webserver (6) Windows Administration Task (6) Microsoft certification (5) Virtualization (5) ADDS (4) Active Directory (4) FTP (4) PHP (4) SQL 2012 (4) SQL Server (4) server (4) DBA (3) MSSQL (3) Networking (3) Offer (3) Webhosting (3) Windows 8 (3) 74-409 (2) Agile Methodology (2) Apache (2) CLI Commands (2) DNS (2) Dedicated server (2) Difference between Active and Passive Connection Mode (2) Fortinet (2) GPO (2) IIS8 (2) IPAddress (2) IPV6 (2) MVA (2) Microsoft News (2) NAT (2) Software Development (2) TFS2013 (2) Uncategorized Post (2) XAMPP (2) firewall Administration. (2) powershell (2) .htaccess (1) ALM (1) Agile vs Scrum Difference (1) Blogging TIPS (1) CPanel (1) Command for Administrator (1) DC (1) DHCP (1) Domain joining nano server (1) Exam 74-409 (1) Excel TIps (1) File server (1) Fortigate Firewall HA (1) Fortigate Firmware Upgrade (1) Free Exam 70-740 (1) Free Voucher (1) Generation2 VM (1) Group Policy (1) HP (1) HP ILO IP CHange (1) HP OA IP Change (1) HP Proliant Servers (1) HTTP to HTTPS (1) Hyper-V (1) IAS (1) IIS Server hardening (1) ILO (1) Install dll (1) MCSA 2016 (1) Microsoft Virtual Academy (1) Microsoft file sharing Port (1) Migration (1) MySQL (1) NPS (1) Nano server (1) Network Drive (1) OA (1) Plesk Panel (1) Ports (1) Ports for windows file sharing (1) RADIUS (1) RDP (1) Remote Desktop Connection (1) SCRUM (1) SQL ErrorLog (1) SQL TEMPDB (1) Second Shot (1) Server 2012 (1) Startup Parameters (1) TEMPDB Movement (1) TIPS (1) Team Foundation Server 2013 (1) Temp profile. (1) Troubleshooting DNS (1) URL Rewriting (1) VDOM (1) VPS (1) VSS (1) Virtual Labs (1) Visual Studio (1) Visual Studio 2012 (1) Visual Studio 2013 (1) Visual source safe (1) Waterfall Model vs Agile Methodology (1) Windows 2016 (1) Windows 7 (1) Windows Server 2012 (1) Windows command line (1) XP (1) certification path (1) exam (1) free online courses (1) protocols/ports for windows file sharing on a firewall (1) sql error (1) what features has been installed in your SQL Server (1) windows 2012 (1) windows Time Service (1) work item types difference (1)

E-Books

Blogger Gadgets