<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Luka Manojlovic &#187; SBS 2008</title>
	<atom:link href="http://luka.manojlovic.net/category/ms-windows-server/sbs-2008/feed/" rel="self" type="application/rss+xml" />
	<link>http://luka.manojlovic.net</link>
	<description>Luka&#039;s technical blog</description>
	<lastBuildDate>Sun, 18 Dec 2011 14:19:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Sinergija 2010 q&amp;a 2 &#8211; sbs 2008 / sbs 7 &#8211; tips and tricks</title>
		<link>http://luka.manojlovic.net/2010/11/18/sinergija-2010-qa-2-sbs-2008-sbs-7-tips-and-tricks/</link>
		<comments>http://luka.manojlovic.net/2010/11/18/sinergija-2010-qa-2-sbs-2008-sbs-7-tips-and-tricks/#comments</comments>
		<pubDate>Thu, 18 Nov 2010 10:47:09 +0000</pubDate>
		<dc:creator>manojlovicl</dc:creator>
				<category><![CDATA[SBS 2008]]></category>

		<guid isPermaLink="false">http://luka.manojlovic.net/?p=266</guid>
		<description><![CDATA[Here are answers to the questions that we were discusing on my session @ Sinergija 2010 Wsus and port question:http://www.wsus.info/index.php?showtopic=10906http://www.wsuswiki.com/WSUSServerFAQ Console crash reasons?http://blogs.technet.com/b/sbs/archive/2009/03/12/sbs-console-crashes-when-duplicate-entries-from-av-products-are-written-into-security-center.aspx Migration? Check this out:http://www.sbsmigration.com/ Backup solutions for SBS 2008 &#8211; we had a presentation on Slovenian Small Business Specialists Community SI try this one&#8230;http://www.backupassist.com/index.html]]></description>
			<content:encoded><![CDATA[<p>Here are answers to the questions that we were discusing on my session @ <a href="http://www.mssinergija.net/sr/sinergija10/vesti/Pages/default.aspx" target="_blank">Sinergija 2010</a></p>
<p>Wsus and port question:<br /><a href="http://www.wsus.info/index.php?showtopic=10906">http://www.wsus.info/index.php?showtopic=10906</a><br /><a href="http://www.wsuswiki.com/WSUSServerFAQ">http://www.wsuswiki.com/WSUSServerFAQ</a></p>
<p>Console crash reasons?<br /><a href="http://blogs.technet.com/b/sbs/archive/2009/03/12/sbs-console-crashes-when-duplicate-entries-from-av-products-are-written-into-security-center.aspx">http://blogs.technet.com/b/sbs/archive/2009/03/12/sbs-console-crashes-when-duplicate-entries-from-av-products-are-written-into-security-center.aspx</a></p>
<p>Migration? Check this out:<br /><a href="http://www.sbsmigration.com/">http://www.sbsmigration.com/</a></p>
<p>Backup solutions for SBS 2008 &#8211; we had a presentation on Slovenian Small Business Specialists Community SI try this one&#8230;<br /><a href="http://www.backupassist.com/index.html">http://www.backupassist.com/index.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://luka.manojlovic.net/2010/11/18/sinergija-2010-qa-2-sbs-2008-sbs-7-tips-and-tricks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SBS 2008 / Exchange 2007 remote.company.com and TLS&#8230;</title>
		<link>http://luka.manojlovic.net/2010/09/05/sbs-2008-exchange-2007-remote-company-com-and-tls/</link>
		<comments>http://luka.manojlovic.net/2010/09/05/sbs-2008-exchange-2007-remote-company-com-and-tls/#comments</comments>
		<pubDate>Sun, 05 Sep 2010 12:18:02 +0000</pubDate>
		<dc:creator>manojlovicl</dc:creator>
				<category><![CDATA[MS Exchange server 2007]]></category>
		<category><![CDATA[MS Scripting]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[SBS 2008]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://luka.manojlovic.net/?p=250</guid>
		<description><![CDATA[Everyone that has ever installed SBS 2008 has encountered the wizard that create certificate and remote workplace &#8211; by default called remote.company.com (yes, you can chose other prefixes but let say that I like remote becouse it is easy to remember for my users&#8230;).SBS wizards generates a certificate for this hostname and uses it for [...]]]></description>
			<content:encoded><![CDATA[<p>Everyone that has ever installed SBS 2008 has encountered the wizard that create certificate and remote workplace &#8211; by default called <strong>remote.company.com</strong> (yes, you can chose other prefixes but let say that I like remote becouse it is easy to remember for my users&#8230;).<br />SBS wizards generates a certificate for this hostname and uses it for all services (Outlook web access, Active Sync stuff and also for SMTP receive and send connectors&#8230;).<br />The problem is when you want to rename your SMTP receive and send connectors to match the records in DNS. It is a best practice to have same SMTP greetings as the records in DNS so for example if you have a domain <strong>company.com</strong> and you have an host record <strong>A</strong> called <strong>mail.company.com</strong> and <strong>MX</strong> record pointed to <strong>mail.company.com</strong> it is correct and I suggest you to folow this rule to have <strong>SMTP greeting</strong> or fqdn for SMTP connectors to match<strong> mail.company.com.</strong></p>
<p>You can rename your connectors however you want by using Exchange management console but you will lose functionality of <strong>TLS </strong>in SMTP traffic &#8211; becouse the certificate <strong>remote.company.com</strong> does not match fqdn or smtp greeting of a connector that advertise <strong>mail.company.com. </strong>You will also get an error in Event log saying:</p>
<p>Microsoft Exchange could not find a certificate that contains the domain name mail.company.com in the personal store on the local computer&#8230;</p>
<p> Ok, what can we do now?</p>
<p>Well turn on Exchange Management Shell &#8211; that is Powershell with modules for Exchange 2007 management &#8211; you can find it in star menu&#8230; And first of all we want to see current Exchange certificates that are enabled for Exchange services by using cmdlet:</p>
<p>[PS] C:\Windows\System32&gt;<strong>Get-ExchangeCertificate </strong></p>
<p>and you wil receive something like this:</p>
<div>Thumbprint                                Services   Subject<br />&#8212;&#8212;&#8212;-                                &#8212;&#8212;&#8211;   &#8212;&#8212;-<br />45EEEB44DF4BFE2EB1B7A7592EA1DF5BF93F44B4  IP.WS      CN=<strong>remote.company.com<br /></strong>42F146B12BEF918A6A8FC730F5AA87AC4ACB1CEB  IP..S      CN=<strong>remote.company.com</strong><br />817F1311CB72FB70F962EC0FAD2D8FA857F114A4  &#8230;.S      CN=sbssrv01.company.local<br />4BAAC7906689AFF0129767CF492AAE058B5DF494  &#8230;.S      CN=Sites<br />8F1D9C5FEB6EF0C39F25175AFBDEA54FE9668EF9  &#8230;..      CN=xxxxxx-xxxxxxxx-CA<br />8E4F33523325500F38ECF41FCDFBBE684AFC6145  &#8230;..      CN=WMSvc-WIN-K7KGUV5MQ40</div>
<div> </div>
<div>Now we should create a new certificate that we will use for SMTP connectors by using cmdlet:</div>
<div> </div>
<div><strong>New-ExchangeCertificate -domainname mail.company.com -PrivateKeyExportable:1</strong></div>
<div> </div>
<div><strong>Warning!</strong> When you are asked if you want to overwrite certificates chose <strong>No!</strong></div>
<div><strong> </strong> </div>
<div>
<div>Confirm<br />Overwrite existing default SMTP certificate,<br />&#8217;45EEEB44DF4BFE2EB1B7A7592EA1DF5BF93F44B4&#8242; (expires 14.1.2012 22:37:04), with<br />certificate &#8217;59D62E7850EE4093AFF1EC73E2623D52058C2B35&#8242; (expires 27.1.2015<br />17:09:02)?<br />[Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help<br />(default is &#8220;Y&#8221;): <strong>N</strong></div>
<div> </div>
<div>so we get output:</div>
<div>Thumbprint                                Services   Subject<br />&#8212;&#8212;&#8212;-                                &#8212;&#8212;&#8211;   &#8212;&#8212;-<br />59D62E7850EE4093AFF1EC73E2623D52058C2B35  &#8230;..      CN=<strong>mail.company.com</strong></div>
<div> </div>
<div>Great!  If we want to be shure that everything is working correctly and that Exchange SMTP service is using our new certificate we can use cmdlet:</div>
</div>
<div>
<p>[PS] C:\Windows\System32&gt;<strong>Get-ExchangeCertificate </strong></p>
<p>[PS] C:\Windows\System32&gt;</p>
<div>Thumbprint                                Services   Subject<br />&#8212;&#8212;&#8212;-                                &#8212;&#8212;&#8211;   &#8212;&#8212;-<br />59D62E7850EE4093AFF1EC73E2623D52058C2B35  &#8230;.<strong>S</strong>      CN=<strong>mail.company.com</strong><br />45EEEB44DF4BFE2EB1B7A7592EA1DF5BF93F44B4  IP.W<strong>S</strong>      CN=<strong>remote.company.com</strong></div>
<div>42F146B12BEF918A6A8FC730F5AA87AC4ACB1CEB  IP..<strong>S</strong>      CN=<strong>remote.company.com</strong></div>
<div>817F1311CB72FB70F962EC0FAD2D8FA857F114A4  &#8230;.S      CN=sbssrv01.company.local<br />4BAAC7906689AFF0129767CF492AAE058B5DF494  &#8230;.S      CN=Sites<br />8F1D9C5FEB6EF0C39F25175AFBDEA54FE9668EF9  &#8230;..      CN=xxxxxxxxxxx-xxxxxxxxxxxx01-CA<br />8E4F33523325500F38ECF41FCDFBBE684AFC6145  &#8230;..      CN=WMSvc-WIN-K7KGUV5MQ40</div>
<div>We can now see that SMTP connectors are using all certificates (S defnies SMTP service).</div>
<div>Ok&#8230; How can you test that TLS works?</div>
<div>You can try it by using telnet client and connect to your server:</div>
<div><strong>telnet mail.company.com 25</strong></div>
<div>
<div> </div>
<div>Exchange should respond something like:</div>
<div>220 <strong>mail.company.com</strong> Microsoft ESMTP MAIL Service ready at Wed, 27 Jan 2010 17:<br />12:09 +0100</div>
<div> </div>
<div>then you can write:</div>
<div><strong>helo test.blablabla.com</strong></div>
<div> </div>
<div>220 <strong>mail.company.com</strong> Microsoft ESMTP MAIL Service ready at Wed, 27 Jan 2010 17:<br />13:07 +0100<br />helo test.blablabla.si<br />250 <strong>mail.xxxxxxxxxxxxxxxx.si</strong> Hello [xxx.xxx.xxxx.xxx]</div>
<div>after that enter command:</div>
<div><strong>starttls</strong></div>
<p><strong> </strong></p>
</div>
<div>server should respond:
<div>220 2.0.0 SMTP server ready</div>
<div> </div>
<div>Server ready? Super! <img src='http://luka.manojlovic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </div>
<div> </div>
<div>PS.</div>
<div>If you did miss something you will receive error from server saying:</div>
<div> </div>
<div>starttls<br />500 5.3.3 Unrecognized command</div>
<div> </div>
<div>If you get that? Read this tutorial again <img src='http://luka.manojlovic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </div>
<div>PS. PS. You do not need to restart anything when you apply this commands&#8230; No need for restarting Exchange services&#8230;</div>
<div>Special thanks to <a href="http://blog.mreza.info/" target="_blank">Saso Erdeljanov</a> for some hints about this issue&#8230;</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://luka.manojlovic.net/2010/09/05/sbs-2008-exchange-2007-remote-company-com-and-tls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange 2007 / 2010 &#8211; remove headers</title>
		<link>http://luka.manojlovic.net/2010/05/24/exchange-2007-2010-remove-headers/</link>
		<comments>http://luka.manojlovic.net/2010/05/24/exchange-2007-2010-remove-headers/#comments</comments>
		<pubDate>Mon, 24 May 2010 21:57:47 +0000</pubDate>
		<dc:creator>manojlovicl</dc:creator>
				<category><![CDATA[MS Exchange server 2007]]></category>
		<category><![CDATA[SBS 2008]]></category>
		<category><![CDATA[headers]]></category>
		<category><![CDATA[remove headers]]></category>

		<guid isPermaLink="false">http://luka.manojlovic.net/?p=232</guid>
		<description><![CDATA[If you are using Windows server 2008 SBS or Exchange 2007 or Exchange 2010 you send with your e-mail also mail headers that (I think) you would not like to &#8220;share&#8221; with external world: Received: from mail.server.si (xxx.xxx.xxx.xxx) by mail.server2.si (172.31.200.2) with Microsoft SMTP Server (TLS) id 8.2.247.2; Wed, 19 May 2010 13:08:47 +0200Received: from SRVEXCH01.domain.local ([10.11.12.2]) [...]]]></description>
			<content:encoded><![CDATA[<p>If you are using Windows server 2008 SBS or Exchange 2007 or Exchange 2010 you send with your e-mail also mail headers that (I think) you would not like to &#8220;share&#8221; with external world:</p>
<p>Received: from mail.server.si (xxx.xxx.xxx.xxx) by mail.server2.si<br /> (172.31.200.2) with Microsoft SMTP Server (TLS) id 8.2.247.2; Wed, 19 May<br /> 2010 13:08:47 +0200<br /><strong>Received: from SRVEXCH01.domain.local ([10.11.12.2]) by SRVEXCH01.domain.local<br /> ([10.11.12.2]) with mapi; Wed, 19 May 2010 13:08:02 +0200<br /></strong>From: xxxxx xxxxx xxxxx@xxxxx<br />To: =?iso-8859-2?Q?xxxxx_xxxxx=E6_=28xxxxx=xxxxx=2Exxxxx=29?=<br /> &lt;xxxxx@xxxxx&gt;<br />Return-Receipt-To: xxxxx@xxxxx<br />Date: Wed, 19 May 2010 13:08:00 +0200<br />Subject: xxxxx<br />Thread-Topic: xxxxx<br />Thread-Index: Acr3Q4r6dSBNnU37R9ypBLYy8PMzcA==<br />Message-ID: &lt;13204AAD07BCDD4EB69C3367FF1783A9124C065BB2@SRVEXCH01.domain.local&gt;<br />Accept-Language: sl-SI<br />Content-Language: en-US<br />X-MS-Has-Attach:<br />X-MS-TNEF-Correlator:<br />acceptlanguage: sl-SI<br />Content-Type: multipart/alternative;<br /> boundary=&#8221;_000_13204AAD07BCDD4EB69C3367FF1783A9124C065BB2_&#8221;<br />MIME-Version: 1.0<br />Return-Path: xxxxx@xxxxx<br />X-MS-Exchange-Organization-PRD: xxxxx.si<br />X-MS-Exchange-Organization-SenderIdResult: Pass<br />Received-SPF: Pass (xxxxx.xxxxx.xxxxx: domain of xxxxx@xxxxx<br /> designates xxx.xxx.xxx.xxx as permitted sender) receiver=xxxxx.xxxxx.local;<br /> client-ip=xxx.xxx.xxx.xxx; helo=mail.xxxxx.si;<br />X-MS-Exchange-Organization-SCL: 1<br />X-MS-Exchange-Organization-PCL: 2<br />X-MS-Exchange-Organization-Antispam-Report: DV:3.3.8917.498;SV:3.3.8919.449;SID:SenderIDStatus Pass;OrigIP:xxx.xxx.xxx.xxx</p>
<p>If you want to remove this stuff we need to create a Hub Transport Rule:<br />Open Microsoft Exchange Console<br />Navigate to:<br />Microsoft Exchange \ Organization Configuration \ Hub Transport \ Transport Rules</p>
<p>Right Click and select <strong>New Transport Rule</strong> and name it &#8220;<strong>Remove headers</strong>&#8221; click <strong>Next</strong>,</p>
<p>chose <strong>From users inside or outside the organization</strong> and select<strong> Inside </strong>click <strong>Next,</strong>chose <strong>Remove header </strong>and as message header just write: <strong>Received </strong>twice click Next&#8230;</p>
<p> </p>
<p>You are done&#8230; Headers will not be sent any more to users outside the organization&#8230;</p>
<p>Bye,<br />Luka (under influence of wonderful <a href="http://www.ntk.si" target="_blank">NT Konferenca 2010</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://luka.manojlovic.net/2010/05/24/exchange-2007-2010-remove-headers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

