CiscoSecure AAA Server (Unix) -- Managing Profiles via CLI

Greetings All,
Am wanting to modify user profiles -- specifically, I am looking to apply or modify password expiry dates.
I understand the general profile structure and syntax, however, I am not able to modify the profile line to include the expiration string (e.g. until "31 Dec 2005") using the UpdateProfile (with -a option) or UpdatePassword commands in the CLI. I know this can be done, easily, using the Web interface, but the situation I am currently facing dictates use of either the CLI commands or direct modification of the user record in the CS database (and I'm no SQL guru).
Does anyone know how I can accomplish this, so that my user profiles will resemble the following:
User Profile Information
user = test{
profile_id = 41
profile_cycle = 4
member = ANALYSTS
password = clear "*******" <font color = "red">until "31 Dec 2005"</font>
Thanks in advance for any assistance.
Edwin Martinez II
PS If I can only accomplish this by direct modification of the database record(s), can you detail the appropriate SQL commands?

I appreciate your reply, but maybe I wasn't clear.
I understand how to modify profiles using the UpdateProfile command. What is happening is that I cannot modify the password entry in the profile to change the expiration.
In regards to the sample profile provided:
user = test{
profile_id = 41
profile_cycle = 4
member = ANALYSTS
password = clear "*******" until "31 Dec 2005"
Say user "test" has allowed his password to expire. The profile contains this expiration date (in this case, 31 Dec 2005) which you can view using the command "ViewProfile -u test". You can also modify the password using the command "ChangePassword -u test -pr clear -opw oldPasswd -npw newPasswd" or, more preferable, "UpdatePassword -u test -pr clear -npw newPasswd". Regardless how you change the password, the string representing the expiration date, " until "31 Dec 2005" ", remains unchanged.
I was hoping that the date could be changed using the following command:
UpdatePassword -a password = clear "******" until "1 Jan 2006"
However, this is not happening. The end result is a profile that has, subesquently, been thoroughly munged, and there is no other recourse but to delete and recreate the profile . Definitely an unnecessary choice, but there seems to be no other recourse.
Anyone with more insight???

Similar Messages

  • Print server, AD, and Profile Manager

    Having a number of issues that I can resolve regarding printing--I am trying to set up profiles in the Profile Manager, but printers are not available or visable. However they are visable in the workgroup manager. The printers reside on Windows print server (2008 R2). Further I can add the printers to my server, but they are not visable in the "Printer Sharing" section of "sharing". So with that, I have a few questions:
    1. Do I need to turn on Kerberos in CUPS? User's don't authenticate to our printers via Kerberos, but via the Account manager of the individual printers.
    2. Why do settings in Workgroup manager not apply? I can add the printers via LDAP the the new groups I have added, but when I open profile manager the changes or printers are not implemented.
    3. How do I make printers visible in Profile Manager?
    I have scoured the net and several manuals, but I can seem to stumble upon the correct answer.

    Hi,
    I have the same issue, very frustrating. Using a Win 2003 AD and 10.8.2 server and clients. If i use WGM I can see all users and groups correctly, but Server.app and Profile Manager does not show them correct.
    Strange that we see issues like this since Profile Manager has been around for a while, really interested to hear other peoples experiences.
    PS I see a similar thing here: https://discussions.apple.com/thread/4417085?start=0&tstart=0

  • PKCS12 certificate payloads in OS X Server 10.9 Profile Manager

    Hi all,
    I'm unable to successfully push .p12 packaged certificate identities to devices managed by OS X Server 10.9 Profile Manager. The problem is that while the file is pushed to the device, it doesn't get unpacked and hence is unable to be used.
    I've identified the problem as Profile Manager setting the payload type incorrectly to "com.apple.security.pkcs1" in the profile rather than "com.apple.security.pkcs12". If I strip the profile signing data and edit it, the profile works perfectly when manually installed.
    So the questions I have:
    1) What's the best way of getting Apple's attention for someone to fix this bug, or is this possibly a browser JavaScript issue incorrectly identifying the payload type (using latest Safari though)?
    2) Does anyone know of a workaround to allow this to still be automatically pushed out without having to manually edit and install on each device?
    (SCEP is out at the moment due to another issue base64 decoding the SCEP request from Mac OS X devices that I'm taking up with the SCEP server vendor - but iOS works fine)
    Thanks!
    Al

    I'm new to OS X Server and Radius, and have just spent way too many hours trying to figure out what I was doing wrong. I could connect to our enterprise wifi perfectly fine when selecting the certificate from the keychain, but I just couldn't get it to work when I uploaded the .p12 file and used it as the WiFi identity. I tried so many combinations of passphrase, no passphrase, pem format, pkcs12 format, resetting Radius server, resetting whole PKI... But I'd always see Certificate: ?Error_-25257? in the Settings window while I was trying to install the profile, and I couldn't see anything useful in the Radius logs when I tried to connect.
    But it turns out, all I needed to do was:
       sed -i '' -e '1s/pkcs1/pkcs12/;t' -e '1,/pkcs1/s//pkcs12/' wifi_profile.mobileconfig
    (changes the first instance of pkcs1 to pkcs12 - don't change both! I was wondering why it was asking me for a password for our public certificate.)
    Will try to update and see if that fixes the problem.

  • Is there a way to have separate permissions between Server app and Profile manager?

    I'm running OS X 10.10.1 (Yosemite) with Server app 4.0 installed.
    I am a System Administrator for a University. I want to give our college techs the ability to manage Profile Manager, but if I grant them Admin rights on the Apple server they will also have access to the Server app, if they have the server app installed on their computer.
    Is there a way to limit access to the Server app, but allow certain individuals admin right to Profile Manager?

    This provides instructions:
    How to use multiple iPods, iPads, or iPhones with one computer

  • Can I distribute s/mime certificates to MDM managed users via Mavericks Server?

    We have a private CA and right now users have to share S/MIME certificates with others manually. Is is possible to embed these certs into each user in Address Book, or distribute them some other way using Mavericks Server?

    Couldn't fix the problem. Had to attach another external storage drive to each computer to use for backup, then erase and rename the TimeCapsule hard drive via Airport utility as well as the second hard drive in the MacMini Server via Disk Utility. I removed both the Time Capsule drive and the second internal hard drive from the "Settings" pane in the "Time Machine" section of Server.
    I still have no idea of what went wrong or if the problem will happen again. It may have been a corrupted file on the backup drives. It may have been Tech Tool Pro or Adode Creative Cloud updater, who knows. But for now, it is working as anticipated. The iMac clients and the MacMini Server are all backed up to the Time Capsule as well as the Mac Mini Server's second internal drive.
    I sure wish there were better documentation available for using Server to manage Time Machine backups!

  • Push config files made in Server app with Profile manager

    As I understand the manual you can distribuate configuration files with Profile manager.
    A bit confused now when I want to use Profile manager to distribuate a configuration file I´ve made in Server app.
    I saved a VPN configuration file and want to distribuate it with Profile manager but how do I import or add that file into the settings pane for my devices in profile manager?

    Hi,
    I have the same issue, very frustrating. Using a Win 2003 AD and 10.8.2 server and clients. If i use WGM I can see all users and groups correctly, but Server.app and Profile Manager does not show them correct.
    Strange that we see issues like this since Profile Manager has been around for a while, really interested to hear other peoples experiences.
    PS I see a similar thing here: https://discussions.apple.com/thread/4417085?start=0&tstart=0

  • Change Server URL in Profile Manager Enrollment Process?

    It appears devices learn the IP or URL of their MDM server during the Profile Manager enrollment process. It must be part of the configuration profile sent to the device. It also appears this is based on the machine's host name. Is there anyway to change that URL - as when the host name of the server changes? If so, where are the files located on the server.
    I believe in the previous iPhone Configuration Utility there was a "server URL" and "Check in URL" that could be set. We can't seem to find any parameters in Profile Manger to control the same. Thanks for any help.

    Hi Jonathan,
    I stumbled on your responses because I was looking for an answer to my own issues.
    I am like most just a lay user, although wth 20 years Mac experience.
    The issue is as folllows:
    I set up Lion Server and I host a Wiki page and I try to run Profile Manager.
    I do not have a registered host name. The hostname is server.name.private.
    In order to reach the server from the Internet my clients use a DynDNS hostname such as "name.dyndns.org".
    My clients can access the Wiki pages with no problems and Safari shows https://name.dyndns.org in the address line.
    However, if they want to connect to Profile manager, the server re-directs https://name.dyndns.org/profilemanager https://server.name.private/auth?redirect=https://server.name.private/devicemana gement/api/authentication/callback
    which the client's browser cannot resolve because the internal hostname is unknown to public DNS servers.
    Why does Profile Manager redirect in the first place ?
    Can this issue be resolved without obtaining an "officially registered" hostname ?
    Thank you for helping.
    Regards,
    Twistan

  • Keep weblogic admin server and managed server running after exiting PUTTY

    How do i keep my managed servers and admin servers running on SOLARIS (unix) boxes even after exiting putty and starting them? Do i need to create like a cron job or something?

    *(after running nohup ./startWebLogic.sh i get Sending output to nohup.out and hangs there)*
    out put from nohup.out =>
    JAVA Memory arguments: -Xms256m -Xmx512m -XX:MaxPermSize=256m
    WLS Start Mode=Production
    CLASSPATH=/usr/Oracle/Middleware/patch_wls1034/profiles/default/sys_manifest_classpath/weblogic_patch.jar:/usr/Oracle/Middleware/patch_ocp360/profiles/default/sys_manifest_classpath/weblogic_patch.jar:/d/ct0/home/shahs06/JAVA/jdk1.6.0_25/lib/tools.jar:/usr/Oracle/Middleware/wlserver_10.3/server/lib/weblogic_sp.jar:/usr/Oracle/Middleware/wlserver_10.3/server/lib/weblogic.jar:/usr/Oracle/Middleware/modules/features/weblogic.server.modules_10.3.4.0.jar:/usr/Oracle/Middleware/wlserver_10.3/server/lib/webservices.jar:/usr/Oracle/Middleware/modules/org.apache.ant_1.7.1/lib/ant-all.jar:/usr/Oracle/Middleware/modules/net.sf.antcontrib_1.1.0.0_1-0b2/lib/ant-contrib.jar:/usr/Oracle/Middleware/wlserver_10.3/common/derby/lib/derbyclient.jar:/usr/Oracle/Middleware/wlserver_10.3/server/lib/xqrl.jar
    PATH=/usr/Oracle/Middleware/wlserver_10.3/server/bin:/usr/Oracle/Middleware/modules/org.apache.ant_1.7.1/bin:/d/ct0/home/shahs06/JAVA/jdk1.6.0_25/jre/bin:/d/ct0/home/shahs06/JAVA/jdk1.6.0_25/bin:/usr/sbin:/usr/bin:/usr/local/bin:/d/ct0/home/shahs06/JAVA/jdk1.6.0_25/bin
    * To start WebLogic Server, use a username and *
    * password assigned to an admin-level user. For *
    * server administration, use the WebLogic Server *
    * console at http://hostname:port/console *
    starting weblogic with Java version:
    java version "1.6.0_25"
    Java(TM) SE Runtime Environment (build 1.6.0_25-b06)
    Java HotSpot(TM) 64-Bit Server VM (build 20.0-b11, mixed mode)
    Starting WLS with line:
    /d/ct0/home/shahs06/JAVA/jdk1.6.0_25/bin/java -server -d64 -Xms256m -Xmx512m -XX:MaxPermSize=256m -Dweblogic.Name=AdminServer -Djava.security.policy=/usr/Oracle/Middleware/wlserver_10.3/server/lib/weblogic.policy -Dweblogic.ProductionModeEnabled=true -da -Dplatform.home=/usr/Oracle/Middleware/wlserver_10.3 -Dwls.home=/usr/Oracle/Middleware/wlserver_10.3/server -Dweblogic.home=/usr/Oracle/Middleware/wlserver_10.3/server -Dweblogic.management.discover=true -Dwlw.iterativeDev=false -Dwlw.testConsole=false -Dwlw.logErrorsToConsole=false -Dweblogic.ext.dirs=/usr/Oracle/Middleware/patch_wls1034/profiles/default/sysext_manifest_classpath:/usr/Oracle/Middleware/patch_ocp360/profiles/default/sysext_manifest_classpath weblogic.Server
    <9-May-2011 1:33:56 o'clock PM PDT> <Info> <Security> <BEA-090905> <Disabling CryptoJ JCE Provider self-integrity check for better startup performance. To enable this check, specify -Dweblogic.security.allowCryptoJDefaultJCEVerification=true>
    <9-May-2011 1:33:57 o'clock PM PDT> <Info> <Security> <BEA-090906> <Changing the default Random Number Generator in RSA CryptoJ from ECDRBG to FIPS186PRNG. To disable this change, specify -Dweblogic.security.allowCryptoJDefaultPRNG=true>
    <9-May-2011 1:33:59 o'clock PM PDT> <Info> <WebLogicServer> <BEA-000377> <Starting WebLogic Server with Java HotSpot(TM) 64-Bit Server VM Version 20.0-b11 from Sun Microsystems Inc.>
    <9-May-2011 1:34:04 o'clock PM PDT> <Info> <Management> <BEA-141107> <Version: WebLogic Server 10.3.4.0 Fri Dec 17 20:47:33 PST 2010 1384255 >
    <9-May-2011 1:34:12 o'clock PM PDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to STARTING>
    <9-May-2011 1:34:12 o'clock PM PDT> <Info> <WorkManager> <BEA-002900> <Initializing self-tuning thread pool>
    <9-May-2011 1:34:12 o'clock PM PDT> <Notice> <Log Management> <BEA-170019> <The server log file /usr/Oracle/Middleware/user_projects/domains/base_domain/servers/AdminServer/logs/AdminServer.log is opened. All server side log events will be written to this file.>
    <9-May-2011 1:34:27 o'clock PM PDT> <Notice> <Security> <BEA-090082> <Security initializing using security realm myrealm.>
    <9-May-2011 1:34:45 o'clock PM PDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to STANDBY>
    <9-May-2011 1:34:45 o'clock PM PDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to STARTING>
    9-May-2011 1:34:58 PM com.sun.faces.config.ConfigureListener contextInitialized
    INFO: Initializing Sun's JavaServer Faces implementation (1.2_03-b04-FCS) for context '/console'
    9-May-2011 1:34:58 PM com.sun.faces.config.ConfigureListener contextInitialized
    INFO: Completed initializing Sun's JavaServer Faces implementation (1.2_03-b04-FCS) for context '/console'
    <9-May-2011 1:35:04 o'clock PM PDT> <Notice> <Log Management> <BEA-170027> <The Server has established connection with the Domain level Diagnostic Service successfully.>
    <9-May-2011 1:35:04 o'clock PM PDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to ADMIN>
    <9-May-2011 1:35:04 o'clock PM PDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to RESUMING>
    <9-May-2011 1:35:06 o'clock PM PDT> <Notice> <Security> <BEA-090171> <Loading the identity certificate and private key stored under the alias DemoIdentity from the jks keystore file /usr/Oracle/Middleware/wlserver_10.3/server/lib/DemoIdentity.jks.>
    <9-May-2011 1:35:06 o'clock PM PDT> <Notice> <Security> <BEA-090169> <Loading trusted certificates from the jks keystore file /usr/Oracle/Middleware/wlserver_10.3/server/lib/DemoTrust.jks.>
    <9-May-2011 1:35:06 o'clock PM PDT> <Notice> <Security> <BEA-090169> <Loading trusted certificates from the jks keystore file /d/ct0/home/shahs06/JAVA/jdk1.6.0_25/jre/lib/security/cacerts.>
    <9-May-2011 1:35:06 o'clock PM PDT> <Alert> <Security> <BEA-090152> <Demo trusted CA certificate is being used in production mode: [
    Version: V3
    Subject: CN=CACERT, OU=FOR TESTING ONLY, O=MyOrganization, L=MyTown, ST=MyState, C=US
    Signature Algorithm: MD5withRSA, OID = 1.2.840.113549.1.1.4
    Key: SunPKCS11-Solaris RSA public key, 512 bits (id 4371458208, session object)
    modulus: 9550192877869244258838480703390456015046425375252278279190673063544122510925482179963329236052146047356415957587628011282484772458983977898996276815440753
    public exponent: 65537
    Validity: [From: Thu Mar 21 12:12:27 PST 2002,
                   To: Tue Mar 22 13:12:27 PDT 2022]
    Issuer: CN=CACERT, OU=FOR TESTING ONLY, O=MyOrganization, L=MyTown, ST=MyState, C=US
    SerialNumber: [    33f10648 fcde0deb 4199921f d64537f4]
    Certificate Extensions: 1
    [1]: ObjectId: 2.5.29.15 Criticality=true
    KeyUsage [
    Key_CertSign
    ]

  • Mandatory Profile via GPO

    Hi Dear,
    I have a requirement to configure couple of terminal servers in Windows server 2012.
    However we do not want any user to save anything onto their local profiles. Around 200 users will be using this terminal server for their use with multiple applications that will be installed in the server.
    Is it possible to configure user mandatory profiles via Group Policy. Really appreciate of someone can provide me the steps preferably in the easy mode. However to test it I have created a test server since I am not that good at registry values would not
    do any harm to the environment.
    I am using Server 2012 as a test terminal server and active directory is 2008.
    Thank You in Advance.
    -vikram

    Hi,
    for assistance with TS/RDS, the dedicated forum is here:
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserverTS
    Further reading for you:
    Manage User Profiles for Remote Desktop Services
    https://technet.microsoft.com/en-us/library/cc742820.aspx
    http://blogs.msdn.com/b/rds/archive/2009/06/02/user-profiles-on-windows-server-2008-r2-remote-desktop-services.aspx
    http://blogs.msdn.com/b/rds/archive/2012/11/13/easier-user-data-management-with-user-profile-disks-in-windows-server-2012.aspx
    Managing Roaming User Data Deployment Guide
    http://go.microsoft.com/fwlink/?LinkId=73760
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • ESA want to retreive logs via cli

    hi,
    i want to retrieve  message tracking logs via cli
    Can some body let me know the procedure

    Retrieve as in FTP copy them?  Or retrieve as in setup syslog to push the logs off to a local syslog server?
    Message tracking cannot be retrieved from CLI.  Only the mail_logs --- which are used to compile the message tracking DB on the appliance(s).
    From the User Guide, 34-36:
    Tracking logs record information about the email operations of AsyncOS. The log messages are a subset of the messages recorded in the mail logs.  The tracking logs are used by the message tracking component to build the message tracking database.
    If you are trying to get the mail_logs...
    You'll need to configure your logs via CLI: 'logconfig' or GUI: System Administration -> Log Subscriptions.  Edit, or suggested to create a new/copy of the log you are needing off-appliance, and set the push as needed per your environment ---
    From the User Guide, 34-6:
    Log Retrieval Methods
    Log files can be retrieved based upon one of the following file transfer protocols. You set the protocol while creating or editing the log subscription in the GUI or via the logconfig command during the log subscription process.
    Log Transfer Protocols
    Manually Download
    This method lets you access log files at any time by clicking a link to the log directory on the Log Subscriptions page, then clicking the log file to access. Depending on your browser, you can view the file in a browser window, or open or save it as a text file. This method uses the HTTP(S) protocol and is the default retrieval method.
    NoteUsing this method, you cannot retrieve logs for any computer in a cluster, regardless of level (machine, group, or cluster), even if you specify this method in the CLI.
    FTP Push
    This method periodically pushes log files to an FTP server on a remote computer. The subscription requires a username, password, and destination directory on the remote computer. Log files are transferred based on a rollover schedule set by you.
    SCP Push
    This method periodically pushes log files to an SCP server on a remote computer. This method requires an SSH SCP server on a remote computer using the SSH1 or SSH2 protocol. The subscription requires a username, SSH key, and destination directory on the remote computer. Log files are transferred based on a rollover schedule set by you.
    Syslog Push
    This method sends log messages to a remote syslog server. This method conforms to RFC 3164. You must submit a hostname for the syslog server and choose to use either UDP or TCP for log transmission. The port used is 514. A facility can be selected for the log; however, a default for the log type is pre-selected in the dropdown menu. Only text-based logs can be transferred using syslog push.
    If you are wanting to just copy over a specific set of logs for a one-time review or to provide... then, assure that FTP is enabled on the interface.  Then, using standard CLI from your desktop - ftp <IP/hostname>.  You'll be in the /configuration directory when you finish authenticating onto your appliance.  After - just simply use standard FTP commands to retrieve the log files you are after.
    Ex.
    $ ftp myesa
    Connected to myesa.
    220 myesa.local Cisco IronPort FTP server (V8.0.1) ready
    Name (myesa:robsherw): admin
    331 Password required.
    Password: 
    230 Login successful.
    Remote system type is UNIX.
    Using binary mode to transfer files.
    ftp> ls
    227 Entering Passive Mode (XXX,16,6,165,16,243)
    150 Opening ASCII mode data connection for file list
    drwxrwx---   4 root     config       1024 Apr 25 10:02 configuration
    drwxrwx---   2 root     config        512 Jun  2  2013 captures
    drwxrwx---   2 root     config        512 Jun  2  2013 diagnostic
    drwxrwx---   2 root     log           512 Apr 25 09:58 upgrade_logs
    drwxrwx---   2 root     log          1024 Apr 25 09:58 authentication
    drwxrwx---   2 root     log           512 Apr 25 09:58 system_logs
    drwxrwx---   2 root     log           512 Apr 25 09:58 cli_logs
    drwxrwx---   2 root     log           512 Apr 25 09:58 trackerd_logs
    drwxrwx---   2 root     log           512 Apr 25 09:58 reportd_logs
    drwxrwx---   2 root     log           512 May  2 15:35 slbl_db
    drwxrwx---   2 root     log           512 Apr 25 09:58 ftpd_logs
    drwxrwx---   2 root     log           512 Apr 25 09:58 euq_logs
    drwxrwx---   2 root     log           512 Apr 25 09:59 updater_logs
    drwxrwx---   2 root     log           512 Apr 25 09:59 euqgui_logs
    drwxrwx---   2 root     log           512 Apr 25 10:01 reportqueryd_logs
    drwxrwx---   2 root     log           512 Apr 25 10:02 mail_logs
    drwxrwx---   2 root     log           512 Apr 25 10:02 status
    drwxrwx---   2 root     log          1024 Apr 25 10:02 asarchive
    drwxrwx---   2 root     log           512 Apr 25 10:02 bounces
    drwxrwx---   2 root     log           512 Apr 25 10:02 error_logs
    drwxrwx---   2 root     log          1024 Apr 25 10:02 avarchive
    drwxrwx---   2 root     log           512 Apr 25 10:02 crash_archive
    drwxrwx---   2 root     log           512 Apr 25 10:03 sntpd_logs
    drwxrwx---   2 root     log           512 Apr 25 09:59 gui_logs
    drwxrwx---   2 root     log          1024 Apr 25 10:04 scanning
    drwxrwx---   2 root     log           512 Apr 25 10:04 antispam
    drwxrwx---   2 root     log           512 Apr 25 10:04 repeng
    drwxrwx---   2 root     log           512 Apr 25 10:04 antivirus
    drwxrwx---   2 root     log           512 Apr 25 10:04 encryption
    drwxrwx---   2 root     log           512 Jan 23 10:55 domain
    drwxrwx---   2 root     log          1024 Feb 27 21:21 domain_3
    drwxrwx---   2 root     log           512 Jan 23 10:55 domain_2
    drwxrwx---   2 root     log           512 Apr 25 09:58 slbld_logs
    drwxrwx---   2 root     log           512 May  2 15:35 slbl_isq_db
    drwxr-xr-x   3 root     log           512 Feb  6 00:00 periodic_reports
    drwxrwx---   2 root     log           512 Apr 25 09:58 snmp_logs
    You can then use standard FTP/UNIX commands to navigate through the directory structure, cd mail_logs, for example and mget the files.
    Ex.
    ftp> cd mail_logs
    250 CWD command successful.
    ftp> ls
    227 Entering Passive Mode (XXX,16,6,165,13,125)
    150 Opening ASCII mode data connection for file list
    -rw-rw----   2 root     log       1399268 May  6 15:33 mail.current
    -rw-rw----   2 root     log       1399268 May  6 15:33 [email protected]
    -rw-rw----   1 root     log        145117 Feb 10 11:58 [email protected]
    -rw-rw----   1 root     log        167043 Feb 11 12:03 [email protected]
    -rw-rw----   1 root     log       1943018 Mar  4 14:14 [email protected]
    -rw-rw----   1 root     log       2404319 Feb 27 09:40 [email protected]
    -rw-rw----   1 root     log       1822273 Mar 20 11:58 [email protected]
    -rw-rw----   1 root     log          1267 Mar  4 14:40 [email protected]
    -rw-rw----   1 root     log       3415936 Apr 24 12:55 [email protected]
    -rw-rw----   1 root     log         67740 Mar 24 16:48 [email protected]
    -rw-rw----   1 root     log         70220 Feb  7 15:29 [email protected]
    226 Transfer Complete
    ftp> mget mail.@*
    mget [email protected] [anpqy?]? a
    Prompting off for duration of mget.
    227 Entering Passive Mode (XXX,16,6,165,180,210)
    150 Opening Binary mode data connection for file '[email protected]'
      2% |*** 
    And so it will copy those off...
    Once complete - the files will now be in the directory on your local desktop.
    I hope this helps!
    -Robert
    (*If you have received the answer to your original question, and found this helpful/correct - please mark the question as answered, and be sure to leave a rating to reflect!)

  • Unable to add File Server Resource Manager Tools on Windows Server 2012 - Errors on restart and roll back install

    Unable to install Windows Server 2012 Feature -  [Tools] File Server Resource Manager Tools.
    Installs, however when I restart the server error messages appears saying feature unable to install, windows reverting changes.
    In the Setup event logs have the following information message "Update FSRM-Infrastructure of package FSRM-All failed to be turned on. Status: 0x800f0922"
    Does anyone have any idea's on why this Feature can not be installed ??
    Scott

    Hi Shaun
    Tried both of your suggestions, however neither strategy worked.
    Strategy 1
    Tried installing via powershell - "install-windowsfeature -name fs-resource-manager -includemanagementtools"   
    Feature un-installed itself during the restart.
    Attempted to use the command "DISM /online /remove-feature /featurename:FSRM-Infrastructure-Services".  However
    this did work because one the Service was'nt installed or two because there was no command option for "/remove-feature"
    PACKAGE SERVICING COMMANDS:
      /Add-Package            - Adds packages to the image.
      /Remove-Package         - Removes packages from the image.
      /Enable-Feature         - Enables a specific feature in the image.
      /Disable-Feature        - Disables a specific feature in the image.
      /Get-Packages           - Displays information about all packages in the image.
      /Get-PackageInfo        - Displays information about a specific package.
      /Get-Features           - Displays information about all features in a package.
      /Get-FeatureInfo        - Displays information about a specific feature.
      /Cleanup-Image          - Performs cleanup and recovery operations on the image.
    Strategy 2
    Tried installing via powershell, using the following command DISM
    /online /enable-feature /featurename:FSRM-Infrastructure-Services, however got the same result, the install backed out during the restart.
    All up back to where I started?

  • Windows Server 2008 R2 activation via KMS failure

    Hello,
    I'm trying to activate about 20 Windows Server 2008 R2 via KMS. Before that I have successfully activated Windows 7 clients and Microsoft Office 2010 products. But when I try to activate Windows Server 2008 R2 clients via kms I'm getting the following error
    on the KMS host: 
    . Exception System.Runtime.InteropServices.COMException (0xC004F074)
    KMS host installed on the machine with Windows 7 Professional OS. From the VAMT GUI I can see the following Windows server license information :
    Key Type : CSVLK
    Edition : ServerStandard;ServerEnterprise;ServerWeb;ServerHPC
    Description : Server 2008 R2 Std and Ent Volume.
    If I try to activate product from the client I get the following error : 
    Error: 0xC004F074 The Software Licensing Service reported that the computer could not be activated. The Key Management Service(KMS) is unavailable. 
    I have searched a lot about this error. But still cannot solve the issue. 
    Thanks & Regards
    Ulzii

    Yes KMS host is Windows 7. I read all documents about KMS but haven't read this doc. So I have to change KMS host or add Win Server KMS host, that's right?
    Yes that's right. Windows "Client" OS editions, when setup as KMShost, cannot issue activations for Windows "Server" OS editions.
    To do so, you will need a KMShost product key for Windows Server - you will only have such a product key if you have purchased Windows Server licenses through Volume Licensing.
    (The Windows 7 KMShost product key cannot be installed on Windows Server OS)
    http://social.technet.microsoft.com/wiki/contents/articles/22510.volume-activation-kms-mak-adba-avma.aspx
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Can't access management interface via vpn connection

    Hi all,
    I can't seem to be able to manage my ASA 5510 when I connect via vpn. My asa sits at a remote colo, and from my office i can connect fine. I have it configured as management-access (dmz), bc as of now we are just doing some staging and all the servers are in the dmz interface.
    When i connect with the vpn client, in the routes it sees 192.168.1.0 255.255.255.0 which is the management network/interface.
    For some reason I can't get access to 192.168.1.1 to use the ASDM.
    Here is how i did my vpn via CLI
    isakmp enable outside
    isakmp identity address
    isakmp policy 10
    authentication pre-share
    encryption des
    hash md5
    group 2
    lifetime 86400
    ip local pool vpnpool 10.1.1.2-10.1.1.10
    access-list split_tunnel standard permit 192.168.200.0 255.255.255.0
    access-list split_tunnel standard permit 192.168.100.0 255.255.255.0
    access-list split_tunnel standard permit 192.168.1.0 255.255.255.0
    group-policy xxxxx internal
    group-policy xxxxx attributes
    dns value
    split-tunnel-policy tunnelspecified
    split-tunnel-network-list value split_tunnel
    username xxxxx password
    username xxxxxx attributes
    vpn-group-policy xxxx
    username xxxxxx password
    username xxxxxx attributes
    vpn-group-policy xxxx
    username xxxx password
    username xxxx attributes
    vpn-group-policy xxxx
    tunnel-group xxxx type ipsec-ra
    tunnel-group xxxx general-attributes
    address-pool vpnpool
    tunnel-group xxxx ipsec-attributes
    pre-shared-key
    access-list vpnra permit ip 192.168.200.0 255.255.255.0 10.1.1.0 255.255.255.0
    access-list vpnra permit ip 192.168.100.0 255.255.255.0 10.1.1.0 255.255.255.0
    access-list vpnra permit ip 192.168.1.0 255.255.255.0 10.1.1.0 255.255.255.0
    nat (inside) 0 access-list vpnra
    nat (dmz) 0 access-list vpnra
    nat (management) 0 access-list vprna
    crypto ipsec transform-set md5des esp-des esp-md5-hmac
    crypto dynamic-map dynomap 10 set transform-set md5des
    crypto map vpnpeer 20 ipsec-isakmp dynamic dynomap
    crypto map vpnpeer interface outside
    Any help would be much appreciated

    it seems like you are missing a line:
    management-access "interface"
    http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/m_711.html#wp1631964

  • How do I get connected to a server on my network via an IP address?  When I try to open in a URL and login as a registered user with proper login it errors out saying there was a problem with connecting to the server?

    I am new to Mac...How do I get connected to a server on my network via a hyper link IP address path?  When I try to open in a URL and login as a registered user with proper login it errors out saying there was a problem with connecting to the server?

    Some of the following is going to use some technical terms — this area is inherently somewhat technical. 
    If you don't understand some part of the following reply, please ask.
    Is this your own OS X Server system on your own network, or is this some other server within some larger organization? 
    You're posting this in the OS X Server forum, which is a software package that allows OS X systems to provide web-based and many other services; to become servers.
    If it's your OS X Server on your network, then the network and DNS configurations are suspect, or the server is somehow malfunctioning or misconfigured.   This is unfortunately fairly common, as some folks do try to avoid setting up DNS services.
    If it's a larger organization and somebody else is managing the server and the network, then you'll probably need to contact the IT folks for assistance; to learn the network setup and DNS requirements, and if there's a problem with the server itself.
    The basic web URL "hyper link IP address path" — without using DNS — usually looks something the following, where you'll need to replace 10.20.30.40 with the IP address of your server:
    http://10.20.30.40
    UptimeJeff has posted a URL that specifies the AFP file system; an OS X file share.  That's used if you're connecting to an Apple storage service somewhere on your network.  You might alternatively need to specify smb://10.20.30.40 or such, if it's a Windows file server.  (There can be additional requirements for connecting to Windows Server systems, too.)
    If there's local IT staff available here, please contact them for assistance.  If these are your own local systems and your own local OS X Server system, then some information on the server will be needed.  (If you're on a NAT'd network, you'll also need to get DNS services configured and working on your local OS X Server system and your network — you'll not be able to skip this step and reference ISP DNS servers here — or things can and usually will get weird.)

  • [Forum FAQ] How to install and configure Windows Server Essentials Experience role on Windows Server 2012 R2 Standard via PowerShell locally and remotely

    As we all know,
    the Windows Server Essentials Experience role is available in Windows Server 2012 R2 Standard and Windows Server 2012 R2 Datacenter. We can add the Windows Server
    Essentials Experience role in Server Manager or via Windows PowerShell.
    In this article, we introduce the steps to install and configure Windows
    Server Essentials Experience role on Windows Server 2012 R2 Standard via PowerShell locally and remotely. For better analyze, we divide this article into two parts.
    Before installing the Windows Server Essentials Experience Role, please use
    Get-WindowsFeature
    PowerShell cmdlet to ensure the Windows Server Essentials Experience (ServerEssentialsRole) is available. (Figure 1)
    Figure 1.
    Part 1: Install Windows Server Essentials Experience role locally
    Add Windows Server Essentials Experience role
    Run Windows PowerShell as administrator, then type
    Add-WindowsFeature ServerEssentialsRole cmdlet to install Windows Server Essentials Experience role. (Figure 2)
    Figure 2.
    Note: It is necessary to configure Windows Server Essentials Experience (Post-deployment Configuration). Otherwise, you will encounter following issue when opening Dashboard.
    (Figure 3)
    Figure 3.
      2. Configure Windows Server Essentials Experience role
    (1)  In an existing domain environment
    Firstly, please join the Windows Server 2012 R2 Standard computer to the existing domain through the path:
    Control Panel\System\Change Settings\”Change…”\Member of. (Figure 4)
    Figure 4.
    After that, please install Windows Server Essentials Experience role as original description. After installation completed, please use the following command to configure Windows
    Server Essentials:
    Start-WssConfigurationService –Credential <Your Credential>
    Note: The type of
    Your Credential should be as: Domain-Name\Domain-User-Account.
    You must be a member of the Enterprise Admin group and Domain Admin group in Active Directory when using the command above to configure Windows Server Essentials. (Figure 5)
    Figure 5.
    Next, you can type the password for the domain account. (Figure 6)
    Figure 6.
    After setting the credential, please type “Y” to continue to configure Windows Server Essentials. (Figure 7)
    Figure 7.
    By the way, you can use
    Get-WssConfigurationStatus
    PowerShell cmdlet to
    get the status of the configuration of Windows Server Essentials. Specify the
    ShowProgress parameter to view a progress indicator. (Figure 8)
    Figure 8.
    (2) In a non-domain environment
    Open PowerShell (Run as Administrator) on the Windows Server 2012 R2 Standard and type following PowerShell cmdlets: (Figure 9)
    Start-WssConfigurationService -CompanyName "xxx" -DNSName "xxx" -NetBiosName "xxx" -ComputerName "xxx” –NewAdminCredential $cred
    Figure 9.
    After you type the commands above and click Enter, you can create a new administrator credential. (Figure 10)
    After creating the new administrator credential, please type “Y” to continue to configure Windows Server Essentials. (Figure 11)
    After a reboot, all the configurations will be completed and you can open the Windows Server Essentials Dashboard without any errors. (Figure 12)
    Figure 12.
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

    Part 2: Install and configure Windows Server Essentials Experience role remotely
    In an existing domain environment
    In an existing domain environment, please use following command to provide credential and then add Server Essentials Role: (Figure 13)
    Add-WindowsFeature -Name ServerEssentialsRole
    -ComputerName xxx -Credential DomainName\DomainAccount
    Figure 13.
    After you enter the credential, it will start install Windows Server Essentials role on your computer. (Figure 14)
    Figure 14.
    After the installation completes, it will return the result as below:
    Figure 15.
    Next, please use the
    Enter-PSSession
    cmdlet and provide the correct credential to start an interactive session with a remote computer. You can use the commands below:
    Enter-PSSession –ComputerName
    xxx –Credential DomainName\DomainAccount (Figure 16)
    Figure 16.
    Then, please configure Server Essentials Role via
    Add-WssConfigurationService cmdlet and it also needs to provide correct credential. (Figure 17)
    Figure 17.
    After your credential is accepted, it will update and prepare your server. (Figure 18)
    Figure 18.
    After that, please type “Y” to continue to configure Windows Server Essentials. (Figure 19)
    Figure 19.
    2. In a non-domain environment
    In my test environment, I set up two computers running Windows Server 2012 R2 Standard and use Server1 as a target computer. The IP addresses for the two computers are as
    below:
    Sevrer1: 192.168.1.54
    Server2: 192.168.1.53
    Run
    Enable-PSRemoting –Force on Server1. (Figure 20)
    Figure 20.
    Since there is no existing domain, it is necessary to add the target computer (Server1) to a TrustedHosts list (maintained by WinRM) on Server 2. We can use following command
    to
    add the TrustedHosts entry:
    Set-Item WSMan:\localhost\Client\TrustedHosts IP-Address
    (Figure 21)
    Figure 21.
    Next, we can use
    Enter-PSSession
    cmdlet and provide the correct credential to start an interactive session with the remote computer. (Figure 22)
    Figure 22.
    After that, you can install Windows Server Essentials Experience Role remotely via Add-WindowsFeature ServerEssentialsRole cmdlet. (Figure 23)
    Figure 23.
    From figure 24, we can see that the installation is completed.
    Figure 24.
    Then you can use
    Start-WssConfigurationService cmdlet to configure Essentials Role and follow the steps in the first part (configure Windows Server Essentials Experience in a non-domain environment) as the steps would be the same.
    The figure below shows the status of Windows Server Essentials.
    Figure
    25.
    Finally, we have successfully configured Windows Server Essentials on Server1. (Figure 26)
    Figure 26.
    More information:
    [Forum
    FAQ] Introduce Windows Powershell Remoting
    Windows Server Essentials Setup Cmdlets
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

Maybe you are looking for

  • How can i send a playlist on itunes as a gift?

    how can i send a song to someone as a gift on itunes

  • PSE 6 on Mac crashes when opening photo files

    Got PSE 6 bundled with Intuos pen tablet.  Installed on iMac G3 running 10.4.11.  Installation went OK and program comes up OK, but when I attempt to open any photo file, the program crashes.  Any suggestions?  Thanks in advance! Joe

  • Using form editor in Adobe 9

    I am trying to use the builtin form editor in Adobe 9 for a basic fillable form.  Setting up the fields is no problem...actually the wizard took care of most of it for me.  I just needed to add a few radio buttons.  However, I would like to add a but

  • Line weight problem

    When I convert fonts to outline then export from CS5 AI or ID as a PDF I sometimes get distortion in vertical strokes ie. the letter L, where the line weight will appear bolder than the original font. The PDF will print showing the bolder line weight

  • IBooks 1.3 on iPod Touch 2G (4.2.1) dictionary not available for this language

    I have an iPod Touch 2G, running 4.2.1.  I also have iBooks 1.3.  Everything is running well, but unfortunately I do not have the built in dictionary for ebooks that I have bought on the iBooks store.  I have 14 books from their store, but I am not a