Friday, August 22, 2014

Configuring Office365 on difficult XP computer

This entry will have no value to anyone else.  It's a specific situation for my own notes.  On the computer named Vostro1500-INTE, the Outlook 2010 has consistent trouble with configuring the Office365 account.


















I tried all these things.
  • Create new mail profile
  • Setting the login/email address to username@domain.onmicrosoft.com
  • Set DNS servers to 8.8.8.8 instead of internal DNS
  • Create and connect to VPN without split tunnel


In the end, I found that the fix was to 1) create a new Windows profile and 2) disable the crappy Trend Micro antivirus.  Of note, I recreated the profile at first wihtout disabling AV and I had trouble configuring email - so perhaps disabling the AV was necessary.

Sunday, August 10, 2014

Using a Windows Server as an authenticated relay server to Office365

If you've got an on-premise device that doesn't support TLS and you're on Office365 (or other outsourced Exchange), you're in a bind.  Most of the info here comes from this article:

http://www.configureoffice365.com/configure-office-365-smtp-relay/

I'm copying and pasting parts of it below, simplifying parts, and adding my own hints.  This presumes Windows Server 2008.  Some Windows 2012 steps are here.

Part 1 - Add IIS if not already installed

  1. In Server Manager, select Add Roles.
  2. On the Select Server Roles page, select Web Server (IIS) and select Install.
  3. Select Next until you get to the Select Role Services page.
  4. In addition to what is already selected, make sure that ODBC Logging, IIS Metabase Compatibility, and IIS 6 Management Console are selected and then select Next.
  5. When you’re prompted to install IIS, select Install. You may need to restart the server after the installation is finished.
Part 2 - Install SMTP

  1. Open Server Manager and select Add Features.
  2. On the Select Features screen, choose SMTP Server. You may be prompted to install additional components. If that’s the case, select Add Required Features and select Next.
  3. Select Install. After the installation is finished, you may have to start the SMTP service by using the Services snap-in for the Microsoft Management Console (MMC).
Part 3 - Add TLS certificate

  1. Office 365 requires TLS encryption and for this server to use TLS, it must have a certificate installed. 
  2. In order to do this the Web Server (IIS) role and IIS Management Console must be installed (needs to be added via Server Manager -> Add Roles).  
  3. To create the self-signed certificate: (Start->Administrative Tools->Internet Information Services (IIS) Manager->Select Host->Server Certificates->Create Self-Signed Certificate)
Part 4 - Configure SMTP server relay

  1. Start->Administrative Tools->Internet Information Services (IIS) 6.0 Manager.
  2. Click on the ‘+’ next to your host name.
  3. Right-click on the [SMTP Virtual Server…] and select Properties. It’s now time to step through each of the tabs to configure the SMTP relay.
  4. General Tab: The IP address should be set to (All Unassigned)
  5. Access Tab: Click Authentication… and select the Anonymous access check box.
  6. Access Tab: Click Connection… Select ‘All Except the list below’ and leave the list below blank. This allows any device inside your firewall to access this relay.
  7. Access Tab: Click Relay… Select ‘All Except the list below’ and leave the list below blank. This allows any device inside your firewall to access this relay.
  8. Messages Tab: No changes. The default works well.
  9. Delivery Tab: Click Outbound Security… Select Basic authentication and enter the username and password that is used to send e-mail to the external server (Office 365 in this case). The user name must be a fully qualified (ex: user@companyname.com) valid Office 365 user licensed for Exchange. Check TLS encryption.
  10. Delivery Tab: Click Outbound connections… Set the TCP port to 587.
  11. Delivery Tab: Click Advanced Delivery and set the Fully-qualified domain name box to the name of the local server that is acting as the relay (ex: myserver1.domain.local). Set the Smart host the full-qualified name of the Office 365 SMTP Server (as of 8/6/14 - this is smtp.office365.com in all cases). Make sure the “Attempt direct…” box is unchecked.
  12. LDAP Routing and Security Tabs: No changes to these areas.
  13. Now there has to be a remote domain setup with the Office 365 domain name in it. Click the ‘+’ next to the [SMTP Virtual Server…] item
  14. Right-click on Domains and select New-Domain which will launch a Wizard.
  15. Select Remote and Next.
  16. Enter the name of the Office 365 vanity domain (ex: mycompany.com)
  17. Now this remote domain will be setup very similarly to the overall SMTP server. Right-click on the new domain name and select Properties.
  18. Select Forward all mail to smart host and enter the same Office 365 SMTP Server as above (ex. smtp.office365.com)
  19. Click on Outbound Security and configure the same as above. Select Basic authentication and enter the username and password that is used to send e-mail to the external server (Office 365 in this case). The user name must be a fully qualified (ex: user@companyname.com) valid Office 365 user licensed for Exchange. Check TLS encryption
  20. Repeat steps 14 through 19 where step 16 is *.com for the domain
  21. Repeat steps 14 through 19 where step 16 is *.org for the domain
Part 5 - Configure the on-premise device
  1. Configure the on-premise device (copier, phone system, etc) with the IP address for the Windows server you have been working with as the SMTP server
  2. For email address, enter the same address you entered in Part 4 step 9
  3. Use port 25 and no authentication of any kind and no SSL or any other kind of encryption
Troubleshooting tips
  • Make sure the firewall on the Windows server allows connections on port 25.  A good test is "telnet 10.0.0.18 25" where 10.0.0.18 might be the IP address of the server you're using as the relay
  • I've seen instances where the first emails can take up to 90 minutes to relay.  I cannot explain this.  But it is true.
  • As a test, try using Windows Mail or Outlook as a test mechanism.  If it succeeds through your test program, it's just a matter of configuring your device (copier, etc) properly
  • On the relay server, there can be error messages located here if things aren't coming through after 90 minutes - C:\inetpub\mailroot\Badmail

Wednesday, July 30, 2014

Keyboard shortcuts to rotate the laptop screen

You can use the keyboard shortcut of control-alt and the arrow keys to alter the rotation of a laptop screen.  This is most valuable when users accidentally rotate their screens . . . where you can return the screen to normal orientation via:

Control - alt - UP arrow

If you wanted, you could rotate the screen using these keyboard shortcuts:

Control - alt - UP arrow - 0 degrees
Control - alt - RIGHT arrow - 90 degrees
Control - alt - DOWN arrow - 180 degrees
Control - alt - LEFT arrow - 270 degrees


Friday, July 25, 2014

Increasing the size of Hyper-V virtual disk on Win 2008 R2

I had to increase the size of a virtual machine on a Windows 2008 R2 host.  I'd go to the settings of the VM and click on "edit" would be greyed out when attempting to edit the hard drive size.  It looked like this.






















I needed to do three things to resize the disk:
1) shut down the VM
2) Delete all the snapshots of the VM
3) Let the VM merge itself to all previous snapshots - see this

It can take minutes or hours for the merge (#3 above) to take effect.

After the merge has taken place, you can increase the size of the disk and then you'll need to extend the size of the hard drive within Windows of the VM:


Monday, July 14, 2014

Moving Legacy X.500 addresses to Office 365 from on-premise servers

I migrated from SBS 2003 to Office365, but I didn't use one of the standard method.  I recreated the users in the cloud and impored PSTs via Outlook.  This works fine except for the problem with internal routing where internal addresses use X.500 addresses and generate NDRs when sending to internal staff.

This is a helpful article on using the NDR text to create the X.500 address, though I found its instructions not quite right.

http://support.microsoft.com/kb/2807779

In my case, I found a slight adjustment needed to make it work.

Let's say you're getting an NDR that says:
IMCEAEX-_O=DOMAIN_OU=FIRST+20ADMINISTRATIVE+20GROUP_CN=RECIPIENTS_CN=JSMITH@namprd07.prod.outlook.com

For the user jsmith, create a new Exchange email address with a type of X500 (no period in the type - it is X500 not X.500), and enter the value with adjustments as suggested by MS in the article above:
Replace any underscore character (_) with a slash character (/).
Replace "+20" with a blank space.
Replace "+28" with an opening parenthesis character.
Replace "+29" with a closing parenthesis character.
Delete the "IMCEAEX-" string.
Delete the "@mgd.domain.com" string.
Add "X500:" at the beginning.

It looks like this.  It takes 5 to 10 minutes or so from when you add the email alias until it works, but it does work when you do it.



As an example, I turned this:

IMCEAEX-_o=ExchangeLabs_ou=Exchange+20Administrative+20Group+20+28FYDIBOHF23SPDLT+29_cn=Recipients_cn=e0c06d4eee7e4ec8b8a38d105ca7793c-joe@namprd08.prod.outlook.com

into this:

/o=ExchangeLabs/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/cn=e0c06d4eee7e4ec8b8a38d105ca7793c-joe


In the case above, I moved an Exchange mailbox from one account to another (via exporting the old mailbox to PST and importing into a new mailbox on a new account).

Friday, July 4, 2014

installing Postfix on Ubuntu as an internal mail server

I had a client who wanted to have an internal email server for sending outbound emails.  This email server would be used for sending scans (via scan to email) where the copier didn't support TLS and the email server required TLS and also for email blasts (where users send out mass emails via a local software program like WorldCast).

I successfully implemented Postfix running on Ubuntu.

These directions (relevant on 7/3/14) and derived from here:
https://www.digitalocean.com/community/tutorials/how-to-install-and-setup-postfix-on-ubuntu-12-04

This will allow you to configure any local mail client to send out unauthenticated emails from these subnets:
192.168.0.0
192.168.1.0
192.168.2.0
192.168.3.0

Just set the SMTP server as the with the IP address of the Ubuntu machine (preferably a virtual machine).

Create a new virtual machine with 2 GB of RAM and 30 GB of HD space.

Download and install Ubuntu Linux from here (964 MB):
http://www.ubuntu.com/download/desktop/thank-you/?version=14.04&architecture=amd64

Once installed using all logical defaults, click the search button in the top of the toolbar and type terminal and run the terminal

Run this:
sudo apt-get install postfix

During the installation, you will see a dialogue box appear, asking you which kind of installation you would prefer. Select “Internet Site”.

For domain name, enter:
domainname.com
(where domainname.com is your domain name - though in truth this is irrelevant)

Once Postfix is installed there are a few steps that need to be taken before it is fully functional.

Once Postfix is installed, go ahead and open the main configuration file.
sudo nano /etc/postfix/main.cf

There are a few changes that should be made in this file.
myhostname = domainname.com

Change this value:
alias_maps = hash:/etc/postfix/virtual
to this value:
virtual_alias_maps = hash:/etc/postfix/virtual

For the value, my networks, add a space and then this value:
192.168.0.0/22

So it looks like this:
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 192.168.0.0/22

The rest of the lines are set by default. Save, exit, and reload the configuration file to put your changes into effect:

sudo /etc/init.d/postfix reload


Of note - this is an outbound only email server.  Separately, you need to make sure you can send out on port 25 (via your firewall and ISP) and that you're not violating any SPF records with this server (or you may need to adjust SPF records).  

Thursday, July 3, 2014

Speed test that doesn't require Flash

When I'm running a speed test on a server, I'm often in a small bind as I can't run my standard tests at www.speakeasy.net/speedtest or www.speedtest.net since most servers don't have flash and it's typically an obstacle to install it.

I found an HTML 5 speed test at www.speedof.me which works just fine, which works just fine on Firefox, which is typically my default browser.