Wednesday, October 20, 2010

New SharePoint Resource Videos for Clients

From Mike Gannotti:

 

I have had two requests from a number of clients that I have started delivering to the web for general client access/re-use. The first came by way of last weeks Coffee Talk show. "Mike, I met you at ShareFest2010 Philly..I need to somehow sell the value of mysites on MOSS and upgrading to 2010 to mngmt..advice?"  [*ShareFest is the annual conference for clinical life science companies that I keynoted last year]. The other is one I have received from three separate clients in last month around building Knowledge Centers. I have uploaded the following for access via the links below. They will also be uploaded to http://www.seproductivity.com shortly where clients can also download them. Both address baseline capabilities that can help drive SharePoint deployment thereby providing a hedge against Google and other compete platforms.

·         Video: The Case for SharePoint MySites

·         Video: Building Enterprise Knowledge Centers 1 of 6

·         Video: Building Enterprise Knowledge Centers 2 of 6

For those clients who may have questions around MySites we will also be presenting this topic live as a part of this week’s Coffee Talk at 9am here http://www.seproductivity.com/Pages/Coffee-Talk.aspx

 


**********************  IMPORTANT--PLEASE READ  ************************
This electronic message, including its attachments, is COMPANY CONFIDENTIAL
and may contain PROPRIETARY or LEGALLY PRIVILEGED information.  If you are
not the intended recipient, you are hereby notified that any use, disclosure,
copying, or distribution of this message or any of the information included
in it is unauthorized and strictly prohibited.  If you have received this
message in error, please immediately notify the sender by reply e-mail and
permanently delete this message and its attachments, along with any copies
thereof. Thank you.
************************************************************************

How to Compare Software Products?

As a SharePoint Specialist,  I am frequently asked to compare products, e.g: SharePoint Vs. Documentum or SharePoint Vs. OpenText Livelink or between Workflow Tools,  When my customers are comparing applications, I recommend that they DO NOT do a direct features comparison. Features comparisons can take a substantial amount of time and provide very little information about each product’s suitability to the task, which is what the customer really needs.

Instead, I recommend that the customer put some time into generating a list (10-20) of use cases or usage scenarios that they need a product to enable. Once the customer has the list, the customer can now do a comparison between the products in the context of the use cases. This method provides a good way to see which product features are actually relevant to the customer’s needs and which features, while sounding good, are just fluff.

 

Once the customer has the product comparison in the context of the use cases (the functional comparison), the customer then needs to do a non-functional comparison between the products. The goal of the non-functional comparison is to determine the organizational impact of each product. For example,
* How does each product handle scaling, load balancing, fail-over?
* What backup / recovery models does each product support?
* How does each product handle security and identity management?
* To what extent does each product integrate with and extend the customer’s existing infrastructure (on-premises or hosted)?
* What resources (human and non-human) does the sustainment team for each product consist of?
* What are the associated costs of each product, both up-front and ongoing?

 

Combining the functional and non-functional comparisons of each product allows the customer to ultimately reach a value comparison between each product. The value comparison should be the determining factor in deciding one product vs. another.

 


**********************  IMPORTANT--PLEASE READ  ************************
This electronic message, including its attachments, is COMPANY CONFIDENTIAL
and may contain PROPRIETARY or LEGALLY PRIVILEGED information.  If you are
not the intended recipient, you are hereby notified that any use, disclosure,
copying, or distribution of this message or any of the information included
in it is unauthorized and strictly prohibited.  If you have received this
message in error, please immediately notify the sender by reply e-mail and
permanently delete this message and its attachments, along with any copies
thereof. Thank you.
************************************************************************

Monday, October 18, 2010

Farm Unavailable and incorrect credentials

I had a harrowing day at work; my password keeps getting locked everytime I do a SharePoint deployment and I had to do multiple deployments using stsadm commands. I had to change my password this morning when my password expired.

I error I was getting was: "The farm is unavailable" and in the Application event log: "Cannot generate SSPI context."

I figured, that the WFE was trying to log onto the SharePoint Database server and it wasn't able to do that. Almost all of the STSADM commands have to access the content database server. But I was lost for quite some time since I logged onto the WFE with my newer credentials and not sure where the older creds are picked up.

What I finally found out was one of the application pool running a SharePoint webapplication was using my credential as the identity account(where the password is not changed). When the stsadm command was running it will use the app pool account, so its trying to use the wrong crentials and after three retries the account is locked. It is really a bad practice to have an application pool running a personal account than a service account. I paid a price of two to three hours for this.

Wednesday, September 22, 2010

RE: Secure Token Service Basics

Just what is an STS anyway:

A Security Token Service (STS) is the plumbing that builds, signs, and issues security tokens using the interoperable protocols.

 

Difference between Active STS and Passive STS:

 

Active STS mode

Passive STS mode

Definition(sort of)

In Active Federation your Relying Party (RP) has its login window (web page) and asks the STS for security token. "Active" to anything capable of using WS-Trust which is the protocol you use to obtain a token from an STS.

Passive Federation is when Relying Party (RP) does not have a login page and redirected to the login page located on STS. Since Web browsers cannot directly make SOAP calls they dumbly redirect to an STS and get the tokens.

Examples

Web Services/WCF

web applications(ASP.NET)

Hosting

Self-hosted / IIS

IIS/or any web server.

What protocol is involved?

WS-Trust protocol

WS-Federation passive protocol.

 

The lack of SOAP capabilities forced some creative solution for "emulating" WS-Trust on top of GET, POST and cookies: the result is the above mentioned dance of redirects, where the browser goes back & forth between previously established addresses on the resource and requestor domains and using cookies for communicating authentication information. THIS is what is meant by passive federation.

 

 

 

 

http://blogs.msdn.com/b/vbertocci/archive/2008/06/05/active-passive-and-passive-aggressive.aspx


**********************  IMPORTANT--PLEASE READ  ************************
This electronic message, including its attachments, is COMPANY CONFIDENTIAL
and may contain PROPRIETARY or LEGALLY PRIVILEGED information.  If you are
not the intended recipient, you are hereby notified that any use, disclosure,
copying, or distribution of this message or any of the information included
in it is unauthorized and strictly prohibited.  If you have received this
message in error, please immediately notify the sender by reply e-mail and
permanently delete this message and its attachments, along with any copies
thereof. Thank you.
************************************************************************

Tuesday, September 7, 2010

View PropertyBag using SharePoint Designer

The Property Bag Settings can store any metadata as Key-Value pairs such as connection strings, server names, file paths, and other miscellaneous settings needed by your SharePoint application.

In SharePoint Designer: To view the property bag. Go to Site -> Site Settings. Then click on the Parameters tab (not sure why they didn't just call it Property Bag). On this tab, you can see the values of all of your custom property bag values (it doesn't show anything built-in). If you need to, you can also modify and remove values from the property bag here. Hopefully this tip is useful sometime in the future when you need to check the values of your property bag. It sure beats the alternative of writing code to display it or firing up the debugger.

There is also a CodePlex project that adds a page in central admin to set the property bag at various levels(server,farm, webapp, site collection)
http://pbs.codeplex.com/
This one for SP2010:
http://pbs2010.codeplex.com/

Thursday, September 2, 2010

Cancel a blocked SharePoint Jobs

If a SharePoint solution deployment fails, yet the timer job is created and not running, you will be unable to redeploy or retract the solution. The retract / deploy buttons will not be present in Central Admin and stsadm will declare that a "deployment or retraction is already under way for the solution". You can find yourself in this state if the “Windows SharePoint Services Administration” service is stopped when you first attempt to deploy, but even after you realise your mistake and start that service, the solution deployment is still stuck.
The answer is hidden in that long list of stsadm operations:
use the stsadm -o enumdeployments to get a list of running jobs and the id's and then use the
stsadm –o canceldeployment –id

This command will cancel the timer job that is meant to deploy the solution. Once it has been cleared, you can deploy successfully. Obtain the id parameter from the url to the appropriate deployment timer job in the Operations -> Timer Job Definitions page

Monday, July 19, 2010

Get the List of users in an AD group

1.       First get the AD path of the object you are trying to the members:

dsquery * -filter (cn=WWAPP-A-CPAAZDashboard)

You can even do like this: dsquery * -filter (userPrincipalName=user123*) or dsquery * -filter (cn=computername)

 

2.       Use the dsget and pass in the path:

dsget group "CN=WWAPP-A-CPAAZDashboard,OU=Groups,OU=WWCRO,OU=WorldWide,DC= companyname,DC=net" -members

3.       Now you can pipe the result of this command to another dsget to get the other AD attributes; Final command:

dsget group "CN=WWAPP-A-CPAAZDashboard,OU=Groups,OU=WWCRO,OU=WorldWide,DC=companyname,DC=net" -members | dsget user -samid –display

 **********************  IMPORTANT--PLEASE READ  ************************ This electronic message, including its attachments, is COMPANY CONFIDENTIAL and may contain PROPRIETARY or LEGALLY PRIVILEGED information.  If you are  not the intended recipient, you are hereby notified that any use, disclosure, copying, or distribution of this message or any of the information included in it is unauthorized and strictly prohibited.  If you have received this message in error, please immediately notify the sender by reply e-mail and permanently delete this message and its attachments, along with any copies thereof. Thank you.  ************************************************************************