Showing posts with label wwa. Show all posts
Showing posts with label wwa. Show all posts

Friday, July 8, 2011

I’m Not Done Flip-Flopping on My Done with Flip-Flopping Flip Flop, OK?

One thing we, all one of us, can agree on, is that I’m not wired correctly.  Part of me is wired with sticks and mud, the rest with duct tape, condoms and beer bottle caps.  I’m all conductive though, trust me.  I just don’t conduct finances well.  I’m more of a fiscal insulator actually, but that’s a story for another year.

So, I drove a stake through WWA and pronounced it dead.  I turned to walk away, in slow motion of course, complete with dramatic movie music, only to have it spring to life and attack me blind.  I got it into a LAPD choke hold, wrestled it to the ground, placed its teeth on the curb and applied a Ed Norton American History-X stomp to it, but it still came to life, and grew additional arms, legs and eye balls as well.

To be fair, I never said the project itself was going to die.  I said it was not going to be maintained online, for public consumption.  It’s very much alive and well in multiple production environments, and therefor gets a daily dose of loving, feeding, and moral support.  As of today, it’s up to build 2011.07.08.002 and contains over two dozen additional features since 2011.05.13.001, the last public release before yanking the project from SourceForge.

To help out a few die-hard supporters and have an easy-to-access repository from almost anywhere, I returned the .zip download to my Google Site (http://sites.google.com/site/skatterbrainz) under the Downloads section.  If you care to keep up with its progress you can either visit it when you really bored, or add an RSS feed from the page to whatever RSS feed reader you prefer.  Cheers! Chou! Bon Voyage! Danka!  Arivadouche!

Wednesday, June 29, 2011

Done Flip-Flopping

I apologize for the flip-flop waffling insanity over WWA.  I submitted a formal request to SourceForge to nuke the project.  It will be no more.  2011 will be a watershed year for me and my family and this is like step one.  Even if I’m a little late to the party.  Just sayin.  I’m sure that this post makes absolutely no sense to anyone whatsoever.  That’s ok.  Neither did I.

Thursday, May 19, 2011

Windows Web Admin - Decision Time

After a week of Tech-Ed immersion, I have decided to pull the plug on Windows Web Admin.  It's been fun, but there is clearly no need to continue work on this project.  Especially in light of Config Manager 2012 features and changes to everything from the UI to the underlying SQL environment.  To the handful of you that have offered feedback and supportive comments: thank you!

Friday, May 13, 2011

Windows Web Admin Update

I posted build 2011.05.13.001 tonight.  This is a fairly big release with quite a few changes.

I'm not going to post any new builds for at least the next week, while I'm off at Tech-Ed in Atlanta.  I will form a decision over that week as to whether it makes sense to continue this project or kill it.  I've heard from a few people over the past month, but overall it seems the only person that needs something like this is me.  I may continue working on it for my own needs, but I'm not sure it will have a place on the Internet after today.  I will decide next week and post an announcement afterwards.

What's new in 2011.05.13.001

  • Role-based Access Control
  • SCCM Collection Report updated

2011.05.13.001.home

Role-based Access Control (or RBAC for you acronym nutballs) involves controlling access to features based on the user being in a list of specific AD user account names.  There are two lists: adds_admins, and sccm_admins.

If a user's ID is entered into the adds_admins list, they will see the "Add", "Disable", "Enable", and "Remove" buttons and links for user and group reports.  If a user is entered into the sccm_admins list, they will see the buttons for adding computers into collections, and removing computers from collections.  If a user is not in one or both groups, they can still view the report details, but won't have access to make modifications via the web interface.

The SCCM Collection report now shows any Advertisements targeted at the collection, including the Package and Program Name information.  The advertisements are cross-linked to the Advertisement details report, as is the Package to the Package details report, so everything is linked up.

Future Plans

Since I've received almost no requests for enhancements, I will follow my own needs from here on out.  So, what exactly am I saying?  I guess I'm saying it could very well go offline and return to an in-house project.  It started as an in-house incubator for other projects, which have grown as a result of borrowing pieces of WWA for other uses.  What are some features I may work on?

  • Create new SCCM Collections
  • Assign SCCM Advertisements to Collections
  • Modify Collection Properties
  • Create Packages, Programs, Advertisements
  • Reset AD User Account Passwords
  • Add and Remove Computers in AD Groups
  • Disable or Enable Computer Accounts

Ambitious?  Absolutely.  Likely?  Who knows.  As with most projects, the features that end up materializing are driven by tactical need, so the list of changes might look entirely different.

Then there's the other option: I could discover an off-the-shelf product, or another open source (or freeware) project that does this as well, or does it better.  If any of these options appear, it might spell the end of WWA entirely.  I will find out next week.  So for now, build 2011.05.13.001 is the latest and final build I will post.  It may also be the absolute last build.

DOWNLOAD WWA build 2011.05.13.001

Monday, May 2, 2011

Windows Web Admin build 2011.05.02.001

This will be the last build update for a while I think.  I'm quickly running out of free time and will have to put this on hold for at least a few weeks or a month or so.  This update includes quite a lot of changes and enhancements.  I've added several new Active Directory reports and a new page just for those (like I did earlier with the SCCM reports).  Among the changes:

1. Moved AD reports to their own page

2. Added new AD reports

3. Modifed AD FSMO report to link over to computers report

4. Users report shows icon for "user" versus" contact rows

5. User details now shows GUID values

6. Added Contact details

7. Renamed "Reports" to "SCCM Reports"

https://sourceforge.net/projects/wwadmin/

Friday, April 29, 2011

Windows Web Admin - Application Settings

This is a quick settings guide to help you configure WWA to work with your environment.  Please refer to the IIS7 configuration instructions I posted yesterday first.  This guide is essentially a "part 2" for getting WWA up and running.

All of the application settings are found in the "_settings.asp" file in the main WWA folder.  Open it with Notepad or any text editor (not Microsoft Word!) and you can easily modify the settings and save it.  Changes are applied immediately upon saving the file.

Most of the settings are identified as standard variables but will have a "Const" statement in front of them, which indicate a non-changing value.  By that, I mean that once the variable is defined and assigned a value, it cannot be modified during the runtime of the application by any other pages within the site.  Ok, then.  On to the setting descriptions…

BASIC GLOBAL SETTINGS

siteActive = True / False

This puts the site into normal operational mode.  If you need to take the site offline or the SCCM database and don't want people using WWA for a period of time, set this to "False" and it will instead display a "come back later" page.  The default setting is True.

showGetStarted = True / False

This setting enables or disables the display of the 'Getting Started' links from the main home page.  To hide them, set this to False.  The default setting is True.

enableADtools = True / False

This setting enables or disables the Active Directory features of WWA.  If you set this to False, no Active Directory related links will be shown on the sidebar.  That will also hide the AD Quick Search section of the main home page as well.  The default setting is True.

enableCMtools = True / False

This setting enables or disables the System Center Configuration Manager 2007 features of WWA.  If you set this to False no links for SCCM features will be displayed on the sidebar or the main home page.  The default setting is True.

CONFIGURATION MANAGER SITE SETTINGS

SWBEM_Security = "EXPLICIT" or "IMPLICIT"

This setting controls how SWBEM provider connections are established with the SCCM host when performing modification operations (adding or removing Collection members, for example).  When set to "EXPLICIT", it will submit a specific USERNAME and PASSWORD combination with the connection request.  In order for this to be useful, you must also configure the SWBEM_USER and SWBEM_PASS variables.  If set to "IMPLICIT", it will attempt to establish the provider connection using the credentials of the IIS application pool.  The default setting is "EXPLICIT".

SWBEM_User  = "username"

This setting is used when SWBEM_SECURITY is set to "EXPLICIT" and defines the user account name to be submitted for SWBEM provider connections to the SCCM site server.

SWBEM_Pass = "password"

This setting is used along with SWBEM_USER when SWBEM_SECURITY is set to "EXPLICIT" and defines the user account password to be submitted for SWBEM provider connections to the SCCM site server.

SMSSiteCode = "AAA"

This is the three-character SCCM site code label to identify the scope of interfacing with SCCM.

SMSServer = "servername"

This is the name of the SCCM site server.

SMSDomain = "domain"

This is the Active Directory domain name in which the SCCM site server exists.  This is typically the NetBIOS name, not the FQDN value.

SCCM_WebReports = "http://[siteserver]/SMSReporting_" & SMSSiteCode

This is the URL to your SCCM Reporting Point host where links to Web Reports will be referred for certain features in WWA.  Include the URL up to, but not including the site code label, or replace the entire value to include the full URL to the base location (including the site code) if you prefer.

DATABASE CONNECTION SETTINGS

dbServerName = "servername"

This is the NetBIOS name of the SQL Server host for the SCCM site.

dbDatabase = "SMS_ABC"

This is the name of the SCCM site database on the SQL Server host.  This will usually be "SMS_" combined with your three-character site code.

dbUsername = "username"

This is the SQL or Active Directory user account name which has appropriate permissions within the SQL Server SCCM site database.

dbPassword = "password"

This is the corresponding password for the dbUSERNAME account defined above.

Note: Do NOT modify the "dsn = " code segment that appears below this.  It is concatenated from the other settings to generate the appropriate SQL connection string at runtime.

ACTIVE DIRECTORY SETTINGS

ldapRoot = "LDAP://DC=contoso,DC=local"

This is the base LDAP distinguished name value for the root of the domain in which you wish to manage with WWA.

ldapSchema = "LDAP://CN=Schema,CN=Configuration,DC=contoso,DC=local"

This is the default schema partition LDAP reference for the same domain identified by the ldapRoot setting above.

AD_DNSname = "contoso.local"

This is the DNS domain name label for the same domain identified by the ldapRoot setting above.

AD_Username = "username"

This is the name of an AD account which has appropriate permissions to view and modify Active Directory user accounts, contacts, and security groups in the target domain.

AD_Password = "password"

This is the corresponding password for the AD user account define above.

maxUserPwdAge = 90

This is the default password expiration allowance (in days).  The default setting is 90.  This is used to calculate days until a user account password expires.

MESSAGING SETTINGS

Note: This feature is not yet enabled but will be enabled in a future release.

enableMessaging = True / False

This option turns SMTP message handling features on or off.  The default setting is True.

useGmail = True / False

This option sets the default SMTP relay host to use Google Mail (Gmail).  The default setting is False.

mailServer = "server.fqdn.name"

This is the FQDN identifier for the SMTP relay host to route outgoing e-mail messages from WWA.  If you wish to use an internal SMTP host, enter the appropriate FQDN name for the server.  If you wish to use Google Mail, enter "smtp.gmail.com".

cdoSendUsingPickup = "local-folder-path"

This is an optional path setting to support adding attachments to outgoing e-mail from within WWA.  I'm not sure I'm ever going to make use of this.  I could, but I'm not sure why I would.  The default setting is "c:\inetpub\mailroot\pickup".

mailUser = "username"

This setting specifies the user account to use for connecting to the SMTP server for sending messages.  For most internal SMTP relay requests, this is left blank ("").  For Gmail however, you must specify a valid Google account name.  The default setting is "".

mailPwd = "password"

This is the corresponding password for the mailUser account defined above.  For most internal SMTP relay requests, this is left blank ("").  For Gmail however, you must specify a valid Google account password.  The default setting is "".

MISCELLANEOUS SETTINGS

timeBias = nnn

This is the default time zone offset value for use when calculating Active Direct and SCCM date/time values which are time-zone related.  The default setting is 300.

Thursday, April 28, 2011

Windows Web Admin build 2011.04.28.001 posted

I apologize for pestering the **** out of you with so many constant updates, but as I've had a few minutes here and there to free my brain to work on this a little I've been trying to cross off my "to-do" list.  I've had many of these finished from other past projects but haven't had time to scrape the goodies out of old files, dust them off, clean-up and refactor the code to fit into my latest mindwarp vision of bit-mashing misery.  That's a long way of saying that I had to grab some very old code, clean it up and fit it into this project.  Someday I know that I will need to stop and refactor this entire project.  I'll be honest: some of the code is a bit stupid looking and inefficient.  I know this.  So if you're looking at it and shaking your head, relax.  Drink a few beers and it will start looking really awesome.  Especially after a case of beer.

https://sourceforge.net/news/?group_id=531017

Latest changes:

  • SCCM reports have been moved from the home page sidebar to their own "reports" page
  • Three new SCCM reports have been added:
    • Windows 7 Readiness Summary (with tabulated results at the bottom) per Collection
    • Obsolete Client Records
    • Unassigned Client Records
  • You can now add an AD user account to multiple AD groups
  • You can now add multiple AD user accounts to a single AD group
  • You can now remove an AD user account from multiple AD groups
  • You can now remove multiple AD user accounts from a single AD group
  • The Network Adapter report had a small bug that I fixed (report6.asp

I recently posted an instruction guide on how to set up WWA on IIS7 using an Application Pool so it can run properly under a protected user context (helps with AD management features).  You can access that here: http://skatterbrainz.blogspot.com/2011/04/setting-up-windows-web-admin-on-iis7.html

Download the latest build here --> http://sourceforge.net/projects/wwadmin/files/wwa.zip/download

Enjoy!  It's still FREE.  I do it because it keeps my brain from melting down.

Setting up Windows Web Admin on IIS7

I should have posted this much sooner, but here goes.  This is a quick how-to procedure for installing and configuring the IIS side of things.  I'm using Windows Server 2008 R2 and IIS7, but this is pretty similar for Windows Server 2008 as well.

IIS Configuration Procedure

1. Download the wwa.zip file and extract it to a folder on your IIS host server

2. Open IIS Manager

3. Expand the Server object

4. Right-click Application Pools, select Add Application Pool…

SNAGHTML7d638f3

5. Enter a Name for the new pool (leave other defaults alone), click OK

SNAGHTML7d4f9a2

6. Right-click on the new Application Pool, click Advanced Settings

SNAGHTML7d887ae

7. Select the ellipses (…) next to the Identity setting…

image

8. Select "Custom account", and click the "Set" button

9. Enter an account (with sufficient account management rights), and the password…

image

10. Click OK, click OK again and again to return to IIS Manager.

11. Expand Sites, right-click "Default Web Site" and select "Add Application"

SNAGHTML7dd5eac

12. Enter the Alias, and select the Physical Path, and click OK

image

13. Double-click Authentication

image

14. Disable "Anonymous Authentication" and enable "Windows Authentication"

image

15. Right-click on the web application object (e.g. "wwa") in the left-hand panel, and select "Manage Application" / "Advanced Settings…"

image

16. Change the Application Pool setting to "WindowsWebAdmin" and click OK

image

17. Click OK and close IIS Manager

You should be good to go.  To test, open your browser and navigate to the appropriate URL.  Once opened, click the "About" link at the bottom of the home page.  Under the "Web Server" section, verify that Authentication Mode is "CONTROLLED" and that your domain account is shown for the REMOTE_USER value.

WWA Build Update

I have another build coming soon.  Some of the changes:

  • SCCM reports moved from sidebar to their own page (reports.asp)
  • Three New Reports being added
  • More features for AD user and group management (enable/disable, add/remove, etc.)

Tuesday, April 26, 2011

Windows Web Admin 2011.04.26.001

A new build of WWA has been uploaded to SourceForge.  This one adds a new report to the main sidebar (filename: report7.asp).  This report adapts the SQL code used by one of the SCCM Windows 7 Readiness web reports and adds a summary tabulation at the bottom.  The target collection can be selected from a drop-down list at the top-right of the report page.  Give it a try and let me know how it works for you.

https://sourceforge.net/projects/wwadmin/

Friday, April 22, 2011

Windows Web Admin: Moving to a New Location

I've created a space for this project on SourceForge.net.  It will be removed from my downloads page and from now on will be maintained here:

https://sourceforge.net/projects/wwadmin/

Windows Web Admin: Build 2011.04.22.001

Minor bug fixes.  Unless I hear more feedback, this is it.  I'm not actively pushing any new features into this.  By the way, if you find this same app on SourceForge - that one is out of date.  I will try to update it as well.  Download it here.

Tuesday, April 19, 2011

Windows Web Admin: build 2011.04.19.001

Based on popular demand, I finally had a few minutes to add one more feature.  Not only can you add a computer to multiple collections - you can now add multiple computers to a selected collection.  It's like two great things in one!  For the price of, uhhhh…. zero?  Ok, popular demand really means one person: Christian.  I hope this helps!  I'll celebrate this as being the FIRST and ONLY feedback submittal.  Congratulations!

Download build 2011.04.19.001

Friday, March 18, 2011

WWA Code Freeze - Part 2

I'm so wishy-washy at times.  No, but seriously, I had to shove one more out because there were some annoying bugs I had to fix and I wanted to get one more AD-to-SCCM feature link done (jumping from AD computer details to the SCCM details, required a query to fetch the ResourceID from the sAMAccountName value.  Not a big deal really, but I wanted to finish that along with the other adjustments).

So, build 2011.03.18.001 has been posted and will be "frozen" until further notice.  It may be a while before I jump back on this, and even the prospect of picking it back up will depend on feedback.

Thursday, March 17, 2011

Code Freeze

I've decided to freeze development of WWA for a while.  I'll wait for feedback of any constructive nature before doing any more work on it.  I'm at a crossroads right now.  I could go much farther or simply stop, but without some kind of input there's no point in pushing ahead right now.

Tuesday, March 15, 2011

Managing Windows, AD and SCCM via the Web?

Yeah, yeah yeah, whatever.  I'm not going to blow my horn anymore, f*** that.  The horn is broken anyway and all I usually blow is hot air.  But sometimes, just sometimes, I can whistle a tune.  In any case, I thought I'd post something fairly relevant today:

Someone asked me (offline of course, the way I HATE it.  I'd rather get feedback via the site so others can see the back-and-forth, and thereby bore themselves to sleep without me having to retype it all, but whatever, on with it…) they said

"Hey Dave.  Why would I want to manage AD or SCCM through a web browser?"

I responded with one word: "Mobile"

And like David Caruso, I shoved my imaginary sunglasses up on my nose and turned to walk away.  If only there were a door in that direction.  Ouch!

It got him thinking though.  I had to demonstrate it on my crappy little Blackberry (that makes for a crappyberry I suppose).  Bring up the web app from the SSL connection, authenticate, and voila!  WWA interface is smiling back at me (through the pinhole screen on my crappyberry).  View collections, packages, programs, advertisements, sites, site boundaries, distribution points, distribution point groups, drill-down into computers and view inventory data, linked over to the user account reports pulled seamlessly from AD, including phone, email, department, all the groups the user is a member of, other users in that department, other users with the same computer model, same operating system and service pack, all the non-windows resources in AD which aren't discovered by SCCM, and on and on and on…

blah blah blah blah.

But you know what the best part of this is?  Nobody.  And I mean NO-BODY is interested.  It's a short-lived one-trick dog.  The March 31 date is being moved up to Saturday, March 26.  No reason to drag this poor decrepit beast around in the mud longer than it needs to.  Oh well, it's been fun building it.

Dave "I can't wait to upgrade my phone" Stein

P.S. I adopted that closing from Ned Pyle, one of my heroes.

Monday, March 14, 2011

WWA Project Web Site is up

https://sites.google.com/site/skatterbrainz/windows-web-admin

WWA Development Notes

Some notes about the current WWA project:

  1. I have no plans on adding the ability to modify SCCM site options.  Those are maintained in the site control file (SCF) and interfacing with that via a web interface, while it can be done, would require more time and effort than I want to devote to it (being a free project and all that).  This goes for site boundaries, senders, discoveries and so on.  I may do something with site status summarizers and alerts, but I'm not sure yet.
  2. The interfaces to Active Directory from a web platform are somewhat limited, and that's by design.  I understand the logic and rationale behind that actually.  Querying AD is one thing, but executing changes to it from the web is a bit different, at least from "classic" ASP.  I really don't enjoy coding with ASP.NET, and haven't had a reason to consider MVC or something off the wall like PHP or Ruby or their .NET variants either.  It's ASP or nothing for now.
  3. The scope of features and capabilities can be dramatically larger and broader with the use of a dedicated database, but I'm not sure it's worth adding that layer on this right now.  The actual production implementations, from which most of this is derived (in bits and pieces), does in fact involve SQL Server resources.  This allows for greater custom control over offline processing, logging and tracking, alerts, and general automation features.  If this project were to actually go somewhere I would be more than happy to pursue that direction, but for now it remains off the table.
  4. I am fully and completely (double reduntant statement, I know) of how "lite" this project is.  The features for managing user access control (role-based or otherwise) are intentionally left out, at least for now.  Therefore, users must consider their own approach to controlling access to any implementations out there.  If interest picks up, I may put more work into role-based access management.  It's really not difficult to add, but I'm focusing the little time I have to spend on this in other areas for now.
  5. I'm trying to keep this project XHTML 1.0 compliant and cross-browser compliant.  I routinely test it with IE9, Firefox 4 and Chrome 10 and it seems to work fine in all three of those.  I know that some of the pages are not 100% compliant, but who cares.  If this turns into something worthwhile (I keep saying that, don't I?) I will address that.  For now, it works ok.
  6. I have no intention of chasing SCCM 2012 at this point.  I'm not rejecting the possibility, but at this time I have no reason to even consider it.
  7. The amount of feedback so far is not very promising, but that could mean a lot of things, so I'm holding off a bit longer before deciding on where this project will go.  I'm pegging March 31 as a possible Go/No-Go date.  If interest doesn't pick up by then, this will be taken down and kept for personal use only.  It wouldn't be the first project to be vaporized.  My son's baseball season is about to start, and as the weather warms up, I will do my best to spend less time indoors, behind a computer.  I think this is a fairly decent start for a project of this type, so who knows.