<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpinPlate &#187; PlateSpinner</title>
	<atom:link href="http://spinplate.com/author/platespinner/feed/" rel="self" type="application/rss+xml" />
	<link>http://spinplate.com</link>
	<description>Just keeping the plates from falling.</description>
	<lastBuildDate>Thu, 16 Feb 2012 16:25:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Antivirus Exclusions for SharePoint 2010 and SQL Server 2008 R2</title>
		<link>http://spinplate.com/2012/02/antivirus-exclusions-for-sharepoint-2010-and-sql-server-2008-r2/</link>
		<comments>http://spinplate.com/2012/02/antivirus-exclusions-for-sharepoint-2010-and-sql-server-2008-r2/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 16:21:15 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[Microsoft Admin]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[SQL Server]]></category>

		<guid isPermaLink="false">http://spinplate.com/2012/02/antivirus-exclusions-for-sharepoint-2010-and-sql-server-2008-r2/</guid>
		<description><![CDATA[This comes up all of the time for me and it is high time that I created a single place for me to see every antivirus exclusion that is necessary for production SharePoint 2010 and SQL 2008 R2 servers to &#8230; <a href="http://spinplate.com/2012/02/antivirus-exclusions-for-sharepoint-2010-and-sql-server-2008-r2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This comes up all of the time for me and it is high time that I created a single place for me to see every antivirus exclusion that is necessary for production SharePoint 2010 and SQL 2008 R2 servers to run efficiently. If you don’t configure antivirus exclusions on your servers you can expect to see performance problems and mysterious errors at some point, especially when load starts getting high.</p>
<p>After the break, there’s a full table that lists out all of the necessary antivirus exclusions that should be configured for Windows servers that are running SharePoint 2010 and/or SQL 2008 R2: </p>
<p> <span id="more-139"></span>
<p>(I’m sorry in advance for how unreadable this may be with the CSS I have right now. I don’t have time to fix it…)</p>
<table border="1" cellspacing="0" cellpadding="0" width="542">
<tbody>
<tr>
<td valign="top" width="43">
<p>Product</p>
</td>
<td valign="top" width="68">
<p>Description</p>
</td>
<td valign="top" width="64">
<p>Exclusion Type</p>
</td>
<td valign="top" width="218">
<p>Location</p>
</td>
<td valign="top" width="147">
<p>Comments</p>
</td>
</tr>
<tr>
<td valign="top" width="43">
<p><font size="1">Windows Server 2008 R2</font></p>
</td>
<td valign="top" width="68">
<p><font size="1">Windows Update Datastore</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">%windir%\SoftwareDistribution\              <br />Datastore</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Windows Update Logs </font></p>
</td>
<td valign="top" width="64">
<p><font size="1">File</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">The following files located in %windir%\SoftwareDistribution\Datastore\Logs:</font></p>
<p><font size="1">Res*.log, Res*.jrs, Edb.chk, Tmp.edb</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">For the files with the wildcared * character, there may be several files in that folder that fit the criteria.</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Windows Security Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">File</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">The following files located in %windir%\Security\Database:</font></p>
<p><font size="1">*.edb, *.sdb, *.log, *.chk, *.jrs</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">From Microsoft: &quot;If these files are not excluded, antivirus software may prevent proper access to these files, and security databases can become corrupted. Scanning these files can prevent the files from being used or may prevent a security policy from being applied to the files. These files should not be scanned because antivirus software may not correctly treat them as proprietary database files.&quot;</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Windows Group Policy Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">File</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">%allusersprofile%\NTUser.pol</font></p>
<p><font size="1">And</font></p>
<p><font size="1">%Systemroot%\System32\GroupPolicy\Registry.pol</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Domain Controllers</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Files and Folders</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">See Comments</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">SharePoint and SQL Server should not be installed on a domain controller but this is sometimes necessary to build development environments. If your SharePoint server is a domain controller, additional AD related antivirus exclusion are listed here: </font><a href="http://support.microsoft.com/kb/822158"><font size="1">MS Support KB822158</font></a></p>
</td>
</tr>
<tr>
<td valign="top" width="43">
<p><font size="1">SharePoint Foundation 2010</font></p>
</td>
<td valign="top" width="68">
<p><font size="1">Core Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Program Files\Common Files\Microsoft Shared\Web Server Extensions</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">Can optionally just do &quot;.\14\Logs&quot; and &quot;.\14\Data\Applications&quot;</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">.NET Temp</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Windows\Microsoft.NET\              <br />Framework64\v2.0.50727\Temporary ASP.NET Files</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">WebTemp</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive: \Users\service account\AppData\Local\              <br />Temp\WebTempDir </font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68"><font size="1"></font></td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\ProgramData\              <br />Microsoft\SharePoint\</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68"><font size="1"></font></td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Users\the account that the search service is running as\AppData\Local\Temp</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">The search account creates a folder in the &quot;gthrsvc_spsearch4 Temp&quot; folder to which it periodically needs to write. </font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Log Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\WINDOWS\system32\LogFiles</font></p>
<p><font size="1">And/Or</font></p>
<p><font size="1">Drive:\Windows\Syswow64\LogFiles</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">On 64 Bit Windows 2008 Server with 64 Bit Product, the location is Drive:\Windows\ Syswow64\LogFiles</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Service Account Temp Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Users\Each App Pool Service Account\AppData\Local\Temp</font></p>
<p><font size="1">And</font></p>
<p><font size="1">Drive:\Users\Default\AppData\              <br />Local\Temp</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43">
<p><font size="1">SharePoint Server 2010 (in addition to the above)</font></p>
</td>
<td valign="top" width="68">
<p><font size="1">Index and Query Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Program Files\Microsoft Office Servers\14.0\Data</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">This folder is used for the indexing and/or query process. If the Index files are configured to reside in a different folder, you also have to exclude that location.</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Enterprise Services Logs</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Program Files\Microsoft Office Servers\14.0\Logs </font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Enterprise Services Binaries</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Program Files\Microsoft Office Servers\14.0\Bin</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">FIM for User Profile Service</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder </font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Drive:\Program Files\Microsoft Office Servers\14.0\Synchronization Service</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">RBS BLOB Store</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Any location where BLOB data is stored</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">See this TechNet link for more info: </font><a href="http://technet.microsoft.com/en-us/library/ee424404.aspx#Section1"><font size="1">MS Office Library on SharePoint BLOB storage</font></a></p>
</td>
</tr>
<tr>
<td valign="top" width="43">
<p><font size="1">SQL 2008 R2</font></p>
</td>
<td valign="top" width="68">
<p><font size="1">Data Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Extension</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">.mdf, .ldf, .ndf</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Backup Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Extension</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">.bak, .trn</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Full-Text Catalog Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Default instance: Drive:\Program Files\Microsoft SQL Server\MSSQL\FTDATA</font></p>
<p><font size="1">Or&#8230;</font></p>
<p><font size="1">Named instance: Drive:\Program Files\Microsoft SQL Server\              <br />MSSQL$instancename\FTDATA </font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">Trace Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Extension</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">.trc</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SQL Audit Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Extension</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">.sqlaudit</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">For more info see: </font><a href="http://msdn.microsoft.com/en-us/library/cc280649.aspx"><font size="1">MSDN SQLAudit Info</font></a></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SQL Query Files</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Extension</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">.sql</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SSAS Data and Temp Folder</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Default: Drive:\Program Files\Microsoft SQL Server\MSSQL.X\OLAP\Data</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">This could be different and in separate places based on the configuration.</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SSAS Backup Folder</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Default: Drive:\Program Files\Microsoft SQL Server\MSSQL.X\OLAP\Backup</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">This could be different based on the configuration.</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SSAS Log Folder</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Default: Drive:\Program Files\Microsoft SQL Server\MSSQL.X\OLAP\Log</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">This could be different based on the configuration.</font></p>
</td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SSAS additional folders</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Any extra folders added for SSAS in addition to what&#8217;s above.</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SQL Server Database Engine</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Process</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">%ProgramFiles%\Microsoft SQL Server\MSSQL10_50.&lt;Instance Name&gt;\MSSQL\Binn\SQLServr.exe</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SQL Server Reporting Services</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Process</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">%ProgramFiles%\Microsoft SQL Server\MSSQL10_50.&lt;Instance Name&gt;\Reporting Services\ReportServer\              <br />Bin\ReportingServicesService.exe</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SQL Server Analysis Services</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Process</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">%ProgramFiles%\Microsoft SQL Server\MSSQL10_50.&lt;Instance Name&gt;\OLAP\Bin\MSMDSrv.exe</font></p>
</td>
<td valign="top" width="147"><font size="1"></font></td>
</tr>
<tr>
<td valign="top" width="43"><font size="1"></font></td>
<td valign="top" width="68">
<p><font size="1">SQL Clustering</font></p>
</td>
<td valign="top" width="64">
<p><font size="1">Folder</font></p>
</td>
<td valign="top" width="218">
<p><font size="1">Q:\ (Your Quorum Drive)</font></p>
<p><font size="1">C:\Windows\Cluster</font></p>
</td>
<td valign="top" width="147">
<p><font size="1">If you&#8217;re running antivirus on a SQL cluster, make sure the Antivirus product and version is cluster-aware.</font></p>
</td>
</tr>
</tbody>
</table>
<div style="direction: ltr"></div>
<h2>References:</h2>
<ul>
<li>Microsoft Support KB822158 &#8211; &quot;Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows&quot;: <a href="http://support.microsoft.com/kb/822158">http://support.microsoft.com/kb/822158</a> </li>
<li>Microsoft Support KB952167 &#8211; &quot;Certain folders may have to be excluded from antivirus scanning when you use a file-level antivirus program in SharePoint&quot;: <a href="http://support.microsoft.com/kb/952167">http://support.microsoft.com/kb/952167</a> </li>
<li>Microsoft Support KB309422 &#8211; &quot;How to choose antivirus software to run on computers that are running SQL Server&quot;: <a href="http://support.microsoft.com/kb/309422">http://support.microsoft.com/kb/309422</a> </li>
</ul>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Antivirus' rel='tag' target='_blank'>Antivirus</a>, <a class='technorati-link' href='http://technorati.com/tag/performance' rel='tag' target='_blank'>performance</a>, <a class='technorati-link' href='http://technorati.com/tag/SharePoint' rel='tag' target='_blank'>SharePoint</a>, <a class='technorati-link' href='http://technorati.com/tag/SQL+Server' rel='tag' target='_blank'>SQL Server</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2012/02/antivirus-exclusions-for-sharepoint-2010-and-sql-server-2008-r2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Can you run the Configuration Wizard on multiple SharePoint 2010 farm hosts at once?</title>
		<link>http://spinplate.com/2011/11/can-you-run-the-configuration-wizard-on-multiple-sharepoint-2010-farm-hosts-at-once/</link>
		<comments>http://spinplate.com/2011/11/can-you-run-the-configuration-wizard-on-multiple-sharepoint-2010-farm-hosts-at-once/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 17:28:26 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[Install]]></category>
		<category><![CDATA[psconfig]]></category>

		<guid isPermaLink="false">http://spinplate.com/2011/11/can-you-run-the-configuration-wizard-on-multiple-sharepoint-2010-farm-hosts-at-once/</guid>
		<description><![CDATA[Simply put, no. Take for example, you install the bits for the service pack 1 upgrade. The first thing, of course, is that you need to finish installing those bits on all of the servers in your farm. But then &#8230; <a href="http://spinplate.com/2011/11/can-you-run-the-configuration-wizard-on-multiple-sharepoint-2010-farm-hosts-at-once/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Simply put, no.</p>
<p>Take for example, you install the bits for the service pack 1 upgrade. The first thing, of course, is that you need to finish installing those bits on all of the servers in your farm. But then after that you need to run the SharePoint Products Configuration Wizard (or run psconfig.exe) to upgrade the installation. I recommend running the wizard first on the app server that serves your Central Administration site. But you really need to wait until it’s finished before running the config wizard on your next server. If you do rush ahead, it won’t let you. I tried it just to see what would happen. When I started the second config wizard in the process, the screen stayed just like this until the first server was finished with the wizard.</p>
<p><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://spinplate.com/blogs/wp-content/uploads/2011/11/image.png" width="624" height="284" /> </p>
<p>So it looks like there is a flag that is checked before it starts. And if one server already is locking up the configuration, the next one will not start until the first is finished.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Install' rel='tag' target='_blank'>Install</a>, <a class='technorati-link' href='http://technorati.com/tag/psconfig' rel='tag' target='_blank'>psconfig</a>, <a class='technorati-link' href='http://technorati.com/tag/SharePoint' rel='tag' target='_blank'>SharePoint</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/11/can-you-run-the-configuration-wizard-on-multiple-sharepoint-2010-farm-hosts-at-once/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A SharePoint Consultant&#8217;s list of scope-growing factors</title>
		<link>http://spinplate.com/2011/11/a-sharepoint-consultants-list-of-scope-growing-factors/</link>
		<comments>http://spinplate.com/2011/11/a-sharepoint-consultants-list-of-scope-growing-factors/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 18:44:49 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[consulting]]></category>

		<guid isPermaLink="false">http://spinplate.com/2011/11/a-sharepoint-consultants-list-of-scope-growing-factors/</guid>
		<description><![CDATA[As I’m preparing to start work on building a single-server SharePoint 2010 pilot rig for a client, I was listing things to check for before I would be willing to shoot off my mouth about how easy the installation will &#8230; <a href="http://spinplate.com/2011/11/a-sharepoint-consultants-list-of-scope-growing-factors/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>As I’m preparing to start work on building a single-server SharePoint 2010 pilot rig for a client, I was listing things to check for before I would be willing to shoot off my mouth about how easy the installation will be.</p>
<p>For those that may find it interesting, here is a list of scope-growing factors that can add major complexity to a simple SharePoint implementation:</p>
<ul>
<li>Incoming email functionality</li>
<li>Non-AD profile sync connections</li>
<li>Write-to AD functionality for profile-sync (as opposed to reading from Active Directory only)</li>
<li>Forms based authentication or claims authentication (instead of old-school Windows auth)</li>
<li>Search content sources other than the local SharePoint content</li>
<li>FAST Search (instead of regular SharePoint search)</li>
<li>PowerPivot</li>
<li>Project Server</li>
<li>Team Foundation Server</li>
<li>SQL Reporting Services</li>
<li>Migration or upgrading of content from other SharePoint farms</li>
<li>Publishing service applications to other SharePoint farms</li>
<li>3rd party add-ons</li>
</ul>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/consulting' rel='tag' target='_blank'>consulting</a>, <a class='technorati-link' href='http://technorati.com/tag/SharePoint' rel='tag' target='_blank'>SharePoint</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/11/a-sharepoint-consultants-list-of-scope-growing-factors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Forefront UAG install fails &#8211; Event ID 11406, Error 1406</title>
		<link>http://spinplate.com/2011/09/forefront-uag-install-fails-event-id-11406-error-1406/</link>
		<comments>http://spinplate.com/2011/09/forefront-uag-install-fails-event-id-11406-error-1406/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 19:21:50 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[Microsoft Admin]]></category>
		<category><![CDATA[Install]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[UAG]]></category>

		<guid isPermaLink="false">http://spinplate.com/2011/09/forefront-uag-install-fails-event-id-11406-error-1406/</guid>
		<description><![CDATA[I had four clean Windows 2008 R2 installed servers all in a row fail when installing Forefront Unified Access Gateway with the same error: Log Name:&#160;&#160;&#160;&#160;&#160; Application Source:&#160;&#160;&#160;&#160;&#160;&#160;&#160; MsiInstaller Date:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 9/29/2011 1:10:10 PM Event ID:&#160;&#160;&#160;&#160;&#160; 11406 Task Category: None Level:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; &#8230; <a href="http://spinplate.com/2011/09/forefront-uag-install-fails-event-id-11406-error-1406/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I had four clean Windows 2008 R2 installed servers all in a row fail when installing Forefront Unified Access Gateway with the same error:</p>
<blockquote><p>Log Name:&#160;&#160;&#160;&#160;&#160; Application     <br />Source:&#160;&#160;&#160;&#160;&#160;&#160;&#160; MsiInstaller      <br />Date:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 9/29/2011 1:10:10 PM      <br />Event ID:&#160;&#160;&#160;&#160;&#160; 11406      <br />Task Category: None      <br />Level:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Error      <br />Keywords:&#160;&#160;&#160;&#160;&#160; Classic      <br />User:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; DOMAIN\#ServiceAccount      <br />Computer:&#160;&#160;&#160;&#160;&#160; localcomputername      <br />Description:      <br />Product: Microsoft Forefront Threat Management Gateway &#8212; Error 1406.Could not write value InstalledBy to key \SOFTWARE\Microsoft\Updates\Microsoft Forefront Threat Management Gateway\7.0.8108\Service Pack 1.&#160; System error .&#160; Verify that you have sufficient access to that key, or contact your support personnel.      </p>
</blockquote>
<p>There was nothing out there helping me. I finally found <a href="http://support.microsoft.com/kb/969865" target="_blank">in Microsoft KB969865</a> saying: “When you run .NET Framework 3.5 SP1 setup <strong>with a user account whose name begins with a &#8216;#&#8217; character</strong>, the installation will fail.” and then it gives the error, which is the exact same as the one I got. In the cause section, it explains that the install tries to write a registry value with the “InstalledBy” username. But the ‘#’ character just happens to be a special prefix character in registry values.</p>
<p>So I tried it again with a different account and the install finishes with no problems at all.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Install' rel='tag' target='_blank'>Install</a>, <a class='technorati-link' href='http://technorati.com/tag/TMG' rel='tag' target='_blank'>TMG</a>, <a class='technorati-link' href='http://technorati.com/tag/UAG' rel='tag' target='_blank'>UAG</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/09/forefront-uag-install-fails-event-id-11406-error-1406/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can&#8217;t use PSconfig to create SharePoint 2010 configdb</title>
		<link>http://spinplate.com/2011/08/cant-use-psconfig-to-create-sharepoint-2010-configdb/</link>
		<comments>http://spinplate.com/2011/08/cant-use-psconfig-to-create-sharepoint-2010-configdb/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 17:59:51 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[command-line]]></category>
		<category><![CDATA[psconfig]]></category>

		<guid isPermaLink="false">http://spinplate.com/2011/08/cant-use-psconfig-to-create-sharepoint-2010-configdb/</guid>
		<description><![CDATA[On a client’s site today I was having a horrible time trying to use psconfig to create a configdb. The reason I was doing it is because the client wanted every SharePoint database to have a certain prefix on the &#8230; <a href="http://spinplate.com/2011/08/cant-use-psconfig-to-create-sharepoint-2010-configdb/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>On a client’s site today I was having a horrible time trying to use psconfig to create a configdb. The reason I was doing it is because the client wanted <strong>every SharePoint database</strong> to have a certain prefix on the database name. You can use the configuration wizard to customize the name of the configdb but it doesn’t let you customize the name of the Central Admin site’s content database. To do that, you need to use PSconfig.exe. No problem, I’ve done this before; sometimes for this exact reason.</p>
<p>But this time I had a horrible time doing it. I don’t know if these factors had anything to do with it but my situation included the following noteworthy factors:</p>
<ul>
<li>Brand new SQL 2008 R2 CU7 Active/Passive clustered SQL environment with a named instance </li>
<li>SQL is configured to use dynamic ports only on TCP/IP </li>
<li>My SharePoint 2010 hosts is configured to connect to use SQL client aliases to connect </li>
<li>SharePoint 2010 was installed with media that was slipstreamed with service pack 1 and the June 2011 CU </li>
</ul>
<p>Here is the command I was trying to use:</p>
<p><font face="Courier New">psconfig.exe -cmd configdb -create -server MYSQLAliasName -database FancyPrefix_SharePoint_Config -dbuser Domain\SPfarm -dbpassword SomePassword -user Domain\spadmin -password SomePassword -admincontentdatabase SP_FTIAP_Admin_Content –passphrase MY_passphrase</font></p>
<p>The error I got in command-prompt window was:</p>
<blockquote><p>The configdb command is invalid or a failure has been encountered.      <br />Cannot connect to database master at SQL server at MYSQLAliasName. The database might not       <br />exist, or the current user does not have permission to connect to it.</p>
</blockquote>
<p>Not helpful. After verifying that I was able to connect I turned to look at the database server. But on the SQL server there was a more descriptive error in the SQL Logs:</p>
<blockquote><p>Error: 18456, Severity: 14, State: 6.</p>
<p>Message      <br />Login failed for user ‘Domain\SPfarm&#8217;. Reason: Attempting to use an NT account name with SQL Server Authentication.</p>
</blockquote>
<p>So at first, I tried to configure SQL to accept Windows Authentication only. That didn’t help, after restarting the services, future attempt got me this error:</p>
<blockquote><p>Error: 18456, Severity: 14, State: 58.</p>
<p>Message      <br />Login failed for user ‘Domain\SPfarm’. Reason: An attempt to login using SQL authentication failed. Server is configured for Windows authentication only. </p>
</blockquote>
<p>So no dice. I kept searching and trying variations. Including altering my syntax to use the “username@domain.local” style but nothing worked.</p>
<p>I never did figure out how to get past the problem. I ran out of time and decided to go around the issue. I created the farm using the configuration wizard and then followed <a href="http://www.bullspit.co.uk/2011/03/19/sharepoint-2010-change-the-name-of-the-administration-content-database/" target="_blank">Cuban Pete’s instructions to change the name of the Admin Content database</a>, which is simply the PowerShell commands needed to change the name in SharePoint and then when to go into SQL Server Managment Studio and change the actual database name.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/command-line' rel='tag' target='_blank'>command-line</a>, <a class='technorati-link' href='http://technorati.com/tag/psconfig' rel='tag' target='_blank'>psconfig</a>, <a class='technorati-link' href='http://technorati.com/tag/SharePoint' rel='tag' target='_blank'>SharePoint</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/08/cant-use-psconfig-to-create-sharepoint-2010-configdb/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Well hello, Dolly</title>
		<link>http://spinplate.com/2011/04/well-hello-dolly/</link>
		<comments>http://spinplate.com/2011/04/well-hello-dolly/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 19:03:56 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://spinplate.com/?p=130</guid>
		<description><![CDATA[After running WordPress for several years, I just today activated the Hello Dolly plugin. I have to say, it really does lighten the mood&#8230; as advertised. Technorati Tags: Internet]]></description>
			<content:encoded><![CDATA[<p>After running WordPress for several years, I just today activated the <a href="http://wordpress.org/extend/plugins/hello-dolly/">Hello Dolly plugin</a>.</p>
<p>I have to say, it really does lighten the mood&#8230; as advertised.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Internet' rel='tag' target='_blank'>Internet</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/04/well-hello-dolly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Searching Through Active Directory</title>
		<link>http://spinplate.com/2011/03/searching-through-active-directory/</link>
		<comments>http://spinplate.com/2011/03/searching-through-active-directory/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 21:19:35 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Windows User]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[command-line]]></category>
		<category><![CDATA[Search]]></category>

		<guid isPermaLink="false">http://spinplate.com/?p=123</guid>
		<description><![CDATA[There used to be a time when it was easy to search for Active Directory users or security groups or computer names. Back in Windows 2000 it was easy but now you need a dozen clicks to get XP or &#8230; <a href="http://spinplate.com/2011/03/searching-through-active-directory/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>There used to be a time when it was easy to search for Active Directory users or security groups or computer names.  Back in Windows 2000 it was easy but now you need a dozen clicks to get XP or Windows 7 to let you search Active Directory.  Lucky for you you can make a quick shortcut to get you there.</p>
<p>Create a new shortcut and make the destination:<br />
     <code>%windir%\system32\rundll32.exe dsquery.dll,OpenQueryWindow</code></p>
<p>Give it a memorable name like &#8220;Active Directory Search&#8221; and consider changing it to a snappier icon and boom, there ya go.  Now you can search through all of the users, contacts, groups and even containers if you use the advanced tab.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Active+Directory' rel='tag' target='_blank'>Active Directory</a>, <a class='technorati-link' href='http://technorati.com/tag/command-line' rel='tag' target='_blank'>command-line</a>, <a class='technorati-link' href='http://technorati.com/tag/Search' rel='tag' target='_blank'>Search</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/03/searching-through-active-directory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Memoirs of a SharePoint 2010 pilot install</title>
		<link>http://spinplate.com/2011/02/memoirs-of-a-sharepoint-2010-pilot-install/</link>
		<comments>http://spinplate.com/2011/02/memoirs-of-a-sharepoint-2010-pilot-install/#comments</comments>
		<pubDate>Thu, 10 Feb 2011 16:36:34 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[consulting]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[working]]></category>

		<guid isPermaLink="false">http://spinplate.com/2011/02/memoirs-of-a-sharepoint-2010-pilot-install/</guid>
		<description><![CDATA[I had a one-day quick gig yesterday where the client had a blanked VM ready and an existing SQL server. He wants to show his users and stakeholders what SharePoint 2010 looks like but doesn’t really know what his or &#8230; <a href="http://spinplate.com/2011/02/memoirs-of-a-sharepoint-2010-pilot-install/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I had a one-day quick gig yesterday where the client had a blanked VM ready and an existing SQL server. He wants to show his users and stakeholders what SharePoint 2010 looks like but doesn’t really know what his or their needs are. I assumed that, like all unplanned and undocumented installations, there would be some unforeseen roadblock and I would need more than the one day I was given. Also, I assumed that if the client wanted to drive or backseat drive the install that it would take much longer.</p>
<p>I was wrong. It went well. And he had a working 2010 farm with all the basic service apps in under 2 hours.</p>
<p>Here are some points to remember when doing a pilot (or any kind of) install:</p>
<ul>
<li>Create all of your service accounts ahead of time. (You DO use service accounts, right??) </li>
<li>Give the setup account admin rights on the SQL servers too and not just the SharePoint servers (this wasn’t necessary for MOSS). If it’s SQL 2008, make the setup account a sysadmin in SQL. (The farm account still just needs “secadmin” and “dbcreator” roles in SQL.) </li>
<li>Remember to turn off the “Default Web Site” in IIS. Also change the bindings so that the port is something other than 80.</li>
<li>Get a static IP </li>
<li>Don’t forget to <a href="http://support.microsoft.com/kb/896861" target="_blank">disable the loopback check</a>. </li>
<li>If your SQL server hosts multiple projects and not just your SharePoint farm, consider using some kind of prefix in front of the database names as you are setting up SharePoint. For example, if you put “SP2010_” at the beginning of all the SQL databases you use, your SharePoint databases will be nicely bunched together when you use SQL Management Studio </li>
<li>When setting up profile synchronization to Active Directory, try to only select OUs that have <em>actual user accounts</em> in them. Avoid the OUs or containers that have service accounts. Nobody wants to store 150+ profiles for service accounts. </li>
</ul>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/consulting' rel='tag' target='_blank'>consulting</a>, <a class='technorati-link' href='http://technorati.com/tag/IIS' rel='tag' target='_blank'>IIS</a>, <a class='technorati-link' href='http://technorati.com/tag/security' rel='tag' target='_blank'>security</a>, <a class='technorati-link' href='http://technorati.com/tag/SharePoint' rel='tag' target='_blank'>SharePoint</a>, <a class='technorati-link' href='http://technorati.com/tag/working' rel='tag' target='_blank'>working</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2011/02/memoirs-of-a-sharepoint-2010-pilot-install/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I’m not dead yet.  I’m feeling happyyyyyy.</title>
		<link>http://spinplate.com/2010/12/im-not-dead-yet-im-feeling-happyyyyyy/</link>
		<comments>http://spinplate.com/2010/12/im-not-dead-yet-im-feeling-happyyyyyy/#comments</comments>
		<pubDate>Wed, 22 Dec 2010 19:19:00 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[working]]></category>

		<guid isPermaLink="false">http://spinplate.com/?p=98</guid>
		<description><![CDATA[Merry holiday dear readers and search engine bots! My employer is assigning me away from my long standing project (2.5 years) after this week. Starting in January, I&#8217;ll be working on&#8230;. something else. I don&#8217;t even know what, yet. But &#8230; <a href="http://spinplate.com/2010/12/im-not-dead-yet-im-feeling-happyyyyyy/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Merry holiday dear readers and search engine bots!</p>
<p>My employer is assigning me away from my long standing project (2.5 years) after this week.  Starting in January, I&#8217;ll be working on&#8230;. something else.  I don&#8217;t even know what, yet.  But it doesn&#8217;t matter.  </p>
<p>What this means for you is that I will have more freedom and time to develop my career and knowledge and that means MORE BLOG POSTING.  (yay!)</p>
<p>Stay tuned&#8230;</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/working' rel='tag' target='_blank'>working</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2010/12/im-not-dead-yet-im-feeling-happyyyyyy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to disable SSL 2.0 and force SSL 3.0 and TLS 1.0 in IIS</title>
		<link>http://spinplate.com/2010/08/how-to-disable-ssl-2-0-and-force-ssl-3-0-and-tls-1-0-in-iis/</link>
		<comments>http://spinplate.com/2010/08/how-to-disable-ssl-2-0-and-force-ssl-3-0-and-tls-1-0-in-iis/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 09:02:00 +0000</pubDate>
		<dc:creator>PlateSpinner</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Microsoft Admin]]></category>
		<category><![CDATA[command-line]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://spinplate.com/2010/08/how-to-disable-ssl-2-0-and-force-ssl-3-0-and-tls-1-0-in-iis/</guid>
		<description><![CDATA[I lot of places want to disable weaker encryption levels and require more secure encryption levels. There isn&#8217;t a lot of clear procedures out there that explain how this is done. So for the greater good, I&#8217;m posting it here. &#8230; <a href="http://spinplate.com/2010/08/how-to-disable-ssl-2-0-and-force-ssl-3-0-and-tls-1-0-in-iis/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I lot of places want to disable weaker encryption levels and require more secure encryption levels. There isn&#8217;t a lot of clear procedures out there that explain how this is done. So for the greater good, I&#8217;m posting it here.</p>
<h3>Follow these steps to make the change manually:</h3>
<ol>
<li><a href="http://windows.microsoft.com/en-US/windows7/Back-up-the-registry">Back up your registry</a> (outside link) </li>
<li>Disable SSL 2.0:
<ol>
<li>Browse to the &quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0&quot; key.&#160; </li>
<li>There is probably a key there called &quot;Client&quot;.&#160; If there is not also a key under there called &quot;Server&quot;, create it. </li>
<li>Create a DWORD for the &quot;SSL 2.0\Client&quot; sub-key called &quot;Enabled&quot; and set it to &quot;0&quot;. </li>
<li>Create a DWORD value for the &quot;SSL 2.0\Server&quot; subkey and set it to &quot;0&quot;, too.&#160; (This will disable SSL version 2.0) </li>
</ol>
</li>
<li>Enable SSL 3.0:
<ol>
<li>Browse to the &quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\&quot; key.&#160; </li>
<li>If there is not a key under there called &quot;SSL 3.0&quot;, create it. </li>
<li>Under &quot;SSL 3.0&quot;, create a key called &quot;Client&quot; and a key called &quot;Server&quot;. </li>
<li>For both &quot;Client&quot; and &quot;Server&quot;, add a DWORD value to each called &quot;Enabled&quot; and set it to &quot;1&quot; (This will enable SSL 3.0). </li>
</ol>
</li>
<li>Enable TLS 1.0:
<ol>
<li>Browse to the &quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\&quot; key.&#160; </li>
<li>If there is not a key under there called &quot;TLS 1.0&quot;, create it. </li>
<li>Under &quot;TLS 1.0&quot;, create a key called &quot;Client&quot; and a key called &quot;Server&quot;. </li>
<li>For both &quot;Client&quot; and &quot;Server&quot;, add a DWORD value to each called &quot;Enabled&quot; and set it to &quot;1&quot; (This will enable&#160; TLS 1.0). </li>
</ol>
</li>
<li>Add support for the RC2, RC4, and 3DES ciphers:
<ol>
<li>Browse to this key: &quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers&quot; </li>
<li>Under &quot;Ciphers&quot; you will add three keys.&#160; The first is called &quot;RC2 128/128&quot;.&#160; The second is called &quot;RC4 128/128&quot;.&#160; The third is called &quot;Triple DES 168/168&quot;. </li>
<li>Do not add any values or keys under the three new keys. </li>
</ol>
</li>
<li>Restart the server. </li>
</ol>
<h3>Or you could just run these commands from an administrative command-line:</h3>
<p>  <code>REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Protocols\SSL 2.0\Server&quot; /v Enabled /t REG_DWORD /d 0 /f<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Protocols\SSL 2.0\Client&quot; /v Enabled /t REG_DWORD /d 0 /f<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Protocols\SSL 3.0\Server&quot; /v Enabled /t REG_DWORD /d 1 /f<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Protocols\SSL 3.0\Client&quot; /v Enabled /t REG_DWORD /d 1 /f<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Protocols\TLS 1.0\Server&quot; /v Enabled /t REG_DWORD /d 1 /f<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Protocols\TLS 1.0\Client&quot; /v Enabled /t REG_DWORD /d 1 /f<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Ciphers\RC2 128/128&quot;<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Ciphers\RC4 128/128&quot;<br />
REG ADD &quot;HKLM\System\CurrentControlSet\Control\SecurityProviders\SChannel\Ciphers\Triple DES 168/168&quot; </code></p>
<p></p>
<h3>Further Reference: </h3>
<ul>
<li><a href="http://support.microsoft.com/kb/245030/">How to Restrict the Use of Certain Cryptographic Algorithms and Protocols in Schannel.dll</a> (Microsoft Support) </li>
<li><a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;187498">How to disable PCT 1.0, SSL 2.0, SSL 3.0, or TLS 1.0 in Internet Information Services</a> (Microsoft Support) </li>
</ul>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/command-line' rel='tag' target='_blank'>command-line</a>, <a class='technorati-link' href='http://technorati.com/tag/IIS' rel='tag' target='_blank'>IIS</a>, <a class='technorati-link' href='http://technorati.com/tag/security' rel='tag' target='_blank'>security</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://spinplate.com/2010/08/how-to-disable-ssl-2-0-and-force-ssl-3-0-and-tls-1-0-in-iis/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

