Posts filed under Tips'n Tricks

Enable Juniper SRX Firewall Logging

Juniper started to migrate their firewalls from Netscreen to the Junos environment 'a couple of' months back. The advantage is that there's a universal OS for routers, switches and firewalls. Just like Cisco IOS. The disadvantage is that the Junos OS is being adapted for the firewalls. So the foundations are there, but there are still lots of features missing and bugs are also still abundant.

The bugs are thankfully mostly related to the WebGUI. On the commandlinethe bugs are in the same league as the Cisco, Checkpoint and every other vendor bugs. No piece of software is perfect.

Posted on March 1, 2011 and filed under Annoying, Hardware, Security, Tips'n Tricks, Junos.

Cisco Secure ACS 5.x and Apple OSX Directory (LDAP)

For testing and development purposes I run a Cisco Secure ACS 5.x in a virtual machine at home. In this environment I also run an Apple Directory Service. I'll be using this setup to test several 802.1x and RADIUS authentication schemes.

To get things going I needed to connect to the ACS to my LDAP Directory. The Apple Directory Service is a bit different from the regular LDAP implementations. They seem to add the 'apple' reference in a lot of attribute values. Thankfully the ACS has a very versatile configuration interface.

Apple references in attribute valuesNormally, the group definition would be 'group' instead of 'apple-group'. So the configuration of the ACS should reflect these variations to the standard.

Posted on March 1, 2011 and filed under Apple, Security, Software, Tips'n Tricks.

Lousy Adobe Reader 10.0.1 Update

Earlier this week I got the announcement (I opened an Adobe application) that there was an update for the Adobe Reader app. Security-conscious as I am, I fired up the update process.

Each time, this process stopped at the (near??) end of the installation with the following error:

The operation couldn’t be completed. (com.adobe.ARM error 1807.)

The error also suggested looking at the log file. Examination of this file showed nothing out of the ordinary. At least not that made sense to me.
There were some lines in the log that made me try to do a work-around (in bold);

Posted on February 9, 2011 and filed under Annoying, Apple, Software, Tips'n Tricks.

PGP Services Menu Integration

During the clean-up of my personal data on my Mac's, I found several PGP encrypted containers, and encrypted files. To see what was stored in them, I needed to install PGP (again).

After installing the software I dug up my keyrings and everything worked fine, until I tried to encrypt an e-mail. In the old days you had a button for encrypting the body of an e-mail message, but today things have changed. PGP is using some sort of (local) proxy to encrypt, decrypt, sign and verify e-mail messages. BUT there's also the possibility to do this with text on the clipboard, or text you selected with your mouse/keyboard.

This is where I ran into some missing functionality; Normally the PGP actions are visible under the 'right-mouse' click -> Services, but no PGP actions available. Further investigation showed that no PGP actions were available on (plain) text in editors. PGP actions on entire files were no problem.

Posted on February 5, 2011 and filed under Annoying, Security, Software, Tips'n Tricks.

802.1x: Machine Access Restriction 'Vulnerability'

Today we ran into a feature of the Machine Authentication Restrictions (MAR) option in the Cisco Secure ACS Radius server. It seems that when you're using the ACS for 802.1x authentication, you have the option of demanding that the authenticating users can only be authenticated when the computer is already authenticated. This way, you make sure that no user can access the network without a legitimate PC.

Posted on January 20, 2011 and filed under Security, Software, Tips'n Tricks.

Geotagging Nikon P7000 RAW files (NRW)

PhotoLinkerI tend to geotag most of my photos. This way I have location information with the photo for future reference. It's also a neat feature that you might exploit when creating photo albums with e.g. iPhoto. The GPS coordinates in the images creates the option to create maps in iPhoto albums.

I use geotagging in two different ways. I use the jf Geocoding plugin in Lightroom and the PhotoLinker application. Both have their (dis)advantages. Something I won't go into in this post.

Posted on December 29, 2010 and filed under Photography, Software, Tips'n Tricks.

OSX CardDAV Server

After the challenges with the iCalDAV server in OSX, I gave up on getting the Addressbook server up-and-running. Somehow, the clients couldn't wouldn't connect. No matter what configuration parameters I tried.

This week I tried to get it up-and-running again. Mainly because I can't concentrate for longer than two hours for my Cisco exams next week. Sometimes you need to clear your head.

For some reason I found the solution within the hour. No idea what the original problem was exactly.

Posted on December 17, 2010 and filed under Apple, Personal, Tips'n Tricks.

Microsoft Office 2008:Mac - Office did not install correctly

Come on.... it isn't even Monday. It's Friday for crying out loud.

What happened you ask? Well.....

I got an e-mail with a XLS file attached (I know.. shit happens). So I tried to open it, but I got a reminder that I hadn't (re)installed Office 2008 on my new iMac. But not to worry. I have the official Microsoft Office 2008 DMG (with matching serial number) on my Drobo, so the installation was done in a matter of minutes.

This is when it happened. Starting office resulted in this error: "Office did not install correctly". It even had a link to a Microsoft article explaining I needed an update. But the update wouldn't install since it was for OSX 10.4 (or something). Installing the latest update didn't solve it either.

Well, remove Office and reinstall it then... That didn't work either. Still the same error.

Searching the Interwebs resulted in a suggestion to remove everything Microsoft from the Mac.... And so I did. Especially the locations like:

/Library/Preferences/
~/Library/Preferences/

should be free of everything Microsoft. After trashing the Trash I reinstalled Office 2008. This time I was asked to enter my name and serial number. Something that didn't happen the first times. Then it occurred to me; I had copied my preferences (and other settings) when I migrated from my old to my new iMac. I guess that Microsoft doesn't support that.

It would have been nice if they had an option in the Removal Tool (which they generously supply) to remove EVERYTHING. I think that they didn't forget it. I think that this is by design. Just to screw with us Mac user.

Posted on December 3, 2010 and filed under Annoying, Microsoft, Personal, Software, Tips'n Tricks.

iMac with Multiple Monitors

One can not have enough screen "real-estate" when working with photos, or while exploring your web-development skillz. So, a single display is simply not an option in my case......

Next to my 27" iMac stands a Dell 24" TFT Display. This Dell display is being abused for two things;

  1. extended display for my iMac, and
  2. as a main monitor for my (Windows) work laptop

using the input selector on the TFT display.

Since I'm a guy and I rock at multitasking (*cough*), I have both my Windows (work) laptop and my iMac powered on. In this scenario I have only one active display on my iMac. The second display should therefor not be used, and this is where Apple fails miserably.

Posted on December 1, 2010 and filed under Annoying, Apple, Software, Tips'n Tricks.

iPhone 3GS, iOS4 and MMS not working

I ran into a problem with MMS after I upgraded to iOS4 on my iPhone 3GS. Somehow, it was impossible to send MMS messages on the KPN cellular network. Searching the Internet revealed that I wasn't the only one.

The general consensus to solve this issue was a restore of the iPhone and not to restore old settings, but start from scratch.

After doing this, MMS still couldn't be sent from the iPhone, so time to do some more research. It turned out that KPN must have change the MMS settings, since my old MMS settings weren't correct anymore. So try these settings BEFORE you restore your iPhone. It might save you a lot of work and time.

Note: the following settings are for the Dutch KPN Network, and probably won't work on other networks / carriers.

Old Settings

APN: portalmmm.nl
Username:
Password:
MMSC: http://mp.mobiel.kpn/mmsc
MMS Proxy: 10.10.100.50:5080
MMS Max Message Size: 300000

New Settings

APN: portalmmm.nl
Username: kpn
Password: kpn
MMSC: http://mp.mobiel.kpn/mmsc
MMS Proxy: 10.10.100.20:5080
MMS Max Message Size: <leave empty>

Notice the differences? Anyway, with these new settings, MMS worked again.

KPN does have a page dedicated to the iPhone (in Dutch), regarding the Internet, and MMS settings. Just check those pages for the lastest settings.

I've updated the original page on my blog with the new settings.

Posted on July 23, 2010 and filed under Apple, Internet, Tips'n Tricks, iPhone.