Before installing Windows Server 2019 Time,Have noticed that the Server Core environment is selected by default,I feel that Microsoft wants to push the operating environment of this instruction mode。And after completing the Windows Server installation,When opening the Server Manager,Then it will suggest that we try to use “Windows Admin Center” IT,So if you want to say it, then try Windows Server 2019 Server Core install Windows Admin Center。
Wrote an article last week "Application specific permission settings cannot include CLSID – SQL」,At that time, I saw it in the system event record on SQL Server,The permissions in question are in the role of SQLSERVERAGENT,There is no problem with the permissions of the server itself (SYSTEM 及 Administrator)。I saw the same message on the AD server today,This time, the server itself has insufficient permissions,Therefore, multiple steps are required to retrieve the permissions from regedit。
Recently check the "event log" of each server,Want to reduce invalid information,And handling error information。This time on SQL Server,There will always be an error message like this:
應用程式特定 權限設定無法將含有 CLSID {806835AE-FD04-4870-A1E8-D65535358293} 與 APPID {EE4171E6-C37E-4D04-AF4C-8617BC7D4914} 之 COM 伺服器應用程式的 本機 啟用 權限授與來自位址 LocalHost (使用 LRPC) (在應用程式容器 無法使用 SID (無法使用) 中執行) 的使用者 NT SERVICE\SQLSERVERAGENT SID (S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430)。您可以使用元件服務系統管理工具修改此安全性權限。
We have several servers in the "system event" there will be many Schannel error messages,Click to show “The following serious warnings have been generated: 40。The internal error status is 1205。” Or “Received TLS from remote client application 1.2 Connection requirements,None of the encryption package servers supported by the client application。SSL connection request failed。” Wait for error message。The reason for this message is that this server provides encrypted services,But the user did not make the connection request in an encrypted way,I, for one,The two servers where this message appears are the Mail Server and the electronic sign-off server,Both use SSL certificates。
Checking a Windows Server today 2008 R2 event,Found "System Event" full of Windows Modules Installer start and stop messages,Internet crawling found An article Is discussing a similar issue,Only the role is “WMI Performance Adapter” service,The reason is that there is a remote service (Like SCOM: System Center Operations Manager) Monitoring computer,Will cause the WMI service to switch on and off in response to it。
Previously because the AD domain was 2003 Hierarchical relationship,So on Windows Server 2012 When you want to join the domain in a later version,You have to go to the "function" side first and put SMB 1.0 Client installed,To successfully join the domain。Recently my colleague upgraded the AD domain to 2008 R2,So I want to shut down the SMB v1 of these servers,To improve security。And when you want to remove,Unable to uncheck,Therefore, the removal method is commanded instead.。
A very special situation happened today,On Windows Server 2012 Adjust the "Security" of a printer in R2,Masaru “Everyone” After changing the "Print" permission from "Allow" to "Deny",It disappeared from the "printer" page,Go to "Device Manager",Also disappear,But the print screen in Excel is still visible,From “\\localhost” I can still see it (Originally opened sharing printing)。Tried to restart Print Spool service and restart,The results are still the same,So I had to try the command mode instead,Change permissions back。
【環境】
● work system:Windows Server 2019
● website platform:IIS 10
● voucher website:ZeroSSL.com (Let’s Encrypt)
Today found in Windows Server 2019 in,After the "Language" - into the "Settings" - "time and language.",A pop “SystemSettingsAdminFlows.exe” Error message,Content is “Windows can not access the specified device、Path or file。You may not have the appropriate permissions,The project can not be accessed。” Check the two Windows Server 2019 Have the same message,Windows Server 2016 and 2012 The normal。
A few days ago to help colleagues in a Windows Server 2008 R2 do Windows Update,Bahrain will no longer be able to reboot into Windows。Open access to repair mode,But there will not be repaired finish,And a”Damaged boot configuration”Messages。It took several hours study,Finally managed to repair,The following is the repair record: