Posts Tagged ‘Computers’

KDE4 Revisited

Thursday, October 30th, 2008

Back in February, I took a look at the new KDE4 and what I had found was less than desired. Always willing to re-address an issue, I installed the newer 4.1 version of the beta and dug around a bit.

I found much of what I had complained about has been cleaned up. Configuration is much easier now and previously missing configuration controls have been put back in place. The KDE team has restored my faith in the new version with this alone. I was dreading a Gnome clone.

They also canned the Duplo Lego look, for something not quite as chunky, but still too large. Thankfully, with the re-established controls in place, you can fix it quickly.

The Plasma widgets never really impressed me and they still don’t, though they are getting better. Dolphin is an interesting file manager, but konqueror still holds my heart there. Both are included, of course, so choice rules supreme. (Not that I do much with a graphical file manager, as the command line is where I typically roam.)

Kickoff finally has the ability to revert to the standard KDE3 style menu. Thank you!

Integration with Compiz-Fussion was seamless and I didn’t run into any troubles – rather amazing considering the complexity of it.

However, the one thing KDE4 still lacks is application stability. I couldn’t go for longer than ten minutes at a time without an application crash. Scrolling menus often didn’t refresh correctly. Shortcut settings would change in the interface, but not work. KMail couldn’t empty the Trash folder on my IMAP accounts without dying. The desktop itself never died, but I couldn’t get much work done.

In short, KDE4 is not ready for real work, but it’s getting better – much better. Once the environment is out of beta, I’m pretty confident at this point that it will suit me just fine and satisfy my needs for a completely configurable desktop environment.

Again, I’m thankful. I didn’t really want to move to Gnome.

Addendum: It appears that the newly released Kubuntu 8.10 has abandoned KDE3 and gone exclusively with KDE4.  I can’t imagine why they would do this, considering the issues I’ve seen with lack of stability.  Time to dig up a test machine and try a fresh install, I think.

Loose Your Data, the Microsoft Way

Thursday, May 1st, 2008

May 1, 2008 (Computerworld) Microsoft Corp. confirmed on Wednesday that it delayed the rollout of Windows XP Service Pack 3 (SP3) because changes to the operating system can corrupt data in the company’s retail point-of-sale and store management software.

I hate to laugh, but I have to.  If it was some bizarre interaction with a third party software package, I might be able to forgive it as an oversight.  But to create two different service packs, for two different OS’s that both corrupt data in one of Microsoft’s own, rather expensive, software packages?  How pathetic can you get?

Certainly it is within the best interest of every systems administrator out there, to test all service packs and updates with the software they run, to ensure that their mission critical applications don’t explode on them.  It falls on their shoulders, ultimately.  However, you would hope that Microsoft, as large as they are, would test their own software against their own OS roll outs.

I know that Microsoft is the 800 pound gorilla in the software cage, which makes them a natural target, but with their recent mistakes in judgment and poor software offerings (Vista simply sucks, the Windows Genuine Advantage is anything but and has screwed up several times now telling valid customers that they’re software thieves, Windows Home Server still corrupts any data you save directly to it across the network, and the last two service packs weren’t released to paying Microsoft Developer Network customers, etc.) I have to wonder if they’re not starting to collapse under their own weight.

Illegal Hyperlinks

Sunday, March 23rd, 2008

This article is scary in so many ways, that it gives one pause to even browse the Web anymore.

The gist of it all, is that the FBI put up some faked URL’s on a message board which they thought was being used for trading child pornography and then recorded the Internet Protocol (IP) number of any system which connected to their fake site. They made no distinction of how a person got the link, however. This means that someone could email the links in question to a person they want to damage, using misleading names on the links and cause a completely innocent person to find the FBI’s honeypot!

The FBI then took the IP information and traced it down to the supposed owner and used this to obtain a warrant for each location for dawn raids.

Let’s be blunt about this: when the FBI made no distinction on how someone got to the site, they engaged in utterly shoddy police work.

One of the most disturbing lines in the article is as follows:

Vosburgh faced four charges: clicking on an illegal hyperlink; knowingly destroying a hard drive and a thumb drive by physically damaging them when the FBI agents were outside his home; obstructing an FBI investigation by destroying the devices; and possessing a hard drive with two grainy thumbnail images of naked female minors (the youths weren’t having sex, but their genitalia were visible).

The obstruction and possession charges seem legitimate, but I have to ask, what the hell is an illegal hyperlink? What is the definition being used for this? If the hyperlink is illegal, can’t the FBI be charged for creating an illegal hyperlink?

Between this kind of questionable police tactics and the ongoing construction and use of data fusion centers, we’ve entered a whole new age of Orwellian existence. I would recommend to everyone to start encrypting everything, whether it is sensitive material or not. Make them waste time on trying to decrypt chocolate chip cookie recipes and text files that only have quotes of the Framers in them. Make them expend effort for nothing, so much effort that they become mired down under the weight of it all.

Following are links to various encryption tools.

http://www.gnupg.org/
http://www.truecrypt.org/
http://www.arg0.net/encfs
http://www.freeotfe.org/

And a page covering many drive encryption systems.

Iterative Insanity the Microsoft Way

Friday, March 7th, 2008

A friend of mine likes to say that the definition of insanity is doing the same thing over and over, and expecting a different result each time.

By that definition, Microsoft is the quintessential model for insanity.

I made the mistake of taking on Windows systems administration a few years ago where I work, as I thought the challenge of learning the intricacies of a previously unfamiliar OS would give me a more rounded experience with systems administration in general and allow me to learn to appreciate why Windows admins seemed to love the environment they worked with. Coming from a solid Unix background, I figured that I would find similarities in function and implementation, to the point that course work would not be needed to learn the ropes. I was correct in that aspect and learned quickly via a couple of incidents where I was able to resolve issues that long time Windows admins could not, that having my previous systems administration experience was a boon in general and very much a keystone to ability that only required study of freely available documentation to attain.

What I was also to learn, however, was that many of the paradigms I was used to would have to be ignored and the replacements that Microsoft had implemented, just plain suck. Consistency of methodology is damn near non-existent. Graphical User Interface (GUI) tools got in the way more times than they helped and their interfaces were inconsistent from each other. To get at the real functionality of the GUI tools, half the time you have to right-click on unexpected places to pull up hidden options. Even the simple structure of system settings are inconsistent and stupidly designed.

A perfect example of the nonsense I ran into can be found in the local security settings of any Windows box. You can find sensible settings, such as, “Domain member: Require strong (Windows 2000 or later) session key” with the options of “Enabled” or “Disabled”.  Just below it, however, are “Interactive logon: Do not display last user name” and “Interactive logon: Do not require CTRL+ALT+DEL” with the same options, “Enabled” or “Disabled”. This double negative verbiage is simply ridiculous.

Or how about the fact that even though you’ve setup your Active Directory (AD) domain when you promoted the first Windows server to be a Domain Controller, with clients logging in on your domain and the forest setup with trusts to other domains, et cetera, the name of the Domain Name System (DNS) domain is still “default_domain_name” (or something like that, memory serving,) until you open up the Microsoft Management Console (MMC), run the Active Directory Sites and Services plugin and right click on the entry to chose “Rename” from the popup menu. This is in spite of the fact that you have to enter the DNS name as part of the AD promotion process. I discovered this when I refused to base our entire network’s DNS service to Microsoft’s implementation and had to copy all the SRV records in the netlogon.dns file to the Unix DNS server. After digging around for an hour or so, I finally found out what was up. Of course, if I had enabled DNS and auto-updates of DNS on the AD controller, the information would have been setup correctly then. Most Windows administrators would have simply setup DNS on the AD controller and been done with it. I’ve even read articles advising doing so, no matter what you’ve been using for DNS before, just in case something breaks later with a change suddenly instigated through an update from Microsoft!

Like I said, inconsistency reigns.

The task set before me this week was a new one. The primary Active Directory controller is old and needs to retire. New hardware was ready to go and was tested, so it was time to replace the old with the new. Yes, Microsoft claims that there is no such thing as a Primary Domain Controller (PDC) anymore, but it is only a half truth – as you still have Flexible Single Master Operations (FSMO) server roles, limiting edits of various services to specific systems. You can (limitedly) spread them out among multiple machines, but that doesn’t change the fact that the FSMO roles exist on specific systems and do not have an order of precedence to roll over to another server, should the FSMO server go down. So, even if you spread out your five FSMO roles among different machines, now you have multiple points of failure instead of one. Net gain: nothing.

In my case, our AD domain is tiny. We support about 30 Windows machines anymore, so we had two AD controllers, with the first one setup as the FSMO role server for all five rolls. (This happens automatically the first time an AD controller is setup in an AD forest.) The process to transfer the FSMO roles can be done in one of two ways: right-clicking on a bunch of clumsy GUI menus through three different MMC plugins or running the ntdsutil on the command line and suffering through what is the most abysmal modal command line interface I’ve ever seen.

ntdsutil sucks – it really, really sucks, but it was better than flopping around in three different MMC plugins. So, I started the process of transferring all five FSMO roles from the old server to the new with the command line tool. The PDC Emulator and RID Master roles transferred without a hitch. But try as I might, the Schema Master, Domain Naming Master and Infrastructure Master roles would not transfer, giving a generic error that multiple searches on Google could not elucidate.

So, I decided to make the new server seize the roles which would not transfer. This worked – to an extent. All five roles were reported by the new server to be handled by the new server, but the two old domain controllers now believed that the old FSMO server was still serving all five roles. How the two which had previously transferred correctly were now on the old machine again, was yet another mystery. At this point I didn’t want conflict, so I tried to transfer the roles back from the new machine to the old, all of which failed without even an error message to tell me something was amiss. I now had two AD controllers in the same AD domain of the same AD forest, who both thought that they were the FSMO role master for all five roles.

I left it this way over the weekend, just to see if things would work out or whether additional error messages might tell me something of what was going on. No change came. No new information was revealed.

I tried demoting the new server to stop acting as an AD controller, but it would not allow me to demote the system, giving yet another seemingly random numbered error message. That was enough for me. In desperation, I did what many Windows administrators do at times like these: start over from scratch and do that exact damn thing all over again. I powered the new machine off, re-installed Windows 2003 Enterprise Server, put on anti-virus software and updated with all patches, promoted it to an AD domain controller and kicked up ntdsutil on the old machine and transferred the FSMO roles in the same order I had during the first attempt. Everything worked perfectly. A quick check with the netdom command showed that all three machines now understood that the new server handled all FSMO roles and the whole process was done in just a few seconds time. I had done everything the second time around as I had the first, each step was in the exact order as I had written down. Nothing different was done and everything suddenly worked.

A friend of mine likes to say that the definition of insanity is doing the same thing over and over, and expecting a different result each time.

I understand now that this is why so many people cannot understand that computers are not supposed to crash or otherwise fail in stupid and unpredictable ways. They keep doing things the Microsoft way and insanity prevails and becomes the norm. They can’t understand that things should work the same way every time and that system up time can be measured in years instead of days on a stable operating system. I’m half convinced that Microsoft went to their once a month “Patch Tuesday” methodology for updates, just to make sure that all Windows machines would have to be rebooted once a month, in order to keep the systems appearing stable. I have also come to realize that many people have been fooled into believing that a boondoggled GUI is “more advanced” or otherwise “better” than editing simple text files for system settings – that somehow editing a text file is primitive in comparison – overlooking the fact that cumbersome GUI’s are often simply doing that very task.

If my varied and insane experiences over the last eight years with Windows has taught me anything, it is that whenever possible, no matter how difficult the transition may be at first – if you can run the service on Unix instead, do so. If you leave it up to Windows, you leave it up to sporadic behavior, inane tools and retarded, clumsy and often secretive GUI interfaces. You seemingly leave it up to pure chance.

To me, that is insane.

Systems Administrators are Your Friends

Friday, July 27th, 2007

Well, who knew. Someone actually decided to push a Systems Administrator appreciating day. Apparently, this is the eighth such occurrence, on the last Friday of July each year.

Web page here.

So, if there’s some kind and appreciative soul out there who wants to make my Systems Administrator day a special one, I’d love to have one of these.

In the meantime, I’ll be crawling under the floor in the machine room, fighting for cable space with the black widow spiders…

The Best OS Comparison Ever Done

Friday, April 27th, 2007

I’ve seen some interesting Mac vs. PC debates, as well as Windows vs. Linux, etc. Most are clearly biased one way or the other.

However, this Ubuntu vs. Vista showdown is the clear winner of intelligent OS comparisons. In a single page, BBspot sums it all up.