This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
kyle_wolff
Active participant
Dec 11, 2020
03:51 PM
Also, I have read How-to-setup-https-SSL-TLS-to-secure-and-encrypt-internal-FNMS, but the only option listed for Non-Windows Lite agent is passing -o CheckServerCertificate=false -o CheckCertificateRevocation=false against ndtrack.sh, but this is not a great option.
... View more
Dec 11, 2020
03:44 PM
Is it possible to configure a Unix standalone agent package (ndtrack.sh) to work on HTTPS? When doing a full agent install, there is an mgsft_rollout_cert file that is required to be in the same directory as the install package and mgsft_rollout_response file. After installation, the certs within mgsft_rollout_cert are pinned on the system so it can communicate using HTTPS. What is required for ndtrack.sh to work using pinned certificates? Is it as simple as including your mgsft_rollout_cert file in the same dir you have your ndtrack.sh, ndtrack.ini and InventorySettings.xml files? Or, does it require something additional passed in the command against ndtrack.sh? Or, is it even possible? I ask because in the documentation for ndtrack command line I see Preferences for SSLCA and SSLCRL related options, but only under the full UNIX agent install column, NOT for UNIX ndtrack.sh. If it's possible, could we an example of how it's done?
... View more
Jul 13, 2020
01:41 PM
Here are some helpful links. SQL Version Detection and Reporting with SCCM https://sccm-zone.com/sql-version-detection-and-report-sccm-2012-r2-12f299b5e63b SQL Server Product and Version Reporting with SCCM https://sccm-zone.com/sccm-zone-sw-sql-server-products-395b89e14ab4
... View more
Jun 24, 2020
01:23 PM
Hi @kclausen, as of December 2019, Analytics in the Cloud did not have schedule and email capabilities. I wanted to check in and ask if this has changed, or if/when the capability is coming?
... View more
May 07, 2020
02:18 PM
1 Kudo
@ChrisG ah-HA! Perfect, this works just fine. Thank you for the tip!
... View more
May 06, 2020
05:17 PM
1 Kudo
Hi @KPBussey , When using Advanced Search, there is (at least in Chrome) no longer the ability to open links in a new tab (aside from clicking on 'Use Classic Search'). Will this be changed in the future? Thank you, -Kyle
... View more
Mar 05, 2020
11:55 AM
I guess more specifically, does Flexera support Photon Linux based VCSA 6.5/6.7 vCenters (appliances)?
... View more
Mar 05, 2020
10:32 AM
Does anyone have experience working in environments that are running Photon OS ("an open source, minimal Linux container host that is optimized for cloud-native applications, cloud platforms, and VMware infrastructure") they can share as it relates to FNMS Discovery and Inventory for VMware and the FlexNet Inventory Agent running on it? https://vmware.github.io/photon/
... View more
Labels
Feb 24, 2020
10:00 AM
3 Kudos
I'm looking for a consolidated list of areas Flexera FNMS customers would need to be aware of and/or double check based on the LDAP channel binding and LDAP signing requirement updates coming from Microsoft in March. https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190023
... View more
Labels
Jan 27, 2020
03:18 PM
1 Kudo
I have a situation where the .actdir.gz files are not being processed by the Application server. They just get placed in the BadLog's folder. Background: File is 48MB 1 Beacon server pulling AD data from 1 DC with multiple trusted domains existing within the forest .actdir.gz file is generated without issue on the Beacon before sending to App server Default IIS Application Settings for /ManageSoftRL of ImportTypesProcessedDirectly includes "activedirectory" (so files coming from the Beacon server are immediately processed) Registry entry within \ManageSoft Corp\ManageSoft\Compliance\CurrentVersion of CommandTimeout REG_SZ 259200 was added (increasing timeout value to 72 hours or 3 days) This was added a while ago and fixed a Database timeout issue .actdir.gz files end up in \ProgramData\Flexera Software\Incoming\ActiveDirectory\BadLogs\failure I've manually processed failed .actdir.gz files running \Flexera Software\FlexNet Manager Platform\Importers\bin\mgsimport.exe -t activedirectory generating a log Log errors include: SQL EXCEPTION: -------------------- System.Data.SqlClient.SqlException (0x80131904): Execution Timeout Expired. The timeout period elapsed prior to completion of the operation or the server is not responding. The wait operation timed out - Unexpected exception in importer There are no "CNF records" within the .actdir .xml, but there are Computer CN's that have the letters "CNF" within it's legitimate Name, but not in any ObjectGUID's or ObjectSid's I've copied one of the .actdir.gz files and processed within an local VM version of FNMS and was able to process it No antivirus software is preventing the file from being processed according to AV logs No duplicate processes for ActiveDirectory import (I've disabled the scheduled task altogether) Thanks for reading. I appreciate any other thoughts or things to try.
... View more
Jan 24, 2020
11:39 AM
1 Kudo
SSO is what they should be using but it's sort of an odd situation where SSO likely won't help here. But I'll pass along the suggestion of the local account on the App server, citing the fact it will circumvent corporate security policies, and see if it works for them (they'd allow the exception). Appreciate the suggestions @erwinlindemann @mfranz .
... View more
Jan 23, 2020
04:40 PM
2 Kudos
Pretty self explanatory. I have my assumptions but am looking for a definitive answer. Is there a way to create a user account in FNMS that is not tied to a Windows domain? Use case is an organization has subsidiaries that are not a part of their domain and need to keep them separate, but someone from that organization needs access to the parent companies' on prem FNMS instance. Their NAT allows the user to get to the to the FNMS Web UI, but they don't want to create an account for the user on the parent company domain.
... View more
Jan 22, 2020
08:40 AM
@erwinlindemann thank you for this. I will test this out and if it works, mark your comment as the solution. I think adding this information would be an excellent addition to Flexera's Web Help article around this topic: https://helpnet.flexerasoftware.com/fnms/EN/WebHelp/index.html#topics/FIB-PortsAndURLs.html https://helpnet.flexerasoftware.com/fnms/EN/WebHelp/index.html#reference/FIB-URLs.html While these online help pages have a couple certificate and CRL related links, including something like the link to the full list of CRL's to whitelist would make it a one stop shop. https://knowledge.digicert.com/solution/SO28935.html
... View more
Jan 21, 2020
05:28 PM
2 Kudos
I'm working in a customer environment experiencing an issue I haven't before and haven't been able to pinpoint why it's happening. Synopsis: Customer environment very locked down so worked closely with firewall team to open up everything required based on Flexera's documentation (firewall audit logs show nothing being dropped) External Firewall rules created based on https://helpnet.flexerasoftware.com/fnms/EN/WebHelp/index.html#topics/FIB-PortsAndURLs.html https://helpnet.flexerasoftware.com/fnms/EN/WebHelp/index.html#reference/FIB-URLs.html TLS 1.1 and 1.2 Client/Server enabled and SSL 2.0 disabled by default, use strong crypto turned on, (standard beacon settings based on Flexera KB https://community.flexera.com/t5/FlexNet-Manager-Knowledge-Base/Transport-Layer-Security-TLS-1-1-1-2-Configuration/ta-p/2250 When CheckCertificateRevocation=True, all files collected on the Beacon servers will not be transmitted to the FNMS Cloud. (assuming because the check against CRL is not happening so file transmission is being denied) When CheckCertificateRevocation=False, all pending files collected are transmitted. I have not experienced this issue with any other customer to date. All are using the default configuration of CheckCertificateRevocation=True with no issues. My question is, what is happening with =True vs =False that is causing files from the Beacon server to not send to the FNMS Cloud, and what needs to happen for =True to work as expected? upload.log states the following: Error 0x80092012: The revocation function was unable to check revocation for the certificate. Error 0xE050044D: Failed to create remote directory /ManageSoftRL Error 0xE0690099: Specified remote directory is invalid, or could not be created ERROR: Remote directory is invalid Upload failed due to a server side issue. This server may be retried during this upload session. Ignoring failover locations for upload on an inventory beacon WARNING: FlexNet Manager Platform has failed to upload a file to all configured upload servers; aborting attempt to upload these file(s) I'm at a loss as Firewall logs show nothing being blocked or dropped.
... View more
Latest posts by kyle_wolff
Subject | Views | Posted |
---|---|---|
172 | Dec 11, 2020 03:51 PM | |
185 | Dec 11, 2020 03:44 PM | |
349 | Jul 13, 2020 01:41 PM | |
435 | Jun 24, 2020 01:23 PM | |
685 | May 07, 2020 02:18 PM | |
703 | May 06, 2020 05:17 PM | |
846 | Mar 05, 2020 11:55 AM | |
855 | Mar 05, 2020 10:32 AM | |
679 | Feb 24, 2020 10:00 AM | |
511 | Jan 27, 2020 03:18 PM |
Activity Feed
- Posted Re: Is it possible to use standalone UNIX agent ndtrack.sh over HTTPS? on FlexNet Manager Forum. Dec 11, 2020 03:51 PM
- Posted Is it possible to use standalone UNIX agent ndtrack.sh over HTTPS? on FlexNet Manager Forum. Dec 11, 2020 03:44 PM
- Got a Kudo for Add NDI File Replication Functionality to the FlexNet Beacon. Nov 18, 2020 04:40 AM
- Got a Kudo for Microsoft 365 / Office 365 Adapter - FNMS 2019 R1 - Azure User Account Roles / Token Generation. Oct 13, 2020 08:02 PM
- Got a Kudo for Re: Microsoft 365 / Office 365 Adapter - FNMS 2019 R1 - Azure User Account Roles / Token Generation. Oct 13, 2020 02:03 PM
- Kudoed FNMS Logging Reference for dcollins. Jul 24, 2020 11:44 AM
- Posted Re: SQL Edition information from SCCM is Missing in FNMP on FlexNet Manager Knowledge Base. Jul 13, 2020 01:41 PM
- Posted Re: Setting up auto report on FlexNet Manager Forum. Jun 24, 2020 01:23 PM
- Kudoed How to allow beacon network scans in a network with ICMP disabled for jjensen. Jun 10, 2020 07:16 PM
- Kudoed Users missing from search results when creating accounts in FNMS On-Premises for jjensen. Jun 10, 2020 07:15 PM
- Got a Kudo for Re: Have a question on enhanced community search?. Jun 06, 2020 10:21 AM
- Got a Kudo for Re: Have a question on enhanced community search?. May 07, 2020 02:29 PM
- Posted Re: Have a question on enhanced community search? on The Hub. May 07, 2020 02:18 PM
- Kudoed Re: Have a question on enhanced community search? for ChrisG. May 07, 2020 02:17 PM
- Posted Re: Have a question on enhanced community search? on The Hub. May 06, 2020 05:17 PM
- Kudoed How to configure the beacon to use a different name or alias than its host name for mrichardson. May 06, 2020 05:13 PM
- Posted Re: Photon OS - VMWare Discovery and Inventory and FlexNet Inventory Agent on FlexNet Manager Forum. Mar 05, 2020 11:55 AM
- Posted Photon OS - VMWare Discovery and Inventory and FlexNet Inventory Agent on FlexNet Manager Forum. Mar 05, 2020 10:32 AM
- Tagged Photon OS - VMWare Discovery and Inventory and FlexNet Inventory Agent on FlexNet Manager Forum. Mar 05, 2020 10:32 AM
- Got a Kudo for March 2020 Updates from Microsoft (LDAP specifically) and the Impact on FNMS. Feb 28, 2020 02:48 PM
Contact Me
Online Status |
Offline
|
Date Last Visited |
Feb 26, 2021
02:17 PM
|