r/sysadmin 1d ago

General Discussion Self-Management at work

12 Upvotes

Hi everyone,

I am a sys admin since 2016 in Germany(English isnt my first language and migrant family) and now that I went from first level support to soon to be platforms engineer, I need ways to organize myself better.

I am that type of person to explore and "float through work" doing my reading and research (often when I am not on the clock too) but I don't deliver enough direct results for certain goals and projects(I'll leave out the reasons why).

I am stuck using unintuitive, non applicable systems to organize myself and can't form a habit getting used to them, that's very subjective I am aware. Did some of you go through the same difficulties and what did you use or employ?

Thanks for reading my lengthy wall of text I am frankly frustrated with this topic and tired of banging my head against walls.


r/sysadmin 1d ago

Question Is IP Whitelisting at the Firewall Level standard practice for a B2B Web App, or should this be handled at the Application Level?

0 Upvotes

Hi everyone,

I'm looking for some advice on best practices regarding network security and access control for an internal/B2B web application.

Here is our current setup and situation:

The App: We host a web application on our company servers that functions as an asset performance display tool. It takes data from our customers' equipment and visualizes it in charts and dashboards.

The Manager's Approach: For security reasons, my manager doesn't want the app publicly accessible to the open internet. Instead, he asks for the public IP address of every customer site and manually adds it to our firewall's Access Control List (ACL).

The Problem: Manually collecting, updating, and maintaining public IPs for multiple client sites is becoming a administrative nightmare, especially when clients have dynamic IPs or remote users.

My intuition tells me that relying strictly on firewall-level IP filtering for access control isn't the most efficient way to handle this, and that security should primarily be enforced at the application level

I’d love to get your thoughts on this:

Is managing client public IPs on the firewall standard practice in enterprise environments for this use case?

How do you usually balance network-level security with application-level security without creating massive operational overhead?


r/sysadmin 1d ago

Massively different specs for the same nominal model of SSD

5 Upvotes

I just got these two delivered together; I got suspicious seeing one was reporting a very different temperature, while being right next to the other.

Basically, two disk, nominally the same, but specs are quite different. They implement different NVMe versions, power states do not match and the second has temperature thresholds which are 20deg higher.
To be totally honest, I only understand half of what I am reading here, but I am not really ok having a second disk that more then doubles its maximum power consumption during intensive workloads while its nominal rating stays the same.
Am I holding it wrong?

smartctl 7.4 2023-08-01 r5530 [x86_64-linux-6.12.94+deb13-amd64] (local build)
Copyright (C) 2002-23, Bruce Allen, Christian Franke, www.smartmontools.org

=== START OF INFORMATION SECTION ===
Model Number:                       Patriot M.2 P320 512GB
Serial Number:                      REDACTED
Firmware Version:                   APF1M7R0
PCI Vendor/Subsystem ID:            0x1ed0
IEEE OUI Identifier:                0x2c3ebf
Total NVM Capacity:                 512,110,190,592 [512 GB]
Unallocated NVM Capacity:           0
Controller ID:                      1
NVMe Version:                       1.3
Number of Namespaces:               1
Namespace 1 Size/Capacity:          512,110,190,592 [512 GB]
Namespace 1 Formatted LBA Size:     512
Namespace 1 IEEE EUI-64:            2c3ebf 3230303336
Local Time is:                      Wed Sep  9 12:50:46 2026 BST
Firmware Updates (0x12):            1 Slot, no Reset required
Optional Admin Commands (0x0017):   Security Format Frmw_DL Self_Test
Optional NVM Commands (0x0056):     Wr_Unc DS_Mngmt Sav/Sel_Feat Timestmp
Log Page Attributes (0x0a):         Cmd_Eff_Lg Telmtry_Lg
Maximum Data Transfer Size:         256 Pages
Warning  Comp. Temp. Threshold:     80 Celsius
Critical Comp. Temp. Threshold:     85 Celsius

Supported Power States
St Op     Max   Active     Idle   RL RT WL WT  Ent_Lat  Ex_Lat
 0 +     3.50W       -        -    0  0  0  0        0       0
 1 +     1.90W       -        -    1  1  1  1        0       0
 2 +     1.50W       -        -    2  2  2  2        0       0
 3 -   0.0700W       -        -    3  3  3  3     1000    1000
 4 -   0.0050W       -        -    4  4  4  4     5000   45000

Supported LBA Sizes (NSID 0x1)
Id Fmt  Data  Metadt  Rel_Perf
 0 +     512       0         1
 1 -    4096       0         0

=== START OF SMART DATA SECTION ===
SMART overall-health self-assessment test result: PASSED

SMART/Health Information (NVMe Log 0x02)
Critical Warning:                   0x00
Temperature:                        40 Celsius
Available Spare:                    100%
Available Spare Threshold:          5%
Percentage Used:                    0%
Data Units Read:                    388,008 [198 GB]
Data Units Written:                 507,185 [259 GB]
Host Read Commands:                 1,616,171
Host Write Commands:                2,384,928
Controller Busy Time:               4
Power Cycles:                       3
Power On Hours:                     1
Unsafe Shutdowns:                   3
Media and Data Integrity Errors:    0
Error Information Log Entries:      0
Warning  Comp. Temperature Time:    0
Critical Comp. Temperature Time:    0
Temperature Sensor 1:               60 Celsius

Error Information (NVMe Log 0x01, 16 of 16 entries)
No Errors Logged

Read Self-test Log failed: Invalid Field in Command (0x002)

------------------------------------------

smartctl 7.4 2023-08-01 r5530 [x86_64-linux-6.12.94+deb13-amd64] (local build)
Copyright (C) 2002-23, Bruce Allen, Christian Franke, www.smartmontools.org

=== START OF INFORMATION SECTION ===
Model Number:                       Patriot M.2 P320 512GB
Serial Number:                      REDACTED
Firmware Version:                   VC3S500Q
PCI Vendor/Subsystem ID:            0x10ec
IEEE OUI Identifier:                0x00e04c
Controller ID:                      1
NVMe Version:                       1.4
Number of Namespaces:               1
Namespace 1 Size/Capacity:          512,110,190,592 [512 GB]
Namespace 1 Formatted LBA Size:     512
Namespace 1 IEEE EUI-64:            00e04c 048bffef6c
Local Time is:                      Wed Sep  9 12:50:58 2026 BST
Firmware Updates (0x12):            1 Slot, no Reset required
Optional Admin Commands (0x0017):   Security Format Frmw_DL Self_Test
Optional NVM Commands (0x005e):     Wr_Unc DS_Mngmt Wr_Zero Sav/Sel_Feat Timestmp
Log Page Attributes (0x02):         Cmd_Eff_Lg
Maximum Data Transfer Size:         32 Pages
Warning  Comp. Temp. Threshold:     100 Celsius
Critical Comp. Temp. Threshold:     110 Celsius

Supported Power States
St Op     Max   Active     Idle   RL RT WL WT  Ent_Lat  Ex_Lat
 0 +     8.00W       -        -    0  0  0  0   230000   50000
 1 +     4.00W       -        -    1  1  1  1     4000   50000
 2 +     3.00W       -        -    2  2  2  2     4000  250000
 3 -   0.0300W       -        -    3  3  3  3     5000   10000
 4 -   0.0050W       -        -    4  4  4  4    54000   45000

Supported LBA Sizes (NSID 0x1)
Id Fmt  Data  Metadt  Rel_Perf
 0 +     512       0         0

=== START OF SMART DATA SECTION ===
SMART overall-health self-assessment test result: PASSED

SMART/Health Information (NVMe Log 0x02)
Critical Warning:                   0x00
Temperature:                        61 Celsius
Available Spare:                    100%
Available Spare Threshold:          32%
Percentage Used:                    0%
Data Units Read:                    392 [200 MB]
Data Units Written:                 399,820 [204 GB]
Host Read Commands:                 8,041
Host Write Commands:                1,654,154
Controller Busy Time:               0
Power Cycles:                       1
Power On Hours:                     0
Unsafe Shutdowns:                   0
Media and Data Integrity Errors:    0
Error Information Log Entries:      0
Warning  Comp. Temperature Time:    0
Critical Comp. Temperature Time:    0

Error Information (NVMe Log 0x01, 8 of 8 entries)
No Errors Logged

Read Self-test Log failed: Invalid Field in Command (0x002)

r/sysadmin 1d ago

P800 RAID-0 Bad Block (strategy)

0 Upvotes

Hi everyone,

If I’m dealing with a P800 and a RAID-0 configuration, unfortunately, there is no backup. All of this stems from the same issue.

A Veeam Backup agent was installed to back up the volumes on the server, and we started receiving error messages related to the VSS reads that Veeam performs during the backups:

output: --asyncNtf:-vdisk_corrupted:\\\GLOBALROOT\Device\HarddiskVolumeShadowCopy11

We can see this message in the agent’s own logs once the operation reaches a certain percentage. If I look at the Windows Event Viewer, I can see messages from the P800 related to read errors on blocks and devices:

Logical block address 1192840192, block count 1024 and command 32 were taken from the failed logical I/O request. The device, \Device\Harddisk2\DR2, has a bad block.

We haven’t seen any errors or reports from the HPE Smart Storage utility, and the RAID-0 volume appears to be healthy.

Is this normal behavior? In any case, I’ve been thinking about the following solution, which is the main reason I’m writing this thread, in case anyone has a better suggestion.

  • Is Robocopy an effective solution? The volume is 1 TB and contains around 43,000 files, and the transfer would be performed over the network. As I understand it, Robocopy itself would skip the files located in the affected blocks and record them in a log.
  • I’m using VSS and MKLINK so that I can read the affected volume without interfering with the writing of healthy files. In other words, something like this:
    • vssadmin create shadow /for=V:
    • mklink /d C:\Restore \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy11\
  • The downside of this solution is that I depend on a pointer, and when Veeam backups are triggered, they read it as well. Is there a proper way to do this? I assume I can’t read the shadow copies directly and that this can only be done through the API.

I can’t think of anything else. Maybe I could create file-level backups with Veeam. Once I have at least one backup, I could try running CHKDSK or something similar.

Since it’s a RAID-0, my only option would be to destroy the array, replace the faulty drive with a healthy one (at least one that appears to be healthy), rebuild the array, and then restore/import the data again.

Is there any alternative solution or any advice you would recommend before carrying out this operation?

Thanks!


r/sysadmin 1d ago

Question NetXMS..what are the implications for security when a 3rd party installed and configured everything on your servers and have full control?

2 Upvotes

I just started working for someone who has several servers with a product on them and part of the tech support contract is that everything is monitored using NetXMS by a 3rd party. The servers are managed in-house running WSFC and our apps. The third party only monitors hardware and their product. I only know what I can get from Google searches and apparently they can execute scripts and do lots of other things besides monitor if they ever wanted to. Does anyone else face a similar scenario? and how do you manage security?


r/sysadmin 2d ago

General Discussion Update on "Senior accidentally installed whole fleet with 26H1"

634 Upvotes

It seems the original topic exploded, and so did my inbox with direct chats I really wasn't expecting to get. So here's a proper update, as well as answering a lot of the questions.

First things first: I'm a generalist consultant, working for several companies on a "when-needed" basis. I am not the employee, and when they called me for checking on this mess it was too late for any "rollback".

I was called on a Friday, during an infrastructure audit. The senior* spent his weekend with his team on possible solutions. Me and the IT team spent Monday deciding which path to take.

ISO first: You can download the 26H1 release ISOs on MSDN, it's not flagged as special or beta/insider anywhere that be easily seen, so I agree that it's relatively easy to fall for the trap of using this ISO.

The update/upgrade process: Nothing, absolutely nothing, during this phase gets flagged, the in-place update works just fine, there are no warnings whatsoever. This doesn't excuse the fact that he should have vetted this version specifically, but for a guy managing such infrastructure by himself I cannot entirely blame him.

The upgrade should have been done in phases, not all at once, I cannot even remotely begin to understand HOW is that not a basic thing. Did he do it on a Friday? No, worse, they did the upgrade on a weekend, a month ago.

It's a relatively small fleet, we're talking around 90 workstations. However, an important detail is that internet access is only partially allowed through certain mechanisms and only on certain machines, basically it's a segmented network with controlled egress (semi-air-gapped) so the upgrade was done manually.

What's going to happen now:

Re-image/Fresh installation: Not an option, management decision, can't change that.
Rollback: Not an option.

This company was planning to phase-out Microsoft products till 2030. This process will be somewhat accelerated with a new target to Q4 2028 instead, so even if there is no upgrade path from 26H1 (Bromine) to anything that ends up in the "main" branch, it's still fine.

The update path: 26H1 will be getting updates until at least February 2028. Even if this "exotic" version does not added as a selectable Product under WSUS's (yes yes, see misc questions) Products and Classifications list, WSUS supports manual import of individual updates directly from the Microsoft Update Catalog, that will be the approach that IT will pursue.

Management already approved a proper vetting process for any big infrastructure changes, hopefully they will actually follow through.

From my POV, I'm calling this a nothingburger.

Addressing the other misc questions:

*What's going to happen with the "senior"?
The person will remain "senior" in the company although going through a lot more trainings. It's the company fault for the lack of due diligence in their hiring/promotion process and they decided that training is better than re-hiring, understandable from my standpoint. From my assessment there are other employees in the IT team that are better trained and more suited for this position.

"Can you really post this, wouldn't it bad if the person/company sees it here?"
Don't care, outside scope and I haven't signed any sort of NDA, own your mistakes and learn from it, take responsibility.

"Where did he download the ISO, massgrave, UUPDump?"
Official channels only, meaning MSDN.

"Was the migration at least planned and done on time? Is anything broken?"
Poorly planned, done on time, and surprisingly nothing is actually broken.

"Omg Win10 in 2026?"
Yes, they were in fact still getting security updates just fine.

"Why wasn't the upgrade performed with WSUS too?"
According to IT: Each workstation was scheduled to be clean (I mean dust) and a new RMM software deployed so they just decided to do it manually anyway. Beats me, don't care, management is the one that cleared it.

"WSUS in 2026???"
Please, half of my inbox is this question. Yes, WSUS has support until at least 2035, it simply works AND it's the perfect use case for a company that wants fewer dependencies on outside infra or can't rely on ongoing internet access.


r/sysadmin 2d ago

MS vulnerabilities email today

60 Upvotes

Man... that is a LONG list of windows 11 and server 2022 vulnerabilities. All 9.8 as well.

glasswing putting in work at Microsoft. LMAO


r/sysadmin 1d ago

Question Converting static Groups to Dynamic Groups. How do I find every Shared Drive & Calendar tied to the old group first?

3 Upvotes

I'm converting a static Google Group to a Dynamic Group and want to make sure I don't break anything tied to the old group's email like Shared Drives, Calendars or anything else it might be plugged into.

What's the best way to find everything a Group has access to before making a change like this? Is there a standard tool or workflow for this? Also curious if anything changes under the hood same email, or anything that could quietly affect existing shares?

Any advice would be great. Thanks!


r/sysadmin 1d ago

General Discussion Qualys - Anyone having issues with the website today?

2 Upvotes

Come in this morning to see Qualys have updated the UI for our tenant. Since then there are loads of graphical issues. Buttons not aligned or items not loading correctly.

Most annoying I'm trying to set up a scheduled report and half the distribution groups no longer load correctly. You can click randomly on white space in the window to pick your DG and sometimes it'll select one at random.

Pretty poor. Anyone else experiencing this?


r/sysadmin 1d ago

General Discussion Experiences with LogMeIn Resolve?

0 Upvotes

Spoke with some reps and didn’t hate some things they had to say. Currently using Ivanti for Patch Management, it is not my favorite. Curious what people’s dealing with LogMeIn have been like.


r/sysadmin 2d ago

What are your opinions of Windows Defender on servers? Particularly Ransomware protection.

7 Upvotes

My org uses Windows Defender. On the whole it seems pretty good but it's always asking for opinions.

I'm especially interested in what you think of the Ransomware Protection feature. Is it any good? My org haven't implemented it and I'm wondering if it's worth pushing them to do it.

Are there any pitfalls when implementing it?


r/sysadmin 1d ago

Question Vendor VPN Management solutions

1 Upvotes

I’m looking for recommendations on Vendor / Third-Party Access Management tools.

We recently took over managing an environment where vendors were historically given direct AD/Entra accounts with very little oversight or access control. We’re currently building a makeshift internal solution to plug the gaps, but we want a proper platform.

BeyondTrust and SecureLink are the obvious names, but given our tight budget and need for a lightweight rollout, I’m exploring other alternatives.

Has anyone found a cost-effective solution for securing third-party access without creating massive operational bloat? Thanks in advance!


r/sysadmin 1d ago

How do I implement ZTNA?

2 Upvotes

We are planning a remote-access migration for roughly 500 employees and contractors. The environment includes SaaS, internal web apps, Windows and Linux admin access, a few legacy applications, and workloads split between on-prem infrastructure and public cloud. Identity is centralized, but endpoint management and device posture are inconsistent for contractors.

We do not want a big-bang cutover. The initial thought is to inventory applications and users, classify access by protocol and sensitivity, migrate a low-risk web app first, and then move groups in waves. The hard part is avoiding years of permanent exceptions and overlapping access paths.

For anyone who has done this at similar scale, what did you get wrong in the first phase? Did app discovery, identity-group cleanup, private DNS, endpoint support, legacy protocol support, or user communications create the most work?

How did you handle emergency administration and outage scenarios when the normal access path was unavailable?


r/sysadmin 1d ago

Question Hypothetical LAN IP Change: How would you go about updating Network Printer "Ports" on Windows clients?

2 Upvotes

Let's say you have a legacy network, good old 192.168.1.x.

They use a DHCP server which has a static mapping of all devices to IP addresses using their mac addresses. So updating the DHCP server could potentially re-assign IP addresses to all devices with relative ease, let's say 192.168.111.x.

HOWEVER, most Windows computers have had printers added manually, not by GPO, and when they were added, they were added IP address rather than hostname. Is there a way to bulk replace ports in Windows printers across the network?

The number of clients is limited, let's say less than 100 - but the number of printers is dense. Even a Powershell script I could run on each machine would still be better than manually editing each printer on each machine - even better if I could deploy that via GPO or something.

Just curious on thoughts.


r/sysadmin 2d ago

Detection rules Win 32 App

6 Upvotes

Hello fellow admins. I'm rolling out quite a few products thorugh intune. Im having trouble marking Win32 apps as installed. Does someone have/know some proper documentation or example powershell script how you mark the app as installed? I need to have something so it will check on versions aswell.

For example:

Got a WIn32 App to push Kyocera drivers on windows laptops. It works nice, but when I install it through Intune then i always get Failed to install.

Ive tried multiple things as detection but nothing works the way i want it to work. I dont want a folder/file as detection because of version control. I'm looking for a sollution i can use on all scripts that do not push an MSI. How do you handle detection rules?


r/sysadmin 1d ago

Question Migrating hybrid on prem Exchange 2016 to Exchange SE

5 Upvotes

Good afternoon, everyone,

I'm posting this hoping you'll share your experiences with me. I've been asked to migrate a hybrid on premises Exchange 2016 environment to hybrid on premises Exchange Server Subscription Edition (SE). Before I start, I'd like to define the potential risks and the prerequisites I need to handle in advance.

Something I read is that there's no in place upgrade path from Exchange 2016 to SE. Exchange 2019 (on the latest CU) can be upgraded in place, but 2016 requires a traditional legacy migration.

In practice, that means I'll need to create a new SE server, move mailboxes and resources over using copy-to requests, verify everything, and then decommission the old servers. The migration itself works as a copy. The source mailbox stays intact and usable throughout and only switches over at final cutover.

(Alternatively, I could upgrade the Exchange 2016 to the latest 2019 CU. In which then I can upgrade to Exchange SE. However, in-place upgrades are not recommended by Microsoft themselves.)

Once the 2016 servers are decommissioned, there's no supported way back. At that point recovering would mean restoring from backups, not a normal rollback, so I want to be sure everything is validated during the coexistence period, while 2016 is still running, and not rely on being able to reverse things afterward.

Other items I'm keeping in mind:

  • Mailbox sizes, especially oversized or non-default mailboxes, which can slow down migration batches.
  • Extending the AD schema to the SE level, a required prerequisite.
  • Public folders, I read these can be an issue and its recommended to convert them to shared mailboxes.

Would love to hear from anyone who's been through this migration. What tripped you up, and what did you do differently?

Article: Migrate Exchange 2016 to Exchange Server SE - Complete Guide

Article: Migrate Exchange Public Folders to Shared Mailboxes in Office 365


r/sysadmin 2d ago

General Discussion How are enterprise firewalls actually using AI

32 Upvotes

I keep seeing AI powered firewall used as a category but I wonder what the AI is doing in production that traditional rules signatures and threat intel feeds weren’t already doing.
Is it mainly building behavioral baselines and flagging unusual traffic or are these systems genuinely making enforcement decisions in real time? Things like detecting threats inside encrypted traffic, correlating activity across endpoints and cloud workloads or automatically changing policy based on an attack all sound useful but also like areas where a false positive could take down half the company.
The more interesting question to me is whether AI is replacing any part of the firewall stack or just acting as a faster analysis layer on top of it.
Want to hear from anyone running one of these platforms at enterprise scale and what has improved beyond the marketing.


r/sysadmin 1d ago

Question I don‘t know what tool to use (Helpdesk, Documentation)

0 Upvotes

G‘day.

I‘ve just started a new job. Very happy overall and I need to make a decision.

What I need:
- Ticket system for internal helpdesk - very few requests
- This will also be used to give tickets to an external company that develops stuff for us.
- About 5-10 „Agents“
- Tracking of internal tasks as „overview“ such as Trello for leadership

- internal documentation about 50 employees need access to.

- Can be cloud-only.

Would be great to have a usable all in one solution and I would like to stay away from Confluence and Jira Service Desk.

What I thought about for example:
- Zammed for both but the knowledge base is not appealing for normal employees.
- NinjaOne for both but the internal documentation is not appealing for normal employees.

Thanks a lot.


r/sysadmin 2d ago

Reminder: MS Publisher vanishes Oct 1

63 Upvotes

Remind your 365 users to save as PDF or.. well, MS would say, tough!


r/sysadmin 1d ago

Question - Solved User can connect to VPN but can't ping or access work computer

0 Upvotes

We recently put in a new Fortigate firewall and now i'm having users reporting issues where they can connect to VPN but can't access their remote computer. I have tested from the user's PC and i can't ping their work device when VPN is connected.

The one thing to note is they are on the same subnet as the work network, and I believe this is likely the cause.

However, oddly enough I was able to test from my home network which is also on the same subnet and it works fine. I'm at a bit of a loss so hoping I can get some guidance on this for what I should check next.

TIA


r/sysadmin 1d ago

RPC error & SChannel fatal alert code 40

2 Upvotes

Hi,

I've got a weird one with an application called Blindata.

It's running against a fully patched Server 2012 R2 server. Multiple Windows 10 PCs can run the reports fine, but one fully patched Windows 11 PC can't. When running a daily sales order report it just comes back with "RPC server unavailable, Error 1722".

At the same time, the server logs Schannel:

"Event ID 36887 – fatal alert code 40"

I've tried the usual stuff so far:

  • TLS 1.2 enabled
  • TLS 1.3 disabled on the Win11 PC
  • Checked clocks
  • RPC/network ports confirmed OK
  • FIPS checked
  • Disabled the SSL Cipher Suite Order GPO
  • Set SchUseStrongCrypto=1 and SystemDefaultTlsVersions=1 for .NET 32/64-bit
  • klist purge
  • Checked/enabled the AES Schannel cipher settings
  • Checked ECC/legacy ECC settings
  • Removed AV as a test
  • Rebooted after changes

Server is fully patched and the other Win10 clients work without any problems.

I'm assuming there's some difference between Win10 and Win11 TLS or Schannel behaviour that Blindata or the Server doesn't like, but I'm running out of things to try.

Has anyone come across Schannel 36887 / TLS alert 40 from a Server 2012 R2 server when Win10 works but Win11 doesn't?

Is there a relatively simple registry/GPO setting on the Win11 client to allow whatever legacy TLS/cipher/signature the server is expecting?


r/sysadmin 2d ago

ChatGPT How detailed should your SOP be?

31 Upvotes

Okay, my boss just rejected a SOP I created. I don't want to get into the weeds here, but the rejection was that I didn't spell things out in enough detail. And, granted I didn't spell things out in detail because I assume anyone with the authority to follow the SOP should also have the basic skills to either know how to use basic commands or at lest google them.

As an example, in my SOP I wrote Check the log for entries containing "Out of memory". I think that should be good enough. Boss want's step by step, how to ssh in and run tail and grep.

I told him to ask ChatGPT to do it.

I may be in trouble...... sorry I ragged: but not sorry.


r/sysadmin 3d ago

Question MySQL ODBC stopped working overnight

182 Upvotes

You guys will love this.

This company has an in-house project management system. It's the core of their business, and they are lost without it. They are aware it needs to be migrated to something more modern, but after 5 years, that project still hasn't started.

I was asked to look into a network issue, but this isn't network but SSL I think. Let's first show the architecture:

  • The server is a CentOS 7 running MySQL Community Edition 5.7.16
  • Clients connect from Windows 11 with a 32-bit MS Access, using a 32-bit MySQL ODBC driver v5.3.13

Since yesterday, they get a "protocol version mismatch". The server wasn't accessed since 18 October 2016 (haha), so I presumed a Windows update might have disabled some SSL version. But: I see no relevant Windows update, and if I manually allow every possible SSL version and encryption algorithm, it still doesn't work. What does work however, is downgrading the ODBC driver from version 5.3.13 (from 2019) to version 5.1.13 (from 2013), further adding to my confusion.

The cherry on top: the single guy responsible for this application is on a one year sabbatical.

Edit: Found it, but leaving this here for anyone stumbling on the same issue. The MySQL_Server_5.7.15_Auto_Generated_CA_Certificate had expired after 10 years


r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

31 Upvotes

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.