19 November 2013

7.5 Summit November 2013 - Slides and Videos

A lot of usefull information can be found here

About Workflow and the Symantec Management Platform

About Workflow and the Symantec Management Platform


The Symantec Management Platform architecture consists of several key parts. These parts include the CMDB, Item Object Model, Resource Model, Solution Layer, UI Framework, and ASDK (Altiris Software Development Kit). Workflow interacts with the platform through a web service layer and the custom web services that are installed directly onto the Symantec Management Platform computer.

However, not all workflow processes directly integrate with the Symantec Management Platform. A workflow process may only depend on the platform for a license for the instance of Workflow Server where it is running.

A workflow process can integrate more fully with the Symantec Management Platform or another solution by using web service calls. A workflow process can work with any standard web service in the Symantec Management Platform or solutions. For example, a process that escalates a ServiceDesk incident can make a web service call to ServiceDesk to change the priority, affect, or urgency.

17 November 2013

Trending Patch Compliance useful tools

This was written by one of our engineers Ludovice Ferre I have written a few utilities to help my customer understand how well our Patch Management tool works for them and with the help of colleagues here in EMEA I’ve integrated them into a single package and I have written a guide to quickly and simply implement the tool. Here are the main link for this project: http://www.symantec.com/connect/articles/adding-patch-trending-your-symantec-management-platform-step-step-guide • Step-by-step installation guide • Main download page • Sample site for hands on test Adding Patch Trending to Your Symantec Management Platform Step by... symantec.com Symantec helps consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or...

Task 0000 GUID Issue

TECH146046 – This is commonly known as the task 00000’s guid issue. This is an error that is a symptom from various solutions that assign tasks to run on a resource that has the default guid of all 00000’s. Some solutions have fixed this issue in … ITMS 7.1

ITMS 7.5 HF1 is targeted for release - Nov 18th

More will follow….

12 November 2013

App Center v4.2 Migration guide

Migration to Symantec App Center 4.2 involves adding new servers that support RHEL/CentOS 6.4 and adding an MDM Core database to the existing App Center database. The migration will involve some down time to current production servers. A first version of a migration guide has now been published to Symwise. This document describes what you'll need to know about migrating to Symantec App Center v4.2. The document can be found here: http://www.symantec.com/docs/DOC6841.

Physical \ Virtual Computer issue

More info on this issue can be found here

09 November 2013

08 November 2013

Symantec Endpoint Protection 12.1.4 is now available


On November 5, 2013, Symantec released Symantec Endpoint Protection 12.1.4. You can download this version from Symantec FileConnect or the Business Critical Services Web site.   
   
This version contains a number of new features, including support for Windows 8.1 and Mac OS X 10.9, a suite of new features for managing Mac clients, and an improved mechanism for reporting priority events as they happen, as well as fixes for customer-reported issues.  Symantec recommends this upgrade for all customers, especially those who manage Mac clients, use Windows 8.1, or require one of the fixes that are included in this release.   
   
For more information about this release, read the updated product documentation in the Related Articles section.


Supportability Statement for Microsoft Windows Embedded

A PDF can be found here

SQL Maintenance script for the Symantec Management Platform database

There is a script available to create a Maintenance task on SQL Server here

03 November 2013

What is new in SQL2012

A lot....even to much to mention in a blog so here you can find out more

02 November 2013

SQL Version builds



 RTM (Gold, no SP)SP1SP2SP3SP4
 SQL Server 2014
     codename Hekaton
     
 SQL Server 2012
     codename Denali
11.00.2100.6011.00.3000   
 SQL Server 2008 R2
     codename Kilimanjaro
10.50.1600.110.50.250010.50.4000  
 SQL Server 2008
     codename Katmai
10.00.1600.2210.00.253110.00.400010.00.5500 
 SQL Server 2005
     codename Yukon
9.00.1399.069.00.20479.00.30429.00.40359.00.5000
 SQL Server 2000
     codename Shiloh
8.00.1948.00.3848.00.5328.00.7608.00.2039
 SQL Server 7.0
     codename Sphinx
7.00.6237.00.6997.00.8427.00.9617.00.1063

01 November 2013

Altiris Licensing - Technical FAQ

How does Altiris licensing work for Notification Server based products?
  • How a license is consumed.
  • What happens when the license count is exceeded.
  • What happens when a time limited (demo/install) license expires.
  • What happens when the Automatic Upgrade Protection (AUP) expires.
  • How to recover a solution license (retirement vs. deletion).
  • Anomalies in expected functionality.

More info about this topic can be found here

How to prepare a workstation for imaging that includes the SMP/NS Agent (Updated October 2013)

Problem

How can I image a computer with the Altiris Agent on it? What is needed to prepare the NS Agent when distributed as part of an image?
 
The Altiris Agent has a unique GUID for each workstation. If done incorrectly, when a new workstation is started with the same GUID as another, Notification Server will begin to manage it as if it is the same system as the other. Inventory from the multiple computers keeps over-writing each other, so systems "seem" to disappear from the NS/SMP console.  MANY solutions are impacted by this.
 
Additionally, Microsoft OS's include a SID or Security Identifier which is unique, and is how Microsoft keeps systems separate in Active Directory.  Like the GUID, if this is duplicated on the network, it causes significant problems in AD and we frequently have to refer customers to Microsoft for multiple days of cleaning up AD.
 

Resolution

Depending on the version or product you're using, there are several potential options.
Using GSS
Ghost Solution Suite has no built-in mechanism for removing the GUID's from NS.  That said, if you have NS7, you most likely have DS7 and should follow the steps for imaging using DS7.
 
However, if you do not have DS7 (or do not intend on using it) then you can either remove the Altiris Agent prior to capturing the image (recommended) or manually remove the GUID from the Agent.  The GUID is in 3 locations in the registry:
 
  1. HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\eXpress\MachineGUID
  2. HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\eXpress\NS Client\MachineGUID
  3. HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\Altiris Agent\MachineGUID
It should be noted however that the agent must be stopped for this to work.  As soon as the agent re-starts, those registry keys will be repopulated!  So, to do this, you should stop the agent service (leave it set to automatic), remove these registry keys, and immediately follow standard procedures in GSS to capture the image without restarting the system in production OR restarting the service.

Using DS 6.5/6.8/6.9
Any of the supported versions of DS 6.x will remove the GUID from the NS/SMP agent if capturing using the supported methods.  The capture image task takes care of this for you by first removing the GUID from the agent and then running Microsoft's Sysprep tool, and then rebooting and capturing the image while in this state.

Using DS 7.x
DS 7.x takes care of this when you run the Prepare for Image Capture task (which is run prior to capturing the image itself).  This is the only supported method of capturing a disk image (as apposed to a backup image). The Prepare for Image Capture task takes care of this for you by first removing the GUID from the agent and then running Microsoft's Sysprep tool  Unlike DS 6.9, you then need to run the Capture Image task separately (before a reboot to production), but the net effect is the same.

Doing things manually (Unsupported)
There are those who insist on running Sysprep manually and only using our engine/tools (Ghost and RDeploy) to capture and deploy the images.
At least one reason for this is that there is a Microsoft Technet article that indicates that the "appropriate" way to modify the default profile is to run Sysprep in Audit mode and then modify the default profile prior to image capture.  Our built-in processes do not support this.  The default profile can be modified in several other ways that are supported by our processes, but we acknowledge that those methods are not "as complete" as the one indicated by Microsoft.  99% of our customers have been satisfied with the other methods of modifying the default profile and we highly recommend trying our method first.  If you are then still not satisfied and insist on doing things this way, you should consider a few things:
  • IF the agent is included then the 3 registry keys indicated under the GSS method must be removed.
  • The Unattend.xml MUST be correctly managed by yourself.  We continually see problems with this method in the XML files where there are issues with architecture and custom commands.  Custom Unattend.XML files are not supported by Symantec, though support offers a best-effort level to help you find / identify problems with it.
NOTE:  If you are using DS 7.x and attempting this method, the Agent should be included and the keys removed manually.  This is a very awkward and again unsupported way of doing things, but in order to synchronize with post-imaging processes, we recognize the need to have the agent installed.  You could actually install the agent post imaging, or follow the KB on including the installer into the Unattend file, both of which would work, but both of which will delay any post-image processes / tasks you may have included in the job.  We recognize this as a viable process, but do not recommend it or support it, other than in a best-effort mode.

Not using Sysprep (Very Bad & Unsupported)
This is both not supported by us and not supported by Microsoft.  Some have found a single article published once-upon-a-time by a Microsoft employee who claims that Sysprep is not needed.  This is incorrect!  Every customer we have found who has done this has required several DAYS of support from Microsoft to clean up their directory.  We will send you to Microsoft when you run into problems and we will not be able to help you with your Active Directory (we can help with duplicate GUIDS, but be warned, it can be messy).  For imaging to work in ANY of our environments, Sysprep MUST be run in some method or manner.
The only exception to this is if you are taking a backup image of a single system and restoring ONLY to that system.  As soon as an image is deployed to more than one system without Sysprep having been run first, it is in an unsupported state.

ITMS 7.5 (Orion) Release of Workflow and Existing Servicedesk Installations

With the release of ITMS 7.5 (Orion), a new version of Workflow is now available. Can I install this version on my existing Servicedesk server?  

Answer: 

No! This is a standalone version of Workflow that is NOT compatible with any version of Servicedesk that is
currently in production. You will break your Servicedesk installation by installing the Orion version of Workflow on your Servicedesk 7.5 server. You should wait until the upcoming 7.5 Sp1 version of Servicedesk releases (scheduled for the first part of November 2013), and update your Servicedesk installation with the revised Workflow and Servicedesk versions that are included as a part of that release.

Quick reference to the HOWTO doc for ITMS 75

These can be found Here

Support Matrix ITMS (6, 7, 71, 7.5)

Can be found here

KNOWN ISSUE: Upgrade to ITMS 7.5: Some tables in DB have different definition form tables in case of clean setup - missing indexes

This issue has been reported to the Symantec Development team. A fix will be available in a later release (Post ITMS 7.5 release). The following is provided as a workaround. Basically run the following queries on your SQL Database to recreate the missing indexes: --Index for ResourceTargetContainerChanges IF NOT EXISTS (SELECT * FROM sys.indexes WHERE object_id = OBJECT_ID(N'[dbo]. [ResourceTargetContainerChanges]') AND name = N'IX_ResourceTargetContainerChanges') CREATE INDEX [IX_ResourceTargetContainerChanges] ON [dbo]. [ResourceTargetContainerChanges] ( ResourceGuid ) --Index for ItemPresentation IF NOT EXISTS (SELECT * FROM sys.indexes WHERE object_id = OBJECT_ID (N'[IDX_ItemPresentation]') AND name = N'IDX_ItemPresentation') CREATE INDEX [IDX_ItemPresentation] ON [dbo].[ItemPresentation] ( BaseGuid ) -- Index for Evt_NS_Item_Management IF NOT EXISTS (SELECT * FROM sys.indexes WHERE object_id = OBJECT_ID(N'[dbo]. [Evt_NS_Item_Management]') AND name = N'IDX_DC_457b321d-26eb-449d-996c- 5aff16a391ec_ItemGuid') CREATE INDEX [IDX_DC_457b321d-26eb-449d-996c-5aff16a391ec_ItemGuid] ON [dbo].[Evt_NS_Item_Management] ( ItemGuid )