<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v4.1.2 (http://www.squarespace.com/) on Wed, 09 Jul 2008 10:50:26 GMT--><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:rss="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:cc="http://web.resource.org/cc/"><rss:channel rdf:about="http://www.shutuplaura.com/journal/"><rss:title>Laura's Rants and Raves</rss:title><rss:link>http://www.shutuplaura.com/journal/</rss:link><rss:description></rss:description><dc:language>en-US</dc:language><dc:date>2008-07-09T10:50:26Z</dc:date><admin:generatorAgent rdf:resource="http://www.squarespace.com/">Squarespace Site Server v4.1.2 (http://www.squarespace.com/)</admin:generatorAgent><rss:items><rdf:Seq><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/7/8/there-are-only-2-positions-on-a-snowboard.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/7/7/an-unexpected-musical-discovery.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/30/self-signed-cert-requirements-in-the-adfs-step-by-step-guide.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/29/suffering-mightily-under-the-iron-fist-of-pki.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/29/better-to-fight-your-battles-with-duct-tapeduct-tape-makes-y.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/26/step-by-step-guide-for-ad-fs-in-windows-server-2008.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/26/with-apologies-to-jeff-foxworthy.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/26/pardon-me-whilst-i-dance-the-dance-of-joy.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/22/first-create-a-unity-of-purpose-then-take-over-the-world.html"/><rdf:li rdf:resource="http://www.shutuplaura.com/journal/2008/6/21/scripting-sysadmin-meme.html"/></rdf:Seq></rss:items></rss:channel><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/7/8/there-are-only-2-positions-on-a-snowboard.html"><rss:title>There are only 2 positions on a snowboard:</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/7/8/there-are-only-2-positions-on-a-snowboard.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-07-08T02:49:29Z</dc:date><dc:subject>humour</dc:subject><content:encoded><![CDATA[<p>One is &quot;looking really cool&quot;...the other is &quot;DEAD!&quot;</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/7/7/an-unexpected-musical-discovery.html"><rss:title>An unexpected musical discovery.</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/7/7/an-unexpected-musical-discovery.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-07-07T22:53:27Z</dc:date><dc:subject>personal</dc:subject><content:encoded><![CDATA[<p>So I'm sure that all of my readers of a certain vintage remember <a href="http://www.a-ha.com/" target="_blank">a-ha</a>, right?[1]&nbsp;Well, it turns out that their <a href="http://www.magne-f.net/" target="_blank">keyboardist </a>has released a few solo projects, the <a href="http://www.amazon.com/Past-Perfect-Future-Tense-Magne/dp/B000ACZUFI" target="_blank">most recent of which</a> I just downloaded off of iTunes on a whim and it's <em>fracking awesome</em>. (And his website is entirely odd and in keeping with my sense of humour, too.)</p><p>What's the album sound like? Well, some people seem to think that my beloved Marillion simply sound like Journey, so I suppose that I need to think of a similarly well-known&nbsp;analogy for this one.&nbsp; Uhhh....hmmm...I suppose Magne smacks a bit of the Goo Goo Dolls, or of the Dave Matthews Band. Maybe.&nbsp; If either of those is your cup of tea, go download &quot;Kryptonite&quot; and &quot;Nothing Here to Hold You&quot; from your MP3 provider of choice to see if the rest of&nbsp;&quot;Past Perfect Future Tense&quot;&nbsp;might float your boat.</p><p>&nbsp;</p><p>[1] You know, that &quot;one-hit wonder&quot; band from the 80's who've actually released something like a dozen albums over the last 22 years.&nbsp; :-)</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/30/self-signed-cert-requirements-in-the-adfs-step-by-step-guide.html"><rss:title>Self-signed cert requirements in the ADFS step-by-step guide.</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/30/self-signed-cert-requirements-in-the-adfs-step-by-step-guide.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-30T15:22:24Z</dc:date><dc:subject>tech Identity AD FS</dc:subject><content:encoded><![CDATA[<p>Putting them all in one place for my own reference and anyone else who needs it.</p><p>How to make it go:</p><ul><li>On ADFSACCOUNT, import the Token-signing certificate from ADFSRESOURCE into the local computer's Personal store.</li><li>On ADFSRESOURCE, import the Token-signing certificate from ADFSACCOUNT into the local computer's Personal store.</li><li>On ADFSWEB, import&nbsp;the root CA for ADFSRESOURCE into the local computer's Trusted Root Certificates store.</li><li>On ADFSCLIENT,&nbsp;import&nbsp;the root CA for ADFSACCOUNT, ADFSRESOURCE, and ADFSWEB into the local computer's Trusted Root Certificates store. (NB: the claimapp sample app will still <em>work</em> if you miss this part, you'll just get one or more &quot;IE doesn't like this cert, do you want to continue?&quot; prompts nagging at you when you attempt to test from the client.)</li></ul><p>All of these can be exported as .cer files; at no point do you need to go exporting private keys from one machine to another. (I think the docs reference exporting the ADFSRESOURCE cert to ADFSWEB as a .pfx file, but I made it work without doing so, for my part.)&nbsp; You will achieve more reliable results if you import the certs using the Certificates MMC, not Internet Explorer, and if you do so while signed on as a local admin on the respective box, so that the certs land in the computer's cert store rather than a user-specific store. The docs indicate that the ADATUM test user doesn't need to be a local admin on the client box to run the sample app, and it doesn't...but doing the leg-work to make the certs behave as desired is another story.</p><p>To see if you have achieved&nbsp;self-signed certificate nirvana, confirm that you can navigate to the following URLs from the client without receiving any cert errors: </p><ul><li><div>https://adfsaccount.adatum.com (NB: will return a blank page. <em>That's fine</em>, you just want to confirm that you can get there without any cert errors.)</div></li><li><div>https://adfsaccount.adatum.com/adfs/fs/federationserverservice.asmx (Will return a standard-looking ASP.NET ASMX page.)</div></li><li><div>https://adfsresource.treyresearch.net (Also blank, but should fire up with no cert errors.)</div></li><li><div>https://adfsresource.treyresearch.net/adfs/fs/federationserverservice.asmx (Standard-looking ASMX page.)</div></li><li><div>https://adfsweb.treyresearch.net (Another blank one.)</div></li></ul><p>The moral of this story being, of course, that self-signed certificates will be the death of me before this day is over.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/29/suffering-mightily-under-the-iron-fist-of-pki.html"><rss:title>Suffering Mightily Under the Iron Fist of PKI</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/29/suffering-mightily-under-the-iron-fist-of-pki.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-29T22:10:37Z</dc:date><dc:subject>tech Identity</dc:subject><content:encoded><![CDATA[<p>So. The 2008 ADFS Step-by-Step guide.&nbsp; (Thank you Matt for the link, once again.)</p><p>The ADFS part?&nbsp; Fairly easy, if you don't count the trailing '/' in the definition of the application URL that, as it turns out, <em>really really matters! </em>and cost me 30 minutes of head-scratching right at the end after I'd figured out everything else.</p><p>Now, the PKI (read: &quot;everything else&quot;) part? Took me the whole fracking weekend to get it right. I don't know if the docs are only 90% of the way there, or if I just wasn't reading carefully enough.&nbsp;JoeK does not kid when he tells you that &quot;publicly-signed PKI certificates are the key to salvation when configuring ADFS.&quot;</p><p>I shall now officially dub the last 3 days: &quot;The ADFS Weekend of Repeated and Abject Failures, though Happily Everything Ended Well.&quot;&nbsp; Too long for a t-shirt slogan, but otherwise captures things quite nicely.</p><p>&nbsp;</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/29/better-to-fight-your-battles-with-duct-tapeduct-tape-makes-y.html"><rss:title>Better to fight your battles with duct tape...duct tape makes you smart.</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/29/better-to-fight-your-battles-with-duct-tapeduct-tape-makes-y.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-29T16:05:18Z</dc:date><dc:subject>personal</dc:subject><content:encoded><![CDATA[<p><a href="http://usanetwork.com/series/burnnotice" target="_blank">Burn Notice</a> returns to us on July 10th.&nbsp;I am...ridiculously amped.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/26/step-by-step-guide-for-ad-fs-in-windows-server-2008.html"><rss:title>Step-by-Step Guide for AD FS in Windows Server 2008</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/26/step-by-step-guide-for-ad-fs-in-windows-server-2008.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-26T21:27:14Z</dc:date><dc:subject>tech Identity</dc:subject><content:encoded><![CDATA[<p><a href="http://technet2.microsoft.com/windowsserver2008/en/library/a018ccfe-acb2-41f9-9f0a-102b80a3398c1033.mspx?mfr=true">http://technet2.microsoft.com/windowsserver2008/en/library/a018ccfe-acb2-41f9-9f0a-102b80a3398c1033.mspx?mfr=true</a></p><p>It's the same basic &quot;playing around with AD FS&quot; scenario that was released as a .DOC file for R2 - treyresearch and adatum and a&nbsp;claims-aware web app, puts the FSA and FSR on a DC, uses self-signed certs...though it's not actually all that hard to install AD CS on the DCs and use an enterprise CA instead of self-signed for this purpose. All the usual&nbsp;&quot;not for production use&quot; caveats are in effect: for those familiar with the phrase, it's &quot;the bouncy slide&quot; in action.</p><p>I'm listing it here because I seriously had no idea that this had been updated for 2008 until the link was sent to me, and my Google-fu usually doesn't let me down that hard, so maybe someone else can't find it either.&nbsp;</p><p>The consolation prize is that my &quot;muddling around and doing what made sense in my head&quot; has actually been a pretty good match to documentation that I hadn't yet seen, so rock on with my bad self, and all.</p><p>(Side note - the navigation on that jump-off page actually isn't the greatest - if you're looking for &quot;Click here for step 1&quot;, &quot;Click here for step 2&quot;, etc., on the main pane,&nbsp;you're not going to find it. Rather, you'll need to expand the nav-bar in the left-hand pane to drill down to the actual steps involved.)</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/26/with-apologies-to-jeff-foxworthy.html"><rss:title>With apologies to Jeff Foxworthy...</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/26/with-apologies-to-jeff-foxworthy.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-26T16:01:16Z</dc:date><dc:subject>tech humour Identity</dc:subject><content:encoded><![CDATA[<p>If your idea of &quot;taking a break&quot; from working is to lie out in the grass under the sun...and listen to an <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032327186" target="_blank">ADFS podcast</a> on your iPod (<em>Hi Matt</em>!), then you just might be an Identity nerd.&nbsp;</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/26/pardon-me-whilst-i-dance-the-dance-of-joy.html"><rss:title>Pardon me whilst I dance the dance of joy.</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/26/pardon-me-whilst-i-dance-the-dance-of-joy.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-26T15:51:37Z</dc:date><dc:subject>personal</dc:subject><content:encoded><![CDATA[<p>My last remaining student loan...is now 100% paid off. That's right, I am free of all educational debt, and have left behind the final vestiges of that hideous period of my life known as &quot;graduate school&quot;. </p><p>If I were a person who drinks at all, I'd be cracking open a bottle of scotch right about now.&nbsp; :-)</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/22/first-create-a-unity-of-purpose-then-take-over-the-world.html"><rss:title>First create a unity of purpose, then take over the world.</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/22/first-create-a-unity-of-purpose-then-take-over-the-world.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-22T00:06:03Z</dc:date><dc:subject>personal</dc:subject><content:encoded><![CDATA[<p>If your taste in films ranges at all towards indie and/or foreign, hie thee to a theatre and watch <a href="http://www.mongolmovie.com/" target="_blank">Mongol</a>. As you might imagine, it's a backstory of Genghis Khan...huge, sweeping, cinematography to die for, and at least one or two good scenes of Mongol horde-i-tude.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.shutuplaura.com/journal/2008/6/21/scripting-sysadmin-meme.html"><rss:title>Scripting / SysAdmin meme</rss:title><rss:link>http://www.shutuplaura.com/journal/2008/6/21/scripting-sysadmin-meme.html</rss:link><dc:creator>Laura E. Hunter</dc:creator><dc:date>2008-06-21T01:29:19Z</dc:date><dc:subject>personal tech</dc:subject><content:encoded><![CDATA[<p>Having been tagged by Mr. Richards, I couldn't refuse.</p><p><strong>How old were you when you started using computers?</strong> </p><p>I was 5, if you can believe it&nbsp;- I was definitely a forerunner of the current&nbsp;crop that has grown up with the technology.&nbsp;</p><p><strong>What was your first machine?</strong> </p><p>An ADAM - basically it was a Coleco game system that also allowed you to drop out to a BASIC compiler so that it could be marketed as &quot;educational.&quot; Bought for me by my Pop-Pop, rest his soul, because I was &quot;a really smart kid&quot; and he didn't want to just get me a Barbie doll or something for Christmas. For a guy who didn't make it past the 3rd grade, in retrospect we can say that the man&nbsp;was onto something.</p><p><strong>What was the first real script you wrote?</strong> </p><p>Lots of BASIC programs and Amiga/Commodore64 stuff - wrote silly little games using little pixelated sprite guys just to see if I could do it...then wound up in a school&nbsp;system that had some teachers and a guidance counselor who (I kid you not) bought into the &quot;girls aren't good at math/computers&quot; codswollop, which derailed me from doing anything substantive in that arena for a few years.</p><p><strong>What scripting languages have you used?</strong> </p><p>BASIC, whatever the C64/Amiga programming language was. C, C++, Java, JavaScript, VBScript, VBA, DOS batch files, AJAX, Ruby, C#.NET, Powershell, command-line automation with the ds* and joeware tools.</p><p><strong>What was your first professional sysadmin gig?</strong> </p><p>Deskside support monkey for a medical supply firm. Didn't know nearly enough when I started the job, so it was&nbsp;massively stressful, but definitely worth putting me on the right path. </p><p><strong>If you knew then what you know now, would have started in IT?</strong> </p><p>Absolutely. I have a profession that I'm (if I say so) very good at, that pays me well, and that has brought me an extensive (albeit physically distant) circle of friends whose intellect I respect and whose company I hold incredibly dear. I've been doing this for over a decade, and I still refer to my job as &quot;getting to play with toys.&quot;</p><p><strong>If there is one thing you learned along the way that you would tell new sysadmins, what would it be?</strong> </p><p>[1] It's only IT: nobody dies. </p><p>[2] If you're working for a company/boss who takes it as a personal affront that you want to take a vacation day that is rightfully yours, that is your first indication that you need to be working somewhere else.</p><p>[3] Surround yourself with people who know more than you do.</p><p><strong>What&rsquo;s the most fun you&rsquo;ve ever had scripting?</strong> </p><p>Writing the AD Cookbook, both times.&nbsp;I love seeing what I can do to efficiently automate AD tasks.</p><p><strong>Who am I calling out?</strong> </p><p>&quot;Tag, you're it!&quot;</p><p><a href="http://www.identitychaos.com/" target="_blank">Brad</a></p><p><a href="http://www.ilmbestpractices.com/" target="_blank">David</a></p><p><a href="http://blogs.dirteam.com/blogs/jorge/" target="_blank">Princess Jorge!</a></p>]]></content:encoded></rss:item></rdf:RDF>