Whew. I so remember now why I quit working in IT and swore I'd never go back. After I got that site certified the other day, I was riding high on puzzle-solving endorphins. I came crashing back down the next morning when I discovered that our overall goal was still not accomplished (the certificate was one part of a larger puzzle, and although I thought it was the final piece, I was incorrect). I spent three hours onsite yesterday, and several more online last night, only to find that not only had I NOT fixed the new thing, I'd broken a couple other things that had worked before. Lame lame lame. That's when the awful feeling came back, the one I remember from my working days, of stomach acid and burning eyes and desperation. Knowing you have to fix something and don't know how and there's nowhere to turn, you just have to keep plugging away at it.
Here is yet another foray into really arcane and uninteresting computer crap. I was trying to set up RPC over HTTP access so the clients could get email using their Outlook software over the internet without opening extra firewall ports. This is a built-in function of Exchange, and Microsoft gives pretty easily followed steps for setting it up - configure the service, set up the access, change a couple ports, add a certificate, configure the client. Kind of a lot of work, but not hard once you find the directions. Unfortunately, it doesn't work. I did everything I was supposed to, tested, and...nothing. Went back over every step, assuming I missed something, typed something wrong...nothing. Went to discussion boards, googled "RPC over HTTP sucks" and...nothing. I undid settings and redid them, removed DNS zones (that I'm grossly unqualified to be mucking about with anyway), called my network engineer friend for a consult, yelled at my husband, lost sleep I desperately needed, and... NOTHING. Finally, I followed all the steps again from the beginning, as if I'd never done it before, but this time added about twice as many port entries as Microsoft calls for and changed the authentication method in the client, both per some random guy on the internet's suggestion, and...success! What???? WHY???? Stupid. Fucking. Microsoft.
While I am happy and relieved that it's working, I'd feel more comfortable about it if I understood WHY. Still, this has been a voyage of self-discovery for me. I have put my husband on notice that any dreams he may have of me ever contributing financially to the family again should be laid officially to rest. Work and I just do not get along.
Thursday, March 29, 2007
From the depths of despair to the peaks of self-congratulation
Posted by Debbi at 1:13 PM 2 comments
Labels: microsoft sucks
Tuesday, March 27, 2007
Self-certifying an IIS site
Or, Why Microsoft Blows.
My husband asked me for help with a consulting job last night, so I dusted off my incredibly old and rusty skills and tried to remember things I did 4 years ago and then translate them to another platform and two generations of operating system later. And I did it! I think. I did something, anyway, and I think I know what else I NEED to do to finish the job. Vague enough for you?
This won't be interesting to anyone but me, probably, but Microsoft annoys me so much that I have to vent it anyway. In my former life, I worked on Lotus Domino servers. They don't have as much market share as Microsoft, which makes no sense to me, as Lotus is more secure and just plain makes more sense. Certificates are a case in point.
Well, let me back up. A certificate is something you add to a web site that tells visitors (or their web browsers) "you can trust this website, its authenticity has been verified." You can get a certificate in two ways. 1 - There are a handful of globally trusted verifiers, whose business it is to verify (duh, and how many times can I say "verify" in one paragraph) that a website is legitimate. So, if you want to make your website look trustworthy, you pay one of these companies to check you out, make sure you're legit, and issue you an electronic certificate to put on your site. 2 - Alternatively, if you're just setting up the site for your own personnel, for example, you can authenticate your own website, and give yourself a homemade certificate. If you do this, people accessing your site will get a message that the certificate is not from one of the big trusted companies, but it will work just the same.
So, I was working on option 2 - creating my own certificate and verifying it myself. In Lotus, which I used to use, there's an easily followed and logical set of steps for doing this. The software designers recognized that this is a common need and made the process as painless as possible. Microsoft, on the other hand, seems to have taken this opportunity to play a little game of hide and seek with web admins. First of all, Microsoft blows in general, and there is no central admin console except what you cobble together yourself out of "snap-ins" (which sound like snap-ONS and make me want to do unnatural and painful things to the morons who developed them). Once you stumble, through trial and error, upon the correct snap-in, you then have to check the properties of the "default site" (hoping it's the right one), then pick one of like 10 tabs with similar and ambiguous names, then finally request a certificate. Now, you'd assume the process for verifying the certificate would be at least a little bit the same, but you would be completely wrong. To verify the certificate, you have to go to add/remove programs in the control panel. WHAT??? You scream in frustration, pulling out your hair! That makes no sense at all! You are correct, sir.
Anyway, I wandered and roamed throughout the operating system on this poor unsuspecting company's server (I had their permission, they were unsuspecting only in their unfounded trust in my abilities) until I finally figured out how to recreate, using a retarded software, that which I could do in my sleep four years ago using an intelligent one. And then my brain exploded, but I had my pride to comfort me.
Posted by Debbi at 9:21 AM 3 comments
Labels: microsoft sucks