How to configure the LDAP settings in Gateway Security 8.1 to perform Invalid recipient protection and for authentication while logging into the user self managed quarantine folder.

  

Description

This document contains procedures that will help you:

Configure the LDAP settings in Gateway Security 8.1 to perform Invalid Recipient Protection.

Successfully authenticate while logging into the user’s self-managed Quarantine folder.

Solution

  1. From the Manager console go to Filtering -> Settings -> Enterprise Settings -> LDAP template.
  2. Figure 1

  3. Click on the Add button to create a new LDAP Template and provide a name, then click Next.
  4. You can select the “All domains” option if you want to have one LDAP template for all the domains that Gateway Security is protecting or choose the specific domains.
  5. Figure 2

  6. You can either choose “Auto detect server” OR click the Add button to add a Valid LDAP server name or IP address. This might be your Domain controller, Exchange server, Lotus Domino, LDAP server, etc.
  7. Figure 3

  8. Give the authentication details to connect to the LDAP Server.
    If the LDAP server requires secure authentication, set the Secure type as ‘Use Secure Authentication’ and click Next.
  9. Figure 4

  10. Select the appropriate LDAP Server Type to load the LDAP attributes automatically, and then click Next.
  11. Figure 5

  12. Leave the default pool settings and click Next.
  13. From the Test window you can do the following:
    1. Test for a single email/Distribution list:
      Enter an email address or distribution list email in the appropriate field and click Send Query.
      Gateway Security will query the LDAP server using the LDAP attributes and return whether it is a valid email address or distribution list.
    2. Web Login Test:
      Enter the username and password that you want to use to login to the Quarantine folder and Gateway Security will verify if the specified login credentials are correct.
  14. Figure 6

  15. Click Next and Finish the LDAP template configuration.
  16. Click OK for Enterprise Settings and distribute the changes.
  17. Go to Filtering -> Settings -> Engine Specific Settings -> LDAP Usage and choose the LDAP template which you created in the Enterprise LDAP settings.
    To ensure that Gateway Security accepts incoming emails only for valid recipients, ensure that the option “Enable SMTP Invalid recipient’s protection” is enabled.
  18. Figure 7

  19. Click Ok and distribute the engine changes.
  20. Go to Filtering -> Settings -> Enterprise Settings ->Quarantine and choose the LDAP template that you want to use to authenticate the users when they try to log into their Quarantine folder.
  21. Figure 8

  22. Click Ok and distribute the changes.

 

Disable/Enable Click Sound in Internet Explorer (IE) for Windows XP/Server 2003/Vista

If you want to disable the click sound in Internet Explorer found in Microsoft Windows XP, Windows Server 2003 or Windows Vista, then follow these steps:

  1. Open the Start Menu / Settings / Control Panel
  2. Double click on the “Sounds” control panel. In this control panel, Scroll down in the events window until you reach “Windows Explorer” and under this you will find “Start Navigation“.
  3. Click on “Start Navigation” and you will see a .wav file appear in the “Name:” box. This is the sound that is associated with the click sound.
  4. In the “Name:” drop down menu, select (None) and then hit “OK“. This will set no sound to be played when you’re navigating on the web.

Keep in mind that this will remove the click sound from hitting buttons and links on all web sites you visit until you set it back. This is a safe change to make and does not affect any other functionality of your Windows Explorer browser.

Conclusion

In this article we have shown easy ways on how to disable the click sound in Internet Explorer and Windows Explorer found in Windows 95, Windows 98, Windows 2000, Windows XP, Windows Server 2003 and Windows Vista.  The changes are made using the Control Panel and don’t require any messy registry changes.

Disable Aero Shake in Windows 7

One of the interesting new features in Windows 7 is the way you can grab a window by the title bar and “shake” it back and forth to minimize everything else. It’s a fun feature, but just in case you want to disable it we’ve got the solution for you.

Disable Aero Shake Manual Registry Hack

Open up regedit.exe through the start menu search or run box, and then navigate down to the following key:

HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows

Once you are there, right-click on the Windows key and create a new key called Explorer.

Disable Aero Shake Regedit

Now right-click on the right-hand side, create a new 32-bit DWORD with the following settings:

  • Name: NoWindowMinimizingShortcuts
  • Value: 1

Disable Aero Shake Regedit

Once you’ve created this, you should log off and back on for the change to take effect.

Downloadable Registry Hack

Simply download, extract, and double-click on DisableAeroShake.reg to enter the information into the registry. To re-enable use the other file.

Download DisableAeroShake registry hack

Which eSCM processes and folders should be excluded from antivirus realtime scanner?

Description:

When you install CA Integrated Threat Management or eTrust Antivirus prior to installing eTrust Secure Content Manager r8, the Antivirus Realtime Scanner acts on data before eTrust Secure Content Manager r8 can analyze or use it. This may interfere with the functionally of the eTrust Secure Content Manager r8 engine.

To avoid conflicts between eTrust Antivirus and eTrust Secure Content Manager r8, you should identify the eTrust Secure Content Manager r8 processes that are running and add the processes to the eTrust Antivirus exclusions list.

Excluding eSCM Processes and Directories from Antivirus Realtime Scanning.

Solution:

Exclude the following process from the Antivirus realtime scanning

icihttp.exe
icismtp.exe
DCollSrv.exe
QmgrSrv.exe
CRepSrv.exe
ECSQDMN.exe
ECSSAFMGR.exe
eCCCleaner.exe
QMgr.exe
ManagerConsole.exe
iGateway.exe
servproc.exe
Exclude the following directories from the realtime scanning

:\Program Files\CA\eTrust SCM :\Program Files\CA\Ingres [EI] :\Program Files\CA\SharedComponents

 Other Relevant Information : Realtime scanner exclusions for machines running Microsoft Exchange: TEC393058 (SupportConnect, SupportOnline). https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=TEC393058 Realtime scanner exclusions for machines running Notes: TEC400737 (SupportConnect, SupportOnline).
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=TEC400737

To copy the IAS configuration to another server

To copy the IAS configuration to another server
Open Command Prompt.

At the command prompt, type netsh aaaa show config >path\file.txt.
This stores configuration settings (including registry settings) in a text file. The path can be relative or absolute, or it can be a UNC path.

Copy the file you created to the destination computer.

At a command prompt on the destination computer, type netsh exec path\file.txt.
A message appears indicating whether the update was successful

Error message when you create the trusted side of a trust between Windows Server 2003-based domains: "The parameter is incorrect"

http://support.microsoft.com/kb/930218

If the names of two domains collide, you can rename one of the domains. If the SIDs of the domains are duplicate, you have to remove one of the domains. Typically, this situation occurs when one of the following scenarios exists:

  • One domain was cloned from the other domain.
  • Before a computer became the first domain controller in either of the two domains, you clone this computer without using the SYSPREP tool.

Alternatively, you can migrate one of the domains to a new domain. However, you cannot migrate a domain to a new SID by using the sIDHistory property. Even if you successfully create a trust after you migrate one of the domain SIDs, you still have duplicate SIDs in user access tokens. Then, users who have duplicate SIDs can access resources that they should be unable to access.