2020/01/09

Windows 7 の EOS 最終通告が日本語だけおかしい件

注:どうでもいい話です。重箱つつっきーな話です。たぶん来週になれば、だれも気にしない、気が付かない話です。

今年初めて Windows 7 Ultimate の PC を起動してみたら、久々に EOS 通知が表示されました(メッセージの変化を楽しむため、「今後、このメッセージを表示しない」はオフの状態の PC)。このメッセージの内容は昨年12月までに仕込まれてたのは確認していましたが、自動的に表示されたのは初確認。たぶんサポート終了する来週には、また違うメッセージになると思う(対象、Windows 10 Home、Ultimate、ESU を購入していないワークグループ構成の Pro)。
でも、何かすごく違和感があるのは私だけ?

旧 MS 公式ブログは List of archived blogs へ

Microsoft の旧公式ブログ サイト https://blogs.technet.microsoft.com や https://blogs.msdn.microsoft.com が完全に廃止され、これらの URL の参照先はすべて List of archived blogs (https://docs.microsoft.com/en-us/archive/blogs/) にリダイレクトされるようになった模様。目的のものを探すのが面倒に。

2020/01/06

AD 環境は 2020年3月の Windows Update に要注意(かも)→ 3 月実施は延期

新年あけましておめでとうございました。

(※以下は、AD DS または AD LDS 運用中の管理者向けに注意しておいたほうがいい”かもしれない”話。AD DS/AD LDS を使っていないところや個人の Windows ユーザーには無関係な話。)

以下の公式ブログにあるように、2020年3月のWindows Updateで、Active Directory (AD DS および AD LDS)に関連する重要な変更(既定のセキュリティ設定の強化)が予定されているそうです。2020年3月は2019年12月時点での予定。

[AD管理者向け] 2020 年 LDAP 署名と LDAP チャネルバインディングが有効化。確認を!(Microsoft Security Response Center)
https://msrc-blog.microsoft.com/2019/10/02/ldapbinding/
2/6 追記) こちらも更新されました "注釈1:2020 年 2 月 5 日時点では、2020 年後半を予定しています。"

上記のブログにあるように、AD 運用している場合は事前にテストしておいたほうが良いと思います。2019年8月のセキュリティアドバイザリ ADV190023(https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/adv190023) で周知してきたと書いてますが、知らない AD 管理者は多いのでは? 事前にテストしておかないと、3 月の Windows Update の後に大変なことになるかもしれないし、ならないかもしれない。

2/5 追記)2/4 PT 付で ADV190023 が更新されました。2020 年後半に延期だそうです。
"The March 2020 updates do not make changes to LDAP signing or channel binding policies or their registry equivalent on new or existing domain controllers.
A further future monthly update, anticipated for release the second half of calendar year 2020, will enable LDAP signing and channel binding on domain controllers configured with default values for those settings."

3/3 追記)  AD LDS は影響なしになったらしい。

2021/1/5 追記)さらに更新。"The March 10, 2020 and updates in the foreseeable future will not make changes to LDAP signing or LDAP channel binding policies or their registry equivalent on new or existing domain controllers." (2020年後半というのものも消え、当面既定を変更することはないみたい)

2019/12/26

Azure Marketplace に Windows Server, version 1909 イメージがなかなか来ないけど...

Azure Marketplace で [smalldisk] Windows Server, version 1909 with Containers イメージを待ってるのですが、なかなかこない。18 か月の短い命の SAC なのに1か月半経過。

イメージは先月からあるけど、使っていいかよくわからないので待ってたんですが、以下の公式ページでも 2019 年 11 月から利用可能になっていると書いてあるので、使ってみるの巻。

Microsoft Windows Server Virtual Machine Images
https://support.microsoft.com/ja-jp/help/4534541/

2019/12/24

Windows Server SAC vNext(20H1)が ver 2004 なことを目視

Windows 10 Insider Preview では、20H1 のバージョンが 2004 になることが決まったようですが、Windows Server SAC 20H1 も ビルド 19035 が出てたので、バージョン 2004 になったはず、を目視してみた。

2019/12/20

Windows 7 ESU ありとなしをテストするダミー更新プログラム

(※2020/2/14 追記、このダミーの更新プログラムは利用できなくなりました。2020-02-B のマンスリーロールアップ KB4537820 とかで確認できます。Windows Update で ESU 向けのマンスリーロールアップを取得するには ESU ライセンス準備パッケージ(KB4538483 or KB4538484)も必要です。)

Windows 7 ESU のインストールをテストするための更新プログラムが出てました。

Update to verify that eligible Windows 7 SP1 and Server 2008 R2 SP1 devices can get Extended Security Updates
https://support.microsoft.com/en-us/help/4528069/

早速試してみた。

Windows Sysinternals 更新情報 (2019 年 12 月 19 日) - Procmon v3.53、Procexp v16.31

2019/12/18 PT に Sysinternals ツールの更新出ました。Procmon v3.53、Procexp v16.31、バグ修正です。

Sysinternals Blog > Process Monitor v3.53, Process Explorer v16.31
https://techcommunity.microsoft.com/t5/Sysinternals-Blog/Process-Monitor-v3-53-Process-Explorer-v16-31/ba-p/1073828

各ツールの日付は署名の日付。

Procmon v3.52 (2019/03/25) → v3.53 (2019/12/11)
https://live.sysinternals.com/files/procmon.zip
Procexp v16.30 (2019/09/05) → v16.31 (2019/12/14)
https://live.sysinternals.com/files/procexp.zip

日付はファイルのタイムスタンプ。

SysinternalsSuite.zip (2019/12/11 PT) -> (2019/12/17 PT)
https://live.sysinternals.com/files/sysinternalssuite.zip

前回の更新:
Windows Sysinternals 更新情報 (2019 年 12 月 12 日) - Sysmon v10.42、Zoomit v4.52、Whois v1.21

参考:総入れ替えスクリプト
Install and update SysinternalsSuite by PowerShell (Technet gallery script center)

(注:このスクリプトに含まれる Expand-Archive は PowerShell 5.0 以降に含まれます。PowerShell 4.x 以前ではエラーになります)

2020/03/16 追記:
※注:2020/06 で Technet Galallery 廃止されるそうなので、installsysinternalssuite.ps1 を追記しました。

 [installsysinternalssuite.ps1]
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
$InstallTo = "$env:ProgramFiles\SysinternalsSuite"
if (Test-Path "$env:TEMP\SysinternalsSuite.zip") {
  Remove-Item -Path "$env:TEMP\SysinternalsSuite.zip"
}
if (!(Test-Path "$InstallTo")) {
  Write-Host "Start Download SysinternalsSuite.zip ..."
  Invoke-WebRequest -uri "https://live.sysinternals.com/files/sysinternalssuite.zip" -outfile "$env:TEMP\sysinternalssuite.zip" -UseBasicParsing
  Write-Host "Expand SysinternalsSuite.zip ..."
  Expand-Archive -Path "$env:TEMP\SysinternalsSuite.zip" -DestinationPath "$InstallTo"
  Write-Host "Add PATH environment variable ..."
  $path = [Environment]::GetEnvironmentVariable("PATH", "Machine")
  $path += ";" + "$InstallTo"
  [Environment]::SetEnvironmentVariable("PATH", $path, "Machine")
  $env:PATH = $path
} else {
  Write-Host "Sysinternals Suite has already been installed in $InstallTo.`r`n"
  Write-Host "Searching https://live.sysinternals.com/ ..."
  $webcontent = (Invoke-WebRequest -uri "https://live.sysinternals.com/files/" -UseBasicParsing).Content
  (((($webcontent.Replace("<br>","`r`n")).Replace("</A>","")).Replace("<A HREF=","")).Replace(">"," ")).split("`r`n")|Select-String "SysinternalsSuite.zip"
  Write-Host "`r`n"
  #Write-Host "Searching current latest version top 5..."
  #Get-ChildItem -Path "$InstallTo\*.exe"| Sort-Object LastWriteTime -Desc |Select-Object -first 5 | Ft LastWriteTime, Name
  [ValidateSet("y","n")] $res = Read-Host "Will you update SysinternalsSuite anyway (y/n) ?"
  if ($res -eq "y") {
    Write-Host "Start Download SysinternalsSuite.zip ..."
    Invoke-WebRequest -uri "https://live.sysinternals.com/files/sysinternalssuite.zip" -outfile "$env:TEMP\sysinternalssuite.zip" -UseBasicParsing
    Write-Host "Expand SysinternalsSuite.zip ..."
    Expand-Archive -Path "$env:TEMP\SysinternalsSuite.zip" -DestinationPath "$InstallTo" -Force
    Write-Host "SysinternalsSuite was updated to latest version."
  }
}