Saturday, May 31, 2008

How Long Does UNDO Take?

How long does the UNDO take?

Think of it this way: Rome wasn't built in a day but it did burn in one.

We've been comfortably using the 750 calendar objects per minute per server metric for data insertion for years now. We've got to admit that when someone asked us how long it would take to remove their data should they need to (something which hasn't happened in production in years, but which we always maintain the contingency plan for anyway) that we had never formally timed it.

So Russ's team went into action with data from a recent 2500 user customer, inserting current data plus two weeks' worth of history took 2hrs 20 minutes.

The UNDO took 30 minutes.

So UNDO takes about 25% of the time of your insertion.

But your mileage will definitely vary: These tests were on empty mailboxes.

If you have users with large mailbox quotas in Exchange, the UNDO will take longer because it has to search through lots of messages to selectively remove only the calendar objects.

Friday, May 30, 2008

Meetings created in EWS RTM Format can not be updated using EWS SP1

I tripped across an issue when trying to use Exchange 2007's Exchange Web Services SP1 to update a meeting that was created in the RTM version. I could not. Here's the error message:

The EWS Id specified is in Exchange 2007 RTM format while your request was made in the Exchange2007_SP1 mode. Please use the Exchange2007 SOAP version header in your request or remove it, or use ConvertId method to convert Id from EwsLegacyId to EwsId format.

The issue -- Exchange changed the EWS identifier format from Exchange 2007 RTM and SP1. ConvertId is required to convert the "EwsLegacyId" to the "EwsId". The change in identifier format is well documented. We don't typically update old meetings, so we haven't come across this issue before. Here's the link to the ConvertID page on MSDN:
http://msdn.microsoft.com/en-us/library/bb891865(EXCHG.80).aspx

and sample C# code: http://msdn.microsoft.com/en-us/library/bb856559.aspx
-Russ

Friday, May 09, 2008

Meeting Maker to iCalendar - no upgrades required

On a phone call this week one of our current migration clients told us that after they were done they were going to upgrade their obsoleted Meeting Maker server. Since this is the first time we've heard this one we asked "why?"

Their answer was a good one: They wanted to be able to export their Meeting Maker data to iCalendar format.

Since we're all about saving you folks money -- we just want to point out that we have an application for exporting your Meeting Maker server to ICS files (i.e., iCalendar), mapping all users and everything.

So if you need it in the future, please just ask.

Monday, May 05, 2008

Cross-Forest Impersonation

David Sterling has blogged about configuring resource forests. His recent post, Cross Forest Exchange Impersonation - where the rubber meets the road (http://msexchangeteam.com/archive/2008/03/24/448500.aspx) provides examples of how one actually configures impersonation permissions. If you want an overview of cross-forest impersonation, David blogged it here.

Everything I've read from David is always well written and informative. His support for the development community is equally exceptional. Thank you, David!

Monday, April 14, 2008

Save XP Petition

What does this have to do with calendaring?

Absolutely nothing.

But Windows Vista is "unsatisfactory" -- a phrase which here means "causes me to blow chunks."

InfoWorld started a petition to save XP -- which I signed as soon as I heard about it

Go there -- you know you must.

Thursday, April 10, 2008

Migration Best Practices

Our most recent migration client had what we consider to be one of the best communications strategies we've seen in a while -- they used this thing called a "web site."


We have seen similar things in the past -- what distinguished these folks was how well-planned and executed their entire user community communication strategy was.
Check out the example.

Wednesday, April 09, 2008

Google Calendars as SPAMbots

I could not believe it when it first happened last week -- but there, tucked in between the usual offers to increase body parts half the world does not have and the insane offers I get in Russian, was a Nigerian scam CALENDAR INVITATION!

And this morning there are now two others:



The huge problem with these of course is that they show up in my calendar (which obviously makes this an interesting variation for the spam-mongers). Russ's comment was classic: It must be SPAM because "Dearest Beloved One" could not be how anyone who knows you refers to you.

To make matters worse it looks as though they're originating out of Google Calendar:


Normally I would start thinking about ways of intercepting this client-side at my Outlook inbox -- but given that the script kiddies of the spamosphere have figured out how to harness Google Calendar for their ends, I'm hoping this one gets solved in Mountain View.

Anybody else noticing this?

Tuesday, April 08, 2008

Exchange Auto Accept Agent: Danger Danger!

We had a client report a weird experience Monday and we wanted to share it for the benefit of others.

They'd just migrated a few metric tons of calendar data into Exchange 2003 sp2.

The data looks fine, but after deleting a resource account that had been registered to the Auto Accept Agent (see the Deployment Guide) they discovered their server CPU usage pegged at 100% (not even a calendar migration usually does this!) and various other wrath-of-your-favorite-deity-type plagues on their Exchange server.

Turns out this is a well-known problem documented in the KnowledgeBase article An Exchange Server 2003 SP2 server becomes unresponsive after you delete a mailbox on which you registered the Auto Accept Agent event sink.

The best way to deal with the problem is to avoid it. (Patient: It hurts when I do this. Doctor: Well don't do that.)

But if you're already in the soup, fixing this problem if it happens to you involves using MfcMAPI. More than that you're going to need to know which registered resource was removed so you can make things right. Since there are no logs to guide you if this should suddenly happen, we recommend the Microsoft Exchange Team Blog article How do you know which mailboxes are registered with the Auto Accept Agent?

Keep track of your resources!

Sunday, March 23, 2008

Creating Delegates / Proxies in Zimbra

Sometimes we find out the coolest stuff while searching for something else.

And this was how we discovered how Meeting Maker users can migrate their read-write and read-only proxies and Oracle Calendar users can migrate their designates into Zimbra Viewer or Manager Roles.

As the Zimbra Wiki points out, zmmailbox can be used to set calendar READ-ONLY permissions (Viewer):

zmmailbox -z -m zyg@DOMAIN mfg -i /Calendar account russ@DOMAIN r

and the followng will set READ-WRITE (Manager):

zmmailbox -z -m zyg@DOMAIN mfg -i /Calendar account russ@DOMAIN rwidx

In the above examples Zyg makes Russ a delegate/proxy/pick your term.

So how do you get the list? In the intermediate MS Access database we use for Meeting Maker conversions it's in the PROXIES table. So the logical next step is for us to write a macro that just exports a batch file you can use to execute this command for everyone you're migrating. Any of you working on a Zimbra migration now we'll happily work with on this (though Zyg is taking a crack at it anyway).

For Oracle Calendar Server conversions it's even easier. Look up UNIACCESSRIGHTS in your OCS Reference Manual.

Friday, March 21, 2008

Tasks in Zimbra 5 - migrating them in

You know the simplest things always have some kind of hellacious complication lurking in them. So it is with what in Zimbra and OCS are called Tasks and in Meeting Maker are called To-Dos.

Meeting Maker has 7 Task Priorities while Zimbra has only 3.

This is how the priorities map when we do a migration:


Meeting Maker Urgent-> Zimbra High
Meeting Maker Important-> Zimbra High
Meeting Maker High -> Zimbra High
Meeting Maker Medium -> Zimbra Normal
Meeting Maker Normal -> Zimbra Normal
Meeting Maker Low -> Zimbra Low
Meeting Maker None -> Zimbra Low

For “Progress” options, Meeting Maker has only 2 levels (Done or Not Done) and Zimbra has 5 (Not started, Completed, In Progress, Waiting on Someone Else, and Deferred). “Done” maps to “Completed” and “Not done” maps to “In progress.”

Tasks are ICS files, but they can't be uploaded with the calendar data so we need to do them separately.

The following curl command will insert “tasks-zyg.ics” into User Zyg’s Tasks list:

curl -vvv -u zyg:PASSWORD --data-binary @tasks-zyg.ics http://SERVER/home/zyg/Tasks?fmt=ics

Oracle Calendar has a weirder case that we're not sure what to do with yet. OCS has priorities 1-9 and A-Z. In Outlook we map to priorities 1-5 with anything above “5” becoming “5.”

For Zimbra from OCS we'll wait until it's an issue for one of you and just define it that way from then on.

Oracle's other bugaboo is in access levels: Personal, Confidential, Normal, Public. Personal and Confidential map to PRIVATE in Zimbra, the other two map to PUBLIC.

Wednesday, March 12, 2008

Why can't I create mailboxes in Exchange 2007 via VMware

I thought it would be simple to create an additional user mailbox in our Exchange 2007 server running in VMWare virtual server. The mailbox creation process fails with this message: "An Exchange 2007 server on which an address list service is active cannot be found."



Why do simple tasks that fail drive me nuts, and take forever to resolve?

What broke? The Microsoft Exchange System Attendant failed to start! Once restarted, I created the mailbox with ease. This was the same thing I saw when creating mailboxes for an Exchange Resource Forest Trust. So for whatever reason, the SA continues to randomly fail to start. A three minute task stretched to fifteen. Reminds me of the joke... I always give 100% effort at work: 10% on Mon, 25% on Tue, 35% on Wed, 25% on Thu, 5% on Fri.

Friday, March 07, 2008

DST: The Gift that Keeps on Giving

The new North American Daylight Savings Time rules are a lot like the message in Repo Man: the life of migrating calendar servers is aways intense.

Here's the thing to keep in mind: If you're going into Exchange 2003 -- make sure you've applied patches for the new DST shifts.

EHLO has this good posting on the subject: Exchange 2003 and DST fix.

Exchange 2007 automatically has the DST shift dealt with.

Now there are some vendors out there who tell you that as long as you're in the same time zone you're covered, you don't need to upgrade Meeting Maker or Oracle Calendar Server. That's true -- until you migrate.

We can handle re-basing the events in either of these to make them work if necessary. Please just be on the lookout in your test lab for meetings and appointments off an hour in the "DST Delta" in March and November.

As always, it is much easier to deal with these if we find them early.

Thursday, March 06, 2008

Entourage adds spice to recurring meetings in Exchange 2007

This has been the week to report about Entourage and its unusual calendar behavior. The day after our blog about Entourage seeing double, Microsoft released another KB article about Entourage and problems with calendaring. We are thrilled to share the spice of life that Entourage has added to our jobs. Brace yourself folks:

"Unexpected modified instances of a recurring meeting may appear when you use Entourage to access a calendar on a computer that is running Exchange Server 2007". This will happen after modifies one or more instances of a recurring meeting. Please see: http://support.microsoft.com/kb/949113. We have not come across this issue, so we don't know the version of Entourage......

Tuesday, March 04, 2008

Seeing double with Entourage and Exchange 2007

One of Sumatra's academic clients has a significant Mac user base. They use Entourage to access their Exchange 2007 calendars. The Mac users have reported that after a few days of use, they saw duplicate items in their calendar. We suspected Entourage (OWA or Outlook 2003 did not create dupes when accessing the same calendars), but we couldn't pinpoint the root cause of the duplicates.

Microsoft reported the duplicates are an Entourage problem. The problem occurs whenever users edit an appointment with a subject line that is identical to other calendar items. Come on... That has to be rare....you're more likely to find a four-leaf clover. Anyone have "Weekly Staff Meeting", "Lunch", "Vacation" on their calendars?

See the KB article: Duplicate calendar items may appear when you use Entourage to access a calendar on an Exchange 2007 server (http://support.microsoft.com/kb/949114)

Note: They were using Entourage 10. The KB article didn't specify the version.

Monday, March 03, 2008

1,300 recurring appointment limit fixed in E2k7 SP1 Update Rollup 1

Remember back in June 07 when Sumatra blogged about how 1,300 recurring appointments broke Exchange 2007? (OK, I forgot, too.) Well, as of 2/28/2008 Microsoft fixed this bug and others in the "Update Rollup 1 for Exchange Server 2007 Service Pack 1" .

Sumatra recommends its migration clients -- and any one who uses calendaring -- install SP1 and Update Rollup 1.

There are many things this update fixes. Here are some that impact calendaring users:

-R

Sunday, February 24, 2008

Hidden Treasure in your Calendar Data

We at Sumatra revel in our reputation as quantitative calendar geeks. One of the means we use to show our prowess with calendar data comes from some of the statistics we can read so readily from Meeting Maker databases, of which the following data we ran on February 8, 2008 is a sanitized example.

Some of the most interesting statistics, the number of meetings that are current is only 2.53% of the total meeting volume. Activities track almost exactly the same at 2.56%. As some of you have heard us say: Our highly advanced mathematics has proven that most events have already happened.

You can expect the same statistics from your Exchange calendar data on an ongoing basis.

Overall Stats

ItemValue% Total
8Feb_DB_v8.8.0.7.mdb File size:
562,237,440.
Total number of meetings:
62,560.
Meeting timeframe:1/1/1940 5:00:00 AM-12/31/2039 12:30:00 PM
Total number of meetings newer than 2/8/2008:1,591.2.54%
Total number of meetings older than 2/8/2008:60,969.97.45%
Total number of meetings without any mapped users:62,560.100.00%
Total number of meetings without any mapped users and newer than 2/8/2008:1,591.2.54%
Total number of Guests:211468
Total number of guests attending meetings newer than 2/8/2008:7,791.3.68%
Total number of guests attending meetings older than 2/8/2008:203,677.96.31%
Total number of guests attending meetings without any mapped users:209,603.99.11%
Total number of guests attending meetings without any mapped users and newer than 2/8/2008:7,791.3.68%
Number of foreign guests00.00%
Total number of activities:1,869,557.
Activity timeframe:1/1/1940-1/2/2040 8:00:00 AM
Total number of activities newer than 2/8/2008:48,026.2.56%
Total number of activities older than 2/8/2008:1,821,531.97.43%
Total number of Activities without any mapped users:1,869,557.100.00%
Total number of Activities without any mapped users and newer than 2/8/2008:48,026.2.56%
Overall Timeframe:1/1/1940-1/2/2040 8:00:00 AM
Number of days:36526


When we turn our attention to the top meeting users, we see some other interesting results. From the same server with approximately 2000 users, the top ten users account for almost 20% of the total meeting activity, account for about 15% of all guests, and about 3% of all activities. While your mileage may vary, it will not vary by much.


Top Meeting Users




UserNum Mtgs% Total MtgsNum Guests% Total GuestsNum Actvy% Total ActvyGrand Total% Grand Total
AV Student Staff3,025.4.83%5,939.2.80%563.0.03%3,588.0.18%
Bela Bartok1,488.2.37%5,514.2.60%3,134.0.16%4,622.0.23%
Adam Ant1,281.2.04%4,516.2.13%2,799.0.14%4,080.0.21%
Claudette Colbert1,084.1.73%3,318.1.56%12,446.0.66%13,530.0.70%
Deanna Durbin1,065.1.70%2,385.1.12%2,045.0.10%3,110.0.16%
Erik Estrada1,031.1.64%2,755.1.30%4,655.0.24%5,686.0.29%
Felix Frankfurter906.1.44%2,029.0.95%10,234.0.54%11,140.0.57%
Research Team Conf Room895.1.43%2,596.1.22%289.0.01%1,184.0.06%
Gary Gilmore857.1.36%1,845.0.87%3,590.0.19%4,447.0.23%
Harry Hope755.1.20%2,375.1.12%2,947.0.15%3,702.0.19%
Top User Total12,387.19.80%33,272.15.73%42,702.2.28%55,089.2.85%
Grand Total62,560.-211,468.-1,869,557.-1,932,117.-


Now let's take a look at one of everyone's favorite subjects: Meetings and Recurring Meetings. As you can see, over 90% of meeting objects are one-time meetings. Of the recurring meetings, the most common are "Daily_Every_N" (which when N=7 means a weekly meeting).


Meeting Frequency Profile



DayNum Recurring Meetings% Total Meetings% Total Recurring Meetings
ONCE58,824.94.02%-
DAILY_EVERY_N2,991.4.78%80.05%
DAILY_DAYS_OF_WEEK364.0.58%9.74%
WEEKLY315.0.50%8.43%
MONTHLY66.0.10%1.76%
Grand Total62560-5.97%



Recurring Meeting Profile



DayNum Recurring Meetings% TotalMeetings% Total RecurringMeetings
Finite end date 3,568.5.70%95.50%
Ongoing (no end date) 168.0.26%4.49%
Grand Total37365.97%-

Friday, February 22, 2008

Trust Me (Part Four) - I see a Resource Forest thru the trees

What's the old expression -- you can't see the forest for the trees? Well, on my fourth attempt, I can.

To recap: What was the problem? I wanted to insert calendar data into Exchanged 2007 that was configured using a Exchange Resource Forest topology. The user mailboxes were linked to a accounts in a user forest. Those user mailbox accounts were disabled. You can not use Exchange Web Services to impersonate a disabled account.

What worked? Here is what I did:
  • Upgraded Exchange 2007 to SP1,
  • Created a service account in the resource forest
  • Gave that service account DELEGATE permissions to ALL of the disabled accounts.
  • Granted permission for the service account to see the user forest's AD
  • Inserted calendar data!

Finding the disabled accounts, and assigning delegate rights to the service account turned out to be easy, thanks to Jian Li’s MSExchange Team Blog “How to access multiple resource mailboxes in Exchange Web Services (EWS)”. He described how it works, and (even better) created a script that has worked well for us (get the Microsoft Script.)

Oh, for the last few days the Exchange System Attendent decided to automatically start, and remain running. No idea why.

-R

Sunday, February 17, 2008

Trust Me (Part Three)

Ran into two issues when configuring the resource forest and the user forest: service accounts and Address List System Service failing.

Service Account: I created two service accounts, one on each machine. The service accounts had the same name. When I went to link the resource account to the account in the user forest, accessing the linked domain controller failed.

Lesson learned - The link failed because I didn't qualify the service account with the user forest (e.g. userforest\mySvcAccount). So Exchange tried to link to the user forest domain controller with the resource service account and failed. Had I created service accounts with two different names, this problem would not have tripped me up.

Address List:

After I fixed the service account issue, the last step of in the "linked mailbox" wizard failed with an invalid address. After much head-scratching, I discovered the system attendent had failed with an MSExchangeSA event ID 1005: "Unexpected error The Local Security Authority cannot be contacted ID no: 80090304 Microsoft Exchange System Attendant occurred. "

Dave Goldman blogged about this: Creating a new mailbox in Exchange 2007 with the new-mailbox cmdlet fails with Address List Service not Available, but only addressed one aspect. My problem was choice (4) - SA stopped. I haven't figured out why it's failing, but restarting the SA allowed me to complete the mailbox link.

OK--everything is set. Next time I'll report on the results of impersonation.

Wednesday, February 13, 2008

Export-Mailbox -- "Exmerge" for Exchange 2007

I had to generate a five PSTs from client data inserted in our lab to help a prospect prove to his management team that the Sumatra Migration tool could read and insert their calendar data into Exchange 2007. It gave me an opportunity to test a new commandlet "export-mailbox" released with Exchange 2007 SP1. Export-Mailbox offers many of the features most of us loved in Exchange 2003's ExMerge.

Be forwarned - the commandlet comes with contraints:
  • It must be run from a 32 bit client machine with Exchange Management Tools (Version Exchange 2007 SP1 or later) installed and Windows PowerShell (Download: Microsoft Exchange Server 2007 Management Tools (32-Bit));
  • It requires Outlook 2003/Outlook 2007 be installed on the 32-bit client machine;
  • Must be "run-as" using an account with Exchange Organization Admin or an Exchange Server Admin privs.
Here is how I exported a single mailbox to a PST:
Export-Mailbox –Identity < mailboxuser > -PSTFolderPath < pathToSavePST >


Here is how we told the client to Import the data from a PST into a client mailbox:
Import-Mailbox -Identity < mailboxuser > -PSTFolderPath < pathToSavePST >

I covered two of the other command-line variations. Ricardo Guerro's MsExchange Team blog post How to Export and Import mailboxes to PST files in Exchange 2007 SP1 details this commandlet. It comes with descriptions and screen-shots.

Yea! Another calendar migration tool for Exchange 2007.
-R

Tuesday, February 12, 2008

Trust Me (Part Two)

This is the second installment on my experience trying to setup a resource forest trust.

Last night I re-installed VMware's Server product on an Windows Server 2003 SP2 box that also had Exchange 2007 SP1 installed. I rebooted the box and left. I lost today's popularity contest to "Smiling Bob" after our early-morning users received "Service Unavailable" when they tried to visit our intranet, OWA, and anything that used Exchange Web Services.

What happened? The Application Event Logs show W3SVC-WP Event IDs 2268 and 2214, and System Events IDs 1002, 1039. It looks like VMware Server and Exchange 2007 are both trying to control IIS (VMware wins....)

To restore the server, I uninstalled VMware Server and reset IIS to run in native mode using this AdsUtil command line:

cscript %systemdrive%\inetpub\AdminScripts\adsutil.vbs set w3svc/AppPools/Enable32BitAppOnWin64 0

BTW, if you want to re-enable 32 bit apps (WOW64 Mode), run this command:
cscript %systemdrive%\inetpub\AdminScripts\adsutil.vbs set w3svc/AppPools/Enable32BitAppOnWin64 1

It was suggested that VMware's WORKSTATION product would be a better choice. I just installed the evaluation version. 'Sure n b'gora' ...web services and the intranet are still available. (Thanks, Chrisopher Q., for the tip!)

Now it's back to trying to build a one-way resource forest-trust.
-R