Showing posts with label Certification. Show all posts
Showing posts with label Certification. Show all posts

Saturday, February 4, 2012

bench3

Understanding Microsoft Certification Exams

    Microsoft Certification helps improve your resume and helps you differentiate yourself from other students competing for the same IT jobs.

    Registration for a Microsoft Certification exam involves Selecting the certification test, selecting your fist exam and then registering for the exam.

    Selecting the certification test

    There are many certifications available from Microsoft. You can choose the one according to your interest and knowledge. Visit the exam registration page to find complete instructions

    Please note that, Microsoft Certification exams are available in a variety of languages. When you register for an exam, you can review the list of languages in which the exam is currently available. If an exam is not available in your native language and you must take it in English, you can request an additional 30 minutes to complete it.

    To request the additional 30 minutes, you need to register by phone rather than online, and you must make this arrangement before appearing at the testing center.

    Select your first exam

    After selecting the certification next step is to select an exam . There are many exams available also from Microsoft. You are required to have some previous knowledge to appear in most of the exams, so check it out too. Also note down the number of attempts allowed to appear in that exam.

    Register for the exam

    All Microsoft Certified Professional (MCP) are looked after by Prometric. Prometric is a testing organization with its presence in more than 3,000 locations worldwide.

    Each exam may cost you about US$155 . These prices keep on changing so you should check them out to from Prometric website. The fees may be little different in some countries due to additional taxes etc.

    How to do the registration

    You can registration either by phone or online. Contact Prometric for this purpose.

    Microsoft Office Specialist exams are looked after by Certiport. To register contact Certiport.

    In case you are registering by phone, please have the following information ready.

  • MCP ID number or Prometric ID number Mailing address and phone number
  • E-mail address
  • Organization or company name
  • Method of payment (Payment has to be made in advance)
  • And to register for a Microsoft Certification exam, Visit the exam registration page to find complete instructions

    Microsoft is dedicated to developing technology that is usable by and accessible to everyone, including people with disabilities. If you are unable to take a Microsoft Certification exam, either using standard testing equipment or within the standard exam duration, the Microsoft Certification program is committed to making all reasonable efforts to accommodate you. Visit the following link for full details about the process for requesting an accommodation. View information regarding special accommodations.

      Pricing For Microsoft Certification:

      Microsoft Certified Technology Specialist (MCTS), Microsoft Certified IT Professional (MCITP), and Microsoft Certified Professional Developer (MCPD) exams typically cost US$150 but are priced according to currency values in specific countries and regions. Exam prices are subject to change. In some countries and regions, additional taxes may apply.

Read More

Monday, October 3, 2011

bench3

Microsoft Certified Courses On Windows 7 | Microsoft Certified Technology Specialist, an Overview

bench3 is resolved to help out those who aspire to become MCTS in Windows 7 Configuring, by introducing a new feature on Practical Test for the said examination viz., Exam 70-680. Before moving to the new feature, it is pertinent to have an overview about the said Examination.

If you are looking for the Topics On Microsoft Certified Technology Specialist (70-680)), follow this link.

Its not a good idea to follow Brain dumps for Exam 70-680: Of course, bench3 do not encourage using brain dumps for passing this certification program for various reasons. among which:

Brain dumps degrades the value of the certification. What is the point in getting a certification by merely reading the questions and answers for the examination?

Do you know? Brain dumps violate copy right rules. Typically, brain dumps are questions taken from the actual examinations either by memorizing or by some illegal means. Either way, it is copy right violation and illegal. The questions are prepared by someone else and you are not allowed to use it as your own.

Understanding MCTS:

Microsoft Certified Technology Specialist (called as MCTS), is a certification accorded by the Microsoft Corporation to those who clear the examination called Windows 7 Configuring or Exam 70-680. This certification merely shows an individual’s in-depth knowledge in a specific area of operation. And those who complete MCTS would be having thorough knowledge in implementation, Trouble Shooting and Debugging with reference to a specific Technology and having experience in that field for one or more years.

Microsoft Certified Courses On Windows 7 Microsoft Certified Technology Specialist, an Overview

This MCTS certification is also seen as a ladder in obtaining MCITP or Microsoft Certified IT Professional.

Details on Microsoft Certification on Windows 7, Configuring:

At present, the Microsoft Corporation offers four Certification examinations with reference to Windows 7 Operating System. They are:

  • Windows 7 Configuring (Exam 70-680)
  • Windows 7 Preinstalling for OEMs (Exam 70-683)
  • Windows 7 Enterprise Desktop Administrator (Exam 70-686)
  • Windows 7 Enterprise Desktop Support Technician (Exam 70-685)

Windows 7 Configuring Examination or Exam 70-680:

The Windows 7, Configuring or Exam 70-680 is available for the individuals

  • with minimum of One or more years experience in IT field; and
  • with experience in implementation and administration of Windows Operating System [Any experience in Windows 7 will make lots of difference] in a Network environment.

Skills and Its Weightage in Exam 70-680:

  • Installation, Up gradation and Migration to Windows 7 [this topic weighs 14% of examination]
  • Deployment of Windows 7 [weighs 13%]
  • Configuration of Hardware and Applications [weighs 14%]
  • Configuration of Network Connectivity [weighs 14%]
  • Configuration of access to resources [weighs 13%]
  • Configuration of Mobile Computing [weighs 10%]
  • Monitoring and Maintenance of systems that run Windows 7 [weighs 11%]
  • Configuration of Recovery and Back-up Options [weighs 11%]

Successfully clearing the examination, will give an Individual, MCTS or Microsoft Certified Technology Specialist Certification in Windows 7, Configuring and moves that individual a step further towards MCITP or Microsoft Certified IT Professional.

Every individual has got 3 choices in the MCITP examinations to become Enterprise Administrator, Enterprise Desktop Administrator 7 and Enterprise Desktop Support Technician 7.

Follow This Link (Topics On Microsoft Certified Technology Specialist (70-680))  To Know the Topics Covered In MCTS or Microsoft Certified Technology Specialist Certification in Windows 7 (70-680)

Read More

Wednesday, June 22, 2011

bench3

Skills Required For Windows 7 Certification 70-680

Microsoft awards various professional certifications upon passing one or more exams. One of the exams is the Windows 7 Certification exam which is for the candidates who operate in computing environments which use Microsoft windows & as a desktop operating system.

Candidates gearing up for the Windows 7 Certification should have at least one year experience in the IT field. They should be equipped with the necessary knowledge to install, deploy and upgrade to windows 7 and simultaneously making sure that there is complete compatibility in hardware and software.

There are various skills that are measured in the following technical tasks:

  • 70-680  - Installing, Upgrading and Migrating to windows 7 (14 Percent): It evaluates the candidate's ability to perform a clean installation and upgrading to windows 7 from previous versions of Windows.
  • 70-680 - Configuring Hardware and Applications (14 Percent): It tests the ability to configure devices and configure application compatibility. The latter objective is not limited to setting compatibility mode and various compatibility issues with the Internet explorer. The candidates are also tested for configuration of application restrictions and configuring Internet Explorer.
  • 70-680 - Deploying windows 7 (13 Percent): The candidate should be able to capture a system image and prepare a system image for deployment. They should be able to deploy system image and configure a VHD.
  • 70-680 - Configuring Access to resources (13 Percent): The candidate should be able to configure shared resources, file and folder access, user account control (UAC). It also requires configuring authentication and authorization along with configuring BranchCache.
  • 70-680 - Network connectivity (14 Percent): The candidates are also tested for configuring network connectivity which accounts for 14 percent. The person should be able to configure Ipv4 network settings and configure Ipv6 network settings, windows firewall, and remote management.
  • 70-680 - Configuring Backup and Recovery options: (11 Percent): To configure backup, configure system recovery options, file recovery options.
  • 70-680 - Configuring Mobile Computing (10 Percent): The candidate should be able to configure BitLocker and BitLocker To Go. He should be able to configure Direct Access, mobility options, remote connections,
  • 70-680 - Monitoring and Maintaining Systems that run windows 7 (11 Percent): The candidate should configure updates to windows 7, manage disks, monitor systems, and configure performance settings.

Candidates can easily prepare for the 70-680 study with the help of software program available. It is available at reasonable rates and you can order them with great convenience. It enables you to get Windows 7 Certification with minimal time and effort invested in the 70-680 study.

Read More

Monday, March 28, 2011

bench3

Internet Explorer 8 Self Signed Security Certificate Error - IP for the UR

I have a server in house that has a self-signed certificate used with SSL on top of IIS.

My pc runs windows 7 64 bit and IE 8. When I type in the address of the server from the pc IE 8 browser as in https://192.168.25.100

IE explodes with certificate error messages.  I have searched the web including the solution of loading the certificate in the the local computer physical store of the trusted certificates when the site is not a trusted site and every permutation within. Still IE shows that there is a certificate problem.

What is worse is when I ask the web server to serve a file to my desktop, IE says the file is not available because the certificates don't match. Is this a problem with IE8, because IE7 was just fine as is Firefox - all version.

Solution:

This issue can be caused by the Root Certificate missing in trusted root store of client machine.

You can open it from Internet explorer which will display the certificate. Click on the button Install Certificate to launch the Certificate Installation wizard.

If it cannot be fixed, please take the following steps to deploy root certificate via Group Policy:

Open Group Policy Management Console.

Find an existing or create a new GPO to contain the certificate settings. Ensure that the GPO is associated with the domain, site, or organizational unit whose users you want affected by the policy.

Right-click the GPO, and then select Edit. Group Policy Management Editor opens, and displays the current contents of the policy object.

In the navigation pane, open Computer Configuration\Windows Settings\Security Settings\Public Key Policies\Trusted Publishers.

Click the Action menu, and then click Import.

Follow the instructions in the Certificate Import Wizard to find and import the certificate.

If the certificate is self-signed, and cannot be traced back to a certificate that is in the Trusted Root Certification Authorities certificate store, then you must also copy the certificate to that store. In the navigation pane, click Trusted Root Certification Authorities, and then repeat steps 5 and 6 to install a copy of the certificate to that store.

Read More

Thursday, August 26, 2010

bench3

Enabling Smart Card Logon With Third-Party Certification Authorities

You can enable a smart card logon process with Microsoft Windows 2000 and a non-Microsoft certification authority (CA) by following the guidelines in this article. There is limited support for this configuration, as described later in this article.

Requirements:
Smart Card Authentication to Active Directory requires that Smartcard workstations, Active Directory, and Active Directory domain controllers be configured properly. Active Directory must trust a certification authority to authenticate users based on certificates from that CA. Both Smartcard workstations and domain controllers must be configured with correctly configured certificates.
As with any PKI implementation, all parties must trust the Root CA to which the issuing CA chains. Both the domain controllers and the smartcard workstations trust this root.
Active Directory and domain controller configuration
  • Required: Active Directory must have the third-party issuing CA in the NTAuth store to authenticate users to active directory.
  • Required: Domain controllers must be configured with a domain controller certificate to authenticate smartcard users.
  • Optional: Active Directory can be configured to distribute the third-party root CA to the trusted root CA store of all domain members using the Group Policy.
Smartcard certificate and workstation requirements
  • Required: All of the smartcard requirements outlined in the "Configuration Instructions" section must be met, including the text formatting of the fields. Smartcard authentication fails if they are not met.
  • Required: The smartcard and private key must be installed on the smartcard.
Configuration instructions
1. Export or download the third-party root certificate. How to obtaining the party root certificate varies by vendor. The certificate must be in Base64 Encoded X.509 format.

2. Add the third-party root CA to the trusted roots in an Active Directory Group Policy object. To configure Group Policy in the Windows 2000 domain to distribute the third-party CA to the trusted root store of all domain computers:
  • Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
  • In the left pane, locate the domain in which the policy you want to edit is applied.
  • Right-click the domain, and then click Properties.
  • Click the Group Policy tab.
  • Click the Default Domain Policy Group Policy object, and then click Edit. A new window opens.
  • In the left pane, expand the following items:
Computer Configuration
Windows Settings
Security Settings
Public Key Policy
  • Right-click Trusted Root Certification Authorities.
  • Select All Tasks, and then click Import.
  • Follow the instructions in the wizard to import the certificate.
  • Click OK.
  • Close the Group Policy window.
3. Add the third-party issuing the CA to the NTAuth store in Active Directory. The smart card logon certificate must be issued from a CA that is in the NTAuth store. By default, Microsoft Enterprise CAs are added to the NTAuth store.
  • If the CA that issued the smart card logon certificate or the domain controller certificates is not properly posted in the NTAuth store, the smart card logon process does not work. The corresponding answer is "Unable to verify the credentials".
  • The NTAuth store is located in the Configuration container for the forest. For example, a sample location is as follows: LDAP://server1.name.com/CN=NTAuthCertificates,CN=Public Key Services,CN=Services,CN=Configuration,DC=name,DC=com
  • By default, this store is created when you install a Microsoft Enterprise CA. The object can also be created manually by using ADSIedit.msc in the Windows 2000 Support tools or by using LDIFDE. For more information, click the following article number to view the article in the Microsoft Knowledge Base: 295663 (http://support.microsoft.com/kb/295663/ ) How to import third-party certification authority (CA) certificates into the Enterprise NTAuth store
  • The relevant attribute is cACertificate, which is an octet String, multiple-valued list of ASN-encoded certificates.
After you put the third-party CA in the NTAuth store, Domain-based Group Policy places a registry key (a thumbprint of the certificate) in the following location on all computers in the domain:
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\NTAuth\Certificates
This is refreshed every eight hours on workstations (the typical Group Policy pulse interval).

4. Request and install a domain controller certificate on the domain controller(s). Each domain controller that is going to authenticate smartcard users must have a domain controller certificate.
If you install a Microsoft Enterprise CA in an Active Directory forest, all domain controllers automatically enroll for a domain controller certificate. For more information about requirements for domain controller certificates from a third-party CA, click the following article number to view the article in the Microsoft Knowledge Base: 291010 (http://support.microsoft.com/kb/291010/ ) Requirements for domain controller certificates from a third-party CA
NOTE: The domain controller certificate is used for Secure Sockets Layer (SSL) authentication, Simple Mail Transfer Protocol (SMTP) encryption, Remote Procedure Call (RPC) signing, and the smart card logon process. Using a non-Microsoft CA to issue a certificate to a domain controller may cause unexpected behavior or unsupported results. An improperly formatted certificate or a certificate with the subject name absent may cause these or other capabilities to stop responding.
5. Request a smart card certificate from the third-party CA.
Enroll for a certificate from the third-party CA that meets the stated requirements. The method for enrollment varies by the CA vendor.

The smart card certificate has specific format requirements:
  • The CRL Distribution Point (CDP) location (where CRL is the Certification Revocation List) must be populated, online, and available. For example:
[1]CRL Distribution Point
Distribution Point Name:
Full Name:
URL=http://server1.name.com/CertEnroll/caname.crl
  • Key Usage = Digital Signature
  • Basic Constraints [Subject Type=End Entity, Path Length Constraint=None] (Optional)
  • Enhanced Key Usage =
o Client Authentication (1.3.6.1.5.5.7.3.2)
(The client authentication OID) is only required if a certificate is used for SSL authentication.)
o Smart Card Logon (1.3.6.1.4.1.311.20.2.2)
  • Subject Alternative Name = Other Name: Principal Name= (UPN). For example:
UPN = user1@name.com
The UPN OtherName OID is : "1.3.6.1.4.1.311.20.2.3"
The UPN OtherName value: Must be ASN1-encoded UTF8 string
  • Subject = Distinguished name of user. This field is a mandatory extension, but the population of this field is optional.
6. There are two predefined types of private keys. These keys are Signature Only(AT_SIGNATURE) and Key Exchange(AT_KEYEXCHANGE). Smartcard logon certificates must have a Key Exchange(AT_KEYEXCHANGE) private key type in order for smartcard logon to function correctly.

7. Install smartcard drivers and software to the smartcard workstation.
Make sure that the appropriate smartcard reader device and driver software is installed on the smartcard workstation. This varies by smartcard reader vendor.

8. Install the third-party smartcard certificate to the smartcard workstation.
If the smartcard was not already put into the smartcard user's personal store in the enrollment process in step 4, then you must import the certificate into the user's personal store. To do so:
  • 1. Open the Microsoft Management Console (MMC) that contains the Certificates snap-in.
  • 2. In the console tree, under Personal, click Certificates.
  • 3. On the All Tasks menu, click Import to start the Certificate Import Wizard.
  • 4. Click the file that contains the certificates that you are importing.
NOTE: If the file that contains the certificates is a Personal Information Exchange (PKCS #12) file, type the password that you used to encrypt the private key, click to select the appropriate check box if you want the private key to be exportable, and then turn on strong private key protection (if you want to use this feature).
NOTE: To turn on strong private key protection, you must use the Logical Certificate Stores view mode.
  • 5. Select the option to automatically put the certificate in a certificate store based on the type of certificate.
9. Install the third-party smartcard certificate onto the smartcard. How to do this varies according to Cryptographic Service Provider (CSP) and by smartcard vendor. See the vendor's documentations for instructions.

10. Log on to the workstation with the smartcard.
Read More