<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sharepoint]]></title>
    <link>http://securityratty.com/tag/sharepoint</link>
    <description></description>
    <pubDate>Thu, 12 Jun 2008 09:50:34 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Blue Skies for Microsofts Cloud Computing]]></title>
      <link>http://securityratty.com/article/3c9eda5c7b392de30995f1ab45b5ef03</link>
      <guid>http://securityratty.com/article/3c9eda5c7b392de30995f1ab45b5ef03</guid>
      <description><![CDATA[Microsoft announced their Azure cloud platform this week a rival to Amazon.coms EC2 and Googles App Engine. Combined with Microsoft Visual Studio, SQL Services, .NET Services, Live Services,...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" height="132" alt="windowsazure" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/windowsazure.jpg" width="196" align="left" border="0"> Microsoft announced their <a href="http://www.eweek.com/c/a/Cloud-Computing/Microsoft-Unveils-Cloud-Platform-Windows-Azure/?kc=EWKNLNAV10282008STR1" target="_blank">Azure cloud platform</a> this week – a rival to <a href="http://www.marketwatch.com/news/story/Amazon-Web-Services-Launches-Amazon/story.aspx?guid=%7B70399F5E-7F4D-4085-A1BD-6D937847B50E%7D" target="_blank">Amazon.com’s EC2</a> and Google’s App Engine. Combined with Microsoft Visual Studio, SQL Services, .NET Services, Live Services, Sharepoint Services and Microsoft Dynamics CRM Services, the new platform will help web developers to build apps for the cloud.
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 10px 0px 0px 10px; border-right-width: 0px" height="244" alt="cloud" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/cloud.jpg" width="166" align="right" border="0">
<p>The Azure announcement is the culmination of years of planning for Microsoft’s “software-plus-services approach to computing.” According to <a href="http://www.eweek.com/c/a/Cloud-Computing/The-Woman-Behind-the-Microsoft-Cloud/?kc=EWKNLNAV10292008STR3" target="_blank">Debra Chrapaty</a>, the woman who runs Microsoft’s data center infrastructure, plans started about four to five years ago to build out data center capacity for the new initiatives. The best place to build a new data center: Quincy, Washington – whose hydroelectric power and commitment to fiber made it a winner. (<a href="http://quincywashington.us/quincy/index.php?option=com_content&amp;task=view&amp;id=57&amp;Itemid=2" target="_blank">Click here</a> for Mayor Hernberry’s update on the impact of the new data centers and apparently new wineries popping up in Quincy.)
<p>Thank goodness for Microsoft. In this economy, we should all be grateful to companies that can still spend between $300 million to $700 million to build just one data center. </p>
]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 13:10:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/data center capacity">data center capacity</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/azure cloud platform">azure cloud platform</category>
      <category domain="http://securityratty.com/tag/microsoft visual studio">microsoft visual studio</category>
      <category domain="http://securityratty.com/tag/platform">platform</category>
      <category domain="http://securityratty.com/tag/googles app engine">googles app engine</category>
      <category domain="http://securityratty.com/tag/mayor hernberrys">mayor hernberrys</category>
      <source url="http://blog.sciencelogic.com/blue-skies-for-microsofts-cloud-computing/10/2008">Blue Skies for Microsofts Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Why some security pros hate SharePoint]]></title>
      <link>http://securityratty.com/article/efdf4a563396186ce951ba98654c6152</link>
      <guid>http://securityratty.com/article/efdf4a563396186ce951ba98654c6152</guid>
      <description><![CDATA[Some SharePoint customers are finding that it's difficult to automate user administration, among other...]]></description>
      <content:encoded><![CDATA[Some SharePoint customers are finding that it's difficult to automate user administration, among other woes.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:49b0414dc65ef2005944bed5c2231587:vA6uNkbk4MWz%2BBDMVdOiFC68olFD4aREtbpA02woz4LLX10WhuSLsvpfBvxQQnKBJCf37Vw59KcS'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:78758995e60ac054bf542fbb14da7871:zr5wsjkEnlJLXK3s%2FMH8nSDdVkih51QNcZfHA5s2cZ42n0P6bOyu5R3GVrcosr3Gn6w4Ex8kuAUetg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7826f5251efa92a9b824256ba71781af:pAZouKolvQycZazP6iD68cf4fLJpF8mvlCLvyWL9BlOqqja2MlRKqCrol7BCNsVn%2BMrKnleW8MoYVQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:77dfad85e7438c1f5e78a307b77e2280:DBeOhkw12ET8oiE7zQsZjfqRRfc7m%2BypXkUQDbYY9jdDad6xHcsVkdsCVrxUclfcAhpqP8lMfecHnw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5fb796d083dd5e63ec5c08866ac4a59a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5fb796d083dd5e63ec5c08866ac4a59a" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/user administration">user administration</category>
      <category domain="http://securityratty.com/tag/sharepoint customers">sharepoint customers</category>
      <category domain="http://securityratty.com/tag/woes">woes</category>
      <category domain="http://securityratty.com/tag/difficult">difficult</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=5fb796d083dd5e63ec5c08866ac4a59a">Why some security pros hate SharePoint</source>
    </item>
    <item>
      <title><![CDATA[VMWare is Better Than Microsoft]]></title>
      <link>http://securityratty.com/article/a030161b183f83f292761020fb04b7d9</link>
      <guid>http://securityratty.com/article/a030161b183f83f292761020fb04b7d9</guid>
      <description><![CDATA[After barely surviving the VMworld registration process, my first session was From Hypervisors to VMware Infrastructure What Matters? or as I would have called it why VMware is so much better than...]]></description>
      <content:encoded><![CDATA[<p>After barely surviving the <a href="http://www.vmworld.com/conferences/2008/" target="_blank">VMworld</a> registration process, my <a href="https://vmworld2008.wingateweb.com/scheduler/eventguide/publicScheduleByType.jsp?ts=1221517325133" target="_blank">first session</a> was “From Hypervisors to VMware Infrastructure – What Matters?” – or as I would have called it “why VMware is so much better than Microsoft…and if you don’t believe that we can help you make even more money on top of your already successful Microsoft business.” (I know, that title is way too long but quite descriptive.)</p>
<p>The session took place at the beginning of Partner Day. The “regular” conference sessions actually begin tomorrow. Today is spent focusing on partner issues and enablement.</p>
<p>The panel for this session included:</p>
<ul>
<li>Mark Chuang <small>Group Manager, Product Marketing, </small>VMware, Inc.</li>
<li>Kenon Owens <small>Staff Systems Engineer, </small>VMware, Inc.</li>
</ul>
<p>You have to remember that <a href="http://www.virtualization.info/2008/09/more-than-20-partners-announces-support.html" target="_blank">most of the Partners here</a> are not vendors like ScienceLogic, but big and small shops that are selling IT, networking and now virtualization solutions into end-customer environments. For these guys, understanding what virtualization partner programs and tools are at NetApp, for example, is very useful. And many of these companies are already selling Microsoft software and surrounding services for Microsoft products. So if you’re VMware, what’s the message to these partners in the face of the Microsoft juggernaut?</p>
<blockquote><p>Microsoft to partners: “You may not like to admit it, but you’re probably already in bed with us.”</p>
<p>VMware to partners: &#8220;Our hypervisor technology outperforms Hyper-V and Xen, especially at scale. And anyway, it’s not about the battle at the hypervisor. It’s about the V-services on top of the hypervisor – VMotion, Storage VMotion, DRS, etc.&#8221;</p></blockquote>
<p>Interesting and what we all already know, or think we know. The scale issue is an interesting one – too soon for <a href="http://blogs.technet.com/virtualization/archive/2008/09/12/pre-vmworld-check-out-hyper-v-server-and-live-migration-demos.aspx" target="_blank">Hyper-V</a> and who uses Xen? But also interestingly enough, no announcement or even talk about extending VMware management tools to other hypervisors. The point, as the VMware product marketing guy made a point of saying, is that the question they needed to answer used to be “Why Virtualization?” and now it’s “Why VMware?&#8221;.</p>
<p>One more tidbit – this survey run by VMware asking their customers:</p>
<p><strong>What are the top 6 apps you are running on VMware today</strong></p>
<ul>
<li>IIS</li>
<li><em>Apache</em></li>
<li>Active Directory</li>
<li>SQL Server</li>
<li>Sharepoint</li>
<li>Exchange</li>
<p><em></em></ul>
<p><strong>That means, 5 of 6 are Microsoft applications. </strong>Certainly it makes it even more challenging for VMware to navigate a path here.</p>
<p>The change since 2004 – would have talked about why virtualize. And now why VMware. (Duh.)</p>
<p>Talking to partners – many of which already have a successful Microsoft business. How VMware <a href="http://gigaom.com/2008/09/14/for-vmware-an-uncertain-future/" target="_blank">enhances your existing Microsoft business</a>.</p>
<p><strong>Top 6 apps running on VMware today (5 of 6 are Microsoft applications)</strong></p>
<ul>
<li>IIS</li>
<li><em>Apache</em></li>
<li>AD</li>
<li>Sql server</li>
<li>Sharepoint</li>
<li>Exchange</li>
</ul>
<p><em>Source: VMware survey</em></p>
<p>Esxi - VMware – true thin hypervisor; maximizes resources utilization (over 100% memory commitment – allows avg of 2:1 memory overcommit) – host system memory is usually the resource bottleneck – plus Advanced Scheduler runs VMs better under load and to a greater capacity (hard to show this part); performance acceleration – using binary translation (32bit), para-virtualization and Hardware Assist (for 64-bit)</p>
<p>(rvi – rapid virtualization indexing)</p>
<p>No parent partition that all hypervisors have to go through</p>
<p>Vs ms/xen</p>
<p>Parent partition – dom 0 =&gt; potentially problem at scale; i/o that could be a bottleneck</p>
<p>Hyper-v SPECjbb comparison</p>
<p>= 9 vms on VMware and hyper-v hypervisors</p>
<p>Outperform (CPU) by 50% - general purpose scheduler isn’t able to keep up? “got to be”</p>
<p>(cpu only test)</p>
<p>Also used VMmark – to demonstrate again that VMware is performance tuned and designed to run at scale vs Hyper-V</p>
<p>Size Does Matter:</p>
<p>Vmware ESXi: 32MB</p>
<p>Hyper-v – 2.6 GB</p>
<p>Xen – 1.2 GB</p>
<p>Hyper-V uses Microsoft Server Core – so the last two Patch Tuesdays had to make changes to Server Core (nothing to do with Hyper-V) but service interruption for Hyper-V.</p>
<p>VMware VMsafe – “Provides an unprecedented level of security” “virtual is more secure than Real” (uh oh – clearly didn’t read about the</p>
<p>*****************</p>
<p>VMware TEST:512 mb vms on server w/ 4gb ram –</p>
<p>7 vms - xensource (w/no memory overcommit)</p>
<p>6vms – hyper-v before error (w/no memory overcommit)</p>
<p>14vms - w/memory overcommit and management</p>
<p>Running sql io sim – heavy workloads</p>
<p>TCO – not just license; now ESXi is free – so hardware</p>
<p>809 - ESXi</p>
<p>871 – vi3 foundation ($995)</p>
<p>1168- vi3 enterprise ($5750)</p>
<p>1621 – hyper-v – 2x cost because of hw</p>
<p>Xen – 1618</p>
<p>Memory overcommit (89% in production vs. test/dev)</p>
<p>Survey – 37% of respondents at 2:1 RATIO OR HIGHER; real average is around 1.8: 1</p>
<p>*********************</p>
<p>This guy Mark sounds like a used car salesman:</p>
<p>“Always On, On Demand Data Center”</p>
<blockquote><p>Hypervisor is very important but what is more important are the v-services on top of this. Manage shared, pooled resources. “Value Above the Hypervisor”</p></blockquote>
<p>How does all this save “your customers” $$?</p>
<p><strong>VMotion – saves cost on planned maintenance: no more overtime, no more time scheduling maintenance windows (see cost framework below)</strong></p>
<p>10 (# of servers) x 6 (@ of updates) x [ (overtime cost 2hrs x $150/hr) + (scheduling downtime # of apps per server 15 x time spend scheduling per app 0.75 hr x $50/hr)] = $58,500</p>
<p>Same thing with using VMware Storage VMotion</p>
<p>Overtime cost + scheduling downtime + planning move + alternative tool cost - $68,750 (2.5 TeraBytes)</p>
<p><strong>The Value of High Availability</strong></p>
<p>- cost of lost business, lost work</p>
<p>- cost of lost productive time</p>
<p>4 hours of downtime x # of users per vm 10 x number of vms per host 15 x cost of user productive time $50/hr x failures per year in 10-host cluster 2 = $60K</p>
<p>(10 servers, 150 vms)</p>
<p><strong>SAVINGS (using enterprise version)</strong></p>
<p>Update management 149,760</p>
<p>HA 60K</p>
<p>DRS, VMotion Storage VMotion 187,250</p>
<p>808,259 – hw, power cooling, etc.</p>
]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 19:00:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/vmware survey">vmware survey</category>
      <category domain="http://securityratty.com/tag/vmware enhances">vmware enhances</category>
      <category domain="http://securityratty.com/tag/vmware infrastructure">vmware infrastructure</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/vmware test">vmware test</category>
      <category domain="http://securityratty.com/tag/overtime cost 2hrs">overtime cost 2hrs</category>
      <source url="http://blog.sciencelogic.com/vmware-is-better-than-microsoft/09/2008">VMWare is Better Than Microsoft</source>
    </item>
    <item>
      <title><![CDATA[BitKoo clamps tight user controls on SharePoint ]]></title>
      <link>http://securityratty.com/article/2137dd12025399fdf517caac4e1708c6</link>
      <guid>http://securityratty.com/article/2137dd12025399fdf517caac4e1708c6</guid>
      <description><![CDATA[Access-control vendor BitKoo Monday unveiled an authentication and authorization gateway that lets users control internal and external access to Microsoft's SharePoint...]]></description>
      <content:encoded><![CDATA[Access-control vendor BitKoo Monday unveiled an authentication and authorization gateway that lets users control internal and external access to Microsoft's SharePoint server. ]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users control internal">users control internal</category>
      <category domain="http://securityratty.com/tag/external access">external access</category>
      <category domain="http://securityratty.com/tag/sharepoint server">sharepoint server</category>
      <category domain="http://securityratty.com/tag/authorization gateway">authorization gateway</category>
      <category domain="http://securityratty.com/tag/authentication">authentication</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <source url="http://www.networkworld.com/news/2008/080408-bitkoo-sharepoint-user-controls.html?fsrc=rss-security">BitKoo clamps tight user controls on SharePoint </source>
    </item>
    <item>
      <title><![CDATA[Directly connect to your corpnet with IPsec and IPv6]]></title>
      <link>http://securityratty.com/article/8fa825adcf64d7fa728dd4b170277578</link>
      <guid>http://securityratty.com/article/8fa825adcf64d7fa728dd4b170277578</guid>
      <description><![CDATA[Contrary to popular belief, the rumors of my demise have been greatly exaggerated. Well, ok, no actual rumors, but hey, one can dream, huh? My spring calendar was full of events in Asia and Australia,...]]></description>
      <content:encoded><![CDATA[<p>Contrary to popular belief, the rumors of my demise have been greatly exaggerated. Well, ok, no <em>actual</em> rumors, but hey, one can dream, huh? My spring calendar was full of events in Asia and Australia, then TechEd US seemed to suddenly appear out of nowhere! So I've been kinda swamped. I've missed writing here; it's good to get back into the swing.</p>  <p>At TechEd this year, I gave a presentation called <strong>&quot;21st century networking: time to throw away your medieval gateways.&quot;</strong> (Actually, I've given this same talk before, at events in Amsterdam, Brussels, Oslo, and numerous on-campus customer meetings. It's time to bring the knowledge to the masses.)</p>  <p>I described an idea of using IPv6, IPsec, NAP, and group policy to build a pretty slick replacement for clunky VPN gateways. Turns out we've been piloting this very idea on our internal corpnet. Like a good little bunny I got myself enrolled in the thing and -- pardon the unattractive gushing -- this thing <em>rawks!</em> Here's a brief rundown of the parts you'd configure on <strong>managed clients</strong>:</p>  <ul>   <li>Windows Vista Business (with Software Assurance), Enterprise, or Ultimate editions</li>    <li>That are domain-joined</li>    <li>Users run as <a href="http://blogs.msdn.com/aaron_margosis/" target="_blank">non-admin</a></li>    <li><a href="http://technet.microsoft.com/en-us/windowsserver/grouppolicy/default.aspx" target="_blank">Group policy</a> applies numerous settings</li>    <li><a href="http://technet2.microsoft.com/WindowsVista/en/library/0d75f774-8514-4c9e-ac08-4c21f5c6c2d91033.mspx?mfr=true" target="_blank">UAC</a> is enabled</li>    <li><a href="http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true" target="_blank">BitLocker</a> is configured to protect confidential information stored offline</li>    <li>The <a href="http://technet.microsoft.com/en-us/network/bb545423.aspx" target="_blank">Windows Firewall</a> is enabled</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb545879.aspx" target="_blank">NAP</a> is used for checking health</li>    <li><a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx" target="_blank">Forefront Client Security</a> for keeping malware off the box</li>    <li><a href="http://technet.microsoft.com/en-us/library/bb742533.aspx" target="_blank">Smart cards</a> for strong authentication of users</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb531150.aspx" target="_blank">IPsec</a> is required for connection authentication and traffic encryption</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb530961.aspx" target="_blank">IPv6</a> is required for worldwide Internet connectivity</li>    <li>A DNS suffix search list represents the data center name space</li>    <li>Static IPv6 DNS servers provide name resolution for hosts in the data center</li> </ul>  <p>What does this give you? True <a href="http://www.microsoft.com/mscorp/twc/anywhereaccess/default.mspx" target="_blank">anywhere access</a>, <a href="http://www.microsoft.com/mscorp/execmail/2007/02-06secureaccess.mspx" target="_blank">anywhere in the world</a>, directly to corpnet resources from managed and secure client PCs. The Internet has replaced private WAN links for good reason: enormous cost benefits. The only thing holding us back from fully utilizing this development has been a lack of way to enforce and monitor the security of clients not physically located within the corpnet. Well, those days are over. Now you can build PCs that are trusted just as if they were on the corpnet, without knowing or caring anything about the underlying network connections. And let me tell you, it's as addictive as a few other substances I could mention, but will refrain, since this is (I hope) a family blog :)</p>  <p>Maybe you've heard of the notion of &quot;<a href="http://en.wikipedia.org/wiki/De-perimeterisation" target="_blank">deperimeterization</a>.&quot; Taken to its extreme, I think it's a bit silly. To put a SQL Server directly on the Internet is just plain stupid -- not because I don't think I could keep it protected, but simply because that's unnecessary risk. Only my web server -- and no one else -- should be talking to my SQL Server. But that web server will be in the same subnet as the SQL Server, and IPsec policies used also here will govern who can connect to the SQL Server. <strong>Warning to any and all network DMZs: your days are numbered!</strong></p>  <p>Shrink your perimeter to that which really matters -- your data center. <em>All</em> your clients live (as we would say in the olden days) &quot;on the outside of the firewall.&quot; Now then, there are two kinds of clients. Managed clients, as I described above, establish IPsec-authenticated/encrypted, group-policy-configured, NAP-enforced IPv6 connections directly to corpnet resources without going through any kind of access gateway. The router connecting you to your ISP is fully sufficient for blocking denial of service attempts. Be sure to follow my advice in &quot;<a href="http://blogs.technet.com/steriley/archive/2006/07/10/Configure-your-router-to-block-DOS-attempts.aspx" target="_blank">Configure your router to block DOS attempts</a>,&quot; and then add two more rules to permit incoming port udp/500 and IP protocol 50 over IPv6. That's it. No NATing or other unnatural network acts are required (finally, you can stop lying to your significant other about why you squirrel yourself away in the computer room all those weekend nights).</p>  <p>Unmanaged clients will continue to use IPv4 to access published Web and Win32 applications through a gateway like <a href="http://technet.microsoft.com/en-us/forefront/edgesecurity/bb687299.aspx" target="_blank">IAG</a>. Since you can't trust these clients nor can you trust the data they're throwing at you, you have to inspect and validate at the perimeter. You can take advantage of IAG's <a href="http://www.microsoft.com/forefront/edgesecurity/iag/whitepapers.mspx" target="_blank">application-modifying capabilities</a> to &quot;wrap&quot; security around poorly-written web apps; you can even download an ActiveX control to unmanaged clients to perform some basic health checking, policy enforcement, and cache clearing. None of these eliminates the final requirement to continue inspecting and removing malware from servers where users store data: <a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734822.aspx" target="_blank">Exchange</a>, <a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734828.aspx" target="_blank">SharePoint</a>, <a href="http://www.microsoft.com/forefront/serversecurity/ocs/default.mspx" target="_blank">Office Communications Server</a>, and <a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx" target="_blank">file servers</a>.</p>  <p><strong>Machines are mobile, data is mobile.</strong> The mainframes and large desktop PCs of the past posses an effective security attribute: the heaviness of the machines. You couldn't easily saunter out the front door with a PC-AT in your pocket! These days, we all line our pockets with tiny little mobile phones stuffed with 16GB of storage. It's now a fact: data moves. And like water, data moves wherever it can, as rapidly as it can, often beyond your control if you don't prepare for that. With properly-configured and managed clients we can enjoy a single access and authentication experience no matter where the computer is physically located. For example: I can sit in my house and enter '&quot;http://internal-web-site-name&quot; in my browser. The DNS suffix search list adds the appropriate suffix, my browser's resolver performs an IPv6 name lookup, and my computer makes an authenticated and encrypted connection, after it meets the NAP policy, directly to that internal server. Very nice. As far as I'm concerned, there's no difference between the Internet and my corpnet. It's all <em>just there.</em></p>  <p>For a while now many of you know I've been speaking and writing, mostly at the conceptual level, about the day when such a way of remote computing will arise. Well, my friends, that day is now. You can indeed build it now, with the products you have. I won't admit it's all peaches and cream: there's a fair number of moving parts here, it's true. But most of these moving parts are parts you're already familiar with: I'm simply encouraging you to move them in a specific way. You'll need to do some custom scripting for client-side connection diagnostics, but that's about it.</p>  <p>My next step is to create a more detailed guide, which I plan to publish through TechNet Magazine. I'm targeting (but not promising) the October issue. The article will include greater details about configuring your infrastructure to support the managed clients I describe.</p>  <p>I've lost track of the swelling number of individual conference attendees and the plethora of email writers who've expressed a desire to build this in their own environments. The one common thread from everyone is &quot;I want to do it now!&quot; Folks, it's really pretty exciting for me to see so many of you ready to cross the chasm from the perdition of paleo-networking (layer upon endless, complex layer of DMZs) into the paradise of flat, simple, cheap, and secure access to information. If you haven't yet, please take the time to read through some of our information (especially Scott Charney's paper) on <a href="http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx" target="_blank">end-to-end trust</a>. Friends, the idea I describe above is the plumbing for realizing the end-to-end trust vision.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3078070" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 16:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/corpnet">corpnet</category>
      <category domain="http://securityratty.com/tag/sql server directly">sql server directly</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/end-to-end trust vision">end-to-end trust vision</category>
      <category domain="http://securityratty.com/tag/users store data">users store data</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx">Directly connect to your corpnet with IPsec and IPv6</source>
    </item>
    <item>
      <title><![CDATA[Orchestria updates data leak prevention suite]]></title>
      <link>http://securityratty.com/article/9993c03d8f1de8d998af9ba10404e17a</link>
      <guid>http://securityratty.com/article/9993c03d8f1de8d998af9ba10404e17a</guid>
      <description><![CDATA[Orchestria announces the sixth version of its data-leak prevention product, adding a way to block and monitor USB and print ports, watch Microsoft SharePoint for unauthorized corporate data, among...]]></description>
      <content:encoded><![CDATA[Orchestria announces the sixth version of its data-leak prevention product, adding a way to block and monitor USB and print ports, watch Microsoft SharePoint for unauthorized corporate data, among other features.]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data-leak prevention product">data-leak prevention product</category>
      <category domain="http://securityratty.com/tag/microsoft sharepoint">microsoft sharepoint</category>
      <category domain="http://securityratty.com/tag/orchestria announces">orchestria announces</category>
      <category domain="http://securityratty.com/tag/monitor usb">monitor usb</category>
      <category domain="http://securityratty.com/tag/print ports">print ports</category>
      <category domain="http://securityratty.com/tag/sixth version">sixth version</category>
      <category domain="http://securityratty.com/tag/features">features</category>
      <category domain="http://securityratty.com/tag/block">block</category>
      <source url="http://www.networkworld.com/news/2008/062408-orchestria-dlp.html?fsrc=rss-security">Orchestria updates data leak prevention suite</source>
    </item>
    <item>
      <title><![CDATA[Past, Present and Future Security Initiatives on Exhibit at Microsoft TechEd]]></title>
      <link>http://securityratty.com/article/a775f7be296ea3190fad435babd2a571</link>
      <guid>http://securityratty.com/article/a775f7be296ea3190fad435babd2a571</guid>
      <description><![CDATA[Blogger: Dan Blum
One of our service directors likes to quote William Gibson: The future is here, its just unevenly distributed
At Microsofts Server and Tools Business (STB) Analyst and Tech Ed...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>One of our service directors likes to quote William Gibson: “The future is here, it’s just unevenly distributed.”</p>

<p>At Microsoft’s Server and Tools Business (STB) Analyst and Tech Ed conferences last week, I saw a vendor and a user community living in the past, present and future with many unevenly distributed capabilities.</p>

<p>In a session on identity management strategy, for example, Microsoft discussed a variety of initiatives. These range from Card Space (futuristic implementation of user-centric Information Card specifications) to ADFS (present day enterprise federation support, though unfortunately lacking full SAML capabilities) to self-service password reset exposed through Office (decidedly backward-looking as this functionality has been available from many vendors through browsers for many years).</p>

<p>In another session on rights management and SharePoint, Microsoft highlighted the opportunity to configure SharePoint libraries to automatically apply Active Directory Rights Management Services protections on downloaded documents. Digital rights management (DRM) is controversial and no strong guarantor of confidentiality. Nonetheless, it is a&nbsp; way to put futuristic self-protecting wrappers on content so as to prevent its accidental leakage or misuse by honest, cooperative users. Because it’s not something that can resist certain types of malicious attackers, many security professionals look down their noses at rights management. Nonetheless, preventing accidental misuse of enterprise information is a big part of the space. It was clear from the number of people in the room asking intelligent questions suggesting realistic expectations that customers see potential value for this technology.</p>

<p>Finally, I was impressed by a presentation on IPSec, PKI and NAP by a Brazilian university IT manager named Rodrigo Imaginario. Starting three years ago, the university combined its student and administrative networks into a single network. Yet servers running ERP and containing administrative content (such as grading information) need to be protected from a subset of students going through their hacking stage. Imaginario implemented a logical security zoning overlay on top of the network using IPSEC in Windows. In the restricted zone, servers only accept connections from Kerberos-authenticated IPSEC clients in the administrative domain. Today, the authentication is being upgraded to use PKI for secure, all campus wireless networking. Imaginario indicated the university took the Windows IPSEC route approach because no additional software had to be purchased. Configuration was difficult, he said, but will get easier with Windows Server 2008. This sounds like an idea whose time has come.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/315701320" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 12:58:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/digital rights management">digital rights management</category>
      <category domain="http://securityratty.com/tag/rights management">rights management</category>
      <category domain="http://securityratty.com/tag/ipsec clients">ipsec clients</category>
      <category domain="http://securityratty.com/tag/sharepoint">sharepoint</category>
      <category domain="http://securityratty.com/tag/brazilian university">brazilian university</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/future">future</category>
      <category domain="http://securityratty.com/tag/configure sharepoint libraries">configure sharepoint libraries</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/315701320/past-present-an.html">Past, Present and Future Security Initiatives on Exhibit at Microsoft TechEd</source>
    </item>
    <item>
      <title><![CDATA[Past, Present and Future Security Initiatives on Exhibit at Microsoft TechEd]]></title>
      <link>http://securityratty.com/article/e17aa4e81a6f3a0ca38bbc6e89d1948d</link>
      <guid>http://securityratty.com/article/e17aa4e81a6f3a0ca38bbc6e89d1948d</guid>
      <description><![CDATA[Blogger: Dan Blum
One of our service directors likes to quote William Gibson: ???The future is here, it???s just unevenly distributed
At Microsoft???s Server and Tools Business (STB) Analyst and Tech...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>One of our service directors likes to quote William Gibson: ???The future is here, it???s just unevenly distributed.???</p>

<p>At Microsoft???s Server and Tools Business (STB) Analyst and Tech Ed conferences last week, I saw a vendor and a user community living in the past, present and future with many unevenly distributed capabilities.</p>

<p>In a session on identity management strategy, for example, Microsoft discussed a variety of initiatives. These range from Card Space (futuristic implementation of user-centric Information Card specifications) to ADFS (present day enterprise federation support, though unfortunately lacking full SAML capabilities) to self-service password reset exposed through Office (decidedly backward-looking as this functionality has been available from many vendors through browsers for many years).</p>

<p>In another session on rights management and SharePoint, Microsoft highlighted the opportunity to configure SharePoint libraries to automatically apply Active Directory Rights Management Services protections on downloaded documents. Digital rights management (DRM) is controversial and no strong guarantor of confidentiality. Nonetheless, it is a&nbsp; way to put futuristic self-protecting wrappers on content so as to prevent its accidental leakage or misuse by honest, cooperative users. Because it???s not something that can resist certain types of malicious attackers, many security professionals look down their noses at rights management. Nonetheless, preventing accidental misuse of enterprise information is a big part of the space. It was clear from the number of people in the room asking intelligent questions suggesting realistic expectations that customers see potential value for this technology.</p>

<p>Finally, I was impressed by a presentation on IPSec, PKI and NAP by a Brazilian university IT manager named Rodrigo Imaginario. Starting three years ago, the university combined its student and administrative networks into a single network. Yet servers running ERP and containing administrative content (such as grading information) need to be protected from a subset of students going through their hacking stage. Imaginario implemented a logical security zoning overlay on top of the network using IPSEC in Windows. In the restricted zone, servers only accept connections from Kerberos-authenticated IPSEC clients in the administrative domain. Today, the authentication is being upgraded to use PKI for secure, all campus wireless networking. Imaginario indicated the university took the Windows IPSEC route approach because no additional software had to be purchased. Configuration was difficult, he said, but will get easier with Windows Server 2008. This sounds like an idea whose time has come.</p></div>
]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 12:58:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/digital rights management">digital rights management</category>
      <category domain="http://securityratty.com/tag/rights management">rights management</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/ipsec clients">ipsec clients</category>
      <category domain="http://securityratty.com/tag/sharepoint">sharepoint</category>
      <category domain="http://securityratty.com/tag/brazilian university">brazilian university</category>
      <category domain="http://securityratty.com/tag/future">future</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <source url="http://srmsblog.burtongroup.com/2008/06/past-present-an.html">Past, Present and Future Security Initiatives on Exhibit at Microsoft TechEd</source>
    </item>
    <item>
      <title><![CDATA[Efficient Data Protection for Microsoft Applications with Backup Exec 12]]></title>
      <link>http://securityratty.com/article/aa6952337b288d176b556a19247c9927</link>
      <guid>http://securityratty.com/article/aa6952337b288d176b556a19247c9927</guid>
      <description><![CDATA[Source: Symantec) Companies today face the ever-increasing challenge of managing the explosive growth of valuable data. Symantec Backup Exe 12 for Windows Servers is the gold standard in Windows data...]]></description>
      <content:encoded><![CDATA[<b>(Source: Symantec)</b>  Companies today face the ever-increasing challenge of managing the explosive growth of valuable data. Symantec Backup Exe 12 for Windows Servers is the gold standard in Windows data protection, providing cost-effective, high performance, disk-to-disk-to-tape backup and recovery. Continuous data protection for Microsoft applications, include Exchange, SQL, Active Directory, and SharePoint, helps ensure that data is continuously backup up as it changes.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=e5dB1J"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=e5dB1J" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/314677188" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 18 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/backup">backup</category>
      <category domain="http://securityratty.com/tag/windows data protection">windows data protection</category>
      <category domain="http://securityratty.com/tag/symantec backup exe">symantec backup exe</category>
      <category domain="http://securityratty.com/tag/valuable data">valuable data</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/continuous data protection">continuous data protection</category>
      <category domain="http://securityratty.com/tag/microsoft applications">microsoft applications</category>
      <category domain="http://securityratty.com/tag/continuously backup">continuously backup</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/314677188/whitepapers.do">Efficient Data Protection for Microsoft Applications with Backup Exec 12</source>
    </item>
    <item>
      <title><![CDATA[Social Software, SharePoint and Microsoft 2.0]]></title>
      <link>http://securityratty.com/article/21a5fc5de3e433c5eae76d90f543be8f</link>
      <guid>http://securityratty.com/article/21a5fc5de3e433c5eae76d90f543be8f</guid>
      <description><![CDATA[I made a deliberate choice in joining Microsoft, in fact a very deliberate choice. I made a bet that we will emerge into a serious online software and services company that not only embraces but leads...]]></description>
      <content:encoded><![CDATA[I made a deliberate choice in joining Microsoft, in fact a very deliberate choice. I made a bet that we will emerge into a serious online software and services company that not only embraces but leads the next generation of Internet technology. I also made a bet that in the future people want to leverage [...]]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 09:50:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/future people">future people</category>
      <category domain="http://securityratty.com/tag/services company">services company</category>
      <category domain="http://securityratty.com/tag/bet">bet</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/internet technology">internet technology</category>
      <category domain="http://securityratty.com/tag/online software">online software</category>
      <category domain="http://securityratty.com/tag/choice">choice</category>
      <category domain="http://securityratty.com/tag/leads">leads</category>
      <category domain="http://securityratty.com/tag/embraces">embraces</category>
      <source url="http://securitybuddha.com/2008/06/12/social-software-sharepoint-and-microsoft-20/">Social Software, SharePoint and Microsoft 2.0</source>
    </item>
  </channel>
</rss>
