Deb Shinder’s Blog

All Blogs  »  Deb Shinder's Blog  »  Archive: May 2009

Remote Server Administration Tools for Windows 7

image Remote Server Administration Tools for Windows 7 RC enables IT administrators to manage roles and features that are installed on remote computers that are running Windows Server 2008 R2 (and, for some roles and features, Windows Server 2008 or Windows Server 2003) from a remote computer that is running Windows 7 RC.

It includes support for remote management of computers that are running either the Server Core or full installation options of Windows Server 2008 R2, and for some roles and features, Windows Server 2008. Some roles and features on Windows Server 2003 can be managed remotely by using Remote Server Administration Tools for Windows 7 RC, although the Server Core installation option is not available with the Windows Server 2003 operating system.

This feature is comparable in functionality to the Windows Server 2003 Administrative Tools Pack and Remote Server Administration Tools for Windows Vista with Service Pack 1 (SP1).

http://www.microsoft.com/downloads/details.aspx?Fa...ang=en

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

SSTP Certificate selection

image If you’ve followed my articles at www.windowsecurity.com, you might have noticed that I did one on SSTP VPN servers.

If you haven’t heard about SSTP, it’s a new VPN protocol that was introduced with Windows Server 2008. SSTP (Secure Socket Tunneling Protocol) is essentially PPP over SSL. What this means is that your VPN client can now be behind a firewall or NAT device (or even a Web proxy) and the SSTP connections will be able to make it through so that your remote users can establish a VPN connection to your network.

The Windows Server 2008 SSTP solution is great. But there’s just one problem. If you don’t handle certificate installation in the right order, you’ll end up in a world of hurt, because it’s not obvious which certificate RRAS is selecting to enable the SSTP connections. And if you end up with the wrong certificate, you’ll have to spend a bit of time untangling things to get them to work the way you want them.

The RRAS team heard our concerns, and with Windows Server 2008 R2 they’ve fixed this problem. With Windows Server 2008 R2, there’s a nice dialog box that enables you to select the certificate you want to use for the SSTP connections. Nice!

Check out Dhiraj Gupta’s great article on this feature over at:

http://blogs.technet.com/rrasblog/archive/2009/02/...n.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

End To End Trust Requirements for the Emerging Cloud Computing Ecosystem

image “End to End Trust fundamentals and requirements for the cloud computing world.  This session will discuss  trustworthiness factors, security and privacy issues that should be part of the planning and implementation of cloud computing ecosystem”

Security and trust issues are the single major hurdle that conspires against accelerated adoption of cloud computing by businesses of all sizes, but enterprises in particular. While cloud computing economics are very enticing, and the ability to leverage massive compute and storage on the cloud provider’s network is attractive, if you can’t be sure that the environment is secure, then all bets are off.

In this Webcast, Doug Cavit, Chief Security Strategist at Microsoft discusses what Microsoft will do to help insure that their cloud computing infrastructure is one that you can trust.

Check it out at:

http://edge.technet.com/Media/End-To-End-Trust-Req...ystem/

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Online Security for Exchange – Secure Exchange in the Cloud

Security is a major issue when it comes to cloud computing. And one of the most popular implementations of enterprise cloud computing is seen with Microsoft Exchange.

Companies of all sized are seeing the benefits of moving from on-premise Exchange deployments to cloud based solutions.

The problem is how do you get the same level of security for your online deployment of Exchange as what you have behind your firewall?

One part of the equation is Forefront Online Security for Exchange or FOSE.

FOSE includes an SLA (SLAs are always a bone of contention with cloud deployments) that promises:

  • Five 9s uptime
  • Email delivery in less than one minute
  • 100% protection against known email viruses
  • 98% capture of al inbound spam
  • Less than 1 out of 250K false positives

Check out the details of FOSE at:

http://blogs.technet.com/forefront/archive/2009/04...e.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

AutoRun changes in Windows 7

As you might know, malware can take advantage of the Windows autorun feature to do their dirty deeds. For this reason, Microsoft decided to change the way that autorun works in Windows 7. image

Here’s a nice blog post by the Microsoft Security Research and Defense Team on the details of how they’ve changed the autorun feature to make sure that malware doesn’t leverage this feature in the future.

Check it out at:

http://blogs.technet.com/srd/archive/2009/04/28/au...7.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

How to configure the Windows Server 2008 CA Web Enrollment Proxy

Here’s a really well done article on how to configure a Windows Server 2008 IIS 7 server as a CA Web enrollment proxy.

As the article states:image

“For those of you that do not know, you can install the Windows Server 2008 CA web site pages on an alternate server from the CA. One reason why you might deploy this configuration is if you currently have a Windows 2000 / Window Server 2003 Certification Authority and need to be able to deploy certificates to Windows Vista and Windows Server 2008 machines via the CA web site pages. Another reason might be because you want to offer certificate enrollment to Internet-based users but do not want to expose your Certification Authority to the Internet.”

I really enjoyed this one – chock full of screenshots and step by step instructions. Just what we need to start off a new configuration!

Check it out at:

http://blogs.technet.com/askds/archive/2009/04/22/...y.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center

Follow TechGenix on Twitter