SANS Exchange security webcast presented by Linux admins

I’m not making this up. From this morning’s email, an announcement from SANS of an upcoming Exchange security webcast. Here’s an excerpt from the announcement:

A Microsoft Exchange Server is often found as one of the most important collaborative assets to current organizations of all sizes. With so much dependency on a reliable e-mail and collaboration
system, many organizations are faced with the problem of how to secure those communications. This webcast will introduce listeners to Exchange messaging protocols and discuss strategies to secure those communications. This webcast will focus on Microsoft Exchange Server 2003. Miles Stevenson has spent the last five years working as a Linux network administrator. He worked in both commercial and
government sectors specializing in low-cost Linux solutions. He currently works as a full time network administrator for the SANS Institute and directs the SANS Assessment program.

Now, I don’t mean any personal disrespect to Mr. Stevenson. However, I don’t understand what in his background as a Linux admin qualifies him to talk about securing Exchange. Securing any enterprise messaging system requires a fair bit of specialized knowledge, including a good understanding of the underlying OS. I wouldn’t expect an Exchange administrator to be able to talk knowledgeably about Linux security, for example. I’m curious about what exactly will be covered in the webcast, but I’ll be on a flight when it’s being presented– if you monitor it, leave a comment here and let me know what you thought about it.

4 Comments

Filed under General Stuff, Musings

Experimenting with MediaManager

I’ve been fooling around with the MediaManager plugin for MoveableType. Its goal is to provide a structured system for creating and tracking entries about books, movies, CDs, and the like. For example, here’s what my current media queue looks like:

Picture 2-1

It still has a few bugs; for example, even though I’m using the sample code from the product page in my page template, I only see one book I’m reading and zero that I’ve read. I also can’t post reviews; I get a MySQL insertion error when I try. However, the overall premise is cool, and I think I’ll be happy with the finished product.

Comments Off on Experimenting with MediaManager

Filed under Reviews

Exchange hotfixes for Entourage 2004 SP2

See, I told you the Entourage blog was about to spring back to life. Today’s entry: the details on the Exchange hotfixes suggested (but not required) for using Entourage 2004 SP2 with Exchange 2000 and Exchange Server 2003.

Comments Off on Exchange hotfixes for Entourage 2004 SP2

Filed under General Stuff, Musings

New vulns in Veritas StorageExec

Hot on the heels of the recent BackupExec vulns, the folks at NGS have been busy finding similar buffer overflow vulnerabilities in the StorageExec product. This Windows IT Pro article credits NGS, but NGS’ own web site doesn’t seem to have an alert. Anyway, Symantec has released hotfixes for StorageExec and StorageCentral.

Of course, the real question is whether Symantec is going to institute the same kind of deep-dive security effort that Microsoft did with their Secure Windows Initiative and Trustworthy Computing. Vendors who don’t do that (paging Mr. Ellison! paging Mr. Ellison to the white security phone!) are going to continue to get their pants pulled down by eager, skilled firms like NGS.

Comments Off on New vulns in Veritas StorageExec

Filed under Security

Service Pack 2 for Office 2004 ships

Today Microsoft announced that it was releasing Service Pack 2 (SP2) for the Macintosh version of Microsoft Office. Apart from the usual bug fixes to all of the Office apps, the big news here is that SP2 makes some major– and welcome– changes to Entourage’s Exchange support.

There’s a long list of tasty new Exchange goodness in the SP2 release, including:

  • A new model for calendaring and address books. Previous versions couldn’t support calendar or contact public folders; this release does. In order to enable that support, the dev team changed the way calendar data is stored and managed. Now you’ll have a calendar on your local machine, plus a calendar for each Exchange account, plus any calendar public folders you have. For most Exchange users, this will be a huge improvement. For the small number of users who’d defined multiple Exchange accounts in the same Entourage identity, you’ll notice that now Entourage doesn’t automatically sync events from every calendar to every other calendar.
  • Much, much better sync performance with Exchange accounts. (They also fixed that annoying bug where the Progress window would pop up even when you’d previously closed it.) Public folder browse performance is greatly improved too.
  • Support for setting permissions on Exchange items. That’s right– you can now grant permissions on any folders in your mailbox, just like you can in Outlook. You can also open other users’ shared folders, provided you have permission to do so.
  • You can create private calendar and contact items.
  • There’s much better support for delegation, including the ability to assign other users as delegates.

There are also some less obvious, but perhaps more welcome, changes. For example, Entourage now honors the Thread-Index and Thread-Topic headers that Outlook uses. That means that conversations with Outlook users will be properly threaded. Entourage also includes a new Conversation view type that properly threads mail messages– a feature that’s long overdue (though you could simulate it by creating your own custom view). You can also do a “get info” on any folder to see how much space it’s taking up on the Exchange server– something I use all the time, given the mailbox limits applied to some of my accounts.

SP2 is available for download from Microsoft’s Mac website; as far as I know, it will update either the RTM or SP1 versions of the Office suite, and you’ll need to install it separately on each machine unless you’re using a software distribution system. Microsoft has also promised to make it available through their automatic update mechanism for Mac Office, but it doesn’t seem to have shown up there yet.

Update: Gerod reminded me that you need an Exchange hotfix to enable sharing and delegation to work; I’d forgotten all about that. (Also updated the links to point to live content)

Update: John Welch has tons of screen shots in his article on SP2.

7 Comments

Filed under General Stuff, Musings

My latest royalty e-mail

I just got a mail message from my agent. Here’s what it said:

Hi Paul,
A direct deposit request has just been sent to our bank for you. Your
money should be deposited into the account you have on file with Studio
B within 2 business days.
The amount of the deposit is: $1.11
The payment is for: Digital Think royalties Q1 2005 – Windows NT Server 4.0 in Enterprise

w00t! ‘Scuse me while I run down to the store and buy a candy bar.

3 Comments

Filed under FAIL

Entourage team blogs

Did you know that there’s a blog maintained by the Entourage team at Microsoft’s Mac business unit? Me neither. But they do, and a little bird tells me that they’re going to start updating it much more regularly. Drop by and add it to your aggregator if you use or support Entourage.

Comments Off on Entourage team blogs

Filed under General Stuff, Musings

Troubleshooting note to self

Note: if you’re troubleshooting an Internet problem, and you use your BuckeyeTel line to call Buckeye’s support number, don’t power-cycle the modem while you’re still on the phone.

4 Comments

Filed under FAIL

Exchange 12 developer roadmap posted

Cool stuff from the PDC: the developer roadmap for E12 was unveiled at PDC today. Terry Myerson has a post on it at the Exchange team blog, or you can just go straight to the PowerPoint deck from the session. I’ve got a lot of catching up to do, since the Cookbook depends on WMI and CDOEXM.

Comments Off on Exchange 12 developer roadmap posted

Filed under General Stuff, Musings

Setting default reviewer permissions

Let’s say you wanted to set every calendar in your organization to grant all users “reviewer” rights. This makes it easy to see detailed calendar data instead of just pure free/busy information. There’s no direct way to do this through CDOEXM or WMI, but Glen Scales has come up with a solution that uses the Exchange 5.5 acl.dll. Check it out here.

Comments Off on Setting default reviewer permissions

Filed under General Stuff, Musings

Northwest joins the BK parade

So Northwest, the other airline with good local air service, just filed for Chapter 11 too.

Comments Off on Northwest joins the BK parade

Filed under Travel

Delta files chapter 11

No big surprise here; Delta filed for Chapter 11 bankruptcy protection this afternoon. I don’t expect this to impact their normal operations, which is good ’cause I’m flying them later this month.

Comments Off on Delta files chapter 11

Filed under Travel

Microsoft rolls out workflow

I actually had real work to do this week, so I couldn’t attend the PDC. That’s too bad, because there’s a lot of interesting stuff happening there. For example, MS today took the wraps off Windows Workflow Services, their platform for workflow integration. There are some interesting touches that I think will help distinguish their offering from their competitors, including integration with Visual Studio and a marketplace for workflow actions (which MS is calling “activities”.) When I get some time, I’ll have to dig into this and see what’s what.

In related news, MS also started talking about changes to InfoPath (hint: no more requirement for a client-side application) and their new Office server platforms. It’s very interesting that they’re focusing on BI and content management as first-class tasks in the new release; we’ll have to wait and see what capabilities they’re able to get in for the 1.0 release.

Comments Off on Microsoft rolls out workflow

Filed under General Stuff, Musings

Byzantine failures

There’s a fascinating article in the most recent issue of RISKS Digest about anomalies and Byzantine failures in flight control systems. I can’t explain it nearly as well as Peter Ladkin, who wrote it, so I won’t try. Although Exchange and Windows aren’t generally vulnerable to Byzantine faults, it’s a fascinating area of study in security-critical systems: how do you design systems that keep working when their inputs are lying?

Comments Off on Byzantine failures

Filed under General Stuff, Musings

Wood County Sheriff’s citizen academy

From our sheriff:

The Wood County Sheriff’s Office Citizen’s Police Academy fall classes will begin Monday September 19, 2005, and Wednesday September 21, 2005. Classes will start at 6:30pm and end at 9:30pm. The classes will end the week of November 13, 2005. Sign up begins June 1,2005 and will continue till classes are full. Maximum class size is 16 people per class. To sign up please call Deputy Dirk Fenimore at (419) 373 – 6519, or send email.

Mark was instrumental in running a similar citizen’s academy for the Perrysburg Police Division. I attended it last year and had a blast– so if you’ve got the time, I think you’ll find the sheriff’s edition well worth your time.

Comments Off on Wood County Sheriff’s citizen academy

Filed under Musings