Entourage public folder access with Exchange 2007

Just to set the record straight: Entourage 2004 works fine with Exchange 2007 public folders.

If you’ve read the Exchange docs (or the Exchange team blog, or any of the zillions of places that reported this), you might be forgiven for being confused. The docs say that public folders are “de-emphasized”, a fancy way for saying that Microsoft is hoping you’ll start using SharePoint instead. The docs also say that OWA 2007 doesn’t support browser-based access to public folders (a regression from Exchange 2003, and a mistake IMHO, but that’s a discussion for another time.)

The Exchange team posted a blog entry explaining the details of what they meant by “de-emphasized”, but it doesn’t mention Entourage. As Exchange 2007 draws more attention, I’m seeing more people asking questions about Entourage and Exchange 2007.

The answer comes in two parts:

  • Entourage uses WebDAV to access public folders (and mailboxes, for that matter) on an Exchange server. WebDAV is fully supported for public folder access in Exchange 2007. It works great; I use it daily with three different Exchange servers.
  • OWA 2003 includes its own code that uses WebDAV to access public folders. There is no equivalent code in OWA 2007, so it can’t display public folder contents. If and when MS adds such code to OWA 2007, that will have no impact on Entourage because Entourage doesn’t use OWA to render public folders, it uses WebDAV.

Hopefully this will help clear things up somewhat, but (as John Welch has repeatedly said) it would be great to see an official statement from MS on this.

Comments Off on Entourage public folder access with Exchange 2007

Filed under UC&C

Huge list of Exchange web services samples

Wow, Matt Stehle may have just become my favorite Microsoft employee. He’s posted a long list of Exchange Web Services samples, some of which are very interesting (this is my current favorite since Entourage can’t do it yet).

Technorati Tags:

Comments Off on Huge list of Exchange web services samples

Filed under UC&C

Multiple subjectAltNames in certificates: now from Entrust

Back in September I wrote a pair of columns about how Exchange 2007 uses certificates. In it I pointed out the utility of having multiple subject alternative names, or subjectAltNames, in a single certificate; doing so allows you to have a single cert that works with autodiscover.yourdomain.com, mail.yourdomain.com, and the real underlying FQDN, all in one cert. Unfortunately, as far as I can tell no commercial CAs will actually issue such a certificate.

However, I got mail today from Andrew Codrington at Entrust. They’ve just introduced a new “unified communications certificate” as part of their partnership with Microsoft. The UC cert includes 10 subjectAltNames, with the option of adding 3 more for an additional $99. Good deal? Maybe; the 1-year cert price is a whopping $599. Still, that’s certainly cheaper than buying 3 standard Entrust certs @ $159 each when you factor in the time and labor required to obtain and install them. More on this later…

Technorati Tags:

Comments Off on Multiple subjectAltNames in certificates: now from Entrust

Filed under Security, UC&C

An embarrassing contrast: Lotusphere vs TechEd

Doggone it, this just isn’t fair. I was going to go to Lotusphere, but decided not to because I’m already going to Orlando twice this year for other trips.. and who’s their keynote speaker? Only the first man to walk on the moon.

The list of past speakers from Lotusphere is pretty impressive: John Cleese; Rudy Giulani, Walter Cronkite… meanwhile, at the flagship MS event, we get… Microsoft executives. Don’t get me wrong; I expect to see executives touting their products, and I appreciate Microsoft’s efforts to bring in sidekicks like Samantha Bee or Mary Lynn Rajskub to liven things up a bit. However, why couldn’t we have an interesting topical speaker? It couldn’t be that hard. Warren Buffett would probably be glad to help his friend Bill out. How about Sean Payton? Scott Adams? The possibilities are limitless.

Comments Off on An embarrassing contrast: Lotusphere vs TechEd

Filed under Musings

View BitLocker recovery passwords stored in Active Directory

So, you can probably tell I’m working on a BitLocker-related project by now…

One drawback to storing BitLocker recovery passwords in Active Directory is that there’s no good way to retrieve the recovery password when you need it, or so I thought. I suggested to the BitLocker team that they consider writing an extension to AD Users & Computers to make it easy for authorized admins to get a recovery password for a given computer– turns out they’d already done it and were deep into the signoff process!

The tool is officially documented in KB 928202. It’s an AD U&C extension that makes the BitLocker recovery information visible; you need to get it from PSS, but it’s a free call, so why not?

Comments Off on View BitLocker recovery passwords stored in Active Directory

Filed under General Tech Stuff, Security

First part of the Data Encryption Toolkit for Mobile PCs released

Great news– Security Analysis, the first part of the Data Encryption Toolkit for Mobile PCs, just went live.The overall Data Encryption Toolkit is a set of tools and guidance to help people secure the data on their laptops using Windows Vista with BitLocker and the Encrypting File System (EFS) in Windows XP and Windows Vista. Look for more pieces of the DET coming soon, as soon as we finish writing them 🙂

Comments Off on First part of the Data Encryption Toolkit for Mobile PCs released

Filed under Security

GRYNX Greylist, multiple recipients, and Verizon Wireless

For the last few weeks I’ve had an odd problem with mail sent from my Treo. The solution ended up being unexpected.

I carry a Treo 700w pretty much everywhere I go. It’s connected via Exchange ActiveSync to my home Exchange server and via IMAP to my server at 3Sharp. Combined with Entourage (and Pocket Outlook’s ability to accept a meeting invite on an IMAP account and put it in the main calendar) this gives me on-the-go access to pretty much everything I need. However, since December or so I haven’t been able to send from my 3Sharp account to some recipients, or so I thought.

This morning I finally got irritated enough to figure out what the problem was. Turns out it was the GRYNX greylist tool Devin implemented back in November. For some reason, it had decided that mail coming from some IPs (including the entire Verizon Wireless network) should be greylisted if the message contained more than one recipient. I guess this was expected behavior, since that’s what a greylisting tool does.

The oddest thing is that I’d get an NDR message on my Treo telling me that there was an invalid recipient and that the message had been filed in the Drafts folder. This was a result of Pocket Outlook attempting to be helpful, but its message didn’t really tell me what I needed to know.

I verified that this was the problem by using telnet from my desktop to log in, issue AUTH LOGIN, and try to send a message with one recipient– worked great. I then did the same thing with two recipients and boom! I got grey. The fix was trivial: I had to add my sender address to the greylist whitelist (huh? did I just say that?) and now mail is working properly.

Comments Off on GRYNX Greylist, multiple recipients, and Verizon Wireless

Filed under FAIL, UC&C

Where to keep your BitLocker recovery password

BitLocker allows you to store your recovery password in a file, in Active Directory, or on paper. However, Microsoft’s Troy Larsen has another, extremely valuable, suggestion:

You might also consider saving a copy of the recovery password to your cell phone—then you will have it when you are a 1000 miles from home and discover that your two year old took your dongle off the desk when you were packing. Not that that sort of thing ever happens.

Comments Off on Where to keep your BitLocker recovery password

Filed under General Tech Stuff, Security

Fab@Home: my next home improvement project

Wow, so many uses for this: a desktop 3-D printer for around $2500. You can’t yet use one of these to print out parts for a second copy, but we’re not that far off.

Comments Off on Fab@Home: my next home improvement project

Filed under General Tech Stuff

Moving your OST in Outlook 2007

I recently needed to move 3 OST files from one disk to another, and for the life of me I couldn’t figure out how. A quick search netted this article, which explained it all: you have to disable cached Exchange mode and block offline use for the OST, then move it. Clear as mud.

Comments Off on Moving your OST in Outlook 2007

Filed under General Tech Stuff, UC&C

Sometimes it’s better to be lucky than smart

So, a couple of weeks ago I bought a refurbished Mac Pro from Apple. It came with a single 250GB SATA drive, with 3 open SATA bays. I had Devin send me two of our spare 250GB SATA drives from a previous project, with the intention that I would create a striped RAID set to hold my VMware Fusion virtual machines.

I popped the two disks in, rebooted the computer, and fired up Disk Utility. After formatting the two disks, I attempted to create a RAID array, but Disk Utility wouldn’t see the second disk. In the process of fooling around, I created a mirrored array and added the first new drive to it, but I couldn’t add the second drive. In frustration, I did a low-level format on drive #2; when the format completed, I was able to add it to the new volume, so I copied my files over to it and went about my business.

Technorati Tags:

Continue reading

Comments Off on Sometimes it’s better to be lucky than smart

Filed under General Tech Stuff

“Failover cluster”: a welcome vocabulary change

I have long been complaining about Microsoft’s inconsistent use of the word “cluster”, which has a specific meaning: a set of interconnected computers that can share work and have at least some redundancy and failover capabilities. The Windows network load balancing folks call their solutions “clusters”, as do the Microsoft Cluster Service (MSCS) team. This is needlessly confusing to customers. Thankfully, I noticed that the Exchange team is doing something about it– if you check out the Exchange 2007 docs, they are now (properly IMHO) labeling their clusters as “failover clusters” to disambiguate clustering-for-redundancy from clustering-for-load-balancing. Yay!

Technorati Tags:

Comments Off on “Failover cluster”: a welcome vocabulary change

Filed under General Tech Stuff

Storing BitLocker recovery information in Active Directory

Windows Vista’s new BitLocker encryption technology is a two-edged sword. On the one hand, it offers excellent protection because it encrypts the entire OS volume with AES-256. On the other hand, if you lose the volume master key (VMK), you’re screwed– there’s no way for you to unlock and recover data from the volume.

To make this less of a danger, Microsoft allows you to create a recovery password that you can use to decrypt the disk. More precisely, the technical overview says:

In BitLocker, recovery consists of decrypting a copy of the volume master key blob that has been encrypted with a recovery key stored on a pluggable USB flash drive or with a cryptographic key derived from a recovery password. The TPM is not involved in any recovery scenarios, so recovery is possible if the TPM fails boot component validation, malfunctions, or disappears.

However, you still have to be very, very careful not to lose the recovery password! Vista includes the ability to back up the recovery password to Active Directory, but Microsoft hasn’t released the public details of exactly how to do this… until today, that is. The new BitLocker AD Guide describes how to enable AD backup of BitLocker recovery information (including the TPM owner password and the BitLocker recovery password for each protected volume).

You’ll need to extend your AD schema to enable this recovery mode. Don’t use the schema extension files on the Vista product DVD to do this. They don’t contain the correct schema properties. Instead, use the schema extension included with the AD Guide itself.

Comments Off on Storing BitLocker recovery information in Active Directory

Filed under Security

iPhone and Apple TV

From an anonymous source commenting on the new Apple iPhone:

I’m looking forward to the iPhone Shuffle which calls one of your contacts at random every time you hit Send.

The iPhone looks seriously shiny, but because it doesn’t support HSDPA I don’t think I want one– I’ve gotten too used to Verizon’s excellent local EvDO coverage. The better an “Internet communicator” the iPhone turns out to be, the more painful its lack of HSDPA will be. (Update: David Pogue sure drank the Kool-Aid.)

As for the Apple TV: meh. I’m not that excited about it, given that it looks like a way to pay $20 for a DRM-encrusted sub-DVD-resolution movie that requires a Mac to play it back. I’d rather have an HD DVD of the movie, or, failing that, I can rip it to my ReadyNAS and stream it through the Xbox 360. Or so I’m told; that doesn’t actually work for me yet… perhaps that’s the Apple TV’s appeal.

Comments Off on iPhone and Apple TV

Filed under General Tech Stuff

Exchange Load Generator / “Swordfish” Released

Very cool news from Microsoft on Friday: they’ve released the production version of the Exchange Load Generator (LoadGen) tool, formerly codenamed “Swordfish”. There are 32-bit and 64-bit versions available, both of which include documentation. LoadGen is a major change from the older LoadSim tool, in that it’s tailored to better reflect actual performance of Exchange 2007 + Outlook 2003/2007. Kudos to Jeff Mealiffe and his team at Microsoft for this release (and thanks to Jessie Zhu, who helped me figure out how to effectively use it!) Look for more on LoadGen in this week’s Exchange UPDATE newsletter.

Technorati Tags:

Comments Off on Exchange Load Generator / “Swordfish” Released

Filed under UC&C