Archive für 8.5.2008

neue Version der Exchange 2007 Management Tools für 32Bit

http://www.microsoft.com/downloads/details.aspx?familyid=6be38633-7248-4532-929b-76e9c677e802&displaylang=en&tm

(in verschiedenen Sprachen released)

The Exchange management tools include the Exchange Management Console, the Exchange Management Shell, the Exchange Help file, the Microsoft Exchange Best Practices Analyzer Tool, and the Exchange Troubleshooting Assistant Tool.

The new Exchange Management Console (formerly named Exchange System Manager) provides Exchange administrators with a graphical user interface (GUI) to manage the configuration of Microsoft Exchange Server 2007 organizations. For more information about the improvements to the Exchange Management Console, see New Administration Functionality in the Exchange Management Console.

The Exchange Management Shell is a new Exchange-specific command-line interface based on Microsoft Windows PowerShell, formerly codenamed “Monad”. You can use the Exchange Management Shell to run a single command or a series of multiple commands for managing your Exchange Server 2007 servers and objects. For more information about the Exchange Management Shell, see Using the Exchange Management Shell.

Auditing in Windows Server 2008

Einen sehr guten Artikel dazu findet sich auf der Seite Jorge’s Quest for Knowledge…

System Center Configuration Manager 2007 Toolkit (Microsoft)

The following list provides specific information about each tool in the toolkit.

  • Client Spy - A tool to help troubleshoot issues related to software distribution, inventory, and software metering on Configuration Manager 2007 clients.
  • Policy Spy - A policy viewer to help review and troubleshoot the policy system on Configuration Manager 2007 clients.
  • Trace32 - A log viewer that provides a way to easily view and monitor log files created and updated by Configuration Manager 2007 clients and servers.
  • Security Configuration Wizard Template for Configuration Manager 2007 - An attack-surface reduction tool for the Microsoft Windows Server 2003 operating system with Service Pack 1 and Service Pack 2 (SP1 and SP2) that determines the minimum functionality required for a server’s role or roles, and disables functionality that is not required.
  • DCM Model Verification - A tool used by desired configuration management content administrators for the validation and testing of configuration items and baselines authored externally from the Configuration Manager console.
  • DCM Digest Conversion - A tool used by desired configuration management content administrators to convert existing SMS 2003 Desired Configuration Management Solution templates to Desired Configuration Management 2007 configuration items.
  • DCM Substitution Variables - A tool used by desired configuration management content administrators for authoring desired configuration management configuration items that use chained setting and object discovery.

Security audit events for Microsoft Windows Server 2008 and Microsoft Windows Vista

Da ich mich in einem Projekt vor kurzem mit W2K3 Sec-Events beschäftigt habe, hinterlege ich mir lieber die Info für W2K8 …

 

http://www.microsoft.com/downloads/details.aspx?FamilyID=82E6D48F-E843-40ED-8B10-B3B716F6B51B&displaylang=en

Freie iSCSI Target Software

Freie iSCSI Target Software findet sich hier:

http://www.nimbusdata.com/products/mysan.php

http://www.rocketdivision.com/download_starwind.html

Absicherung der Client - Server Kommunikation Exchange 2007

Ein wirklich guter Blogeintrag findet sich zu diesem Thema auf dem Blog von Elan Shudnow.

Wichtig war für mich die grundsätzliche Aussage:

By default, Client to Server Authentication is encrypted using TLS via this Client Receive Connector. TLS is advertised and when using POP3/IMAP4, basic authentication, credentials will only be available after initiating a TLS encrypted connection

Jedoch sollte man sich wirklich den gesamten Artikel zu Gemüte führen… :-)

Domänen Controller als Clusterknoten - keine gute Idee - warum?

Wie Russ Kaufmann in seinem Blog gut beschreibt, gibt es diverse Gründe gegen DCs als Clusterknoten. Aus eigener Erfahrung mit Kunden, die dies unbedingt wollten, habe ich dies nochmal aufgegriffen.

It is considered a very bad practice, in the community, to run Domain Controllers (DCs) as nodes in a cluster. While Microsoft says it is possible, and it is even discussed in KB171390

So, why do so many people recommend against doing it? Let’s hit the main reasons:

  • Microsoft clearly recommends against it in KB281662
  • It is not supported for Exchange per KB898634
  • There are known issues with file share clusters per KB834231
  • The SQL team strongly recommends against it for performance reasons
  • Some hotfixes for DC/GCs may not be recommended for clusters
  • There is overhead involved with running the DC/GC on each node of approximately 130 MB of RAM, plus issues with replication traffic and overhead involved with responding to authentication and logon requests
  • There are issues with multihomed DCs where the private connections also get registered in DNS and can cause many systems to fail to properly logon/authenticate - the check box to not register the private heartbeat connection is not honored by a domain controller without proper hotfixes or registry hacks
  • If they are the only DCs in the org, then they must also be Global Catalog servers (GCs) and must also host DNS
  • If they host DNS, they should point to each other for their own DNS resolution, which will cause failures in resolution if one node is down
  • There are issues with FSMO roles and how will they will be handled if the node that hosts them is down
  • There are problems with the first node coming online if it is the only DCs in the org because the cluster service needs to validate its own account, but it can’t find the DC if the node is pointing to the other for DNS per proper DNS practices and the same is true for services such as SQL and Exchange that use service accounts
  • There are issues with possible failures if the DC is too busy being a DC and the cluster service can’t access the quorum drive as required
  • The hisecdc security template will break clustering if it is used to secure domain controllers

SharePoint Content Deployment Wizard

Die Beta 2 ist am 28.02.08 released worden. Daneben hier zusätzlich noch ein Link auf den Introducing the SharePoint Content Deployment WizardBlog.

The SharePoint Content Deployment Wizard is a tool for SharePoint 2007 which provides the means to deploy the following content:

- site collections
- webs
- lists
- folders
- list items (including files)

Content is exported using the Content Migration API (PRIME) as a .cmp file (Content Migration Package) which can be copied to other servers for import. Unlike the out-of-the-box tools, the Wizard allows *granular* selection of content via a treeview.

Group Policy Documentations Survival Guide (Microsoft/PDF)

jep… so einen netten flyer habe ich zuletzt für Windows Server 2008 in Orlando auf der TechEd erhalten…

 

alternativ gibt es auch die html Variante

Discovery Wizard for SharePoint (Quest Freeware)

im Nachgang zu meinem vorherigen Blogeintrag muss gesagt werden, dass Quest sich auch des Themas angenommen hat:

Do you know how many Microsoft SharePoint servers, site collections or sites are on your network? Discovery Wizard for SharePoint freeware gathers critical data about your SharePoint inventory (SPS and WSS) and displays the discovered results in two easy to read, HTML reports.

Download Discovery Wizard for SharePoint Freeware to quickly identify your SharePoint environment and begin understanding how your business is using it today.