<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">An Infrastructure Geek Floating in a Sea of UberCoders</title><subtitle type="html">Various bits that float through my skull, usually related to security</subtitle><id>http://blogs.technet.com/b/lrobins/atom.aspx</id><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/" /><link rel="self" type="application/atom+xml" href="http://blogs.technet.com/b/lrobins/atom.aspx" /><generator uri="http://telligent.com" version="5.6.50428.7875">Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><updated>2008-10-15T20:27:00Z</updated><entry><title>I Have Not Fallen Off the Face of the Earth. Not Yet, Anyway.</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/archive/2012/07/17/i-have-not-fallen-off-the-face-of-the-earth-not-yet-anyway.aspx" /><id>http://blogs.technet.com/b/lrobins/archive/2012/07/17/i-have-not-fallen-off-the-face-of-the-earth-not-yet-anyway.aspx</id><published>2012-07-18T01:13:00Z</published><updated>2012-07-18T01:13:00Z</updated><content type="html">Me, and My...Blog 
 As I've noted previously, I'm a terrible, terrible blogger. It's not that I don't have content for this blog, mind you. It's that I have a whole pile of it backed up, waiting to be polished and published. However, before I can post any of it, I have to do things like build virtual machines that I can use for demonstration purposes, take screenshots, polish text, dig up informational links, make sure that the things I suggest are properly vetted, do everything with appropriate...(&lt;a href="http://blogs.technet.com/b/lrobins/archive/2012/07/17/i-have-not-fallen-off-the-face-of-the-earth-not-yet-anyway.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3509482" width="1" height="1"&gt;</content><author><name>Laura A. Robinson</name><uri>http://blogs.technet.com/lrobinsmsft_4000_live.com/ProfileUrlRedirect.ashx</uri></author><category term="admin free" scheme="http://blogs.technet.com/b/lrobins/archive/tags/admin+free/" /><category term="zero admins" scheme="http://blogs.technet.com/b/lrobins/archive/tags/zero+admins/" /><category term="bad blogger" scheme="http://blogs.technet.com/b/lrobins/archive/tags/bad+blogger/" /></entry><entry><title>"Admin Free" Active Directory and Windows, Part 2- Protected Accounts and Groups in Active Directory</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/archive/2011/06/23/quot-admin-free-quot-active-directory-part-2-protected-accounts-and-groups-in-active-directory.aspx" /><id>http://blogs.technet.com/b/lrobins/archive/2011/06/23/quot-admin-free-quot-active-directory-part-2-protected-accounts-and-groups-in-active-directory.aspx</id><published>2011-06-23T20:19:00Z</published><updated>2011-06-23T20:19:00Z</updated><content type="html">I am a terrible blogger when it comes to timeliness and consistency of post intervals. I admit it. All I can say is, it has been a busy summer. I actually have a half-dozen posts queued up for publication, but each needs to be scrubbed and fleshed out before I post them, so even though I may be slow to get them out, please know that there are definitely more in this series. 
 In the "Don't do as I do" category... 
 All screenshots and text examples provided in this post were captured on a Windows...(&lt;a href="http://blogs.technet.com/b/lrobins/archive/2011/06/23/quot-admin-free-quot-active-directory-part-2-protected-accounts-and-groups-in-active-directory.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3437147" width="1" height="1"&gt;</content><author><name>Laura A. Robinson</name><uri>http://blogs.technet.com/lrobinsmsft_4000_live.com/ProfileUrlRedirect.ashx</uri></author><category term="virtual" scheme="http://blogs.technet.com/b/lrobins/archive/tags/virtual/" /><category term="windows server 2008" scheme="http://blogs.technet.com/b/lrobins/archive/tags/windows+server+2008/" /><category term="Security" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Security/" /><category term="Windows Media Player" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Windows+Media+Player/" /><category term="R2" scheme="http://blogs.technet.com/b/lrobins/archive/tags/R2/" /><category term="RBAC" scheme="http://blogs.technet.com/b/lrobins/archive/tags/RBAC/" /><category term="DHA" scheme="http://blogs.technet.com/b/lrobins/archive/tags/DHA/" /><category term="Admin-free" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Admin_2D00_free/" /><category term="Active Directory" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Active+Directory/" /><category term="admin free" scheme="http://blogs.technet.com/b/lrobins/archive/tags/admin+free/" /><category term="APT" scheme="http://blogs.technet.com/b/lrobins/archive/tags/APT/" /><category term="compromise" scheme="http://blogs.technet.com/b/lrobins/archive/tags/compromise/" /><category term="AD" scheme="http://blogs.technet.com/b/lrobins/archive/tags/AD/" /><category term="zero admins" scheme="http://blogs.technet.com/b/lrobins/archive/tags/zero+admins/" /></entry><entry><title>"Admin Free" Active Directory and Windows, Part 1- Understanding Privileged Groups in AD</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/archive/2011/06/23/quot-admin-free-quot-active-directory-and-windows-part-1-understanding-privileged-groups-in-ad.aspx" /><id>http://blogs.technet.com/b/lrobins/archive/2011/06/23/quot-admin-free-quot-active-directory-and-windows-part-1-understanding-privileged-groups-in-ad.aspx</id><published>2011-06-23T17:55:00Z</published><updated>2011-06-23T17:55:00Z</updated><content type="html">Admin-Free Active Directory 
 If You Haven't Been Hacked, You May Not Be Looking Closely Enough 
 Clearly, I am not the most conscientious blogger, as can be observed by the lack of any posting regularity here. This is in part due to the fact that for the past few years, the team on which I work has been busy helping compromised customers respond to a specific class of attacks known as Advanced Persistent Threat (APT) attacks. Because there is much debate in the security community about what is...(&lt;a href="http://blogs.technet.com/b/lrobins/archive/2011/06/23/quot-admin-free-quot-active-directory-and-windows-part-1-understanding-privileged-groups-in-ad.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3437123" width="1" height="1"&gt;</content><author><name>Laura A. Robinson</name><uri>http://blogs.technet.com/lrobinsmsft_4000_live.com/ProfileUrlRedirect.ashx</uri></author><category term="Security" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Security/" /><category term="RBAC" scheme="http://blogs.technet.com/b/lrobins/archive/tags/RBAC/" /><category term="DHA" scheme="http://blogs.technet.com/b/lrobins/archive/tags/DHA/" /><category term="Admin-free" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Admin_2D00_free/" /><category term="Active Directory" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Active+Directory/" /><category term="admin free" scheme="http://blogs.technet.com/b/lrobins/archive/tags/admin+free/" /><category term="no admins" scheme="http://blogs.technet.com/b/lrobins/archive/tags/no+admins/" /><category term="APT" scheme="http://blogs.technet.com/b/lrobins/archive/tags/APT/" /><category term="compromise" scheme="http://blogs.technet.com/b/lrobins/archive/tags/compromise/" /><category term="AD" scheme="http://blogs.technet.com/b/lrobins/archive/tags/AD/" /><category term="zero admins" scheme="http://blogs.technet.com/b/lrobins/archive/tags/zero+admins/" /></entry><entry><title>Lost all of your Zune DRM'd songs?</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/archive/2010/04/22/lost-all-of-your-zune-drm-d-songs.aspx" /><id>http://blogs.technet.com/b/lrobins/archive/2010/04/22/lost-all-of-your-zune-drm-d-songs.aspx</id><published>2010-04-23T03:32:00Z</published><updated>2010-04-23T03:32:00Z</updated><content type="html">So, it turns out that if you don't sign into the Zune marketplace for 30 days, all of your DRM'd content expires. I got a new 64 GB Zune HD recently and couldn't figure out why it was loading so slowly. I usually just sync my Zunes when I'm home, because my work laptop (which travels with me) runs Windows Server 2008 R2 and I never thought it was a big deal to just synch with one of my personal machines when I was home. 
 Despite the fact that I subscribe to the marketplace on a quarterly basis...(&lt;a href="http://blogs.technet.com/b/lrobins/archive/2010/04/22/lost-all-of-your-zune-drm-d-songs.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3327757" width="1" height="1"&gt;</content><author><name>lrobins@microsoft.com</name><uri>http://blogs.technet.com/lrobins_4000_microsoft.com/ProfileUrlRedirect.ashx</uri></author><category term="windows server 2008" scheme="http://blogs.technet.com/b/lrobins/archive/tags/windows+server+2008/" /><category term="Zune" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Zune/" /><category term="Windows Media Player" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Windows+Media+Player/" /><category term="R2" scheme="http://blogs.technet.com/b/lrobins/archive/tags/R2/" /><category term="collection" scheme="http://blogs.technet.com/b/lrobins/archive/tags/collection/" /><category term="update" scheme="http://blogs.technet.com/b/lrobins/archive/tags/update/" /><category term="DRM" scheme="http://blogs.technet.com/b/lrobins/archive/tags/DRM/" /></entry><entry><title>Publishing Delta CRLs on IIS 7</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/archive/2008/12/29/publishing-delta-crls-on-iis-7.aspx" /><id>http://blogs.technet.com/b/lrobins/archive/2008/12/29/publishing-delta-crls-on-iis-7.aspx</id><published>2008-12-29T17:07:00Z</published><updated>2008-12-29T17:07:00Z</updated><content type="html">If you have migrated or upgraded the sites on which you host your CA CRLs and delta CRLs to IIS 7, you may have noticed a (rather frustrating when you're experiencing it) new behavior. IIS 7 will, by default, reject requests containing double escape characters (for example, files containing a "+" sign in the name, such as delta CRLs). While this is a valid, standards-based security feature, the end result is that your clients cannot retrieve delta CRLs from an IIS 7-hosted site unless you change...(&lt;a href="http://blogs.technet.com/b/lrobins/archive/2008/12/29/publishing-delta-crls-on-iis-7.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3174370" width="1" height="1"&gt;</content><author><name>lrobins@microsoft.com</name><uri>http://blogs.technet.com/lrobins_4000_microsoft.com/ProfileUrlRedirect.ashx</uri></author><category term="certification authority" scheme="http://blogs.technet.com/b/lrobins/archive/tags/certification+authority/" /><category term="certificate authority" scheme="http://blogs.technet.com/b/lrobins/archive/tags/certificate+authority/" /><category term="CA" scheme="http://blogs.technet.com/b/lrobins/archive/tags/CA/" /><category term="windows server 2008" scheme="http://blogs.technet.com/b/lrobins/archive/tags/windows+server+2008/" /><category term="certificate revocation list" scheme="http://blogs.technet.com/b/lrobins/archive/tags/certificate+revocation+list/" /><category term="CRL" scheme="http://blogs.technet.com/b/lrobins/archive/tags/CRL/" /><category term="IIS 7" scheme="http://blogs.technet.com/b/lrobins/archive/tags/IIS+7/" /><category term="&amp;quot;+&amp;quot;" scheme="http://blogs.technet.com/b/lrobins/archive/tags/_2600_quot_3B002B002600_quot_3B00_/" /><category term="delta CRL" scheme="http://blogs.technet.com/b/lrobins/archive/tags/delta+CRL/" /></entry><entry><title>Virtualized Offline CAs</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/lrobins/archive/2008/10/15/virtualized-offline-cas.aspx" /><id>http://blogs.technet.com/b/lrobins/archive/2008/10/15/virtualized-offline-cas.aspx</id><published>2008-10-16T00:27:00Z</published><updated>2008-10-16T00:27:00Z</updated><content type="html">First, the warnings: 
 1. Sometimes I am a bit of a salmon, meaning that I have a tendency to swim upstream, metaphorically speaking. More specifically, I like to take current thoughts around "best practices" and pick them apart to see if they actually make sense as a best practice. One of my favorite words is "specious". A specious argument is one that seems to make sense on the surface, but when actually evaluated, turns out not to make so much sense, after all. 
 2. Anything I say in this blog...(&lt;a href="http://blogs.technet.com/b/lrobins/archive/2008/10/15/virtualized-offline-cas.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3136983" width="1" height="1"&gt;</content><author><name>lrobins@microsoft.com</name><uri>http://blogs.technet.com/lrobins_4000_microsoft.com/ProfileUrlRedirect.ashx</uri></author><category term="virtualized" scheme="http://blogs.technet.com/b/lrobins/archive/tags/virtualized/" /><category term="vm" scheme="http://blogs.technet.com/b/lrobins/archive/tags/vm/" /><category term="certification authority" scheme="http://blogs.technet.com/b/lrobins/archive/tags/certification+authority/" /><category term="certificate authority" scheme="http://blogs.technet.com/b/lrobins/archive/tags/certificate+authority/" /><category term="offline" scheme="http://blogs.technet.com/b/lrobins/archive/tags/offline/" /><category term="CA" scheme="http://blogs.technet.com/b/lrobins/archive/tags/CA/" /><category term="online" scheme="http://blogs.technet.com/b/lrobins/archive/tags/online/" /><category term="virtual" scheme="http://blogs.technet.com/b/lrobins/archive/tags/virtual/" /><category term="Hyper-V" scheme="http://blogs.technet.com/b/lrobins/archive/tags/Hyper_2D00_V/" /><category term="windows server 2008" scheme="http://blogs.technet.com/b/lrobins/archive/tags/windows+server+2008/" /><category term="virtualize" scheme="http://blogs.technet.com/b/lrobins/archive/tags/virtualize/" /><category term="hsm" scheme="http://blogs.technet.com/b/lrobins/archive/tags/hsm/" /></entry></feed>