Morello's Blog

Information on private clouds, datacenters, Azure, security, and PKI.

August, 2005

  • Windows Server 2003 R2 DFS Replication rocks

    I recently did some work with one of the best features of the upcoming R2 release of Windows Server 2003, DFS Replication.  DFS Replication is the successor to FRS and it has a lot of goodness about it it, primarily the fact that it does delta replication.  In other words, if you have a 1GB file that you change 6K in, we now only replicate that 6K (plus some inconsequential amount of state information) rather than the entire 1GB file like FRS does.  This is great for branch office scenarios or anywhere else you want to mirror a directory across multiple systems.

  • idNexus 3.0 released

    Alacris, one of our key PKI partners, just released version 3 of their excellent idNexus product.  idNexus is a registration authority front end that provides smart card provisioning and lifecycle management capabilites.  It's built on .NET and heavily leverages / integrates with Active Directory to provide great customization and workflow capabilities.  If you've ever done a smart card deployment with our CA technology, you've probably noticed that our smart card management UI is rather, uh, limited.  That's because the smart card enrollment pages were designed mainly as a developer reference to illustrate the programatic capabilities of our CA platform.  Because of this, we don't offer 'in the box' mechanisms to deal with PIN unblocks, customized issuance workflows, reporting, or many of the other things my clients want.  So, I always use idNexus for any client I'm working with where we're doing a large smart card deployment.
  • "Who am I? Why am I here?"

    No, this is not the second coming of much (and unduly) ridiculed Ross Perot running mate James Stockdale.  But the often misunderstood quote seemed like a good title for the first post.  So, to introduce myself, I'm John Morello and I'm a Senior Consultant with Microsoft.  My specialties are public key crypto and general network and Windows security.  I've helped numerous large enterprises and government agencies design and deploy PKIs and technologies that leverage them (think IPSec, smart cards, 802.1x).  I'm part of Microsoft Consulting Service's East Region Practice and I've been at Microsoft for 5 years.  I'm an LSU graduate and I live in Baton Rouge, LA.  My goals with this blog are to provide our customers and partners with best practices, tips, and general thoughts on all things Windows security related, but particularly those things related to our PKI platform.