250 Hello

Random Musings on Exchange and Virtualization

September, 2012

  • Exchange 2013 Video Sessions From TechEd Australia 2012

    If you are looking to see the first public presentations on Exchange 2013, then look no further!  Channel 9 has recordings from last week’s TechEd Australia.

    You can find these great sessions on Exchange 2013:

     

    Exchange Server 2013 High Availability and Site Resilience - EXL315

    Exchange 2013 High Availability And Site Resilience

     

     

    Exchange Server 2013 Architecture Deep Dive – EXL311

     

    Exchange 2013 Architecture Deep Dive

     

    Exchange Server 2013 Deployment and Coexistence - EXL332

    Exchange 2013 Deployment And Coexistence

     

     

     

    The New Exchange - Archiving and Compliance - EXL333

    Exchange 2013 Archiving And Compliance

     

     

    Still reading this?  What’s wrong with you? Go get your geek on!!!!

     

    Smile 

     

    Cheers,

    Rhoderick

    Technorati Tags: ,
  • Important Upcoming Certificate Changes

    Please be aware that there is a pending change for the minimum key length for certificates with RSA keys.  The private keys used in these certificates can be derived and could allow an attacker to duplicate the certificates and use them fraudulently to spoof content, perform phishing attacks, or perform man-in-the-middle attacks.

     

     

    The update is available on the Download Center as well as the Microsoft Update Catalog for all supported releases of Microsoft Windows. In addition, Microsoft is planning to release this update through Microsoft Update in October, 2012 after customers have a chance to assess the impact of this update and take necessary actions to use certificates with RSA keys greater than or equal to 1024 bits in length in their enterprise.

    Recommendation:  Microsoft recommends that customers download the update and assess the impact of blocking certificates with RSA keys less than 1024 bits in length before applying the update to their enterprise. Please see the Suggested Actions section of in the advisory for more information.

     

    This update will impact HTTPS web services which have a RSA key length of less than 1024 bits.  Examples will include Outlook, Exchange web services and web browsers.  This article discusses the impact of KB2661254 to Internet Explorer. 

     

     

    Known issues with this security update,  after the update is applied:

    • A restart is required.
    • A certification authority (CA) cannot issue RSA certificates that have a key length of less than 1024 bits.
    • CA service (certsvc) cannot start when the CA is using an RSA certificate that has a key length of less than 1024 bits.
    • Internet Explorer will not allow access to a website that is secured by using an RSA certificate that has a key length of less than 1024 bits.
    • Outlook 2010 cannot be used to encrypt email if it is using an RSA certificate that has a key length of less than 1024 bits. However, email that has already been encrypted by using an RSA certificate with key length that is less than 1024 bits can be decrypted after the update is installed.
    • Outlook 2010 cannot be used to digitally sign email if it is using an RSA certificate that has a key length that is less than 1024 bits.
    • When email is received in Outlook 2010 that has a digital signature or is encrypted by using an RSA certificate that has a key length of less than 1024 bits, the user receives an error that states that the certificate is untrusted. The user can still view the encrypted or signed email.
    • Outlook 2010 cannot connect to a Microsoft Exchange server that is using an RSA certificate that has a key length of less than 1024 bits for SSL/TLS. The following error is displayed: "Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the site's security certificate. The security certificate is not valid. The site should not be trusted."
    • Security warnings of "Unknown Publisher" are reported, but installation can continue in the following cases:
      • Authenticode signatures that were time stamped on January 1, 2010 or on a later date, and that are signed with a certificate by using an RSA certificate that has a key length of less than 1024 bits are encountered.
      • Signed installers signed by using an RSA certificate that has a key length of less than 1024 bits.
      • ActiveX controls signed by using an RSA certificate that has a key length of less than 1024 bits. Active X controls already installed before you install this update will not be affected.

     

     

    There are four main methods for discovering if RSA certificates with keys less than 1024 bits are in use:

    • Check certificates and certification paths manually
    • Use CAPI2 logging
    • Check certificate templates
    • Enable logging on computers that have the update installed

     

     

    To quickly check a single certificate the Public Key attribute can be inspected using the Certificates MMC snap-in as shown below.  If you need steps to open the Certificates MMC please read this.

    This certificate is OK as it has a 2048 bit key. 

    Checking Certificate RSA Key Length Less Than 1024 Bits

     

    For more details on the additional methods to check and information on resolutions please read the full Security Advisory for this update

     

    Cheers,

    Rhoderick.

  • Re-Release Of Exchange 2010 SCOM Management Pack

    Since the System Centre Operations Manager (SCOM) Management Pack (MP) for Exchange 2010 has been re-released to the Microsoft download center, I thought that it would be worth bubbling this up.  The previous post can be found here on the blog.

    Exchange 2010 SCOM Managemet Pack Download August 2012

    This is build 14.03.0038.004 of the MP, and is dated August 31st 2012. 

     

    System Center Operations ManagerThe Microsoft Exchange Server 2010 Management Pack includes a complete health model, extensive protocol synthetic transaction coverage, and a full complement of diagnostics-based alerts and service-oriented reporting, including mail flow statistics. Alerts are classified by impact and recovery action, and are now processed by a new component called the Correlation Engine. The Correlation Engine suppresses duplicate alerts whenever possible to help front-line monitoring technicians monitor Exchange more efficiently. Most diagnostic information used in the Exchange 2010 Management Pack, including events and performance counters, is specifically engineered for monitoring. Very little tuning is required to monitor your Exchange organization. The Exchange 2010 Management Pack will scale with your environment.

    Cheers,

    Rhoderick

    Technorati Tags: ,,
  • System Center 2012 SP1 Beta Available

     

    The beta release for System Center 2012 SP1 is now available for you to download and test in your lab environments.  This is an interesting release as it is adding support for Windows Server 2012.  In the case of SCVMM 2012 SP1, it means that it can only be installed on the RTM version of Windows Server 2012. 

     

    At least I know what I’ll be doing this weekend now Smile 

     

    System Center 2012 SP1 Beta Download

     

     

    The Virtual Machine Manager server for the Beta release of System Center 2012 SP1 will only run on Windows Server 2012. For full prerequisites, see the document “Virtual Machine Manager in System Center 2012 Service Pack 1” at the following link: http://go.microsoft.com/fwlink/?LinkId=254803..  (Note that at the time of posting the documents were still CTP, and not beta releases)


    Prerequisites for Configuration Manager can be found at: http://go.microsoft.com/fwlink/?LinkId=252950.


    All other components now support Windows Server 2012 and SQL Server 2012 in addition to the operating systems that were supported in System Center 2012. For details on what was supported in System Center 2012, see http://go.microsoft.com/fwlink/?LinkId=255218.

     

    Cheers,

    Rhoderick

     

    Technorati Tags: ,
  • Upcoming Changes to Forefront Products

    If you leverage products from the Forefront family, then you will want to read about changes announced today on the Server & Cloud blog.

     

    TMG Discontinued

     

    Today, as a result of our effort to better align security and protection solutions with the workloads and applications they protect, Microsoft is announcing changes to the roadmaps of some of the security solutions made available under the Forefront brand.

    1. As part of this effort, the next release of Forefront Online Protection for Exchange, which has long been part of the Office 365 solution, will be named Exchange Online Protection. 
    2. In response to customer demand, we are adding basic antimalware protection to Exchange Server 2013.  This protection can be easily turned off, replaced, or paired with other services (like Exchange Online Protection) to provide a layered defence. 
    3. We are discontinuing any further releases of the following Forefront-branded solutions:
      • Forefront Protection 2010 for Exchange Server (FPE)
      • Forefront Protection 2010 for SharePoint (FPSP)
      • Forefront Security for Office Communications Server (FSOCS)
      • Forefront Threat Management Gateway 2010 (TMG)
      • Forefront Threat Management Gateway Web Protection Services (TMG WPS)

    For collaboration protection, SharePoint and Lync Servers will continue to offer the built-in security capabilities that many customers use to protect shared documents.  For remote access, DirectAccess and Routing and Remote Access Server (RRAS) VPN in Windows Server 2012 provide secure remote access for Windows and cross-platform clients, as well as cross-premise access through site to site VPN. Forefront Unified Access Gateway (UAG) 2010 also continues to provide secure application publishing and cross-platform SSL VPN remote access for a range of mobile devices.
    We will continue to provide maintenance and support for the following Forefront solutions through the standard Microsoft support lifecycle (see chart below), but the discontinued Forefront offerings will no longer be available for purchase as of Dec. 1, 2012.

     

    Cheers,

    Rhoderick

     

    Technorati Tags: ,
  • Return of The MEC

    WP_000315

    This week I am fortunate to be at MEC along with thousands of other people who are passionate about Exchange, and are looking to get the latest information on Exchange Server 2013.  

     

     

     

     

     

    WaterfallThe event is at the Gaylord Palm Hotel in Orlando, and I have to say it is a spiffy place with coy carp, alligators and a really big salt water tank with lots of really nice big fish.  Gators

       

     

     

     

     

     

    I’m Looking forward to the advertised smorgasbord of fun treats!

    • Get exclusive Exchange 15 content directly from the engineering team
    • Get hands-on experience with Exchange 15
    • Enjoy unparalleled access to Exchange team members, Masters and MVPs
    • Preview amazing new products from select vendors
    • Build personal relationships throughout the Exchange community

    Cheers,

    Rhoderick