<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Blog di Feliciano Intini : 1.1-NAP</title><link>http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx</link><description>Tags: 1.1-NAP</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Nuova guida su NAP nella serie delle nuove guide Microsoft Infrastructure Planning &amp; Design (IPD)</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/06/30/nuova-guida-su-nap-nella-serie-delle-nuove-guide-microsoft-infrastructure-planning-design-ipd.aspx</link><pubDate>Mon, 30 Jun 2008 16:06:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3080957</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3080957.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3080957</wfw:commentRss><description>In pieno stile serendipity , leggendo l'ultimo post sul blog di NAP non solo ho appreso di una nuova interessante guida che vi aiuta nelle scelte architetturali da prendere di fronte alla progettazione di una soluzione NAP: Selecting the Right NAP Architecture...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/06/30/nuova-guida-su-nap-nella-serie-delle-nuove-guide-microsoft-infrastructure-planning-design-ipd.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3080957" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/5.2.0-SCOM+2007+_2800_ACS_2900_/default.aspx">5.2.0-SCOM 2007 (ACS)</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.0-Host+Security/default.aspx">2.0-Host Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.5-Windows+Server+2008+Security/default.aspx">2.5-Windows Server 2008 Security</category></item><item><title>Versione definitiva del "Microsoft Forefront Integration Kit for Network Access Protection", portale NAP, podcast su Stirling</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/06/05/versione-definitiva-del-microsoft-forefront-integration-kit-for-network-access-protection-portale-nap-podcast-su-stirling.aspx</link><pubDate>Thu, 05 Jun 2008 13:07:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3066464</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3066464.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3066464</wfw:commentRss><description>Riprendo doverosamente il post di Renato che annuncia il rilascio definitivo del &amp;quot; Microsoft Forefront Integration Kit for Network Access Protection &amp;quot; di cui vi avevo parlato in occasione della relativa versione Beta. Come &amp;#232; buona abitudine...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/06/05/versione-definitiva-del-microsoft-forefront-integration-kit-for-network-access-protection-portale-nap-podcast-su-stirling.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3066464" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.0-Host+Security/default.aspx">2.0-Host Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.3-Forefront+Client+Security/default.aspx">2.3-Forefront Client Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.6-Forefront+Stirling/default.aspx">2.6-Forefront Stirling</category></item><item><title>Definitivamente disponibile il Windows XP Service Pack 3 (SP3), anche in italiano: non poche le novità in area sicurezza</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/05/07/definitivamente-disponibile-il-windows-xp-service-pack-3-sp3-anche-in-italiano-non-poche-le-novit-in-area-sicurezza.aspx</link><pubDate>Wed, 07 May 2008 09:38:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3051512</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>12</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3051512.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3051512</wfw:commentRss><description>&lt;blockquote dir="ltr" style="margin-right: 0px"&gt;   &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Riprendo doverosamente il &lt;a href="http://blogs.technet.com/italy/archive/2008/05/06/windows-xp-service-pack-3-disponibile-per-il-download-anche-in-italiano.aspx" target="_blank"&gt;post di Renato sul blog Technet&lt;/a&gt; che annuncia appunto la disponibilit&amp;#224; definitiva del &lt;strong&gt;Windows XP Service Pack 3&lt;/strong&gt; sia su Windows Update che sul Microsoft Download Center. Dico &amp;quot;definitiva&amp;quot; perch&amp;#233; avrete notato in questi giorni una anomala sospensione della sua disponibilit&amp;#224; (e di quella del &lt;strong&gt;SP1&lt;/strong&gt; di &lt;strong&gt;Windows Vista&lt;/strong&gt;): un problema di compatibilit&amp;#224; dell'ultimo minuto relativa al prodotto Microsoft Dynamics Retail Management System ha richiesto di fermare le rotative per mettere in campo il meccanismo di filtering ed evitare che i clienti dotati di questo prodotto possano inavvertitamente installare questi service pack. Quindi &lt;u&gt;vi raccomando&lt;/u&gt;, questa volta pi&amp;#249; che mai (anche tenuto conto della distanza dal suo precedente service pack e quindi della sua corposit&amp;#224;...), &lt;u&gt;di consultare le informazioni disponibili pre-installazione&lt;/u&gt; (Release Notes, - di solito ignorate...;-)... - , FAQ e note relativa alla gestione di pre-release di IE, tutte opportunamente raccolte da Renato e Giorgio sul &lt;a href="http://blogs.technet.com/italy/archive/2008/05/06/windows-xp-service-pack-3-disponibile-per-il-download-anche-in-italiano.aspx" target="_blank"&gt;blog Technet&lt;/a&gt;).&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Come fatto per &lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/04/15/disponibile-windows-vista-sp1-in-italiano.aspx" target="_blank"&gt;&lt;strong&gt;Windows Vista SP1&lt;/strong&gt;&lt;/a&gt;, approfitto per estrapolarvi le migliorie e le novit&amp;#224; di sicurezza dal &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=68C48DAD-BC34-40BE-8D85-6BB4F56F5110&amp;amp;displaylang=en" target="_blank"&gt;documento definitivo di overview&lt;/a&gt; in modo da averle tutte qui &lt;em&gt;at a glance&lt;/em&gt;: quelle migliorate&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Background Intelligent Transfer Service (BITS) 2.5&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;BITS 2.5 is required by Microsoft System Center Configuration Manager 2007 and Windows Live&amp;#8482; OneCare&amp;#8482;. BITS 2.5 helps improve security. If you use BITS to transfer data, the new features also improve flexibility. Microsoft Knowledge Base article &lt;/font&gt;&lt;a href="http://support.microsoft.com/Default.aspx?kbid=923845"&gt;&lt;font color="#0000ff"&gt;923845&lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt; describes BITS 2.5.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;IPSec Simple Policy Update for Windows Server 2003 and Windows XP&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;This update helps simplify the creation and maintenance of IPSec filters, reducing the number of filters that are required for a server and domain isolation deployment. The Simple Policy Update removes the requirement for explicit network infrastructure permit filters and introduces enhanced fallback to clear behavior. Microsoft Knowledge Base article &lt;/font&gt;&lt;a href="http://support.microsoft.com/Default.aspx?kbid=914841"&gt;&lt;font color="#0000ff"&gt;914841&lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt; describes this previously released update in more detail.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Digital Identity Management Service (DIMS)&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;DIMS make it possible for users who log on to any domain-joined computer to silently access all of their certificates and private keys for applications and services.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Wi-Fi Protected Access 2 (WPA2)&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;This update to Windows XP provides support for WPA2, the latest standards-based wireless security solution derived from the IEEE 802.11i standard. Microsoft Knowledge Base article &lt;/font&gt;&lt;a href="http://support.microsoft.com/Default.aspx?kbid=893357"&gt;&lt;font color="#0000ff"&gt;893357&lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt; describes this update.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;e quelle nuove:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Network Access Protection (NAP)&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;NAP is a policy enforcement platform built into Windows Vista, Windows Server 2008, and Windows XP SP3 with which you can better protect network assets by enforcing compliance with system health requirements. Using NAP, you can create customized health policies to validate computer health before allowing access or communication; automatically update compliant computers to ensure ongoing compliance; and optionally confine noncompliant computers to a restricted network until they become compliant. For more information about NAP, see &lt;/font&gt;&lt;a href="http://www.microsoft.com/technet/network/nap/napfaq.mspx"&gt;&lt;font color="#0000ff"&gt;Network Access Protection: Frequently Asked Questions&lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt;.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;CredSSP Security Service Provider&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;CredSSP is a new Security Service Provider (SSP) that is available in Windows XP SP3 via Security Service Provider Interface (SSPI). CredSSP enables an application to delegate the user&amp;#8217;s credentials from the Client (via Client side SSP) to the target Server (via Server side SSP). Windows XP SP3 involves only the Client side SSP implementation and is currently being used by RDP 6.1 (TS), though it can be used by any third party application willing to use the Client side SSP to interact with applications running Server side implementations of the same on Vista / LH Server. There is a &lt;/font&gt;&lt;a href="http://download.microsoft.com/download/9/5/E/95EF66AF-9026-4BB0-A41D-A4F81802D92C/%5BMS-CSSP%5D.pdf"&gt;&lt;font color="#0000ff"&gt;technical specification&lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt; of this SSP available at the Microsoft Download Center. [...]&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Descriptive Security Options User Interface&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/DefinitivamentedisponibileilWindowsXPSer_A38E/clip_image002_2.jpg"&gt;&lt;font color="#0000ff"&gt;&lt;img style="border-right: 0px; border-top: 0px; margin: 0px 15px 0px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="clip_image002" src="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/DefinitivamentedisponibileilWindowsXPSer_A38E/clip_image002_thumb.jpg" width="203" align="left" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/b&gt;&lt;font color="#0000ff"&gt;The Security Options control panel in Windows XP SP3 now has more descriptive text to explain settings and prevent incorrect settings configuration. Figure 1 shows an example of this new functionality.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/DefinitivamentedisponibileilWindowsXPSer_A38E/clip_image002_2.jpg"&gt;&lt;font color="#0000ff"&gt;&lt;/font&gt;&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a name="_Ref182647421"&gt;&lt;font color="#0000ff"&gt;Figure &lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt;1. Security options explanatory text&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Enhanced security for Administrator and Service policy entries&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;In System Center Essentials for Windows XP SP3, Administrator and Service entries will be present by default on any new instance of policy. Additionally, the user interface for the &lt;i&gt;Impersonate Client After Authentication&lt;/i&gt; user right will not be able to remove these settings.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Microsoft Cryptographic Module&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;Implements and supports the SHA2 hashing algorithms (SHA256, SHA384, and SHA512) in X.509 certificate validation. This has been added to the crypto module rsaenh.dll. XP SP2 crypto modules Rsaenh.dll/Dssenh.dll/Fips.sys had been certified according to FIPS 140-1 specifications. The Federal Information Processing Standard (FIPS) 140-1 standard has been replaced by FIPS 140-2, and these modules have been validated and certified according to this standard. For more information, see the &lt;/font&gt;&lt;a href="https://www.microsoft.com/technet/archive/security/topics/issues/fipsdrsp.mspx?mfr=true"&gt;&lt;font color="#0000ff"&gt;Microsoft Kernel Mode Cryptographic Module&lt;/font&gt;&lt;/a&gt;&lt;font color="#0000ff"&gt;.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;Windows Product Activation&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;As in Windows Server 2003 SP2 and Windows Vista, users can now complete operating system installation without providing a product key during a full, integrated installation of Windows XP SP3. The operating system will prompt the user for a product key later as part of Genuine Advantage. As with previous service packs, no product key is requested or required when installing Windows XP SP3 using the update package available through Microsoft Update. [...]&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Ho in cantiere una nuova edizione del mio &lt;a href="http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx" target="_blank"&gt;Microsoft Security Portal&lt;/a&gt; dove aggiunger&amp;#242; queste nuovi puntatori, &lt;em&gt;stay tuned&lt;/em&gt;!&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/05/07/definitivamente-disponibile-il-windows-xp-service-pack-3-sp3-anche-in-italiano-non-poche-le-novit-in-area-sicurezza.aspx&amp;amp;;title=Definitivamente disponibile il Windows XP Service Pack 3 (SP3), anche in italiano: non poche le novit&amp;agrave; in area sicurezza" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/05/07/definitivamente-disponibile-il-windows-xp-service-pack-3-sp3-anche-in-italiano-non-poche-le-novit-in-area-sicurezza.aspx&amp;amp;title=Definitivamente disponibile il Windows XP Service Pack 3 (SP3), anche in italiano: non poche le novit&amp;agrave; in area sicurezza" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/05/07/definitivamente-disponibile-il-windows-xp-service-pack-3-sp3-anche-in-italiano-non-poche-le-novit-in-area-sicurezza.aspx&amp;amp;title=Definitivamente disponibile il Windows XP Service Pack 3 (SP3), anche in italiano: non poche le novit&amp;agrave; in area sicurezza" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/05/07/definitivamente-disponibile-il-windows-xp-service-pack-3-sp3-anche-in-italiano-non-poche-le-novit-in-area-sicurezza.aspx&amp;amp;title=Definitivamente disponibile il Windows XP Service Pack 3 (SP3), anche in italiano: non poche le novit&amp;agrave; in area sicurezza" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/05/07/definitivamente-disponibile-il-windows-xp-service-pack-3-sp3-anche-in-italiano-non-poche-le-novit-in-area-sicurezza.aspx&amp;amp;t=Definitivamente disponibile il Windows XP Service Pack 3 (SP3), anche in italiano: non poche le novit&amp;agrave; in area sicurezza" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3051512" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.0-Host+Security/default.aspx">2.0-Host Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.2-Windows+Vista+Security/default.aspx">2.2-Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.8-Windows+XP+Security/default.aspx">2.8-Windows XP Security</category></item><item><title>Rilasciata la RC2 Refresh in attesa del Windows XP SP3</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/03/26/rilasciata-la-rc2-refresh-in-attesa-del-windows-xp-sp3.aspx</link><pubDate>Wed, 26 Mar 2008 09:19:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3021255</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3021255.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3021255</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;Non ho mai assistito ad una attesa cos&amp;#236; spasmodica per un Service Pack... (anche se la comprendo benissimo) e quindi ho pensato utile segnalarvi il rilascio pubblico di una nuova build (5508) della RC2 emessa proprio in corrispondenza della data che era stata stimata per il rilascio definitivo del &lt;strong&gt;Windows XP SP3&lt;/strong&gt;:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;a href="http://www.microsoft.com/downloads/info.aspx?na=40&amp;amp;p=2&amp;amp;SrcDisplayLang=en&amp;amp;SrcCategoryId=&amp;amp;SrcFamilyId=114f3599-12af-42b2-aab1-b969a62c68a7&amp;amp;u=http%3a%2f%2fforums.microsoft.com%2fTechNet%2fShowPost.aspx%3fPostID%3d3061999%26SiteID%3d17%26mode%3d1" target="_blank"&gt;Windows XP Service Pack 3 Release Candidate 2 Refresh - Now Available On Windows Update&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;... e anche sul &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=114F3599-12AF-42B2-AAB1-B969A62C68A7&amp;amp;displaylang=en" target="_blank"&gt;Download Center&lt;/a&gt; (naturalmente in inglese, tedesco e giapponese). Oltre a segnalarvi questa emissione, che potr&amp;#224; risultare utile solo a coloro che si occupano di &lt;em&gt;testing&lt;/em&gt;&amp;#160; (su ambienti non di produzione, mi raccomando!), approfitto per indicarvi la nuova versione del documento di &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=68C48DAD-BC34-40BE-8D85-6BB4F56F5110&amp;amp;displaylang=en" target="_blank"&gt;overview delle funzionalit&amp;#224; incluse nel Service Pack 3&lt;/a&gt;, tra le quali vi evidenzio quelle legati agli aspetti di sicurezza: quelle migliorate...&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font size="2"&gt;Background Intelligent Transfer Service (BITS) 2.5 &lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font size="2"&gt;IPsec Simple Policy Update for Windows Server 2003 and Windows XP &lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font size="2"&gt;Digital Identity Management Service (DIMS) &lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font size="2"&gt;Wi-Fi Protected Access 2 (WPA2)&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;...e quelle nuove:&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Network Access Protection (NAP)&lt;/li&gt;    &lt;li&gt;Descriptive Security Options User Interface&lt;/li&gt;    &lt;li&gt;Enhanced security for Administrator and Service policy entries&lt;/li&gt;    &lt;li&gt;Microsoft Kernel Mode Cryptographic Module&lt;/li&gt;    &lt;li&gt;Windows Product Activation&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Comunque siate pazienti... se il rilascio viene rinviato &amp;#232; solo per migliorare ulteriormente la qualit&amp;#224; di questo Service Pack. D'altra parte non &amp;#232; cos&amp;#236; lontano ormai: forse tra un mesetto la versione definitiva (a meno di ulteriori rinvii... ;-), e a seguire altre 3-4 settimane per la versione italiana.&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/03/26/rilasciata-la-rc2-refresh-in-attesa-del-windows-xp-sp3.aspx&amp;amp;;title=Rilasciata la RC2 Refresh in attesa del Windows XP SP3" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/03/26/rilasciata-la-rc2-refresh-in-attesa-del-windows-xp-sp3.aspx&amp;amp;title=Rilasciata la RC2 Refresh in attesa del Windows XP SP3" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/03/26/rilasciata-la-rc2-refresh-in-attesa-del-windows-xp-sp3.aspx&amp;amp;title=Rilasciata la RC2 Refresh in attesa del Windows XP SP3" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/03/26/rilasciata-la-rc2-refresh-in-attesa-del-windows-xp-sp3.aspx&amp;amp;title=Rilasciata la RC2 Refresh in attesa del Windows XP SP3" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/03/26/rilasciata-la-rc2-refresh-in-attesa-del-windows-xp-sp3.aspx&amp;amp;t=Rilasciata la RC2 Refresh in attesa del Windows XP SP3" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3021255" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.0-Host+Security/default.aspx">2.0-Host Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.1.0-Security+Update+Mgmt/default.aspx">2.1.0-Security Update Mgmt</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.8-Windows+XP+Security/default.aspx">2.8-Windows XP Security</category></item><item><title>Beta del "Microsoft Forefront Integration Kit for Network Access Protection"</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/03/14/beta-del-microsoft-forefront-integration-kit-for-network-access-protection.aspx</link><pubDate>Fri, 14 Mar 2008 11:12:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2998116</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/2998116.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=2998116</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;Ecco un nuovo programma beta della serie &amp;quot;&lt;em&gt;Solution Accelerators&lt;/em&gt;&amp;quot; (di cui vi ho detto in questo &lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/03/04/rilasciato-l-external-collaboration-toolkit-for-sharepoint.aspx" target="_blank"&gt;post&lt;/a&gt; sul toolkit per Sharepoint). Questa volta il kit si propone di aiutare i professionisti IT delle aziende che hanno sia la soluzione &lt;a href="http://www.microsoft.com/forefront/clientsecurity/default.mspx" target="_blank"&gt;&lt;strong&gt;Forefront Client Security&lt;/strong&gt;&lt;/a&gt; (ricordo che &lt;strong&gt;FCS&lt;/strong&gt; &amp;#232; la &lt;a href="http://blogs.technet.com/feliciano_intini/archive/2007/05/03/Lancio-di-Forefront-e-System-Center-la-sicurezza-e-nulla-senza-il-controllo.aspx" target="_blank"&gt;soluzione anti-malware di Microsoft&lt;/a&gt; per le realt&amp;#224; aziendali dedicata ai sistemi operativi di base, sia client che server) sia &lt;strong&gt;Windows Server 2008&lt;/strong&gt; (per la parte di &lt;strong&gt;&lt;a href="http://technet.microsoft.com/en-us/network/bb545879.aspx" target="_blank"&gt;Network Access Protection - NAP&lt;/a&gt;&lt;/strong&gt;): in questa situazione i clienti hanno gi&amp;#224; tutto l'occorrente per realizzare una soluzione integrata che permetta di far accedere alla rete aziendale solo i client che risultino conformi alla policy creata ad-hoc sullo stato dell'applicazione anti-malware e di gestire il processo di adeguamento per i client non conformi.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Il kit intende aiutare passo passo nella realizzazione di questa soluzione:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/BetadelMicrosoftForefrontIntegrationKitf_ABAE/image_2.png"&gt;&lt;font face="Calibri" size="3"&gt;&lt;a href="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/BetadelMicrosoftForefrontIntegrationKitf_ABAE/image_2.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; margin: 0px 15px 0px 0px; border-left: 0px; border-bottom: 0px" height="326" alt="image" src="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/BetadelMicrosoftForefrontIntegrationKitf_ABAE/image_thumb.png" width="115" align="left" border="0" /&gt;&lt;/a&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;u&gt;Fase di &lt;strong&gt;configurazione&lt;/strong&gt;&lt;/u&gt;: il componente del kit &amp;quot;&lt;em&gt;System Health Validator (SHV)&lt;/em&gt;&amp;quot; serve per stabilire le &amp;quot;&lt;em&gt;health policies&lt;/em&gt;&amp;quot; che verranno forzate su ogni client dotate di Forefront Client Security. Tipicamente queste sono che FCS sia installato, in esecuzione e con le file di signatures aggiornate.&amp;#160; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;u&gt;Fase di &lt;strong&gt;verifica&lt;/strong&gt;&lt;/u&gt;: il componente del kit &amp;quot;&lt;em&gt;System Health Agent (SHA)&lt;/em&gt;&amp;quot; controlla in tempo reale lo stato di conformit&amp;#224; del client FCS rispetto alle policy aziendali impostate nella fase precedente. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;u&gt;Fase di &lt;strong&gt;adeguamento&lt;/strong&gt;&lt;/u&gt;: Se il &lt;em&gt;System Health Agent&lt;/em&gt; rileva un problema su un computer, a tale client viene inibito l'accesso alla rete per prevenire l'eventuale diffusione di malware verso altri sistemi nella intranet. Sempre il &lt;em&gt;SHA&lt;/em&gt; opera per adeguare il client alle policy e dopo tale processo al client viene ridato il permesso di accedere alla rete. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Credo sia davvero interessante iniziare a vedere NAP in azione e questo kit vi aiuta in un paio d'ore a mettere in campo una soluzione subito operativa!&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Qui il &lt;a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2017&amp;amp;InvitationID=MESQ-9779-TKPW&amp;amp;SiteID=14" target="_blank"&gt;&lt;strong&gt;link&lt;/strong&gt; per partecipare alla beta&lt;/a&gt; e qui il &lt;a href="http://blogs.technet.com/secguide/archive/2008/03/13/new-beta-available-microsoft-forefront-integration-kit-for-network-access-protection.aspx" target="_blank"&gt;post&lt;/a&gt; del blog dei Solution Accelerators di Security &amp;amp; Compliance che ne parla.&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/03/14/beta-del-microsoft-forefront-integration-kit-for-network-access-protection.aspx&amp;amp;;title=Beta del " target="_blank" protection??="Protection??" Access="Access" Network="Network" for="for" Kit="Kit" Integration="Integration" Forefront="Forefront" Microsoft="Microsoft"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/03/14/beta-del-microsoft-forefront-integration-kit-for-network-access-protection.aspx&amp;amp;title=Beta del " target="_blank" protection??="Protection??" Access="Access" Network="Network" for="for" Kit="Kit" Integration="Integration" Forefront="Forefront" Microsoft="Microsoft"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/03/14/beta-del-microsoft-forefront-integration-kit-for-network-access-protection.aspx&amp;amp;title=Beta del " target="_blank" protection??="Protection??" Access="Access" Network="Network" for="for" Kit="Kit" Integration="Integration" Forefront="Forefront" Microsoft="Microsoft"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/03/14/beta-del-microsoft-forefront-integration-kit-for-network-access-protection.aspx&amp;amp;title=Beta del " target="_blank" protection??="Protection??" Access="Access" Network="Network" for="for" Kit="Kit" Integration="Integration" Forefront="Forefront" Microsoft="Microsoft"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/03/14/beta-del-microsoft-forefront-integration-kit-for-network-access-protection.aspx&amp;amp;t=Beta del " target="_blank" protection??="Protection??" Access="Access" Network="Network" for="for" Kit="Kit" Integration="Integration" Forefront="Forefront" Microsoft="Microsoft"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2998116" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.0-Host+Security/default.aspx">2.0-Host Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.3-Forefront+Client+Security/default.aspx">2.3-Forefront Client Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.5-Windows+Server+2008+Security/default.aspx">2.5-Windows Server 2008 Security</category></item><item><title>Riepilogo delle novità su Network Access Protection (NAP)</title><link>http://blogs.technet.com/feliciano_intini/archive/2007/12/29/riepilogo-delle-novit-su-network-access-protection-nap.aspx</link><pubDate>Sat, 29 Dec 2007 11:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2689167</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/2689167.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=2689167</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;E' davvero da tanto che non vi parlo di &lt;strong&gt;&lt;a href="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx" target="_blank"&gt;Network Access Protection (NAP)&lt;/a&gt;&lt;/strong&gt; e questo &amp;#232; male: questa soluzione tecnologica &amp;#232; una delle funzionalit&amp;#224; chiave del prossimo &lt;strong&gt;Windows Server 2008&lt;/strong&gt;, tanto attesa da praticamente tutti gli amministratori di sicurezza con cui ho avuto modo di parlare. Ci sono diverse informazioni che &amp;#232; bene non perdere, e che vi riepilogo qui di seguito.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Parto dalla &lt;a href="http://blogs.technet.com/nap/archive/2007/12/20/microsoft-press-says-nap-the-world.aspx" target="_blank"&gt;segnalazione&lt;/a&gt; di un imminente libro Microsoft Press dedicato al Networking di Windows Server 2008, con ben 6 capitoli dedicati al NAP:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;a href="http://www.microsoft.com/MSPress/books/11160.aspx" target="_blank"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="134" alt="NAP book" src="http://blogs.technet.com/blogfiles/feliciano_intini/WindowsLiveWriter/RiepilogodellenovitsuNetworkAccessProtec_AE57/NAP%20book_3.gif" width="134" border="0" /&gt;&lt;/a&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Se, come me, siete anche nostalgici appassionati dei libri veri, quelli di carta, non potete perdervi la nuovissima serie di titoli in arrivo su Windows Server 2008: per quelli di sicurezza vi aggiorner&amp;#242; man mano nel mio solito &lt;a href="http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx" target="_blank"&gt;Microsoft Security Portal&lt;/a&gt; (cercate le voci con (BK)).&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Lo scorso Teched a Barcellona &amp;#232; stata poi un'occasione per &lt;a href="http://www.microsoft.com/presspass/misc/11-13NAPSideBar.mspx" target="_blank"&gt;segnalare&lt;/a&gt; i grandi progressi in termini di &lt;strong&gt;interoperabilit&amp;#224;&lt;/strong&gt; di questa soluzione tecnologica:&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Un paio di aziende (UNETsystem e Avenda Systems) hanno segnalato l'estensione di NAP a piattaforme non-Microsoft (Mac e Linux). In particolare, un &lt;a href="http://blogs.technet.com/nap/archive/2007/12/03/hot-news-want-to-try-out-the-linux-nap-client.aspx" target="_blank"&gt;post del blog sul NAP&lt;/a&gt; ha poi segnalato anche la possibilit&amp;#224; di poter provare gi&amp;#224; una &amp;quot;Evaluation Beta 1 Release&amp;quot; del NAP Client per Linux di Avenda Systems.&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Celestix Networks ha segnalato l'imminente rilascio di appliance di rete progettati ad-hoc per NAP.&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Il parco installato di client sotto NAP ha raggiunto i 150.000 desktop, di cui ovviamente per ora la parte principale (circa 70.000) &amp;#232; quella direttamente implementata dalla nostra rete interna. Questo primo mega-deployment gi&amp;#224; in produzione &amp;#232; documentato in un &lt;a href="http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000000983" target="_blank"&gt;case study&lt;/a&gt;.&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Non indugiate ad iniziare ad approfondire gli aspetti tecnologici del NAP: trovate altre risorse nel mio solito &lt;a href="http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx" target="_blank"&gt;Microsoft Security Portal&lt;/a&gt;.&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2689167" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category></item><item><title>Virtualizzazione per ottenere maggiore sicurezza sul client? Non per ora direi ...</title><link>http://blogs.technet.com/feliciano_intini/archive/2007/11/23/virtualizzazione-per-ottenere-maggiore-sicurezza-sul-client-non-per-ora-direi.aspx</link><pubDate>Fri, 23 Nov 2007 11:19:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2548213</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/2548213.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=2548213</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;In questi giorni ho realizzato un nuovo approfondimento sugli scenari possibili di rafforzamento per il client aziendale, nella situazione tipica di un computer portatile che viene usato sia al lavoro che a casa: è naturale la preoccupazione di difendere l'azienda da tutte le "schifezze" che il computer può magari contrarre mentre si naviga a casa in piena libertà ... Diversi clienti hanno da sempre provato a valutare la fattibilità e l'efficacia di soluzioni di separazione dei due ambiti casa/ufficio, come il dual-boot di due sistemi operativi paralleli, e ora, con la diffusione delle soluzioni di virtualizzazione, si stanno riproponendo questo dubbio: &lt;u&gt;si otterrebbe maggiore sicurezza dal separare i due ambiti con le nuove tecnologie di virtualizzazione?&lt;/u&gt; Per dare risposta a questa domanda ho fatto delle riflessioni che ho pensato possano interessarvi e quindi vi condivido. Intanto ho trovato un comune denominatore in queste soluzioni: sia il dual-boot su dischi/partizioni interne, sia il dual-boot su dischi veloci esterni, sia l'uso di immagini virtuali, sono tutte soluzioni di "duplicazione e separazione", duplicano il sistema operativo per separarne l'uso in due scenari diversi. Vediamo vantaggi e svantaggi:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Vantaggio: &lt;/font&gt; &lt;ul&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;si propongono di ottenere una &lt;u&gt;separazione&lt;/u&gt; netta di sistemi operativi, applicazioni, impostazioni computer, impostazioni utente e/o dati.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Svantaggi:&lt;/font&gt; &lt;ul&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Introducono una notevole complessità e un appesantimento delle procedure di gestione dei sistemi: di fatto abbiamo 2 sistemi operativi da gestire (se già le aziende fanno fatica a gestirne uno, figuriamoci due !)&lt;/font&gt;&lt;/li&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Alcune soluzioni non garantiscono l’esatta duplicazione di funzionalità: è purtroppo un dato di fatto che un sistema operativo "guest" (quello virtuale) non ha lo stesso accesso a periferiche e interfacce hardware.&lt;/font&gt;&lt;/li&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;&lt;u&gt;Sono anacronistiche rispetto all’evoluzione delle esigenze degli utenti&lt;/u&gt;: a questo proposito ho coniato una frase in stile Microsoft per descrivere questa tendenza, &lt;strong&gt;&lt;em&gt;"Unified &amp;amp; Secure Digital Experience"&lt;/em&gt;&lt;/strong&gt;.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Già, rifletteteci anche voi sull'ultimo punto, sulla base della vostra esperienza personale: &lt;em&gt;&lt;u&gt;gli utenti mal si adattano alla separazione stagna di ambiti di fruizione di contenuti digitali: oggi si lavora anche mentre si è a casa, e si fruisce di servizi online (non necessariamente connessi al lavoro, vedi fenomeno Web 2.0) anche mentre si è in ufficio&lt;/u&gt;&lt;/em&gt;. Dal mio punto di vista, già da sola questa considerazione basterebbe per abbandonare questa ipotesi d'uso di ambienti separati. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Ma poi mi sono anche chiesto: ma questa "separazione" che si vuole ottenere con queste soluzioni è davvero un vero e proprio "isolamento" dal punto di vista sicurezza? Io credo di no e provo a spiegarvelo: per farlo ho bisogno di condividere un concetto molto illuminante che ho appreso dal mitico &lt;a href="http://blogs.technet.com/markrussinovich"&gt;&lt;strong&gt;Mark Russinovich&lt;/strong&gt;&lt;/a&gt; nel nostro recente incontro a Redmond, il concetto di &lt;strong&gt;Security Boundary&lt;/strong&gt;, che si spiega nei tre punti seguenti:&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Esiste una Security Policy&lt;/font&gt;&lt;/li&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Si ha modo di determinare, monitorare e forzare il rispetto di questa Security Policy&lt;/font&gt;&lt;/li&gt; &lt;ul&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Esempio: “C’è giustizia se ci sono le leggi ma non si riesce a farle rispettare ?”&lt;/font&gt;&lt;/li&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Quindi: “C’è sicurezza se ci sono le Security Policy ma non si riesce a forzarle?”&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Le violazioni della Security Policy sono gestite come problemi di sicurezza e quindi vanno trattate come tali (individuare le vulnerabilità e correggerle).&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Ecco il punto: &lt;u&gt;le soluzioni tecnologiche accennate (dual-boot, virtualizzazione...) non sono attualmente in grado di realizzare un vero e proprio “Security Boundary”&lt;/u&gt;: t&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;ipicamente l'attuale punto debole è che non si riesce a forzare il rispetto delle Security Policy. Un e&lt;/font&gt;&lt;font face="Calibri" size="3"&gt;sempio: non avere meccanismi nativi per forzare quando è possibile usare una Virtual Machine, e quando è vietato, in base alla rete a cui si è connessi. &lt;/font&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;E' per questo che per ora l'approccio migliore possibile per il rafforzamento del client aziendale è il ricorso alle&lt;/font&gt;&lt;font face="Calibri" size="3"&gt; soluzioni di &lt;em&gt;Policy Enforcement&lt;/em&gt; multi-livello (&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2007/01/10/piano-dell-opera.aspx"&gt;&lt;strong&gt;Defense In-Depth&lt;/strong&gt;&lt;/a&gt;), di cui ne sono un esempio tra tutte il &lt;a href="http://www.microsoft.com/nap"&gt;&lt;strong&gt;NAP&lt;/strong&gt;&lt;/a&gt; per la rete ed &lt;a href="http://www.microsoft.com/rms"&gt;&lt;strong&gt;RMS&lt;/strong&gt;&lt;/a&gt; per i dati.&lt;/font&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Magari nel futuro le soluzioni di virtualizzazione si evolveranno anche per rappresentare una soluzione di sicurezza, per per ora sono orientate ad altri obiettivi (consolidamento risorse di calcolo, gestione delle compatibilità applicative).&lt;/font&gt; &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Condividete queste considerazioni ?&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2548213" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.0.0.0-Microsoft+Strategy+_2600_amp_3B00_+Initiatives/default.aspx">0.0.0.0-Microsoft Strategy &amp;amp; Initiatives</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/0.1.0.0-Security+_2600_amp_3B00_+Privacy/default.aspx">0.1.0.0-Security &amp;amp; Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0-Application+Security/default.aspx">3.0-Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0-Data+Security/default.aspx">4.0-Data Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.3-Rights+Management+Services/default.aspx">4.3-Rights Management Services</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.0-Host+Security/default.aspx">2.0-Host Security</category></item><item><title>Secure Socket Tunneling Protocol (SSTP): il nuovo protocollo VPN di Microsoft</title><link>http://blogs.technet.com/feliciano_intini/archive/2007/07/03/Secure-Socket-Tunneling-Protocol-SSTP-il-nuovo-protocollo-VPN-di-Microsoft.aspx</link><pubDate>Tue, 03 Jul 2007 16:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1430357</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/1430357.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=1430357</wfw:commentRss><description>Ho appena avuto modo di ripassare le tecnologie VPN offerte da Microsoft, e ho notato una succulente novità che non deve assolutamente perdere chi si occupa di sicurezza: mi riferisco al nuovo protocollo di tunneling che Microsoft introdurrà in Windows Server 2008, il Secure Socket Tunneling Protocol (SSTP), anche accennato dall'amico Renato nell'annuncio sulla disponibilità della CTP di giugno.
...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2007/07/03/Secure-Socket-Tunneling-Protocol-SSTP-il-nuovo-protocollo-VPN-di-Microsoft.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1430357" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.3-VPN+Technologies/default.aspx">1.3-VPN Technologies</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.2-Windows+Vista+Security/default.aspx">2.2-Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/2.5-Windows+Server+2008+Security/default.aspx">2.5-Windows Server 2008 Security</category></item><item><title>Oggi vorrei tanto essere a San Francisco ...</title><link>http://blogs.technet.com/feliciano_intini/archive/2007/02/05/Oggi-vorrei-tanto-essere-a-San-Francisco-_2E002E002E00_.aspx</link><pubDate>Mon, 05 Feb 2007 17:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:625894</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/625894.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=625894</wfw:commentRss><description>E perché mai, direte voi ? Ahiahiahi... La città è bellissima a prescindere da qualsiasi evento, ma non si  può ignorare che oggi a San Francisco si apre l'RSA Conference!...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2007/02/05/Oggi-vorrei-tanto-essere-a-San-Francisco-_2E002E002E00_.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=625894" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0-Network+Security/default.aspx">1.0-Network Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.1-NAP/default.aspx">1.1-NAP</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.2-Remote+Access+Quarantine/default.aspx">1.2-Remote Access Quarantine</category></item></channel></rss>