Archive

Archive for April, 2013

Get Started with #SharePoint Server 2013 Quickly on #Windows #Azure

Another good blog posts by Bill Baer (Microsoft) that shows how easy it is to try out SharePoint Server 2013 on Azure!

In order to remain competitive in today’s business climate you need to be able to respond to change and challenges quickly.  Sometimes that means adjusting your SharePoint infrastructure on a moment’s notice to maintain a competitive advantage.

Infrastructure as a Service solves these challenges through a ready-to-use, pay as you go solution which means you can deploy in hours as opposed to days, whether you’re looking to deploy a simple SharePoint-based Internet site or to quickly provision a development environment.

SharePoint 2013 on Windows Azure Virtual Machines enables you to rapidly deploy and host your business websites on a secure, scalable cloud infrastructure.

What are Windows Azure Virtual Machines?

Windows Azure Virtual Machines enable organizations to deploy custom Windows Server images to Windows Azure. Virtual Machines provide developers complete control of the application environment and allow easy migration of existing applications to the cloud. To learn more about Windows Azure Virtual Machines see also http://www.windowsazure.com/en-us/home/scenarios/virtual-machines/.

How can I benefit from Azure IaaS?

Business Mobility

Windows Azure Virtual Machines allow you to easily move your applications and infrastructure back and forth from on-premises to the cloud without requiring any changes to the existing code – if you’ve virtualized SharePoint 2013 in on-premises you can quickly and easily move your virtual hard drives between your datacenter and the cloud.

License Mobility

With License Mobility through Software Assurance, you can deploy certain server application licenses purchased under your Volume Licensing agreement in an Authorized Mobility Partner’s datacenter. To learn more about License Mobility see also http://www.microsoft.com/licensing/software-assurance/license-mobility.aspx . With License Mobility through Software Assurance, you can deploy certain server application licenses purchased under your Volume Licensing agreement in an Authorized Mobility Partner’s datacenter. Read more…

Vulnerability in Remote Desktop Client – #RDS

Microsoft Security Bulletin MS13-029 – Critical

Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2828223)

Published: Tuesday, April 09, 2013 | Updated: Wednesday, April 10, 2013

Version: 1.1

General Information

Executive Summary

This security update resolves a privately reported vulnerability in Windows Remote Desktop Client. The vulnerability could allow remote code execution if a user views a specially crafted webpage. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Critical for Remote Desktop Connection 6.1 Client, Remote Desktop Connection 7.0 Client, and Remote Desktop Connection 7.1 Client where affected on Windows XP, Windows Vista, and Windows 7. It is rated Moderate for Remote Desktop Connection 6.1 Client, Remote Desktop Connection 7.0 Client, and Remote Desktop 7.1 Client where affected on Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2. For more information, see the subsection, Affected and Non-Affected Software, in this section.

The security update addresses the vulnerability by modifying the way that Remote Desktop Client handles objects in memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.

Recommendation. Most customers have automatic updating enabled…

Continue reading here!

//Richard

#Windows #Azure Virtual Machines and Virtual Network now are generally available

As I use to write; THIS IS INTERESTING! I think that Microsoft will take some market share for sure with their cloud service offerings!

Windows Azure Virtual Machines and Virtual Network now are generally available. We have new prices for Virtual Machines, Virtual Network, and Cloud Services.

Today is a major milestone for Windows Azure and all of our customers and partners. We are excited to announce that Windows Azure Virtual Machines and Windows Azure Virtual Network now are generally available. We also want to update you on new prices for Virtual Machines, Virtual Network, and Cloud Services.

Virtual Machines and Virtual Network help you meet changing business needs by providing on-demand, scalable infrastructure. These infrastructure services enable you to extend your data centers and workloads into the cloud while using your existing skills and investments. With these services, you can:

  • Provision Microsoft SharePoint farms in minutes without up-front hardware investments. Integrate full-trust code to run rich apps and provide Internet-facing collaboration sites.
  • Prototype your newest app or extend data marts into the cloud using Virtual Machines as a robust infrastructure for Microsoft SQL Server software. Scale on demand and connect to your on-premises infrastructure using Virtual Network.
  • Embrace rapid innovation using the cloud for development and test scenarios. You can spin up any test lab or sandbox quickly, and be agile in your learning, development, and prototyping.

Let’s take a closer look at the news that we are announcing today with general availability.

New high-memory instances for Virtual Machines

When your apps need more memory, new 28-gigabyte (GB) and 56-GB instances deliver.

Updated SLA

When you deploy multiple instances of Virtual Machines, Microsoft provides a financially backed 99.95 percent monthly service level agreement (SLA).

Customer support

Our customer support team is ready and available to help you troubleshoot 24 hours a day, seven days a week. We have several support plans tailored to meet your needs—from basic developer support to Premier Support. When you work with Microsoft, you have a single vendor to call for cloud and on-premises needs. 

Validated workloads

The best of Microsoft server products are validated to run on Virtual Machines, including Microsoft Dynamics NAV 2013, SharePoint Server 2013, BizTalk Server 2013, and more. We also offer prebuilt virtual machine images—such as BizTalk Server and SQL Server—through the Windows Azure Virtual Machines Image Gallery with hourly pricing. Prebuilt Linux images—such as CentOS, Ubuntu, and Suse Linux Enterprise Server (SLES)—are available in the Image Gallery from commercial distributors. In addition, a wide variety of the most popular open source applications are available as prebuilt images in VM Depot, a self-service community portal. Read more…

#Citrix #NetScaler 10 on Amazon Web Services – #AWS

Yes, it’s here! 🙂

Mainstream IT is fast embracing the enterprise cloud transformation and selecting the right cloud networking technologies has thus quickly emerged to be an imperative. As mainstream IT adopts IaaS (Internet as a service) cloud services, they will require a combination of the elasticity and flexibility, expected of cloud offerings and the powerful advanced networking services used within emerging enterprise cloud datacenters. 

Citrix® NetScaler® 10 delivers elasticity, simplicity and expandability of the cloud to enterprise cloud datacenters and already powers the largest and most successful public clouds in the world. With NetScaler 10, Citrix delivers a comprehensive cloud network platform that mainstream enterprises can leverage to fully embrace a cloud-first network design. 

Citrix and Amazon Web Services (AWS) have come together to deliver industry-leading application delivery controller technology. NetScaler on AWS delivers the same services used to ensure the availability, scalability and security of the largest public and private clouds for AWS environments. Whether the need is to optimize, secure or control delivery of enterprise and cloud services, NetScaler for AWS can help accomplish these initiatives economically, and according to business demands. 

The full suite of NetScaler capabilities such as availability, acceleration, offload and security functionality is available in AWS, enabling users to leverage tried-and-true NetScaler functionality such as rewrites and redirects, content caching, Citrix Access Gateway™ Enterprise SSL VPN, and application firewall within their AWS deployments. Additional benefits include usage of Citrix CloudBridge™ and Citrix Branch Repeater™ as a joint solution. 

Citrix NetScaler transforms the cloud into an extension of the datacenter by eliminating the barriers to enterprise-class cloud deployments. Together, NetScaler and AWS delivers a broad set of capabilities for the Enterprise IT: 

Hybrid Cloud Environment 

Hybrid clouds that span enterprise datacenters and extend into AWS can benefit from the same cloud networking platform, significantly easing…

Continue reading here!

//Richard

Demystifying Citrix Excalibur Architecture – via @kbaggerman

A great blog post by Kees Baggerman! 🙂

For all XenApp admins and consultants out there Project Avalon will bring a big change as we are used to having XenApp servers running on the (what seemed to be) everlasting Citrix Independent Management Architecture and we’re heading to Citrix FlexCast Management Architecture (already included in XenDesktop at this moment) and will be included in the Citrix Excalibur Architecture.

IMA

When looking up IMA in the eDocs you’ll find:

Independent Management Architecture (IMA) is the underlying architecture used in XenApp for configuring, monitoring, and operating all XenApp functions. The IMA data store stores all XenApp configurations.

Basically IMA exists to manage the XenApp or Presentation Server farms by enabling the communications between servers. As stated it transfers information about all XenApp functions like licenses, policies, sessions and server loads. All management tooling within these versions of Citrix’s PS/XA rely on this service for information.

According to Communication ports used by Citrix Technologies IMA uses the following ports:

Ports Source Prot. Comment
2512 Common Citrix Communication Ports TCP Independent Management Architecture (IMA)
2513 Access Gateway 5.0 Controller administration TCP IMA-based Communication

As we can see IMA uses 2512 (by default) to communicate with other servers and the Access Gateway Controller uses 2513 (by default) for IMA-based communication. The port IMA uses can be changed or queried via the commandline tool IMAPORT.

Brian Madden did a blogpost way back in 2007 but it’s definition of IMA is still current:

Independent Management Architecture is:

  • A data store, which is a database for storing MetaFrame XP server configuration information, such as published applications, total licenses, load balancing configuration, MetaFrame XP security rights, and printer configuration.
  • A protocol for transferring the ever-changing background information between MetaFrame XP servers, including server load, current users and connections, and licenses in use
FMA

With the introduction of XenDesktop we got a new architecture called Flexcast Management Architecture. This new architecture has got an agent-based setup where we can install the operating system including the basic applications that need to be installed and after that we can install an agent. This agent registers itself to a controller and is offered through StoreFront to the end user.

This will be delivered by two different types of agents, one to support Windows Server OS’s and one for Windows Desktop OS’s.

Andrew Wood did an article on Excalibur and used this diagram to explain the architecture:

Citrix FlexCast Management ArchitectureCitrix FlexCast Management Architecture

  • Receiver provides users with self-service access to published resources.
  • StoreFront authenticates users to site(s) hosting resources and manages stores of desktops and applications that users access – Web Interface as a platform is essentially resting, but it will cease to be.
  • Studio is a single management console that enables you to configure and manage your deployment, a dramatic reduction over the 23 consoles you could well have today. Studio provides various wizards to guide you through the process of setting up an environment, creating workloads to host applications and desktops, and assigning applications and desktops to users.
  • Delivery Controller distributes applications and desktops, manages user access, and optimizes…

Continue reading here!

//Richard

Report: Android malware doubled in 2012, infecting 33M devices

Malware attacks on devices running Google’s (NASDAQ:GOOG) open-source Android mobile operating system more than doubled in 2012, security solutions firm NQ Mobile reports.

NQ Mobile - Malware by Year
NQ Mobile saw a year-over-year increase of malware of 163 percent.

NQ Mobile discovered 65,227 new pieces of mobile malware in 2012 compared to 24,794 in 2011, a year-over-year increase of 163 percent. Among all new malware discovered last year, 94.8 percent of threats were designed to attack Android, compared to just 4 percent targeting rival open-source platform Symbian. In all, more than 32.8 million Android devices were infected in 2012, up from 10.8 million in 2011, representing an increase of more than 200 percent.

Chinese devices accounted for 25.5 percent of infected Android devices, followed by India (19.4 percent), Russia (17.9 percent), the United States (9.8 percent) and Saudi Arabia (9.6 percent). Fifty-three percent of U.S. Android owners have installed a mobile security app on their device, NQ Mobile adds.

Sixty-five percent of mobile malware discovered in 2012 falls into the category of Potentially Unwanted Programs–e.g., root exploits, spyware, pervasive adware and Trojans (surveillance hacks). Twenty-eight percent was designed to collect and profit from a user’s personal data, and 7 percent was built to prevent the user’s device from functioning properly.

The primary methods for delivering malware in 2012 included App Repackaging (adding lines of malicious code into a legitimate app and reloading it onto a third-party marketplace), Smishing (asking consumers to click on a fraudulent link, triggering a malicious app download or directing their browser to a rogue website) and Malicious URLs (redirecting the browser from genuine websites to clone sites intended to collect personal data).

Critics maintain Google has failed to sufficiently police its Google Play digital storefront, making it easy for attackers to distribute malware via Android applications. Google has made strides to reduce Android threats, however: In early 2012, it unveiled Bouncer, which scans Google Play for malicious apps, and its Android 4.2 OS update, a.k.a. Jelly Bean, bakes in application verification tools.

The NQ Mobile report…

Continue reading here!

//Richard

#Ericsson to acquire #Microsoft #Mediaroom

April 9, 2013 1 comment

This is interesting!!! 🙂

  • Underlines Ericsson’s commitment to being partner of choice for Video distribution across multiple networks and devices
  • Places Ericsson in lead for TV Anywhere consumption
  • Ericsson becomes leading player for innovative video distribution with combined market share of more than 25%

Ericsson (NASDAQ:ERIC) has reached an agreement with Microsoft (NASDAQ:MSFT) to acquire its TV solution Mediaroom business. This will make Ericsson the leading provider of IPTV and multi-screen solutions with a market share of over 25%. Closing expected during the second half of 2013.   Mediaroom is situated in Mountain View, California and employs more than 400 people worldwide.  

Per Borgklint, Senior Vice President and Head of Business Unit Support Solutions at Ericsson said: “Ericsson’s vision of the Networked Society foresees 50 billion devices to be connected via broadband, mobility and cloud. Future video distribution will have a similar impact on consumer behavior and consumption as mobile voice has had. This acquisition contributes to a leading position for Ericsson with more than 40 customers, serving over 11 million subscriber households. In addition, Ericsson will be powered with senior competence and some of the most talented people within the field of IPTV distribution.”

The global IPTV market is estimated to reach 76 million subscribers in 2013 with revenues of 32 BUSD, growing to 105 million subscribers and 45 BUSD in 2015.

“Mediaroom is the leading platform for video distribution deployed with the world’s largest IPTV operators. This strategic acquisition positions Ericsson as an industry leader thanks to the skills and experiences of the talented people of Mediaroom combined with Ericsson’s end to end service capabilities” Borgklint concluded.

The total media solution portfolio of Ericsson in the TV and video space combined with a further increased focus on consumer needs will be the foundation for providing services to end users. The importance of video distribution capabilities for the customers and their consumers will be increasing as more and more LTE networks are deployed and filled with smartphone users.

“We are proud of the number one IPTV market position that we have achieved with Mediaroom. Ericsson’s complementary portfolio of TV and networking services will help drive the future growth and development of Mediaroom,” said Tom Gibbons, Corporate Vice President of Microsoft Corporation. “Ericsson is positioned to be a valuable strategic partner for operators and TV service providers around the world as the IPTV market evolves.”

Microsoft Mediaroom is the TV technology behind many of the world’s leading television service providers like AT&T U-verse®, Entertain of Deutsche Telekom, Telefonica, TELUS Optik TV(TM) and Swisscom. Mediaroom-powered TV services are offered on more than 22 million set top boxes deployed throughout the Americas, EMEA and APAC.

Read more here:

Press release – Ericsson to acquire Microsoft Mediaroom

Q&A: Why Ericsson snagged Microsoft’s Mediaroom

//Richard

 

Heads Up – issues with Access Gateway Plug-in for Mac OS X Version 2.1.4 – #Citrix, #NetScaler

Well, I guess that you’ve already read all the good things about the new capabilities of the newer Access Gateway plug-in, Receiver and Access Gateway Enterprise that together with StoreFront will add additional features and functions that haven’t existed before. It’s now built to work together with the Receiver on the Windows and Mac OS X platforms and promises a lot by various blog posts from Citrix and others (incl. myself).

Here is an example of what it can (should) do: What’s new with Access Gateway MAC Plug-in release 2.1.4

But is the Access Gateway Plug-in that great? Well, before you plan to implement version 2.1.4 on OS X and especially if you want to leverage the SSL VPN functionality and host checks (EPA) then read the Important notes and Known issues for this release:

Important Notes About This Release:

  1. The Access Gateway Plug-in for Mac OS X Version 2.1.4 supports Citrix Receiver Version 11.7
  2. Import the secure certificate for Access Gateway into the Keychain on the Mac OS X computer.
  3. The Access Gateway Plug-in for Mac OS X Version 2.1.2 and earlier versions are not supported on Mac OS X Version 10.8.
  4. Endpoint analysis scans for antivirus, personal firewalls, antispam, Internet security, and EPAFactory scans are not supported for Mac OS X.
  5. Client certificate authentication is not supported for Mac OS X.

First of all I’d say that these notes are not that great if you ask me! Why do I have to add the cert into the Mac Keychain? Why doesn’t the plug-in support the more “advanced” host checks like personal firewalls, certificates etc.?

Wait, it get even worse!! And before you go to the whole list I’d highlight these top ones that I’m kind of surprised about:

  • It doesn’t support LAN access
  • Upgrading doesn’t work
  • Doesn’t apply proxy settings configured in session profile
  • It doesn’t support SAN certificates
  • Users cannot start the Access Gateway plug-in if the Receiver is already started, you first have to shut down the Receiver

Here you see the full Known Issues list for this release:

  1. When users disable wireless on a Mac OS X computer and connect by using a 3G card, the Access Gateway Plug-in does not upgrade automatically through Citrix Receiver. If users select Check for Updates to upgrade the plug-in, the upgrade fails and users receive the error message “Updates are currently not available.” [#45881]
  2. If you run stress traffic for HTTP, HTTPS, and DNS simultaneously, the Access Gateway Plug-in fails. [#46348]
  3. When users disable wireless on a Mac OS X computer and connect by using a Vodafone Mobile Broadband Model K3570-Z HSDPA USB 3G stick, the Access Gateway plug-in does not tunnel traffic. [#256441]
  4. If you configure an endpoint analysis policy and also enable the client choices page and proxy servers in a session profile, occasionally a blank choices page appears after users log on. When you disable the choices page in the session profile, the choices page appears correctly. [#316331]
  5. If users connect to Access Gateway with the Access Gateway Plug-in for Mac OS X and then run ping with a payload of 1450 bytes, the plug-in fails to receive the ICMP reply. [#321486] Read more…

Tech Preview of #Citrix #XenApp support for the #Lync 2013 VDI Plug-in

Good info from Derek Thorslund.

As you may have already noticed, earlier this week we opened up our Tech Preview program for optimized support of the Microsoft Lync™ 2013 client to all current Citrix XenApp customers under active Subscription Advantage. This phase of the Tech Preview program gives our customers the opportunity to evaluate the Citrix Receiver Display Adapter that integrates with Microsoft’s Lync™ 2013 VDI Plug-in for Windows. The Display Adapter plug-in has been posted on the Citrix Downloads page under “Citrix Receiver” in the “Betas and Tech Previews” section (visible to Citrix customers and partners after login).  Please use the Support Forum to provide feedback or request assistance from the community.

Read more here!

//Richard

Windows #Intune – Toyota rolls out to more than 3000 clients

Automotive Retailer Avoids $1.3 Million in IT Costs with Cloud-Based PC Management Tool

Toyota Motor Europe (TME) had no tools to manage 3,500 car-diagnostic PCs running outside the corporate domain at 3,000 dealerships. TME chose Windows Intune to manage the PCs remotely from a web-based console. It can standardize software deployments to ensure consistent customer service and enhance the security of managed computers to reduce downtime at dealerships. Remote assistance capabilities will also help reduce on-site support costs.

Business Needs
Toyota Motor Europe (TME) manages a network of 30 national marketing and sales companies (NMSC) across Europe. These organizations oversee more than 3,000 dealerships.

In early 2012, TME replaced its stand-alone car-diagnostic tool called IT2 with 3,500 new PCs running more up-to-date software, including Tech Stream and Picoscope. The PCs also store technical documentation. Mechanics attach the PCs to a Vehicle Information Module that connects to a vehicle’s engine to provide critical maintenance information, such as how to reprogram and update a vehicle’s computer chip. The PCs were installed by an external company. The computers are not joined to the domain and operate outside the corporate firewall.

TME did not have a management solution for these 3,500 computers. “We wanted everyone to use the new tools, but we had no visibility into how the dealerships were working with the PCs,” says Niels Svaerke, Manager, Business Process Office, After Sales at Toyota Motor Europe. 

NMSC staff downloaded diagnostic software to the PCs from a Toyota intranet site. However, there was no way for headquarters to verify that all dealerships received and installed the software updates concurrently. “It was difficult to ensure that everyone was providing the same level of service by using the same corporate systems and auto diagnostics,” says Dirk Christiaens, Manager of Enterprise Architecture at Toyota Motor Europe. “Also, the head office had no way of knowing if the dealerships deployed an antivirus solution for their PCs, a worrying scenario as they were connected directly to the Internet.”

NMSC employees performed on-site support for mechanics, which often entails travel time. Sometimes, NMSC staff called an external company to reinstall all the software on the PC. Either scenario incurred wasteful downtime at the dealerships.

Solution
To solve these issues, Toyota Motor Europe decided to evaluate Windows Intune, the cloud-based PC management service from Microsoft. Staff at the NMSC can use the web-based Administration console in Windows Intune to run PC management tasks remotely, including software distribution. All that is required is a standard Internet connection, a browser running Microsoft Silverlight, and the Windows Intune client software installed on the PCs at the dealerships. The client returns information on the PC, including software and hardware inventory, and endpoint protection and update status to the Administration console.“We wanted to move into cloud computing, so Windows Intune met our needs perfectly,” says Christiaens. “Windows Intune had a more flexible, pay-as-you-go model, with no additional bandwidth or server costs.”

Read the whole case study here!

//Richard