<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Alex Tcherniakhovski - Security : Forefront</title><link>http://blogs.msdn.com/alextch/archive/tags/Forefront/default.aspx</link><description>Tags: Forefront</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Network Access Protection DHCP Enforcement Walkthrough</title><link>http://blogs.msdn.com/alextch/archive/2008/08/20/network-access-protection-dhcp-enforcement-walkthrough.aspx</link><pubDate>Thu, 21 Aug 2008 01:16:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8882516</guid><dc:creator>alextch</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/alextch/comments/8882516.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alextch/commentrss.aspx?PostID=8882516</wfw:commentRss><description>&lt;P&gt;This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at &lt;A href="http://www.microsoft.com/info/cpyright.htm" mce_href="http://www.microsoft.com/info/cpyright.htm"&gt;http://www.microsoft.com/info/cpyright.htm&lt;/A&gt;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;BR&gt;In this walkthrough we will examine the steps required to setup NAP environment using DHCP enforcement method. We will also look at how the Forefront codename “Stirling” leverages NAP to enforce a wide range of security configuration settings.&lt;BR&gt;&lt;A class="" href="http://www.alextch.members.winisp.net/nap-dhcp/nap-dhcp.wmv" mce_href="http://www.alextch.members.winisp.net/nap-dhcp/nap-dhcp.wmv"&gt;Please, follow this link to watch the walkthrough&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Useful links:&lt;BR&gt;&lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;amp;displaylang=en"&gt;Forefront Codename “Stirling” document library&lt;/A&gt;&lt;BR&gt;&lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;amp;displaylang=en"&gt;Step-by-Step Guide:&amp;nbsp; Demonstrate NAP DHCP Enforcement in a Test Lab&lt;BR&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8882516" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alextch/archive/tags/Forefront/default.aspx">Forefront</category></item><item><title>Incorporating KB938054 patch into the stand alone Forefront Client deploymnt </title><link>http://blogs.msdn.com/alextch/archive/2008/06/26/incorporating-kb938054-patch-into-the-stand-alone-forefront-client-deploymnt.aspx</link><pubDate>Fri, 27 Jun 2008 01:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8658701</guid><dc:creator>alextch</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/alextch/comments/8658701.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alextch/commentrss.aspx?PostID=8658701</wfw:commentRss><description>&lt;P&gt;&lt;SPAN class=selitemdesc&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Calibri','sans-serif'"&gt;This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN class=selitemdesc&gt;&lt;SPAN style="FONT-SIZE: 10pt"&gt;&lt;A href="http://www.microsoft.com/info/cpyright.htm" minmax_bound="true" mce_href="http://www.microsoft.com/info/cpyright.htm"&gt;&lt;SPAN style="COLOR: #0033cc; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-size: 11.0pt"&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN minmax_bound="true"&gt;http://www.microsoft.com/info/cpyright.ht&lt;/SPAN&gt;&lt;SPAN style="COLOR: #0033cc; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-size: 11.0pt"&gt;m&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN style="COLOR: #0033cc; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-size: 11.0pt"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN style="FONT-SIZE: 10pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;This screen-cast outlines the steps to create a stand-alone Forefront Client Security client installation package which incorporates the latest (at the time of writing &lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 9pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;KB938054&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;) patch. This approach allows to speed-up the deployment of the client and potentially reduces the number of the required reboots.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A href="http://www.alextch.members.winisp.net/fcspatched/fcspackage.wmv"&gt;&lt;FONT face=Calibri size=3&gt;Please, follow this link to see the screen-cast&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Please, not that this approach may not work with the future patches released for Forefront Client.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8658701" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alextch/archive/tags/Forefront/default.aspx">Forefront</category></item><item><title>Migrating to Forefront Client Security</title><link>http://blogs.msdn.com/alextch/archive/2008/05/06/mgrt2ffc.aspx</link><pubDate>Wed, 07 May 2008 00:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8464032</guid><dc:creator>alextch</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/alextch/comments/8464032.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alextch/commentrss.aspx?PostID=8464032</wfw:commentRss><description>&lt;P&gt;&lt;SPAN class=sel_item_desc id=ctl00_SPWebPartManager1_g_5a026fb0_0d62_4e18_8e36_33af58d279e5_ctl00_lblDescription&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%" minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/info/cpyright.htm" minmax_bound="true" mce_href="http://www.microsoft.com/info/cpyright.htm"&gt;&lt;SPAN style="COLOR: #0033cc; LINE-HEIGHT: 115%; mso-bidi-font-size: 11.0pt" minmax_bound="true"&gt;&lt;SPAN minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;http://www.microsoft.com/info/cpyright.htm&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=sel_item_desc&gt;This screencast explores a strategy of conducting a migration from competitive anti-malware products to Forefront Client Security. It proposes an approach of how to leverage various Microsoft technologies (AD, MOM 2005, WMI) to address common challenges during large migration projects. The screencast includes architectural discussion of the solution and demonstrates the approach in practice by conducting an automated migration process from Trend Micro Officescan and Symantec AntiVirus 10.X.&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN class=sel_item_desc&gt;
&lt;P&gt;&lt;SPAN class=selitemdesc&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;A href="http://www.alextch.members.winisp.net/mgrt2fcs/mgr2fcs.wmv"&gt;Please, follow this link to see the screen-cast, which focuses on the migration from TrendMicro Officescan.&lt;/A&gt;&amp;nbsp;Recommend watching the first portion of this screen-cast even if you are migrating from a different product, since I explain the migration architecture in this screen-cast. The remaining screen-cast focus more on the 'how-to" aspects of the migration.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=selitemdesc&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;A href="http://www.alextch.members.winisp.net/mgrt2fcs/sav2fcs.wmv" mce_href="http://www.alextch.members.winisp.net/mgrt2fcs/sav2fcs.wmv"&gt;Please, follow this link to see the screen-cast, which focuses on the migration from Symantec 10&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8464032" width="1" height="1"&gt;</description><enclosure url="http://blogs.msdn.com/alextch/attachment/8464032.ashx" length="6925" type="application/octet-stream" /><category domain="http://blogs.msdn.com/alextch/archive/tags/Forefront/default.aspx">Forefront</category></item><item><title>Performing Mutual Authentication via IPSec in a MOM 2005 workgroup environment</title><link>http://blogs.msdn.com/alextch/archive/2008/04/30/fcswrkgroup.aspx</link><pubDate>Wed, 30 Apr 2008 23:36:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8444855</guid><dc:creator>alextch</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/alextch/comments/8444855.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alextch/commentrss.aspx?PostID=8444855</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%"&gt;&lt;FONT face=Calibri&gt;This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/info/cpyright.htm" minmax_bound="true" mce_href="http://www.microsoft.com/info/cpyright.htm"&gt;&lt;SPAN style="COLOR: #0033cc; LINE-HEIGHT: 115%; mso-bidi-font-size: 11.0pt"&gt;&lt;SPAN minmax_bound="true"&gt;&lt;FONT face=Calibri&gt;http://www.microsoft.com/info/cpyright.htm &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;This walkthrough will concentrate on mitigating some of the security limitations of MOM 2005 when managing machines, which are part of a workgroup environment, or to be more specific which are not part of an Active Directory Forest.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;We will look at how to utilize PKI infrastructure in conjunction with IPSec capabilities of the Windows platform to perform mutual authentication based on X509 certificates.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Please, note that this walkthrough is only applicable to the MOM 2005 environment, since SCOM 2007 has a built-in mechanism to utilize X509 certificates to provide mutual authentication in a workgroup environment.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;For details on how to configure SCOM 2007 to perform mutual authentication using X509 certificates see my blog on &lt;B&gt;&lt;A href="http://blogs.msdn.com/alextch/archive/2008/04/21/scomecerts.aspx"&gt;Configuring SCOM 2007 to perform mutual authentication with non-domain joined machines using X509 certificates&lt;/A&gt;. &lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;When deployed in an Active Directory environment MOM2005 server and MOM2005 clients will mutually authenticate each other by using Kerberos Protocol. This is the default behavior of MOM 2005 which is controlled by the Mutual Authentication Required Setting of MOM 2005 server. This mutual authentication provides the assurance to the server that the alert and event information received from the clients is coming from the trusted source (in other words is not spoofed). At the same time the client is assured that the information it is sending is going to the trusted destination i.e. MOM 2005 server and not some imposter. Hence the built-in mutual authentication mechanism provides the foundation for secure operation of MOM 2005.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;In a workgroup environment Kerberos authentication cannot be performed, therefore in order to accommodate the management of non-domain joined machines we are forced to disable the mutual authentication option on MOM 2005. Since this setting is global it consequently affects both domain joined machines and non-domain-joined machines, therefore significantly reducing the level of security within the MOM 2005 environment.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;To mitigate this limitation of MOM2005 we can utilize IPSec to perform mutual authentication via X509 certificates. The basic idea of this solution is to leverage the fact that the IPSec channel has to be establish prior to the MOM specific traffic ever being exchanged, so by utilizing the mutual authentication capabilities of IPSec we can regain that high level of assurance that the data is being exchanged between the trusted peers.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A href="http://www.alextch.members.winisp.net/fcswrkgrp/fcsworkgroup.wmv"&gt;&lt;FONT face=Calibri size=3&gt;To see the walkthrough, please, follow this link.&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8444855" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alextch/archive/tags/PKI/default.aspx">PKI</category><category domain="http://blogs.msdn.com/alextch/archive/tags/Forefront/default.aspx">Forefront</category></item></channel></rss>