<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://port25.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Port 25: The Open Source Community at Microsoft : Community, Identity and Authentication</title><link>http://port25.technet.com/archive/tags/Community/Identity+and+Authentication/default.aspx</link><description>Tags: Community, Identity and Authentication</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 40109.1145)</generator><item><title>UNIX Interop in Vista Beta 2 and Longhorn Server</title><link>http://port25.technet.com/archive/2006/07/06/UNIX-Interop-in-Vista-Beta-2-and-Longhorn-Server.aspx</link><pubDate>Thu, 06 Jul 2006 17:06:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2708</guid><dc:creator>jcannon</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2708</wfw:commentRss><comments>http://port25.technet.com/archive/2006/07/06/UNIX-Interop-in-Vista-Beta-2-and-Longhorn-Server.aspx#comments</comments><description>&lt;p&gt;Another guest blog this week from &lt;em&gt;Identity Management Program Manager, Shamit Patel&lt;/em&gt;:&lt;br /&gt;---------------------------------------------&lt;br /&gt;&lt;br /&gt;Hi,&lt;br /&gt;Last week, we released two new utilities to help customers achieve UNIX&amp;nbsp;/ Windows Interop. The first is a set of utilities and the SDK for the Subsystem for UNIX Architecture (SUA) in Vista Beta 2 &amp;amp; Longhorn. For those unaware, SUA is a native subsystem residing on top of the Windows kernel, just like the Win32 subsystem. It provides the basic infrastructure to run UNIX-based applications and scripts on Windows Vista (Ultimate and Enterprise) and Longhorn Server. &lt;br /&gt;&lt;br /&gt;We&amp;#39;ve also released the UNIX-side components for Identity Management with UNIX. This essentially provides the utilities which enable password sync between Windows and UNIX environments. These are the UNIX-based utilities to enable successful synchronization. &lt;br /&gt;&lt;br /&gt;I realize many of you may not be testing Vista or Longhorn, but for those who are, or have corporate testing, we would love to hear your feedback on the product, scripts and documentation. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;View full post on &lt;a href="http://blogs.msdn.com/shamit/archive/2006/07/04/656493.aspx"&gt;Longhorn Server Identity Management for UNIX components&lt;/a&gt;&amp;nbsp;and &lt;a href="http://blogs.msdn.com/shamit/archive/2006/07/04/656496.aspx"&gt;Vista Beta 2/Longhorn Utilities and SDK for UNIX Subsystem&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;Download Utilities &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=93ff2201-325e-487f-a398-efde5758c47f&amp;amp;displaylang=en"&gt;and SDK for Subsystem for UNIX-based Applications in Microsoft Windows Vista / Longhorn Server Beta 2&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;Download &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8edbe153-b4f3-4df6-b0ad-54a43c02ca29&amp;amp;DisplayLang=en"&gt;UNIX Side Components for Identity Management for UNIX&lt;/a&gt; &amp;ndash; Shipped with Windows Server codenamed Longhorn Server Beta 2.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Thanks all,&lt;br /&gt;Shamit&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2708" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Identity+and+Authentication/default.aspx">Identity and Authentication</category><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category><category domain="http://port25.technet.com/archive/tags/Downloads/default.aspx">Downloads</category></item><item><title>Security and Directory Services for UNIX Guide Released</title><link>http://port25.technet.com/archive/2006/06/30/Security-and-Directory-Services-for-UNIX-Guide-Released.aspx</link><pubDate>Fri, 30 Jun 2006 18:23:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2698</guid><dc:creator>admin</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2698</wfw:commentRss><comments>http://port25.technet.com/archive/2006/06/30/Security-and-Directory-Services-for-UNIX-Guide-Released.aspx#comments</comments><description>&lt;p&gt;We&amp;#39;ve got a quick guest blog before the holiday weekend on a new set of&amp;nbsp;interoperability tools released this week by Microsoft, and in conjunction with some very talented folks in our partner, sales &amp;amp; services group. Welcome Luis Camara Manoel, Program Manager for in Communications &amp;amp; Collaboration...&lt;em&gt;take it away Luis:&lt;/em&gt;&lt;/p&gt;&lt;p&gt;------------------&lt;br /&gt;&lt;img src="http://port25.technet.com/photos/interviews/images/2699/original.aspx" border="0" alt="" width="100" height="100" /&gt;&lt;br /&gt;&lt;strong&gt;(Luis&lt;/strong&gt; &lt;strong&gt;Camara Manoel)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Hi all,&lt;br /&gt;The Interoperability and Migration Solutions team at Microsoft is very happy to have just released the &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=144f7b82-65cf-4105-b60c-44515299797d&amp;amp;displaylang=en"&gt;Windows Security and Directory Services for UNIX Guide&lt;/a&gt;. This guide details step-by-step instructions for providing security and directory services for mixed Windows and UNIX environments using Active Directory. The approach we followed here describes multiple options to achieve two different system end-states:&lt;/p&gt;&lt;p&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; UNIX clients are enabled to use Windows Active Directory Kerberos for authentication while continuing to use a UNIX-based store for authorization. &lt;/p&gt;&lt;p&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; UNIX clients are enabled to use Windows Active Directory Kerberos for authentication and use Active Directory LDAP for authorization. &lt;/p&gt;&lt;p&gt;We have also added some tools and templates to help plan, develop, deploy, and operate these solutions.&lt;/p&gt;&lt;p&gt;Although this release addresses AD integration only for Solaris 9 and for RedHat 9, it is pretty simple to see how it would apply to other UNIX and UNIX-like systems. &lt;/p&gt;&lt;p&gt;You can download the guide at &lt;a href="http://go.microsoft.com/?linkid=5118169"&gt;http://go.microsoft.com/?linkid=5118169&lt;/a&gt; and please let me know what you think. I am very interested in finding out how the guidance is received. &lt;br /&gt;&lt;br /&gt;Have a great holiday weekend,&lt;br /&gt;-Luis&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2698" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Identity+and+Authentication/default.aspx">Identity and Authentication</category><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category><category domain="http://port25.technet.com/archive/tags/Downloads/default.aspx">Downloads</category></item><item><title>The Future of IdMU, help us help you...</title><link>http://port25.technet.com/archive/2006/05/25/The-Future-of-IdMU_2C00_-help-us-help-you_2E002E002E00_.aspx</link><pubDate>Thu, 25 May 2006 14:56:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2539</guid><dc:creator>admin</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2539</wfw:commentRss><comments>http://port25.technet.com/archive/2006/05/25/The-Future-of-IdMU_2C00_-help-us-help-you_2E002E002E00_.aspx#comments</comments><description>&lt;div class="Section1"&gt;&lt;p class="MsoNormal"&gt;&lt;font face="Verdana"&gt;&lt;strong&gt;The Future of IdMU, help us help you...&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="Verdana"&gt;I would like to thank everyone who posted comments in my Identity Management for UNIX intro web session. While I am keen on getting your feedback on Windows 2003 R2 and Longhorn Beta releases, I am also interested in getting your views on the direction you feel that this product should take for future releases. I have received good feedback so far on topics&amp;nbsp;such as: expanding IdMU feature-set to support authentication over LDAP, and providing a Kerberos based solution that knits well with AD.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="Verdana"&gt;I would like to hear more ideas and request your opinion on what direction you feel IdMU should take next.&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;font face="Verdana"&gt;Please take a moment to comment below or submit mail to &lt;/font&gt;&lt;a style="color: blue; text-decoration: underline" href="mailto:port25@microsoft.com" title="mailto:port25@microsoft.com"&gt;&lt;font face="Verdana"&gt;port25@microsoft.com&lt;/font&gt;&lt;/a&gt;&lt;font face="Verdana"&gt; with the subject:&amp;nbsp; IdMU Ideas.&amp;nbsp; I will be responding to comments and email and look forward to a productive discussion.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span&gt;&lt;font face="Verdana"&gt;-Shamit&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2539" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Identity+and+Authentication/default.aspx">Identity and Authentication</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category></item><item><title>Windows Security and Directory Services for UNIX Solution Guide</title><link>http://port25.technet.com/archive/2006/05/11/Windows-Security-and-Directory-Services-for-UNIX-Solution-Guide.aspx</link><pubDate>Thu, 11 May 2006 19:36:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2441</guid><dc:creator>admin</dc:creator><slash:comments>18</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2441</wfw:commentRss><comments>http://port25.technet.com/archive/2006/05/11/Windows-Security-and-Directory-Services-for-UNIX-Solution-Guide.aspx#comments</comments><description>&lt;font face="Verdana" size="3"&gt;&lt;p&gt;&lt;font face="Verdana" size="2"&gt;Jason Zions pointed us to this&amp;nbsp;newly revised Windows Security and Directory Services for UNIX solution guide, still in beta. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Verdana" size="2"&gt;Description of the Guide and access instructions from&amp;nbsp;Luis Camara Manoel, Program Manager, Collaboration Solutions Team:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Verdana" size="2"&gt;&lt;em&gt;&amp;quot;The Windows Security and Directory Services for UNIX v1.0 Beta guide provides several solutions for enabling interoperability between UNIX and Windows infrastructures. The solutions included in this Beta release describe multiple options to achieve two different end states: &lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul style="margin-bottom: 0in"&gt;&lt;li class="MsoNormal"&gt;&lt;font face="Verdana" size="2"&gt;&lt;em&gt;How to enable UNIX clients to use Windows Active Directory Kerberos for authentication while continuing to use a UNIX-based store for authorization. &lt;/em&gt;&lt;/font&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;font face="Verdana" size="2"&gt;&lt;em&gt;How to enable UNIX clients to use Windows Active Directory Kerberos for authentication and use Active Directory LDAP for authorization. &lt;/em&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font face="Verdana"&gt;&lt;em&gt;&lt;font size="2"&gt;To download and read the solution online, please visit Microsoft Connect: &lt;/font&gt;&lt;a style="color: blue; text-decoration: underline" href="https://connect.microsoft.com/default.aspx" title="https://connect.microsoft.com/default.aspx"&gt;&lt;font size="2"&gt;https://connect.microsoft.com/default.aspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;. Follow registration procedures and select &amp;ldquo;The Windows Security and Directory Services Guide for UNIX v1.0&amp;rdquo; program to enroll and download the beta.&amp;quot; &lt;/font&gt;&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Verdana" size="2"&gt;Per Jason:&amp;nbsp; &amp;quot;Although the guide gives step-by-step instructions for setting up AD integration only for Solaris 9 and for RedHat 9, it&amp;#39;s pretty easy to see how it would extend to lots of other UNIX and UNIX-like systems.&amp;quot;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Verdana" size="2"&gt;To download the paper you&amp;#39;ll need a Passport Account (the link above will prompt you for one) which is used to send updates, if you wish, on new releases and an announcement when the guide is final.&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Verdana" size="2"&gt;Let us and Luis know what you think!&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2441" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Identity+and+Authentication/default.aspx">Identity and Authentication</category><category domain="http://port25.technet.com/archive/tags/Interop/default.aspx">Interop</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category><category domain="http://port25.technet.com/archive/tags/Server+Center/default.aspx">Server Center</category></item><item><title>Oil and Water?</title><link>http://port25.technet.com/archive/2006/04/21/Oil-and-Water_3F00_.aspx</link><pubDate>Fri, 21 Apr 2006 23:35:00 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2200</guid><dc:creator>admin</dc:creator><slash:comments>20</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://port25.technet.com/rsscomments.aspx?PostID=2200</wfw:commentRss><comments>http://port25.technet.com/archive/2006/04/21/Oil-and-Water_3F00_.aspx#comments</comments><description>&lt;font size="2"&gt;&lt;font color="#000000"&gt;&lt;strong&gt;Oil and Water?&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;It&amp;rsquo;s been an interesting week for Interop inside the lab &amp;ndash; we&amp;rsquo;re running an IPSEC interoperability project to test Fedora, OpenSUSE, RHEL, SLES, Ubuntu, and Mandriva with Windows Networking technology, and ran interviews both with the IDMU (Identity Management for Unix) Program Manager and with Paul Moore, CTO of Centrify.&lt;br /&gt;&lt;br /&gt;Today I spoke with Jeremy Moskowitz, a Windows/Linux interoperability expert, to get his take on some of the recurring challenges in starting interop projects and why it matters.&amp;nbsp; He&amp;rsquo;s done a lot of work on the topic of group policy, and writes books and teaches on-site classes for IT professionals.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sam: What&amp;#39;s the main thing that you find people don&amp;rsquo;t understand about Windows/Linux interop? &lt;/font&gt;&lt;/font&gt;&lt;blockquote dir="ltr" style="margin-right:0px;"&gt;&lt;font size="2" color="#000000"&gt;Jeremy:&amp;nbsp; People often don&amp;rsquo;t realize how many points of contact between the two systems you can actually interoperate. I wrote a book with Thomas Boutell, and in 10 chapters we isolated 8 points, including desktop, applications, email, networking and authentication.&lt;br /&gt;&lt;br /&gt;Sam: Authentication is an interesting topic &amp;ndash; what do you lay out as the main approaches here?&lt;br /&gt;&lt;br /&gt;Jeremy:&amp;nbsp; There are a lot of different approaches.&amp;nbsp; For example, if it&amp;rsquo;s a &amp;ldquo;mostly Linux&amp;rdquo; shop that needs to integrate a couple of Windows machines, you&amp;rsquo;d use OpenLDAP.&amp;nbsp; If it&amp;rsquo;s a mixed Windows and Linux/Unix shop running Active Directory, integrate Linux &amp;amp; Unix systems as Windows clients.&lt;br /&gt;&lt;br /&gt;Sam: Do you cover that in the book?&amp;nbsp; Are you using IDMU to run a Windows NIS master?&lt;br /&gt;&lt;br /&gt;Jeremy: When we wrote the book, Win2K3 R2 hadn&amp;rsquo;t shipped and SFU was a separate application.&amp;nbsp; We decided to write a chapter on updated procedures for Win2K3 R2 as a download from &lt;/font&gt;&lt;a href="http://www.winlinanswers.com/" target="_blank"&gt;&lt;font size="2"&gt;&lt;font color="#000000"&gt;www.winlinanswers.com&lt;/font&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&lt;font color="#000000"&gt;. It should be available in May, so check back often. &lt;br /&gt;&lt;br /&gt;Sam: What do you usually see as the main obstacle in IT shops to do Windows and Linux integration?&lt;br /&gt;&lt;br /&gt;Jeremy:&amp;nbsp; Windows and Linux guys in a given company don&amp;#39;t talk much &amp;ndash; they usually only meet up playing softball on opposite&amp;nbsp;teams at the company picnic.&lt;br /&gt;&lt;br /&gt;Sam: Sounds like some cultural interop issues?&lt;br /&gt;&lt;br /&gt;Jeremy:&amp;nbsp; There has historically been a religion problem which causes problems in doing these things.&amp;nbsp; I&amp;#39;m a pragmatist - I have Windows running a bunch of systems but my website runs on LAMP.&amp;nbsp; I needed a great web designer and a site he could maintain, and what he knew was PHP.&lt;br /&gt;&lt;br /&gt;Sam: What&amp;#39;s one great thing people will get out of reading your book?&lt;br /&gt;&lt;br /&gt;Jeremy:&amp;nbsp; When I gave my session on interop at LinuxWorld, I asked the audience of about 70 people: &amp;ldquo;Who here is running Exchange?&amp;rdquo;&amp;nbsp; 60 people raised their hands.&amp;nbsp; I said, &amp;ldquo;Keep your hands up.&amp;nbsp; Now drop your hand if you&amp;#39;re planning on walking away from your Exchange infrastructure and just to have something that runs on Linux.&amp;rdquo; One person dropped their hand.&amp;nbsp; Exchange is here and people need to manage it.&lt;br /&gt;&lt;br /&gt;So the question is, &amp;ldquo;How do we use Linux to manage the exchange environment?&amp;rdquo;&amp;nbsp; In the book we detail an approach that uses a front end Linux server that will, for free, scrub email, scan for viruses, and verify the delivery address for routing across backend mail servers (Exchange, sendmail, etc).&amp;nbsp; You offload things that typically run on the Exchange server and bog it down.&amp;nbsp; By using a Linux box to front-end Exchange, you get more horsepower out of your Exchange server so that you get better performance for what you&amp;#39;re paying for.&lt;/font&gt;&lt;/font&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;font size="2" color="#000000"&gt;You can see Jeremy&amp;rsquo;s new site at &lt;/font&gt;&lt;a href="http://www.winlinanswers.com/" target="_blank"&gt;&lt;font size="2"&gt;&lt;font color="#000000"&gt;http://www.winlinanswers.com&lt;/font&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2" color="#000000"&gt;, or see other stuff he&amp;rsquo;s done at &lt;/font&gt;&lt;a href="http://www.moskowitz-inc.com/" target="_blank"&gt;&lt;font size="2"&gt;&lt;font color="#000000"&gt;http://www.moskowitz-inc.com&lt;/font&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2" color="#000000"&gt; Jeremy will be answering comments on this thread, so if you have some tough questions about AD interop, OpenLDAP, Samba 3.0, SFU, or related topics, this is the place to ask.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Sam&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2200" width="1" height="1"&gt;</description><category domain="http://port25.technet.com/archive/tags/Sam+Ramji/default.aspx">Sam Ramji</category><category domain="http://port25.technet.com/archive/tags/Identity+and+Authentication/default.aspx">Identity and Authentication</category><category domain="http://port25.technet.com/archive/tags/Community/default.aspx">Community</category></item></channel></rss>