Thursday, October 18, 2007

Quest acquires eXc Software

Not much fanfare about this acquisition on our end but if you go to http://www.excsoftware.com/ you'll see our logo on eXc's home page. I'm excited about this for a few reasons...

  • Agentless connectivity to non-Windows systems - lots of applications in Quest for this set of products
  • Single sign-on with mainframes - what else can I say here, I'm interested!
As with any acquisition we're figuring out how and where to specifically integrate eXc's bits but in the meantime the eXc team will continue doing business as usual except with a much larger team backing them up!

Technorati Tags:
,

Tuesday, October 16, 2007

ActiveRoles Management Console for Active Directory

Both my friends Dmitry and Bob have written about the RC1 release of the Management Console for Active Directory that is based on Quest's Active Roles product and built on PowerShell. I've copied the info direct from Bob's blog...

We just shipped RC1 of our Active Directory (and ADAM) managment commands for PowerShell. Congratulations to our awsome dev team... See below for details of what we provide for free by simply downloading our CMDLETs from http://www.quest.com/activeroles-server/arms.aspx.


CMDLETS at a Glance
Windows Server 2008 CMDLETS 1-4
General Object Management CMDLETS 5-11
Group Management CMDLETS 12-17
Computer Management CMDLET 18
User Management CMDLETS 19-24

CMDLETS Description

***Manage Windows 2008 Password Policy
1. Add-QADPasswordSettingsObjectAppliesTo
Add PSO links on a Password Settings object. Windows Server 2008 is required.

2. Get-QADPasswordSettingsObject
Retrieve Password Settings objects that match the specified conditions. Windows Server 2008 is required.

3. New-QADPasswordSettingsObject
Create a new Password Settings object (PSO). Windows Server 2008 is required.

4. Remove-QADPasswordSettingsObjectAppliesTo
Remove PSO links on a Password Settings object. Windows Server 2008 is required.

*** Object Management
5. Move-QADObject
Move the specified object to a different location (container) in Active Directory.

6. Remove-QADObject
Delete the specified objects in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

7. Rename-QADObject
Change the name of the specified object in Active Directory.

8. Get-QADObject
Retrieve all directory objects in a domain or container that match the specified conditions. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

9. New-QADObject
Create a new object of in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

10. Set-QADObject
Modify attributes of an object in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

11. Convert-QADAttributeValue
Convert attribute values of a directory object to the specified .NET type.

***Group Management
12. Set-QADGroup
Modify attributes of a group in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

13. Add-QADGroupMember
Add one or more objects to a group in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

14. Get-QADGroup
Retrieve all groups in a domain or container that match the specified conditions. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

15. Get-QADGroupMember
Retrieve the members of a group in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

16. New-QADGroup
Create a new group in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

17. Remove-QADGroupMember
Remove one or more members from a group in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

***Computer Management
18. Get-QADComputer
Retrieve all computer objects in a domain or container that match the specified conditions.
(This command looks lonely...)

*** Users Management
19. Get-QADUser
Retrieve all users in a domain or container that match the specified conditions. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

20. Enable-QADUser
Enable a user account in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

21. Disable-QADUser
Disable a user account in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

22. Unlock-QADUser
Unlock a user account in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

23. New-QADUser
Create a new user account in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

24. Set-QADUser
Modify attributes of a user account in Active Directory. Supported are both Active Directory Doman Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).

***Other
25. Get-QADPSSnapinSettings
View default settings that apply to all cmdlets of this PowerShell snap-in.

26. Set-QADPSSnapinSettings
Modify default settings that apply to all cmdlets of this PowerShell snap-in.

27. Connect-QADService
Connect to the ActiveRoles Server Administration Service via the ActiveRoles Server ADSI Provider, or to a certain Active Directory domain controller or a certain server running an Active Directory Lightweight Directory Services (AD LDS) instance via the regular LDAP ADSI Provider.

28. Disconnect-QADService
Close the connection, if any exists. A connection could be established by using the Connect-QADService cmdlet.

Technorati Tags:
, , ,

Friday, October 12, 2007

Listen up Oracle and IBM!! You should support direct authentication against Active Directory

I caught this post and the original post about Oracle 11g security over at over at James McGovern's blog. If you aren't regularly reading his blog you need to.

Oracle 11g Password algorithm revealed: Kinda interesting how easy it is to crack Oracle passwords. Maybe this begs the question of whether databases should store passwords anyway? I am of the belief that Oracle and IBM should within their products support direct authentication against Active Directory for this type of functionality.

I totally agree with what James states - IBM, Oracle and others should be supporting direct authentication against Active Directory. What does that *really* mean? Good question, I'm glad you asked. Well, for one thing, it doesn't mean just LDAP authentication, in my opinion. Let's go a step further and request the Holy Grail, please! We want Kerberos-based authentication.

If we have Kerberos-based authentication the world of SOA, protocol transitioning, web services and multi-tier architectures is opened up in addition to enabling the Holy Grail - true end-to-end single sign-on. There's no reason for you guys (IBM, Oracle, etc) to feel that you have to own this piece of the puzzle. Isn't there enough value-add in the rest of your platform?

Technorati Tags:
, , , ,

Wednesday, October 10, 2007

An extensible admin console based on PowerShell

It's PowerGUI. We released a new version last night and you can see the excitement in my friend Dmitry Sotnikov's email that he sent out...

Yesterday night we put PowerGUI 1.0.11 on the downloads page, I posted the announcement on my blog, and (eventually after my wife started threatening me with divorce) went to bed.

Today when I came to the office PowerGUI went well over 25K downloads – 500+ of which happened during the night, and my blog is having the best day ever with 1000+ visits already.

There are quite a few references on the web:

We are in the middle of incredible growth – the one we never had before, and I think in retrospect this is basically because a few factors played together in a perfect storm:

  • We implemented a great feature – lightweight PowerShell editor – and significantly improved it thanks to internal feedback.
  • We pre-announced the feature right before the weekend. This generated interest and made people wait for what was coming.
  • The catchy name of the announcement – Notepad for PowerShell – helped as well.
  • Good execution by the team on all sides: listening to feedback, implementing well, setting up perfect guerrilla marketing.
There are loads of videos, documentation, cmdlets and a community that are contributing to this free tool. If you haven't checked it out yet you should...

P.S. It keeps getting better: 2,000 blog hits and almost a 1,000 downloads at this point today!

Technorati Tags:
, ,