May 2004 - Posts

ASP.NET controls - Granular security

1) you need a repository for your permissions ie a database structure
2) design user, page, group then usergroups,pagegroups tables linking all with proper keys
 a) associate users to groups and groups to pages in composite tables usergroups,pagegroups
3) add permission columns for view, add, update, delete - one column for each permission - setting 0/1 for allowed/not
4) build custom(extended) base page which
 a)does the lookup of user on these tables to retrieve permission sets
 b)loads the permissions into session
 c)authentication of user ie if user's group does not have permissisons on page
5) build custom(extended) webcontrols  which
 a)map a (design time)property to the above permissions
 b)verify the above permissions
 c)do something based on b) eg hide, set enabled=false, change CSSClasss attrubue or other cool stuff like hiding EditCommandColumn and ButtonColumn in a datagrid

6) add custom assembly to VS.NET

SQL Server scalability (64 bit)

SQL Server scalability casestudies for IT managers:

http://www.microsoft.com/sql/64bit/productinfo/casestudies.asp

other
http://www.enertia-software.com/item.asp?item=622
http://www.intel.com/business/casestudies/raymond_james.pdf
http://www.intel.com/business/bss/products/server/itanium2/testimonials.htm
http://www.intel.com/business/casestudies/koehler.pdf
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=0
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=1
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=2
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=3
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=6
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=8
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=9
http://www.intel.com/business/bss/swapps/server2003/testimonials.htm?showAll=true&selected=11

http://www.unisys.com/products/es7000__servers/news_a_events/all__news/01218375.htm

http://www.hp.com/products1/itanium/testimonials/banca.html
http://www.hp.com/products1/itanium/testimonials/comp_usa.html
http://www.hp.com/products1/itanium/testimonials/finnish.html
http://www.hp.com/products1/itanium/testimonials/denizbank.html

some posts:

http://blogs.msdn.com/brada/archive/2004/03/10/87635.aspx
http://weblogs.asp.net/rwlodarc/archive/2003/04/24/6006.aspx
http://stupidevilbastard.com/archives/2004/02/18/intel_admits_64_bit_is_next_big_thing.php
http://weblogs.asp.net/jdennany/posts/31691.aspx
http://weblogs.asp.net/volkerw/archive/2004/02/25/80175.aspx
http://weblogs.asp.net/oldnewthing/archive/2003/11/19/55757.aspx
http://weblogs.asp.net/frankarr/archive/2004/03/25/95564.aspx
http://weblogs.asp.net/mdavey/archive/2004/03/19/92568.aspx
http://weblogs.asp.net/wallym/archive/2004/01/29/64749.aspx
http://weblogs.asp.net/pleloup/archive/2003/10/29/34389.aspx
http://weblogs.asp.net/volkerw/archive/2004/04/12/111860.aspx
http://sqljunkies.com/WebLog/jt_kane/archive/2003/09/29/247.aspx

 

 

 

 

Why Windows update/Automatic Windows Update suck (part 3)

After seeing the latest developments and improvements I still have several issues with the Automatic Windows Update and the windows update site.

1) patch distribution of patches is still not good enough.
   I think that critical patches should be BUNDLED with the latest version of Windows Media, MSN Messenger, IE or even third party apps like Winzip and Adobe. 
2) critical (remote exploitable or currently expoited) patches are not prioritized in the automated download process nor in the sequence, nor in download urgency in respect to other security patches
3) patches are not supported by scripts, group policies, .reg registry files, IPSEC rules or configuration files which the user installs with a simple click, in which protective features such as firewall, automatic updates can be turned on and features like RPC, files sharing or ports turned off.

XP SP2 RC1 issues

After playing with XP SP2 RC1 for a while I still have a few things which bother me.
I had a look at group policies typing gpedit.msc in the Run command.

I found following issues:

RPC policies are still undefined ie it still allows unauthenticated anonymous users to log in ... with the bad practices around I doubt it will be switched on

Automatic updates are not enabled -> users will be able to switch then off too easily

Anyone can push the right buttons to get these sorted?


links:

http://microsoft.weblogsinc.com/entry/5967532431807386/
http://www.drweb.de/weblog/weblog/index.php?p=28
http://weblogs.asp.net/jeffdav/archive/2004/03/22/94080.aspx
http://graemef.com/blog/archive/2004/03/23/652.aspx
http://weblogs.asp.net/pmarcucci/archive/2004/01/14/58628.aspx
http://weblogs.asp.net/jambrose/archive/2004/04/11/XPSP2RC1Firewall.aspx
http://radio.weblogs.com/0126569/2004/03/21.html
http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx
http://weblogs.asp.net/brianjo/archive/2004/02/24/79229.aspx
http://weblogs.asp.net/mhawley/archive/2004/03/23/94860.aspx
http://dotnetjunkies.com/WebLog/d0m1/archive/2004/02/05/6635.aspx
http://blogs.msdn.com/tims/archive/2004/03/08/85898.aspx
http://blogs.bartdesmet.net/bart/archive/2004/02/27.aspx
http://blogs.geekdojo.net/adam/archive/2004/02/24/1200.aspx
http://e-oddie.com/blog/professional/archive/2004/05/09/292.aspx
http://weblogs.asp.net/David_Gristwood/archive/2004/05/25/141419.aspx

http://weblogs.asp.net/alexbarn/archive/2004/05/29/144349.aspx

http://weblogs.asp.net/despos/archive/2004/05/31/144809.aspx