<?xml version="1.0" encoding="utf-8"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<title>Paul&apos;s Digital Lounge and Cigar Bar</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/" />
<modified>2007-06-24T00:03:13Z</modified>
<tagline></tagline>
<id>tag:www.identit.ca,2007:/blogs/paul//1</id>
<generator url="http://www.movabletype.org/" version="3.2">Movable Type</generator>
<copyright>Copyright (c) 2006, Paul Adare</copyright>
<entry>
<title>Virtual Server 2005 R2 Service Pack 1 Beta 1 Is Now Available!</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2006/04/virtual_server_2.php" />
<modified>2007-06-24T00:03:13Z</modified>
<issued>2006-04-29T01:42:33Z</issued>
<id>tag:www.identit.ca,2006:/blogs/paul//1.78</id>
<created>2006-04-29T01:42:33Z</created>
<summary type="text/plain">A beta of Virtual Server 2005 R2 service pack 1 is available today for download. Virtual Server 2005 R2 service pack 1 will support the hardware virtualization capabilities developed by AMD and Intel. By supporting both AMD Virtualization and Intel...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>A beta of Virtual Server 2005 R2 service pack 1 is available today for download. Virtual Server 2005 R2 service pack 1 will support the hardware virtualization capabilities developed by AMD and Intel. By supporting both AMD Virtualization and Intel Virtualization Technology, customers will be provided better interoperability, strengthened isolation to prevent corruption of one virtual machine from affecting others on the same system, and improved performance for non-Windows guest operating systems. The beta of Virtual Server 2005 R2 service pack 1 is available at <a href="http://www.microsoft.com/virtualserver." target="_blank">www.microsoft.com/virtualserver.</a></p>

<p>Microsoft will have two betas of Virtual Server 2005 R2 SP1. Beta 2 is scheduled for calendar Q4, with general availability in Q1 2007.</p>

<p>Beta 1 of Virtual Server 2005 R2 service pack 1 includes:</p>

<p>- Intel Virtualization Technology compatibility<br />
- Host Clustering technical white paper and the VB script</p>

<p>Beta 2 is planned to include the features of Beta 1 plus:</p>

<p>- AMD Virtualization Technology compatibility<br />
- Active Directory integration and management features<br />
- Volume Shadow Service</p>

<p>The Beta 1 download is available via Microsoft Connect.  Select the Virtual Server 2005 R2 SP1 Beta program from the list of available programs that appear here: <br />
<a href="https://connect.microsoft.com/availableprograms.aspx." target="_blank">https://connect.microsoft.com/availableprograms.aspx.</a></p>]]>

</content>
</entry>
<entry>
<title>Interesting RMS Issue</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2006/04/interesting_rms.php" />
<modified>2007-02-17T06:35:34Z</modified>
<issued>2006-04-21T10:29:40Z</issued>
<id>tag:www.identit.ca,2006:/blogs/paul//1.77</id>
<created>2006-04-21T10:29:40Z</created>
<summary type="text/plain">So I&apos;m working on an RMS deployment for a customer and we ran into a weird issue that up until now I&apos;d never seen before so I thought that I&apos;d share the problem and what we finally discovered to be...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Windows Rights Management Services</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>So I'm working on an RMS deployment for a customer and we ran into a weird issue that up until now I'd never seen before so I thought that I'd share the problem and what we finally discovered to be the cause of the problem.<br />
<b><u>Problem Description</u></b><br />
If a user, let's call her Alice since RMS is a cryptographic application, created a piece of protected content using the built-in Office protection methods (IOW not using a custom template) and assigned another user, say Bob, a specific set of limited rights on the content, when Bob opened the content, rather than having the limited rights assigned appeared to have full control of the content. Now if Bob were to create a piece of protected content, and assigned limited rights to Carol, when Carol opened the protected content, she had the correct rights assigned. Similarly, if Carol assigned rights on content to Bob, everything worked as expected. If Bob or Carol assigned rights on content to Alice, Alice had the correct rights when opening the content. So the problem only occurred when Alice was protecting content. Finally, if Alice protected content using a custom template, everything worked as expected.<br />
Examining the EULs issued to Bob or Carol showed that regardless of the protections assigned by Alice, Bob and Carol had the OWNER right, which is similar to NTFS full control, in the EUL.<br />
<b><u>Cause and Resolution</u></b><br />
After opening a case with Microsoft's CSS we discovered what was causing this problem. The customer uses the email attribute of security groups to list the email address of the owner of each group. They do this so that they have a point of contact for adding user accounts to the group in question. This was the cause of the problem we were seeing. It turned out that Alice was the owner of a group that contained Bob and Carol and because of the practice of adding the group owner's email address to the email attribute of the group anyone who was a member of that group was being granted OWNER rights to the content. Removing Alice's email address from the email attribute of the group, and flushing RMS' group cache resolved this problem.</p>

<p>The other side effect of this issue is that <b>any</b> member of a group that contained Alice's email address in the email attribute would have OWNER rights on the content, even if they had not been specifically assigned rights on the content.</p>

<p>The reason that this behaviour did not appear when using custom templates is that the templates used the special RMS group Anyone which obviously doesn't have an email attribute.</p>

<p>The customer in question is going to fix up the security groups that affect their pilot deployment, however, this behaviour may well prevent them from pursuing a broader deployment of RMS.</p>

<p>Hope this helps.</p>]]>

</content>
</entry>
<entry>
<title>Want the Performance Improvements in Virtual Server 2005 R2 But Still Want to Use Virtual PC 2004?</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2006/04/want_the_perfor.php" />
<modified>2007-06-24T00:02:04Z</modified>
<issued>2006-04-19T09:37:34Z</issued>
<id>tag:www.identit.ca,2006:/blogs/paul//1.76</id>
<created>2006-04-19T09:37:34Z</created>
<summary type="text/plain">In addition to some new features (host based clustering using iSCSI, x64 support, etc.) VS 2005 R2 also includes some fairly significant performance improvements. What if you&apos;re running, and want to keep on using VPC 2004 but you&apos;d still like...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>In addition to some new features (host based clustering using iSCSI, x64 support, etc.) VS 2005 R2 also includes some fairly significant performance improvements. What if you're running, and want to keep on using VPC 2004 but you'd still like to have the performance improvements that VS 2005 R2 provides? Now that VS 2005 R2 is free, there is a simple solution to this problem. If you install VS 2005 R2 on a system that already has VPC 2004 installed, a number of components that are shared between the two products will be installed and will then be available to VPC 2004. These shared components contain most of the performance improvements in VS 2005 R2 and as such will be available to VPC 2004 after installing VS 2005 R2. Note that if you don't plan on using VS 2005 R2 you don't need to have IIS installed before installing VS 2005 R2. Also note that you won't get any of the new features as these are all VS specific, however, you will get the benefit of the performance improvements.<br />
This will also allow you to take advantage of the latest version of the Virtual Machine Additions which ship with VS 2005 R2. To use the new Additions you can either manually mount the ISO from Program Files\Microsoft Virtual Server\Virtual Machine Additions in a VPC guest or, if you want to be able to install the updated Additions using the Action menu item in VPC, copy the VMAdditions.iso file from that folder to the Program Files\Microsoft Virtual PC\Virtual Machine Additions folder, replacing the existing Additions ISO.<br />
</p>]]>

</content>
</entry>
<entry>
<title>Microsoft Executive Circle Webcast: Security360 with Mike Nash: Building a Secure, Connected Infrastructure with Digital Certificates</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2006/04/microsoft_execu.php" />
<modified>2007-02-28T10:45:30Z</modified>
<issued>2006-04-18T11:52:05Z</issued>
<id>tag:www.identit.ca,2006:/blogs/paul//1.75</id>
<created>2006-04-18T11:52:05Z</created>
<summary type="text/plain">Brian Komar, my business partner, is Mike Nash&apos;s guest on today&apos;s Microsoft Executive Circle Webcast. Should be a good one!...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Public Key Infrastructure</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Brian Komar, my business partner, is Mike Nash's guest on today's <a href="http://www.identit.ca/events.html" target="_blank" title="Webcast details">Microsoft Executive Circle Webcast</a>. Should be a good one!</p>]]>

</content>
</entry>
<entry>
<title>IdentIT Inc. Finally Has A Decent Web Site</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2006/04/identit_inc_fin.php" />
<modified>2007-02-28T10:46:22Z</modified>
<issued>2006-04-18T11:48:44Z</issued>
<id>tag:www.identit.ca,2006:/blogs/paul//1.74</id>
<created>2006-04-18T11:48:44Z</created>
<summary type="text/plain">Brian and I decided that it was finally time for IdentIT Inc. to have a proper web site so I built and published one. The URL is http://www.identit.ca....</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>General</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Brian and I decided that it was finally time for IdentIT Inc. to have a proper web site so I built and published one. The URL is <a href="http://www.identit.ca" target="_blank" title="New web site for IdentIT Inc.">http://www.identit.ca</a>.</p>]]>

</content>
</entry>
<entry>
<title>I&apos;m Back!</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2006/04/im_back.php" />
<modified>2007-02-15T12:24:21Z</modified>
<issued>2006-04-18T11:13:08Z</issued>
<id>tag:www.identit.ca,2006:/blogs/paul//1.73</id>
<created>2006-04-18T11:13:08Z</created>
<summary type="text/plain">So after an extended absence, that I&apos;m sure most folks have not even noticed, I&apos;ve decided to try to keep my blog up to date. There, didn&apos;t that make your day?...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>General</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>So after an extended absence, that I'm sure most folks have not even noticed, I've decided to try to keep my blog up to date. There, didn't that make your day?</p>]]>

</content>
</entry>
<entry>
<title>VSDM Installation Instructions</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/vsdm_installati.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-25T10:21:02Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.65</id>
<created>2005-04-25T10:21:02Z</created>
<summary type="text/plain">Sorry for the delay on getting this posted! Without any further ado, let&apos;s look at how to install VSDM. The first step is to download and execute the installer. You can download VSDM by clicking here if you&apos;ve not already...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Sorry for the delay on getting this posted! Without any further ado, let's look at how to install VSDM.<br />
The first step is to download and execute the installer. You can download VSDM by clicking <b><i><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ff59c543-5107-42f6-9252-a8cde3b53915&DisplayLang=en" target="_blank" title="VSDM Download">here</a></i></b> if you've not already done so. The requirements for VSDM are as follows:</p>

<ul><li>Supported Operating Systems: Windows 2000, Windows Server 2003, Windows XP</li>
<li>Microsoft Virtual Server 2005</li>
<li>.NET Framework 1.1</li>
<li>Internet Information Services (IIS), with ASP.NET (note that the VSDM installer will add ASP.NET and/or enable the ASP.NET extensions if necessary)</li>
<li>Client side requires: Internet Explorer (6.0 or greater)</li></ul>

<p>To get started with the install, run the file you downloaded.</p>

<p>Due to the fact that this entry contains a lot of screen shots, I'm using MT's Extended Entry capability so you'll need to click the link below to view the remainder of this entry. Please feel free to leave a comment with any questions you might have. If you've tried to leave comments before and were turned off by the fact that they required an email address, please try again as I've disabled that requirement.</p>]]>
<![CDATA[<p>Running the downloaded installer for VSDM opens the first of three wizards that allow you to control the installation process.</p>

<p><BLOCKQUOTE><ol><br />
<li>On the <b>Welcome to the Virtual Server Deployment Manager 1.3.0 (VSDM) Setup Wizard page</b>, click <b>Next</b>.</li><br />
<li>On the <b>License Agreement</b> page, click <b>I agree</b>, and then click <b>Next</b>.</li><br />
<li>On the <b>Select Installation Folder</b> page, select an appropriate folder for VSDM, and then click <b>Next</b>.</li><br />
<li>On the <b>Confirm Installation</b> page, click <b>Next</b>.</li><br />
<BLOCKQUOTE>The VSDM installation begins. When the installation is complete, the second of the three wizards, the <b>VSDM IIS Configuration Wizard</b> is launched.</BLOCKQUOTE><br />
<li>In the <b>VSDM IIS Configuration Wizard</b>, on the <b>Step 1: Please locate your Virtual Server Installation</b> page, confirm that the information is correct, and then click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep1.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep1.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep1-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><li>On the <b>Step 2: Enable ASP.NET Runtime Engine 1.1</b> page, click <b>Next</b>.</li><br />
<BLOCKQUOTE><b>Note:</b> There will not be anything for you to select on this page. If you don't have ASP.NET installed, the installer will add it and enable the ASP.NET extension automatically. If you have ASP.NET installed, but don't have the extension enabled, the installer will enable it. If you have ASP.NET installed and have the extension enabled, the installer will report this.</BLOCKQUOTE><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep2.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep2.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep2-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><li>On the <b>Step 3: Please select your IIS installation method</b> page, select the appropriate option to either install VSDM as a new web site, or to install it as a virtual folder (or virtual directory) in an existing web site, and then click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep3.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep3.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep3-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><BLOCKQUOTE><b>Note:</b> The next page will present one of two options, depending on which option you chose in Step 3.</BLOCKQUOTE><br />
<li>If you chose to install VSDM as a new web site, on the <b>Step 4: Please select your configuration</b> page, in the <b>Name</b> box, enter a name for your web site. In the <b>Port</b> box, enter an unused port for the new web site, and then click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep4a.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep4a.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep4a-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><li>If you chose to install VSDM as a virtual directory in an existing web site, on the <b>Step 4: Please select your configuration</b> page, in the <b>Host Web Site</b> list, select an existing web site, in the <b>Folder</b> box, type the name for the new virtual directory, and then click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep4b.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep4b.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep4b-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><li>On the <b>Step 5: Choose authentication method</b> page, click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep5.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep5.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep5-thumb.PNG" width="221" height="173" border="0" /></a><br />
<BLOCKQUOTE><b>Note:</b> There really is nothing to configure here. If you attempt to clear the <b>Integrated Windows authentication</b> check box, a message will appear informing you that you must select at least one authentication method. If you want to change the authentication methods for the VSDM web site, you'll need to do so after the installation is complete by using the <b>Internet Information Services (IIS) Manager</b>.</BLOCKQUOTE><br />
<li>On the <b>Step 6: Virtual Server Options</b> page leave the <b>Create reference to the Virtual Server Web Admin</b> and <b>Create Virtual Server folder in website root</b> options enabled. This will create a link to the Virtual Server Administration Web site from within the VSDM web site. I've found a bug relating to this option which I'll describe later. For now, it is important that you leave these options enabled. You also have the option to create the VSDM security groups at this time.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep6.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep6.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep6-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><li>On the <b>Step 7: VSDM Client Support</b> page, click <b>Next</b>. I'm not entirely sure what this option is for, but as the page says, it is under development and is not currently available.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep7.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep7.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep7-thumb.PNG" width="221" height="173" border="0" /></a></p>

<p><li>On the <b>Review your settings</b> page, verify that all of the settings are correct, and then click <b>Finish</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmstep8.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmstep8.php','popup','width=442,height=347,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmstep8-thumb.PNG" width="221" height="173" border="0" /></a><br />
</ol></p>

<p>The VSDM IIS configuration is now complete and the <b>VSDM Configuration Wizard</b> is launched. This wizard builds the XML file that VSDM uses for its configuration information.<br />
<ol><br />
<li>In the <b>VSDM Configuration Wizard</b>, on the <b>Welcome</b> page, click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfig.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfig.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfig-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Introduction</b> page, click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigintro.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigintro.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigintro-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Step 1: Installation Information</b> page fill in the options as follows:<br />
<BLOCKQUOTE><ul><br />
<li><b>Title:</b> This will appear in the top panel of the VSDM Web site.</li><br />
<li><b>Display:</b> If this is enabled, the <b>Title</b> wil be displayed in the top panel of the VSDM web site.</li><br />
<li><b>Show Server:</b> If this is enabled, the FQDN of the VSDM server will be displayed in the top panel of the VSDM web site.</li><br />
<li><b>URL:</b> This is supposed to create a hyperlink for the <b>Title</b> value. <b>Note:</b> This is where I think I've identified the bug that I mentioned earlier. It would appear that the wizard actually writes this value to the wrong location in the XML file. Rather that doing what it is supposed and creating a hyperlink for the <b>Title</b> value, this value gets written to the XML file where the value for the Virtual Server Administration web site is supposed to be written. I've reported this to Nelson, but have not heard back from him as of yet. For now, I'd recommend that you either leave this value blank, or if you must fill it out, use the URL for your VS Administration web site, i.e. http://hostname:1024/VirtualServer. No matter what you do here, the <b>Title</b> value will not have a hyperlink behind it. To get a hyperlink you'll need to manually edit the XML file after the installation is complete.</li><br />
<li><b>Install Path:</b> The location of the Virtual Server installation.</li><br />
<li><b>Images:</b> I haven't been able to figure out what <b>Images</b> are as of yet. Any ideas?</li><br />
<li><b>Templates:</b> Templates are existing VHD files that you make available to your users. They can use these VHD files to create their own virtual machines.</li><br />
<li><b>ISO:</b> ISO files that your users can attach to their virtual machines.</li><br />
<li><b>Configs:</b> Where the user created virtual machines are stored.</li><br />
<li><b>Runtime:</b> Another option I haven't managed to figure out yet.</li><br />
</ul></BLOCKQUOTE></li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep1.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep1.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep1-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Step 2: Security/Administrators</b> page, delete the 2 sample rows, and then add your VSDM Administrators using the following parameters:<br />
<BLOCKQUOTE><ul><br />
<li><b>Primary:</b> This indicates the primary Administrator contact for the VSDM web site. Selecting this checkbox will cause <b>(primary)</b> to appear beside the administrator's link on the web site.</li><br />
<li><b>Contact:</b> Selecting this option causes the administrator to be listed on the VSDM web site.</li><br />
<li><b>Display Name:</b> The name of the administrator as it should appear on the VSDM web site.</li><br />
<li><b>Email:</b> The email address of the administrator. This will appear beside the administrator's name on the web site and will create a <b>mailto:</b> hyperlink.</li><br />
<li><b>Domain:</b> The domain containing the administrator's account.</li><br />
<li><b>User:</b> The administrator's account name.</li><br />
</ul><br />
</BLOCKQUOTE></li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep2.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep2.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep2-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Step 3: Security/Users</b> page, add any users and/groups that should be able to create new virtual machines or to manage existing machines that they own or have been granted permissions for, and then click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep3.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep3.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep3-thumb.PNG" width="311" height="233" border="0" /></a><br />
<BLOCKQUOTE><b>Note:</b> There seems to be another bug here that I hit consistently and that I've seen reported at least once in the public news groups. As soon as I click in the <b>Display Name</b> column below <b>Users(Domain/Users)</b> the installer throws an exception (see below). I can click <b>Continue</b> and, well, continue.<br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep3error.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep3error.php','popup','width=440,height=147,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep3error-thumb.PNG" width="220" height="73" border="0" /></a><br />
</BLOCKQUOTE><br />
<li>On the <b>Step 4: Security/Guests</b> page, add the users and/or groups that should be able to see or operate virtual machines for which they have been assigned permissions, and then click <b>Next</b>. Guests can only see and operate virtual machines. They cannot create or configure them.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep4.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep4.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep4-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Step 5: Security/Teams</b> page, add the users and/or groups that should be able to create new virtual machines or to manage existing machines that they own or have been granted permissions for, and then click <b>Next</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep5.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep5.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep5-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Step 6: Templates</b> page, add the existing VHD files which you want to make available to your users as templates for new virtual machines. Use the following parameters, and then click <b>Next</b>:<br />
<BLOCKQUOTE><ul><br />
<li><b>Disabled:</b> If selected prevents the template from being used to create new virtual machines.</li><br />
<li><b>ID:</b> ID number assigned to the template.</li><br />
<li><b>Name:</b> The name for the template as displayed on the VSDM web site.</li><br />
<li><b>Image Path:</b> The absolute path to the folder containing the VHD.</li><br />
<li><b>Image Name:</b> The file name, minus the .VHD extension of the VHD.</li><br />
<li><b>Description:</b> A brief description of the template. This appears along with the <b>Name</b> on the VSDM web page.</li><br />
</ul></BLOCKQUOTE></li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep6.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep6.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep6-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Step 7: CD/DVD ISO Images</b> page, add the existing ISO file which you want to make available to your users. ISO files listed here will be available to users to attach to the virtual machines they create. Use the following parameters, and then click <b>Next</b>:<br />
<BLOCKQUOTE><ul><br />
<li><b>Disabled:</b> If selected prevents the ISO from being attached to virtual machines.</li><br />
<li><b>ID:</b> ID number assigned to the ISO.</li><br />
<li><b>Name:</b> The name for the ISO as displayed on the VSDM web site.</li><br />
<li><b>Image Path:</b> The absolute path to the folder containing the ISO.</li><br />
<li><b>Image Name:</b> The file name, minus the .ISO extension of the ISO.</li><br />
<li><b>Description:</b> A brief description of the ISO. This appears along with the <b>Name</b> on the VSDM web page.</li><br />
</ul></BLOCKQUOTE></li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigstep7.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigstep7.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigstep7-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Save Changes</b> page, click <b>Finish</b>.</li><br />
<a href="http://www.identit.ca/blogs/paul/images/vsdmconfigdone.php" onclick="window.open('http://www.identit.ca/blogs/paul/images/vsdmconfigdone.php','popup','width=622,height=467,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.identit.ca/blogs/paul/images/vsdmconfigdone-thumb.PNG" width="311" height="233" border="0" /></a></p>

<p><li>On the <b>Installation Complete</b> page, click <b>Close</b>. The installation of VSDM is now complete.</li><br />
</ol></BLOCKQUOTE></p>

<p><b>Note:</b> If you want to make any changes to either the VSDM IIS configuration, or to the VSDM XML configuration after the installation is complete, you can rerun either of the configuration wizards from the <b>VSDM - Virtual Server Deployment Manager</b> menu You can also edit the XML configuration file directly by using an XML editor (or even Notepad).</p>

<p>To start using VSDM, open a browser and then open either the VSDM web site, or the VSDM virtual directory, depending on which option you chose during the installation. Stay tuned for documentation on how to use VSDM.</p>

<p>Questions or comments? Please leave a comment!</p>]]>
</content>
</entry>
<entry>
<title>Microsoft Windows Rights Management Services (RMS) with Service Pack 1 (SP1) Released</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/microsoft_windo.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-19T09:18:11Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.55</id>
<created>2005-04-19T09:18:11Z</created>
<summary type="text/plain">RMS SP1 has been released and is available for download from here. SP1 introduces some significant changes for RMS and if you&apos;re working on a deployment of RMS, or if you&apos;ve already deployed it, you really should start evaluating and...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Windows Rights Management Services</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>RMS SP1 has been released and is available for download from <b><i><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=8EF6D80A-6A9C-4FB9-AB51-790980816FFE&displaylang=en" target="_blank" title="RMS SP1 Download">here</a></i></b>. SP1 introduces some significant changes for RMS and if you're working on a deployment of RMS, or if you've already deployed it, you really should start evaluating and working with SP1 right now. The product team has done a great job at making the deployment of SP1 pretty painless and because of their efforts it is entirely feasible to stage the SP1 deployment as you see fit. SP1 and RTM can peacefully coexist.<br />
I'll talk some more about the changes in SP1 in the near future, but for now here are the top 10 reasons (from Microsoft) to download and install SP1 now:<br />
<ul><li>No longer requires an Internet connection for deployment; RMS SP1 runs in air-gap networks?in other words, networks with no Internet connection.</li><br />
<li>Enables third parties to integrate RMS information protection into server-based applications?such as records and document management, e-mail gateways, and e-mail archival systems?for comprehensive information security platform.</li><br />
<li>Smart card integration for an additional layer of security.</li><br />
<li>Compliance with Federal Information Processing Standards (FIPS).</li><br />
<li>Eases deployment rollout with familiar Microsoft technologies?for example, Microsoft Systems Management Server (SMS).</li><br />
<li>Dynamic role-based security enables RMS policies to be applied based on dynamic groups and defined by queries of Microsoft Active Directory for certain attributes.</li><br />
<li>Supports Virtual PC for cross-platform support.</li><br />
<li>Streamlined authentication process for RPC over HTTP provides better end-user experience.</li><br />
<li>Support for phased deployment of RMS SP1 in v1 environments.</li><br />
<li>Enhanced tools and guidance with RMS SP1 Toolkit.</li></ul><br />
</p>]]>

</content>
</entry>
<entry>
<title>Virtual Server Deployment Manager 1.3.0 (VSDM)</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/virtual_server_1.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-17T10:27:14Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.52</id>
<created>2005-04-17T10:27:14Z</created>
<summary type="text/plain">Microsoft has released a new tool, the Virtual Server Deployment Manager (VSDM) that can help those of you who use Virtual Server 2005 in shared development and testing environments. One of the really cool things about this tool is that...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Microsoft has released a new tool, the Virtual Server Deployment Manager (VSDM) that can help those of you who use Virtual Server 2005 in shared development and testing environments. <br />
One of the really cool things about this tool is that it allows normal non-administrative users to manage their own virtual machines.<br />
You should think of VSDM as a resource kit tool in that it is offered for use without any official support. However, I am working with the developer of the tool (install the tool and you'll see who the developer is <g>) and will be posting some unofficial documentation to my blog. I hope to have it all done today, however, that may not happen. At a minimum I'll be documenting the installation process today (though if the developer isn't working on a Sunday, there may well be a small gap or two).<br />
VSDM can be downloaded by clicking <b><i><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=FF59C543-5107-42F6-9252-A8CDE3B53915" target="_blank" title="VSDM Download">here</a></i></b>.</p>

<p>You can find the home page for VSDM by clicking <b><i><a href="http://blogs.msdn.com/nelson_araujo/archive/category/9970.aspx" target="_blank" title="VSDM Home Page">here</a></i></b>.</p>

<p>Finally, <a href="http://blogs.technet.com/jhoward/default.aspx" target="_blank" title="John Howard's Blog"><b><i>John Howard</i></b></a>, an IT Evangelist with Microsoft UK, and<a href="http://blogs.technet.com/megand/default.aspx" target="_blank" title="The Soul of a Virtual Machine"><b><i> Megan Davis</i></b></a>, a technical writer on the Windows Server User Assistance team will more than likely be blogging about this tool as well. Even if they aren't their blogs are both definitely worth checking out.</p>

<p>Stay tuned for documentation.<br />
</p>]]>

</content>
</entry>
<entry>
<title>New Virtual Server e-Learning Course</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/new_virtual_ser.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-14T09:06:26Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.37</id>
<created>2005-04-14T09:06:26Z</created>
<summary type="text/plain">Microsoft Learning has released an eLearning course on Virtual Server: Title: Course 2288: Using Microsoft&amp;#174; Virtual Server 2005 Course Type: Self-paced Course Available Offline: Yes Estimated Time of Completion: 5 Hours Description: This course prepares students to migrate legacy applications...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Microsoft Learning has released an eLearning course on Virtual Server:<br />
Title: Course 2288: Using Microsoft&#174; Virtual Server 2005<br />
 Course Type: Self-paced Course<br />
 Available Offline: Yes<br />
 Estimated Time of Completion: 5 Hours<br />
 Description: <br />
This course prepares students to migrate legacy applications and consolidate server functions by using Microsoft Virtual Server 2005.<br />
 Objectives: <br />
At the end of the course, students will be able to: <br />
<ul><li>Install and configure Virtual Server 2005.</li><br />
<li>Configure virtual machines on Virtual Server 2005.</li><br />
<li>Migrate applications and servers to virtual machines.</li></ul></p>

<p>Visit <a href="https://www.microsoftelearning.com/eLearning/offerDetail.aspx?offerPriceId=62154" target="_blank">https://www.microsoftelearning.com/eLearning/offerDetail.aspx?offerPriceId=62154</a> for more information.</p>]]>

</content>
</entry>
<entry>
<title>Microsoft&apos;s Virtualization Support Policies Updated</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/microsofts_virt.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-14T00:15:22Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.36</id>
<created>2005-04-14T00:15:22Z</created>
<summary type="text/plain">Today Microsoft published three new Knowledgebase articles that are significant to those who are using, or are thinking about using virtualization technologies. The first of these articles, Microsoft Virtual Server Support Policy (897613) lays out Microsoft&apos;s support policies for Windows...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Today Microsoft published three new Knowledgebase articles that are significant to those who are using, or are thinking about using virtualization technologies.<br />
The first of these articles, <a href="http://www.support.microsoft.com/kb/897613" target="_blank" title="Microsoft Virtual Server Support Policy">Microsoft Virtual Server Support Policy (897613)</a> lays out Microsoft's support policies for Windows Server System software running in Virtual server virtual machines. This article basically states that all Windows Server System software is supported in a Virtual  Server environment with the exception of the software listed in the second of the three articles.  In addition, this article points to several server consolidation Solution Accelerators  (including the one that one of <a href="http://www.identit.ca/blogs/paul/2005/03/vs_and_vpc_at_t.php" target="_blank">my TechEd sessions</a> is based on).<br />
The second article, <a href="http://www.support.microsoft.com/kb/897614/" target="_blank" title="Windows Server System software not supported within a Microsoft Virtual Server environment (897614)">Windows Server System software not supported within a Microsoft Virtual Server environment (897614)</a> lists the Windows Server System software that is not currently  supported in a Virtual Server environment. the list is surprisingly short, with only 5 items on the list, and one of those, Certificate Services,  is actually supported given Windows Server SP1 .<br />
 The final article, <a href="http://www.support.microsoft.com/kb/897615" target="_blank" title="Support policy for Microsoft software running in non-Microsoft hardware virtualization software (897615)">Support policy for Microsoft software running in non-Microsoft hardware virtualization software (897615)</a> supersedes articles 273508 and 320220 and updates and clarifies the support policy for virtual environments such as VMWare.</p>]]>

</content>
</entry>
<entry>
<title>Virtual Server MOM Management Pack Released</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/virtual_server.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-13T23:53:50Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.34</id>
<created>2005-04-13T23:53:50Z</created>
<summary type="text/plain">The long anticipated MP for Virtual Server 2005 has finally been released and is available for download. I&apos;ll be testing this MP over the next week or so and will share my results here when I get a chance....</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>The long anticipated MP for Virtual Server 2005 has finally been released and is available for <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=B8BBF08F-134A-46CE-9D63-FB7EF5258059&displaylang=en" target="_blank" title="VS MOM MP">download</a>.<br />
I'll be testing this MP over the next week or so and will share my results here when I get a chance.<br />
</p>]]>

</content>
</entry>
<entry>
<title>Finally back up and running!</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/finally_back_up.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-13T22:46:25Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.33</id>
<created>2005-04-13T22:46:25Z</created>
<summary type="text/plain">Some of you may have noticed that I haven&apos;t made any entries since April the 7th. Although I&apos;ve been busy, that isn&apos;t why I haven&apos;t blogged for a while. It seems that my hosting provider made some changes to my...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>General</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>Some of you may have noticed that I haven't made any entries since April the 7th.  Although I've been busy, that isn't why I haven't blogged for a while. It seems that my hosting provider made some changes  to my server and these changes broke MovableType.  My blog itself has been accessible, I just haven't been able to make any changes to it.  Without going into the gory details this has been a very frustrating experience which fortunately seems to have been resolved.<br />
 So, I'm back!</p>]]>

</content>
</entry>
<entry>
<title>Time Synch Between Guests and Hosts</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/time_synch_betw.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-07T11:47:24Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.32</id>
<created>2005-04-07T11:47:24Z</created>
<summary type="text/plain">A very common request in the public news groups is, &quot;How can I disable the time synch between guests and the hosts OS? &amp;#60;insert any number of varied reasons why this needs to be disabled&amp;#62;. One of the big problems...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Virtual Server and Virtual PC</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>A very common request in the public news groups is, "How can I disable the time synch between guests and the hosts OS? &#60;insert any number of varied reasons why this needs to be disabled&#62;. One of the big problems with the way time synch is implemented in both Virtual PC 2004 and Virtual Server 2005 is that it doesn't respect time zone differences between the guest and the host. What exactly do this mean? Well, say for example the your host is set to Eastern Standard time (UTC -5) and one or more of your guests are set to Pacific Standard time (UTC -8) and that the current time on the host is 11:00 AM EST. This means that the time in PST should be 8:00 AM PST (3 hours earlier). When the time is synched between the guest and the host, VS and VPC don't take into account the fact that the time zones require a delta of 3 hours and the time in the guest will be set to 11:00 AM, which means that it will be off by 3 hours. This can cause all kinds of problems, for example Kerberos authentication issues if both your guests and your host are in the same Active Directory domain. As I mentioned above, there are a number of other reasons why you may want to disable the time synch, this is just one example.<br />
Disabling the time synch in Virtual Server 2005 is very easy. Simply open the VS Administration web site, edit the configuration of the virtual machine in question, on the Status page, click the <b>Virtual Machine Additions</b> link, and then clear the <b>Host time synchronization</b> check box. Note that the virtual machine needs to be completely shut down in order to make this change. If the guest is running, or is in a saved state, the check box will be disabled.<br />
In Virtual PC 2004 disabling the time synch is more involved as there is nothing in the GUI that allows this change to be made. It is important to understand that time synch occurs in two different ways; any time you boot a guest it synchs time with the host, and periodically while the guest is running (if you have the additions installed) it also synchs time with the host. Completely disabling time synch in the guest requires two changes in VPC:<br />
<ol><li>In the guest, you need to disable the Virtual Machines Additions Services Application service. This can be done through the Services console. Note that disabling this service does not impace the performance gains you receive when the additions are installed, nor does it affect the additional display capabilities provided by the additions. In all of my testing, the only impact this has is on the time synch. Of course, you should test this as YMMV.</li><br />
<li>Edit the .VMC file used by the guest</li><br />
</ol></p>

<p>The .VMC files used by the guests are XML format files that contain configuration information specific to each guest. <b>NOTE:</b> I <b><i>strongly</i></b> suggest that you make a copy of your .VMC file before attempting to make any manual changes to it. Also, make sure that the guest is shutdown. You can use any text editor to make these changes.<br />
You need to add some XML tags to this file, and it is important that they be added in the correct location. The new tabs need to be added to the integration/microsoft portion of the tree and it is important that you add the tags to the existing tree and that you do not create a new tree. Here are the steps to make this change:<br />
<ol><li>Open the .VMC file in a text editor and search for &#60;integration&#62;.</li><br />
<li>The should be only one &#60;integration&#62; string in the file, and it should be immediately followed, on a new line, by &#60;microsoft&#62;.</li><br />
<li>Directly below the &#60;microsoft&#62; tag, add the following tags, each tag on a new line:</li><BLOCKQUOTE><br />
&#60;components&#62;<br />
&#60;host_time_synch&#62;<br />
&#60;enabled type="boolean"&#62;false&#60;/enabled&#62;<br />
&#60;/host_time_synch&#62;<br />
&#60;/components&#62;<br />
</BLOCKQUOTE><br />
<li>Save the file and start your guest</li><br />
</ol></p>

<p>Time synch between the guest and the host will now be disabled.<br />
Note that this is obviously not the optimal solution. I'd like to see two things in future versions:<br />
<ol><li>A GUI based method to disable time synch in VPC</li><br />
<li>Have the time synch process respect the time zone differences between the guests and the host. Ideally this would be a configurable option as I can anticipate some situations where this would be useful and some where it would not be desirable</li><br />
</ol></p>

<p>One final caveat here. You may well find that disabling the time synch feature means that your guests loose time (after all, there is a reason that the time synch feature is in the products in the first place). You should thouroughly test the effect that disabling this feature has before deciding on whether or not it is the right way to go.<br />
If you have any questions, please feel free to add a comment to this entry.</p>]]>

</content>
</entry>
<entry>
<title>Microsoft Identity Management Server (MIIS) Sessions at TechEd</title>
<link rel="alternate" type="text/html" href="http://www.identit.ca/blogs/paul/2005/04/microsoft_ident.php" />
<modified>2006-04-19T21:54:13Z</modified>
<issued>2005-04-06T10:10:26Z</issued>
<id>tag:www.identit.ca,2005:/blogs/paul//1.31</id>
<created>2005-04-06T10:10:26Z</created>
<summary type="text/plain">So it looks like I&apos;m going to be rather busy at TechEd in Orlando this year (guess I can leave my golf clubs at home :-)). I just picked up my third session, this one on cross-platform password management with...</summary>
<author>
<name>Paul Adare</name>

<email>pkadare@identit.ca</email>
</author>
<dc:subject>Identity Management</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.identit.ca/blogs/paul/">
<![CDATA[<p>So it looks like I'm going to be rather busy at TechEd in Orlando this year (guess I can leave my golf clubs at home :-)). I just picked up my third session, this one on cross-platform password management with MIIS. The session number and title is <b>SVR327: Cross-Platform Password Management with Microsoft Identity Integration Server 2003 (MIIS)</b>. Here is the abstract for the session:<br />
<i>With MIIS 2003 SP1, password management has become a first class citizen of the lifecycle management. In this session, we discuss how MIIS can be used to secure accounts from provisioning to de-provisioning, how passwords can be managed in any identity store, how to synchronize passwords changed by the user from his Windows desktop to any identity store managed by MIIS, and how users can manage passwords for systems that do not participate in password synchronization through a Web portal. In addition, get a preview of a new end user password self-service reset tool that we will ship in a future release of MIIS.</i></p>

<p>MIIS has a pretty big presence at TechEd this year as you can tell from the following list of sessions and hands-on labs that either cover MIIS directly, or at least mention MIIS in the abstract:<br />
<ul><li>CSI200  (Strategic Briefing Session) Connected Systems: Applications of the Future (session)</li><br />
<li>CSI322  Identity Integration Using Host Integration Server and BizTalk Server (session)</li><br />
<li>SEC04  Using Microsoft Identity Integration Server to Synchronize User Identity Information and Credentials (lab)</li><br />
<li>SRV04  Microsoft's Identity Management Solution (session)</li><br />
<li>SRV05  Developing Management Agents with the Identity Integration Server 2003 Management Agent Software Development Kit (lab)</li><br />
<li>SVR210  Enforce Endpoint Health Policy with Network Access Protection (NAP) (session)</li><br />
<li>SVR215  Microsoft Identity Integration Server 2003: What's New in Microsoft Identity Integration Server 2003 SP1, Futures and Roadmap (session)</li><br />
<li>SVR220  Microsoft's Identity Management Strategy and Roadmap (session)</li><br />
<li>SVR304  Server Migration Chapter One: Novell Netware and NT 4 Migration Planning (session)</li><br />
<li>SVR317  Microsoft IT: Managing Identity Lifecycle, Consistency and Self-Healing with MIIS (session)</li><br />
<li>SVR318  Developing Solutions on the Microsoft Identity and Access Platform (Part 1) (session)</li><br />
<li>SVR322  Providing Web SSO and Identity Federation Solutions Using Active Directory Federation Services Windows Server 2003 R2 (session)</li><br />
<li>SVR323  Active Directory Federation Services Architecture Drilldown (session)</li><br />
<li>SVR324  Deploying Web SSO and Identity Federation Solutions Using Active Directory Federation Services: Scenarios and Strategies (session)</li><br />
<li>SVR325  Identity Lifecycle Management Using Microsoft Identity Integration Server 2003 (MIIS) (session)</li><br />
<li>SVR326  How to Build a Self-Service Application Using Microsoft Identity Integration Server 2003 (MIIS) (session)</li><br />
<li>SVR328  Microsoft Identity Integration Server 2003 Deployment Best Practices (session)</li><br />
<li>SVR400  Developing Solutions on the Microsoft Identity and Access Platform (Part 2) (session)</li><br />
</ul><br />
If you can't make a session, or if you have additional questions, feel free to drop by the cabana area.</p>]]>

</content>
</entry>

</feed>