Data padding is a cryptographic technique used by asymmetric algorithms to protect against attacks that rely on the unencrypted text being simple. The .NET Framework supports two padding schemes for the RSA algorithm: Optimal Asymmetric Encryption Padding (OAEP) and PKCS #1 v1.5. Generally, use OAEP, because it is newer and more secure than PKCS. Use PKCS only when you are communicating with a legacy client that you know does not support OAEP. Currently, all Windows operating systems released prior to Windows XP lack support for OAEP, including Windows 2000. The most challenging aspect of encryption is converting data into the byte array format. To convert strings to byte arrays, use the System.Text.Encoding.Unicode.GetBytes and System.Text.Encoding.Unicode.GetString methods. For example, the following console application encrypts a string using PKCS#1 v1.5 data padding, and then immediately decrypts and displays the string:
Lessons in this chapter:
Failover. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421
Windows 7 Power Configuration Power plans are collections of settings that specify how a computer running Windows 7 uses energy. A new computer running Windows 7 comes with three power plans named High Performance, Balanced, and Power Saver. Many original equipment manufacturers (OEMs) also supply their own custom Windows 7 power plans that they may precisely optimize for a specific hardware configuration. In general, the High Performance power plan allows hardware to run at its maximum speed but uses more energy, and the Power Saver plan configures hardware devices in such a way that they use less energy with a corresponding reduction in performance. When a portable computer is running on battery power, it runs for a shorter amount of time before the battery drains completely when configured to use the High Performance power plan compared to when the same computer is set to use the Power Saver power plan. You can use the Power Options control panel, shown in Figure 11-26, to select a power plan for a client running Windows 7. The default power plan for a newly installed client running Windows 7 is Balanced.
Outlook Anywhere allows clients using Microsoft Outlook 2007 and Outlook 2003 to access Exchange Server 2007 using the RPC over HTTP protocol. The primary benefit of using Outlook Anywhere is that it simplifies the configuration of remote access to Exchange. Access can be granted without having to use VPN connections, and rules allowing the quick setup of RPC over HTTP access to Exchange are built into Internet Security and Acceleration (ISA) Server, Microsoft s firewall and proxy product. Outlook Anywhere can be enabled by clicking on Enable Outlook Anywhere on the Actions pane when the Client Access role is selected under the Server Configuration node. When configuring Outlook Anywhere, you need to specify the external host name, the authentication type, and whether you want to allow SSL offloading. The authentication options are Basic and NTLM with the option to use SSL offloading. SSL offloading allows you to use an SSL accelerator device to assist with the processing load involved in encrypting network connections to the Client Access server, as shown in Figure 2-21. You should not enable SSL offloading unless your server has an SSL accelerator device, as this can cause connection problems.
You can configure Parental Controls for a standard account but not for an administrator account. You can limit logon hours and control access to websites, games, and executable programs on a per-user basis. You can also generate and view activity reports. You can use Content Advisor to control website access for all users. IE7+ allows you to contribute to news feeds and provides aggregator functions that update news feeds automatically and let you read them offline. You can use the Print Preview and Page Setup controls to configure how a webpage appears when you print it out and to configure the webpage headers and footers. You can enter variables in the Page Setup dialog box that control the content and format of the page headers and footers. You can configure the IE7+ Search Bar by adding search providers and specifying defaults.
Key Terms
TCP Port 135 %WINDIR%\SYSTEM32\Sessmgr.exe %WINDIR%\PCHealth\HelpCtr\Binaries\Helpsvc.exe %WINDIR%\PCHealth\HelpCtr\Binaries\Helpctr.exe
Avg. Page Density (full) Shows how filled the pages are. Scan Density Shows the ratio between the Best Count of extents that should be necessary to read when scanning all the pages of the index and the Actual Count of extents that were read. This percentage should be as close to 100 as possible. Values less than 75 percent indicate serious external fragmentation. Logical Scan Fragmentation
Resolving Lost Passwords for Local User Accounts
Lesson 3: Supporting User Objects and Accounts
Lesson 2: Using soapExtensionTypes
Virtual private networking allows secure remote access to resources on an organization s internal network for users outside the network. The VPN is a virtual network that enables communication between a remote-access client and computers on the internal network or between two remote sites even though the computers might be in different locations and separated by a public network such as the Internet. ISA Server 2004 supports two VPN tunneling protocols: Point-to-Point Tunneling Protocol (PPTP) and Layer Two Tunneling Protocol with Internet Protocol security (L2TP/IPSec). PPTP uses Point-to-Point Protocol (PPP) user authentication methods and Microsoft Point-to-Point Encryption (MPPE) to encrypt IP traffic. L2TP/IPSec uses PPP user authentication methods and IPSec encryption to encrypt IP traffic. ISA Server 2004 supports a variety of VPN authentication protocols. Whenever possible, you should use MS-CHAP version 2 or Extensible Authentication Protocol (EAP). VPN quarantine control allows you to scan the VPN client computer configuration before allowing it access to the organization s network. You can use VPN quarantine control to prevent remote access to a private network until a client-side script validates the remote-access client configuration. ISA Server supports two types of VPN connections: remote-client access VPN connection, and site-to-site VPN connections. When you enable VPN access on ISA Server, it uses the VPN Clients network, the Quarantined VPN Clients network and remote site networks to filter network traffic. Implementing a VPN infrastructure must be planned carefully because you are deliberately exposing your internal network to the Internet. For the highest level of security, implement the most secure authentication and tunneling protocols possible.
C. Restoration of backup sets can always be done by members of the Administrators
Figure 6-24
Further, you needn t worry about users. If you are using a different namespace internally, but you want them to log on with the external network name, for example,, just add it as the preferred user principal name (UPN) suffix in your directory. DNS will be simpler to manage, your internal network will be protected from external access, and your users won t know the difference!
