So you want to be a consultant…

Earlier today I posted a link to Steve Friedl’s illustrated guide to IPSec. Steve’s site has a whole load of technical tips, but one item I stumbled across was his extremely interesting review of consultancy practices (subtitled as “Why work 8 hours/day for someone else when you can work 16 hours/day for yourself?”).

As an IT consultant (albeit one employed by a global IT services organisation), married to a PR consultant, I can really relate to some of Steve’s consulting maxims, the most pertinent of which I’ve quoted below:

  • “‘Trust’ is your best job security”.
  • “You are primarily in the customer service business, not the technical business”.
  • “For a good consultant, your voice is comforting: Be very easy to find”.
  • “The best way to appreciate the value of a good [specification] is to do a project without one”.
  • “Customers hate ‘unhappy surprises’ much more than ‘timely bad news'”.
  • “Ongoing business is much more important than maximizing every billable hour” (which goes hand in hand with “hourly arrangements of any substantial magnitude require that you have earned your customer’s trust”).
  • “It’s better to give away some time than to throw away your reputation” (but remember “if the customer doesn’t know you did work off the clock, you don’t get credit for it”).
  • “Detail is comforting to a customer”.
  • “If you routinely take ownership for your own mistakes, you’re much more likely to be believed when you claim something is not your doing”.
  • “Your best advertisement is publishing of original, technical content”.
  • “It’s a huge asset to communicate well – cultivate this skill vigorously”.
  • “Your references are your reputation in the consulting world”.
  • “The customer is not always right”.
  • “The Internet never forgets: don’t provide dirt for your future”.
  • “If you’re booked up solid, your rates are too low”.
  • “Your long-term customers are your best customers”.
  • “The best way to make a lot of money is to make your customers a lot of money”.
  • “You must know how to read your customer”.
  • “Your customers are buying your judgment, not just your time”.
  • “Being known for your integrity is the Holy Grail of consulting”.

He also makes some useful observations on technical skills and certification:

“Your references and your experience are far more important than your certifications. What counts here is truly learning the subject matter, and there is no harm in obtaining the certificate in the process. But if the goal is just to collect some paper, it leads to the prototypical computer jockey with lots of alphabets after his name but limited power in the driver’s seat.

Where the skills question gets tricky is when getting outside your comfort zone: a customer will ask you about a project that you are almost, but not quite, qualified for. Surprisingly, this happens a lot: if you have conducted yourself well, your customer would rather find a way to use you – a known quantity – than find somebody else. This occurs over a fairly wide range of skills.

When considering one of these projects, the first rule is: never lie to your customer about your skills. Be completely candid with your customer about what you know and how you would address the project. This would likely include substantial off-the-clock time as you got up to speed on the technology in question.”

Well worth a read for any consultant (whether self employed or not) and for any customers who employ consultants too!

An introduction to IPSec

I’ve been meaning to write something about Internet protocol security (IPSec) ever since I heard Steve Lamb talk about it a few months back but Owen Cutajar blogged about Steve Friedl’s Illustrated Guide to IPSec a few days back which gives a much better description than I ever will! Steve’s site has a whole load of useful technical tips, but as his URL might give away, he comes at things from a UNIX perspective.

For Windows users who are interested in implementing IPSec, I recommend that you read both Steve Lamb’s blog and Steve Friedl’s Illustrated Guide to IPSec, but what follows is a brief description of some high-level concepts which might help to put it all into context.

Although it sounds complex, symmetric key cryptography is a very basic method of encrypting messages (e.g. DES or AES/Rijndael) using a shared secret. The plain text input is encrypted to produce cipher text which is transmitted to the intended recipient, who can then decrypt it to produce plain text output. An example of such a mechanism is the Caesar shift, whereby characters are shifted by a known number of places (the shared secret), so that for example if the shared secret is 3, A becomes D, B becomes E, and so on. Symmetric key cryptography is simple, and fast, but relies on some form of mechanism for exchanging keys (shared secrets).

Symmetric key cryptography

Public key cryptography is an asymmetric encryption mechanism, whereby knowledge of the encryption key doesn’t provide the methods to decrypt the message. The recipient of the message generates a pair of keys (using a certificate authority) and publishes the public key in a directory so that anyone can send them encrypted messages that only they can read. This pair of keys is actually a single key split mathematically using a one-way algorithm (i.e. one which current mathematics does not allow to be reversed). When sending a message, it is encrypted with the recipient’s public key and they can decrypt it (using their private key). Unfortunately even this method has its weaknesses as it is slow, subject to what is known as a “known ciphertext” attack and requires the public key to be trusted (i.e. to be from a known certificate authority).

Asymmetric key cryptography

The real-world answer is often a hybrid encryption process whereby a symmetric session key is encrypted using the recipient’s public key and then, once this key has been decrypted by the recipient (using their private key), they can read messages encrypted using the session key. The session key is transmitted with the encrypted message as a digital envelope. Once the message exchange is complete (whether that is literally the transfer of a message, or a communication session) the session key is disregarded (i.e. its life is finite – dictated by the length of the session).

IPSec is used to authenticate and/or encrypt TCP/IP communications, securing either specific ports or all IP traffic and is obligatory for IPv6.

In an Active Directory environment, IPSec is generally configured via group policy and both the client and the server must be configured. No reply is issued to rejected packets – they are simply dropped. Installing a certificate authority (CA) is a simple process (although because a lot of the configuration is wizard-based, it can be difficult to appreciate exactly what has been done). Windows Server 2003 Certificate Services allows a hierarchy of CAs to be implemented (generally with the root CA kept offline once the hierarchy is established) as well as adhering to public key standards from RSA, Entrust and Verisign (licensed by Microsoft to avoid any per-certificate cost issues). Once a certificate has been issued the client no longer needs to communicate with the CA. Of course, internal CAs are only suitable for internal use of IPSec (a trusted CA needs to be used for securing traffic across the Internet).

One of the advantages of IPSec is that, because it works at the network layer, it can be used to provide secure data transfer without affecting applications; however the downside is that architects (or administrators) should carefully consider the impact that encrypting all traffic would cause as some security software (e.g. intrusion detection systems) will no longer function.

Service packs, feature packs and releases – how they should work

The various Microsoft product groups issue service packs, feature packs and releases. This is all very well, but they mean different things to different people and are confusing. Then, last Friday, Paul Thurrott reported in the Windows IT Pro magazine network WinInfo Daily Update that Virtual Server 2005 SP1 will now become Virtual Server 2005 release 2 (R2). This might sound like a trivial name change but what it means for legal users of Virtual Server 2005 (a basically good product, but with a few fairly significant bugs), they will need to purchase R2, rather than install a free service pack.

If Microsoft follows this path they are going the way of Apple, who issue point version upgrades to their OS X operating system and have the audacity to charge existing users for a full product (there is no upgrade available).

In my opinion:

  • Service packs should fix bugs (security or otherwise) and that critical patches should be released in advance of a rolled-up, regression tested, service pack. Ideally service packs should also have a predictable timescale (e.g. 6 months after product release then every 12 months from then on until the product reaches end of life).
  • Feature packs should offer new features for an established product. I don’t believe that there should have been any additional features included with Windows XP SP2 (e.g. the Windows Firewall) – instead SP2 should have been a set of bug fixes (alleviating some of the deployment issues associated with new technology) and additionally Microsoft should have offered a free feature pack for Windows XP which provided the extra security features. In this way, users can stay at the latest supported product release (service pack level) but choose which feature packs to add. Security features and other important updates should be free of charge. Others which enhance a product might carry a small charge.
  • Mid-life releases (e.g. Windows Server 2003 R2) are all very well as a marketing mechanism for rolling the latest service packs into a product for new users, but should not preclude existing users from gaining from the latest service pack/feature pack updates. If a product really warrants a new licence, then it should carry a new (major) version number!

Following this model, Virtual Server 2005 R2 should really be a service pack and there should be an additional feature pack for the new features which Microsoft plans to ship (of which there are precious few details at present). As for supporting Linux as a guest operating system – it either works or it doesn’t – Microsoft needs to make up it’s mind as to whether it is a supported guest or not (if they are smart they will say “yes” – that way users can have a virtual Linux guest running on a Windows host if they need the best of both worlds, with Microsoft still gaining licence revenues for the host operating system and the virtualisation software).

Missing disk space

A few months back, I was chatting with my Dad about his PC (you know, one of those “family IT support desk” jobs) and he was wondering what had happened to all of his hard disk space. David Chernicoff has written an article for Windows IT Pro magazine about the case of the missing disk space and it’s worth a read. I certainly found it interesting – especially the bit about true sizing cf. disk manufacturers’ idea of storage units.

Having trouble accessing a recently installed instance of MSDE? Make sure the MSSQLSERVER service is started!

I just spent ages trying to work out why I couldn’t access the Microsoft SQL Server Desktop Engine (MSDE) instance that an application had just installed… it may sound obvious, but make sure the MSSQLSERVER service is started!

In my defence, if an application requires a server or service restart after installation, I expect it to tell me that’s what it needs, but the version of MSDE 2000 SP3A downloaded by Altiris Notification Server 6.0 didn’t seem to do that. I had similar problems a few weeks back whilst playing around with Community Server. On both occasions, I though it might be a problem with my security credentials so I downloaded the SQL Server Web Data Administrator but that couldn’t access the database either. It was only once I’d checked that all the MSDE services were running (MSSQLSERVER was not) that everything jumped into life.

Another tip whilst I’m on the subject – MSDE 2000 SP3A requires a strong password to be set for the sa user. If using a repackaged version of MSDE (as I was), try extracting the package and examining the setup files to find the SA password that has been set as part of the application installation (e.g. using the SAPWD= option for setup.exe).

Great mobile handset – shame about the connectivity software

Notwithstanding the fact that last month I wrote about how I’d finally found a use for a camera phone, my preferred feature list for a mobile handset is quite simple:

Other features I might use are a loudspeaker (handsfree) mode and GPRS; but whilst camera, FM radio, and even MP3 player are nice to haves, they are by no means essential. As for smartphones, I have a Nokia 6600 but I’ve barely scratched the surface on its capabilities (mostly because I’m scared of running up huge bandwidth usage costs on my personal account).

For a long time now, the standard handset given out to most corporate users in the UK has been the Nokia 6310i. For a while it was the Nokia 6810, but my new work phone is a Nokia 6021 and I love it!

Nokia 6021

Meeting all of my ‘A list’ criteria above, the 6021 is the perfect phone for me but I had some fun and games trying to get it to synchronise my contact details with Microsoft Outlook. Once I worked out how to turn on the Bluetooth functionality within my Fujitsu Siemens Lifebook S7010D, I could get the phone to communicate with the PC via Bluetooth, but although the Nokia PC Suite (v6.5.12) seemed to detect the phone, I couldn’t get the Nokia PC Sync utility to recognise the Bluetooth connection.

After spending ages creating and breaking down Bluetooth pairings between the phone and my laptop, I finally gave up, remembering that I had the same issue with my 6310i too and that IrDA seemed to work every time. Sure enough, an IrDA connection did the trick but the whole point about a Bluetooth-enabled phone is that I can synchronise my phone and my laptop without having to activate IrDA and set up a line of sight connection.

Come on Nokia – you’ve produced a great phone – now how about some decent connectivity software to go with it…

Making IE 7 look like IE 6 to get around website restrictions

I just picked this up via Rory Street and although I haven’t tried it, it certainly looks interesting for those who are having problems accessing websites which check the browser version when using the Internet Explorer (IE) 7.0 beta…

Mark Harrison has a post on his blog which talks about changing the IE7 user agent string so that websites think you are using IE6 (a tip from the IEBlog). He also has links to scripts to switch the associated registry setting.

Microsoft solution accelerator for business desktop deployment (BDD) v2.5 released

Thomas Lee reports that Microsoft have released updated versions of the business desktop deployment (BDD) enterprise edition and standard edition solution accelerators.

As he provided my BDD training, Thomas knows far more on the topic than I do and his blog carries details of the improvements in BDD v2.5.

If BDD is a mystery to you, check out my post from earlier in the year about the Microsoft solution accelerator for business desktop deployment, the Microsoft solutions framework and the Microsoft operations framework.

Looking at what’s coming in BizTalk Server 2006

I’m not a BizTalk Server expert (by any stretch of the imagination), but I do know the concepts behind the product. Just before I left Conchango, I had the opportunity to attend a session delivered by Sue MacDermott (a technical pre-sales specialist with Microsoft UK) where she outlined the new features in the next release – BizTalk Server 2006 – currently scheduled for en early 2007 release. Some of what I was told is covered by a non-disclosure agreement (NDA), but the information below is in the public domain.

BizTalk Server 2006 is not a major release – Microsoft’s current cycle is for a major release every four years and an incremental release in between, so from that we can expect to see the next major BizTalk release, making use of the Windows communication foundation (codenamed Indigo), to be released in early 2008.

It is a common misconception that BizTalk Server 2006 will be released this November, at the same time as Visual Studio 2005 (codenamed Whidbey) and SQL Server 2005 (codenamed Yukon). In fact, it is expected that BizTalk Server 2006 will be officially launched at the same November 7th event, but the only product available at that time is expected to be beta 2. At the time of writing, Microsoft expect to provide a release candidate in the new year, before the product is finally released in the spring.

The reason for the delay (and the 2006 moniker, whereas SQL Server and Visual Studio are both 2005 products) is that there is a dependency on some of the 2005 technologies that are being released in November – namely Visual Studio 2005 and the Microsoft .NET Framework v2.0. There are no hard dependencies on SQL Server 2005, and BizTalk Server 2006 can used either SQL Server 2000 or 2005, but Microsoft did say that initial testing has indicated significant performance improvements when run on the latest SQL Server build (one of my former colleagues at Conchango indicated this may be as much as 30% faster).

Detailing all of the enhancements in BizTalk Server 2006’s is too much for a single blog post, (and in any case, much of the information should soon be available from Microsoft) but the main improvements are across the following areas:

  • Management and operations, introducing the concept of a BizTalk application which groups related components such that the administrator’s view can match the application architecture.
  • Business user empowerment with real-time alerting and notification, a business activity monitoring (BAM) portal and deeper Windows SharePoint Services (WSS) integration.
  • Windows server system integration (with support for SQL Server 2005, Visual Studio 2005 and the Microsoft .NET Framework 2.0, Virtual server 2005 the 64-bit versions of Windows Server 2003).
  • Setup, upgrade and deployment, with a new installer which checks for dependencies (split into mandatory “T1” items, which will block installation if they are missing, and “T2” items such as MSXML where a .CAB file may be downloaded if necessary to ensure that the latest versions are available at installation time), simplified configuration (through the application paradigm), and improved orchestration deployment (down from 74 clicks in BizTalk server 2004 to just a few operations within the new BizTalk Administration Console).

Other improvement areas are the core engine, with improvements around:

  • Handling large messages during a transformation – writing out to disk rather than running out of memory, albeit with a corresponding performance hit.
  • Handling bad messages with out having to roll back all related messages.
  • Ordered delivery to ensure that sequenced messages arrive in sequence.
  • More granular performance counters.
  • A new flat file schema wizard.
  • Engine throttling.

There are also new adapters, with MSMQ and MQSeries adapters now available out of the box (for BizTalk Server 2004 these were separate downloads), as well as new e-mail receive (POP3) and Windows SharePoint Services (WSS) adapters. In addition, existing adapters are enhanced (e.g. e-mail compose within the SMTP adapter, usability improvements and performance counters for adapter troubleshooting). Other new features include the ability to connect to UNC file shares using alternate credentials, SOAP array support and an ability to call web services without orchestrations (i.e. messaging only scenarios) using content based routing (CBR) send ports, and the ability to suspend failing HTTP requests.

On the development front there are new redeployment tools, support for zooming in/out of large orchestrations, and collapsed shapes are preserved in the orchestration designer (OD).

Overall, administration is simplified so that most operations are controlled through the BizTalk Administration Console; although health and activity tracking (HAT) is still available and Microsoft Operations Manager (MOM) is recommended for monitoring not only BizTalk (with an updated management pack) but also all of the related components (IIS, SQL Server, etc.).

The BizTalk Administration Console is a Microsoft management console (MMC) snap-in, with a new group hub concept which allows the overall status to be viewed at a glance, as well as improvements for analysing the root cause of issues, isolating errors, grouping and filtering of queries, and bulk operations (e.g. resume all, terminate all, suspend all).

Administration can also be performed via scripting APIs, or the command line (a number of sample scripts are available).

Microsoft are making a great play on the ordered processing functionality in BizTalk Server 2006 and the demonstration I saw showed a graphical application with sending and receiving components whereby the presenter wrote her name in the sending application the vectors for the pixelated data were sent to make it appear (albeit a bit jumbled), in the receiving application. Once ordered delivery was enabled, the sending and receiving copies were identical. This ordered processing can be handled in a number of ways and send-side order processing is available for any adapter; but if implemented on the receiving end, it requires an adapter with appropriate support (e.g. MSMQ or MQSeries) or for sequential data, an HTTP or SOAP adapter can be used. Orchestrations can use the ordered delivery setting on the orchestration receive port and a orchestration convoy to get the stream of ordered messages.

Looking at the new adapters, the WSS adapter features:

  • Receipt of documents from (and posting documents to) a SharePoint document library.
  • Filter inbound documents based on views.
  • Archival of documents to another document library.
  • Promotion of document properties.

The new POP3 adapter features:

  • Polling for e-mail and attachments via a POP3 receive location.
  • Population of e-mail header properties within the message context.
  • POP3 over SSL.
  • Configurable TCP port number.

Line of business adapter choices are also enhanced with Microsoft’s purchase of the iWay adapters for:

  • Clarify.
  • JD Edwards.
  • Oracle Applications.
  • Oracle DB.
  • PeopleSoft.
  • SAP.
  • Siebel.
  • TIBCO Rendezvous.
  • TIBCO JMS (EMS).

(iWay customers that have purchased licenses for the .NET-based adapters will receive a license for the corresponding Microsoft adapter with the purchase of Software Assurance).

A major enhancement in BizTalk Server 2006 is the flat file schema wizard – used to accept messages from a flat file, for example a comma separated variables (.CSV) file, an EDI document, or a text file produced by a custom legacy application. To enable processing of this format using BizTalk Server developer needs to define a flat file schema (an XSD with additional flat file annotations).

Also improved is the interchange processing related to flat file document interchange. In BizTalk Server 2004, one bad document will result in the whole interchange being suspended whereas with BizTalk Server 2006’s recoverable interchange processing, only the “bad” elements are suspended and most of the processing is carried out as normal.

For business users, BizTalk Server 2006 has improved alerting capabilities, finally providing real time information via a new out-of-the-box portal and native integration with BizTalk messaging. There is also a software development kit with a new dynamic web part generator for WSS as well as integration with the Microsoft Office Business Scorecards Accelerator and SQL Server 2000 Reporting Services.

Finally, for those who want to have a look at BizTalk Server 2006, Owen’s blog has details of where to download the latest beta.

A quiet news day?

Today must be a “quiet news day”. We see precious little IT news in the national press, and I know it’s the middle of August, but Metro, the UK’s free newspaper for commuters in and out of our major cities, is really scraping the barrel with its IT reporting this morning. On page 21, a sixth of a page is given over to a story about a worm attacking Windows 2000 (Hackers target Windows 2000) – an officially unsupported operating system. I wouldn’t mind that such a non-event is reported if only it were accurate. According to the Metro article:

“The basic effect of the worm is not damaging but irritating – it forces the computer to repeatedly shut down and reboot, clogging networks.”

Since when did a reboot clog up a network? (A few bytes of DHCP traffic; an increased number of logons). Allegedly, “ABC News producers were forced to use electronic typewriters to prepare TV scripts”. It seems to me that the most pertinent point of the article was the quote from a security expert from McAfee who said that the time between vulnerability exposure and exploit is lessening – something we’ve known for some time now. Microsoft’s advice on what to do about this exploit, known as Zotob indicates that “only a small number of customers have been affected… [with] no indication of widespread impact to the Internet” (although Sophos lists a dozen types of malware exploiting the MS05-039 vulnerability used by Zotob).

The Metro reporter, Sarah Hills, needs to do some research – perhaps instead of alarming a generally computer-illiterate public she should point out that Windows 2000 is old and those organisations affected should tighten up their anti-virus protection! More to the point, the exploit also affects Windows XP and Windows Server 2003 – not just Windows 2000!

In the same paper, immediately below the “Hackers target Windows 2000” piece, is another one about how “Bluetooth thieves log your laptop”, scanning parked cars for Bluetooth devices locked in the boot. Isn’t Bluetooth off when my laptop is switched off?

I know it’s all about stories being newsworthy, but what I’d really like to see is the occasional IT piece in the national press which is both accurate and timely, without being alarmist.