ÿWPCÆ /[ŒLwz‚÷#µæ`h}œe±B¼oÚ§jÉB±étïf< )ŒÅÕzºècb—a¦(´®ä™VûÇéÕdû‚ý±Óýxx]Õ’îôÆÛVIrÒ™z[®nËϸøó š b WÏŒä øªïr"A§hÃ¸Ž®Šld–”ðÍ1þU–áëK» Ë z‚eÊ<pÿ•â²&ôêÕÔ{À×QJ³±žP—F–V{ŽÎĦFœ…i"ùк7¨Œ 6ŸûƸä¼uN´eÝ®ÃÇ`G+L{¬­5ùá&z{Õ¸_<þeZÐorI×É|KÇ5‡ñ)Oõ€`ûb¬æŸC 4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó88T ÿÿ,toc 2toc 2Ó  ÓÓ ÿÿÜ4Œ ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó8;T ÿÿ,toc 3toc 3Ó  ÓÓÿÿÜ4Œ ä ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó8;T ÿÿ,toc 4toc 4Ó  ÓÓÿÿÜ4ä <ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó8;T ÿÿ,toc 5toc 5Ó  ÓÓÿÿÜ4<”ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó85T ÿÿ,toc 6toc 6Ó  ÓÓ ÿÿÜ4ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó8! ÿÿ,toc 7toc 7Ó  ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ  Ó85T ÿÿ,toc 8toc 8Ó  ÓÓ ÿÿÜ4ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó85T ÿÿ,toc 9toc 9Ó  ÓÓ ÿÿÜ4ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó@8T ÿÿ0index 1index 1Ó  ÓÓ ÿÿÜ4Œ ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó@8T ÿÿ0index 2index 2Ó  ÓÓ ÿÿÜ4Œ ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  ÓP5T ÿÿ8toa headingtoa headingÓ  ÓÓ ÿÿÜT$ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ>4ÿÿX°` ¸ hÀpÈ xÐ (#>ÓÓ  Ó@! ÿÿ0captioncaptionÓ  ÓÔ  ÔÔ  ÔÔ  ÔÔ  ÔÓ  Ó^ÿÿ:_Equation Ca_Equation CaptionÔ  ÔÔ  ÔÔ  ÔÔ  Ô%ä2¼A`ArialTT0ä2¼A`Helvetica3|x «ô\  `*Times New RomanTTôôCô\  PŽ6QôPô\  `*Times New RomanTTXXPô\  PŽ6QXP%ä2¼A`ArialTTomanTTXXXä2¼P±³kCXP0ä2¼A`HelveticaanTTôÛ`ä2¼P±³kCôP%ä2¼A`ArialTTomanTT;ä2¼P±³kCP(>ì×$¡¡Ô€XwTXõôÔÔ€XwTXXXwTÔ˜HP LaserJet 4M Plus,ð,,,,,ð0ÑB)ÞÏfA)5„ÿU‹ÿÀÀÀÝ ƒì×!ÝÔ€XwTXõôÔÔ€XwTXXXwTÔÝ  ÝÔ_ÔÒܰÒÒܰÒÔ€Xø5XXXwTÔÔ  Ôò òññAppendix€D15.2.1_I€ññMicrosoft€NT€Is€A€Viable,€Well„Supported€Web€Platform€Solutionó óÐ ° ÐÌBy€Neal€Ô_ÔCabageÔ_Ô€ÌÌò òIntroductionó óÔ€ô×HõXXø5ÔÔ€ô]aõõô×HÔÓ öhRÓÐ h¸ ÐThe€question€was€recently€raised€as€to€why€we€choose€to€work€with€Windows€NTÏtechnologies€on€some€projects,€rather€than€one€of€the€various€*Ô_ÔNIXsÔ_Ô€(e.g.,€Ô_ÔLinuxÔ_Ô€or€one€of€theÏvarious€flavors€of€Unix).€Security€and€reliability€are€among€a€few€of€the€well„known€concernsÏabout€using€an€NT„based€platform.€Consequently,€I€drafted€this€document€to€address€someÏof€these€issues€and€to€document€some€of€the€advantages€of€going€with€NT.€Ó 3Ó¥öhRÓÌò òSecurityó ó€Ð c  ÐWindows€NT€initially€got€a€bad€rap€for€its€security€problems.€This€was€largely€due€toÏMicrosoft's€emphasis€on€ease„of„use€at€the€expense€of€security.€While€ease„of„use€stillÏremains€at€the€forefront€of€Microsoft's€product„development€efforts,€it€might€appear€that€MSÏhas€finally€heard€the€voice€of€concern€and€has€begun€taking€strides€to€fix€the€problem.€In€fact,Ïlast€year€Windows€NT€won€Britain's€highest€level€of€security€certification:€ÌòòAfter€more€than€a€year€of€intensive€testing,€the€U.K.€Information€Technology€Security€EvaluationÐ å5 ÐCriteria€(Ô_ÔITSECÔ_Ô)€certification€board€awarded€Windows€NT€Server€4.0€and€Windows€NTÏWorkstation€4.0€and€E3/FC„2€rating„generally€acknowledged€as€the€highest€security€evaluationÏpossible€for€a€general„purpose€operating€system.€The€security€standards€agency€evaluationÏincluded€examinations€of€the€source€code€and€design€documentation€of€Windows€NT€4.0€withÏService€Pack€3.€Testers€also€had€direct€access€to€the€engineers€who€designed€and€tested€theÏserver€operating€system.óóòò€1óó€Ð }Í ÐFurther,€Microsoft€has€announced€plans€to€work€more€closely€with€the€U.S.€federalÏgovernment€to€ensure€high„level€Ô_ÔSSLÔ_Ô€encryption,€which€will€make€secure€transactions,€suchÏas€e„commerce€purchase€transactions,€even€more€secure:€ÌòòMicrosoft€Corp.€today€announced€plans€to€support€Ô_ÔFIPSÔ_Ô€140„1€and€Ô_ÔFORTEZZAÔ_Ô,€two€key€federalÐ Ë Ðcryptographic€standards€important€to€the€protection€of€U.S.€government€communications.€As€partÏof€a€broader€federal€security€initiative,€Microsoft€plans€to€include€in€future€products€NationalÏInstitute€of€Standards€and€Technology€(Ô_ÔNISTÔ_Ô)€Ô_ÔFIPSÔ_Ô€140„1„validated€cryptographic€modules€asÏwell€as€native€support€for€secure€sockets€layer€(Ô_ÔSSLÔ_Ô)€Web€communications€using€Ô_ÔFORTEZZAÔ_Ô.ÏThis€support€underscores€Microsoft's€continuing€commitment€to€meet€the€security€requirementsÏof€its€federal€customers.€This€commitment€already€includes€supporting€several€U.S.€DepartmentÏof€Defense€initiatives,€including€the€Defense€Messaging€System€(Ô_ÔDMSÔ_Ô),€Medium€AssuranceÏMessaging,€Desktop€and€Network€Security€Frameworks,€and€Public€Key€Infrastructure,€as€well€asÏtrusted€systems€initiatives€such€as€C2€compliance€and€evaluation.óóòò2óó€Ð ¯#ÿ( ÐFurther,€Windows€2000€(W2K)€is€being€touted€for€having€even€greater€refinement€in€theÏareas€of€security,€reliability,€and€performance.€ÌòòLeading€security€specialists€at€Internet€Security€Systems€(Ô_ÔISSÔ_Ô€Group)€have€concluded€thatÐ ='"- ÐWindows€2000€represents€a€great€leap€forward€for€the€security€of€Microsoft€products.€In€addition,Ïit€raises€the€bar€for€the€entire€industry€by€integrating€leading„edge€security€technologies,€as€wellÏas€addressing€the€lessons€learned€from€one€of€the€world's€most€prolific€operating€systems.€ThisÏcombination€of€innovation€and€experience€makes€Windows€2000€the€most€secure€operatingÏsystem€Microsoft€has€ever€shipped,€and€certainly€one€of€the€most€secure€in€the€industry€today.ÏSee€the€details€of€this€study€at€http://www.iss.net/w2k/.óóòò3óó€Ð Õ+%'3 Ðò òReliabilityó ó€Ð >-Ž(5 ÐÔ_ÔAs€with€security,€Windows€NT€reliability€has€improved€drastically€over€the€past€few€years,Ïthrough€OS€revisions€and€service€pack€releases.€NT4€represents€a€major€reliability€enhancement€over€previous€versions:€ÌòòMicrosoft€has€improved€the€reliability€of€Windows€NT€Server€4.0,€providing€a€comprehensive€set€of€updates€in€Service€Pack€5€(SP5).€Strengthened€with€the€improvements€in€Service€Pack€4€and€Service€Pack€5,€Windows€NT€Server€provides€the€highest€reliability€and€availability.€Reliability€is€one€of€the€most€powerful€characteristics€of€the€Windows€NT€Server€operating€system.€The€system€ensures€high€availability€of€information€and€services€in€three€ways:€by€uniformly€handling€hardware€and€software€system€faults,€protecting€user€programs€from€each€other€as€well€as€the€system,€and€providing€data€and€system€recovery€mechanisms.€Windows€NT€Server€has€the€ability€to€tolerate€faults€while€still€maintaining€the€availability€of€the€system,€applications,€network€resources,€and€data.óóòò4óó€ÌOnce€again€however,€W2K€is€being€touted€by€high„profile€professionals€in€the€industry€as€being€a€leap€forward€in€the€product's€quality.€ÌòòOverall,€dot.com€IS€managers€indicated€that€they€were€very€pleased€with€the€scalability,€reliability,€and€manageability€improvements€they€found€in€Windows€2000€over€Windows€NT.€.€.€.€[but€their€study€was]€inconclusive€in€the€area€of€directory€services€(specifically€the€use€of€Active€Directory)„the€dot.com€IS€managers€interviewed€had€not€yet€made€extensive€use€of€the€policy/procedure€and€management€extensions€built€into€the€new€directory€server.óóòò5óó€ÌMichael€Dell,€chairman€and€CEO€of€Dell€Computer€Corp.,€also€came€out€in€support€of€this€new€version€of€the€OS."If€you€care€about€stability,€reliability,€and€manageability,€you€should€run€[Windows€2000]€across€your€enterprise,"€said€Dell.€And€he€takes€that€personally:€Dell€runs€Windows€2000€on€his€own€laptop;€his€company€runs€its€Web€site€with€it.6€ÌAnother€issue€to€consider€when€looking€at€reliability€is€viruses.€As€Linux€users€are€quick€to€point€out,€their€environment€remains€largely€virus„free€to€date,€but€this€may€soon€change€as€the€user€base€increases.€Where€Microsoft€has€already€dealt€with€this€issue€and€a€plethora€of€virus„protection€options€exist,€Linux€remains€virtually€unprotected,€as€pointed€out€in€an€article€titled,€The€Coming€Linux€Plague:€ÌòòLinux€(and€the€other€versions€of€Unix)€desperately€needs€credible€anti„virus€software€to€stave€off€the€coming€epidemic€before€it€happens.€Think€of€it€as€a€flu„shot.óóòò7óó€ÌSo€this€all€beckons€the€question:€Is€a€*NIX€platform€a€better€way€to€go?€Darryl€Braaten,€a€member€of€the€Site€Server€list€on€15seconds.com€had€this€to€say:€Ìòò"There€is€definitely€more€effort€put€into€making€some€versions€of€*nix€secure.€But€in€general€I€would€not€call€it€better€or€worse€then€NT€in€general.€I€have€a€few€machines€sitting€in€the€clear€[and]€the€only€one€that€was€ever€compromised€was€a€Redhat€Linux€box."óóòò8óó€ÌRobert€Chartier,€also€of€the€list,€further€commented€by€pointing€out€that€a€lot€of€times€it's€more€about€the€quality€of€the€team,€not€the€operating€system,€that€makes€the€biggest€difference€in€the€security€of€a€system:€Ìòò"One€of€the€points€I€did€try€to€get€across€was€that€on€either€system€there€are€steps€that€have€to€be€taken€to€secure€the€box€down,€you€just€have€to€know€how€to€do€it€properly€and€unfortunately€a€M$€certification€just€does€not€cut€it.€I€would€look€more€at€experience€than€certification."óóòò9óó€ÌSo€the€consensus€from€the€community€seems€to€be€that€an€*NIX„based€platform€is€not€the€be„all,€end„all€quick€fix€to€the€issue€of€stability€and€security€that€some€might€contend.€Further€support€comes€from€a€recent€ZdNet€article€entitled€"Microsoft's€Not€The€Only€Security€Foul„Up":€ÌòòAll€of€the€Unixes,€including€BSD,€Linux,€SCO€and€Solaris,€have€more€than€their€share€of€security€problems.€Think€about€it.€The€recent€rash€of€distributed€denial„of„service€attacks€were€all€launched€from€unsecured€Solaris€systems.€And,€much€as€I€rag€on€Outlook,€the€all€time€champion€application€for€security€holes€must€be€that€Unix€mail€transfer€agent,€which€still€sends€most€e„mail€along€its€way:€Sendmail.€Windows,€Linux,€whatever.€If€you€want€your€systems€to€be€trouble„free,€you€need€to€take€a€lot€of€trouble.€Hard€work€and€due€diligence€are€the€only€real€security€answer."óóòò10óó€Ìò òVendor€Supportó ó€ÌNow€that€we€have€taken€a€stab€at€defending€the€NT€platform,€let's€focus€on€some€of€the€advantages.€ÌOne€of€the€greatest€advantages€to€choosing€any€product€that€will€be€the€foundation€of€your€business€is€vendor€support.€In€an€article€in€NetworkWorld.com,€Mike€Daher,€vice€president€at€MicroStandard€Distributors,€said:€Ìòò"Until€[system€builders]€get€the€support€we€need€from€Red€Hat,€until€they€come€to€us€instead€of€thinking€we€all€have€to€come€to€them,€open€source€and€Linux€is€going€to€continue€to€be€all€hype.€"I'm€no€more€of€a€fan€of€Microsoft€than€the€next€person,€but€I€can€say€that€the€support€we€get€from€Microsoft€is€superior,€and€less€expensive.€Microsoft€always€comes€to€our€door,€they€bring€demo€units,€keep€us€in€touch€with€their€engineers,€and€certification€for€our€people€costs€only€$2000€each,€on„site.€Red€Hat€wants€$5,000€a€person€and€we€have€to€fly€our€people€to€Durham,€[N.C.]."óóòò11óó€Ìò òPlatform„Dependent€Rapid€Application€Development€(RAD)€Supportó ó€ÌAs€if€that€wasn't€enough€of€a€reason€to€seriously€consider€an€NT„based€platform,€look€at€the€tremendous€advantage€provided€to€developers€writing€Active€Server€Pages€(ASP)€with€the€use€of€Site€Server.€Site€Server€is€a€collection€of€COM€objects€that€extend€the€capabilities€of€ASP,€and€thus€have€the€ability€to€significantly€reduce€the€amount€of€time€and€effort€needed€to€develop€a€Web€application.€It€features€components€that€aid€in€the€production€of€Personalization€and€Membership€functionality,€commerce,€and€auction€solutions,€and€more.€Marc€Tabini,€a€noted€Site€Server€developer,€said:€"Microsoft€Site€Server€is€something€similar€to€a€team€of€engineers€available€for€building€advanced€websites.€In€the€hands€of€a€well„trained€developer,€Site€Server€can€do€miracles€as€demonstrated€by€the€Barnes€and€Noble,€and€Dell€online€stores."òò12óó€ÌA€book€on€the€topic€of€Site€Server€introduces€the€product€by€saying:€ÌòòIn€this€sort€of€environment,€starting€from€scratch€in€a€complex,€scalable€site€can€be€an€expensive€task.€Site€Server€3.0€gives€you€a€head€start€in€putting€your€site€together€and€building€a€scalable€configuration.óóòò13óó€ÌFinally,€there€is€the€matter€of€what€industry€leaders€are€doing€that€should€be€considered.€What€after€all,€is€a€better€indication€of€a€product's€viability€than€what€your€predecessors€have€chosen€to€do.€Compaq€and€CyberSource€have€both€come€out€in€support€of€the€Site€Server€Commerce€Edition,€Commerce€solutions,€and€the€implicit€NT€platform.òò14óó€ÌAn€independent€survey€conducted€by€Netcraft€also€provides€some€useful€information.€Ìòò"We've€seen€a€significant€increase€in€the€number€of€e„commerce€customers€using€a€Microsoft€platform,€especially€among€our€top„tier€customers,"€says€Doug€Isom,€product€marketing€manager€at€CyberSource.€"Customers€choose€to€implement€Microsoft€Site€Server€Commerce€Edition€because€it's€proven€to€be€a€high„performance,€highly€scalable€and€reliable€solution.€In€addition,€it's€an€easy€platform€to€develop€to,€it€comes€with€a€complete€set€of€tools€and€it's€designed€for€ease€of€integration€with€value„added€services€like€those€we€provide€at€CyberSource."óóòò15óó€ÌòòSite€Server€Commerce€Edition€has€shown€tremendous€momentum€among€e„commerce€businesses€and€top€shopping€sites.€Several€surveys€from€Netcraft,€an€independent€research€organization,€show€that:€Ìð"ð€€Site€Server€Commerce€Edition€powers€70%€of€commerce€server€sites€in€Shop.org's€top€100€shopping€sites,€while€its€closest€competitor€has€only€15%.€Ó  ÓÓ öhRÓÌð"ð€€82%€of€commerce€server€sites€in€Ziff„Davis/Interactive€Week's€top€500€Web€sites€use€Site€Server€Commerce€Edition,€compared€to€8%€who€use€its€closest€competitor.€óóÓ  ÓÓ ÓÌòòð"ð€€An€October€1999€Netcraft€survey€of€sites€using€SSL€(Secure€Sockets€Layer)€security€certificates€shows€that€73%€of€sites€using€commerce€servers€use€Site€Server€Commerce€Edition€to€power€their€e„commerce€solutions,€while€10%€use€its€closest€competitor.òò16óó€óóÓ  ÓÓ öhRÓÌòòThese€surveys€demonstrate€that€Site€Server€Commerce€Edition€is€not€only€widely€adopted,€but€more€of€the€successful€sites€using€commerce€servers€today€use€Microsoft€Site€Server€Commerce€Edition€than€any€other€commerce€server.òò17óó€Ó  ÓÓ 3Ó¥ÓÌSite€Server€Commerce€Edition€is€a€key€component€of€Windows€DNA€along€with€Windows€NT€and€Windows€2000,€Microsoft's€SQL€Server(tm)€database,€Microsoft€SNA€Server€and€Microsoft€Visual€Studio.€Microsoft€Commerce€Server€2000€„„€the€next€generation€of€Site€Server€Commerce€Edition€„„€will€also€join€the€Windows€DNA€family€when€it€is€released€later€this€year.€Commerce€Server€2000€is€designed€to€simplify€the€process€of€building€sophisticated,€customer„centric€Internet€and€extranet€selling€sites.òò18óó€Ì"Site€Server€Commerce€Edition€on€Windows€2000€is€an€even€better€platform€for€building€e„commerce€solutions€than€Site€Server€Commerce€Edition€on€Windows€NT€4.0,"€said€Kevin€Kenefic,€a€senior€engineer€in€Compaq's€enterprise€solutions€and€services€division..€"And€when€Microsoft€comes€out€with€Commerce€Server€2000€later€this€year,€that's€going€to€improve€the€picture€even€more."òò19óóóóò òAbout€the€Authoró ó€ÌNeal€Cabage€is€the€lead€application€engineer€for€Iconixx€in€the€company's€Santa€Monica,€Calif.,€office.€He€can€be€reached€at€Ô  Ôòòncabage@iconixx.comóóÔ  Ô.€Ìò òFootnotesó ó€Ì1.€British€Government€Confirms€High€Security€of€Microsoft€Windows€NT€4.0€http://www.microsoft.com/PressPass/features/1999/05„03ntsecure.asp€Ì2.€Microsoft€Enhances€Windows€NT„Based€Support€For€Key€U.S.€Government€Security€Standards€„€Plans€to€Provide€FIPSS€140„1„Evaluated€Cryptography€and€Support€For€Secure€Web€Communications€Using€FORTEZZA€http://www.microsoft.com/PressPass/press/1998/Aug98/FIPSPr.asp€Ì3.€Security€Services€Launch€Showcase€http://www.microsoft.com/WINDOWS2000/guide/server/features/securitylaunch.asp€Ì4.€Reliability€and€Fault€Tolerance€in€Windows€NT€Server€http://www.microsoft.com/NTServer/fileprint/exec/overview/reliability.asp€Ì5.€Proving„the„Point:€Interviews€with€Next„Generation€Windows€2000€dot.coms€http://www.microsoft.com/windows2000/guide/server/reviews/dotcoms.asp€Ì6.€Dell€says€Windows€2000€is€ready€to€roll€http://www.networkworld.com/news/2000/0216windowsroll.html€Ì7.€The€Coming€Linux€Plague€http://www.securityfocus.com/frames/?content=/templates/article.html%3Fid%3D2€Ì8.€15€Seconds,€Site€Server€ListServ€Administrated€by€15Seconds:€http://www.15Seconds.com€List€Archives/Search:€http://local.15Seconds.com/search€Subscription€Information:€http://www.15seconds.com/listserv.htm€Advertising€Information:€http://www.internet.com/mediakit/€Ì9.€Ibid.€Ì10.€Microsoft's€Not€The€Only€Security€Foul„Up€http://www.zdnet.com/sr/stories/column/0,4712,2457967,00.html€Ì11.€Red€Hat€takes€heat€over€certification€http://www.networkworld.com/news/2000/0313redhatbash.html€Ì12.€Professional€Site€Server€3.0,€Wrox€Publishing,€Page€2.€Ì13.€Professional€Site€Server€3.0€Commerce€Edition,€Wrox€Publishing,€Page€2.€Ì14.€Performance€Gains€on€Windows€2000,€Customer€Successes€Build€Momentum€for€Microsoft€Site€Server€Commerce€Edition€http://www.microsoft.com/presspass/features/2000/02„15ssce.asp€Ì15.€Ibid.€Ó  ÓÓ ÓÌ16.€Ibid.€Ì17.€Ibid.€Ì18.€Ibid.€Ì19.€Ibid.€Ó  ÓÓ öhRÓÌÔ€ôôôÔÔW€ô\  `*Times New RomanTTWÔÓ  ÓÓ ÓÌÔ€XXXÔÔC€%ä2¼A`ArialTTCÔÌÔ€ôôôÔÔW€ô\  `*Times New RomanTTWÔÌÓ  ÓÔ€ÔÔC€%ä2¼A`ArialTTCÔCopyright€1999„2000€internet.com€Corp.€All€RIGHTS€RESERVED.Ô€XXXÔÔC€%ä2¼A`ArialTTCÔ