Category Archives: Mobility Rant

Security Flaw in an Apple Product? – Surely You Jest

I’m not the only one taking a look at provisioning the iPhone. My focus was to show it working though, and not a complete analysis of the low-level details. Good thing someone else did then :)
(…)
Adding my two cents on the flaw described at http://cryptopath.wordpress.com/2010/01/29/iphone-certificate-flaws/

Certificates – A Minor Technology Update

A couple of weeks ago I performed an upgrade of my LAN at home. A trusty old Pentium 4 that had been doing it’s duties as a Windows Server 2003 domain controller showed signs of old age, and kept locking up at an increasing rate. I’m guessing that the hard drives, and possibly a couple of the fans had started to take enough of the abuse :) Trying to fix it wouldn’t make sense economically, and while I’ve spare parts and computers with similar specs I wanted to go 64-bit. It all ended up in me re-installing two low-end PowerEdge tower servers running Windows Server 2008 to 2008 R2. The improvements in Hyper-V was one of the reasons, but while at it I thought it would be a good idea to upgrade the domain controller too. (Note to others out there running Linux-based NAS boxes: don’t assume they like 2008 DCs just because they boast AD integration, and worked happily with 2003. Samba can bite my shiny metal ass…)
(…)
An executive summary of the NDES and Certificate Enrollment Web Services in 2008 R2.

Restricting Exchange ActiveSync Access – Redux

A few weeks ago I had a look at some of the new features in Exchange 2010 regarding how Exchange ActiveSync (EAS) can be “locked down” or restricted to only allow certain devices to sync (as opposed to the default open-for-all configuration). While those techniques specifically targeted Exchange 2010 there are some other methods you can employ as well, and I thought I’d take a look at some of them here. Not all of them are bullet proof, but it’s interesting to have them listed nonetheless.
(…)
Going through a number of options for restricting which devices can sync to Exchange ActiveSync.