Tuesday, March 19, 2013

Worldwide Cyber Attacks


The Government Security News published an article titled: "German Telecom Company Provides Real-Time map of Cyber-attacks". If it is credible, and at this point I have no reason to doubt its credibility, it is a fascinating bit of technology. Deutsche Telekom (the folks behind T-Mobile) indicates that there are about 450,000 cyber-attacks worldwide per day.
The portal has a digital map which reveals the alleged country origin of the cyber-attacks. I found it interesting- in the last month, the top 5 countries conducting attacks were listed as:
  1. Russian Federation
  2. Taiwan, Province of China
  3. Germany
  4. Ukraine
  5. Hungary
The United States was 6th and China came in a distant 12th. Granted China might be "laying low" because of the Mandiant_APT1_Report - But I doubt it.
The number one attack type was the Server Message Block (SMB) Network services attack against port 445. Of the short time I monitored the portal, there were numerous hits from Australia, Bosnia and Herzeg, and Columbia.
This capability tends to concern me greatly- What about you?
The article can be found at: http://www.gsnmagazine.com/node/28720?c=cyber_security&utm_source=Homeland+Security+Insider+--+March+14%2C+2013&utm_campaign=Feb.+27%2C+2013&utm_medium=email 
Check it out....

Thursday, February 28, 2013

The Deep Web; an Intelligence Challenge

There is a great deal of well deserved, comment, about Cyberspace Security. The White House as planted a stake in the ground that will affect how we respond to this threat to our National Security and Economy.  The President stated “cyber threat is one of the most serious economic and national security challenges we face as a nation” and that “America's economic prosperity in the 21st century will depend on cyber security.”  America faces a very unique challenge. We need to proactively secure our physical cyber infrastructure and deal with those who clandestinely and vigorously attack our cyberspace from external and internal sources. This puts us on the horns of a dilemma. As a country of laws and people who value their privacy; Anonymity travels in close relationship to “Freedom of Information.” We can get a handle on the former (it will be a monumental effort but not insurmountable).The latter raises the classic intelligence conundrum of not only defining capability but determining intent. If approximately 99% of the information to be analyzed is within an environment that is designed for anonymity and obscurity, we have our work cut out for us. I speak of the Deep Web. Several companies have gone where none have gone before and began mapping this galaxy, but much remains to be done. Traditional search and indices are not enough. Big Data analytical techniques are going to be needed. Ways to safely disseminate this information to those who need it must be found and most of all, diligent vigilance and respect for our laws must be maintained.

Friday, August 24, 2012

Maranatha & Associates, Inc. Profile


Founded in 1996, Maranatha & Associates has been providing Service with Integrity as a reseller and as a services company.  Maranatha & Associates (MAI) is a Vietnam veteran owned, Small Disadvantaged Business (SDB). We are a one-stop shop for your System Integration needs. MAI has provided clients with products supporting their existing and planned solutions.  We have provided development, systems design and support, built contemporary web sites, developed small to enterprise-level software, and provided information technology consulting services to both Federal Government and Commercial clients. Our passion is the development and support of enterprise applications that make a difference. We use innovative approaches to boost productivity levels and eliminate wasted processes for our customers. At MAI success is measured in the seconds and dollars regained by each and every client.  As the CTO and CIO’s trusted adviser, MAI provides the best solutions to aide executives in maximizing the return on their investments.  Our deep industry knowledge enables clients to address issues specific to their businesses, and our unique small stature with a large impact approach provides the capabilities to help ensure we serve our clients extremely well.
Since 1996, our mission has been to develop software solutions that make it easier and quicker for our client’s to do business. We measure our success by every second regained by our client. Our highly trained, highly experienced team is capable of accepting the challenge and delivering your project as promised with remarkable results



Friday, December 9, 2011

Virtualization is for Small Businesses

With all the hype and hoopla about the cloud, we sometimes forget that small businesses need the same type of tools needed by the large enterprises. We need it on a much smaller scale, but we still need it. After many years in the mines of the large companies I came to realize that they are in fact a conglomeration of small companies who in fact sometimes compete inadvertently with each other - But that's a subject for another blog.


Many small companies have no IT department and they may or may not be tech savvy...Much of the technology is intimidating. My next series of blogs is focused on lighting the dark art of the Cloud. Please check out the lessons I embed in this and upcoming blogs. This is part one.

<

Monday, September 19, 2011

The Journey begins with the First Step

The journey to cloud computing begins with our existing infrastructure and applications. Good Grief Charlie Brown, we can't just throw everything out and start over "in the cloud". We need to leverage exisiting investments, skills, and to the extent possible, processes. Mostly, when you bring up uhet subject "cloud", people immediately think of public cloud offerings. There is a reason for that . First is "Pooling". Pooling is the activity that enables us to break down the traditional physical silos of infrastructure and create capacity pools of CBU, memory, storage, and networking - all aspects of the Data-center - to maximize our use of resources. Secondly, we want the cloud to be able to enable automated scaling up and scaling down of resource capacity to workloads efficiently - VMware referes to this as "Elasticity". Third is "Automation". To be a truly dynamic, on-demand environment, then it has to be fully automated. All of theses characteristics have a significant impact on lowering costs. They also provide the foundation for an infrastructure that will support the agility that a business stakeholder wants. In fact, some Agencies are factoring the process of "agility" into their Enterprise Architecture policies. Cloud Computing provides the right architecture to enable infrastructure on-demand.

However, I must admit that I am not a big fan of the public cloud as it currently stands in its maturity. Many of these clouds do not have an "exit" strategy and once you are in, you are not able to back out. Additionally, being a risk averse individual, I am not yet willing to relinquish my authority and responsibility for the security and privacy of my company's resources and employees to a third pary where I have no visibility as to how they maintain security. That being said, does not negate our goal of leveraging exisiting investments currently in place in the datacenter. The concept of the cloud architecture can be applied to our existing datacenter and the creation of a Private Cloud

But, infrastructure is only the begining of the journey and it is not prudent to think that consolidation of the servers in the data center amounts to cloud computing... The clip below gives you and idea of what VMware's vision is as to get to the cloud...

Thursday, September 8, 2011

This way to the Cloud

Well, is the cloud the next great IT innovation? It could be or it could be a wispy apparition that dissipates on the winds of poor planning. Public Cloud, Private Cloud, Hybrid Cloud, SaaS, PaaS, or IaaS are all sophisticated buzzwords to us “mere mortals” that conjure up images of cutting edge technologies that will resolve all our Information Technology issues. However, I maintain that if we limit our thoughts about “The Cloud” strictly to technology, we are in for a disappointment. If we only complete an element of the cloud environment (e.g., server consolidation) we are only going to get a portion of the benefit of what the strategy and architecture of cloud computing can provide.

We need to begin our path to the cloud by defining the business problems that need to be solved, explicitly set goals, and translate these pain points into services that need to be delivered. During this blog discussion, I am going to suggest certain business imperatives that cloud computing addresses introduce a framework that I believe is critical to the eventual desired end state of cloud computing.



  • First of all a major promise of cloud computing is a much better approach to helping IT drive greater agility…


  • Secondly, the cloud has proven to lower costs (60% on CapEX, 30% on OpEx and up to 80% on Energy)


  • The third business imperative that is addressed is ensuring compliance and security, while also maintain business-required service levels

OK, now what are these layers critical to a successfully end state of cloud computing – There are Three…



  1. Your infrastructure and existing investments: Organizations must take existing IT processes and ensure that they can be brought into the cloud environment.

  2. The growing demand for a new brew of business applications. Ultimately, infrastructure is there simply to support applications. So it’s important for us to address this layer as well. How we approach applications can affect both costs – OPEX, and Agility.


  3. The third tier is our End User. The challenge is to enable end users with the freedom to have access anytime, from anywhere while still ensuring security, and support all of this in a cost-effective manner.

    Over the next weeks and months I will expand on this framework by discussing how the leading vendors are addressing these issues – so watch this space…

Sunday, January 2, 2011

Think Architecture, Not Just Operating System

We move into the New Year with anticipation of doing great things with our infrastructure and improve the efficiency of our operations. Unfortunately, many have a tendency to look at the latest great thing (e.g., application, Operating System, etc…) as the magic bullet. Each vendor points to how his/her product is the “killer app” that will save our infrastructure. I am not a cynic, but before we invest time and money into a product we need to step back and make sure we are implementing the correct architecture. This is especially true for SMB or government directorates/offices with their own budgetary authority. The term architecture (from the Greek word architektonike) can refer to a process, a profession, or documentation. As a process, architecture is the activity of design¬ing and constructing buildings and other physi¬cal structures primarily to provide shelter. In our context, architecture is a structured process to help ensure the stability of valuable business processes and assets. I like to think a good architecture is constructed in pyramid layer fashion, from the ground up. Every lasting architecture has been conducted in this manner – Whether structural (Egypt or Mexico) or logical (ISO layers) or a combination of both (network infrastructure/virtualization). I find it comforting to see the major players like Cisco, VMware, EMC and Symantec collaborating to provide a solution to a fragmented architecture. A good architecture allows the designer flexibility in both the vertical and horizontal plane of his design. Vertically, it will account for the foundation and services (network and user/application) layers and horizontally, it will consider the business foundation of the organization. It will consider size, location, and business policies and procedures. It should be flexible enough to accommodate the 1000 person office located on a metro campus or dispersed state wide and since one size does not fit all a good baseline architecture should also fit the small 25 person branch with teleworkers. An example baseline architecture is shown. This example is based on a Cisco model but can be applied universally. Have a Blessed and Great New Year.

Wednesday, October 20, 2010

Creating A Virtual Machine

Creating a virtual machine from scratch is a three step process.

First I ran the New Virtual Machine wizard to create a virtual machine. The NewVirtual Machine wizard guided me through the key steps for setting up a new virtual machine, helping me set the virtual hardware specifications and other parameters. A virtual machine provides a base x86 platform and you use the wizard to choose devices to install on that platform. For example, you select the number of virtual processors, the amount of memory, the virtual disk capacity, and so forth. Next I set the virtual machine to connect to a physical CD-ROM device or an ISO file, power on the virtual machine, and install the operating system just like you would for any new physical machine. Finally, I installed VMware Tools to enhance the performance and manageability of the virtual machine. The VMware Tools installation wizard automatically selects the VMware Tools version appropriate for the operating system running in the virtual machine.

After creating a new virtual machine, like a physical computer, it has a blank hard disk. Before you can use it, you need to

partition and format the virtual disk and install an operating system. You can install the operating system from an installation CD-ROM or create an ISO image file and install from that file.The basic procedure to install the guest operating system from CD-ROMs is to first insert the installation CD or floppy into the physical device. Then on the VM menu on workstation menu bar for the virtual machine, click the Settings option to open the Virtual machine Settings editor. On the Hardware tab, for CD/DVD Drive, be sure to enable Connect at power on option under the Device Status. Then when you power on the virtual machine, it will boot from the installation CD. From there you can follow the instructions provided by the operating system vendor to partition the disk and install the operating system. A faster and often more convenient method is to install from an ISO image file. To do so, you must change the virtual machine settings to connect to the ISO image instead of the physical device. Virtual machines support both attended and unattended installations. You can install VMware Tools after installing the guest operating system VMware Tools is a suite of utilities that enhances the performance and manageability of a virtual machine. The installers for VMware Tools for Windows, Linux, FreeBSD, and NetWare guest operating systems are bundled into Workstation as ISO image files.

Viola, we have a virtual machine on our host…. Next week we will look at “configuring virtual networks”… Hopefully, this will keep you from making the same mistakes I and my two colleagues made.

Saturday, October 9, 2010

Snap! This is not a “no Brainer”

Earlier this week I was walking past a desk with two “techies” deep in pensive conversation and actively gesturing. Curiosity got the best of me, so I asked them “What’s up”? Well it appears that they had just deleted and reinstalled a Windows VM in their VMware Workstation host and they could no longer see it. I smiled because I thought of something my father used to say, “if you live long enough, you are bound to see your old mistakes be committed by someone else”.

The trouble was that they did not remember that the default for a network adapter on a VM was NAT. This happens when we use the network wizard setting as “Typical”. They could not see the VM on the network because the network adapter setting needed to be set at “Bridged” for the VM to appear on an equal network status as the host. NAT configures a virtual machine to share the IP and MAC addresses of the host. The virtual machine and the host share a single network identity that is not visible outside the “workstation” network. In a “Bridged” network; the virtual network adapter in the virtual machine connects to the physical network adapter in your host computer, allowing it to connect to the LAN the host computer uses.

The point is, these folks were not novices and had easily overlooked a small but vital step. No, not the fact that when reinstalling the VM, they used all default settings but they did not remember the old adage; “when nothing else works, RTM….” It would have saved them energy and the irritation that a passer-by resolved their issue. They seemed relieved when I told them that that had just happened to me yesterday.

Fortunately, there is a cornucopia of knowledge to help you out of a jam. VMware has white papers, forums, training sessions, and videos. You are not alone…

Monday, October 4, 2010

Try it: you’ll like it….

This is aimed at the small to medium business that wants to get started in virtualization but thinks it takes too much of an investment. Well I’m here to tell ya – That aint the case. There are two VMware products with which you can start to learn what it’s all about and if you want to go further. One is VMware Server. VMware Server is a Free and easy way to get introduced to virtualization. VMware Server provides a risk-free introduction to Windows and Linux application server virtualization. I am currently evaluating it and the other introductory product – VMware Workstation 7.
The top three reasons many business use either of these products is (a) Test and Development of software and IT environments, (b) use of virtual machines to evaluate software, and (c) they want to assess what this virtualization thing is all about. Now before we go any farther, I want to let you know that there is another free product out there: It’s the VMware vSphere Hypervisor (ESXI). However, it does require a dedicated server (recommended 4GB Memory and dual socket, dual core). The next step after ESXI would be vSphere. So if you have a server with the requisite configuration, go for it. But if you are just feeling your way – look at VMware Server or VMware Workstation 7 to begin. There is a cost for VMware Workstation 7 – Approximately $190.00. Now let’s do a quick comparison of these two products.
First of all neither require a dedicated server. They both can run on a Dual Core PC (XP, Win 7, or Linux) with 2GB Ram. This is the minimum that I would recommend. Remember the more ram and processing power, the more virtual machines/better performance. Both can run either Windows or Linux as a guest operating system. OK, what are the differences? They are Basic. VMware Server is designed with the Data Center in mind… it is a Server product while VMware Workstation 7 (while more flexible) is built for the desktop/laptop. With Workstation 7 you can demonstrate a complete network solution on your laptop – You can even run ESXI on one of your virtual machines. OK, which should I use….? Remember the universal answer – It all depends.
Actually, I plan to use both…. I can use VMware Server to establish a small test and development lab to evaluate software. When I am ready, I can use the VMware upgrade roadmap so that I do not lose my infrastructure investment. I can also use VMware Workstation as a demonstration platform both for the infrastructure and developed solutions.
How will you use these entry points?

Wednesday, September 8, 2010

Go Ahead, Rub the Lamp....

Well, I have been to the mountain top, but now I am back in the valley. I saw the big “cloud” and it looks like a magic genie. It offers “IT as a service”, reduction in time to a positive ROI, more freedom for end users, and effective control for the IT department. Well Aladdin, what do you think? Is it real or just smoke and mirrors? My take is that it is real but like the story goes, you need to be wise and prepared when you let the genie out of the bottle. This is sophisticated technology and just because it has a lot of graphical interfaces with the underlying code does not mean you can treat it like a series of drag-and –drop applications.
Remember that virtualization is networking and the same principles (and more) apply. Think of basic virtualization as today’s version of clustering – powerful but like the “genie”, waiting for some unsuspecting soul to have a momentary lapse in vigilance only to find they are trapped inside the “bottle of frustration”. Fortunately, the reigning “King of the cloud” and your ole buddy, the” IT Sage” understands this dilemma and stands ready to assist you. VMware has a veritable plethora of documentation, training videos, online training, discussion groups, and people like me, who have become converts, to assist you on your journey.
Maranatha & Associates, Inc., the sponsor of this blog, has partnered with the “royal court” of “cloud computing and stands ready to assist you on your journey. The video below depicts our philosophy.

Thursday, September 2, 2010

VMWorld 2010: Days 2 & 3

Wow, what a rush. These three days have been at a non-stop pace. There are over 17,000 attendees. Over 13,000 hands-0n lab sessions (advanced and basic), ranging from installation of vSphere to troubleshooting VMware networking issues have been completed. The logistics of this conference has been intense. These folks "get it". No matter if you are a potential customer, a reseller, or a partner, VMware will win you over (is it the "dark side? - don't think so)... There are real programs here for everyone. Validation is shown in the "partners" that are investing their resources to support virtualization and the VMware paradigm. There are heavy weights like EMC, HP, Symantec and others who have reinvented themselves in the image of virtualization, e.g., Wyse, the thin client producer (remember them). The bottom line is that it is apparent that this product is currently setting the IT industry on a new path. Whether you want to call it "Cloud Computing" or enhanced data centers, it is not just infrastructure but a living treatise on how commercial and public sector entities can do business more efficiently. The goal is quite ambitious - satisfy the two factions of the company enterprise who traditionally are at odds with each other - the end user who wants freedom and the IT department who requires control - Good Luck with That....

Monday, August 30, 2010

VMworld 2010 - Day One

After arriving last night, I was raring to go this morning. Up early (4:00AM PDT)... Waiting for someplace to open so I can eat breakfast... Find a Denny's and around 7:00AM head down to the Moscone Center to register and am struck with the enormity of this conference. VMware has decided to make a statement.... They have taken over every cardinal point of the compass in the Moscone Center. The image is of only the West Moscone Center Building. As far as I could see, North and South buildings were equaly adorned. The guys really planned an intense convention... If it deals with VMware, it is here. There are sessions on every aspect of current and near term projected VM products. The Hands-On Lab is state of the art (VM art -that is)- Both Basic an Advanced subjects are covered. The discussions, at least the ones I attended were informative, interactive, and at times intense-I loved it. I estimate that there are over 320 breakout sessions and workshops being attended by approximately 16,000 attendees. The planners are quite socially oriented and are "eating" their own dog food". They have set up stations where we can use Thin-Client machines to access apps in their "private-cloud" and have created mobile apps proving that VMware is aiming to design for user personal computing and not just for the personal computer. Tonight's the welcome reception and gracefully, the first session is not until 0930 tomorrow. I'm looking forward to the Keynote.













Friday, August 27, 2010

Hey, Doesn't that Cloud Look Like a....

2010, so far, has been an exciting year. New “killer apps” such as Android and VMware (although not new , it has expanded to epic proportions) have gotten our attention with a vengeance. Cloud Computing, no matter what your feelings about it has become a household word. What’s that you say? Cloud Computing is nothing more than a reinvention of the “Data Center”. Well partly true, but it is much more than that. The underlying technology –Virtualization - can change the way small and medium companies do business – not to mention the “green” produced by large companies and Government agencies. My sponsor, Maranatha & Associates, Inc., has shown me that it can be used internally to enhance the efficiency of the business infrastructure and significantly lower the total cost of ownership. Isn’t that a primary activity in a successful business…? Do more with less? VMware, Microsoft, and Citrix seem to think so. They have built products that permit the SMB to be more productive and expand into the market by adding their own Open Source Products into an integrated solution, such as MAI’s MOSIS Systems Integration Solution. If you want to learn more about what the industry thinks, watch the video below of Paul Maritz, VMware President and Chief Executive Officer.



Okay, I’m interested; I am going to VMWorld 2010 and check this out stay tuned because I will be blogging daily… STAY TUNED!

Monday, January 26, 2009

Open Source: “Democracy” enhancement or “Economic” stimulus

Recently I received a very interesting comment about the use of Open Source software – the commenter stated he thought that Open Source software created a society of more democracy, more openness and less concentration of power and for him economic benefit is not so important as democracy.

This posed an interesting question for me; does the Open Source software enhance democracy or stimulate the economy? I came up with an answer of “Yes, but it depends…” The concept of open source is going to become an undercurrent to almost everything the new United States administration does," declared Open Source Initiative (OSI)'s Michael Tiemann. "The American concept of democracy is not just of the people and by the people but with the people." He said we have already seen a commitment to this open philosophy throughout President Obama's election campaign. Mr. Tiemann went on to say, "I think what we will see now is a maturation in America and around the world of an understanding of the open source model."

When pondering this question, I found myself on the horns of a dilemma. I realized that this was not a binary question. If I am in a dictatorship, it may make no difference how much software I write and distribute freely under a GNU license, I still am in a dictatorial regime and thus in this case, the answer is No! However if I am fortunate enough to live in a country whose overnmental foundation is democratic, the production and Open Source distribution of software available to the general populace does enhance democracy by empowering more people than commercial proprietary software – the last United States Presidential election is a case in point – Yes, Open Source software does enhance democracy. The ready availability (meaning free or inexpensive) of various types of modifiable applications to the general public confirmed a genre whereby individual citizens could express their opinions and amuse or annoy the rest of the citizenry.

Now as far as being an economic stimulus – the conventional answer is: Yes, but Open Source software comes with an explicit or implicit price tag. If as a small business or a government agency, you do not understand this, you are in for a rude surprise. It should not come as a mystery why companies that were producers of large and expensive proprietary software are now co-opting Open Source software companies or adopting a previously unimaginable Open Source philosophy.

Potential Open Source clients need to be aware that, just like democracy, it comes with a price – diligence. If your choice of an OS application is not mature, you may find you’re with unexpected development costs and at lease Operations & Maintenance (O&M) costs.

On the up side, I have found that through diligent research, Open Source software can serve as a catalytic framework (at a minimum) or as a complete application (requiring on configuration) – depending on you requirements.

OK, so what do you think….?

Monday, January 12, 2009

Common Mistakes made by new LINUX Administrators

MAI in our quest to enlighten, share and empower are always seeking knowledge worthy of sharing. This Blog Article takes advantage of the knowledge of Jack Wallen: A major player and writer of Linux articles for TechRepublic. Jack was responsible for bringing Linux to TechRepublic. And for years Jack not only managed the Linux content on the site but was the primary writer for that OS that most thought only fit for schools and hacker basements. Time did march on and so did the acceptance of Linux. Jack keeps his Linux fingers typing to help others learn the ins and outs of the OS. In his "spare" time, Jack does graphic/web designs, writes crime-thrillers (waiting to be published), and mountain bikes with his lovely wife.

For many, migrating to Linux is a rite of passage that equates to a thing of joy. For others, it’s a nightmare waiting to happen. It’s wonderful when it’s the former; it’s a real show stopper when it’s the latter. But that nightmare doesn’t have to happen, especially when you know, first hand, the most common mistakes new Linux administrators make. This article will help you avoid those mistakes by laying out the most typical Linux missteps.

Note: This information is also available as a PDF download.

#1: Installing applications from various types
This might not seem like such a bad idea at first. You are running Ubuntu so you know the package management system uses .deb packages. But there are a number of applications that you find only in source form. No big deal right? They install, they work. Why shouldn’t you? Simple, your package management system can’t keep track of what you have installed if it’s installed from source. So what happens when package A (that you installed from source) depends upon package B (that was installed from a .deb binary) and package B is upgraded from the update manager? Package A might still work or it might not. But if both package A and B are installed from .debs, the chances of them both working are far higher. Also, updating packages is much easier when all packages are from the same binary type.

#2: Neglecting updates
Okay, this one doesn’t point out Linux as much as it does poor administration skills. But many admins get Linux up and running and think they have to do nothing more. It’s solid, it’s secure, it works. Well, new updates can patch new exploits. Keeping up with your updates can make the difference between a compromised system and a secure one. And just because you can rest on the security of Linux doesn’t mean you should. For security, for new features, for stability — the same reasons we have all grown accustomed to updating with Windows — you should always keep up with your Linux updates.

#3: Poor root password choice
Okay, repeat after me: “The root password is the key to the kingdom.” So why would you make the key to the kingdom simple to crack? Sure, make your standard user password something you can easily remember and/or type. But that root password — you know, the one that’s protecting your enterprise database server — give that a much higher difficulty level. Make that password one you might have to store, encrypted, on a USB key, requiring you to slide that USB key into the machine, mount it, decrypt the password, and use it.

#4: Avoiding the command line
No one wants to have to memorize a bunch of commands. And for the most part, the GUI takes care of a vast majority of them. But there are times when the command line is easier, faster, more secure, and more reliable. Avoiding the command line should be considered a cardinal sin of Linux administration. You should at least have a solid understanding of how the command line works and a small arsenal of commands you can use without having to RTFM. With a small selection of command-line tools on top of the GUI tools, you should be ready for just about anything.


For More information on these items and other mistakes new LINUX administrators make; See TechRepublic article at http://blogs.techrepublic.com.com/10things/?p=455

#5: Not keeping a working kernel installed
Let’s face it, you don’t need 12 kernels installed on one machine. But you do need to update your kernel, and the update process doesn’t delete previous kernels. What do you do? You keep at least the most recently working kernel at all times. Let’s say you have 2.6.22 as your current working kernel and 2.6.20 as your backup. If you update to 2.6.26 and all is working well, you can remove 2.6.20. If you use an rpm-based system, you can use this method to remove the old kernels: rpm -qa grep -i kernel followed by rpm-e kernel-{VERSION}.

#6: Not backing up critical configuration files
How many times have you upgraded X11 only to find the new version fubar’d your xorg.conf file to the point where you can no longer use X? It used to happen to me a lot when I was new to Linux. But now, anytime X is going to be updated I always back up /etc/X11/xorg.conf in case the upgrade goes bad. Sure, an X update tries to back up xorg.conf, but it does so within the /etc/X11 directory. And even though this often works seamlessly, you are better off keeping that backup under your own control. I always back up xorg.conf to the /root directory so I know only the root user can even access it. Better safe than sorry. This applies to other critical backups, such as Samba, Apache, and MySQL, too.

#7: Booting a server to X
When a machine is a dedicated server, you might want to have X installed so some administration tasks are easier. But this doesn’t mean you should have that server boot to X. This will waste precious memory and CPU cycles. Instead, stop the boot process at runlevel 3 so you are left at the command line. Not only will this leave all of your resources to the servers, it will also keep prying eyes out of your machine (unless they know the command line and passwords to log in). To log into X, you will simply have to log in and run the command startx to bring up your desktop.

#8: Not understanding permissions
Permissions can make your life really easy, but if done poorly, can make life really easy for hackers. The simplest way to handle permissions is using the rwx method. Here’s what they mean: r=read, w=write, x=execute. Say you want a user to be able to read a file but not write to a file. To do this, you would issue chmod u+r,u-wx filename. What often happens is that a new user sees an error saying they do not have permission to use a file, so they hit the file with something akin to chmod 777 filename to avoid the problem. But this can actually cause more problems because it gives the file executable privileges. Remember this: 777 gives a file rwx permissions to all users (root, group, and other), 666 gives the file rw privileges to all users, 555 gives the file rx permissions to all users, 444 gives r privileges to all users, 333 gives wx privileges to all users, 222 gives w privileges to all users, 111 gives x privileges to all users, and 000 gives no privileges to all users.

#9: Logging in as root user
I can’t stress this enough. Do NOT log in as root. If root privilege access is needed to execute or configure an application, you should su to root in a standard user account. Why is logging in as root bad? Well, when you log on as a standard user, all running X applications still have access only to the system limited to that user. If you log in as root, X has all root permissions. This can cause two problems: 1) if you make a big mistake via a GUI, that mistake can be catastrophic to the system and 2) with X running as root that makes your system more vulnerable.

#10: Ignoring log files
There is a reason /var/log exists. It is a single location for all log files. This makes it simple to remember where you first need to look when there is a problem. Possible security issue? Check /var/log/secure. One of the very first places I look is /var/log/messages. This log file is the common log file where all generic errors and such are logged to. In this file you will get messages about networking, media changes, etc. When administering a machine you can always use a third-party application such as logwatch that can create various reports for you based on your /var/log files.

Sidestep the problems

These 10 mistakes are pretty common among new Linux administrators. Avoiding the pitfalls will take you through the Linux migration rite of passage faster, and you will come out on the other side a much better administrator.

Sunday, November 23, 2008

Open Source Implementation – Factors for Success

The difference between the successful open source implementation, in which the value of open source is realized for a company, and the unsuccessful one, in which the struggle to use open source is not worth the effort, amounts to knowing your problem, knowing the software, and knowing yourself.

The key to a successful outcome in applying open source is a thorough understanding of answers to the following questions:
• What problem are you trying to solve?
• How would open source software help in providing the solution?
• Does any open source software provide all or part of the solution?
• How can the maturity and stability of relevant open source software be determined?
• What skills are required to install, configure, customize, integrate, operate, and maintain the open source software?
• Does your organization have the needed skills? If not, how can they be acquired and institutionalized?
• In which cases does the value provided by the open source software exceed the cost of using and maintaining it, compared with other solutions?

An IT department that intends to adopt open source must have not only the resources to do so, but also a belief in skills building and an inclination to take increased responsibility for its IT infrastructure. We have analyzed the nature of open source and have listed three different models that can help companies evaluate the vast world of open source in a manner that is consistent and enables them to understand their own capabilities.

The models are:

1. Open Source Maturity Model: A set of questions that help determine the stability and maturity of an open source project, the responsibilities involved in using a particular piece of open source, and the skills needed to manage those risks (http://www.navicasoft.com/pages/osmmoverview.htm)
2. Open Source Skills and Risk Model: A set of questions that help determine the ability of an organization to handle various risks and the tolerance of risk for a specific project (See Open Source for the Enterprise By Dan Woods and Gautam Guliani – From which much of this article is borrowed)
3. Software Cost and Risk Model: A set of questions that help determine the total costs and risks of using open source as a solution for a project (http://sunset.usc.edu/csse/research/COCOMOII/cocomo_main.html)

Monday, October 13, 2008

Open Source Software… Reality versus Myth

Recently, I have been working a couple of projects that have pitted commercial software against Open Source Software (OSS) during an evaluation phase to decide which to use in an enterprise CRM application. Initially, the commercial software won because of reluctance to change the selection process, misunderstanding of the real completeness of a COTS product (most COTS products require some degree of customization – the amount depends on the enterprise architecture and the complexity of the API), an over reliance on the face value of information provided during the presales phase of acquisition, and finally, the focus of the Open Source developers to provide an engineering framework and not a finished product (Although this is changing as more as more OSS developers recognize the commercial value of their product e.g., MySQL, SugarCRM, and Talend).

The adoption of OSS in the government is gaining momentum. OSS is reaching significant penetration well beyond its traditional IT infrastructure domain and is moving into applications, business intelligence and customer relationship management (CRM). Drivers of OSS adoption are also changing, witnessing increasing user maturity. The lower cost and local economic development benefits that drove early adopters have been replaced by total cost of ownership (TCO) considerations and the desire to overcome procurement complexity.

Currently, there is little expectation that open source will really free users from vendor dependence. However, an important aspect is the emergence of collaborative development efforts between agencies that use an open-source development process. The other side of the coin is; have you ever acquired a COTS product for an enterprise application that did not require engineering or significant “customized development”? Even such stalwarts as Microsoft are designing there signature products (such as Office) as platforms capable of being engineered, configured, and developed into enterprise applications.

FYI…. The commercial product first chosen, had to be abandoned due to cost and non-adaptability to the overall architecture…

Tuesday, June 17, 2008

Open Source Ponderers, Ponder No More

Now that you feel fairly comfortable with your understanding of various Open Source licensing models – not sure which one is the best but you do know the differences… What Now? This will depend on a number of interrelated things - The capabilities of your company (which is closely associated with the “entrepreneurial model” of your company) and the maturity of the open source software. Are you a small or medium size company with an “early adopter” or “pragmatic” attitude? Are you a government agency – Federal, State or Local? Are you willing to internally “productize” an open source application? Do you have the programmers and testers to undertake such an endeavor? Should you outsource? Your next steps and decisions will be probably determined by how you answer these questions.

For example, if I am a small business or local government entity, I would probably want a “COTS” product (or at least one that is considered mature) because I have no interest in redistributing it (additionally, this makes my licensing choice a little easier.). I now must make a choice on Open Source application maturity. I also need to decide if I customize and integrate the chosen application with my internal resources or partner with an innovative company that focuses on Open Source integration within the enterprise. What would you do?

Your input is important because there is, understandably, a plethora of Open Source documentation written from the engineering aspect or from the entrepreneurial view point. But it is equally important that discussion from the “Business Person” requirement and concerns be heard….

Stay tuned, for discussions on “early adopters” versus “pragmatist” business models and their use of Open Source…

Monday, May 19, 2008

What is Open Source software and just what does it mean for your business?

This is the first in a series of blogs by MAI personnel to stimulate discussions within the community about Open Source software and its future impact on your business. This blog is purely introductory and will be followed up by blogs which specifically address both technical and business issues.

What is Open Source software and just what does it mean for your business? First, Open Source software does not mean “public domain”. For software to be in the public domain, the author must disclaim the copyright in the code. Open Source authors retain their copyrights. The difference lies in what the copyright holders elect to do with their rights in the code.

It is important for a business to understand that open source is fundamentally grounded in intellectual property law. There are five basic rights in copyright: the right to perform, the right to display, the right to copy, the right to make derivative works and the right to distribute. All software licenses grant the first two. The most significant differences between open source and proprietary software are the rights under copyright that the licensor grants to the licensee and the use philosophy behind each. The proprietary licenses restrict the use of the software as much as possible while the open source licenses have the aim to encourage wide use. Additionally, do not confuse Open Source and not being commercial. Open Source software can be commercial and in our case the “Free” in “Free Software” equates to “Freedom of use” not price.

There were some exceptions in the early nineties when the larger commercial software companies allowed “restrictive” inroads into their applications through the use of “Macros” (this practice quickly dried up once the larger firms saw this as a threat). This practice continues through the use of proprietary code such as (Application Programming Interfaces (APIs). However, businesses must carefully examine their licenses if they want to redistribute the modified code.

There are several good sources on Open Source licensing. One is “Understanding Open Source and Free Software Licensing” by Andrew M. St Laurent and another is titled “Succeeding with Open Source” by Bernard Golden. The knowledge of the fundamentals of intellectual property (as it pertains to software) helps in understanding what open source means to the several classes of users: (1) Small and medium-size businesses; (2) Enterprise customers; (3) Original equipment manufacturers (OEM); (4) Independent software vendors (ISV); and (5) Educational software and schools. Each of these categories has its unique requirements and issues which must be managed. Although having varying degrees of complexity, depending on your category, these issues are manageable. This is witnessed by the entrance of the major commercial vendors’ (Sun, Oracle, etc…) entrance into the Open Source arena at various levels.

Stay tuned….