Monday, March 24, 2014

New Tool Release - ASPASC (ASP.Net Application Services Configuration Tool)

After a long time about thinking of creating a tool that I could use to easily configure and maintain Membership and Role for ASP.Net applications that use ASP.Net Application Services, I finally got around into creating one.

The tool is a WCF application, which can connect to existing aspnetdb databases or help the user create a new aspnetdb database.

The tool can then maintain the users and roles available to each application in the database, as well as add additional applications.

You can find the tool on Codeplex: ASP.Net Application Services Configuration tool

As always, the tool is Open Source, so feel free to dig around, use it and should you find any issues, let me know.

Tuesday, August 13, 2013

TOTP for ASP.Net Web Forms

Ok, so following my previous post (Two-Factor Authentication - What's the right way) I decided to go on and create a Proof of Concept on how to implement RFC 422 (the way a lot of web services implement 2 Factor Authentication, including Google, Microsoft, DropBox, LastPass etc) using ASP.Net with the Membership Provider.

Although I managed to find a lot of sample code to implement the RFC in .Net code, I failed to find anything that implements this using ASP.Net Membership Provider (MP). In just a few words, MP is a solution built in to .Net Framework that allows for user and credential management in .Net applications (more here). Please note that the same concept can be applied in different frameworks.

Monday, June 3, 2013

Two-Factor Authenication - What's the right way

Following the numerous compromises of accounts to various online services (with the most news-covered being the Twitter account compromises), more and more online services are providing means for Two-Factor Authentication (2FA).

Just as a short primer, authentication is the procedure a service has in order to verify that the user claiming to want to authenticate is actually the user which holds the account. A good simple example (of one-factor authentication) is a username/password combination. I authenticate to the service by providing my username/password combination, and since I am the only on that should know this, I am authenticated as being the owner of the account.

The big problem with the above is what happens if my credentials are stolen or compromised? Well, the service can be tricked by a third person, which can provide the valid username/password combination, into thinking that the third person is me! Granted, there are cases where this is actually desirable (such as shared accounts) but in the end, the result is the same; the service has no way to identify that the person between the chair and the keyboard (or behind the touchscreen nowadays) is the account holder.

Thursday, January 3, 2013

Give your Hyper-V Guest OS's Wireless Internet

I was playing around with creating a virtual lab for a Microsoft Certification I had to do, using Hyper-V on Windows Server 2008 R2. This involved setting up several VMs, which would need updates etc. 

Since my desktop computer uses a wireless USB card for internet connection (my home router is quite a ways away for an ethernet cable and I am too lazy to route one through the wall :) ), I had to figure out how to do this. 

First step, of course, is to make sure that the Hyper-V host can actually utilize the USB wireless dongle. Apart from drivers, you will need to install the "Wireless LAN Service" feature (or you might get stuck for a couple of days trying to figure out why the dongle doesn't work when it should - like I did :) ). 

Next you will need to do a couple of things; Ken Schaefer's blog post was the starting point. Though mostly text based, he links to a blog post by John Paul Cook which provides an illustrated version of Ken's post (as well as an alternative method). Basically, you leverage the Windows Server RRAS role, namely NAT, to route traffic from your Hyper-V Internal network (it needs to be internal - external binds the network to a physical NIC, whereas private does not allow access to the host machine) to the Wireless interface.

What the above blogs failed to mention was a small but important detail: when assigning an IP address to the internal network interface, that address needs to be in the range of the IP addresses used by the VMs. So, if your Hyper-V internal network uses a 10.0.0.0 network, you should allocate an IP within that range (as an example, 10.0.0.250).

Once that is done (assuming the VMs are server OSs and are assigned a static IP address), you need to make sure you can both communicate with the Internet and with any Domain Controllers you may have as a VM (at least, in my case - remember, this is my lab setup). So, the final step is re-configuring the NICs in the VMs to have as a Gateway the IP you assigned to the Internal network NIC (i.e.10.0.0.250) and the DNS servers should be your Domain Controller's IP as primary, and the Internal network's IP address.

The above allowed me to access the internet from the Hyper-V VMs, and do what was needed. Cheers :)

Friday, October 14, 2011

FIM 2010 With ORACLE MA

For a recent FIM 2010 installation, I had to connect to an ORACLE DB (which was the authoritative source).

I had found a number of articles and forum posts that had bits and pieces of information about what to do, none of which was complete. So, I decided to add this blog post as a short how-to.

Since FIM 2010 runs on Server 2008 R2, you need the 64-bit client tools for ORACLE. I found that the 64-bit 11.2.0 client setup package works best (for ORACLE 11g) and can be found here. Install the Full Client.

Now, there are a couple of steps you need to do (or make sure they where done by the installer) for the configuration to work:
  • Set (or create) the ORACLE_HOME environment variable. Should have a value of the installation path up to the client_X folder.
  • Add to the PATH environment variable the value leading up to the path where you have placed your TNSNAMES file.
  • Give access to the Synchronization Service account to the ORACLE client installation folder (make sure they are inherited up to the folder where your TNSNAMES file is stored).

After the installation completed, I fired up the Synchronization Service Manager, created an ORACLE MA, and tried to connect to the database to read a View I had created. Everything worked as a charm!

FIM 2010 with SAP

I was at a customer that requested a FIM installation that would get data from SAP HR 6.0.
So, after the installations where completed, the first thing I tried was actually connecting to SAP.
To do this, you need the SAP .NET Connector 2.0 from SAP website (http://service.sap.com/connectors) and you need some files from the msi package. More on this here.
Now, what the article does not say is that you additionally need to configure how FIM will communicate with SAP.
If you get an error when trying to connect through the ERP MA Configuration Tool stating that it cannot communicate with SAP, you need to configure the services.
The way to do this is to add in the services file (under Windows\System32\drivers\etc) the following lines:
sapdp##  32##/tcp # SAP Dispatcher.       
sapgw##  33##/tcp # SAP Gateway.          
sapsp##  34##/tcp # 
sapms##  36##/tcp # SAP Message Server.   
sapdp##s 47##/tcp # SAP Secure Dispatcher 
sapgw##s 48##/tcp # SAP Secure Gateway 

where the ## is the system number your client has given their SAP system.
(Find the documentation for the above here). 

There are a couple of things you should try if even this fails:
  • Run the ERP MA Configuration tool as Administrator.
  • Instead of providing the name of the server in ASHOST, type in the IP.
    (Even though I added the entry in the hosts file, I still needed to give the IP.)
Now, I also had an issue when Discovery started. The progress bar would go all the way to the end, and then I would get a message stating:     
The functions or structures in your configuration do not match those in the discovery cache. Saving will produce an unusable ERP MA.
Click ‘Yes’ to rebuild definitions from discovery cache.
Click ‘No’ to cancel Saving.

When I clicked 'Yes' I would get an application exception stating that there was an error retrieving a referenced BAPI function from Discovery. After spending a couple of hours trying to figure it out, I logged out of the machine and went home. The next day, it worked! No idea why, so just try to log out and then back in.

Another issue I faced, once I had the MA set-up in the Sync Service Manager, after trying to do a full import, I kept getting an error stating a "stopped-extension-dll-exception". Looking in the Eventlog, I found out that a FileNotFoundException was thrown and it was looking for the .xml file in the Extenstions directory. So, I needed to set the MA Name to the .xml file exported by the ERP MA Configuration Tool. Once I did that, everything worked like a charm.

Monday, January 12, 2009

Isolate applications on your PC

A lot of IT professionals and security experts try to lock down their machine against malicious code (especially those who run Windows OS's). When I come along a new free application, I first like to try it out in a virtual machine environment, just to be on the safe side in case their is malicious code running in the application.

But, there are malicious applications that can detect the virtual environment, and do not try to exploit the machine. What can someone do in that case?

There is a very very nice applications, called Sandboxie by Ronen Tzur. This small application basically runs any application (even installers) in isolated space, so any changes made to the filesystem are not reflected in the actual systems' filesystem. This space may be discarded at any time, and with it, any changes made by malicious code.

The newest version (3.34) has the addition of a DropMyRights like feature, which runs the isolated application with the lowest possible level of rights on the machine. In general this is a very nifty application, and one that is very modestly priced. Purchase allows the user a lifetime subscription of updates, and unlimited use of the application on any computer that the end-user owns.

There are limitations though (such as the inability of Sandboxie to be installed on Vista or XP 64 bit versions, due to Windows PatchGuard), but is overall, in my modest opinion, a must have application for the security conscious.