Long-winded Longhorn aims at server security

While not due for general release until this time next year, Microsoft's next-generation server platform, codenamed Longhorn, will be a more secure, manageable, and modular operating system, according to the company.

During his presentation at this year's Tech.Ed conference in Sydney yesterday, Microsoft server division senior product manager David Lowe said security, reliability and performance are the prime concern of people running servers and the company has focused its development efforts on those areas.

"We looked at the way services work in the operating system and reduced the surface area of those services," Lowe said, adding that the right services now run under the right privileges.

Other security enhancements include the Bitlocker volume encryption tool and ability to selectively block new device installations.

While Vista and Longhorn is a shared development project with 70 to 80 percent common code, Lowe said Microsoft has not yet announced the official name for the server, but will do so "soon".

Conceding the company's TCP/IP stack hasn't changed since Windows 95, Lowe said Longhorn's stack is a complete redesign and supports IPv4 and IPv6 natively.

"No additional configuration needs to be done and Longhorn has expanded IPSec integration," he said.

"TCP can now auto-tune packet size based on the network, and the enterprise QoS allows us to mark packets at the protocol level and prioritize traffic, for example with VoIP."

The new Windows Firewall with advanced security supports three different profiles and additional configuration options down to the IP address, computer, and user levels.

Also new is Network Access Protection (NAP) which can be used to provide a statement of health that is checked against a preconfigured policy. NAP supports DHCP, VLAN, 802.1x, and IPSec.

Windows servers have long been tethered by the requirement of a GUI, but this all changes with Longhorn's new "Server Core" architecture.

"People use servers for certain roles and configurations [and] if you don't need any graphical applications you don't need a GUI," Lowe said. "You can run your server in a headless scenario increasing the reliability and security."

The core server roles are DNS, DHCP, File and Active Directory but if you need anything else you need a full installation.

Other new features include a server monitoring and management tool, a re-built Active Directory, and Terminal Services that support end-to-end encryption and smartcards.

Longhorn will ship with version 7.0 of the IIS Web server which now sports a modular architecture with 40 installation components.

IIS 7.0 has a built-in management console running over HTTP, but will be integrated into Server Manager by the time it is released.

Regarding virtualization, Lowe said Longhorn won't ship with the new hypervisor, but the Windows Server Virtualization will be available within six months of Longhorn's release. This means it may not appear until 2008.

More about: HIS Limited, Microsoft

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/150/handbrake/

HandBrake

HandBrake is an opensource tool that allows you to backup your DVDs so that you can store and watch them on your computer. Features include: ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia