The recent announcement from Amazon of the Virtual Private Cloud (VPC) represents the next big advance in the evolution chain for cloud computing. Enterprises can now integrate their IT infrastructure with Amazon's vast computing and storage resources, using a VPN connection from their data center to their own virtual private cloud which then looks like part of their internal network.
Until the release of VPC, companies were left to build applications and utilize the cloud as a separate and somewhat siloed portion of their computing environment. In addition to the VPN connection, VPC allows cloud users to control their IP addressing within the Amazon cloud (previously IT addresses were assigned randomly). This may sound trivial, but it solves some tricky problems that made it hard to integrate cloud and internal resources.
Prior to VPC, every time you started a server in Amazon, you would get a new, randomly assigned IP address for that server. This created a lot of issues with how typical applications operate, e.g.: how do you communicate the address of this new server? How do you run authentication/certificate processes with a changing address? How do you deal with identity when IP addresses change at every start? Add to this the fact that cloud servers were separate from internal servers, so internal services that you normally take advantage of (DNS, LDAP, etc.) were not available without a lot of work. VPC provides a way to connect cloud resources to your data center and start to smooth over the differences.
Okay, how does this work? A standard edge networking device in your data center is configured to connect with Amazon's VPC. You can create your own sub-nets within Amazon, and when you launch a server you assign it to one of them. You specify the IP address range for your servers, and VPC performs the "security dance" to build the VPN between the edge device and your private network in Amazon's cloud. All you have to do is update your routing tables so that processes in the data center can reach applications in the cloud and you're off to the races.
By allowing customers to integrate their data center networks with Amazon's cloud, VPC takes the first step in bringing the cloud and the enterprise data center together. While one large hurdle has been removed, there's still work to be done, as indicated in RightScale's blog. As enterprises review the VPC offering, there are things they need to consider as they determine how to deploy and use it.
So to sum up, Amazon's VPC represents an exciting step forward along the road to making the cloud truly enterprise-ready. Cloud computing has come a long way over the last two years, and in many ways Amazon has been setting the pace. Their new offering lays the foundation for the next set of solutions for enterprise adoption from other companies in the cloud computing ecosystem. At CloudSwitch, we're excited to take advantage of the ongoing improvements by Amazon to their infrastructure, and working hard to eliminate complexity and make cloud computing simple, seamless and more cost-effective than ever.
With the iPhone more than earning its place in the consumer market, it is now being adopted by enterprises. But just how easy it is to create robust enterprise applications for the iPhone, as well as all the other major mobile platforms? With Ruby and HTML in the cloud, according to Rhombobile CEO Adam Blum, the answer is "Very easy." Blum will be presenting a 45-minute breakout session at iPhone Developer Summit 2009 West, being held November 3rd, 2009, at the Santa Clara Convention Center in conjunction with SYS-CON's 4th International Cloud Computing Expo (November 2-4, 2009).
IBM today announced a more effective way for organizations to quickly build, deliver and manage high quality services. Through new software integrations, organizations can manage and automate processes across their development, test and operations teams. These new integrations give clients better control over the services they provide to customers while lowering the overall cost of delivery and shortening the time to market for new services.
In this session David Snead will address the legal, business and marketing issues of involved in moving into these new services, and what anyone entering into a new contract, or marketing to end users needs to know. Some areas of discussion include how to create a marketing campaign that capitalizes on the differences between the new world of hosting and the old world, as well simple explanations combined with examples for any business owner that needs to outsource technology.
Yahoo! is developing and utilizing Internet-scale cloud computing services to improve Yahoo! consumer experience, speed innovation, simplify operating environments, and reduce costs. Yahoo! Cloud Services are in production today supporting web-serving properties and data processing environments. Keynote Speaker Shelton Shugar will also discuss how Yahoo! Cloud Services store and deliver web content, personalize content for consumers, optimize Ad selection and placement, improve search results, provide scalable virtual computing environments, and process and store enormous amounts of data to improve consumer experiences and drive innovation.
Based on real-world case studies, this session by Agatha Poon will identify key operational imperatives including location, regulatory support, security, and interoperability that help shaping a scalable, global cloud infrastructure, and its timeline.
Cloud Computing, the long-held dream of computing as a utility, has the potential to transform a large part of the IT industry, making software even more attractive as a service and shaping the way IT hardware is designed and purchased. But if it is already a commercial reality, why does Richard Stallman call it "worse than stupidity"? What, if any, are the new economic models enabled by Cloud Computing, and how can a service operator decide whether to move to the cloud or stay in a private datacenter? What changes should be made to the design of future applications software, infrastructure software, and hardware to match the needs and opportunities of Cloud Computing? All these questions may leave you wondering, but at the Cloud Computing Conference and Expo, Rob Walters, Willie Tejada, Terry Woloszyn, Barry X Lynn, Adam Blum and Greg O’Connor will be sure to help you to better understand whether Enterprise-Level Cloud Computing is a far-off dream or a present reality.
This session will cover how to enable rich and complete User Experience customizations. According to Ranjith Ramakrishnan and Bhushan Nene, building on the new features of Silverlight 3 and Windows Azure, delegates will see these concepts in action in a demo of a Customer Loyalty Management application.
The time has finally come for collaboration in the cloud. Multiple offerings and tools are now readily available for your organization to migrate your on-premise collaborative applications (e.g., e-mail, instant messaging, and portals) to the Cloud. Implementation and use of these tools alone, though, will not guarantee your organization a successful migration. Jeffrey Miller will guarantee you that when you leave this session you will be ready to move forward in the successful evaluation and migration of their collaborative applications.
With the push to maximize IT amid the ever shrinking IT budgets, one of the “holy grails” of IT is to use the cloud service model to reduce the TCO for their endpoints whether it is desktops, laptops, or smart mobile phones. Danny Kim will go in-depth into the architecture and deployment of how FullArmor, an innovative vendor that's developed one of the first commercial Windows Azure cloud service, provided full endpoint management, security, and software deployments through the cloud for hundreds of thousands of endpoints in the emerging markets at a fraction of the cost of traditional models.
In the previous post we looked at how to configure the SQLAuthenticator password encryption options. Among other encryption algorithms we discovered that on creating a user from the WLS console, WLS would create the associated user in a database table with password "password" encrypted to:
{SHA-1}W6ph5Mm5Pz8GgiULbPgzG37mj9g=
...when the SHA-1 option was set.
As was mentioned in the previous post, as the database table with its users and passwords may be shared by non-WLS based applications, it's important that those systems can encrypt passwords and compare them to the WLS result. In other words, in the example above, given that WLS generated a SHA-1 encrypted password, if another system uses the same SHA-1 algorithm will it generate the same encrypted password allowing it to compare the database SHA-1 encrypted password against the SHA-1 encrypted password it has?
In order to check we can get the same encrypted results, we'll investigate generating a SHA-1 password using the Oracle database's encryption facilities (so in this case the database acts as the other subsystem), comparing the database's encrypted SHA-1 password to that of WLS.
The following solution owes thanks to Sean at Oracle Support who very patiently led me in the right direction with my findings.
dbms_crypto
Oracle database fans will be familiar with the dbms_crypto package that provides encryption support.
dbms_crypto allows us to generate an encrypted password that we can compare to the WLS result. From table 34-1 of the dbms_crypto link, we note that dbms_crypto supports the following one-way hash algorithms: SHA-1, MD4 and MD5. As WLS via the JCE extensions (see the previous post) supports SHA-1, MD2 and MD5, it's fortunate we picked SHA-1 for this example.
The following anonymous PL/SQL block shows an example using the dbms_crypto package hash function with SHA-1 to produce an encrypted result:
Note the output, a hex value, and doesn't match our WLS output for the same plaintext password "password" encrypted with SHA-1.
DECLARE
input_string VARCHAR2(8);
raw_input RAW(128);
encrypted_raw RAW(2048);
BEGIN
input_string := 'password';
raw_input := utl_raw.cast_to_raw(convert(input_string, 'AL32UTF8','US7ASCII'));
encrypted_raw := dbms_crypto.hash(src => raw_input, typ => dbms_crypto.hash_sh1);
dbms_output.put_line('Output: ' || encrypted_raw);
END;
/
Output: 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8
...where the hexStringToByteArray function is borrowed from Dave L on StackOverflow.
byte[] bytearray = hexStringToByteArray("5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8");
String base64encoded = new BASE64Encoder().encodeBuffer(bytearray);
Cloud testing is a new way of establishing reliability, leveraging the Cloud to drive traffic to websites – to measure, analyze and assure performance at web-scale. It gives companies confidence that applications, whether in the Cloud or in a data center, can withstand unexpected surges in traffic. Optimizing responsiveness and the user experience before going into production or when changes occur is critical. Tom Lounibos, Dan Barstow and Mike Kavis know that all the attendees will leave their session with an understanding of cloud testing and how it is used today to ensure website reliability and performance.
Cloud computing offers tremendous advantages, providing unparalleled scalability and flexibility to deliver some of business’ most important applications. According to Gene Golovinsky, many businesses are reluctant to adopt cloud-based solutions out of concern for the privacy and security of their data. Unwarranted fear, misguided uncertainty and general uneasiness surround the issue, preventing many organizations from adopting cloud-based solutions. Misconceptions about the inherent security of cloud-based solutions will be explored and methods of overcoming those concerns will be addressed.
Securing data and applications that run on the web and in the cloud are among the most pressing information technology challenges for organizations today. Attacks made through common hacking techniques can lead to financial loss, compliance headaches and disastrous issues with customer privacy and overall satisfaction. At the Cloud Computing Conference & Expo, Lars Ewe will further discuss that while business applications are going online at a record pace, security solutions today are not keeping up. The lack of a proper protocol to test for application vulnerabilities can quickly result in large-scale security breakdowns.
At the Cloud Computing Conference and Expo, Peter Coffee’s session will discuss how cloud computing should not merely relocate the familiar pains, delays, and costs of conventional application development. The cloud already offers developers an expanding field of high-leverage frameworks that measurably improve developer productivity, accelerate deployment and radically reduce project risk.
As the Cloud Computing model proliferates, so will the potential threats. Thanks to the Cloud, the line between the endpoint and the enterprise has blurred. Therefore, it calls for a radically different kind of approach using a trustworthy computing model. At the Cloud Computing Conference and Expo, Dipto Chakravarty will examine ways to use a combination of open source as well as proprietary tools to protect the business assets at the edge of the network in concert with the hub of the enterprise.
Many in the industry have heard of Hadoop, and in his session at Cloud Computing Conference & Expo, Christophe Bisciglia, Co-Founder of Cloudera, gets a little deeper. Hadoop is based on the same methods Google uses to store and process petabytes of data, but thanks to contributions from many in the open source community you can leverage these same methods to make sense of every increasing volumes of enterprise data. Bisciglia will highlight the technical and business issues that make Hadoop so powerful for large scale data processing.
Hundreds of definitions from swarms of providers have created confusion and devalued the cloud storage landscape. In his session at Cloud Computing Conference & Expo, Cameron Bahar, Founder and CTO of ParaScale, will skip to the real questions, who is using cloud storage and why? He will detail cloud storage customer examples and the benefits achieved by leveraging this technology.
Rich Services for Cloud Computing for businesses represent a growing trend from software users wanting responsive and immersive interactions from any location. As business applications begin presenting information the same way as the social web – interactive and visual – and carry the same reach, IT departments must adapt.
Yahoo! is running the largest Hadoop clusters in the world – 25K+ servers, analyzing billions of Web pages, multiple petabytes of storage and billions of records per day. In his session at Cloud Computing Conference & Expo, Eric Baldeschwieler, VP Hadoop Software Development at Yahoo!, will explain what the distribution is, why Yahoo! is sharing its investment in testing Hadoop and how it benefits the larger cloud ecosystem.
Too often organizations have deployed virtual infrastructure tactically to reduce server sprawl or speed application deployments. Without a higher level view of organizational priorities, bad habits persist; unused snapshots and zombie VMs become more the rule than the exception causing budgets to continue their upward spiral. As organizations begin to view virtualization strategically and consider its role in cloud infrastructure, it is important to consider the success factors of this foundational element. In his session at Cloud Computing Conference & Expo, Adam Hawley, Director of Product Management for Oracle VM, will examine virtualization considerations such as workload availability, performance, and integration with enterprise systems and resources that are necessary to improve operational efficiency and service delivery.
Has there ever been a more exciting time to be a small software vendor? Or a larger market opportunity for service providers? Or greater flexibility for customers? Cloud is more than a shift in technology architecture; it's a shift in the full business lifecycle of technology providers and consumers. In his session at Cloud Computing Conference & Expo, Chris Arangio, Product Manager in the Cloud Infrastructure Group at EMC, will discuss the impact of the cloud including the challenges and opportunities for service providers, technology implementers, ISVs and their customers. It will highlight the importance of an ecosystem as a critical enabler and long term business opportunity, and describe key considerations for cloud service consumers and other participants in this ecosystem when developing a cloud strategy.
New Trier High School is consistently considered one of the best public high schools in the country. This documentary looks at different social groups at New Trier High School in Winnetka Illinois. It features interviews with more than 40 New Trier students.
An documentary about the Inter City Firm, a football (soccer) gang that fights with other football gangs before games.