<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zen Dzign</title>
	<atom:link href="http://www.zendzign.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zendzign.com</link>
	<description>The official ZZ Servers Blog</description>
	<lastBuildDate>Sun, 27 Dec 2009 18:14:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Anti Virus and PCI Compliance</title>
		<link>http://www.zendzign.com/2009/12/anti-virus-and-pci-compliance/</link>
		<comments>http://www.zendzign.com/2009/12/anti-virus-and-pci-compliance/#comments</comments>
		<pubDate>Sun, 27 Dec 2009 18:14:00 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[malicious software]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=92</guid>
		<description><![CDATA[Last year PCI DSS 1.2 was released changing the intent of the controls required for anti-virus software. In version 1.1 anti-virus software was only required for systems commonly affected by viruses and excluded UNIX based operating systems and mainframes. Version 1.2 now requires all operating system types commonly affected by malicious software be protected and [...]]]></description>
			<content:encoded><![CDATA[<p>Last year PCI DSS 1.2 was released changing the intent of the controls required for anti-virus software. In version 1.1 anti-virus software was only required for systems commonly affected by viruses and excluded UNIX based operating systems and mainframes. Version 1.2 now requires all operating system types commonly affected by malicious software be protected and removes the exclusion for UNIX and mainframes. These changes now open the requirement for protection from &#8220;malicious software&#8221; such as worms, trojans, adware, spyware or any &#8220;malicious software&#8221;.<span id="more-92"></span></p>
<p>In the past, it was though Linux servers were safe from viruses but recently hackers have been taking advantage of this false sense of security. Some researchers point out that 70% of attacks on Linux honeypots were infected with a 6 year old virus (RST-B)* and used as command and control points for botnets.</p>
<p>ZZ Servers now offers affordable F-Prot anti-virus software for Windows, Linux, Exchange, BSD and Solaris. Protect your servers, desktops and critical infrastructure today. Contact <a href="http://www.zzservers.com/">ZZ Servers</a> at 800-796-3574 or email support@zzservers.com to arrange for installation of anti-virus software today.</p>
<p>*RST-B is a backdoor malware runs on Linux/UNIX platforms and infects ELF files in the current and /bin directories. This Linux backdoor and virus compromises system security by allowing remote users to manipulate and access infected machines. If executed as root, it will start processes listening on two network interfaces which provide a remote root shell.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/12/anti-virus-and-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SimpleScripts and Softaculous Script Installer Plugins Now Available in InterWorx 4.0</title>
		<link>http://www.zendzign.com/2009/11/simplescripts-and-softaculous-script-installer-plugins-now-available-in-interworx-4-0/</link>
		<comments>http://www.zendzign.com/2009/11/simplescripts-and-softaculous-script-installer-plugins-now-available-in-interworx-4-0/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 21:45:03 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[InterWorx]]></category>
		<category><![CDATA[Control Panel]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[hosting control panel]]></category>
		<category><![CDATA[Interworx-CP]]></category>
		<category><![CDATA[lamp]]></category>
		<category><![CDATA[shared hosting]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=89</guid>
		<description><![CDATA[The latest release of InterWorx Hosting Control Panel Version 4.0 now includes plugins for two 3rd party script installer plugins &#8211; SimpleScripts, and Softaculous.

These plugins replace the old &#8220;ScriptWorx&#8221; functionality, for those of you that are familiar with it. However, they do more than just replace the functionality. In addition to just installing scripts like [...]]]></description>
			<content:encoded><![CDATA[<p>The latest release of InterWorx Hosting Control Panel Version 4.0 now includes plugins for two 3rd party script installer plugins &#8211; <a href="http://www.simplescripts.com/" target="_blank">SimpleScripts</a>, and <a href="http://www.softaculous.com/" target="_blank">Softaculous</a>.<br />
<span id="more-89"></span><br />
These plugins replace the old &#8220;ScriptWorx&#8221; functionality, for those of you that are familiar with it. However, they do more than just replace the functionality. In addition to just installing scripts like wordpress, magento, etc, these software packages all the end user to also easily upgrade their software when new versions are released.</p>
<p><strong>Are these script installers free?</strong></p>
<p>Yes, and no. It depends on how you want to use them. Both packages have &#8220;Free versions&#8221; that are either ad-supported or limited in some way. See below for details.</p>
<p><strong>Which script installer should I choose?</strong></p>
<p>You can choose to enable either, or both on your InterWorx servers. You decide based on what makes sense for you and your customers. SimpleScripts is enabled by default.</p>
<p><strong>Why is SimpleScripts enabled by default?</strong></p>
<p>We choose to enable the SimpleScripts plugin by default because we felt that it provided the easiest transition for end users that are used to using ScriptWorx to install scripts.</p>
<p><strong>What are my options if I don&#8217;t want myself or my customers to pay anything extra?</strong></p>
<p>Both software packages have free versions, so you don&#8217;t have to do anything!</p>
<p><strong>What about my old ScriptWorx installs?  Can I import them?</strong></p>
<p>With some scripts, you may be able to import existing script installs into the script installer software packages for management. Check the relevant documentation for details.</p>
<p><strong>How are SimpleScripts and Softaculous different than one another?</strong></p>
<p>As you might expect there are a number of differences.  I will cover some of the important differences and similarities here.</p>
<ul>
<li> User interface<br />
Even though both script installer packages provide similar functionality, they have significantly different user interfaces. See each software package&#8217;s website for demonstrations.</li>
</ul>
<ul>
<li>Available Scripts<br />
While there is a lot of overlap in script support, there are some differences as well. See the websites linked above for details.</li>
</ul>
<ul>
<li>Service Design<br />
SimpleScripts is a &#8220;software as a service&#8221; solution &#8211; when the end user clicks on the SimpleScripts menu item in SiteWorx, they are sent to the simplescripts.com website. Before they get sent there, simplescripts is granted a special FTP user and API access to their SiteWorx account data, and SimpleScripts uses these tools to perform the script installation. Information about what scripts are installed where is maintained on the SimpleScripts servers. No SimpleScripts software is actually installed on the InterWorx server. The SimpleScripts software is updated on the SimpleScripts servers.</p>
<p>The Softaculous software is actually installed and run on each InterWorx server. It gets installed automatically the first time the plugin is enabled. The softaculous software itself is installed under /usr/local/softaculous, and the software packages softaculous can install get placed in /var/softaculous. Softaculous also makes use of the InterWorx API to assist the user with the installs. Softaculous will install a cron job periodically check for new script updates.</li>
</ul>
<ul>
<li>Software Administration<br />
With SimpleScripts, you can customize your customer&#8217;s interaction with the software by creating your own SimpleScripts &#8220;web host account.&#8221; This is not required, but it does allow you extra flexibility in managing SimpleScripts on your servers. Resellers also can have the option of using their own SimpleScripts web host account as well. SimpleScripts provides a &#8220;host key&#8221; and a &#8220;host API key&#8221;, both of which can be entered in The SimpleScripts portion of NodeWorx.</p>
<p>Softaculous has an administration interface built in that is accessible via NodeWorx, that allows you to configure various options.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/11/simplescripts-and-softaculous-script-installer-plugins-now-available-in-interworx-4-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InterWorx Hosting Control Panel 4.1.0 Upgrade</title>
		<link>http://www.zendzign.com/2009/11/interworx-hosting-control-panel-4-1-0-upgrade/</link>
		<comments>http://www.zendzign.com/2009/11/interworx-hosting-control-panel-4-1-0-upgrade/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 21:39:00 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[InterWorx]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[hosting control panel]]></category>
		<category><![CDATA[Interworx-CP]]></category>
		<category><![CDATA[lamp]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[shared hosting]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=85</guid>
		<description><![CDATA[The dedicated team at InterWorx has released Hosting Control Panel 4.1.0.
This is the first release of the 4.x series that will be automatically applied to all current InterWorx servers, versions 3 and higher. All InterWorx servers that have auto-updates enabled can and should receive this update.

This will be an incremental release for servers already running [...]]]></description>
			<content:encoded><![CDATA[<p>The dedicated team at InterWorx has released Hosting Control Panel 4.1.0.</p>
<p>This is the first release of the 4.x series that will be automatically applied to all current InterWorx servers, versions 3 and higher. All InterWorx servers that have auto-updates enabled can and should receive this update.<br />
<span id="more-85"></span></p>
<p>This will be an incremental release for servers already running version 4.0.0. For servers running version 3.0, this upgrade will be significant. From version 3 to 4, virtually every aspect of the software has been improved, inside and out.</p>
<p><strong> Special notes for the version 3 to version 4 upgrade </strong></p>
<p>Given the magnitude of this upgrade from version 3 to version 4, there are a few things you should be on the lookout for:</p>
<p>1) Problems accessing InterWorx immediately following the upgrade<br />
IF you or your customers experience any problem logging in or accessing interworx after the upgrade, the first thing to try to fix it is to login as root, and restart interworx with the command</p>
<div style="margin: 5px 20px 20px;">
<div style="margin-bottom: 2px;">Code:</div>
<pre style="border: 1px inset; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 50px; text-align: left;" dir="ltr">service iworx restart
service httpd restart</pre>
</div>
<p>If problems persist after that, please open a support ticket.</p>
<p>2) Problems accessing webmail immediately following the upgrade<br />
IF there are any problems accessing webmail, try the following things first:</p>
<div style="margin: 5px 20px 20px;">
<div style="margin-bottom: 2px;">Code:</div>
<pre style="border: 1px inset; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 66px; text-align: left;" dir="ltr">service iworx restart
service httpd restart
~iworx/cron/iworx.pex --fively</pre>
</div>
<p>If problems persist after that, please open a support ticket.</p>
<p>3) Problems running PHP scripts on client websites<br />
We do not expect there to be significant problems with PHP scripts, but interworx version 4 does provide suphp as an optional server-wide option. In order to provide this feature, the upgrade script will have to make modifications to the clients&#8217; apache virtualhost config files. If these files have been heavily customized, manual intervention may be required.</p>
<p>If needed, backups of the original virtualhost config files will be in /etc/httpd/conf.d/conf_backup/ after the upgrade.</p>
<p>If there are any website problems, first just try restarting the webserver and see if that helps.</p>
<p>As always, any other problems with or questions about this update can be sent via e-mail to <a href="support@zzservers.com">support@zzservers.com</a>, or by opening a support ticket via the web at <a href="https://www.zzservers.com/support" target="_blank">https://www.zzservers.com/support</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/11/interworx-hosting-control-panel-4-1-0-upgrade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kerio MailServer for Windows 7</title>
		<link>http://www.zendzign.com/2009/11/kerio-mailserver-for-windows-7/</link>
		<comments>http://www.zendzign.com/2009/11/kerio-mailserver-for-windows-7/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 23:30:31 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[Kerio Mail Server]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[kerio]]></category>
		<category><![CDATA[mail server]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=82</guid>
		<description><![CDATA[On October 7, ServerWatch covered Kerio MailServer’s certification for Windows 7 and Mac OS X 10.6. “Kerio&#8217;s groupware extension of Microsoft Outlook, Kerio Outlook Connector, is also updated for Windows 7&#8230;In addition to Windows 7 support, Kerio added support for Mac OS X 10.6 Snow Leopard, iPhone 3.1 and iPod Touch 3.1.1 in late September.”
]]></description>
			<content:encoded><![CDATA[<p>On October 7, <em>ServerWatch</em> covered <a href="http://list.kerio.com/lt.php?id=K0oFAQRTBVMBTQcAWAJFVVcFAAtS">Kerio MailServer’s</a> certification for Windows 7 and Mac OS X 10.6. “Kerio&#8217;s groupware extension of Microsoft Outlook, Kerio Outlook Connector, is also updated for Windows 7&#8230;In addition to Windows 7 support, Kerio added support for Mac OS X 10.6 Snow Leopard, iPhone 3.1 and iPod Touch 3.1.1 in late September.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/11/kerio-mailserver-for-windows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Allow Kerio Mail Server Support for Any ActiveSync-Enabled Mobile Device</title>
		<link>http://www.zendzign.com/2009/11/allow-kerio-mail-server-support-for-any-activesync-enabled-mobile-device/</link>
		<comments>http://www.zendzign.com/2009/11/allow-kerio-mail-server-support-for-any-activesync-enabled-mobile-device/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 23:27:59 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[Kerio Mail Server]]></category>
		<category><![CDATA[activesync]]></category>
		<category><![CDATA[cell phone email]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[kerio]]></category>
		<category><![CDATA[mail server]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=79</guid>
		<description><![CDATA[Most modern mobile devices are capable of synchronizing email, contacts, calendars, and tasks &#8220;over-the-air&#8221; via the Microsoft ActiveSync protocol. Since November of 2006, Kerio MailServer has been able to synchronize with most mobile devices which support the ActiveSync protocol. As a measure of quality assurance, any new device which implements the ActiveSync protocol must be [...]]]></description>
			<content:encoded><![CDATA[<p>Most modern mobile devices are capable of synchronizing email, contacts, calendars, and tasks &#8220;over-the-air&#8221; via the Microsoft ActiveSync protocol. Since November of 2006, Kerio MailServer has been able to synchronize with most mobile devices which support the ActiveSync protocol. As a measure of quality assurance, any new device which implements the ActiveSync protocol must be thoroughly tested against Kerio MailServer before it is officially supported. This means that Kerio MailServer maintains an internal list of officially supported devices, and any device not in this list will be denied synchronization.<br />
<span id="more-79"></span></p>
<p>In 2009, there has been a significant number of new phones, such as the Palm Pre, or those based on the Google Android operating system, which either natively implement ActiveSync, or include a number of 3rd party applications to add ActiveSync support to the device. These devices are currently being tested against Kerio MailServer and may be added to the officially supported device list in the near future. However, there is an opportunity to instruct Kerio MailServer to ignore it&#8217;s supported device list and allow synchronization with any ActiveSync based device. For details regarding this configuration you can refer to the <a href="http://list.kerio.com/lt.php?id=K0oFAQRTBVIGTQcAWAJFVVcFAAtS">Knowledge Base article</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/11/allow-kerio-mail-server-support-for-any-activesync-enabled-mobile-device/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliant Hosting &#8211; Are you sure your host knows what PCI is and what they are selling?</title>
		<link>http://www.zendzign.com/2009/10/pci-compliant-hosting-are-you-sure-your-host-knows-what-pci-is-and-what-they-are-selling/</link>
		<comments>http://www.zendzign.com/2009/10/pci-compliant-hosting-are-you-sure-your-host-knows-what-pci-is-and-what-they-are-selling/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 15:01:23 +0000</pubDate>
		<dc:creator>David M. Zendzian</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[shared hosting]]></category>
		<category><![CDATA[Small Business]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=70</guid>
		<description><![CDATA[I recently had a discussion with a potential customer on why they should work with ZZ Servers instead of one of the now hundreds of other hosting providers offering PCI &#8220;compliant&#8221; hosting services. After spending the last 5 years doing PCI Level 1 validations I have run into many areas that hosting providers just do [...]]]></description>
			<content:encoded><![CDATA[<p>I recently had a discussion with a potential customer on why they should work with ZZ Servers instead of one of the now hundreds of other hosting providers offering PCI &#8220;compliant&#8221; hosting services. After spending the last 5 years doing PCI Level 1 validations I have run into many areas that hosting providers just do not get PCI and what hosting providers need to know to provide secure &amp; compliant hosting. I have also been able to compile a list of questions that I can use to determine if they are just trying to sell a service or really provide a PCI solution.</p>
<p><span id="more-70"></span></p>
<p>I was able to spend a good 1/2 an hour with the now new customer and help them understand how our approach meets the intent of PCI and is not focused only on trying to &#8220;make the sale.&#8221;  However, for those that we do not know what questions to ask of a hosting provider I have started a new project where I will be &#8220;shopping&#8221; for a new hosting provider and will post the communications I have with them, along with some additional comments on what their answers would mean to me if I was in my QSA role evaluating their solutions.  I will keep the communications anonymous to prevent any liability issues, but feel free to use any of the questions or comments I have when discussing hosting solutions with any providers you may be examining; and feel free to use my questions against us when you call and ask about PCI or Compliant based hosting with ZZ Servers.</p>
<p>With that in mind, here is the first discussion with a decent data-center with multiple data-centers fully owned and operated by their staff in the northern midwest.  I have highlighted items that caused me to be concerned about their understanding of PCI and what it takes for merchants or service providers to be hosted with managed PCI solutions.  Please note, anyone can take a rack of hardware and managed / deploy it in a compliant manor.  But that is not what these hosting providers are selling.  They are selling compliant solutions, leading customers who do not fully undersand the requirements to think they are meeting all of the requirements.</p>
<p>***Chat Information*You are now chatting with &#8216;Paul&#8217;<br />
*Paul: *Greetings, my name is Paul.  Welcome to &lt;HOSTING PROVIDER&gt; Sales.  With<br />
whom am I speaking?   How may I be of assistance?<br />
*you: *Hello, i saw your VPS servers have a $50/mo PCI certification?<br />
what does that provide? Does that mean i&#8217;ll be compliant? do i need<br />
anything else? does that include my scanning, pen test,<br />
internal/external? log monitoring?<br />
*you: *hello?<br />
*Paul: *Hello, sorry about that<br />
<strong>*Paul: *the PCI certification will include all scans for your server to<br />
be entirely compliant</strong><br />
<em>&#8211; This is common, many people belive that if you get your ASV scanning &amp; answer questionairre you are compliant..if it was only that simple</em><br />
*you: *so it is only the scans?<br />
*you: *not the rest of the compliance needs?<br />
*you: *internal &amp; external scans then?<br />
*Paul: *it covers all services needed<br />
*you: *external logging/monitoring, firewalls, IDS, 2 factor remote<br />
access, pen-testing (internal/eternal), asv scanning &amp; internal scanning<br />
(&amp; other stuff i can&#8217;t remember atm)??<br />
<strong>*Paul: *Yes, it is the complete service</strong><br />
<em>&#8211; how can he say it&#8217;s scanning, then a complete service? At this point I really believe the sales guy does not know what he is selling</em><br />
*you: *applicatoin &amp; network penetration testing? how do you have that<br />
for $50/mo? the best quote I have from a professional pen-testing<br />
company is 5000/year<br />
*Paul: *let me double check<br />
<strong>*Paul: *yes, it does, I have confirmed</strong><em><br />
&#8211; confirmed? if you can&#8217;t tell by now that I am asking questions above his knowledge level; why not conference in someone who knows the answer..<br />
&#8211; Many hosting providers want you to email or fill in a form so they can manage their response, if they can&#8217;t answer your quetions at all hours<br />
&#8211; then are you sure they can manage your compliance needs at any hour??  Get them to bring the expert on the phone while you are asking questions!</em><br />
*you: *interesting, do you have a detailed whitepaper or pdf on the<br />
complete services offereed?<br />
*you: *and i assume i&#8217;ll have to get more than 1 server<br />
<strong>*Paul: *No, you can have PCIC with one server</strong><br />
<em>&#8211; big big red flag!! If you are only using paypal/google for payments then yes this is right but if you are not then the requirement for &#8220;single use&#8221; is pretty important</em><br />
*you: *and that includes firewalls too right? do i have a dedicated<br />
rfc1918 address space?<br />
*you: *you can?<br />
*you: *how do you satisfy the &#8220;single purpose&#8221; requirement?<br />
*you: *where a server can not be a web &amp; database server<br />
<strong>*Paul: *we do not require a cluster for pcic<br />
&#8211; </strong><em>I wasn&#8217;t asking about a cluster. This is a typical issue, the sales team is use to selling hosting of servers but does not understand PCI.  I guess they have not had<br />
&#8211; any PCI training (which you merchants &amp; service providers are required to have annually)<br />
</em>*you: *you do not, but PCI requires that<br />
*you: *pci has something somewhere that requires each server have a<br />
single function<br />
*you: *do you have any documentation? or details about what is included<br />
in your PCI services?<br />
<strong>*Paul: *I do not have a detailed outline, but I know these are the<br />
standards we follow</strong><br />
<em>&#8211; Another warning&#8230;PCI is documentation heavy, if they do not have documentation, have they really done all thats required?</em><br />
*Paul:<br />
*<a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml</a><br />
*you: *yes i am familiar with that<br />
*you: *our QSA has ingrained tht into us<br />
*you: *i was just curious because some of your answers do not jibe with<br />
what the PCI-DSS requires<br />
*you: *ok i think i have enough for now; thank you for your time<br />
*you: *Have a great night..oh one last question; where are your<br />
data-centers located?<br />
*Paul: *My pleasure, they are in &lt;LOCATION&gt;<br />
*you: *any other geographic areas?<br />
*Paul: *they are all located in &lt;ONE LOCATION&gt;<br />
*you: *thank you have a great night<br />
*you: *oh one other questoin<br />
*you: *what technology do you use for your remote 2 factor auth &amp; vpn<br />
technology?<br />
*you: *rsa/certificates/?<br />
*Paul: *The only vendors I have info on at the moment are control scan,<br />
security metrics, trustkeeper, and clone systems<br />
*you: *so it&#8217;s not included w/the pci service?<br />
*you: *it&#8217;s a 3rd party vendor we have to engage?<br />
*Paul: *Send me an email to &lt;SALES-EMAIL&gt; and I will find out for sure<br />
<em>&#8211; Remember earlier they said it included all required services? Again, lack of documentation &amp; training lead me to think they just do not know what the requirements are or what they are selling</em><br />
*you: *ok thank you, have a great night/morning</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/10/pci-compliant-hosting-are-you-sure-your-host-knows-what-pci-is-and-what-they-are-selling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Create an SSL certificate with strong, 2048 bit encryption</title>
		<link>http://www.zendzign.com/2009/10/create-an-ssl-certificate-with-strong-2048-bit-encryption/</link>
		<comments>http://www.zendzign.com/2009/10/create-an-ssl-certificate-with-strong-2048-bit-encryption/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 16:59:45 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[Kerio Mail Server]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=68</guid>
		<description><![CDATA[When creating either a self signed certificate or a certificate request, Kerio MailServer uses 1024 bit encryption. You may however prefer stronger encryption, especially if you are using a signing authority such as GoDaddy, which requires 2048 bit encryption. In this case, you may use the free OpenSSL utility that is available with most Unix [...]]]></description>
			<content:encoded><![CDATA[<p>When creating either a self signed certificate or a certificate request, Kerio MailServer uses 1024 bit encryption. You may however prefer stronger encryption, especially if you are using a signing authority such as GoDaddy, which requires 2048 bit encryption. In this case, you may use the free OpenSSL utility that is available with most Unix or Linux based systems. There is also a version of the tool available for the Windows Operating system.<br />
<span id="more-68"></span> Self signed certificates generated by Kerio MailServer carry a default expiration of 1 year. The OpenSSL utility will also allow you to define your own expiration, for example 3 years. For specific instructions and usage of the OpenSSL utility, read the <a href="http://list.kerio.com/lt.php?id=K0oEAQhRAF4GTQcAVAJFVVcFAAtS">Knowledgebase article</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/10/create-an-ssl-certificate-with-strong-2048-bit-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kerio MailServer and Mac OS X Snow Leopard</title>
		<link>http://www.zendzign.com/2009/08/kerio-mailserver-and-mac-os-x-snow-leopard/</link>
		<comments>http://www.zendzign.com/2009/08/kerio-mailserver-and-mac-os-x-snow-leopard/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 15:41:32 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[Kerio Mail Server]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=64</guid>
		<description><![CDATA[Apple has announced that Mac OS X Snow Leopard will be available on Friday, August 28, 2009. Kerio MailServer versions 6.7.1 and older do not fully support the desktop clients in Mac OS X Snow Leopard. Therefore, Kerio advises that all Kerio MailServer customers do not upgrade to Mac OS X Snow Leopard at this [...]]]></description>
			<content:encoded><![CDATA[<p>Apple has announced that Mac OS X Snow Leopard will be available on Friday, August 28, 2009. Kerio MailServer versions 6.7.1 and older do not fully support the desktop clients in Mac OS X Snow Leopard. Therefore, Kerio advises that all Kerio MailServer customers do not upgrade to Mac OS X Snow Leopard at this time. While Kerio does not disclose information about unreleased products, Kerio remains committed to the Mac platform and Kerio MailServer will support Mac OS X Snow Leopard in the next service release.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/08/kerio-mailserver-and-mac-os-x-snow-leopard/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Amazon confirms EC2/S3 does not meet PCI guidelines</title>
		<link>http://www.zendzign.com/2009/08/amazon-confirms-ec2s3-does-not-meet-pci-guidelines/</link>
		<comments>http://www.zendzign.com/2009/08/amazon-confirms-ec2s3-does-not-meet-pci-guidelines/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 14:35:38 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[compliant hosting]]></category>
		<category><![CDATA[pci compliance]]></category>
		<category><![CDATA[pci complliant hosting]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=58</guid>
		<description><![CDATA[If your business requires PCI compliant hosting services because you store, transmit or process cardholder data, hosting in the cloud may not be for you.  Most cloud providers do not have the controls or processes in place to protect sensitive cardholder data or the willingness to enter into required business arrangements with merchants.  Because of [...]]]></description>
			<content:encoded><![CDATA[<p>If your business requires PCI compliant hosting services because you store, transmit or process cardholder data, hosting in the cloud may not be for you.  Most cloud providers do not have the controls or processes in place to protect sensitive cardholder data or the willingness to enter into required business arrangements with merchants.  Because of this, it is impossible to meet several requirements found in current PCI standards, leaving your business at risk for heavy fines by not being compliant.</p>
<p><span id="more-58"></span></p>
<p>One such example would be Amazon EC2.  In a recent discussion at <a href="http://developer.amazonwebservices.com/connect/message.jspa?messageID=139547" target="_blank">amazonwebservices.com</a> forum and <a href="http://it.slashdot.org/story/09/08/17/0438207/Amazon-Confirms-EC2S3-Not-PCI-Level-1-Compliant">slashdot.org</a> users were discussing a desire to move to Amazon EC2 and maintain PCI compliance.  While not surprising, at least there was a concrete answer to were Amazon stands with regards to its role in its customer’s compliance.  In an email from Taimur Rashid, an account manager at Amazon Web Services, he states <em>“We do not and will not provide a written agreement attesting compliance and assuming responsibility for cardholder data.”</em><em> </em></p>
<p>PCI requires all merchants maintain a written agreement between the merchant and service provider that outlines responsibility for cardholder data.  “<em>Requirement 12.8.2 Maintain a written agreement that includes an acknowledgement that the service providers are responsible for the security of cardholder data the service providers possess.”</em><em> Without this simple agreement, you cannot be compliant.</em></p>
<p>In addition to not allowing a written agreement, Amazon also will not allow on site audits required for Level 1 and <a href="http://www.zendzign.com/2009/06/level-2-merchants-required-to-have-on-site-assessment-by-qsa/">now Level 2 merchants</a>.  Cindy S from Amazon Web Services states “<em>If you have a data breach, you automatically need to become level 1 compliant which requires on-site auditing; that is something we cannot extend to our customers.”</em></p>
<p>Based on the 2 statements above, Amazon EC2/S3 is currently not capable of providing the level of service required for PCI compliance on any level.  If you are a merchant and require PCI compliance, avoid the cloud and find a reputable service provider which specializes in PCI compliance such as <a href="http://www.gsihosting.com/">GSI</a>, <a href="http://www.rackspace.com">Rackspace</a> or <a href="http://www.zzservers.com/">ZZ Servers</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/08/amazon-confirms-ec2s3-does-not-meet-pci-guidelines/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>InterWorx Hosting Control Panel Version 4.0 Available Now For All New Installs!</title>
		<link>http://www.zendzign.com/2009/08/interworx-version-4-0-available/</link>
		<comments>http://www.zendzign.com/2009/08/interworx-version-4-0-available/#comments</comments>
		<pubDate>Sun, 16 Aug 2009 20:21:08 +0000</pubDate>
		<dc:creator>Peter Zendzian</dc:creator>
				<category><![CDATA[InterWorx]]></category>
		<category><![CDATA[Control Panel]]></category>
		<category><![CDATA[hosting control panel]]></category>
		<category><![CDATA[shared hosting]]></category>

		<guid isPermaLink="false">http://www.zendzign.com/?p=54</guid>
		<description><![CDATA[ZZ Servers is pleased to announce the InterWorx development team has released   InterWorx version 4.0.  InterWorx 4.0  contains many new features and enhancements. We believe that you will be very pleased with the final product and that this release will maintain the same high standards of quality which you have become accustomed to [...]]]></description>
			<content:encoded><![CDATA[<p>ZZ Servers is pleased to announce the InterWorx development team has released   InterWorx version 4.0.  InterWorx 4.0  contains many new features and enhancements. We believe that you will be very pleased with the final product and that this release will maintain the same high standards of quality which you have become accustomed to from InterWorx.</p>
<p><span id="more-54"></span></p>
<p>InterWorx 4.0 is available now for all new installations. Existing InterWorx 3.0 installations should begin to be automatically updated within the next few weeks. It is recommended that ALL users upgrade their existing InterWorx installations when the update becomes available.</p>
<h3>New Features &amp; Improvements</h3>
<div>
<ul>
<li>
<div>New Features</div>
<ul>
<li>
<div><acronym title="Application Programming Interface">API</acronym>:</div>
<ul>
<li>
<div>Hugely expanded capabilities of XMLRPC</div>
</li>
<li>
<div><acronym title="Simple Object Access Protocol">SOAP</acronym> support</div>
</li>
<li>
<div>Command Line Interface &#8211; interactive and programmatic</div>
</li>
</ul>
</li>
<li>
<div>Email:</div>
<ul>
<li>
<div>Domainkeys, SPF, and Remote <acronym title="Mail Exchange Record">MX</acronym> support</div>
</li>
<li>
<div>Roundcube support added</div>
</li>
</ul>
</li>
<li>
<div>Line by line validation of user input</div>
</li>
<li>
<div>New <acronym title="Asynchronous JavaScript and XML">AJAX</acronym> controls for all services in NodeWorx</div>
</li>
<li>
<div>SPEED! We’ve made huge steps forward in speeding things up across the board</div>
</li>
<li>
<div>Improved memory footprint</div>
</li>
<li>
<div>SiteWorx users can reset their own password if they forget</div>
</li>
<li>
<div>Multiple external MySQL servers can be maintained by NodeWorx, and assigned to SiteWorx users when the account is created (one per SiteWorx account)</div>
</li>
<li>
<div>Dedicated <acronym title="IP Addresses">IPs</acronym> are now dedicated to a SiteWorx account, not just a single domain, so accounts with <acronym title="Secure Sockets Layer">SSL</acronym> can have secondary domains.</div>
</li>
<li>
<div>Mass Transfer Importer now runs in the background, so if you leave, you can come back and it will still be running. Also runs several imports in parallel for faster importing.</div>
</li>
<li>
<div>Updated importers for migration from cPanel and Plesk</div>
</li>
<li>
<div>Integrated suPHP support</div>
</li>
<li>
<div>Ruby on Rails support via Passenger</div>
</li>
<li>
<div>New Settings page to control commonly accessed parts of the InterWorx configuration</div>
</li>
<li>
<div>View server logs in real time without the need for shell access</div>
</li>
</ul>
</li>
<li>
<div>Security Improvements</div>
<ul>
<li>
<div>Upgraded the internal version of <acronym title="Hypertext Preprocessor">PHP</acronym> to 5.2.x</div>
</li>
<li>
<div>All input to the system is now handled through a single point, which allows us to validate input much more thoroughly</div>
</li>
<li>
<div>Implemented suPHP internally for improved security through privilege separation</div>
</li>
</ul>
</li>
<li>
<div>Visual Enhancements</div>
<ul>
<li>
<div>New theme system is much simpler to create your own theme</div>
<ul>
<li>
<div>Custom branding fully supported</div>
</li>
</ul>
</li>
<li>
<div>Built-in themes are now <acronym title="Cascading Style Sheets">CSS</acronym> only &#8211; no more tables</div>
</li>
<li>
<div>Memory graph is much clearer</div>
</li>
</ul>
</li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.zendzign.com/2009/08/interworx-version-4-0-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
