Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Sunday, 22 June 2014

Plus ca change

I’ve worked with mainframes for over 30 years and I’m used to seeing trends moving in one direction and then, a few years later, going in the opposite direction. Each initiative gets sold to us as something completely new and the solution that we’ve been waiting. I imagine you share my experience. I originally worked on green screens with all the processing taking place on the mainframe. In fact, I can remember decks of cards being punched and fed into the mainframe. I can remember the excitement of everyone having their own little computer when PCs first came out. I can remember client/server being the ultimate answer to all our computing issues. Outsourcing, not outsourcing – we could wander down Memory Lane like this for a long time.

What always amazes me is when I’m working with sites that are predominantly Windows-based, and they still get that frisson of excitement over an idea that I think is pretty commonplace. It was only a few years ago (well maybe about five) that the Windows IT teams were all excited about VMware and the ability to virtualize hardware. They couldn’t believe mainframes had been doing that since the 1960s.

Then there was the excitement about using Citrix and giving users simple Linux terminals rather than more expensive PCs. Citrix have a host of products, including GoToMeeting – their conferencing software. With Citrix desktop solutions, all the applications live on the server rather than on each individual computer. It means you can launch a browser on your laptop, smartphone, tablet, or whatever device you like that has a browser, and see a Windows-looking desktop and all the usual applications. So, it’s just like a dumb terminal connecting to a mainframe, which does all the work and looks after all the data storage. Nothing new there!

And now Microsoft are selling Office 365, which, once you’ve paid your money, means that all the applications live in the cloud somewhere, and so does the data. It seems that all subscribers are like remote users, dialling into an organization’s mainframe that could be located in a different country or on a different continent. Looked at another way, IT departments are in many ways outsourcing their responsibilities – and we all remember when outsourcing was on everyone’s mind.

Office 365 seems like a very mature product and one whose time is about to come. You get more than just the familiar Office products like Word and Excel. You get SharePoint, Lync, and Exchange (and I’m talking about the Enterprise version of Office 365). Lync lets users chat to each other – a bit like using MSN used to. And SharePoint provides you with an intranet as well file and document management capabilities. You get Outlook, Publisher (my least-favourite piece of software), Access (the database), and InfoPath (used for electronic forms). You also get a nicely integrated Yammer – Microsoft’s Enterprise Social Networking (ESN) tool. There’s also PowerBI, a suite of business intelligence and self-serve data mining tools coming soon. This will integrate with Excel, so users can use the Power Query tool to create spreadsheets and graphs using public and private data, and also perform geovisualization with Bing Maps data using the Power Map tool.

And while the actual tools that are available on these different platforms and computing models, over time, are different, it’s the computing concepts that I’m suggesting come and go and come again, and go again! It’s like a battle between centralization and decentralization. Everyone likes to have that computing power on their phone or tablet, but whenever you need to do some real work, you connect (usually using a browser) to a distant computing monolith. So, plus ça change, plus c’est la même chose.

Sunday, 15 June 2014

Having your cake and eating it

Everyone knows that mainframes are the best computers you can have. You can run them locally, you can hide them in the cloud, and you can link them together into a massive processing network. But we also know that there are smaller platforms out there that work differently. Wouldn’t it be brilliant if you could run them all from one place?

Last summer we were excited by the announcement from IBM of its new zBC12 mainframe computer. The zBC12 followed the previous year’s announcement of the zEC12 (Enterprise Class), and 2011 saw the z114, with 2010 giving us the z196. So what’s special about those mainframes?

Well, in addition to IFL, zIIP, and zAAP specialty processors, and massive amounts of processing power, they came with the IBM zEnterprise BladeCenter Extension (zBX), which lets users combine workloads designed for mainframes with those for POWER7 and x86 chips, like Microsoft Windows Server. So let’s unpick this a little.

One issue many companies have after years of mergers and acquisitions is a mixed bag of operating systems and platforms. They could well have server rooms across the world and not really know what was running on those servers.

IBM’s first solution to this problem was Linux on System z. Basically, a company could take hundreds of Linux servers and consolidate them onto a single mainframe. They would save on energy to drive the servers and cool them, and they would get control of their IT back.

IBM’s second solution, as we’ve just described, was to incorporate the hardware for Linux and Windows servers in its mainframe boxes. You’d just plug in the blades that you needed and you had full control over your Windows servers again (plus all the benefits of having a mainframe).

But what about if you could actually run Windows on your mainframe? That was the dream of some of the people at Mantissa Corporation. They did a technology demo at SHARE in August 2009. According to Mantissa’s Jim Porell, Network World read their abstract and incorrectly assumed that they were announcing a product – which they weren’t. The code is still in beta. But think about what it could mean: running all your Windows servers on a mainframe. That is quite a concept.

Again, according to Jim, they can now have real operating systems running under their z86VM, although, so far, they are the free versions of Linux. Their next step will be to test it with industrial strength Linux distros such as Red Hat and Suse. And then, they will need to get Windows running. And then they’ll have a product.

Speaking frankly, Jim said that currently they have a bug in their Windows ‘BIOS’ processing in the area of plug-and-play hardware support. Their thinking is that it’s a mistake in their interpretation of the hardware commands and, naturally, they’re working to resolve it.

The truth is that it’s still early days for the project, and while running Linux is pretty good, we can already do that on a mainframe (although you might quibble at the price tag for doing so). But once the Mantissa technical people have cracked the problems with Windows, it will be a product well worth taking a look at, I’m sure. But they’re not there yet, and they’re keen to manage expectations appropriately.

Jim goes on to say that once the problems are solved it’s going to be about performance. Performance is measured in a couple of ways: benchmarks of primitives, benchmarks of large-scale for capacity planning, end user experiences, and what they are willing to tolerate. So it seems that they have business objectives around performance where they could be successful if they supported only 10 PCs, then more successful with a 100 PCs, and even have even greater success if they can support a 1000 PCs.

Jim Porell describes z86VM as really just an enabler to solving a wide range of ‘customer problems’ by enabling direct access between the traditional mainframe and the PC operating systems that are co-located with it.

I think that anything that gets more operating systems running on mainframe hardware has got to be good. And I’m prepared to wait for however long it takes Mantissa to get Windows supported on a mainframe. I’ll definitely feel then that I’m having my cake and eating it!



Sunday, 11 March 2012

Operating systems on a stick

You’re probably familiar with IBM’s z Personal Development Tool Adapter, which allows users to develop mainframe software without a mainframe. In effect, users plug a very expensive memory stick into their PC and it acts like a mainframe.

But now, IBM has extended the idea by allowing users with the appropriate memory stick to load a cloud-hosted Windows or Linux operating system onto their PC – although they will need a Windows or Linux computer with a 64-bit processor. It’s called the Secure Enterprise Desktop (SED) and comes packaged as an extension to IBM’s Smart Business Desktop Cloud service.

The memory stick plugs into a USB port (as you’d expect) and comes with its own HTTPS stack, bootloader, and the necessary proprietary code to create a secure VPN channel connection between a partitioned drive on the user’s PC and a remotely-located server.

That’s nice, you say, but what’s the point? Well, it’s another way of allowing BYOD (Bring Your Own Device). This is an issue that I blogged about a little while ago, and one that is beginning to raise its head at many sites. Users like the devices they’ve bought themselves and are familiar with, rather than the products IT allocates them. And they want to use those devices to access their work-based data and applications.

Running the bootloader from the memory stick protects the business from the problem of home machines being riddled with viruses and trojans. The PC establishes a connection to the server, then there’s two-way authentication to ensure you’re who you say you are and the server is really the right one for your company (and not anyone else’s). Once this connection is established, the user downloads a small (kernel-based virtual machine) hypervisor, which allows the user to choose a Linux or Windows operating system. Any changes the user makes to data is written in an AES-256 encrypted format to a portion of the local hard drive with the key retained on the stick, and these changes are replicated back to the cloud-hosted operating system.

The device offers a range of authentication options, including a built-in card reader as well as PIN.

If the memory stick gets removed, the operating system instantly stops because the connection to the remote server has been severed. Re-inserting the stick allows re-authentication to occur and the user can carry on as before.

Users have the option to download the host operating system from the cloud, so they can continue to work without an Internet connection – if that’s what they require.

At the server end, a Linux server with Apache and OpenLDAP (open Lightweight Directory Access Protocol) are required.

It seems like a very useful innovation. What do you think?

Sunday, 13 November 2011

Guest blog – Mainframe security: who needs it?

This week, for a change, I’m publishing a blog entry from Peter Goldberg, a senior solution architect at Liaison Technologies, a global provider of cloud-based integration and data management services and solutions based in Atlanta. He works directly with customers to identify their unique data security and integration challenges and helps to design solutions to suit their organizations’ requirements. A frequent speaker at industry conferences on eBusiness security issues and solutions, he can be reached at pgoldberg@liaison.com.

I’ve been helping companies on both sides of the pond solve their data security problems for many years now. If I’ve learned one thing, it’s this: when I go into an organization that runs Windows, there’s little question of the need for data security. The organization knows it and so do I. When I visit a company whose IT infrastructure revolves around a mainframe, however, the mindset is often quite the opposite. In fact, the biggest data security misconception I encounter is the belief that the mainframe environment is inherently secure. Most IT staff view the mainframe as just another network node. Why? Because it’s universally perceived as a closed environment and, therefore, invulnerable to hackers.

In some cases, it’s the mainframe IT pros who hold this conviction. In other instances, it’s the executive management team. Lack of management attention allows “bad practices” to continue. I can tell you this without reserve: data stored in mainframes needs protection just as much as sensitive information stored on a Windows server or anywhere else. And, as systems continue to support more data, users, applications, and services, effective security management in the mainframe environment becomes significantly more difficult.

News flash: mainframes can be hacked!

For that simple reason, mainframe security should not be taken for granted.

Even though the mainframe is a mature platform, there is a real shortage of mainframe-specific security skills in the market. And, the few mainframe security practitioners who are out there spend a lot of time implementing configuration and controls within their environments as well as putting into place security systems like RACF, which provide access control and auditing functionality. As for other security measures, in my experience, the mainframe people know about encryption, but they’re not terribly aware of newer data security techniques like tokenization as it relates to protecting data within the mainframe environment and beyond.

Tokenization is a data security model that substitutes surrogate values for sensitive information in business systems. A rapidly rising method for reducing corporate risk and supporting compliance with data security standards and data privacy laws, it can be used to protect cardholder information as well as Personally Identifiable Information (PII) and Protected Health Information (PHI).

In fact, for companies that need to comply with the Payment Card Industry’s Data Security Standard (PCI DSS), tokenization has been lauded for its ability to reduce the cost of compliance by taking entire systems out of scope for PCI assessments. And, even in companies that do not deal with PCI DSS or other mandates, tokenization has proven effective for managing the duplication of data across LPARs and for facilitating the usage of potentially sensitive data for development purposes.

Too often, compliance audits skim over mainframe control weaknesses and there are also fewer mainframe-specific security guidelines. But this does not mean that significant risk is not there. You can apply a risk-based, defence-in-depth approach within the mainframe environment by using stronger mainframe host security controls and by using tokenization to protect the data itself.

To beef up data security on a mainframe, here’s my advice:
  1. Bring in mainframe security experts to identify and remediate risks, and to develop and enforce security policies and procedures.
  2. Develop in-house capabilities and skilled professionals across the mainframe platform to support security initiatives.
  3. Evaluate available security configuration and administration tools – there are some really good ones out there.
  4. Apply an in-depth security strategy that includes secure access and authentication controls, and use them appropriately.
  5. Adopt encryption and tokenization to protect sensitive information. Through their proper implementation, it’s really not that hard to achieve a true high level of protection within the mainframe environment.

Protecting sensitive and/or business-critical data is essential to a company’s reputation, profitability, and business objectives. In today’s global market, where business and personal information know no boundaries, traditional point solutions that protect certain devices or applications against specific risks are insufficient to provide cross-enterprise data security. Combining encryption and tokenization, along with centralized key management, as part of a corporate data protection programme works well – including in mainframe-centric environments – for protecting information while reducing corporate risk and the cost of compliance with data security mandates and data privacy laws.

Don’t be fooled: your mainframe isn’t inherently secure. Doing nothing is no longer an option!

Thanks Peter for your guest blog.
And remember, there's still time to complete the mainframe user survey or place a vendor entry in the Arcati Mainframe Yearbook 2012.

Sunday, 30 October 2011

Two things you thought would never happen at IBM

I guess any two pundits sitting in a room together 10 years ago and talking about IBM’s future would have been more likely to predict Star Trek-like beaming technology and computers you could talk to than a mainframe that integrated Windows servers and woman landing the top job at IBM.

And here we are. It’s almost November 2011, and both are about to come to pass.

The zEnterprise 196 and the Business Class version, the zEnterprise 114, mainframes come with the zEnterprise BladeCenter Extension. Initially this supported AIX on Power blades and Linux on x86 blades. This fit nicely with IBM’s model of the universe because it owns AIX and Linux is, of course, open source – ie it doesn’t belong to anybody. The Unified Resource Manager (URM) controls the operating systems and hypervisors on the mainframe and the blades. But now – the previously unthinkable – IBM promises that it will have Windows running on its HX5 Xeon-based blade servers for the zBX chassis before the end of this year.

Microsoft Windows Server 2008 R2 Datacenter Edition will run on the PS701 blade servers in the zBX enclosures. The zBX extension can have 112 PS701 blades or 28 HX5 blades.

This is clearly important for those sites that use mainframes or are ready to upgrade to mainframes and still have a big Windows-using population. It’s interesting that so many people consider Windows to be the de facto computing platform. I recently had a conversation where Windows laptops were given the metaphor of rats or beetles – they just turn up everywhere – and Linux was given the metaphor of a stealth operating system or a hidden shadow – it was everywhere, but you didn’t see it. Why stealth, well because Linux turns up behind the scenes on routers, on TiVO boxes, on supercomputers, as the precursor to Android on smartphones, making movies at Pixar and Dreamworks, in the military, governments, everywhere!

After Windows on IBM hardware, the next thing we hear is that Virginia M Rometty, a senior vice president at IBM, is going to be the company’s next CEO – starting in January. “Ginni”, aged 54 (as all the releases inform us), succeeds Samuel J Palmisano, who is 60, and will remain as chairman.

Ms Rometty graduated from Northwestern University with a degree in computer science, joined IBM in 1981 as a systems engineer. She moved through different management jobs, working with clients in a variety of industries. Her big coup was in 2002, when she played a major part in the  purchase of the very big consulting firm, PricewaterhouseCoopers Consulting. PwC staff were used to working in a different way from IBM’s and managing that culture shift was down to Ms Rometty.

In 2009, Ginni became senior vice president and group executive for sales, marketing, and strategy.

You’ll recall that Sam Palmisano took over in 2003 from Louis V Gerstner Jr, who’d joined IBM from RJR Nabisco in 1993 and helped turn round an ailing IBM. The previous incumbent had been the lacklustre John Akers.

I suppose with Siri on iPhones and the much less serious about itself Iris on Android, we’ve moved some way towards being able to talk to a computer – even if it is a smartphone. Still no sign of Scotty being beamed up, though!

Sunday, 18 September 2011

Mainframe maintenance – a new paradigm with new challenges

For many organizations, we’re beginning to see a new model of how IT customer support can be organized – and the model is coming from management who are completely platform-agnostic. To them, IT is IT – it doesn’t matter whether something runs on a mainframe or a distributed platform. And this new way of working brings with it new challenges.

This whole change in staff structure is also being encouraged by the advent of the zEnterprise hybrid machines with their zBX blades running everything from AIX to, potentially, Windows. A consequence is that a mainframe specialist could be dealing with a Linux error message, or a Windows SharePoint guru might be trying to understand what’s going on inside CICS. What can you do to help them?

Or let’s suppose in a more traditional mainframe environment, for whatever reason, you lost some of your top technical people. Perhaps they got jobs elsewhere or perhaps they retired early, but suddenly you find yourself with a huge knowledge gap. Maybe you can transfer someone across from the distributed team. Or maybe you can recruit one of the new generation of youngsters who are learning the benefits of mainframe computing. But whatever you do, there will be a fairly long period of time during which anything out of the ordinary occurring is going to leave everyone scratching their heads and searching Google – whereas, previously, your in-house expert knew exactly what to do. So, in this situation, what are you going to do?

Let’s not worry too much at this stage about Service Level Agreements (SLAs) and performance targets. Let’s simply focus on the problem. How can any organization, irrespective of how its IT team is constructed, ensure that appropriate expertise is available at all times to whichever staff members are available?

Obviously you can have the manuals, and some could be on the IBM mainframe portal, but that doesn’t give you speedy access to the necessary information. A Google search will reveal hundredsof pages of results, but it takes a degree of expertise to sift through those and find the correct one quickly. And someone without any expertise could spend a very long time reading solutions to completely different problems before ever finding the right one. Not a satisfactory way to provide IT services to customers – whether internal or external to the organization.

So what would be a good solution? How can these issues of staff working outside their comfort zone be dealt with in a way that is good for the business? And what kind of a solution will still be able to ensure those business-critical mainframes are being supported in a year’s time, in five year’s, or even further into the future?

This is where a new breed of solutions that can address this coming challenge are positioning themselves. One of these, Softlib with its iSolve product (www.softlibsw.com/mvs.aspx), allows an organization to combine all its IT-related information into a single virtual library. That means users – your harassed staff – have to search in only one place, not as previously in many places, to find a solution to any problem. And once you have a single location for information available, you can allow product champions and other IT-literate staff access to it – which should result in more empowered and satisfied users and fewer calls to the Help Desk.

It makes sense to organize the information in this single virtual library using themes, so CICS information might be one theme, IMS another, Linux a third, etc. The information in the library starts from IBM and third-party software vendors’ manuals, and can be supplemented with information from newsgroups and other online resources. Plus, you can add your own technical expertise.

Access to the information can be from a Web browser or a terminal server. It can be hosted locally, or as a cloud-based resource. The advantage of the cloud route is that the information is looked after by Softlib and they already have access to a huge number of the resources you’ll need. So you can start using the facility almost immediately. Plus the online documentation is automatically updated when new information becomes available. Other benefits include knowledge usage analytics that can help address missing or outdated knowledge, and seamless integration with CRM, bug-tracking, Service Desk, content-management applications, etc.

All in all, Softlib’s iSolve product has a lot to offer most mainframe sites, and certainly provides an answer to the question of what to do if you restructure your IT customer support and need to extend the working expertise of your staff onto other platforms such as AIX and Windows. It also offers a solution to the problem of losing key mainframe experts in a mainframe-only environment.


Saturday, 2 July 2011

Where do the tablets go?

So, your organization has a mainframe – had one for years – and everything is nicely locked down. You can recover almost up to the minute the system or subsystem crashed (which it hardly ever does), and you’ve got people who seem to know, almost by instinct these days, when something isn’t performing quite right.

On top of that, you’ve got another layer of IT. People who use laptops with Windows and/or people who use Linux, and possibly bits or Solaris dotted around. These people have more interesting lives. They have to fight to get the best performance. Their back-up strategy is good if they can recover to last night! They probably still insist on people using XP as their Windows operating system because Vista was no good and it’s a bit of a jump to Windows 7. Plus they’re probably coming to the end of a virtualization project to reduce the number of server boxes they’ve got lying around. Parhaps they’re installing Citrix to virtualize desktops, or SharePoint to produce an intranet and join up all the separate islands of computing.

Plus you’ve got remote users, who are logging in over somebody else’s wifi. Or they might be using the 3G network on their smartphone. It’s your fault, of course, because you spent so long changing your CICS and IMS applications so they could be used in a Service-Oriented Architecture (SOA) environment. But, I guess you have strategies in place to secure the connection, and secure what applications they can run, and what data they can see.
In fact, you’re probably convincing senior managers in your organization that it really was their idea all along to combine the strengths of mainframe computing with the flexibility of distributed systems. What your organization needs is a nice z196 mainframe – perhaps one of the planned-but-not-quite-announced Business Class (BC) machines.

For those of you who’ve spent the past year on Mars, the z196 brings together the latest mainframe technology with POWER7 and x86 IBM blade systems, giving potential users z/OS, AIX, Linux, and (coming soon) Windows, all on the one box. At this stage, I should point out that there are very strong arguments for going to zLinux. It’s been around for 10 years now, and is just becoming an overnight success – as they say.

So, there you are thinking that you can use your mainframe experience and expertise to tidy up all the other computing areas in your organization and get them under your control when HR tells you they have supplied everyone on the board of directors with an iPad. Now, you might think this is a good opportunity to bring some of the board into the 21st century, but it creates yet another rip in the secure blanket you've been throwing over the company’s computing infrastructure. Can you set up a security policy for iPads? Well, yes, if they come into a Microsoft server – in the same way you would for Mac users. Can you allow board members to download apps? Or can they have only pre-approved ones? Where do you start building proper security? It’s back to herding cats!

And don’t think I’ve singled out iPads, Androids have similar issues. You can download firewalls and anti-virus software for them, but it’s not the same as RACF!

And it might not just be board members – you may still have road warriors that want the small form factor of a tablet. The issues of theft or forgetfulness compound your security problems.

My suggestion at this stage is to wait for Windows 8 tablets, and hope that the policies laid down by the non-mainframe ITers will apply to them. And by then, Windows will be running on our z196 box. So everyone’s a winner!

Saturday, 25 June 2011

What’s a mainframe, Daddy?

After years of sliding my security card in the lock and entering the machine room/data centre and seeing the mainframes in there change from Sci-Fi-style boxes with flashing lights to more mundane-looking boxes. From seeing simple DASD with less capacity than the memory stick in this laptop be replaced with cache controllers and more sophisticated data storage devices. It always seemed that there were plenty of mainframes around and any normal person (me) was constantly being offered tours round installations. So it comes as a bit of a shock when a youngster clearly has no idea what a mainframe looks like or what it does!

OK, no-one may have actually said those words as such, but that was the message. Plus, I was with some friends on Saturday when the conversation turned to discussing what use a mainframe was in this day and age! As Arcati Director, Mark Lillycrop, so eloquently put it recently, mainframes are thought of as ‘your dad’s technology’. Most of the people I was chatting to felt that mainframes were relics of the past and anything they can do, a few servers could do just as well!

So for many of us mainframe verterans, our job is to get out there and spread the word. We need to tell people exactly what a mainframe is, what it can do, and how people are interacting with them all the time, but don’t realise it. That way, the new generation of youngsters that are beginning to get access to mainframe technology at universities and elsewhere will arrive with a knowledge of what mainframes can do, and why working with them can be so enjoyable.

So let’s just start with the absolute beginner’s guide to mainframes. They are computers – just like your laptop – except that over the years they faced and solved all the problems about back-ups and restores, security, and high-speed data access. They have been around for a long time – which is a good thing because lots of people have moved the technology forward. They allow millions of users controlled access to information – allowing them to create, modify, and save data from almost any data entry device you can think of, including browsers.

Mainframes have been virtualized since the 1980s, and some of the software first saw the light of day in the 1960s. Most Windows data centres have only been virtualizing for the past five years! It’s true that laptops etc are everywhere – in your home, at work, etc – but mainframes are working away in the background. Everytime you take money from an ATM (cash machine) your bank is running a transaction on a mainframe. And it is banks and large financial institutions that use mainframes. And they do it because of the reliability. They do it because, should there be an outage, they can recover back to almost the last second before they went down. Almost no transactions are lost. And as a bank customer, I like that. Lots of non-mainframe-using sites think they are doing quite well if they can recover data back to last night! You see the difference in scale here.

Mainframes run an operating system (z/OS, but could be z/VM or z/VSE) and on top of that are a number of subsystems – you might think of them as apps (but big ones!). These subsystems include CICS and IMS. Now, both of these have been being developed since the 1960s and provide ways of accessing data very quickly and securely. They allow users to fill in virtual forms. And they store data in a way that means it can be accessed very quickly.

Another ‘app’ you may have heard of is DB2. DB2 is a comparative youngster, having arrived in the 1980s. It stores data in a ‘relational’ way rather than the more traditional ‘hierarchical’ way. DB2 is a database that can exist on Windows machines as well as mainframes (and many devices in between).

Mainframes can also run Linux (z/Linux) and all the Linux applications. That makes them very cost-effective replacements for sites with numerous ageing Linux servers. Linux has been available on mainframes for just over 10 years.

And there’s plenty of software available to control all aspects of this mainframe behemoth. And you can link them together at different sites in different countries round the globe.

So if anyone asks you what’s a mainframe, you can tell them that it’s the most successful server architecture ever devised and it’s all around them doing important work.