News: 1614693606

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft previews Windows Server 2022: Someone took a spanner to core plumbing features

(2021/03/02)


Ignite Microsoft has released a preview of Windows Server 2022, with "secured core", improved Windows Containers, and MsQuic protocol support in the kernel.

Windows Server can also be deployed using an "as a service" model in the style of Windows 10, though there are important differences. The regularly updated version is simply called Windows Server (plus a release number such as 2004), is in the semi-annual release channel, and requires a subscription licence called Software Assurance, so is not a cheap way to get the latest Windows Server forever.

[1]

Each semi-annual channel release is supported for only 18 months. Also, there is no desktop GUI for the semi-annual channel, only the stripped-down Server Core option, or Nano Server for containers. Given the above limitations, it is the traditional long-term support versions of Windows Server, like Server 2022, that are likely to be used for non-ephemeral installations.

[2]

Windows Server 2022 looks much like Windows 10; all the interesting changes are in core plumbing features

[3]

Windows Server 2022 will be generally available later this year. It features what Microsoft has called "secured core," a term it has [4]already used for Windows 10 PCs . Secured core uses Trusted Platform Module (TPM) 2.0 for a hardware root of trust; Credential Guard, which stores secrets using virtualization for an isolated process; and Hypervisor-Protected Code Integrity (HVCI), which verifies kernel code before execution (again using virtualisation) to isolate the verification code.

SMB over QUIC, AES-256 encryption

Microsoft's [5]MsQuic protocol is in the kernel, an implementation of the QUIC transport protocol used both for HTTP/3 internet calls and file transfer over SMB (Server Message Block, used for Windows networking).

SMB also now supports AES-256 encryption. Microsoft claims to have improved network performance in Server 2022. UDP (User Datagram Protocol) performance is improved by offloading more work to the network card hardware and by using UDP Receive Side Coalescing (RSC), which combines multiple packets into one. RSC was previously only used for TCP packets.

[6]According to Microsoft's Principal Program Manager Ned Pyle, SMB over QUIC will allow "mobile users, hybrid users, travelling internet users, instead of using a VPN, [to] tunnel SMB traffic over the QUIC protocol which is a UDP, TLS, highly secure, easily firewall-traversing protocol… but still get the SMB goodness of mapping drives, it won’t change a bit."

[7]

The latest Windows Admin Center: note all the options for Azure integration in the left-hand column

Microsoft has improved hybrid on-premises/Azure cloud capabilities in this release, including upgraded storage migration services, for moving data between servers, that support target servers using Azure File Sync. Azure File Sync lets admins over-provision local storage, moving seldom used files to Azure Files storage automatically.

There are also upgrades to Windows Containers, including up to 20 per cent smaller image service and the ability to use Group Managed Services Accounts (gMSA) with Azure Active Directory, without domain joining the container host to Azure AD. The idea is to allow Windows containers to run on Kubernetes with better performance and fewer limitations.

The preferred administration tool for Windows Server is now the browser-based Windows Admin Center (WAC). Running the old Server Manager, a traditional desktop application, brings up a prompt urging admins to try WAC instead. WAC is also available in the Azure portal. Azure Arc is a service enabling admins to manage Windows Server on-premises from Azure.

The latest WAC uses HTTP/2 for improved performance. Azure File Sync, we are [8]promised , is a "much more reliable experience."

The security section of WAC now shows the status of Secured Core features. There are additional features available for users of Azure Stack HCI, on-premises hardware managed through Azure and paid for by subscription.

Microsoft's platform is still built largely on Windows Server, despite the fact that Azure now runs more Linux VMs than Windows. However, a new release of Windows Server though is no longer the big news it once was, with the company preferring to talk up its Azure cloud; and many of the new features are designed to integrate with Azure or (like the improved Windows containers) to run on Azure.

[9]

Despite that, the company has been consistent in delivering new Windows Server releases every three years or so, and continues to make progress on its goals of easier administration, removing reliance on the server desktop GUI, and stripping down the operating system so that most features are optional components. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YD5vLdcMYEAuXv9jLFl8cQAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://regmedia.co.uk/2021/03/02/server2022.jpg

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YD5vLdcMYEAuXv9jLFl8cQAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2020/11/17/microsoft_pluton_cpu_hardware_security/

[5] https://www.theregister.com/2020/05/04/microsoft_reveals_msquic_quic_implementation/

[6] https://techcommunity.microsoft.com/t5/itops-talk-blog/smb-over-quic-files-without-the-vpn/ba-p/1183449

[7] https://regmedia.co.uk/2021/03/02/admin-center2.png

[8] https://blogs.windows.com/windows-insider/2021/01/15/announcing-windows-admin-center-preview-2012/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YD5vLdcMYEAuXv9jLFl8cQAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://whitepapers.theregister.com/

karlkarl

I am generally using these server releases as my Windows workstation OS of choice.

Currently they are very close to the sweet spot of enough consumer features making it nice for a GUI desktop, yet not exhibiting too much criminality with regards to data theft. So much so that I even choose this OS edition for my dear sweet parents laptops XD.

The only thing that could ruin this is if Microsoft removes the GUI desktop from server releases. I can honestly see this happening since "Core" is now the default and the GUI stuff has been given a tacky name of "Legacy Desktop Experience".

So enjoy it whilst it lasts I suppose :)

Marty McFly

>"criminality with regards to data theft"

You failed at the corporate speak. It is properly stated as "Monetizing the user after the sale"

WAC?

BenM 29

If its anything like WAC on my PC its awful..... the UI is bad, the update management is even worse (have to install the updates for each extension individually!) and "treacle like" is being kind to it.

To be fair to it, one can do almost anything you want though a web page... got to be good, amirite?

Hey ho. Onwards in the Microsoft dictated direction!

p.s. it just took two attempts to correctly load all 14 VMs on my cluster into the Virtual Machine bit of the interface, even though they are all present in the Roles section. First time it ignored any hosted on node 2 the cluster hosts and displayed all the machines hosted on node 1. FOCM and Hyper-V manager are waaaaaaay more reliable/quicker when run remotely.

Re: WAC?

chivo243

I tried to use it, I tried to like it, it crapped the bed at every turn. I tried, really, it sounds like a nice concept...

eswan

"SMB over QUIC will allow "mobile users, hybrid users, travelling internet users, instead of using a VPN, [to] tunnel SMB traffic over the QUIC protocol which is a UDP, TLS, highly secure, easily firewall-traversing protocol… "

Oh, that sounds terrifying.

Captain Obvious

My thoughts exactly - a NEW attack vector that can directly access your files. What could POSSIBLY go wrong?

New Windows Server - but the company would rather talk about Azure

Mr Dogshit

I signed up for Ignite this morning, and was prompted to indicate my interests. Windows Server wasn't even listed as an option.

Oh, and hands up everyone who's seen server core in production use... Yeah, me neither.

Does it support TLS 1.3?

LDS

Last time I checked Windows didn't support it yet.

It should be a case of "Just plug in a new kernel, and suddenly your
existing filesystem just allows you to do more! 20% more for the same
price! AND we'll throw in this useful ginzu knife for just 4.95 for
shipping and handling. Absolutely free!"

- Linus Torvalds on linux-kernel