ICC Meeting: |
IFAS COMPUTER COORDINATORS
|
Message from Andrew Carey to the ACTIVEDIR-L: We’ve received several reports of users using non-domain joined Windows XP computers being unable to access domain joined resources following this weekend’s change. In most cases this can be resolved by setting “Network security: LAN Manager authentication level” in the computers local security policy to “Send NTLMv2 response only. Refuse LM & NTLM” by utilizing one of the three methods below: Method 1: Edit the Local Security Policy
Method 2: Edit the registry from a command prompt (recommended for advanced users)
Method 3: Edit the Registry Directly (recommended for advanced users)
Andrew Carey |
Based on some reports he had heard from the counties, Steve expressed his concern that this reghack may be needed on some Windows Vista and Windows 7 machines as well -- though this did not appear to be the case with his own non-domain joined laptop at home running Win 7 Home Premium. Bill Black responded that he thought the county reports might be due to the fact that those machines were joined to a county domain which might be pushing policies that are incompatible with our required settings.
Accessing protected websites
Steve had noted in an e-mail to the ICC that he has various websites, usually class websites, that have been secured by denying read access to ANONUSER on the web server file system and adding an additional security for read access. That security group is then populated with the appropriate course autogroup(s) to control access by registered students.
Since the InCommon Silver implementation, http access from Macs has been problematic. In many cases, the user is prompted for credentials but repeatedly presented with an "improper credentials" message. This has been making it impossible for students to complete on-line courses in a number of instances.
It turns out that Safari works (with only one noted exception so far) but Firefox and Chrome do not. Alex forwarded a message from Joe Gasper that suggested Chrome could be made to work on Linux and Macintosh by running with command-line arguments:
Chrome.exe --args --auth-schemes="basic"
The question, however, is how to implement commandline arguments on the Mac. Steve believes that can be done with Applescript, but does not fully understand the details. Consequently, he is not sure this would be practical for most end-user situations.
Implementing the Mobile Computing Security policy (previous discussion).
Updates as available...
Wake on LAN support coming to campus: (previous discussion)
Updates as available...
New Secunia site license (previous discussion)
Updates as available...
KACE agent deployed to IFAS (previous discussion)
Updates as available...
Domain Policy and redirect duration (previous discussion)
Updates as available...
CNS working to implement NAC for UF wireless (previous discussion)
UFW going away
Notice was put on NETMGRS that: "On the morning of Monday, August 13th, the "ufw" wireless network will be changed to forward users to the same on-ramping site as "ufinfo". At that point the "ufw" wlan will no longer be usable for general connectivity. All users who have not already done so will need to transition to the new "uf" wlan to gain network access."
Antivirus software on Macs
Jimmy Anuszewski had questioned the requirement for antivirus on Macintosh. At the very least he felt that ClamXav should be considered over the Sophos solution that is being recommended. Steve had pointed folks to a Mac Virus/Malware FAQ that offered some good Macintosh security advice and which seemed to back-up Jimmy's contentions. Dan Cromer said that he had passed Jimmy's comments on to the UF security folks.
Jimmy also suggested that it might be time to consider officially offering Macintosh support within IFAS.
Being proactive on switch-over
Dan Miller put out a plea for getting proactive on the switch-over well prior to the Fall term:
Message from Dan Miller to the NETMGRS: IT Support Staff, This is a reminder of coming wireless changes and a request for assistance. We still have thousands of people using the old 'ufw' wireless system which is scheduled to be sunset on Aug. 13. UFIT is concerned about the current backlog and the coming wave of new and returning students, staff, and faculty. We have just implemented a timeout of active 'ufw' wireless sessions after 2 hours to encourage people to move to the new 'uf' network now. Some users may be upset due to lost work even though we have been sending targeted emails to them for the past week. Please help us with this transition in the following ways:
Apologies for cross-posts. We are trying to get the word out to everyone. Please refer to the email from July 6 "Major NAC Posture Assessment changes coming July 16, Aug 13, and Sept 5" for more details or go to http://getonline.ufl.edu/. Thanks, Dan Miller |
Steve noted that this is going to create a lot of work at the unit level. He mentioned that when his building went Wallplate, he was essentially relegated to being an end-user on his own network. For anything needing to done Steve has to submit a ticket to CNS and CNS staff resolves the issues themselves. Steve feels it a bit ironic that now that local support is required due to central network changes, that there is no hesitation to push down the responsiblity to us for resolving issues. Steve just wishes the entire system was a little more distributed where unit staff could feel valuable at all times rather than only in those situations where we are needed to help with some particular tricky implementation that was decided on by the higher ups.
Disconnect with UF Security?
James Moore pointed out that the NAC posture assessment was not CNS's doing, rather this was mandated by UF Security. CNS is merely putting their box in front of that connection so that everyone has to proxy through it. CNS isn't particularly happy with the situation either because they will be called upon for resolution in a number of situations themselves and will have to relay some of those to the security folks as well. Steve pointed out that there seems to be somewhat of a communications disconnect with UF Security. He gave the example of the Oct 2011 Security Workshop where the presentation ended with this slide:
.
Steve had sent a number of questions concerning PGP to the specified list and received no response at all. Similarly, Jimmy Anuszewski has recently sent some queries related to posture assessment with the same result. That seems pretty poor.
New wireless is a great improvement in many ways
James said that the new system is great for connectivity and he (along with the rest of us) has enjoyed being able to roam between WAPs without losing connection or having to reauthenticate. The only downside he has noticed with when the edge of darkspots are encountered his smartphone keeps switching between wireless and 4G and thus battery life takes a considerable hit.
Configuration difficulties
Winnie Lante said hat setting up the new wireless appears to be too difficult for most to handle on their own and that foisting this on everyone within two weeks of the start of Fall term is obviously going to cause major problems for many. Winnie reported doing an informal survey while swimming at the pool yesterday. She asked the four lifeguards if they had used the new network; they were all aware that they were supposed to be using that but only one of them had been able to do that successfully before giving up.
Steve asked where we should go if we can't resolve getting someone connected. Winnie said that she had responded to Tim Fitzpatrick's e-mail and that he had said they are working with the UF Computing Help Desk on creating a FAQ; the only problem is that this is needed NOW.
Steve noted that he had created an administrative install point for this at \\ad.ufl.edu\ifas\software\UFwireless. He based that on the IT wiki instructions and has found it to work well in his limited testing. Steve created a readme.txt file describing the process, but basically you run two programs via the command line, passing the appropriate arguments and the laptop will be ready for use. Steve plans to try adapting this to USB use for installing on student laptops--he is hopeful this will make the process quick and easy but would like others to try it and report the results to the ICC-L.
David Blackman noted that the automatic and manual install processes seem to ask for saving connection credentials. He was concerned with how that is supposed to work with multi-user laptops. Steve responded that he has always declined to save the credentials during the install and that the above mentioned administrative install foregoes that altogether. In his limited experience, one can perform the administrative install and then a user will be prompted for credentials upon first connection. Steve does not know, however, whether or not a different user would connect with the original user's credentials if those had been saved. One would certainly hope not.
Steve mentioned having one Mac that just would not connect. It turned out after the meeting that the solution was to delete a particular certificate from the keychain; apparently the bad cert was preventing the connection. Once that was done things worked flawlessly.
UF Exchange updates (previous discussion)
Viewing of attachments in OWA blocked temporarily
Microsoft released security advisory 2727111 that impacts previewing the content of e-mail attachments in OWA. UF has disabled this feature until a patch is released.
legacy.mail.ufl.edu is being decommissioned
Very few have this in their mapi client configuration settings (like two within IFAS overall), but be warned that this temporary name which was used during the migration to Exchange 2010 is going away.
Outsourcing of student email?
Updates as available...
Sakai e-Learning System now in production (previous discussion)
Updates as available...
Alternate IFAS domains in e-mail (previous discussion)
Updates as available...
Electronic Copy - Print Output Cost Reduction program (previous discussion)
Updates as available...
Split DNS solution for UFAD problems (previous discussion)
Updates as available...
New web cluster (previous discussion)
Chris Leopold reported that Santos Soler has been severely side-tracked from his main web migration tasks by having to fix MFP issues related to the inCommon Silver changes.
Windows 7 Deployment via the WAIK, MS Deployment Toolkit 2010, USMT 4.0, WDS, and SCCM (previous discussion)
MDT 2012
Updates as available...
SCCM for IFAS
Work continues on the central SCCM plans.
Updates as available...
Exit processes, NMB and permission removal (previous discussion)
Updates as available...
Re-enabling the Windows firewall (previous discussion)
Updates as available...
Services Documentation: Is a Wiki the way? (previous discussion)
Updates as available...
Moving from McAfee VirusScan to Microsoft Forefront Endpoint Protection? (previous discussion)
Dennis Brown mentioned having used SCCM to build a machine using a package that Kamin Miller had created. He was concerned that this installed FEP and wondered if that was okay. Alex York responded that until we have the UF SCCM infrastructure in place, that FEP will not be an enterprise solution. Using it prior will be the same as installing Microsoft Security Essentials. Alex said that he can show Dennis what to uncheck in order to avoid getting FEP installed.
Print server (previous discussion)
Updates as available...
Recording lectures for Distance Education (previous discussion)
Mike Ryabin asked about the Mediasite Desktop Recorder that Steve had entered into last month's notes. Steve responded that this appliance was something he had heard about and wondered whether or not it might be supported at the UF level, as Steve continues to look for lecture recording solutions for when our existing Accordent Capture Stations must be removed (once WinXP goes end-of-life in April of 2014). Steve had not investigated further however. Mike suggested that he might go through Patrick Pettus to investigate this further and Steve would be interested in anything he might discover.
New DHCP reservation site created (previous discussion)
You are reminded that Santos Soler has created a new DHCP reservation site which you may use to request reservations.
Restoration of back-ups on the file server
Wayne Hyde intends to document and announce proper usage as time permits.
Membership of ". IFAS-ICC" e-mail distribution group to be narrowed to ICC members only (previous discussion)
Steve will keep this as a standing item on our agendas for now as a reminder. The ICC distribution list is more targeted and restricted to IFAS IT support folks only.
IFAS efforts toward Green IT (previous discussion)
Updates as available...
Creating guest GatorLink accounts: singly or in bulk (previous discussion)
Steve had left this on the agenda in case further discussion was deemed warranted.
Can IFAS support DirectAccess in the future? (previous discussion)
Alex York is looking into the possibility of supporting DirectAccess at the IFAS level. While this would provide a wonderful new service for domain-joined laptops, and in fact be a strong impetus for joining some laptops to the domain which we previously had not, it still will not address non-domain joined machines -- both laptops and personal machines owned by faculty, students, and staff. A VPN will obviously still be required and the question is whether or not IFAS wants to maintain an in-house VPN indefinitely.
Moving away from the IFAS VPN service (previous discussion)
Steve pointed out that he prefers "l2tp over ipsec" rather than the Cisco Anyconnect Client because of the way the former functions on non-managed machines. Upon connection with l2tp, network resources can be directly access via their UNC paths. That does not work with the Anyconnect client because the local user account is assumed and the only way present alternate credentials is to map the resource as a drive letter:
This requirement makes connecting to shared resources considerably more difficult via the Anyconnect client. Since CNS has declared its desire to eventually remove the l2tp VPN access, Steve feels IFAS should consider maintaining their own solution--but hopefully one that would provide private IPs rather than public numbers.
VDI desktops as admin workstations (previous discussion)
Updates as available...
Wayne's Power Tools (previous discussion)
Updates as available...
Computer compliance tool in production (previous discussion)
Updates as available...
Folder permissioning on the IFAS file server (previous discussion)
You are reminded to please take the time to read and implement the new standards. If you have any questions get with Wayne or Steve.
Disabling/deleting computer accounts based on computer password age (previous discussion)
This is yet another matter for which finding time for implementation is proving difficult. Steve wants folks to remember that Andrew Carey had a good plan for dealing with this which perhaps Alex can find the time to address eventually. In the meantime, it would be very good of each OU Admin to consider mimicking the proposed plan manually by keeping their own records and deleting any computer object which have been disabled for 90 or more days; Wayne's Power Tools can identify those. Steve has finally begun doing that for his own unit and it has made his view within ADUC much more agreeable.
Since BitLocker stores its keys within the computer object in UFAD, Alex York and Chris Leopold are considering scavenging those keys for secure storage elsewhere. That would provide a fallback for decrypting a drive should the associated computer object be deleted.
Core Services status (previous discussion)
Updates as available...
ePO updates (previous discussion)
Updates as available...
Status of SharePoint services (previous discussion)
IFAS migrating to centralized MOSS
Updates as available...
Public folder file deletion policies and procedures status (previous discussion)
Updates as available...
Patching updates... (previous discussion)
Microsoft
The August Microsoft patches will include 9 bulletins (5 "Critical," and 4 "Important") addressing multiple vulnerabilities in Microsoft Windows, Internet Explorer, Exchange, SQL Server, Server Software, and Developer Tools.
McAfee provides podcasts on the highlights of each month's offerings.
Adobe
Flash ActiveX 11.3.300.268 was released late last week. It fixes an issue where the FlashPlayerUpdateService was crashing on many systems. But wait! They soon updated that to 11.3.300.269 and now I hear they've got 11.3.300.270; it's enough to make you dizzy! The latest secure version is still 11.3.300.257.
Adobe has announced plans to release security updates for Adobe Reader/Acrobat this patch Tuesday.
Cyber Self Defense Class Via Videoconference
Message from Dan Cromer to the IFAS-Announce-L: Cyber Self-Defense Class The popular UFIT “Cyber Self Defense” class will be held via videoconference on Thursday, October 25. This is a great opportunity for UF and affiliated staff around the state to learn about a variety of safety and personal information security issues when going online. Do you use the Web to make purchases? Do your kids spend a lot of time on social media? Participate in this session and find out more about safe Web browsing, encrypting and backing up files, email, and wireless security. UF information security engineer Derrius Marlin leads an interactive discussion on topics that get participants thinking about how to protect both personal and work-related information. Videoconference ports are limited!
A confirmation email will be sent, followed by additional course information, handouts, and connectivity information the week of the class. |
MS Office News update (previous discussion)
Updates as available...
Job Matrix Update status (previous discussion)
Updates as available...
Remedy system status (previous discussion)
Updates as available...
WINS removal
Chris Leopold said that WINs is going away at the UF level on September 16th. His recommendation is to remove it on our machines sooner rather than later, especially since we have moved our DFS to FQDN now. The only issue he could see might be with some very old applications. Steve asked if Chris had talked to Joe Hayden about that as Steve suspects Joe might be one of those potentially running such things.
Windows Update Errors
Francis Ferguson asked if anyone had been getting Windows Update errors. He has seen this with a number of machines lately that he was trying to patch; these were machine that he had not yet joined to the domain. The errors were eventually resolved by shutting down and restarting several times but he has no idea why they occurred or exactly what resolved them. No one else reported having seen such a thing.
Dennis Brown mentioned that his assistant, Jeanne Tucker, had supposedly fully updated machines after a rebuild, begun copying files back, then had the copy interrupted by a reboot forced via WSUS. A number of folks responded that they reboot and rerun a manual Windows Update yet again to ensure all patches are installed first before proceeding. Sometimes there are dependencies whereby one patch is not needed until another one has been done.
Getting IFAS to officially support Apple
Jimmy Anuszewski asked how one might go about getting IFAS to officially support Apple products, since he is seeing more and more students and staff using those products. Steve pointed out that the official means for doing this would be to build a consensus at the ICC level, have us draw up a formal recommendation which Dennis Brown would take to ITPAC as our representative. Should ITPAC approve that recommendation, then it would be up to IFAS Administration whether or not the IMM would be modified to so declare. In Steve's experience, this process is much like walking barefoot on hot coals, but somewhat less satisfying in end result. Steve noted that he supports Apple products locally via a knowledgeable local staff member; he suggests doing this for one's own unit is the way to go rather than trying to turn the entire IFAS system that direction.
WordPress (previous discussion)
Chris Leopold asked if anyone had heard about a de-emphasis on WordPress at the UF level. Jimmy said that this was discussed at the last Web Administrators meeting. Most felt that whatever UF decided on centrally would have little effect on what they were doing currently. There was very little expectation that any CMS would be widely successful here at UF.
We re-discussed the difficulties of backup/restore with mySQL and John Wells said that he is okay with the potential loss of a day or two of data. He feels the applicability of WordPress to their needs overrides these other potential issues.
WebDAV and VDI announcement pending (previous discussion)
Updates as available...
Big Blue Button proof-of-concept server (previous discussion)
Updates as available...
Results of GPO disabling for non-portable devices (previous discussion)
Updates as available...
The meeting was adjourned on time at about noon.