Jump to content

Recommended Posts

Posted

Hello,

 

As anybody been able to integrate Active Directory and SIMS.Net together? We've just moved to SIMS.Net and if possible would like the ability for SIMS.Net not to bring up the prompt but instead log them straight in based on their AD Credentials.

 

Thanks,

 

Rob

Posted

:eek: Surely this is a security risk?

 

What if a member of staff logons onto to a machine and goes walkabouts as they always do without locking it, when a kid wals up and opens SIMS and they can get access to all the info!:eek:;-)

Posted
:eek: Surely this is a security risk?

 

What if a member of staff logons onto to a machine and goes walkabouts as they always do without locking it, when a kid wals up and opens SIMS and they can get access to all the info!:eek:;-)

 

That is the exact reason that our LEA's given for not implementing this, tis VERY risky if your staff aren't absolutely spot-on with logging off.

Posted

Hello,

 

Thanks PRicho that worked. I just wanted to see how it works - not sure whether we will use it yet as concerns about security (same reasons as specified in above posts). It's a shame you aren't required to type your windows username and password into the SIMS.Net logon box as an extra bit of security.

 

Thanks,

 

Rob

Posted

How would this work in terms of an AD user changing their password? Would you have to manually go into SIMS System Manager to change it there too or would it happen automatically?

 

Dave.

Posted
if you change your password in AD it automaticly changes in sims.net, ive just tryed it my self

 

I understood (from the consultant who came to move our SIMS installation to our new server) that SIMS doesn't check passwords, it simply trusts the username it is passed. When they said "integration with Active Directory" I thought it was going to be something a tad fancier too - I thought I'd be getting SIMS checking against our LDAP directory and so on. I figure this is still a useful feature, though - it would seem to be perfect for SIMS over Terminal Services, so a user just needs to type their normal domain username and password to start a terminal session, then SIMS trusts the TS server and logs the user in automatically. I'm planning (in my copious spare time) to turn our SIMS server into a terminal services server, I'll see if this actually works.

 

--

David Hicks

  • 3 weeks later...
Guest Guest
Posted
I understood (from the consultant who came to move our SIMS installation to our new server) that SIMS doesn't check passwords, it simply trusts the username it is passed.

 

Is this true? From what i can think of it must be as adding a line to a clients ini file isnt going to make SIMS "intergrate" into anything.

 

If this is the case capita have dropped even lower in my expectations, and that *really* is saying something!! Feck me, what a terrible company! Good job they are "friends" with labour eh? :rolleyes:

Posted

The problem is users who use crap passwords, write down their crap passwords, tell their crap passwords to other people and consider their convenience more important than keeping data secure, buffered by management who doesn't see password (and thus data) security as a big part of the teachers job and so doesn't bollock them sufficiently when said lax password security is raised as an issue.

 

Single sign-on doesn't help with that, multiple passwords doesn't either because I bet anyone on here £5 that at least 50% of your staff have an identical AD and SIMS password, regardless of whether you've told them not to. That password will also give you access to their online banking 30% of the time, and they'll tell you that "I use that for everything" after telling it to you accidentally.

  • Thanks 2
Guest Guest
Posted (edited)
The problem is users who use crap passwords, write down their crap passwords, tell their crap passwords to other people and consider their convenience more important than keeping data secure, buffered by management who doesn't see password (and thus data) security as a big part of the teachers job and so doesn't bollock them sufficiently when said lax password security is raised as an issue.

 

Single sign-on doesn't help with that, multiple passwords doesn't either because I bet anyone on here £5 that at least 50% of your staff have an identical AD and SIMS password, regardless of whether you've told them not to. That password will also give you access to their online banking 30% of the time, and they'll tell you that "I use that for everything" after telling it to you accidentally.

 

lmao True.

 

Id say I know around 75-80% of the teachers passwords. God help them all if i was that type of person to raid their banks! Mind i do need a new car *mawhaha..*

Edited by Guest
Posted

sims not yet broke our AD, folder redirection just stopped working after applying ( yet another ) upgrade

but to be honest we immediately felt the benefit of the upgrade as we all got an icon changed !! wow :D

Posted
sims not yet broke our AD, folder redirection just stopped working after applying ( yet another ) upgrade

but to be honest we immediately felt the benefit of the upgrade as we all got an icon changed !! wow :D

 

LOL :D

  • Thanks 1
Posted
Reminds me, a kid once asked me the name of one of my collegue's wife. The kid was sat at a computer at the logon screen with the collegues's user name already typed in.
Posted
We make our users change AD passwords every 45 days, SIMS never makes them change it so it's a fair bet they're different here.

 

have you tested to see if oldpassword1, oldpassword2, oldpassword3 works? :)

 

I'd rather they had _one_ good, hard-to-guess or bruteforce password that they were careful not to disclose.

Posted
The problem is users who use crap passwords, write down their crap passwords, tell their crap passwords to other people and consider their convenience more important than keeping data secure, buffered by management who doesn't see password (and thus data) security as a big part of the teachers job and so doesn't bollock them sufficiently when said lax password security is raised as an issue.

 

Couldn't agree more.

 

Single sign-on doesn't help with that, multiple passwords doesn't either because I bet anyone on here £5 that at least 50% of your staff have an identical AD and SIMS password [...]

 

... disagree. I think it's well-documented that single sign-on does help for the following reasons:

 

1) It's easier to audit one authentication on one system than eg. 5 authentications on 5 systems running different types of authentication.

 

2) It's easier to configure your one point of authentication to have the security level you desire. "Force all your access through one door, and make sure you understand the security of that door". I *trust* the Windows implementation of Kerberos, I don't trust the fact that SIMS doesn't encrypt passwords before sending.

 

3) I restate, but the principle of requiring your users have ONE password instead of several WILL, overall, reduce the risk of passwords being compromised.

 

4) If a password has been compromised, there's one place to change it. Less confusion for the unsavvy user.

 

Ok... I hear your points. But there's no use being fatalistic about it: "nobody will ever take security seriously" etc...

Posted
Also, wasn't there a recommendation in the BECTA Security guidelines to implement federated access control (and therefore SSO)?
Posted

Well, we have the following passwords in the school for staff:

 

1. Their windows domain account, used for windows, helpdesk, room booking

2. Their email username and password, used for any system provided by county, so email, SiX, learning gateway etc...

3. Their website password, used for editing the school website

4. Their SIMS.net password

5. Their voicemail pin

 

And then, there are a few with access to other systems such as FMS, Nova-T4, and Expo Electro.

 

I know of at least 5 teachers who have those details written in their diaries. This number increases for our TAs.

 

A single sign on would increase security no-end.

  • 1 year later...
Posted
:eek: Surely this is a security risk?

 

What if a member of staff logons onto to a machine and goes walkabouts as they always do without locking it, when a kid wals up and opens SIMS and they can get access to all the info!:eek:;-)

 

I think you have answered your own question - The security risk is about staff leaving their workstations logged in and going walkabouts. I would be seriously worried about anybody leaving their workstation unattended with access to the network and email, let alone SIMS :eek:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...