Jump to content

Recommended Posts

Posted (edited)

This project isnt about staff locking their workstations, its providing Single Sign on, not having staff to remember yet another password, enabling them to be more efficient and productive, might mean they start the lesson 5 minutes sooner, all those 5 minutes adds up

 

Yes, staff should lock their workstation and our's here do, they are proactive about security. I think you have slightly strayed off topic here, as the entire topic was about creating Single Sign In, not the politics surrounding security of workstations.

 

(We currently have single sign on for all our web services, email etc - SIMS is the only one not linked, and now it is!)

Edited by SovietRussia
Posted

I don't know teh mechanism of Windows logins, if implemented properly, can't it be made as secure as the login to Windows?

I'm asking because the main point of SaSO was to be able to extend it to other systems that may well be web based, so you don't have to log in to windows first.

The server talks to AD but you can use the same credentials.

 

We're looking at a project where multiple disparate systems will all have the same username fed from the MIS, but we want ideally the passwords to be centralised, and so ideally from AD.

 

For the case in point, man in the middle isn't a major issue, putting in another barrier is the requirement. So yes, you're right Windows + L does the same thing.

But if SLT don't even understand the point, or the need for this, if it's SLT you're battling not the teachers, then you might as well give up... or come up with a bit of code as a fun project that puts in a barrier and there is no harm done.

 

I agree with you @SovietRussia but why if you have a really secure environment where they do already lock their stations do you want to make them sign in to SIMS? If you've reached @matt40k 's utopia environment, then why do you want that barrier. it will use the same sign on, but do it secretly, and save even more time. Just implement trustedauto

Posted
This project isnt about staff locking their workstations, its providing Single Sign on, not having staff to remember yet another password, enabling them to be more efficient and productive, might mean they start the lesson 5 minutes sooner, all those 5 minutes adds up

 

It's called trusted(auto) mate. It's already present and I personally would\have\do push schools moving towards it. It makes sense to use a central single AD user rather than a separate less secure SQL login. I don't agree with requiring the user to re-authenticate. It's just wrong and makes me annoyed.

Posted
As much as I love a good start up... There are quite a lot of reasons this might not be a great idea... least of all it won't take much for Capita to add a few lines of code and completely kick the venture into touch...

 

Doesn't touch the SIMS code at all - it just fires up the exe. It's that simple :) You could point the config at VLC Media Player if you so wished!

 

I realise that's its strength and weakness - it's just a simple little AD logon executable.

 

For most schools, SLT approve the policy of locking workstations. People will still forget to. If you're using auto login, that's a problem (though of course they'll often leave SIMS open too, that's another issue). An extra auth layer there could just be a savior - our feedback is that users don't want SIMS to auto-logon without prompt, but they'd like it to use the AD password. In that regard, job done.

 

It's not difficult, it's not long winded. It's simple. If they can't do that, they shouldn't have access to the data. Period.

 

But they will do it, and that access will not be taken away. While a fuss can be kicked up, those staff will continue to be given access to that data, as they need it to do their jobs. A staff member's teaching union would kick up a storm if it was any way otherwise.

  • Thanks 1
Posted
Some times it's fun to make you noyed :p

 

Hehe yer, it normally gets things sorted as well. One day I'll write a MIS system just because Capita narked me off.

Posted
Hehe yer, it normally gets things sorted as well. One day I'll write a MIS system just because Capita narked me off.

Please please please call it XYZMIS and make it implement SaSO and TidyBackups as defaults :)

Also Google integration wouldn't go astray

Posted (edited)

OK, will do. The day Capita kills my family* and I go all Geeky Liam Neeson I shall implement SaSO and call it XYZMIS - perhaps I'll call the company 001A Better than Superman, batman and the hulk combined software development ltd?

 

* by dropping the latest SIMS release (with patches) on floppy discs on top of them - all 4 billion of them

Edited by matt40k
Added tragic death
Posted

As the author of this thread I'd like to thank you all for your input. I'm going to hold off with the SIMS single sign on for the time being.

 

Yesterday afternoon I went into an open ICT suite and found a senior head of dept had left themselves logged on to a computer, usb drive loaded with what ever data plugged in and her handbag open with purse and car keys ready to be taken. I'm losing the security fight all ends up by the looks of it.

Posted

Sucks.

When I find an open machine I set a screen saver and ask for password to unlock. Usually the text banner one with a message like "School Security Page".

 

Did 2 last week. Nobody has ever complained or even mentioned it. They either disable it quietly or more likely don't know how and are too embarrassed to ask.

Posted
Just got a call back from Capita; unfortunately it is not possible to have SIMS request the user for their AD username and password, its either SIMS logins, automatic AD, or choice. If need be we can put a change request in via SupportNet.
Posted

Anything you do will fail when things like this happen:

 

Yesterday afternoon I went into an open ICT suite and found a senior head of dept had left themselves logged on to a computer, usb drive loaded with what ever data plugged in and her handbag open with purse and car keys ready to be taken.

 

You'd be better off getting cats and putting cat nip in the keyboard. Actually I suspect training that cats to lock the workstation when they leave the room and to lay on the keys until they return might be easier than training some people.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...