Jump to content

Recommended Posts

Posted

Hi just quick question does anyone know how to change the preset username format in SIMS?

 

We are about to have it set up here at the school and they claim it can't be done but there has to be away, currently our login for computers is "DPenfold" but SIMS wants to put Penfold, David (or something close to that).

 

Just trying to save time manually changing this for all staff members we are about to add on.

Posted
Although I hate to go against Phil :) you can change the defaults inside SIMS if you don't want to go with Windows Authentication. It's in Panel 1 of Focus|System Manager|Settings.
Posted (edited)

i too can understand the reasoning for not using single sign on. it adds another layer of security for the schools most sensitive and confidential information because we all know we can not trust a teacher not to leave themselves logged on anywhere.

 

As @Skelacia response for the solution to your query.

Edited by dapaulio
Posted
Yes Windows is the way to go

In what sense is it more secure?

 

If a student found out a teachers username and password surely they could log straight into SIMS? :confused:

Posted
In what sense is it more secure?

 

If a student found out a teachers username and password surely they could log straight into SIMS? :confused:

 

Which is 75% likely to be the same password they're using for domain login.

 

 

1) N+1 passwords = people writing them down.

2) One decent password is better than two terrible ones

3) SIMS access is curtailed as soon as a leaver's domain account is disabled, no need to manage accounts in two places.

4) You can set password policies for a Windows domain login.

5) SIMS-based logins leave the username and password in the clear (viewable in taskmanager with command-line column turned on) when launching SIMS components like exams organiser, leading to password disclosure to anyone with admin rights on the computer/terminal server they're using. Since SIMS has practically zero auditing unless money is changing hands, a user with admin rights on the computer can act as another user within SIMS.

  • Thanks 3
Posted (edited)
5) SIMS-based logins leave the username and password in the clear (viewable in taskmanager with command-line column turned on) when launching SIMS components like exams organiser, leading to password disclosure to anyone with admin rights on the computer/terminal server they're using. Since SIMS has practically zero auditing unless money is changing hands, a user with admin rights on the computer can act as another user within SIMS.

 

well fook me i never knew that. that is really bad.

 

surely this will also happen with single sign on which reinforces using a separate sims login is better than authenticating with your windows user. @pete do you know what other modules within sims also does this?

Edited by dapaulio
Posted

^ Nope. For Windows auth/SSO it launches ExamsW.exe with the /t (trusted) switch instead.

 

Windows login:

 

SIMSTrusted.png

 

SIMS login:

 

SIMSPasswordDisclosure.png

 

In terms of applications, I know the problem affects Nova T6, Options, Exams Organiser and the old System Manager 6 (which yes, no-one should be using).

Screen Shot 2016-01-29 at 12.00.24.png

SIMSPasswordDisclosure.jpg

  • Thanks 1
Posted

I think there has been some confusion lol

 

I am not asking about actually logging in (or process off etc.), just changing a template specifically how SIMS creates usernames.

 

When we come to import staff members into SIMS it creates the username as Penfold, David (or something close to that), then we have to manually go in to the staff profile and change the username to 'DPenfold'.

 

I'm just trying to see if there was away to tell SIMS to set the username how we would want it and not it's original settings.

 

However if can't be done then it can't

Posted

@DPenfold, yes can be done, like @Skelacia and @Linfit have said - its detailed in the documentation > log in to sims, then click documentation. Bit concerned "they" claim it cant be done.

 

Just to repeat myself, SIMS SQL logins is insecure, it may add a false layer of "security" but it adds a massive security hole. Windows security is far more secure. You should be teaching staff win key + L. It isn't difficult and far, far more secure then saying log out of SIMS

Posted

Thanks for the clarification, I have relayed this to the network manager (and the additional information) which I think he had already prepared for.

 

Additionally thanks for the keyboard shortcut, I acctually didn't know about that one, useful to know and pass on to other. Thanks again :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...