Jump to content

Recommended Posts

Posted
i got it to work - white list emarker.co.uk in smoothwall - and for app blocker, set it up as publisher like this e-Marker2®-e2-p-005, version 16.0.0.0 and above, in "", from O=DRS DATA SERVICES LIMITED, L=MILTON KEYNES, C=GB

after in publisher tab publisher name is O=DRS DATA SERVICES LIMITED, L=MILTON KEYNES, C=GB (this should be all filled in)

under the product name, file name and file version just put a star in the box* as soon as i did this it started working. It may need a manual install but at least all users can run it once its installed

Let me know how you get on

 

I also managed to get it to work by whitelisting in smoothwall but just check that the whitelist you added to is included in authetication exception policies. and also app locker was preventing the user from running so also included allow publisher rule.

 

Thanks to all posts in this thread which helped me.

Posted

To date - the others haven't come back with an answer to me for "is this for work or on the side?" question I asked them.

 

That tells what you need to know really.

  • 2 weeks later...
Posted

I've got one member of staff for whom this doesn't work on their school laptop, even when signed in as a local admin using their home connection (or hotspotting my phone). The software refuses to sign in, saying it couldn't contact the server.

 

We have TLS 1.1 disabled on our machines, so I'm now wondering if that's what's breaking it.

 

Will test.

Posted
I don't envy you folks needing to support this, it comes up every few years here and we're (Backed up by the head) quite clear that we're not installing software on school devices that allows teachers to benefit financially themselves.

If they want to earn extra money, they can do it outside of school hours on their own equipment.

To date - the others haven't come back with an answer to me for "is this for work or on the side?" question I asked them.

 

That tells what you need to know really.

FYI still no updates. So we have our answer on that one as to what it's actually for.
Posted

I can't take credit for this, as another colleague got the software working by adding the following to the root of our web filtering tool (Lightspeed for us) and firewall.

 

*.emarker.co.uk, *.e-marker.co.uk

 

eMarker's 2nd line support number if required is 0345 121 4021

Posted (edited)

After a bit of testing, I've determined that the "e-Marker CMI+ v8.11.0.6" application requires TLS 1.0. Anyone wanting stronger ammunition for not supporting this software on school devices, there you go!

 

That's the one that's installed to Program Files by an MSI, not the v22.6 one that runs from user profiles (that one just needs to not have HTTPS inspection, so fine for home use).

 

It will fail to connect if TLS 1.0 is disabled on the device (giving the "Could not connect to server" pop-up) but with TLS 1.0 enabled, entering random login details will instead return the message "Login rejected", indicative of successful communication with the servers. We disable TLS 1.0 and 1.1 via GPO, so even with a local admin user on a home WiFi connection, the software wasn't able to connect to its servers.

 

I've been kind and loaned one of our staff members a school machine with a vanilla Windows install (not domain joined) as they have no other device available.

Edited by jthompson
  • Thanks 2
  • 10 months later...
Posted
If this is the same package that cropped up with a couple of staff here, the following AppLocker rules will suffice.

 

Two EXE publisher rules are needed, to allow your users to install and then run the software.

 

Name: E-Marker setup.exe publisher rule
Action: Allow

Publisher: O=DRS DATA SERVICES LIMITED, L=MILTON KEYNES, C=GB
Product name: 
File name: SETUP.EXE
File version: 16.0.30530.185 and above

 

Name: E-Marker application publisher rule
Action: Allow

Publisher: O=DRS DATA SERVICES LIMITED, L=MILTON KEYNES, C=GB
Product name: E-ASSESSMENT™
File name: DRS.PLATFORM.UI.FRAMEWORK.HOST.EXE
File version: 22.6.0.0 and above

 

The first one is obviously to allow the downloaded setup file to be run. That then downloads and installs the application to the user's own profile. The second rule allows that installed application to be run.

 

Not aware of any issues with it once running, but that may yet come to light, I suppose.

 

To update this for the version being seen currently (e-Marker2®-e2-p-010), we've needed to add one more AppLocker rule. The rule is a script hash rule.

During a failed installation, follow the error message to locate the install.log file. Alongside install.log will be EULApackage\EulaAccepted.bat. Add that bat file to the AppLocker script hash rule. The batch is a one-liner that literally just runs echo "Successfully Installed".

 

The latest version of the other variant, CMIPlus Marker, is still an MSI that installs to Program Files, and it still requires TLS 1.0 to be enabled in order for the user to sign in, etc.

  • Thanks 1
Posted

Am struggling getting this working with Smoothwall for some reason (am sure I get this working last year for another member of staff)

 

I've got e-marker.co.uk and emarker.co.uk in do not inspect in Smoothwall and it's still not working. Getting the red

 

"The System could not complete the requested actions as your network connection is unavailable. The system will now close."

 

Stuck now!

Posted
It's worked for us in recent days, by having no https inspection. I wonder if there are some other domains to account for.

 

Possibly? I've emailed aqa support so lets see what comes back. I'll report back.

Posted

I've noticed that if last year's version isn't uninstalled first, it'll remain as the version that gets launched, even if you've installed the latest version.

 

For instance if e-Marker2-e2-p-005 is still installed from last year, installation of e-Marker2-e2-p-010 from this year will appear to succeed, but it'll be 005 that will actually run. That one seems to give a communication error when attempting to sign in.

Uninstalling it and then installing 010 again then all works as expected.

  • Thanks 1
Posted
I've noticed that if last year's version isn't uninstalled first, it'll remain as the version that gets launched, even if you've installed the latest version.

 

For instance if e-Marker2-e2-p-005 is still installed from last year, installation of e-Marker2-e2-p-010 from this year will appear to succeed, but it'll be 005 that will actually run. That one seems to give a communication error when attempting to sign in.

Uninstalling it and then installing 010 again then all works as expected.

This is interesting, I didn't get chance to take a closer look and didn't get a response from AQA as yet but I'll try and see if this is the issue we are experiencing.
Posted
I've noticed that if last year's version isn't uninstalled first, it'll remain as the version that gets launched, even if you've installed the latest version.

 

For instance if e-Marker2-e2-p-005 is still installed from last year, installation of e-Marker2-e2-p-010 from this year will appear to succeed, but it'll be 005 that will actually run. That one seems to give a communication error when attempting to sign in.

Uninstalling it and then installing 010 again then all works as expected.

 

Does look like the teacher has e-Marker2-e2-p-005 so am trying to get them to find a new URL to download the latest version.

 

Cheers.

Posted
I've noticed that if last year's version isn't uninstalled first, it'll remain as the version that gets launched, even if you've installed the latest version.

 

For instance if e-Marker2-e2-p-005 is still installed from last year, installation of e-Marker2-e2-p-010 from this year will appear to succeed, but it'll be 005 that will actually run. That one seems to give a communication error when attempting to sign in.

Uninstalling it and then installing 010 again then all works as expected.

 

Superstar you are! Teacher now on and working. :-)

  • 3 weeks later...
Posted
Senso for us in the end, might be worth looking if you have anything else doing decryption (worked fine for staff today.)

 

which allow list did you put it in? and what urls?

 

thanks,

 

dan

Posted
which allow list did you put it in? and what urls?

 

thanks,

 

dan

Hi Dan, I put in exe's instead of URL's - AutoUpdater.exe|LFAMarker.exe|LoggingClient.exe|Drs.platform.ui.framework.host.exe

 

Edit No spaces in DRS

  • Thanks 1
Posted
If this is the same e-marker software that WJEC uses (by DRS or something like that)...then giving the folder in Program Files (x86) full permissions for the user that will be using it worked for me.

 

The software doesn't work when in school or via the VPN, though that's because our filtering blocks it. I'm not bothering fixing it, because IIRC, staff aren't allowed to use the software on the school's network (think I got that from a previous teacher who was doing it). I created a local user on the staff laptop for them to log into at home, instead of using the AOVPN and gave that account full permissions on the folder in Program Files (x86). I've had confirmation from the member of staff that it works for them at home, using the local account on the laptop.

Thanks for the tip. Read and write access got it to the login screen.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...