Jump to content

Recommended Posts

  • 10 months later...
Posted
Before I start on ours has anyone installed the new version yet, any workarounds needed etc.

 

Just installed the Summer 2024 CMI+ version. It looks like it still needs to have TLS 1.0 enabled on in order to sign in, like in previous years.

  • Thanks 1
Posted (edited)

Just encountered this year's E-Marker2 now. The AppLocker rule for the main executable (DRS.PLATFORM.UI.FRAMEWORK.HOST.EXE) need adjusting to update the publisher and product name:

 

Rule type: EXE publisher rule

Action: Allow

Group: [your user group]

Publisher: O=AQA MILTON KEYNES LIMITED, L=MILTON KEYNES, C=GB

Product name: E-MARKER2®

File name: DRS.PLATFORM.UI.FRAMEWORK.HOST.EXE

File version: 24.17.0.0 and above

Edited by jthompson
  • Thanks 1
  • 3 weeks later...
Posted
Just installed the Summer 2024 CMI+ version. It looks like it still needs to have TLS 1.0 enabled on in order to sign in, like in previous years.

Do we know if this is definitely the case?

 

If it is, we are probably going to get a bunch of push back about it because its a security issue... but in trade off between security and someone else's priority, it's security.

Posted
Do we know if this is definitely the case?

 

If it is, we are probably going to get a bunch of push back about it because its a security issue... but in trade off between security and someone else's priority, it's security.

 

It is in our environment. Turning TLS 1.0 back on on the client gets the software working. It seems surprising given how close to deprecation TLS 1.0 must be now in regular Windows 11 home computers.

  • 2 weeks later...
Posted
It's worked for us in recent days, by having no https inspection. I wonder if there are some other domains to account for.

 

Had to allowlist some e-marker.co.uk domains from SSL/HTTPS deep Inspection today. When testing I saw it contact the following domains.

Not sure which one(s) exactly don't like being inspected, but we've allowed them all and it's working again for our staff:

 

e1p001dirsev.e-marker.co.uk

e1p001script.e-marker.co.uk

e1p001marker.e-marker.co.uk

e1p002marker.e-marker.co.uk

e1p003marker.e-marker.co.uk

e1p004marker.e-marker.co.uk

e1p005marker.e-marker.co.uk

emp001web.e-marker.co.uk

idp001web.e-marker.co.uk

Posted
We have one VLAN with no MITM certificate - if it is installed under this then it runs with SSL interception when moved back to the staff laptops VLAN. If installed with interception then it needs interception disabled when running, so TLDR install it with no interception and it will run with interception...
Posted
It is in our environment. Turning TLS 1.0 back on on the client gets the software working. It seems surprising given how close to deprecation TLS 1.0 must be now in regular Windows 11 home computers.

 

Why pay to update the software they know most of their markers are going to shout and scream until we make it work?

Posted
It is in our environment. Turning TLS 1.0 back on on the client gets the software working. It seems surprising given how close to deprecation TLS 1.0 must be now in regular Windows 11 home computers.

 

this will be disabled here soon on all clients its only done on DCs at the mo - so hopefully next years version will support TLS 1.2 or 1.3

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/tls-1-0-and-tls-1-1-soon-to-be-disabled-in-windows/ba-p/3887947

i think its the Next major relase of 11 24H2 that it wil be disabled by default - i think i read that somewhere.

Posted

ew. I had to install this last year for a few staff (Who aren't here now) but the TLS 1.0 thing would give me cover to proclaim it as toast from a security standpoint if asked for again.

 

That's really nasty, it's 2024, not 1997.

Posted
Just had an issue not sure if people should be aware - I had installed it on staff laptops - but a member of staff has been off sick but has still been e-marking and has uploaded something with the school logo - I don't quite understand it myself but it breaches the employment contract you shouldn't be doing work for other companies if you are off sick.
Posted
I'm not sure the fact that it's installed on a school-managed device would have any bearing there. They can fall foul of that just as easily using their own device.
  • 10 months later...
Posted

Hi Guys, 

 

Just wanted to add to this as we've been hounded by some of our teachers to have this installed (they had it on their old staff laptops apparently, before my time).  It's so they can do marking for the WJEC outside of their day job. 

We remembered seeing something online a while back saying it should not be installed on work devices. Of course, typical we can't find the document again today. So my colleague decided to call the WJEC application support team. 

It turns out the teachers are told not to use work devices at all, the WJEC went as far as telling us that it's in their contracts with them, to not use a work device! They mentioned things like conflicts of interest and protentional data breaches as the reasoning. 

 

Before we saw that document many months ago, we did start doing what most of you are talking about here, trying to get the damn thing working on our network! 

But now it's an easy one for us, no! Check your contract. 

 

Hope that helps some of you!

 

AB

 

  • Like 2
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...