Jump to content

Recommended Posts

Posted

Hopefully an edugeeker will be able to answer my question before monday.

 

Im restructuring our S drive which sims sits in. I've restricted staff from a lot of folders. However, the SIMS folder has always been completely unrestricted to staff. I want to ensure staff can't take ownership etc or delete files.

 

What set of permissions do you have in your setup of the SIMS folder?

 

Thanks

 

Phil

Posted

A standard user should never have Full Control. This is the permission that essentially allows them to change permissions, etc. All it takes is one user at the top of a folder structure to wipe out any permissions down the tree. Full Control should only used by Administrators, etc. Also, give access to the 'Deny' permission and it's just asking for trouble. I was always taught that you should never need Deny permissions to be set either, as you should be able to control access to a resource by only granting what is needed.

 

Last place I worked was managed system by EDS where the main public share all users had full control over. So all these folders were being created with specific permissions for users and groups, and on a regular basis we would have to make a phone call to the helpdesk to get the permissions reset as someone had overwritten things. Nightmare.

 

Our setup for SIMS is that a drive mapping is made to the S: drive but it is hidden. Also, I believe (set this up a while ago) that they have Read only access to it as well. You do however need modify to do a fresh install SIMS on to a workstation as it writes to the S: drive during the install :confused:.

 

Also, remember to exclude the s:\sims\setups from the On-Access on your Anti-Virus policy as this slows down the launch of SIMS.

 

HTH

 

Pete

Posted

I have Full Control for my S: drive, although this is limited to a group called "SIMS Staff" (which is limited to all staff.. ).

 

Ideally, though, I would prefer to have it properly set, but I have never found any instructions within the Capita docs that say what it should be (not that I have specifically looked though).

Posted

what permission level does the SIMSPERM.BAT file set?

I know that if this hasn't been run then users cannot run the workstation upgrades..

 

Our S: Drive & SIMS Server is maintained by the LEA, though I tend to double check SOLUS has run and that the upgrades apply to all the clients.

Posted
A standard user should never have Full Control. This is the permission that essentially allows them to change permissions, etc. All it takes is one user at the top of a folder structure to wipe out any permissions down the tree. Full Control should only used by Administrators, etc. Also, give access to the 'Deny' permission and it's just asking for trouble. I was always taught that you should never need Deny permissions to be set either, as you should be able to control access to a resource by only granting what is needed.

 

Last place I worked was managed system by EDS where the main public share all users had full control over. So all these folders were being created with specific permissions for users and groups, and on a regular basis we would have to make a phone call to the helpdesk to get the permissions reset as someone had overwritten things. Nightmare.

 

Our setup for SIMS is that a drive mapping is made to the S: drive but it is hidden. Also, I believe (set this up a while ago) that they have Read only access to it as well. You do however need modify to do a fresh install SIMS on to a workstation as it writes to the S: drive during the install :confused:.

 

Also, remember to exclude the s:\sims\setups from the On-Access on your Anti-Virus policy as this slows down the launch of SIMS.

 

HTH

 

Pete

 

Does this work fine for Workstation upgrades too?

Posted

The read/write access to the S: drive is historic from the days of common platform and even earlier when SIMS was a series of DOS modules.

 

SInce that data is now held in SQL and and documents are maintained in the docstorage the open access to the drive should be reveiwed.

 

Our SIMS shared drives are configured for users to see certain area's only depending on their role in the school.

 

All can see the route H:\sims to allow for a central connect.ini, and then only the sims star folder is accessable admin staff who need to see either the CTF's or the datafeeds.

We then have an area available to specific staff that hold data that is sent to the LEA via AVCO. This includes the location of the census and SWC returns.

 

The SIMSPerm.bat is only designed to set the local machine with athe correct security levels.

Posted
There has never been a need for staff to have full access rights to use or upgrade SIMS.

 

Can't get NOVA T4 or T6 to work without full access rights for those staff that use NOVA.

Posted

There's little in the S: drive these days that staff would need full access to... SNOVA folder for nova users (that don't log in to T4 as "default user"(?)) could be one, but I don't really see the need for anywhere else as everything else goes straight into SQL these days.

 

Having said that, or looking at the same point from a different direction I suppose, so long as you've got a backup of the SNOVA folder since the last timetable change and the S: drive since the last upgrade, nothing much else should change day to day :)

Posted

We've been told to run wssecurity

 

Btw does anyone actually know what permissions this makes? It takes an aweful long while. I imagine it to be setting full control to everything including the reg settings or something!

 

We all talk about it setting permissions, but what permissions? I've installed workstations without running this and they still work. This maybe because I've set them up as local admins.

 

Since last weekend, I defragged the D: drive on our sims server and everythings very very slow. Queries are taking extra long. I've been in touch with .ICT and they said that defragging will only improve file system performance. They then tried to re-index the sims database but this has not fixed the slowness problem. We're flatlining the CPU with 100% everytime a staff member pulls down the simplest of queries.

 

I'm beginning to wonder if its a mssql issue?

 

Please help! :eek:

Posted

WSSecurity.exe is a file that we have been told to exec. Its a bit like simsperm.bat. However, .ICT gave us it. It was written by one of the tech's there. We are supposed to use it instead of simsperm.bat.

 

The server is a...

HP Proliant ML370

4GB RAM

2x 3.20Ghz Xeon Cores ( Total of 2 CPU's )

3x SCSI 15k 73GB Drives RAID5

 

It's getting on now, almost 5 years old.

 

The speed at which queries are running is very slow. The client's sims goes all white asthough its waiting for a response from the server.

 

Looking at the server, theres 2 instances of sqlservr.exe. 1 @ 50-60% and the other at 0% but will also raise upto 50-60% at times. When this happens its all maxed out. The MEM usage of one sqlservr.exe is 1,500,500k and the other 212,000k.

 

I find it really frustrating that .ICT can't help us any more other then defraggin the database!!!1

 

Please help. I noticed a few other posts about it on here back in 2006 with sqlservr.exe being so high but end up with "capita will fix this in the next update".

Posted

What are the sizes of the sims.mdf and ldf. There is a specific tool for defragging the sql data base that can help with slow issues. I would also have a look at the event logs as these can fill up with messages that are not errors.

 

What version of SQL are you running

Posted

sims.mdf 2,655,000KB

sims.ldf 8,384KB

 

.ICT ran a defrag query that re-indexed it. Is this the same tool you're referring to?

 

I've just checked and cleaned the event log's anyway. Nothing much that appears to be anything.

Posted

D: is the drive on the server which has S:Sims Folder shared which is then mapped as the S:drive.

 

Access to the D:drive on the server is as follows:

Everyone: special permissions on this drive only read and execute no inheritance.

 

on mapped S:drive (Sims shared folder)

1. MIS manager with full control no inheritance

2. Authenticated users list folders read and execute no inheritance

 

We also have software permissions for users deployed through GPOs:

%UserProfile%\Local Settings\Temp\*.temp

Allows Sims to use self registration for DLLs during installation.

 

Hope this has been of help :)

  • 1 year later...
Posted (edited)
Does anyone actually know "best practice" set of permissions for the SIMS folder on the server? I've been looking for weeks and no one seems to know!!

 

i don't think capita do, so the rest of us arn't going to have a chance!

 

ours have full read/write access to the folders, but not full control so cannot take ownership etc

 

EDIT:they also have to have read write access to the sims folder on the C:\program files (capita say that you should set them up as local admins) they also need to have access to the sims.ini files in C:\windows plus the temp directory

Edited by glennda
Posted
Does anyone actually know "best practice" set of permissions for the SIMS folder on the server? I've been looking for weeks and no one seems to know!!

 

I think BOSSMAN's post is a working example of very nice strict permissions. The only time you need extra is for certain modules e.g. NovaT or Options, mainly the legacy suite.

 

i don't think capita do, so the rest of us arn't going to have a chance!

 

ours have full read/write access to the folders, but not full control so cannot take ownership etc

 

EDIT:they also have to have read write access to the sims folder on the C:\program files (capita say that you should set them up as local admins) they also need to have access to the sims.ini files in C:\windows plus the temp directory

 

i remember getting mixed messages when .ICT supported us, but Capita own them now so it should be consistent.

Posted

i remember getting mixed messages when .ICT supported us, but Capita own them now so it should be consistent.

 

we are supported by our lea, and the two/three main people that knew what they where talking about left and now they seem to be pretty hopeless, i have just signed up to the capita support site as all they do is search it on there and email it to us! its quicker to cut out the middle man!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...