Jump to content

Recommended Posts

Posted

4.2.8- SSO. It's called Active Directory Directory Services Authentication. Or Open Directory if you use Macs. But what do they *mean* by "external resources"? And how are they proposing this SSO?

 

Paul, really interesting post!

 

On the bit I've quoted, they are talking about a scheme called Shibboleth (or AAA depending on where you look). It seems to be a more open version of what Microsoft tried (and failed) to do with MS Passport.

 

Google wasn't very helpful as Becta move their documents every week to improve our searching skills, so here's some reasonable starting point links:

 

http://schools.becta.org.uk/index.php?section=lp&catcode=_le_pp_po_03&rid=11277

http://industry.becta.org.uk/display.cfm?resID=14598

 

As to how it works, it's quite hard to find docs on that, but they have conducted research so I'm sure it'll be fine.

Posted

4.2.8- SSO. It's called Active Directory Directory Services Authentication. Or Open Directory if you use Macs. But what do they *mean* by "external resources"? And how are they proposing this SSO?

 

Paul, really interesting post!

 

On the bit I've quoted, they are talking about a scheme called Shibboleth (or AAA depending on where you look). It seems to be a more open version of what Microsoft tried (and failed) to do with MS Passport.

 

Google wasn't very helpful as Becta move their documents every week to improve our searching skills, so here's some reasonable starting point links:

 

http://schools.becta.org.uk/index.php?section=lp&catcode=_le_pp_po_03&rid=11277

http://industry.becta.org.uk/display.cfm?resID=14598

 

As to how it works, it's quite hard to find docs on that, but they have conducted research so I'm sure it'll be fine.

 

AAA is is becta's name for the project shibboleth is technology...

 

http://shibboleth.internet2.edu/

 

Russ

Posted
As to how it works, it's quite hard to find docs on that, but they have conducted research so I'm sure it'll be fine.

 

Basically, Shibboleth is due to replace Athens in Universities by 2007.

The history of this is that Athens has been running for years (early 90's) as a centralised authentication source for Universities services (eg web of science, library services etc) that all universities can access. It currently requires Uni's to set up students accounts with on Athens. The replacement is Shibboleth. The advantage of Shibboleth is that a centralised authentication source is not required as it can use the universities local authentication server (MS-AD, OpenLDAP, SUN iplanet, Novell e-directory,whatever). Shibboleth can then hook into web services etc and users are authenticated against their local auth server. For example Apache has a Shibboleth plugin - so If I wrote an educational resource site I could use the plugin to authenticate people from different sources without setting up accounts.

 

Becta's plan is to extend this idea to schools

Posted

Could someone tell me what is meant by 4.1.3:

 

Caching and Content Delievery second bullet point:

 

Caches shall not be in-line with the instituation's broadband connection?

 

We currently have a content-cache server which redirects people to the proxy server and then outside would this be counted as in-line?

 

Wes

Posted

That would make sense. Having looked through most of the spec it looks like I may have to price up replacing most if not all the switches in this school. (Which I was going to do, but now it's gonna cost a whole lot more!).

 

 

Wes

Posted

Trying to get some work done ...

 

Right ... a little explaination is in order for this one with some background from other documentation.

 

From what I can see Becta's view on Caching and Content Pre-positioning means that the ideal structure is ....

 

The institute has a local cache. This is to be use for frequently requested files and media rich files. This can be pulled on request of pre-positioned (ie downloaded before needed).

 

The net stage is your ISPs cache ... which should be accessed for infrequently requested files.

 

At least one of these caches should have some level of authentication, preferably pass-through (ie no login ... it pulls the details from the machine you are on or via some other ticket) or it should authenticate via SSO (the same username and password for everything ... ok, that is a very tight summary but that's all that you need to know of SSO for this bit)

 

The pre-positioning is quite often a selling feature of a number of caching and filtering appliances / servers. For media rich content it can be a boon, for other content your own cache and the upstream cache (ie the ISPs) usually suffice. Your pre-positioning may also be tied in with a Learning Platform though ... something to be aware of.

 

The 'in-line' section I believe it refers to the idea that your cache should not by a pass through box ... ie 2 NICs and all traffic goes through it to access your broadband line (or be the target point of your connection at your ISP)

 

Not only can this be bad for performance, it is not fault tolerant in most cases (yeah ... there are a number of exceptions... but we are talking about a regular school budget here)

 

I have asked for clarification on the above point and a direct link to the Caching and Content Pre-positioning paper (it is mentioned in a number of other documents ... but I can't find a link to it via Becta's search or Google).

Posted

Firstly - is it worth opening a new Forum specifically for BECTA issues, much like the KS3 ICT Pilot? Possible sub headings could be Hardware, Software, Policies..............

 

Secondly - I don't see anywhere that suggests a list of BECTA approved educational software. ie. - can be used on a network (whatever the OS), is easy to install and if necessary use existing authentication such as AD in MS and could be made available via a Web UI to enable full access from home.

 

It's OK saying that institutions shall do this or should do that, how about saying that teachers shall ensure that the software they buy using eLC meets a minimum criteria?

Posted
It's OK saying that institutions shall do this or should do that, how about saying that teachers shall ensure that the software they buy using eLC meets a minimum criteria?

 

they do:

 

Design criteria

• Pedagogical and administrative applications shall support open standards that allow the

import and export of data in a range of commonly used formats that are independent of a

particular platform.

• All educational applications shall provide an interface that is designed or can be tailored to

suit the age and ability of the learners.

• Documents and data which are intended potentially to have a long lifetime should not be

solely saved to proprietary file formats.

• Where only proprietary standards are available, strategies should be provided for migrating

to open formats if and when they become available.

• Applications used in institutions should be designed for network installation.

Posted
I shall require £1m and 3 years to implement all the daft and unreasonable demands from this document.

 

But none of us will because the government’s plan, supported by Mr Owen Lynch Chief Executive of Becta, is to farm all these services out to contractors, as they believe that the job will be done better this way. Owen Lynch made these points in the Educational Guardian back in 2003. Companies like Capita will win these contracts as they have this government in their pocket; one of their Directors was even caught up in the cash for peerages allegations.

Posted

I have had confirmation that the 'in-line' reference does refer to the use of a cache for pass through ... and that this is a big no-no.

 

The Caching and Content Pre-positioning document has been archived pending review (and likely to be superceded by forthcoming documents)

 

As for the software ...

Becta rarely approve things ... and if they do it is after a long and arduous process to ensure they have given people all the information and all the options.

What they tend to do now is put together a set of criteria as to what applications shall be able to do, should be able to do, etc ... it is up to the individual institute to decide whether the software is educationally valid.

 

I've been asked to remind people that the both documents should be taken together ... the technical specification is not a shopping list of things that have to be bought right now ... it is part of a 5 year plan that institutes and support providers should move to.

Posted

Is it worth doing if as petectid says we'll all be out in the cold in about 5 years anyway? Of course if the first few LEAs have nothing but problems this may change? If the school decides it doesn't want to outsource 1). Where do they stand? and 2). What happens if they don't does the BSF just say no you can't have a new school built or does it curtail your ICT part of the BSF fund?

 

Wes

Posted
It's OK saying that institutions shall do this or should do that, how about saying that teachers shall ensure that the software they buy using eLC meets a minimum criteria?

 

they do:

 

Design criteria

• Pedagogical and administrative applications shall support open standards that allow the

import and export of data in a range of commonly used formats that are independent of a

particular platform.

• All educational applications shall provide an interface that is designed or can be tailored to

suit the age and ability of the learners.

• Documents and data which are intended potentially to have a long lifetime should not be

solely saved to proprietary file formats.

• Where only proprietary standards are available, strategies should be provided for migrating

to open formats if and when they become available.

• Applications used in institutions should be designed for network installation.

 

I'd settle for: "all educational applications shall have a close button in the top right and not make you watch 2 minutes of scrolling credits before they actually exit." What is it with the people who make educational software :?

 

I think:

All educational applications shall provide an interface that is designed or can be tailored to suit the age and ability of the learners
is definitely a long, long way off at the moment.

 

It would be nice if there was some sort of gov't accreditation scheme similar to curriculumonline, but based on a published set of criteria or a scoring system. Unfortunately, I suspect the cost of implementing it would mean software publishers would have to pay for the privilege, putting smaller publishers at a disadvantage. It would also be nice if developers had to specify in detail the Key Stage points that their software covered.

  • 2 weeks later...
Posted

I'm about to collate the remarks from the thread together to feedback to Becta. I'll summarise in this thread first in case anyone wants to add anything I may have missed or not explained enough.

 

A final call for comments then.

Posted

Ok, I'm reading through the technical specification atm. I'll make some comments as I go through it.

 

Network:

 

Managed switches. I would love all managed switches, however I am trying to expand, convert and upgrade the network all at the same time. Making managed switches a mandatory will not magically make it happen without time and money. My network has to run all year round and due to conversion to fibre and expansion current work can only be completed during holidays which means to wire the entire building and have managed switches will be at least another 3-5 years.

 

Each time I replace a switch I have to get fibre put in, the cabinet replaced and all the current connections certified or replaced and certified. Much of the network has had little investment in the years before I started, and even by myself at times due to time and cost.

 

802.3ab? Thats Cat 6 isn't it? Making this a *requirement* is daft, I don't bother with more than cat 5e certification, cat 6 is somewhat stricter and therefore takes more time and effort with little benefit over cat 5e for most uses also it has more physical difficulties for use.

 

I still have a building full of Cat 5, It will take tens of thousands to replace. Much actually passes cat 5e certification and can remain in place until the network has been expanded. Oh and most of my fibre is 62nm but you aren't going to get 10GB out of much other hardware for a long time yet, I'm keeping a low contention ratio instead.

 

Have the people who wrote this document ever priced 10GB? It will get cheaper yes, but throwing vast bandwidth at any problems wont solve them.

 

I'm also not happy with the shall for 100mb for all devices, that misses out older print servers that are often 10Mb but are more than adequate. I'm not going out of my way to get 1Gb NICs for client either, PXE and WOL is all I'm really interested in.

 

IP: My RBC will NOT give me a real external IP, all my data has to be port forwarded and I have no real control over our connection. I have also been told not to expect QoS ever.

 

I can't say I'm very happy with having a RBC or the LA pokeing thier noses in when all I want is a real internet connection.

 

Wired network upgrade paths: Replace Cat 5e with 6! What a complete waste of money. I don't think that sould really be in the advanced upgrade path, its really not going to get you anywhere at this point in time.

 

 

Class of Service/Qos/Vlans. Due to the previously mentioned issues it will be a while before this can be implemented. For the general network we must not forget that to use some of these advanced features the *client* os and nic drivers must also support them. I am quite happy for Becta to write some new drivers for my Marvell NICs to implement VLAN support. If not then I can only use port based rather than tagged.

 

Remote Access: I'm not happy with most remote access solutions from a security and data protection standpoint. I'm really not sure if I want my admin staffs data availiable to anyone with the right password. This complicates matters with extra features like client certificates and tokens.

 

VPNs. I'm not a fan of VPNs and my isp makes my life difficult, although I did finally get the ports opened for pptp, ipsec and l2tp.

 

Sychronisation: This is a major pain in the ass. I loath all laptops because they are not always connected and this makes like difficult from a network managment view point. I also have virtually no wireless in the building due to its physical properties. I dislike offline folders and I'm certinly not going to use that godwaful excuse of the offline sims.net. Teachers also like to fill there laptops with viruses and spyware, but I haven't had time to implement the procedures and policy for staff laptops for network use, so currently they aren't allowed to use them on the network. Although as there is no wireless and the wired network is not complete its not like there is anywhere to plug them in!

 

Standards for applications: Ahahahaha. Sims.net still requires Microsoft Office last time I used it. Afaik PDF are also a closed format? Stored documents not save in propriatry format, thats complete nonsense and totally unworkable in my opinion. There is no way I'm going to tell the users to save in more than one format.

 

Oh and most applications *aren't* designed for network installation in my experience, I have shouted at a great many pieces of dire educational software for example.

 

Whats an open format for databases? Would you not need the database as an sql dump for that?

 

Browsers used in institutions shall allow the installation and use of third party plug-ins. By who exactly? Not the user I hope!

Institutions shall use a content filtering system that should be managed by LAs/RBCs in discussion with institutions. We use RM's its rubbish.

 

The audio and video spec is also a bit odd. Why go on about open standards for all the office type applications and then choose mostly closed, licensed formats for audio and video (mp3 and mpg for example)? Same issue with animation.

 

I'm getting the feeling that the application specifications are simply derrived from the fact that open office exists rather that the idea that they should be open formats. Another example is the vector formats, nice idea but many vector apps don't use these formats as they are rather outdated and poorly implemented. Xara for example doesn't use svg or vml.

 

Communications: As bits of the network are still 100Mb hub and the RBC wont give me QoS this is rather pointless.

 

No email filtering is available from the RBC afaik. Except the fact they delete all messages with exe and zips and I CAN'T have this disabled despite various arguments with them on the pointlessnes of apparently virus scanning email if you infact delete the attachements anyway.

 

Instant messaging? I think not!

 

WiKis? This document is starting to feel like the open source appreciation society, and a touch preachy and patronising. Same goes for RSS.

 

 

MIS: Ah the bain of my life, the fact that the sims.net upgrade and bromcom upgrade somehow moved them to being my responsibility even though they weren't before. It doesn't matter what you do or say on this front, its all up to Capita really isn't it?

 

E-portfolios: Could someone please explain what these are? Its all sounding a bit managment speak from here.

 

Why must I consult my RBC/LA before I want to do anything? They NEVER ask me!

 

 

I'll go through some more tomorrow. These are honest comments and have just been thrown onto the page, but I really do feel that all becta does is spout managment gibberish to make the govenment feel it has some idea what is going on with IT in schools. It doesn't. There is no point producing long winded and detailed documentation like this if no one ever sees it or there is no money or time to implement it.

 

David

Posted

Thoughts continued.....

 

Implementation of ICT security etc: I did look at getting hold of a copy of BS 7799 but it appears that you need to pay someone lots of money for one :p

 

Seems I'd better write a security policy then! And some procedures, but there is a template to help in the appendix, good.

 

Physical security is difficult in a school due to the way rooms are used, it tends to be more damage to equipment that is the main issue, although laptops have a habbit of dissapearing - mostly because they are left all over the building :roll:

 

Sensitive data is sometimes left unattended or unsecured, but not by me. Teachers are given more restricitve accounts becasue they love to leave themselves logged in and wander off. I have the admin machines lock when the screensaver comes on, there is little more I could do except not let anyone use anything or stand behind them when they work!

 

Resource Management: Shalls for recording license KEYS for every device? They're having a laugh? Tens of keys and hundreds of computers and version numbers too? I'm quite happy to keep an eye on total usage and make sure its within the license agreement but thats going rather too far. Software patches and security patches on *INDIVIDUAL* machines? They can *shall* this all they want, I'm not doing it.

 

Redundancy. Fair enough, but this is much more difficult for servers and network equipment. Transparently and immediatly transfered to the failover hardware? and in what mystical world is this supposed to happen. If I can't afford to run the machines and servers I do own I can hardly start to run clustered servers can I? I have a san box, if it dies everything dies. I have a blade center attached to it, if this dies everything dies. I can't have a live redundant copy of the san, it would cost at least 30k, perhaps another 40k for the servers! They are full of as much redundancy as possible, ups, psu, lan, hba, san storage processor are all redundant and hot failover but sometimes hardware or software faults will take down an entire system. If it dies, people will simply have to wait until it is fixed.

 

User IDs. I don't see how you can protect your users ids, passwords yes, user ids no. The only way would be to use a random system for producing user Ids. I'm sure most of us here use a set of rules to produce IDs so they are therefore easily guessed.

 

Should use use lowercase and capitals? Have these people ever worked with children? Its bad enough waiting for the pause when you ask them their name let alone their user number, how on earth will they cope with complex passwords. They do however have to change them every 30 days.

 

My passwords are secured in my office, I use them often. Keeping them locked away in a sealed envelope is a slightly rose tinted view of how to keep them. I will be moving them to a password safe application in the near future. I must be nearing 100 seperate passwords for various devices and applications by now!

 

Backup: Daily media should be stored in a fireproof safe? Um, no its going to stay in the tape library with all the other tapes. All weekly tapes are exported/imported every week and are held off site. If the school burns down then there is more to worry about than 4 days worth of data. I wonder how we are supposed to allow the students to do everything they might need to do for thier work, particularily audio and viedo work if there is no where to store this data or back it up to removable media in a sensible amount of time and for example tapes.

 

My users get 100MB for years 9-11 and 200MB for 12-13. This is increased if the user has a real need for more, but not usually beyond 500MB. Staff aren't limited (yet!). If I want more than this then its not going to fit on a single lto2 tape, which starts to make life complicated for backups and restores. The users have a seperate 1GB on the Mac server as it has an lto3 drive.

 

If I were to increase these limits that much then I will need additional disk enclosures for my san box and a larger enterprise backup system. I'm not overly fond of disk backups, 400GB still being the same size as an lto3 tape uncompressed. I would guess that about 20% of the 400k files are actually academic work.

 

Spyware: Shall have access to spyware protection? Are there any really good commercial spyware products? When we move to Symantec 10.1 in the summer it should have some spyware protection. I am far more worried about rootkits than spyware, although they are often used together.

 

Firewalls: I have firewalls on the clients (window controlled by gpo) but not as yet on the servers, I will run the server lockdown utility when I have the time to implement and test it once server migration has been completed. Same goes for ipsec.

 

Edge firewalls would be more of an issue if I had *real* internet access, but I do pass most data through a debian vm running shorewall.

 

Auditing. When was the last time you were able to sit down and sift through 500 thousand audit entries? I'm not even logging all those details, its just left on whatever 2003 logs by default.

 

Wired security. Erm, putting cables in wall cavaties? Have these people seen schools? Mine is built of concrete, blockwork, steel and asbestos. I have no wall cavities! Its surface mount, false ceiling or nothing!

 

Edge: Should be 1GB between edge and the core? I do have GB but this seems a little pointless until I get GB for my internet connection!

 

Redundancy? I can't. Its not my router for a start, it belongs to bt. I have only one line - a LES 10Mb. There are more outages caused by the LA and Segfl than me. I have had 3-4 loss of service events this year already. And email getting stuck on their mail server for over a month.

 

Edge Tech: Again, pointless to specify these things as many of us have no control over what protocols our edge equiptment and services provide. As I said the router is not mine and I have no access to it. No point supporting QoS when segfl said no chance of getting it anyway.

 

Video conferencing? No chance, I've been through this with the LA, no QoS, no point.

 

Network Core. Lots of shalls here, most are expensive and time consuming to set up. I'll have one of those nice HP procurve 9000 series thanks! Even the 5400s are classed as edge switches by hp.

 

Too many silly Shalls in enabling the core too. As I mentioned earlier I don't have QoS availiable end to end from the client to the server so there is little point in using QoS/CoS yet.

 

SANs: I use fibre, but not FCIP afaik. iSCSI doesn't work with Vmware ESX for example.

 

 

Technoloigies for the user device: Specifying battery life on laptops? Isn't this all getting a bit to contol freeky? Why is everything specified to such exacting requirements. The fact that a lithium ion battery only lasts a couple of years wether you use it or not seems to have been forgotten.

 

 

 

 

 

 

So there we have it, a long technical specification. The problem is it has great detail in some areas, and is a bit vague in others. It refers to a great many other standards too. My issue is this: This document does not help me in any way. I know what needs to be done and how, but this does not facilitate these things in any way. What will it do for most schools out there? Nothing I'm afraid. Its all a bit of a rose tinted view of how these things work. Becta should come and visit a few schools round here to see that as they are using computers that are seven years old, then this document has nothing applicable to them. Time, money and skills are the issue, not functional specifications.

 

I'm sure I could implement most of these standards and ideas, but only if the users would go away for a couple of years. Trying to manage all these things and deal with anything up to 50 interuptions a day is difficult. I suppose I'm quite lucky to understand most of the things in the document, but I would consider that I am rather underpaid for my current level of knowledge, as I'm sure many of us are. Can you really see any of this happening with our current budgets and staffing?

 

David

Posted

Backup: Daily media should be stored in a fireproof safe? Um, no its going to stay in the tape library with all the other tapes. All weekly tapes are exported/imported every week and are held off site. If the school burns down then there is more to worry about than 4 days worth of data. I wonder how we are supposed to allow the students to do everything they might need to do for thier work, particularily audio and viedo work if there is no where to store this data or back it up to removable media in a sensible amount of time and for example tapes.

 

ii am going to disagree here as you have got duty in law to keep data safe and also look at admin system losing 4 days worth of data is a major deal.

 

Russell

Posted

The requirement is cat5e as a minimum, not cat6 !

 

Design criteria

• The network shall be cabled with fibre optic cable or Cat5e or Cat6 copper cabling.

 

also its worth mentioning that by utilising (relatively cheap) managed switches it possible to segregate the network using VLANs this will improve security,reliability and save costs on wiring. IMO managed switches are worth the extra - but maybe not in a tiny primary school with a handful of computers.

 

Stored documents not save in propriatry format, thats complete nonsense and totally unworkable in my opinion

 

Better that than have students save to propriety formats that they cannot open at home or in other schools without buying hundreds of pounds worth of software. This is basically to prevent schools from being locked in to certain file formats. THere are already a few schools in this country that already run on open standards software - it is entirely possible. Students who have not payed for eg MS access cannot work on database documents at home. I don't think its acceptable for state schools to require students to pay for these products to work at home when there are freely available open alternatives (and potentially they would need to pay for a new operating system, I know a few kids that upgraded their pc's to linux).

Posted
The requirement is cat5e as a minimum, not cat6 !

 

Design criteria

• The network shall be cabled with fibre optic cable or Cat5e or Cat6 copper cabling.

 

also its worth mentioning that by utilising (relatively cheap) managed switches it possible to segregate the network using VLANs this will improve security,reliability and save costs on wiring. IMO managed switches are worth the extra - but maybe not in a tiny primary school with a handful of computers.

 

Stored documents not save in propriatry format, thats complete nonsense and totally unworkable in my opinion

 

Better that than have students save to propriety formats that they cannot open at home or in other schools without buying hundreds of pounds worth of software. This is basically to prevent schools from being locked in to certain file formats. THere are already a few schools in this country that already run on open standards software - it is entirely possible. Students who have not payed for eg MS access cannot work on database documents at home. I don't think its acceptable for state schools to require students to pay for these products to work at home when there are freely available open alternatives (and potentially they would need to pay for a new operating system, I know a few kids that upgraded their pc's to linux).

 

 

Institutions shall install 802.3ab or 802.3z Ethernet in their backbone, between their servers and key network hardware.

 

Also I'm not sure I would say that managed gigabit switches are cheap (they want 1GB to clients), thats not so say thats not what I have been fitting, but they aren't cheap.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...