Jump to content

Recommended Posts

Posted

Hello . I need your advice again.

 

The head has asked me for the password to get access to the server and all the computers.

 

There is no way I'm going to give the root password away, as a lot of you know I spent hours and hours ( may be days) of my own time setting up this new domain for free in the school holidays and I'm not letting them damage it .

 

Views please.

 

Problem the new copier/printer is hired and I cannot get access into the settings ( hire firm password protected it) so they are coming in to set it up and I have been ask for the server password.

 

1..So if I just set up a account / password for them to do this..Is this the way to get around this problem ?.

 

2.. what permissions do I need to give for them to do this.

 

3..How to do it.

 

Note. its a private run school. no l.e.a. etc.

Posted

firstly, you need your own login. You shouldn't be using administrator. No one should.

 

If someone wants admin, they need a good reason. Provided they do have a good reason, duplicate their login account and alter the username so it's obvious it's an admin account. I generally append '.admin' to the username and use some humorous wallpaper.

 

Secondly, the printer people don't need access to your server. Just ask them to setup the printer end of things and then ask them to tell you the IP to use and to hand over the printer driver to use. You can do the rest yourself.

Posted

I agree with Geoff. Doesn't make any sense from a security or technical standpoint to have people all over the place who are "administrators". The schools' network would become a mess all too quickly.

 

Good luck!

Posted

How do you run your printers? Just Win2k+ que's?

If so just give them a static ip. YOU can install drivers and link the too.

What do they actually need to setup on your network?

We have hired stuff too but they would NEVER get admin.

Posted

absolutely agree with all the above advice.

 

To alleviate the heads fears maybe a sealed envelope only to be opened in a dire emergency with the admin password written inside.

 

Regarding the copier yes they can set the ip etc... on it then give you these details to do the server side of things. Or give them an admin login that you then change when they are finished or just log on for them and stay there. Or change the password to something and tell them then change it when they have finished.

 

Unless the head can give you good reason why they would need to access the server and machines with the domain admin password then don't give it to them.

 

Ben

Posted

The head of the school should have access to any of the passwords.

 

You have to think from his/her position - what would happen if you fell under a bus/moved or had to be sacked :) (tricky if working for free but hope you see my point).

 

I personally would write them down inside a sealed envelope and point out the potential problems if they were to get into the wrong hands.

 

Then leave the head to do what they want.

 

 

regards

 

Simon

Posted

No I dont think they should, they are basically teachers.

If you work on your own its not a problem. There would be huge disruption anyway if you were in hospital or were out of action and they had the passwords. Remember its not hard to get the password for a admin account if you have physical access to the server. They can get retreive it when they are in a position (aka a replacement for you) to properly manage the network or at least have someone trained to handle it in the interm. At least you would have left it in a running state. God knows what would happen to it after that if they had admin for a couple of weeks and were *guessing* how to do things.

Posted
Well that's the thing with per user admin logins. You can work out who broke it. That means they get all the hassle when stuff they broke doesn't work and they get to fix it. If they can't I come in out of hours and charge overtime and fix it. Their admin account gets disabled too.
Posted

Documentation of the network would be better (I think). If a Systems Administrator documents the network, its settings, and password- and stores this safely- then there is no need for this "nuclear bunker" type thing where you rip open the envelope and make sure the keys match and then type in synchronicity on the count of three...

 

I use a Network DNA type of system where telephone numbers of contacts, account details, contractors, policies, passwords etc are printerd out and stored in a folder in the server room marked "Network Documentation". It would be easy to find.

 

Having said all that, it isn't a *bad* idea so long as the Head doesn't open the secret envelope just for the hack of it!

 

;-)

Posted

As mentioned above, you should leave a copy of the password in a sealed envelope IN THE SCHOOL'S SAFE. Nobody should be accessing the system who doesn't now what they are doing as it WILL go tits up.

 

You cannot keep the login details from the head if he asks for them - it's their network not yours!

 

I also agree that noody who is 'untrusted' should be allowed any sort of priviledged access to the system. The copier people will spin some sort of line about not being able to set up the machine and test it but if you set up an IP port on the server with a static address and give that address to the copier guys they CAN set up their half and test it from a machine (since you've done your bit already). You will also find that most companies require you to fill in a fax-back form before the engineer arrives asking for an IP and other details.

Posted

Seal your passwords in an envelope, sign across the back in a water base marker (if they steam it it can be seen and then place in a laminating pouch, melt it until it is sealed and then sign that too.

 

Then you will *really* know if people have needed your passwords

Posted

It's a difficult one, and something i've experienced much pain with! :)

 

I'd imagine you are in a better position Mike working without pay as you do. Surely the school have no legal hold over you. You are (like) a consultant who is working on the system as a specialist.

 

The whole point, as everyone is saying, is that you get the school to realise the danger inherrant in letting those password/s fall into the wrong hands.

 

The horrible consequences are that there will be an unknown introduced into the equasion with every fix ~ What did that person do that may be screwing things now?

 

At worst make them another admin on a client PC - once they've got into the settings and set that up, you should be good to go with whatever you need to do. I would expect them to leave you with the drivers and hopefully a manual.

Posted

Does anyone know where you can get those snap open plastic wallets ala wargames for me to put my password in?

 

I should have a said about putting the password in an envelope "put a password in a sealed envelope" thats not to say it's the current one :) with good password practice you would update this envelope every month or whatever.

 

Ben

Posted

@plexer: I made an additional admin account with a ridiculously complex username and password :twisted:

They only need A password.

Posted
@plexer: I made an additional admin account with a ridiculously complex username and password :twisted:

They only need A password.

 

Me too. It hit the fan a couple of months ago when I was off - resulting in me being accused of not keeping the password in the safe. Turned out they wanted the local PC admin passwords and couldn't figure out how to get them with the domain one, which they'd found as I found the envelopes all torn open in the safe.

 

I didn't push it.

Posted

Hello . Your all great, and Good advice. :D

 

Well There is no way they are going to get any root or administrators password or sealed 'bomb' proof envelopes, ( you say keep it in the school safe ? what safe ? you mean the money box that's left lying around in the office ! .).

 

 

Another thing about this school some parents come in to help and this reminded me some time ago when one of them wanted to go on the internet (dial up in them days) so she clicked on the dialup icon then she decided that she had to put in the user name and password (which she did no know) she asks the head and the only one she had was for our email account , she put this and of cause it would not work .

So I get frantic phone calls that the internet was not working.. all she had to do was click ok in the first place because it was pre set by me.

 

So you could imagine what some of them could do to this domain if they had a password to get in.( the heads husband builds/takes apart computers ! ? ! * mainly old 486's win 95 ) :!:

 

Another thing I provided and built the sever up and have provided some of the hardware for the network which you could say is on loan.

 

what I have done about the printer is put a note on it asking for a static IP address of xxxxx etc. and asked for the Mac address.

And if he wants to test it he can use his laptop plugged into the printer , and I will set it up in my own time.

If the school chairperson/parent who this ordered this digital copier/printer and took its delivery then arranged for it to be moved again some time next week also ask them to set it up and never even thought to ask my advice first well they will have to wait till I'm ready to put it on the network .

 

 

 

 

 

Thanks. From Michael.

Posted

I think you need to step back and look at this situation from the outside.

 

Its really great that you are helping someone out for free but having an employee or contractor or helper or anyone dictating policy (when not specifically asked to do so) to an organisation will most probably lead to a catastrophic breakdown in relations and end up with marbles being taken home. :(

 

Give them the passwords and explain your concerns if they are misused and leave them to it.

 

Clarify which pieces of equipment the schools owns and which pieces of equipment you are loaning to them and whether you will be taking them home once marbles are involved :p

 

 

regards

 

Simon

Posted

Hi. and thanks for comments,

 

What I will do is to have a word with the head and talk about the problems with the staff and any 'helpful' parent messing about with this system and pointing out the damage they could do.Then take it from there.

 

 

 

From Michael.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...