Jump to content

Recommended Posts

Posted

Has any school requested and received a copy of the service level agreements that their emPSN-framework contracts are being delivered under yet?

 

We asked on behalf of the primary schools we support - only to be eventually told that KCOM / Capita hadn't finished writing them yet!

 

When we pointed out to the rep in question that surely this should have been something that was done before they started selling services to schools if the services were going to be measured against them, there was an amusing amount of "umming" and "ahhing".

 

Heard from another secondary in our region that they had a similar response when the question was posed by them.

  • 1 month later...
Posted
Anyone? I've attempted to get something, anything from Capita but at the minute it seems like a game of "Laaa laaa laaa - we can't hear youuuu"

 

Nothing yet. Shocking in my opinion.

  • 1 month later...
Posted (edited)

Has anybody received anything? Or even had any positive responses when asking for it?

 

When I asked Capita for more information in relation to their HTTPS filtering project recently, I threw in a request for a copy of the SLA (the conversation went something along the lines of "Did you actually consult with the school as your client before making this arbitrary decision over a change in the service? Because this was NOT mentioned when you were pitching for the business last year! BTW can I have a copy of the SLA to see how you're supposed to implement change?") and they expertly ignored all requests related to the provision of a copy of the SLA.

 

Given this defiant silence in relation to the SLA, if I were being cynical I could very well start to believe that SLAs do not exist in relation to any services procured off the emPSN framework at all!

 

Has anyone actually had a copy of their SLA from either KCOM, Virgin, Capita or RM in relation to their emPSN connection yet?

Edited by TheCrust
Posted
Has anybody received anything? Or even had any positive responses when asking for it?

 

When I asked Capita for more information in relation to their HTTPS filtering project recently, I threw in a request for a copy of the SLA (the conversation went something along the lines of "Did you actually consult with the school as your client before making this arbitrary decision over a change in the service? Because this was NOT mentioned when you were pitching for the business last year! BTW can I have a copy of the SLA to see how you're supposed to implement change?") and they expertly ignored all requests related to the provision of a copy of the SLA.

 

Given this defiant silence in relation to the SLA, if I were being cynical I could very well start to believe that SLAs do not exist in relation to any services procured off the emPSN framework at all!

 

Has anyone actually had a copy of their SLA from either KCOM, Virgin, Capita or RM in relation to their emPSN connection yet?

 

No, to put it simply. And we are having similar issues with HTTPS connections which is causing havoc with all manor of devices.

Posted
What have they done in terms of HTTPS?

 

They have "SSL Enabled us" and given us a certificate to publish to all of our computers on the Root CA. Any certificates that are received from websites, have the issuers replaced with OpenHive and a lot of services reject this because they dont trust it. Cant install the certificate to tablets, so anything secure on there is rejected, including our MDM profile. So we cant push apps anymore, or update, or use certain apps. And every secure website throws up an error in Safari.

Posted

Errr, my knowledge of SSL certificates for websites and HTTP is ropey at best but I have been dealing with it enough on IRC to know that it's quite pointless as it is - Openhive "replacing" them as *another* man in the middle, effectively doubling the risk?

Could someone explain that to me? I am making an outright assumption that I'm being daft rather than Capita doing something dangerous.

Posted
Errr, my knowledge of SSL certificates for websites and HTTP is ropey at best but I have been dealing with it enough on IRC to know that it's quite pointless as it is - Openhive "replacing" them as *another* man in the middle, effectively doubling the risk?

Could someone explain that to me? I am making an outright assumption that I'm being daft rather than Capita doing something dangerous.

 

Pretty much covers it yeh, and a lot of services will instantly reject the modified certificate. Rightly so.

 

No you're far from being daft.

Posted (edited)

@TMODAlpha So in effect they did stuff, completely without consultation with you as their customer, that has had a negative impact on portions of your network?

 

Hmm. That's not good and I know what I would be telling them in that situation. The polite version goes something like: "I say, chaps, you have breached your part of the contract by not only not supplying me a SLA to measure the performance of the service against, but then imparting changes in an arbitrary manner without consultation or consideration on how they effect me mean there has been a negative effect on the operation of some of my systems. Either you remedy this situation and start playing by the rules, or I consider the agreement between us terminated." :bolt:

 

 

When I asked them what they were up to with this HTTPS / Certificate project on behalf of our supported primary schools - one thought we had had was by acting as a "man in the middle" they could intercept stuff to which they had no legal right such as between the exam boards, or the DfE, and the school - they eventually came back with this:

 

We can assure you that we do not de-crypt or re-encrypt any part of a user request. In order to perform the filtering function, Webshield looks at the user REQUEST URL to determine the host portion of the HTTP-part of an HTTPS request. This allows Webshield to carry out an allow/deny decision on the requested host name of the server, prior to any data being fetched from the web server (the RESPONSE). The software that Capita uses allow us to use either the full URL when asking for an allow/deny decision, or just the hostname of the web site (note this is still the REQUEST not the RESPONSE).

 

Following the action taken by Webshield to either allow or deny the REQUEST, if the request is valid no further interaction takes place, the data is fetched from the web server and delivered through the Webshield proxy server directly to the web browser. As stated we do not at any stage de-crypt or re-encrypt data and neither is there caching of any data, nor any data held on the Capita operated proxy servers. When the actual requested data is fetched it simply flows through the proxy server, the transmission over the Internet is secured, as is the transmission across the emPSN. We do not log, nor cache any aspects of content from the RESPONSE.

 

Obviously if the request is not valid/denied the user will receive a deny page from Webshield.

 

This process is the same for HTTP requests and for HTTPS request and our Webshield service does not differ in this sense from the previous embc service.

 

We are required by both duty of care responsibility, and by UK law enforcement organisations to trace requests back to their source should an investigation be triggered. The Webshield system report logs enable us to trace users and timestamp the URL requests but again this does not allow us to inspect at any time detail or content. This is also a requirement of the emPSN and therefore of the service.

 

I presume based on your concerns that we were inspecting content you asked if the school can opt out of this HTTPS inspection entirely and remain on the current filtering system.

 

The answer is you can but opting out will have an operational impact on your school users. You will lose the flexibility of per-user filtering for HTTPS web sites, which typically impacts the staff in school who are more likely to access these sites. Such that, should an HTTPS web site be denied by your site-wide policy (e.g. banking), you lose the advantage of user-based filtering (UBF) i.e. role based/ profiled access to the internet. Even if you log in, no action can be taken to relax the filtering for this web site.

 

I'm still not entirely sure what to make of that response as it didn't really address the questions I had put to them - but one impression I got from it was they were giving me something in the hope I would shut up and go away.

Edited by TheCrust
Can't spell for toffee!
Posted

"Lose the flexibility of per-user filtering for HTTPS websites"

 

Capita have always had a habit of over-complicating things. We've got a defunct RM Smartcache 2 box that's been in action for many years that did exactly that without having to faff around like that?

Posted (edited)

Hold on a sec...

 

This bit...

 

The answer is you can but opting out will have an operational impact on your school users. You will lose the flexibility of per-user filtering for HTTPS web sites, which typically impacts the staff in school who are more likely to access these sites. Such that, should an HTTPS web site be denied by your site-wide policy (e.g. banking), you lose the advantage of user-based filtering (UBF) i.e. role based/ profiled access to the internet. Even if you log in, no action can be taken to relax the filtering for this web site.

 

Sounds like they're saying this...

 

If you opt out - then you'll lose all ability to be able to access sites under slightly less restrictive filtering, for example being able to log into the "inthehive" system as a teacher to be able to show a youtube video to your class. Your finance departments will also be unable to look at anything to purchase due to all sales sites being filtered with you having no way to reduce the filtering level.

 

P.S. It's our ball and if you want to play - it's by OUR rules

 

Is anybody else reading that or is it just me?

Edited by korifugi
makin' sense and takin' names.
Posted
It seems each week there's a different problem with emPSN and if I had known about all the grief we would have I would have used a different ISP when EMBC finished!
Posted (edited)

TBH this is exactly why we jumped ship as soon as we were able - there had been so many niggles and gripes with EMBC over the years that the rather secretive "you'll get information in due course (probably when its too late to go to market or do anything else)" nature of the procurement process was the final nail in the coffin for us.

 

From a purely selfish angle, neither the lack of a SLA from any emPSN provider, or Capita's HTTPS project bother me one jot because I have a connection with a commercial provider and run my own services - but I am coming at it from the perspective of the feeder schools we provide support to have to live with it and we, by association, have to deal with it on their behalf when it (inevitably!) goes wrong.

Edited by TheCrust
Posted

Interestingly enough - I have three sites using Capita's filtering and all of them are asking me and @TheCrust what is going on...

 

The Fourth - which is getting their filtering via RM are having no such problems.

 

So I have to ask - what are Capita actually playing at? There seems to be no issue with providing "what it says on the tin" with RM. Although - I haven't actually got an SLA for them either, so begs the question...

 

Has ANYone got an SLA for ANY of the services, no matter who provided by - for ANYthing under the EMPSN umbrella?

Posted

As most of you know I am not actively involved in this anymore (and soon won't even be remotely involved) and I haven't really seen anything around the HTTPS Cert until it appeared here ...

 

However, I'm struggling to see what the question is?

 

The service (it seems) is to ensure that any https traffic is passed via the webshield service, and part of this is by using an SSL cert so that if anyone tries to bypass the filter to access a HTTPS site it sticks 2 fingers up to them? The way that the service is being described (the REQUEST initiates the query on the filter about what category the site is in and does the user have rights to access sites within that category) is pretty straight forward. They don't touch the RESPONSE side (which is what MITM decrypts will do) so asking "what are they doing with it" is a bit of a red herring.

 

Honest question here ... not intended to trip anyone up, but do folk know the difference between REQUEST and RESPONSE when it comes to filters / proxies? If this isn't made clear then it can cause confusion (heck, I spent 3 months hammering down what this meant when looking at filters, etc in 1999 ... at the same time as trying to get my head around DNS and BIND ...)

Posted

To be honest Tony, the underlying issue from our perspective is Capita seemingly acting in a rather high-handed way - refusing to disclose if there is even a SLA, let alone what the terms of it might be, implementing changes (seemingly arbitrarily) without consultation with the schools as clients, and being reluctant to discuss any part of those changes with either us as the client's technical contacts or the clients themselves - that sort of thing. I know the other secondaries in our LA have issues with Capita's performance too: good examples from email contact I've had with other NMs are the handling of calls, and poor performance of the webshield service.

 

At the emPSN pre-sales briefings we (and representatives from the feeder schools we support) attended, all sorts of promises were made by both provider and LA representatives: not least that given previous niggles with EMBC, the schools themselves would be the direct clients of the providers so could talk directly to the companies involved rather than have to route stuff through the LA. Further promises were made that services and connections procured would be provided to SLA, and the individual schools would be able to access and manage the contracts under the SLA, putting them "back in the driving seat" if (when!) things started to go awry.

 

Now as far as we can tell nearly six months on, there is no SLA. Nor procedure for the management of change, mechanism for the providers to actually communicate with the clients or vice verse, or for the clients to actually monitor the performance of the providers in any meaningful way and deal with non-performance.

 

It seems like there is an impenetrable wall of silence surrounding this issue: the providers themselves seem to deflect or ignore any question on the matter, and our LA appears to go selectively deaf when this subject comes up. It's all highly frustrating when all I want to do is establish where the schools stand in the relationship with providers under the emPSN framework!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...