Jump to content

Eric

Members
  • Posts

    71
  • Joined

  • Last visited

Everything posted by Eric

  1. Yes - I'm planning to do this tomorrow, but was hoping someone on here might know someone who knows.
  2. I'm not surprised that the DfE is one that doesn't.
  3. We're using G Suite, so can add a domain alias pretty easily, but it causes staff some confusion.
  4. We have a spiffing domain: .academy. But we have occasional problems because various organisations and websites don't recognise this as a legitimate domain when registering for services. A particular culprit is the DfE. Does anyone out there have a contact at the department who might be persuaded to fix this for (all of) us? Thanks in advance!
  5. I'm not much interested in the technicalities of the particular SSO - it's the sharing of passwords between internal systems and externally-facing websites (potentially containing the kind of information that the ICO cares about) which the ICO has, in the past, said should not happen. I'm just saying ...
  6. Err, not this one. Here is an example where the ICO only rapped a school's knuckles (hard) for permitting duplicate passwords internally and externally, but I definitely recall a £60,000 fine for something similar. Of course, the real issue was (I hope) procedures. We definitely want single-sign-on, so let's hope that the ICO is happy with it when it's backed up by something like 2FA.
  7. When we bought RM Integris they told us that api access was available; now it appears that it is "two or three releases away," at least unless you're a partner with a pre-integration. OTOH I've seen threads around here which seem to indicate that some kind of Integris api is already available. I'd love more information. Does anyone have any, please?
  8. So, we have a single physical server which we need to upgrade from 2008 to 2012. I am considering building a brand new server in a hyper-v partition and migrating over to that. This will take care of (1) years of cruft everywhere (2) setting up NPS with a brand new certificate (for wireless auth, especially) (3) changing the domain name to something which doesn't clash with an existing .com! etc. What do you think? Can this work? Would it be reasonable to keep the new h-v machine as the new server forever, or do I need to think about migrating it back onto physical hardware? Should I be able to create a new partition and install an h-v "base machine", in the new domain, which I can then use to manage the h-v server? If I've made any glaring errors it's because I would know much better how to do this using Vmware, which isn't available here.
  9. I'm looking for someone to do a site survey for Meraki in a school in Surrey. It seems not many people will do this. Please PM me if you would like more information.
  10. "Poisoned" implies deliberate intent, whereas posts lower down seem to indicate that this is something broken in your DNS provider's infrastructure. If you set your TTLs (time-to-live) to something like five minutes, this won't produce much more load on your DNS servers, but should allow you to fix any future problems within five minutes, plus however long your DNS provider takes to reload your zone. Any "poisoned" DNS servers, wherever they are, should refresh any cached RRs at least every five minutes. Personally, if you are using a free DNS service, I would suggest that you are likely to get what you pay for
  11. Are you sure? When do the clients check their lease, if they "believe" that it is very long?
  12. It seems as if Sysinternals' 'regjump' program is still available: http://live.sysinternals.com/regjump.exe
  13. I use MDT and think it's great. Be warned that it does have a learning curve, especially if you have to learn how to create silent installers for it. I happen to use open source Fog to push the images out, but I'm wondering how many you will want to do at once? There is an option, which I haven't tried, to get MDT to write everything you need to external media, which you then simply need to boot from. In the simple case you could use a USB thumb drive.
  14. Hi Shaun, That's an interesting idea. Please can you describe the insecurities when using VLANs to separate network security groups? I think I know what I'm doing here, and I'm not sure what you believe the risks are ... BTW, a long time ago it was possible to get packets to skip between VLANs, but those bugs were fixed. Andrew
  15. OK, so apps can be pushed without prompting for AppleID password. But: 1. The device has to have been logged into the App Store with that AppleID at some time. 2. The device prompts for the installation, just no password. I'm sure what people really want is "Configurator over-the-air," and this isn't it. Arguably things have to be like this though, to keep users secure from hacks which might otherwise silently install malware.
  16. Thanks, Abillybob. that's pretty much what I thought the situation was. And I've had confirmation from Meraki directly that they don't support silent apps install.
  17. Abillybob - can you expand on this, please, as silent app install is a bit of a holy grail. What exactly do you mean by "just save the iTunes password?"
  18. Grumbledook, I have stumbled upon this thread again. Do you now have case law references in this area, please? I would be very interested in them.
  19. Please can anyone recommend air con suppliers in London? We need to install in our server room; may need additional expertise because I'm interested in keeping all the muck from the school (children) out. Thanks in advance.
  20. What is your considered opinion regarding iPad security? Do you think that they are safe at all? Do you think that it is reasonable to "process" pupil and staff data on them, without additional layers of security (in the sense used by the Data Protection Act?) I am inclined to regard iPads used with a PIN or passphrase as being as secure as a laptop with encrypted disk, although sadly they are likely to be using a shorter passphrase to generate the key material. Please tell me what you think.
  21. I'm a bit slow, but I've just noticed that MLS (Micro Librarian Systems) has been bought by Capita. That'll be another piece of software to avoid in the future, then
  22. John, You say, "etched." Do I gather that you did this without recourse to Apple (who are clearly hard to persuade to do engraving on educational sales.)
  23. Sharon, Please can you enlarge on your answer? Which part of Apple will do this for you, and for how many devices? I've just spoken to Apple and they have told me that they definitely won't do this in the UK, but that some Resellers do (for a cost), though it sounds as if this might be third-party!
  24. Thanks. I'm still interested. I hate old/rubbish/lazy "educational" software ...
×
×
  • Create New...