ashleyturner86
Members-
Posts
16 -
Joined
-
Last visited
Reputation
0 NeutralAbout ashleyturner86

-
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Hi Nick, As per the details I previously mentioned, anyone that's already a member of the administrators group already has local logon rights - therefore, my "systemadmin" user already has this level of access, but yet still suffers from this issue. I.e. adding in "all users" (or those who I want to be able to use HAP) to have local logon rights, will surely make no difference to this fundamental issue affecting systemadmin? -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
It is indeed an RM school. A single CC4.3 server setup (i.e. Server 2008 R2) - HAP is therefore installed on the CC4 FRDC. The UPN is "SchoolName.internal". -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Hi Nick, Please see below. The AD username and domain fields were both in clear text as expected, but the password was a string of gobbledygook - I presume this is also expected, and is actually somehow encrypted?? \\MFS-SR-01\RMStaff \\MFS-SR-01\RMShared Documents \\MFS-SR-01\%username%$ \\MFS-SR-01\%username%$ -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Nick, Contents of web.config below. I've not made any changes to it other than those described to lock down the setup.aspx page, and removing the entry for .svg as per another post. -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
I've not yet enabled local logon rights for everyone, but as previously mentioned, that is enabled for "administrators", so shouldn't be affected the use for my "systemadmin" user. You browse to the URL, and the login page successfully loads. I enter the systemadmin credentials, press "login", and it then loads a plain white page, with the error "You do not have permission to view this directory or page." If I then press the "back" button in the browser, I can see a HAP screen (title bar is there, along with the side menu bar, and the "logout" link), but the minute I try and do anything (such as click on the "my files" icon), exactly the same page as above is displayed with the same error. -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
It unfortunately hasn't done for me. I've even totally trashed everything and started again (the AppPool in IIS, the website itself, the extracted contents from the ZIP installer etc.), but still had exactly the same issue. I am however using HAP v8 (latest available from the site), and all the instructions are aimed at v7. Can't see that anything is drastically different though -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Hi Nick, Okay thanks - didn't realise that was the case, and don't remember seeing anything about that in the instructions. However, the policy being applied to the server hosting HAP already has "administrators" listed as allowed to log on locally, but yet when I login with a systemadmin user, it still gives the error. I.e. I guess the "allow log on locally" setting could be relevant later to get staff and students working, but I can't see that it's relevant for my systemadmin user, which is suffering from the same issue. -
HAP on CC4 server, and SSL certificates
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Hi folks, I managed to generate a CSR using certmgr.msc, and specify the required SANs. However, upon submitting to my SSL provider (JANET - they provide free SSL certificates via Comodo for educational establishments), they've rejected it because of the internal SANs as I feared they would. Have others definitely done this, and obtained an SSL certificate for the external FQDN of the website, as well as having SANs for internal server names etc.? I don't have huge experience with SSL certificates, so I'm not sure if it's an issue with the provider I'm using, or if others would have the same stance. Thanks again, -
HAP installed, but errors when anyone logs on
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Hi Nick, I've checked the other web.config files, but can't see anything that strikes me as problematic. When you say to check that users have "local logon rights" on the server, what exactly do you mean? Users can't current logon to the actual server hosting HAP (which I don't think is unreasonable?). -
Hi All, I'm hoping someone out there may be able to help me with this. I've installed HAP as per the documentation and video guides, and gone through the initial configuration (with the setup.aspx page). You can successfully browse to the external FQDN of the HAP server, and see the login box, but get errors when logging in. Whether I try as a domain administrator, pupil or staff user, once you've entered your credentials, you get prompted with a "The Website declined to show this webpage" page. You can then click on the "Go back to the previous page" link, which takes you into the HAP website (can see the menu bar on the left etc.), but there's a warning saying "You have attempted to access a restricted resource". If you attempt to use the icons on the menu bar to go anywhere (user's files, booking system etc.), you then get the same "website declined" error. I've not changed the configuration of the web.config file at all, other than as prompted to, to restrict access to the setup.aspx website, and to cure the known issue by removing the entry for .svg files. The same thing happens from IE8, 9 & Chrome. Any thoughts?
-
HAP on CC4 server, and SSL certificates
ashleyturner86 replied to ashleyturner86's topic in Home Access Plus+
Thanks for the pointer. So to do it "properly", I need to create a CSR for a multiname SSL certificate, which includes the external FQDN (hap.domainname.co.uk), and the internal server name (SVR-001)? That being the case, 2 questions: 1. How do you create a multiname CSR (the IIS7 GUI doesn't appear to give the option - only lets you specify one CN using the wizard)? 2. Will a public CA provide an SSL certificate which also includes details of an internal server which they can't "verify"? I've read around a bit, and found the following document, which suggests they will, but only for a finite period of time - it seems the general stance on this is changing, and all public CAs won't be able to do this in the future: https://cabforum.org/Baseline_Requirements_V1.pdf -
Hi, I'm after some advice about setting up HAP on a CC4 first server, and specifically the SSL certificates. With a standard CC4 FS, the "RM" website already exists, and is bound to TCP 443 - it's used for internal RM stuff (learning resources etc.), and makes use of a self issued SSL certificate. By adding the HAP content to "D:\RMNetwork\RMManage\Web Components\HAP\", the HAP website can then also use TCP 443. But, unless I'm missing something, that presents a problem with certificates - as you can only have 1 certificate bound to the "RM" website, you must either choose to: -Replace the existing one with the "proper" SSL one obtained from an online trusted CA (which secures "hap.domainname.co.uk" or similar for HAP access, but then will break learning resources), -Keep the existing self signed one (which keeps learning resources etc. working, but means the HAP website isn't secured). Have I missed something obvious, or is the above true, and if so, what do others do? Thanks in advanced for any assistance
-
Hi all, Many thanks for the suggestions, but i've now solved my own problem !! In case it's of any use to others, what I was trying to achieve was connectivity between a SIMS.net client, and the SQL DB, across a WAN with firewalls and routers in the way - therefore needing to lock down the port usage so the bear minimum of "holes" needed opening to allow comms. Use the SQL Management studio (or SQLTools for Express) to bind the SQL instance to a given port - e.g. 5555. The SQL instance is then listening on this port. By default, clients connect on UPD 1434 to the SQL Service Browser, which then directs them to the instance they've requested, and they then connect (on the port previously specified - e.g. 5555). However, you can use the client's connect.ini to lock it to a port (contrary to my previous thoughts!). If you specify "ServerName={ServerName}\{InstanceName},{port#}", the client will initiate communication directly with the SQL instance, negating the need for communications to the SQL Server Browser on UPD 1434. Along with the 1 port you then specify for the DMS, you then only need 2 ports for SIMS communications. Many thanks again for the help and suggestions.
-
I believe the SQLTools.exe is only for SQLExpress, and i'm running Full SQL (also running SQL2008 not 2005, not that that should make any difference)... I've already used the SQL Management Studio to change TCP ports - under the "protocols for {InstanceName}". However, this is surely only changing the port SQL is "broadcasting" on from the server. The end client SIMS installation must be told somewhere how to connect to this. The connect.ini supplies the server and instance name, but not the port number. So I believe it simply uses a default of UDP1434 to make its initial connection, then changes to the specified port once it's "up-and-running"). If possibly, I want to change that default initial usage of UDP1434, and I guess tell the SIMS installation that the SQL instance is available on my given port#, so it uses this port# right from the start
-
Yep - the TCP Dynamic Port field is blanked, and the static port is set for the "IPAll" field (and the service was restarted). Regardless of whatever the settings are on the SQL Server, when the SIMS.net client on the end machine is first loaded, it has no connection to the SQL database. It must therefore attempt to establish a connection when you login, on some port (currently UDP1434), so how can this be changed ?? I.e. it's a change\setting\specification at the client end that's needed. Almost something you'd add to the connect.ini after the instance name (e.g. "ServerName={IPAddress}\{InstanceName},{port#}"), but alas i've tried that, and it doesn't work.
