Jump to content

Jollity

Members
  • Posts

    290
  • Joined

  • Last visited

Reputation

264 Excellent

About Jollity

  1. Seeing the same here. We are on Lightspeed MDM. This MDM vendor indicates it is a bug Apple know about and will fix in a future update.
  2. Yes I agree the issue we saw is not something Smoothwall could correct. It seems to be an iOS or maybe an MDM issue. So far we have only seen it happen after the IOS 15 update itself and resyncs would fix it.
  3. We have also seen an issue with the Smoothwall certificate on update to iOS15. The iPad stops behaving as if the certificate was in place - so websites appear as untrusted. Looking in settings we can still see the certificate there but it appears to have no name. On re-syncing the device through Lightspeed MDM, sometimes several times, we eventually get the the certificate replaced and working again.
  4. I looked into this a few years ago, and did not find any school MISes that would handle nursery sessions properly. The proper solution I thought was to get a dedicated nursery package and then link it to the MIS. We were looking at Connect Childcare I think. However this all ended up too expensive and time consuming and we ended up using a spreadsheet with macros. I have not researched this recently so better solutions may have emerged. Most recently I have set up to do this with a homemade system again with powershell scripts to go from bookings on parent portal, to register spreadsheet on onedrive, then imported back to the MIS for billing. The exact requirements seemed too unique to fit any pre-made system.
  5. I see I did not search enough for previous discussions. Sounds like on Smoothwall it is fixed but we have to recreate our CA, which will be a rather a pain to distribute to all the BYOD users. http://www.edugeek.net/forums/smoothwall-direct-support/208719-create-https-inspection-certificate-validity-825-days.html Also on this issue: http://www.edugeek.net/forums/netbooks-pda-phones/208249-ipados-13-firewall-issues.html
  6. I think I have found a source of headaches for those applying HTTPS inspection to iPhones. I have not done as much testing on this as I would like, but thought I should get it out there because it seems to check out and I have not found anyone else talking about it. One of my colleagues updated his iPhone to iOS 13 yesterday when this new update was released and now receives certificate invalid errors on HTTPS pages tested (in Safari) when using our BYOD wi-fi network, which is HTTPS inspected by Smoothwall. We checked the "Enable full trust for root certificates" settings we have had to start setting since iOS 10.3. It appears that iOS 13 introduced new requirements for HTTPS certificates to be treated as valid: Requirements for trusted certificates in iOS 13 and macOS 10.15. In particular the one that seems to be catching out Smoothwall is: "all TLS server certificates issued after July 1, 2019 (as indicated in the NotBefore field of the certificate) must follow these guidelines: [...] TLS server certificates must have a validity period of 825 days or fewer (as expressed in the NotBefore and NotAfter fields of the certificate)." This would not affect our Smoothwall root certificate for HTTPS inspection (as that claims to be issued ages ago), but all the certificates issued for individual sites are issued recently and have a validity periods of 831 days. I am not sure if this will affect iPad OS, arriving next week, but if it does it would definitely be a reason we would not be pushing that out to pupil iPads yet.
  7. Thank you everyone for your views. They confirm my impression that screen monitoring staff routinely is not normal. It certainly is documented in our policies that we do this and we do flag it to staff, but I totally agree on there being a significant risk of seeing irrelevant personal information when screen viewing. I had a preliminary discussion with SMT today and I think the policy will be changed to web logging only, possibly with routine check by designated SMT member of the report showing sites and searches made by staff that have been blocked.
  8. We currently have the AB Tutor client on staff only PCs as well as those used by the pupils, monitored infrequently by an SMT member. This is done as check against them accessing inappropriate content, but I think this is probably unnecessarily intrusive and we ought to be achieving the purpose by monitoring the web filter logs for alerts rather than screen monitoring. I was wondering what was common practice around monitoring staff. Do you have the like of Impero, NetSupport, etc on staff PCs as well as pupil? If so, do you have it setup to prevent screen viewing without the staff member's knowledge? How about keystroke monitoring type systems like Securus or NetSupport DNA?
  9. We got the same letter. I did eventually get clarification from them that they understood the legal obligation to share the data was under Section 10 of the Children’s Act 2004 There seems to be a general duty of cooperation. Interested to hear what other people think, but I think they may have a valid legal basis for requesting the data as a legal duty. However, in Kent at least they really ought to be asking us to share it in a more sensible way. The best I have got from them is that we can encrypt the spreadsheet and send the password to a different email address.
  10. This is a good idea but would not work in our case. The temporary route is completely different from the final one - it involves branching off a separate building, which is fed by its own fibre. We have discussed just setting up a permanent route that way, but it would involve an excessive amount of digging.
  11. It is a good point, but we would I think be okay on that because we have the SFP from the cable's current location that is being displaced by the building work. I think they will be compatible - need to check that though.
  12. All very useful input. Pre-terminated fibre is not something I had given much thought to, so thank you for that suggestion. I will put some consideration into how the costs of pre-terminated fibre and wifi link compare in the case.
  13. Have you had experience with these? If so, any issues compared to cables?
  14. The schools has rudely decided to build a new building over one of my cable runs, that goes from the core switch to an IT suite of 25 and classrooms with about 60 ipads. Once the building is built there will be a new fibre cable run underneath, but for about a year I need to be able to keep that part of the network connected with a temporary link - about 70m. There is no easy route to bury a temporary cable, but one could be strung along the side of some buildings and along a wire without getting in the way or crossing anywhere people are likely to hit it. Options I can think of: Wireless backhaul - Ubiquiti airfibre perhaps aerial copper cable with lightning surge protectors at both ends aerial fibre cable I am leaning towards just stringing up a copper cable, but I know that copper between buildings is frowned at for electrical reasons. Anyone had a similar problem?
  15. Thank you, Kevin. Good to know it works for someone. It looks as if we will be delaying one-to-one devices for the moment, so the question is now less urgent for us.
×
×
  • Create New...