Jump to content

Jollity

Members
  • Posts

    290
  • Joined

  • Last visited

Everything posted by Jollity

  1. Seeing the same here. We are on Lightspeed MDM. This MDM vendor indicates it is a bug Apple know about and will fix in a future update.
  2. Yes I agree the issue we saw is not something Smoothwall could correct. It seems to be an iOS or maybe an MDM issue. So far we have only seen it happen after the IOS 15 update itself and resyncs would fix it.
  3. We have also seen an issue with the Smoothwall certificate on update to iOS15. The iPad stops behaving as if the certificate was in place - so websites appear as untrusted. Looking in settings we can still see the certificate there but it appears to have no name. On re-syncing the device through Lightspeed MDM, sometimes several times, we eventually get the the certificate replaced and working again.
  4. I looked into this a few years ago, and did not find any school MISes that would handle nursery sessions properly. The proper solution I thought was to get a dedicated nursery package and then link it to the MIS. We were looking at Connect Childcare I think. However this all ended up too expensive and time consuming and we ended up using a spreadsheet with macros. I have not researched this recently so better solutions may have emerged. Most recently I have set up to do this with a homemade system again with powershell scripts to go from bookings on parent portal, to register spreadsheet on onedrive, then imported back to the MIS for billing. The exact requirements seemed too unique to fit any pre-made system.
  5. I see I did not search enough for previous discussions. Sounds like on Smoothwall it is fixed but we have to recreate our CA, which will be a rather a pain to distribute to all the BYOD users. http://www.edugeek.net/forums/smoothwall-direct-support/208719-create-https-inspection-certificate-validity-825-days.html Also on this issue: http://www.edugeek.net/forums/netbooks-pda-phones/208249-ipados-13-firewall-issues.html
  6. I think I have found a source of headaches for those applying HTTPS inspection to iPhones. I have not done as much testing on this as I would like, but thought I should get it out there because it seems to check out and I have not found anyone else talking about it. One of my colleagues updated his iPhone to iOS 13 yesterday when this new update was released and now receives certificate invalid errors on HTTPS pages tested (in Safari) when using our BYOD wi-fi network, which is HTTPS inspected by Smoothwall. We checked the "Enable full trust for root certificates" settings we have had to start setting since iOS 10.3. It appears that iOS 13 introduced new requirements for HTTPS certificates to be treated as valid: Requirements for trusted certificates in iOS 13 and macOS 10.15. In particular the one that seems to be catching out Smoothwall is: "all TLS server certificates issued after July 1, 2019 (as indicated in the NotBefore field of the certificate) must follow these guidelines: [...] TLS server certificates must have a validity period of 825 days or fewer (as expressed in the NotBefore and NotAfter fields of the certificate)." This would not affect our Smoothwall root certificate for HTTPS inspection (as that claims to be issued ages ago), but all the certificates issued for individual sites are issued recently and have a validity periods of 831 days. I am not sure if this will affect iPad OS, arriving next week, but if it does it would definitely be a reason we would not be pushing that out to pupil iPads yet.
  7. Thank you everyone for your views. They confirm my impression that screen monitoring staff routinely is not normal. It certainly is documented in our policies that we do this and we do flag it to staff, but I totally agree on there being a significant risk of seeing irrelevant personal information when screen viewing. I had a preliminary discussion with SMT today and I think the policy will be changed to web logging only, possibly with routine check by designated SMT member of the report showing sites and searches made by staff that have been blocked.
  8. We currently have the AB Tutor client on staff only PCs as well as those used by the pupils, monitored infrequently by an SMT member. This is done as check against them accessing inappropriate content, but I think this is probably unnecessarily intrusive and we ought to be achieving the purpose by monitoring the web filter logs for alerts rather than screen monitoring. I was wondering what was common practice around monitoring staff. Do you have the like of Impero, NetSupport, etc on staff PCs as well as pupil? If so, do you have it setup to prevent screen viewing without the staff member's knowledge? How about keystroke monitoring type systems like Securus or NetSupport DNA?
  9. We got the same letter. I did eventually get clarification from them that they understood the legal obligation to share the data was under Section 10 of the Children’s Act 2004 There seems to be a general duty of cooperation. Interested to hear what other people think, but I think they may have a valid legal basis for requesting the data as a legal duty. However, in Kent at least they really ought to be asking us to share it in a more sensible way. The best I have got from them is that we can encrypt the spreadsheet and send the password to a different email address.
  10. This is a good idea but would not work in our case. The temporary route is completely different from the final one - it involves branching off a separate building, which is fed by its own fibre. We have discussed just setting up a permanent route that way, but it would involve an excessive amount of digging.
  11. It is a good point, but we would I think be okay on that because we have the SFP from the cable's current location that is being displaced by the building work. I think they will be compatible - need to check that though.
  12. All very useful input. Pre-terminated fibre is not something I had given much thought to, so thank you for that suggestion. I will put some consideration into how the costs of pre-terminated fibre and wifi link compare in the case.
  13. Have you had experience with these? If so, any issues compared to cables?
  14. The schools has rudely decided to build a new building over one of my cable runs, that goes from the core switch to an IT suite of 25 and classrooms with about 60 ipads. Once the building is built there will be a new fibre cable run underneath, but for about a year I need to be able to keep that part of the network connected with a temporary link - about 70m. There is no easy route to bury a temporary cable, but one could be strung along the side of some buildings and along a wire without getting in the way or crossing anywhere people are likely to hit it. Options I can think of: Wireless backhaul - Ubiquiti airfibre perhaps aerial copper cable with lightning surge protectors at both ends aerial fibre cable I am leaning towards just stringing up a copper cable, but I know that copper between buildings is frowned at for electrical reasons. Anyone had a similar problem?
  15. Thank you, Kevin. Good to know it works for someone. It looks as if we will be delaying one-to-one devices for the moment, so the question is now less urgent for us.
  16. Thank you all. I have misgivings but management really like the idea of providing protection off site - they see it as a selling point for one-to-one iPads. From what I have heard, most schools have not gone down this route. The "political approach" seems to be the usual one. Security is a good point, FN-GM. I am also uncomfortable about exposing a proxy externally, even with certificate protection. Maybe the internal website access could be restricted with a rule on the Smoothwall? Though it feels as if there are going to be other loopholes and something more like a VPN would be advisable if we have to do this.
  17. We are considering setting up filtering for pupils using school iPads at home. Can anyone share their experience of how well Smoothwall Global Proxy works in practice? Particularly on iPads. It feels to me as if routing all their Internet traffic via the school is going to cause some additional unreliability.
  18. Thank you for your responses everyone. Sorry I did not get back to this thread earlier today. I should have said "necessarily not comply". I meant that if it is not a legal requirement, we might still comply as we do want our children vaccinated, but it is more complicated as we have to work out that legal basis (explicit parent consent?) and the school has to make a decision about whether we should be doing this. It is helpful to know that this seems surprising to nearly everyone else. I did talk to the vaccination people yesterday, their answer was not very satisfactory, hence my post above. They said they wanted the information to be able to send out consent letters for vaccination to the pupil's addresses. They needed us to send regular updates to the information for data protection reasons, to make sure the letters did not go to the wrong place. Now I am thinking, if this is the only reason, why can't we send out the consent letters and get the parents to consent to us sharing data at the same time. That would seem much safer. They were originally suggesting just sending the data by email. When I said that was not satisfactory they said we could use the egress switch secure email system. It seems legitimate, but details like retention period are not listed in their public privacy policy, they are supposed to be in Egress' contract with the NHS. Grumbledook's idea of contacting their data protection officer sounds like a good next step. The privacy policy on the Trust's website just points me to their communications team, so I suppose I shall ring them. This makes me realise I am not sure of a legal point. Do we have a responsibility to vet the policies of data controllers to whom we transfer data, if the legal basis for that transfer is valid? We clearly have an obligation to check out all these things and get them in a written contract if we are passing the data to a data processor, but what if we are passing to a completely separate data controller (as I think would apply in this case). If the legal basis for the transfer was data subject consent then I suppose that could not be informed unless we gave the subject access to information about retention times etc. But if the legal basis is something like "compliance with a legal obligation" or "protect the vital interests of the data subject", then I am not sure what our obligations are. The controller we are transferring to has a responsibility to inform the data subject about these things, so maybe the responsibility passes to them? Or are we still deemed reckless if we have not checked these things out?
  19. I was concerned about that, but the email address is an NHS one and the phone numbers match with those given out for immunisation services on our county council website, so I think the source is genuine.
  20. We have had a letter from the NHS Child Health Information Service asking for names, dates of birth and addresses for all our pupils to track immunisations. They want termly updates with any changes - which is rather a pain in itself. Due to change in school secretary and GDPR reviews it has been passed to me to look at. Is this all perfectly normal? Anyone know if this is definitely a legal requirement? Not that I think we would not comply, but if it is that makes things straightforward from a data protection point of view.
  21. I have used Millgate for some of my APs. I had not thought of them for consultancy, it is a good thought. Has anyone had on site assistance from them on wi-fi?
  22. Yes that was one. There was also a free one available at airprintactivation.com (gone now) that I did not entirely trust, but I think some people had success with.
  23. I have been investigating the same thing. See this thread. Here is my idiosyncratic and probably inaccurate summary of the MDMs that seem to be recommended, in roughly ascending order of cost. Apple Profile Manager - cost £20 + Mac mini - Runs on an individual mac; Not very reliable, particularly over 300 devices Lightspeed - cost £5 per device per year - Okay, but not good at keeping up to date with the latest features Zuludesk - cost £5 per device per year + support contract (~£700) - up-and-coming MDM Meraki - seems to get mixed reactions - some love, some hate Airwatch - maybe a bit more business oriented rather than education? I don't really know much about it JamfPro - $16 per device per year + $750 setup - widely regarded as the most powerful
  24. My guess would be that the photocopiers do not support AirPrint themselves and that there is software running on virtual machine that is providing AirPrint access to the printers installed on there. There are various pieces of software that can do that, though I cannot remember any names off the top of my head.
  25. Our wi-fi network is a Ubiquiti Unifi setup that I have gradually built up to full site coverage over the last few years. It is a mix of N and AC APs, and has served us fairly well, but has only really been for staff BYOD and a limited number of pupil devices. We are now looking at getting into class sets of devices in a big way, and I can see a substantial increase in density may well be needed. It has been suggested to me that I get a consultant in to take a look, especially at AP placement, and I do see a value in getting a second opinion. However I suspect most consultants are going to want to sell me one of Ruckus, Meru, Aerohive, etc. I am open to being told it would be worth us getting a different system, but it would have to be a case that would persuade me and the management that it was worth the money. I need someone as unbiased as possible. Does have any thoughts on finding a consultant who is Ubiquiti friendly? Maybe I should just be going for the approach of slapping a unifi AC Pro in each classroom?
×
×
  • Create New...