-
Posts
2,502 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jamesb
-
For what sort of music? For free stuff I usually go with Jamendo. Otherwise I usually rely on the Nokia music store, since that's integrated nicely with my phone/media player.
-
Two websites can't share the same IP address and port. It causes fun stuff to happen. However they can have different IP addresses and the same port, or different ports and the same IP address. Just trying to clarify as I think poor witch is getting a bit boggled. So adding another IP address will let you put the moodle site on that (new) address, and on port 80. You'll then need to get any requests for the moodle site going to that IP address by getting a DNS record set up to point at it. That's probably the simplest way to do it, and it avoids having to move to IIS where you'd still need to add another IP address.
-
To RM or not to RM, that is the question...
jamesb replied to Little-Miss's topic in Network and Classroom Management
Yes, it does. GPOs applied on a CC3 system could cause all sorts of fun and games. Deploying software through GPOs often just wouldn't work, simple as that. Changing the AD structure into a sensible, logical one could break CC3. All sorts of little niggles and touches which basically mean the only way to safely manage the network was to use the tools provided - which don't provide the full functionality you'd get using purely AD. And of course, renaming a computer is always fun. Have they sorted that in CC4? Its not a mine is bigger and better than yours attitude. Any network management software is designed to do one thing, make managing the network easier. If it weren't designed for that then it wouldn't be much use. The drawback is that as part of making it easier to manage you do lose some of the more advanced features and customisations which are available. Its like the difference between driving an automatic and a manual. Each have their fans, and their place, but you'll never find a performance-obsessed racer who loves customising their car driving an automatic. Of course, you'll be much less likely to find a little automatic town car wrapped around a tree as well, which I think just strengthens the analogy. I'm not trying to be insulting or unprofessional at all about CC3, and I do believe that it does have its place, but suggesting that it (or any managed network) is as advanced and powerful as a properly configured network without a 3rd party management layer just isn't something I'm happy to do. -
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
Merge the domains, it'll be easier. -
I believe that the important fact is your employer only owns anything you create in the course of your employment (unless your contract states otherwise) so if you create something not related to your job role, then they've no claim. This isn't a legal opinion at all, just my own interpretation.
-
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
Is there any option in the LDAP setup to query the GC? I'm basing this on Sharepoint access, but its only just occurred to me that Sharepoint may do something clever in terms of checking domains. The only thing I can think of which I did have to do was to give the service account running Sharepoint permission to read the second domain. I take it you've got a service account running the websites? -
Take a clue-stick along to the meeting and people'll listen. Alternatively point out what a publicity crisis it'd be if one of the kids decided to kick up a fuss about their music being given away free, without them having agreed to it. The school's taking on the role of publisher here it seems - so they're liable.
-
To RM or not to RM, that is the question...
jamesb replied to Little-Miss's topic in Network and Classroom Management
To a degree, yes, in that a vanilla network is something which can be customised to any school, college, university or business as needed with the same skillset. So when/if you move on, someone else can come in and find a vanilla network, and should be able to maintain in. There's a much broader base of people who can support a vanilla setup than there are for any of the proprietary management systems, whichever you choose. Personally I'd say the big difference comes down to maintenance hours. If you've got full-time tech staff who can support a vanilla network, vanilla'd be better as a rule. If you've got part-time tech staff, or if you've got multi-role staff (IT Teacher/Network Manager combined for example) then the time saving might be worthwhile. Maybe a better way to describe it would be responsibility. If you've got technical staff who can take full responsibility for the network, then vanilla's most likely your best option. If you want someone else taking responsibility, go with managed. -
The Intellectual Property office has something to clarify this a little So the way I see it, downloading a digitally copyrighted file is done using a device which can make multiple copies (computer), and is therefore a reprographic method. This means that the educational license exceptions wouldn't apply. The rules seem quite clear on what is allowed, and most textbooks specifically state that they can be copied in part for educational purposes, suggesting that it isn't a default permission.
-
Teachers and support staff are employees of the school, therefore under contract. Students are not under contract so to be safe I'd want to get a signed agreement from them relinquishing rights in favour of the school. The same in the case of exams, the student is not employed and the piece should be their own original work. In that case, the following applies:
-
What software restriction policies are in place at the user level? Is there anything on that system's AD object which prevents it from reading the policy?
-
Good point. If they've composed and written it, its theirs. Has the school got permission from them for its sale?
-
A normal domain account with permission assigned to log on to the DC by adding them to the Allow logon locally permission under Default Domain Controllers Policy should work fine. I assume that's why you were going to use an admin account? I'd be surprised if any of the Operators groups could do anything outside of their own function, that's the idea behind them. Print Operators can manage print queues, Server Operators can do basic maintenance tasks, Backup Operators can manage backups, and so on. Internet access isn't part of any of those roles.
-
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
Thinking about it, there's no need to modify LDAP to look at two domains. Why are the users not simply using their full domain\username, or username@domain to log on? With DNS set up, and the permissions configured, that should sort it. -
To RM or not to RM, that is the question...
jamesb replied to Little-Miss's topic in Network and Classroom Management
That isn't a problem with vanilla networks per se, but the setup. There are vanilla networks which are highly secure, very nicely set up, incredibly easy to manage (since they've been designed properly and the AD structure has been planned and designed to suit purpose, along with the GPOs), and user-friendliness is a matter of opinion. Personally I find the restrictions that CC3 used to place on me as a network manager to be crippling. It does take work to get a vanilla network set up properly, and a lot of technical knowledge, but once that work's been done and everything's in place it'll beat any one-size-fits-all solution. -
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
True, but the computers will be sending a request to their own DC for authentication - if that DC doesn't have permissions for those users to authenticate in its domain then it won't forward the authentication request. -
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
Right, we're getting somewhere then. Create a domain local group and go to add members to it, you should find that you're able to add members from the foreign domain. Failing that, on the foreign domain create a universal security group and you should be able to surface that in the curriculum domain. -
Legally Recording/Distributing Cover Songs seems to go into some detail about selling cover versions, it might help.
-
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
If the users from the admin domain are visible in the curriculum domain, and can authenticate there, then it should be automatic from that point on. The sites will go to the curriculum DC to authenticate credentials, the curriculum DC will recognise that its not credentials for accounts in its own domain and fire the requests off to the trusted admin DC, that'll come back saying that the users do exist and are valid, and that should be it. I think so anyway. -
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
I should point out that I don't use Windows 2k, so can't be completely sure that this would be the right route. Basically though you should be able to create a group with membership assigned to all of the users from the admin domain, then allow it Network Authentication permission, but deny Interactive Logon to all machines. This'll allow them to authenticate, but not actually log on to any computers. The permission you need is under Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assignment | Deny log on locally. Add the group you've created to hold the users and apply it at the appropriate point for any machines in the network where you want them unable to log on. You can lock down various other permissions as well. Active Directory Users, Computers, and Groups - goes into a bit more detail on interactive logon and network authentication. -
Replicate usernames and password only between Win2k domains
jamesb replied to siuko's topic in Wireless Networks
Trusts. Understanding domain trusts These seem to be coming up a lot lately. It'll allow the users to be authenticated in the trusted domain (assuming you set up a one-way trust) and you can just remove their right to log on interactively to any computers in that domain via GPO, or simply not provide them any permissions other than to authenticate. -
Ten copies of all client OSes since DOS 6, one copy of each server OS. So it'll let you play with Windows 3.11 as well.
-
Free and legal music downloads - Jamendo is another one which provides free music, and a nice variety of it as well.
-
Used to have a subscription which I paid for myself and was definitely worth it, now on an MSDN license paid for by the company and equally worthwhile.
-
Just discovered that the bank guard one is also on Snopes, but verified as true - snopes.com: On Guard
