Jump to content

howartp

Members
  • Posts

    3,884
  • Joined

Everything posted by howartp

  1. Good morning. We use UniFi with NPS to provide Radius auth. When a user connects their iPad to the wifi, the cert they're prompted with has an expiry of 7th March 2020 (ie yesterday) and is the local self-signed certificate from the NPS server. However, in NPS > Policies > Constraints > PEAP > the certificate there is NOT the one that is expired. (It's our realworld cert that expires on 12th March and is already renewed to 2021) If I set UniFi not to use NPS, it doesn't prompt the cert error, so i'm presuming it's definitely NPS. I have changed the UniFi keystore cert pair already, but that also uses our realworld cert so wouldn't be prompting 7th March. I've restarted UniFi controller and the NPS server fully. Can anyone suggest where else I would find a certificate setting that I need to update for UniFi/NPS not to prompt an expired cert? Peter
  2. We did 2008 R2 to 2016 (via 2012) at half term. If you google your error, you'll find you need to run some adprep commands manually first. Peter
  3. No, nothing like that. I'm still asleep but trying to think why they'd need it - you're using a website to remotely access virtual machines on AWS within the browser so the firewall shouldn't come into it, should it? To say PISA use technical solutions, they don't seem to understand what they're doing with those solutions.
  4. I don’t recall any issues with AWS. It all just worked from that perspective.
  5. Nope.
  6. Ours is due next week, on Exchange 2010. My notes say: Not sure if that's same for Exchange 2016.
  7. I'll be turning off old server next week (migrated at half term) and seeing if anything's broken before I destroy it. SQL 2016 Standard I believe. No need to keep DB running on old server if you've migrated the DB to new server.
  8. We got hit by this about 6 months ago, after we'd changed our school IP address then sent out a mass parent email. Took about 2-3 weeks before traffic to Yahoo/AOL returned normal.
  9. Photocopiers with Papercut?
  10. Most of ours are 100mb with 1GB uplinks. We put Wifi across school about 8 years ago and put POE 1GB switches in key cabs at that point; APs, IP Phones and Paxton therefore get 1GB by default. This year I've budgeted to put POE 1GB in the remaining cabs, either 8, 12 or 24 ports, and swap around some of the HP 2524 switches that have SC Fibre transceivers with other switches that take LC fibre 1GB ethernet ports so I can reverse the stack in some locations.
  11. It's one of the following 6 updates: KB4507456 2019-07 Security Only Quality Update KB4474419 2019-09 Security KB4099950 2018-04 Update KB4507704 2019-07 Update KB4503269 2019-06 Security Only Quality Update KB3140245 Update My suspicion is KB4474419 as that KB number seems to be re-released periodically with new content. I've declined all 6 in our WSUS for now. Peter
  12. This is a note for closing the stable door after the horse has bolted, in case it affects anyone else. Due to a new install of WSUS by our engineers as part of domain upgrade, some windows updates which I'd previously declined were pushed out to servers and PCs alike. My finance and payroll server went down Wednesday night to finish installing the updates - but never came back up as something was corrupt. It booted to the windows system repair screen. Skipping past the several hours trying to combine the previous days backup with the live data/databases on Wednesdays HDD (and currently waiting 24 hours since I raised a "critical - no functionality" ticket with Civica), I finally managed to revert the windows updates and boot the server back up about 2.30pm, minus the windows updates. For anyone facing same issue, let it boot into the repair wizard that comes up (it'll be asking for keyboard language), and open the command prompt. Determine which drive is currently your C:\Windows drive (it won't be C:, it's been either D: or G: on mine depending how many drives you have) by typing: until you find the one with Windows on it. Then the main command you need is (substitute F: for D: or G: etc): It might fail with error 5 (I think) about closing/finishing some revert procedures and tell you to retry in a few minutes. If you do retry, it will give you a different error. However, restarting the server at this stage will successfully enter into "Stage 1 of 3" reverting/rolling back upgrades, and eventually boot you back into Windows. Hope this helps other users, now or in the future - I believe some users had issues with the August 2019 updates if March 2019 updates hadn't been installed prior. Peter
  13. Morning all. Our careers team want to use http://www.wexonline.co.uk but it only works in IE with VBscript enabled. Any thoughts?? Peter
  14. I don't understand either of these posts. The migration tool worked fine for us on 900 PCs, with no users needing to be logged on so the issue of staff having admin rights is a moot point. If it needs internet access, then add auth bypass rules on your firewall/filter for sophos destinations, so that no auth is needed.
  15. Definitely They can also (by CSV) add additionals to a group, eg the pastoral team assigned to that year group are added to all year 9 class groups.
  16. I'm intentionally replying to an old thread here as it's the first and only search result on google for this issue. The answer is actually in a KB article on Capita support, but to save anyone coming to it in future looking for the answer: On the new server with the new "SOLUS Deployment Service", close the SOLUS UI then go to c:\ProgramData\Microsoft\Crypto\RSA Right-click the MachineKeys folder, go to properties then security. You'll find nobody has any permissions to the folder. Edit Administrators and give them Full Control. Now re-register your site in SOLUS UI.
  17. Server 2016 DC upgrades Plus whatever other servers I can get done/migrated.
  18. Have you got DNS or your Smoothwall/firewall adding the modification to force all traffic to restricted? Otherwise non-logged in users will get everything. Once the modification is on, forcing everything to restricted, that's when GSuite can get involved and govern who gets what.
  19. We use it all the time. Year 7-11 have restricted permissions, sixth form have moderate permissions and staff have unrestricted. If you're not logged in, I don't think you get anything - certainly not a lot. Peter
  20. Biometric in the canteen is stored in an SQL type database on a server or kitchen PC (which could be stolen or remotely hacked into) so that multiple biometric endpoints (tills and revals) can use it; touchID is in a secure proprietary chip within the individual iPad and even if the iPad is stolen or hacked, it's not just an SQL database with a network password protecting it.
  21. Hi GrumbleDook The thing is, we don’t require anyone to use TouchID, and it is actively skipped in the Apple setup wizard. Staff and students are choosing to go into settings and enable it, we don’t require it to secure devices and deliver curriculum etc etc etc. Similarly a SAR or Right to Erasure would be impossible as we don’t have any access to that biometric data - it’s not a bio fingerprint/datapoint stored on our servers for the purpose of cross-platform authentication etc. Is this not different? Peter
  22. Hello. Our DPO is Veritau and our onsite rep (Assistant Head) had an audit with them this week to see what we're doing right and wrong. My colleague confidently stated that we don't use biometrics anywhere in school - until the Veritau person asked "...any iPads...?" Staff iPads all have Touch ID fully enabled, student iPads have it enabled for iTunes but not for screen unlock. Has anyone crossed the bridge of GDPR vs Touch ID before, or equivalents on Android etc? Did you obtain opt-in permission to use and store their biometric data for the purposes of unlocking iPads? (I'm kinda playing devils advocate here, because I believe the bio data is stored in the locked security chip on the device? And the use of touch ID is entirely down to the staff/student concerned to voluntarily register their fingerprint on the device itself - but I need some sort of an answer to give to the assistant head so looking for other folks views?) Peter
  23. That's what I thought! How to make the headline look good - base the comparison on very quick 100mb ethernet, not 1gb ethernet!
  24. I can't see from that code why you need "7Zip for Powershell" module installed, as it's calling 7Zip directly from the command line. At a guess, are you on a 64bit server with 7Zip 32bit installed, in which case path would be "Program Files (x86)"?
×
×
  • Create New...