Teth
Members-
Posts
190 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Teth
-
This year is a BIG image change for us so I will be adding SP3 to it if for no other reason it will save 250 machines hammering the WSUS server for 103 updates each when I start rebuilding IT suites in the summer. We got an adobe CS3 site license this year and given its a pig that takes more than 40mins to install by GPO I'm going to put it in the base image along with some new java based introductory programming softwre called greenfoot which doesn't like to be run from a network share. Our current base image is more than 2 years old so I'll be creating new GPOs etc for it too for a good oldfashioned fresh start.
-
You can take the take the right click out too with a regedit In the HKey_currentuser of your mandatory profile for students. I found it quite quickly with google at the beginning of this year when I had to fix that for our network.
-
Just found this today while I was doing some forum browsing since its exam week for the students. Worked superbly I'm really pleased. Very fast and first class presentation. I voted on your new feature list for detection of files that have been renamed as I'd love to be able to permanently get rid of all the mousebreaker games no matter what they have been renamed.
-
Now that seems to be what we're looking for I'll look into how it would integrate with our school website when I get the time.
-
Intresting I'll look into that one. We are intending online payment to be a prime goal of this to reduce the amount of wasted admin time from kids that get given envelopes of cash or cheques to bring in which then don't get handed in to the right people or get lost .etc An e-commerce solution would cut out the child in alot of cases and would hopefully radically improve record keeping.
-
In school we run a lot of extra curricular trips and activities which are funded in part or in whole by parental contributions. Currently this is an entirely cash and paper based system and in a school with over 1,200 pupils it is becoming unweildy. We are conwsidering adding an e-commerce element to the system which would allow parents to pay for specific trips and contributions using credit and debit cards on the school website. Obviously the sums of money involved are potentially large and the security and peace of mind of parents is essential or the system will not bring the benefits and cost savings we desire. Is anyone already doing something like this or considered it? any info or suggestions you have would be very useful when the idea is taken to the school board.
-
We buy pretty much exclusively from Dell now too. I always shop around HP and Fujitsu but our account manager at dell will always beat them and usuually by a considerable margine. They seem to reward loyalty and of course volume purchases. To give you an idea this time last year we bought 57 desktops 2 computer suites. All ultra lowprofile small cases vista capable ie they have a dedicated video card. Spec as follows. Core 2 Duo E6400 2.13ghz 2GB DDR2 80GB HD Radeon 1300 128MB DVI video cards. optical mice + the nice dell keyboards. DVD-RW (they are media studies suites) Windows XPhome license 17" 1280x1024 screens from dell's pro range not the value ones. The 3 Year Warrantly was thrown in and their service through that has been fantastic with the 1 blown Monitor, 2 faulty laptops and a bad DVD drive we've had out of the close to 200 machines we've now bought from them. They were all swapped next day no questions. This was our 3rd major order from dell and our account manager got the price down to a touch over £400 a machine and they were delivered the following week. Like any of the big suppliers Dell, RM, Fujitsu, HP get in touch with their public sector sales department your Locla authority may already have a rep assigned so might be worth checking. They want to sell machines in volume and they will relish the opertunity to win a school as a cleitn becasue they know we will have a 3-7 year renwal cycle and thats the kinda business that keep them going.
-
You control panel is different entirely to MMC. Some of the items in control panel will start an MMC put its not an MMC in itself so there are 2 seperate sections of GP to configure to properly lock it up. An account with access to control panel fully restricted could still access disk management, services, computer management etc directly if they knew how to start an MMC and add the apropriate snapin unles you lock the snapins individually or the MMC as a whole.
-
In combination with locking out all MMCs with group policy you should be covered tho. A software restriction policy to restrict executables to only running from locations you aprove is a must I think too. Only our 6th form computing students are an exception to the policy that prevents running anythign executable including Java, swf, bat, com, vbs, etc.. from removable drives and home drives. They have a slightly different policy that allows them to run executables from a folder in their home space that only 6th form pupils can create and use. Its neccesary for pascal with delphi and VB2005 Projects. They don't tend to abuse it because there are only 23 of them in the school so tracking down an offender wouldn't take long. They are still banned from running installers of course. We put so much effort into restricting what they can do lol. On my list for tomorrow is preventing the intel graphics options from being accessable by a student and resetting a room full of screen back to 1280x1024 instead of 800x600 which they worked out how to do on our new suite today.
-
Check your group policies. There is a setting in user policies under I think admin templates > Windows Components probably called Microsoft manage console or something similar that allows you to set what MMC snapins are available to anyone with that policy applied. Mine are set so that Teachers can access only the Active directory User and computers so they can reset passwords. Pupils are restricted from starting ANY MMC snapin. They have no need to. That should cure your current problem but I would also advice carefully checking your permissions on AD OUs themselves. Even if a pupil could start an AD users and ciomputers MMC on my network they stil could not access any settings etc because they don't have permission to browse them. The teacher group has slightly higher permission to allow them to change passwords but in general only Techs and NMs should have AD access. In a default 2k3 installed domain I think only domain and enterprise admin groups have access to AD so you may have inheritted some unwise changes to AD security.
-
I'd also be really intrested to see this guide as I preferre to do installs by GPO. I have CS3 Web Premium running here but I gave up on the GPO and added it to the RIS image for the machines and redeployed the 2 rooms that need it. Not a solution I like but there was a time factor. I'd like to sort out a GPO installer still asa longterm solution.
-
Ok bad start to the morning today came in to find the print server / secondary DC couldn't be contacted on the network except by IP. Logged in locally to find the DNS service had died due to "insuficient no paged memory" restart of the server sorted it but obviosuly there is a long term fix needed here not my current top priority tho. After getting that restarted and numerous people that had only managed partial logins etc logging out and back in again all seemed fine until I started getting reports of "suspicious looking icons on peoples desktops with blue shortcut arrow icons on them". After seeing one I knew imediatly it was offline files. Now my quandry. These offline files icons are showing for only a few users but for those users its all their files on their desktops or my documents. Their my documents and dekstops are mapped to their home directory which is on a different server not the one that crashed this morning. That server has offline files turned off explicitly on every share I have checked so I'm really confused. How can offline files be active on a share that has it explicitly turned off. And how can I turn it off properly again. The reason I'm nto happy to just leave this is that all user accounts are wiped by the logoff script. If for some reason somone had done some work and it had not been updated on the server version of the files when they logoff that updated or new document would be lost when the profile is deleted. I can find loads of guides and info on the net for enabling offline files but nothing related to turning it off when it is already suposedly off. This only applies to less than a dozen users who suceeded in logging in while the secondary DC was down this morning. The secondary DC is not the file server that the home directory shares is on.
-
Another guniea pig reporting in. I'd already done a fair bit of trial and error learning myself with 7.1 server but in the intrests of consistency when I follow your guide for dansguardian I went through you 6.01 + webmin guides today and all seems totally fine. You have a little bit of repition in it static IP near the end of the server one and open-ssh repeated in both but it doesn't hurt to rerfesh the ssh part I think. Clear and concise guide thank you. I look forward to following the dansguardian one. Will you be doing dans guardian with AD integration or with ident for user based logging and filtering? I've been experiementing with AD integration with varying results myself. In cluding a hilarious mess up I related earlier were I had the linux box authenticating its own local user logins via AD
-
How goes your work on the guide. I recently started work on this as a side project myself. I had it all set up and working with the version 2.8 of dans guardian from the repositories but upon trying to enable authentication I discovered that requires version 2.9 which needs installed from source and its all gona a bit pete tong from there I think I have everything configged right but the startup script seems to have an error. A step by step guide would be handy. On the bright side I've learnt loads about Linux the last couple of days doin this and enjoyed it.
-
Bright side this is a VM trial run before I do this on actual hardware. So thats the first thing for the "mistakes not to make on the proper version" list I'm sure there will be plenty more. I'm currently trying to work out the right config for compiling 2.9.9.1 for ubuntu. Its all good fun of course. Sure beats desktop support.
-
ok this is an oops on my part defiently when I changed config for kerberos or samba or ntlm which I did recently one of the guides I followed must have beena little more than I actually wanted, because after creating an account in AD on a hunch named "root" I can now log in as root on the linux server using the password I gave it in AD but not the password I knwo is set on UNIX. I guess this isn't a disaster but I wasn't expecting all authentication to go through AD just the proxy.
-
Ok I've been working on a squid + dansguardian + ntlm auth filtering Proxy as a sidep project this week so far gotten about 3 hours total at it but going well. all was goin great I have squid in and authing against AD with winbind functioning beautifuly. Dansguard wasn't using the usernames tho but I cfould out thats cos ubuntu only has 2.8 in the repository not 2.9 so I need to do a source install. I restarted the machine after adding all the packages neccessary to compile and... I can't log in even tho I'm 100% sure the password is right. I logged in as another user that had sudo rights and did sudo passwd root and changed it and... still can't log in. Can anyone think of anything I might have done during the config of samba /kerberos that might rpevent a root login cos thats the only thing I can think of I've changed recently that is authentication related but I'm not experienced enough with Linux to know what I'm looking for.
-
Out of intrest and hopefully without derailing the thread too much. For adapter teaming on your servers what do people use. Load balancing by Windows TCP/IP 802.3 LAG Protocol (which obviosuly requires support on switches) Or HP / CISCO Proprietry solutions? I've had some problems in the past getting our Broadcom cards to negotiate LAG correctly. One of them abjectly refuses until checksum offload is disabled. I've always meant to do some throughput testing on the different solutions but never found the time.
-
Is there only a single pair of Fibres terminated in the large cabinet? I would have thought that very unusual as a fibre "cable" tends to have a minumum of 3 pairs and if your pulling the cable you might as well terminate them all. I would use more of these fibre pairs to get more bandwidth and redundancy from your Core switch out to that cabinet. Fibre GBICs are cheap these days.
-
Thanks all its all terribly pricey. Not sure if the moeny can be found but priceing seems to be pretty similar across the board. We'd need a Premium suite to get photoshop and dreamweaver in.
-
Ok I'm having some trouble. The school has used Studio MX for a long time for GCSE and A-level ICT. Howver this year alot of the new resources wont open becasue they want Studio MX 2004 or greater version of the apps like Flash and Dreamweaver. So its upgrade time. The trouble is from what I can see on Adobe's website since they bought macromedia they have basically added a Zero to the prices for everything. Studio MX was licenced by site license before my time for the princely sum of £640. Now I can find no mention of "site licensing" and licensing by product for 80-90 per item per machine is just not an option. Has anyone had recent dealings with them could point me in the right direction for reaonable licensing costs on an academic network?
-
Last thign worth mentioning some apps such as Office and Visual studio come with tools to produce their own GPO deployable packages. Other apps are the oposite end of the scale such as Macromedia Studio MX and Photshop elements which are an absolute ^&*$ to package. I've been beating my head against the brick wall that is Elements 5.0 since lunch and I still can't make it install without that photo import wizard which hijacks any mass storage device you plug in.
-
There is also ORCA which is part of one of the XP or 2k3 support packs. Its a much more powerful tool but but has a vertical learning curve. Between them you can do most things but there are much more userfriendly tools some with alot of automation but they are prohibatively expensive at least for us. appdeploy.com is your friend here. It has general hot-to articals and a database of apps with notes from experienced packagers on the various quirks and work arounds for them.
-
Yep its says its running in domain mode and the radial button for firewall off is the one that filled even tho its greyed out. But unless I set exceptions applications are being firewalled anyway. I've something of a breakthrough in the next 5mins. After rebuilding my test firtual machine again and reapplying GPOs its working properly.. now if I could just work out why.
-
Morning. Just getting back to this issue now. I've ruled out Malware with a clean machine build in the testing Vlan. Firewall was on after install from the windows CD then it was off by GPO Properly after its first restart. WSUS kicked in and restarted after the first round of updates. Firewall still off 2nd round of updates machine restarted and its back to its not showing firewall icon on the network connection but behaving very much like a firewalled machine. Sadly that 2nd round of updates is 120+ updates depending on the machine. I'm gonna try some internet searches first cos I don't really want to get into a game of install one update at a time. I'm wondering if there was an update to the firewall which was supposed to be acompanied by an update to the GPO that some how missed on my DCs?
