Jump to content

dmj

Members
  • Posts

    1,769
  • Joined

  • Last visited

Everything posted by dmj

  1. I think you're just coming up against the reality of modern IT infrastructure. The CX series are designed to be configured by code, and is supported by HP in their ansible modules https://github.com/aruba/aoscx-ansible-collection and terraform provider https://registry.terraform.io/providers/aruba/aoscx/latest The idea is that as you provision your server (with code) you hook out to the switches to configure those at the same time. It's often known as a software defined network, that your configuration in one area automatically updates something else. You also get decent backup protection, security/approval process of who's made changes and a log of those changes. The generally accepted view here seems to be that all this stuff is far too complicated and a waste of time for the average school because there are more pressing issues than dealing with stuff. I guess that depends how long you plan on being in IT though.
  2. There are two types of certificate you will need. 1) The SAML signing cert. this is used to sign the SAML assertions and is typically a long lived self signed certificate. You don't need to get a third party to sign that as you include the public key in the ADFS metadata. Just create a new keypair with openssl and use that. 2) The webserver certificate. I guess this is what you are asking about ? personally I'd use an ACME domain validated certificate and have the renewal scripted. Otherwise you could just use the same cert that you use for your other servers and add the SAN for the ADFS server.
  3. I don't have a specific issue with the default configurations, a few thoughts though: As others mentioned there is difficulty analysing a domain and comparing to default config. The API's for Office 365 and Google workspace are available to all, so a method to check for configuration drift and provide a base config as code would be helpful. (A well maintained terraform provider would be most welcome). The extra (paid) option to save data in UK regions should be unacceptable from a GDPR perspective if we want data location to be secure (Google Workspace) Lack of options on O365 when adding third party applications (this may be fixed, I've not managed an O365 domain for nearly two years) IIRC there was a significant issue with allowing users to install third party apps which then allowed access to onedrive/ all users emails/ personal info etc - Google did a much better job because you could deny access based upon what access the application needed, but it does need some configuration and I forget the defaults. Most schools will just block this or allow a whitelist, it's an issue when staff tell students to install X,Y,Z that then gives a company access to all the users details. I also recall there was an issue whereby 0365 users could use the SMTP server in their domain to spoof emails from another domain that they don't own. You had to use some telnet trickery but I certainly recall sending an email from #random-school when using the O365 relay. I was working in Unix support at the time and the Windows team didn't even seem to comprehend the issue, so it's entirely likely it was an internal misconfiguration - still it was a bit worrying that could even happen.
  4. Same thing in our school build, there was things we didn't need but had to have - wired connections (when all the chromebooks don't have RJ45) and massive server rooms with cooling. What we really needed was space, but we weren't allowed that as they spent all the money on cabling and switches. I mentioned it to DfE at BETT one year (about 5 yrs ago) they were 'aware' of the issue but there's no incentive to fix it as the schools have to be one size fits all.
  5. Really? you must be new here. If it's not the way they've always done it, nobody wants to learn a new system even if it's going to save time/money and be better for the long term. Try posting on this forum about IasC, terraform, docker or pretty much any technology that isn't a paid solution from some select vendors and you are pretty much left with a blank stare, or even open hostility. As for LTSC, pretty much the same as any LTS release of anything - if you want stability and have mission critical systems so need to have the reassurance that there will not be breaking changes then it's a good move for some. It may also help with licensing if you chose to buy perpetual licenses (if that is even a thing nowdays) and just upgrade/re-buy every 10 years. It would probably save a few quid.
  6. dmj

    New server

    They probably realise that if you have ZFS experience you can do all the backups without veeam !
  7. dmj

    New server

    I would seriously consider using ZFS over XFS for storage partitions. The snapshot features are second to none. A good overview of the features: https://en.wikipedia.org/wiki/ZFS
  8. I've used an opensource syslog server for windows logging in the past, worked well. I think these days I would recommend using the ELK stack for this, as there is more visibility/gui. It is also free and opensource, but there is a paid hosted option if you want (we use this option) https://www.elastic.co/blog/elasticsearch-free-open-limitless
  9. Funny you should say that, I went to great lengths to get two FTTP providers, terminating at different exchanges. Total redundancy. I thought, until contractors went through both cables when digging the road elsewhere. Normal chaos ensued.
  10. Decent monitors do all this these days. Mines an HP, at work we have Dell monitors.
  11. That's the one thing that really gets on my tits is pronouncing SQL as 'sequel'. Mysequel, postgresequel?? Idiots.
  12. I suppose our scheme was part parental contribution then, many of the parents paid in full - so would qualify as BYOD. I'm afraid I don't recall the statistics of how many decided to pay in full and how many were paying monthly.
  13. No Uniforms, School shoes, calculators. Many schools literally send students home if they don't have these. We just added Chromebooks to the list. Our SLT/Governors didn't think £100 per year extra didn't seem out of the ordinary But with 25% FSM you are a different demographic.
  14. oh ok. I didn't realise. We didn't call it a contribution because they either bought into it or didn't. Contribution sounds like it's some sort of voluntary thing. yes it was voluntary to opt into the scheme, but if they didn't keep up payments there would be a court summons. Hence I didn't recognise it as a a 'contribution'. Full BYOD with a mass of different devices at secondary level? Hell no. Even on a University campus we barely supported student devices and there was no obligation to use one.
  15. The scheme we operated was NOT parental contribution or school owned. Parents were expected to buy a device. The school provided the scheme for purchase/warrant/repairs.
  16. I worked for a school where we forced 1:1 devices for all yeargroups. IIRC we started rolling it out around 2015 and it is still running successfully. in a nutshell. We planned two years in advance to make sure wifi/FTTP was redundant and upto spec The initial rollout was with two yeargroups (circa 300 students in each yeargroup), two yeargroups the next year and then each year. School invested in workshop for chromebook repairs, techs self trained how to solder watching youtube! School make inital purchase of chromebooks for each student + 20% The 20% are spare parts and the cost to parents includes this amount We committed to repairing the devices for 3 years Device turnaround time for a hardware fix was typically less than 8hrs - any motherboard soldering would get a replacement, log the issue on a postit and resolder the components at a later date so we could get the board back out. Software issues were typically fixed in under 5min - reimage the device and delete any plugins Parents with more than one child in school receive a discount (forget the details) Students with FSM are subsidised 100% by the school FMS proportion was low, this was an affluent, rural area Parents pay for the chromebook entirely or by payment plan over two years Total cost to parents was around £280 for 3 years IIRC it was about £10/month for two years. School fixes all issues including accidental damage. Intentional damage was charged extra. All repairs were from the stock of 20% spare machines (swapping out parts with other broken kit) For circa 2000 devices after the scheme rolled out fully, this amounted to one full time tech doing repairs (we did shifts) Uptake onto scheme was about 98% but pretty much all students had a device of some kind. There was strain on pastoral groups getting parents onboard - not a technical thing but bear in mind with planning Some parents sent their kids in with other equipment, macs/windows/linux/chromebooks etc. School didn't oppose it but didn't fix the devices either. Cost saving on IT suites/ textbooks / paper etc easily paid for wifi upgrades/tech time and subsidies/repairs.
  17. Thanks, thats really interesting and explains why Amazon don't care if they are not getting charged.
  18. Chargeback is voluntary, and usually used for debit cards. With credit cards use a section 75 claim as it's backed by UK law as the CC company is legally required to reimburse you if there is a breach of contract. If you are buying anything worth over £100 then it's good advice to use a credit card for this added legal protection.
  19. I think 'serverless' is getting misapplied in this thread. In a cloud native environment 'serverless' generally means an application running in a container on a managed server - AWS this is Lambda functions, GCP it is called CloudFunctions and in Azure it is called Azure functions. I think that's the generally accepted meaning of serverless.
  20. +1 for using a credit card here, because it's covered by a section 75 claim. If you have any trouble with Amazon, just call the cc company and explain it was a breach of contract because the goods didn't arrive. The credit card company will refund the money.
  21. Agreed, but I wanted to dispel the myth that it's a requirement or some sort of unsupported configuration as it's actually quite a common setup.
  22. Off topic nitpick: I think you're slightly overstating the reliance on a windows DNS server. Yes AD uses DNS, in the same way it uses CIFS/SMB shares or DHCP, but its not in any way reliant on Windows DNS. it's a fairly common situation in larger organisations who operate public DNS servers to use BIND as their AD DNS (At my last place we had 20,000 users on BIND/AD DNS). It is a standard and supported configuration.
  23. You'd need server license/CALs to be compliant AFAIK. NUC is overkill for DHCP IMO.
  24. 99% sure the LA provided router / filtering will be capable of running DHCP. If they don't let you have root on it, have you asked them about whether they could configure/manage DHCP for you? Isn't that the same problem you're trying to get away from - managing an on-site server? FWIW I did used to run a high availability DHCP that failed over to a server running in a cloud provider. It wasn't true serverless as I still had to manage that VM it did work well though. I think you just need to be pragmatic about it, if you can't get a decent solution using the network equipment that you have (or can you reflash any of it with OpenWRT?), having a couple of raspberry pi's with a failover DHCP capability or the Unifi kit that you suggested would both be good options.
  25. yeah riding experience is really difficult to describe in words. Especially counter steering - it's interesting to try on a bicycle or motorcycle at low speed though. Just slightly push the handlebars in one direction and you'll see it steers in the opposite direction. So when you're turning into a corner, you're actually pushing the handlebar counter to the way you're turning. My only 'advice' would be that you COMMIT to a corner. Once you've decided the gear, speed and the path you'll be taking you don't change. If you've made a mistake and are going too fast you have to commit further and lean in harder 99/100 you'll make it*. If you slam the brakes on and try and right the bike 99/100 you'll crash. *unless you have a square tyre trail bike, when it will run out of tyre and spit you off backwards. Been there.
×
×
  • Create New...