IIS secuity practices
Mon, 09/28/2009 - 08:39 — jaklein.ncsu.eduMicrosoft's Internet Information Server (IIS) uses a local computer account, IUSR_servername to provide access to the filesystem and other resources for anonymous web users. We've had some problems getting the permissions correct for this acount.
I'd like to propose the following scheme, based on the recommendations from Microsoft's IIS 6.0 Security Best Practices
Firewall contexts set to allow new nagios access
Fri, 09/25/2009 - 08:41 — jaklein.ncsu.eduAs we work to bring the new Nagios system on-line, there's a lot of firewall changes that need to get made.
Comtech has established a range of addresses for all OIT devices meant for monitoring, and the intention is to open this address range (referred to as "OIT-Monitor") for incoming access for monitoring protocols for all datacenter subnets. This will make firewall settings easier and quicker for ComTech, and allow everyone less back and forth in setting up firewall rules for new VLANS.
WolfTech self-signed certificate
Wed, 09/23/2009 - 16:57 — jaklein.ncsu.eduTo communicate over ssl with the WolfTech domain controllers, you will need to import the ITECS root Certificate Authority.
In the near future, WolfTech will be moving to the NCSU CA run by OIT SnC. At that point, the root certificate will change.
How to edit your firewall in Web-Kickstart
Mon, 09/21/2009 - 11:14 — jjneely.ncsu.eduA question commonly asked, how does one best edit /etc/sysconfig/iptables during a Web-Kickstart %post?
You could include the entire file in the %post section of your kickstart. However, what about the default ports added for AFS, or another use file that may wish to slightly alter the host's firewall?
My friends, sed is the answer. The RHEL or Realm Linux 5 firewalls include a 'RH-Firewall-1-INPUT' chain where the Red Hat customizations live, so lets edit that:
ISO blog maintaince on Sept 19 (talk like a pirate day)
Fri, 09/18/2009 - 15:37 — jaklein.ncsu.eduTomorrow is International Talk like a Pirate day
I have some content filters in place on the ISO blog that I will be testing in honor of this most sacred and special of days. Please don't page anyone to report problems with our site tomorrow, it's all part of a scheduled, planned test.
Internal OIT Active Directory organization planning begun
Tue, 09/15/2009 - 07:41 — jaklein.ncsu.eduYesterday Kevin and I met with Danny and Harry and discussed how to address the proliferation of OU admins in the WolfTech domain from within OIT. We now have 11 OIT OUs, (OIT-AC, OIT-ComTech-CMS, OIT-OCC, ISO_PROV,ISO_SHS,ISO_RnD, TSS_CS, TSS_LSS, TSS-DS, TSS-SC not to mention ITD-DSP), which is causing problems because being an OU admin in WolfTech implies a level of communication with the rest of the admin community that simply isn't present in most cases.
license02 software firewall adjusted for flexLM monitoring
Thu, 09/10/2009 - 15:30 — jaklein.ncsu.eduFYI, I've adjusted the software firewall on license02 so that the new Nagii can monitor it properly.
Tooltips added to ISO blog
Wed, 09/09/2009 - 10:34 — jaklein.ncsu.eduFolks,
I added a drupal module, JTooltips, to the ISO blog. I'm trying to make our site "richer" without adding a lot of work to content creation. It shouldn't impact access, just AJAX things up a bit, but if people hate it, it's easy enough to turn off.
John
WolfTech AD configuration
Tue, 09/08/2009 - 08:22 — jaklein.ncsu.eduThe wolfech.ad.ncsu.edu is the domain used by all groups on campus,
These documents provide information about how OIT is using WolfTech
Access group "OIT-ISO-Tech" created in QIP
Fri, 09/04/2009 - 15:06 — jaklein.ncsu.eduIn order to reduce duplicate calls for ComTech, improve our security practices, and generally speed up request processing for QIP access, ComTech has created a QIP role named "oit-iso-tech"
This role provides access to QIP objects, and members can easily be added or removed from the role. The initial membership of this role will be the staff in ISO-PROV and ISO-SHS (those that do production QIP work in ISO)
