Public
E-mail notifications turned on
Mon, 10/05/2009 - 16:15 — jaklein.ncsu.eduBe careful what you wish for!
E-mail notifications have been added to this site, as some folks were missing them from our earlier blogs/drupal sites. You'll see a link for "subscriptions" at the bottom of most content.
Minor OIT OU changes in WolfTech
Tue, 09/29/2009 - 17:01 — jaklein.ncsu.eduI'm working to clean up and standardize our OU=OIT in the WolfTech active directory.
I've created under "Management Objects" a "People Groups" container, for holding groups representing teams or other assemblies of humans or human analogs.

Down to 8 servers that can't be monitored
Tue, 09/29/2009 - 12:45 — jaklein.ncsu.eduIIS secuity practices
Mon, 09/28/2009 - 08:39 — jaklein.ncsu.eduMicrosoft's Internet Information Server (IIS) uses a local computer account, IUSR_servername to provide access to the filesystem and other resources for anonymous web users. We've had some problems getting the permissions correct for this acount.
I'd like to propose the following scheme, based on the recommendations from Microsoft's IIS 6.0 Security Best Practices
OIT internal OU discussion 9/22/2009
Fri, 09/25/2009 - 14:45 — jaklein.ncsu.eduPresent: John K, Kevin S. Patrick W. Tom F., Dan E. Danny D
We got a small group together to advise management on how to best consolidate the many OU's that OIT is creating in WolfTech. There's more background at
http://xteams.oit.ncsu.edu/iso/node/470
The results of the meeting were
Firewall contexts set to allow new nagios access
Fri, 09/25/2009 - 08:41 — jaklein.ncsu.eduAs we work to bring the new Nagios system on-line, there's a lot of firewall changes that need to get made.
Comtech has established a range of addresses for all OIT devices meant for monitoring, and the intention is to open this address range (referred to as "OIT-Monitor") for incoming access for monitoring protocols for all datacenter subnets. This will make firewall settings easier and quicker for ComTech, and allow everyone less back and forth in setting up firewall rules for new VLANS.
"Monitoring" ports to open to the "OIT-Monitor" range of addresses
Fri, 09/25/2009 - 07:43 — jaklein.ncsu.eduThe monitoring servers in the OIT-Monitor range of addresses should have incoming access to the following ports for all OIT servers:
echo-reply
echo-request
dest-unreach
UDP and TCP 161 (SNMP read)
TCP 5666 (Nagios NRPE)
UDP 1161 (SMC)
TCP 9999 (MRTGEXT)
tcp/524 (NCP)
tcp/427 (SLP)
tcp/389 (LDAP)
tcp/636 (LDAPS)
tcp/13782 (Netbackup)
WolfTech/SAR meeting 9/23/2009
Thu, 09/24/2009 - 09:19 — jaklein.ncsu.eduAttending: Dan G, Billy B., Kevin S. John K, Mark S., Mike McC, Craig DeS, Jack F and Richard M.
Continuation of previous meeting in July in which we discussed using Wolftech to replace etssauth servers and Sun IDM integration.
Craig gave an overview of how the portal et al currently used the Auth Tree eDir, and it's requirements. We discussed how AD password policies differ, and covered some workflows about what would happen if one's basic access to one's desktop was controlled by the P1..P5 security policies.
WolfTech self-signed certificate
Wed, 09/23/2009 - 16:57 — jaklein.ncsu.eduTo communicate over ssl with the WolfTech domain controllers, you will need to import the ITECS root Certificate Authority.
In the near future, WolfTech will be moving to the NCSU CA run by OIT SnC. At that point, the root certificate will change.
Meeting with ITRE on 9-22-2009
Tue, 09/22/2009 - 14:53 — jaklein.ncsu.eduDan G., Billy B, and I (John K) met with Anne L. from ITRE to discuss their migration to WolfTech.
They've been working with ComTech since Febuary to get their firewall configurations set so that they can use DHCP and access other campus resources. They are on VLANs 1414 and 1410.
They're going to get a "default" layout, under OU=ITRE,OU=Research in WolfTech.
