windows

First meeting 11-12-2009

Hi Folks,

Danny and I have started talking again about having regular meetings to better co-ordinate our efforts.  We're hoping to set up a semi-weekly get-together at first, and we'll review the frequency once we get things rolling.

Please feel free to delegate or refuse this appointment as appropriate.  I know that not everyone on the invite list can attend, but there is no time when everyone is free.

Shared Windows space for software distribution

I met with Bill Coker and we're going to try to get a software distribution share to deliver ISOs to on-campus administrators.  Products like SAS are up to 3 DVD's of install media, and with the double layer ISOs it's hard to deliver without a good old fashioned network share.

I'm clearing up space on the oitfs0 Celerra share, which we'll link in under the path

\\wolftech.ad.ncsu.edu\oit\Original_Media

I'm meeting with Bill again today or tomorrow to branstorm how he wants to manage rights -- I'll introduce hi to the automatically created groups in WT.

ActivePerl available for installation via GPO/Group membership

I've packaged the 32 and 64 bit ActivePerl distributions for Windows, version 5.10.1.1006.

To have it installed via GPO from the WolfTech domain, add the computer or groups of computers to the group FW-OIT-ActivePerl-5.10.1.1006, which you'll find in OIT/Software Packages/OIT Software

 

Tasks and stakeholders to decomission the UNITY active directory

It's getting time to talk about what needs to happen for a clean and successful decommissioning of the Unity domain,  I'd like to start by identifying the stakeholders and calling them together to discuss their transistion needs and priorities.

Here's the services so far identified

Time sync and group policies

In working with group policies, I've run into some frustrating test conditions where the policies I set just weren't getting set on the target computers.

Checking into the event log, the issue appears to be that the clock on my vmware machine was too far out of sync with the time on the WolfTech domain controllers for a session to be established, and so the workstation service principal couldn't log in and get the list of gpo's it should apply.

Minor OIT OU changes in WolfTech

I'm working to clean up and standardize our OU=OIT in the WolfTech active directory.

I've created under "Management Objects" a "People Groups" container, for holding groups representing teams or other assemblies of humans or human analogs.

Picture of OIT OU layout in wolftech

IIS secuity practices

Microsoft's Internet Information Server (IIS) uses a local computer account, IUSR_servername to provide access to the filesystem and other resources for anonymous web users.  We've had some problems getting the permissions correct for this acount.

I'd like to propose the following scheme, based on the recommendations from Microsoft's IIS 6.0 Security Best Practices

Internal OIT Active Directory organization planning begun

Yesterday Kevin and I met with Danny and Harry and discussed how to address the proliferation of OU admins in the WolfTech domain from within OIT.  We now have 11 OIT OUs,  (OIT-AC, OIT-ComTech-CMS, OIT-OCC, ISO_PROV,ISO_SHS,ISO_RnD, TSS_CS, TSS_LSS, TSS-DS, TSS-SC not to mention ITD-DSP), which is causing problems because being an OU admin in WolfTech implies a level of communication with the rest of the admin community that simply isn't present in most cases.

WolfTech AD configuration

The wolfech.ad.ncsu.edu is the domain used by all groups on campus,

These documents provide information about how OIT is using WolfTech

Windows servers now checked every 90 min for backup agents

We've added a new check, "backup agent" to the "windows-hosted" servers.

This check tests to see if either the NetBackup OR Avamar agents is loaded.  If one is, then it return green, if neither are found or on any errors, a yellow alert is generated.

We'll be deploying this on other Windows machines shortly.