Technology Update TSAG Meeting 3/13/03
Announcements: Disaster Recovery Test:[Bill] (2/18-19) Networking Infrastructure: DNS, DHCP, Authentication (3/5) Infrastructure: Voice/IP Change Over ( 1/18-20 => 3/29-31) [Greg] We need your help! SMTP Authentication Recap ( 3/1 )[Chris] Directory Authentication for Peoplesoft HR/FN (1/13 => 2/19 ) Campus UID, Address, or Peoplesoft Operator ID Password resets handled by University Helpdesk and PS Helpdesk
Peoplesoft/Directory Architecture CSUNUtah Web Server App Server DB Server Workstation https ldap(s) Increase Load CPU: 50% in Kernel Space Increased Load Problems: Negative Interaction between PS/AppServer and Directory! We had to revert back to PS/Database Authentication.
Agenda TII Stage 2 Update (Will Trask) Mainframe Status (Don Foster) Microsoft Server Licensing Updates (Steve) Novell Software Licensing (Steve) IDS (Greg) Security Proposals (Steve)
Mainframe Status Approximately, 50% of the applications have been migrated off. 2000 user accounts daily users 134 remaining apps16 appear active All apps must be removed by June 30 Local units are responsible to identify and to migrated their applications off More info is needed: A meeting can be arranged to work out details Contact point: Don (x 5215)
Microsoft Licensing Changes New contract CSU-wide contract (effective 1/1/03) Information on the processes, etc., is still being ferreted out Four separate processes and licensing categories: Server Software: obtained via CSU ITAC members (for our campus it’s the CIO) CSU has a total allocated budget of $387, CSUN's portion is $27, Your task: Send the list of licenses you need/want Stay tuned for Keys, CDs, and more information
Novell Software License Year 3 of a three year Campus-wide contract We are adjusting the contract to reduce cost Provides software and support Value Bundle $6.50/Calculated FTE Netware ZENworks Your task: to provide information in your area to what products your using, etc.
Intrusion Detection System
Network Access Controls ICMP == Ping Block all inbound ICMP (on 3/17) Except to identified Internet Servers Block all outbound ICMP (on 4/1) Block all inbound UDP/TCP (on 4/4) Except to identified Internet Servers We have a list of identified Internet Servers Last call for your Internet Servers! I will send complete list to TSAG!
Telnet versus VPN/SSH We have a limited number of Internet Servers that support telnet (~8-10) Goal: to Phase out Telnet at the Campus/Internet Boundary Originally proposed over one year ago Need time to educate and to deploy client software Require either SSH for a limited set of Internet Servers VPN Proposed Date: ? 1/1/04