Configuration Management Supplement 67 Robert Horn, Agfa Healthcare.

Slides:



Advertisements
Similar presentations
Automatic Configuration of DICOM Network Applications Experience with Frozen Draft of Supplement 67 DICOM Anniversary Conference & Workshop Baltimore,
Advertisements

Windows Server 2003 AD 安裝設定與管理維護 林寶森
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 4 Installing and Configuring the Dynamic Host Configuration Protocol.
How to Succeed with Active Directory Robert Williams, PhD CEO Secure Logistix Corporation.
System Center Configuration Manager Push Software By, Teresa Behm.
DICOM INTERNATIONAL DICOM INTERNATIONAL CONFERENCE & SEMINAR April 8-10, 2008 Chengdu, China DICOM Security Eric Pan Agfa HealthCare.
TAC Vista Security. Target  TAC Vista & Security Integration  Key customer groups –Existing TAC Vista users Provide features and hardware for security.
Active Directory: Final Solution to Enterprise System Integration
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 13: Troubleshoot TCP/IP.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 5: Planning, Configuring, And Troubleshooting DHCP.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Lesson 20 – OTHER WINDOWS 2000 SERVER SERVICES. DHCP server DNS RAS and RRAS Internet Information Server Cluster services Windows terminal services OVERVIEW.
Systems Architecture, Fourth Edition1 Internet and Distributed Application Services Chapter 13.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 8 Introduction to Printers in a Windows Server 2008 Network.
Chapter 8: Network Operating Systems and Windows Server 2003-Based Networking Network+ Guide to Networks Third Edition.
Robert Horn, Agfa Corporation
Understanding Active Directory
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Final Design and Implementation
What’s New in DICOM 2004 Robert Horn Agfa Healthcare Chair DICOM WG-06 (Base Standard)
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
Network Services Lesson 6. Objectives Skills/ConceptsObjective Domain Description Objective Domain Number Setting up common networking services Understanding.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
Network LANscape Servers & Equipment Found In a Typical Local Area Network (LAN) By George Squillace New Horizons of MichiganGeorge Squillace MCT, MCSE,
S New Security Developments in DICOM Lawrence Tarbox, Ph.D Chair, DICOM WG 14 (Security) Siemens Corporate Research.
XA R7.8 Upgrade Process and Technical Overview Ruth Anne Pharr Sr. IT Consultant, CISTECH Inc.
Sept 13-15, 2004IHE Interoperability Workshop 1 Integrating the Healthcare Enterprise Audit Trail and Node Authentication Robert Horn Agfa Healthcare.
IT:NETWORK:MICROSOFT SERVER 2 DHCP AND WINDOWS DEPLOYMENT SERVICES.
September, 2005What IHE Delivers 1 ITI Security Profiles – ATNA, CT IHE Vendors Webinar 2006 IHE IT Infrastructure Education Robert Horn, Agfa Healthcare.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
September, 2005What IHE Delivers 1 G. Claeys, Agfa Healthcare Audit Trail and Node Authentication.
1 Understanding the TCP/IP Protocol Suite Industry standard Enables enterprise networking and connectivity.
Module 8 Configuring Mobile Computing and Remote Access in Windows® 7.
COMP1321 Digital Infrastructure Richard Henson February 2014.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
SUS Commander Sean Merritt. Background Department of Natural Resources uses a Software Update Server to update the user’s PCs. The log files are cryptic.
Module 5: Designing a Terminal Services Infrastructure.
Scalable Systems Software Center Resource Management and Accounting Working Group Face-to-Face Meeting October 10-11, 2002.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
February 8, 2005IHE Europe Educational Event 1 Integrating the Healthcare Enterprise Basic Security Robert Horn Agfa Healthcare.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 4 Installing and Configuring the Dynamic Host Configuration Protocol.
DICOM INTERNATIONAL CONFERENCE & SEMINAR Oct 9-11, 2010 Rio de Janeiro, Brazil Security, Privacy & Networking Lawrence Tarbox, Ph.D. Washington University.
A Brief Documentation.  Provides basic information about connection, server, and client.
OS Services And Networking Support Juan Wang Qi Pan Department of Computer Science Southeastern University August 1999.
TCP/IP (Transmission Control Protocol / Internet Protocol)
Experiment Management System CSE 423 Aaron Kloc Jordan Harstad Robert Sorensen Robert Trevino Nicolas Tjioe Status Report Presentation Industry Mentor:
Network Infrastructure Microsoft Windows 2003 Network Infrastructure MCSE Study Guide for Exam
Virtualization Technology and Microsoft Virtual PC 2007 YOU ARE WELCOME By : Osama Tamimi.
1 Active Directory Administration Tasks And Tools Active Directory Administration Tasks Active Directory Administrative Tools Using Microsoft Management.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
Chapter 12 The Network Development Life Cycle
MICROSOFT TESTS /291/293 Fairfax County Adult Education Courses 1477/1478/1479.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter One Introduction to Exchange Server 2003.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Integrating the Healthcare Enterprise Improving Clinical Care: Enterprise User Authentication For IT Infrastructure Robert Horn Agfa Healthcare.
Directory Services CS5493/7493. Directory Services Directory services represent a technological breakthrough by integrating into a single management tool:
What’s New in DICOM 2004 Created by: Robert Horn – Agfa Healthcare Chair DICOM WG-06 (Base Standard) Presented by: Bas Revet – Philips.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Chapter 4: server services. The Complete Guide to Linux System Administration2 Objectives Configure network interfaces using command- line and graphical.
COMP1321 Digital Infrastructure Richard Henson March 2016.
Chapter 1 Computer Technology: Your Need to Know
Module 8: Networking Services
File System Implementation
Tailor slide to customer industry/pain points
DHCP, DNS, Client Connection, Assignment 1 1.3
Presentation transcript:

Configuration Management Supplement 67 Robert Horn, Agfa Healthcare

Configuration Management The Problem being solved The Problem being solved Use Cases Use Cases Sup. 67 – DICOM Configuration Management Sup. 67 – DICOM Configuration Management

The Problem Being Solved Installation of DICOM equipment Installation of DICOM equipment »Takes too long »Requires too much effort »Requires time consuming, multi-vendor coordination »Involves too many mistakes Upgrading and repairing DICOM equipment Upgrading and repairing DICOM equipment »Requires too much service effort for configuration tasks that are unrelated to the problem being solved. »Configuration complexity prevents customer self-help for simple problems

Use cases Add a new machine Add a new machine Locate Actor, IP, AE-title, Security information Locate Actor, IP, AE-title, Security information Single node power up and establish configuration Single node power up and establish configuration Time Synchronization Time Synchronization

Constraints Support vendor extensions Support vendor extensions Support site and enterprise extensions Support site and enterprise extensions Consider installed IT support facilities in selection Consider installed IT support facilities in selection Do not invent a new protocol Do not invent a new protocol

Network Services DHCP DHCP »Assigns IP address, hostname »Informs DNS of assignment »Provides routing, NTP, DNS, etc. information to client DNS DNS »Provides hostname to IP lookup services »Provides server location lookup services NTP NTP »Provides accurate time and time synchronization »See for descriptions, software, evaluation, and configuration guidance.

LDAP Very Widespread use, Very Widespread use, –No surprises to the IT staff –Large base of trained users and administrators –Large base of software clients Support by Microsoft, Unix, Open Source Support by Microsoft, Unix, Open Source Support for federated databases Support for federated databases Easy to extend by adding schema Easy to extend by adding schema

Infrastructure requirements DHCP, DNS, NTP, LDAP may be on one host, or may be on multiple hosts. DHCP, DNS, NTP, LDAP may be on one host, or may be on multiple hosts. Normal network design issues, nothing special for the DHCP, DNS and NTP services. Normal network design issues, nothing special for the DHCP, DNS and NTP services. LDAP is increasingly integrated into IT operations. This makes its use for configuration management more attractive, but means a greater planning involvement with the IT organization. LDAP is increasingly integrated into IT operations. This makes its use for configuration management more attractive, but means a greater planning involvement with the IT organization.

Beyond AE-Titles –Installation and Network Configuration oriented –Locate Application given the AE-title »TCP/IP parameters –AE Configuration »SOP Classes supported (SCU/SCP, Transfer Syntaxes) »Vendor extension »Obtain new unique AE-Title –Device Configuration »Description »Vendor extension »Hospital extension

Preconfigured Installation Large network addition Large network addition Multiple vendors Multiple vendors Reduce coordination and scheduling delays Reduce coordination and scheduling delays Reduce configuration errors Reduce configuration errors Reduce staging requirements Reduce staging requirements

Preconfigured Installation A A A A B B B LDAP LDIF Network Planning Prepared Configurations Prepared Configurations Vendor A Preparation Vendor B preparation DHCP IT Organization

Add another machine DHCP LDAP DNS Get IP, hostname, etc. Find LDAP Server Query Configuration Obtain Unique AE Titles Update Configuration Install Hardware Assign Name Configure System

Customer Assisted Maintenance –Simple device swap –Remote reconfiguration –Local reconfiguration

Present Supplement Status Supplement 67 – Proposed for Frozen Draft Supplement 67 – Proposed for Frozen Draft Could be updated and final by September or October. Could be updated and final by September or October.

Configuration Management Actors

Individual AE Title LDAP Schema DICOM Configuration Unique AE Titles Registry Individual AE Title Devices Vendor Information, Certificates, Device Configuration parameters, etc. AE-Title, Description, AE Configuration parameters, etc. Network AE Transfer Capability SCU/SCP, Hostname, Port, etc. } This portion is used to provide unique AE titles automatically.

# # The following attribute types are defined in this document: # #NameSyntaxMultiplicity # #dicomDeviceNamestringSingle #dicomDescriptionstringSingle #dicomManufacturerstringSingle #dicomManufacturerModelNamestringSingle #dicomVersionstringMultiple #dicomVendorDatabinaryMultiple #dicomAETitlestringSingle #dicomNetworkConnectionReferenceDNMultiple #dicomApplicationClusterstringMultiple #dicomAssociationInitiatorboolSingle #dicomAssociationAcceptorboolSingle #dicomHostnamestringSingle #dicomPortIntegerSingle #dicomSOPClassOIDSingle #dicomTransferRolestringSingle #dicomTransferSyntaxOIDMultiple #dicomPrimaryDeviceTypestringMultiple #dicomRelatedDeviceReferenceDNMultiple #dicomPeerAETitlestringMultiple #dicomTLSCipherSuitestringMultiple #dicomAuthorizedNodeCertificateReferenceDNMultiple #dicomThisNodeCertificateReference DNMultiple #dicomInstalledboolSingle # LDAP Schema

Example of attribute definition # 3.1 dicomDeviceNamestringSingle # # This attribute stores the unique name (within the scope of the LDAP database) # for a DICOM Device. # # It is a single-valued attribute. # This attribute's syntax is 'Directory String'. # Its case is not significant for equality and substring matches. # attributetype ( NAME 'dicomDeviceName' DESC 'The unique name for the device' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX SINGLE-VALUE )

Objects Defined # The following object classes are defined in this document. All are # structural classes. # #NameDescription # #dicomConfigurationRootroot of the DICOM Configuration Hierarchy #dicomDevicesRootroot of the DICOM Devices Hierarchy #dicomUniqueAETitlesRegistryRootroot of the Unique DICOM AE-Titles Registry Hierarchy #dicomDeviceDevices #dicomNetworkAENetwork AE #dicomNetworkConnectionNetwork Connections #dicomUniqueAETitleUnique AE Title #dicomTransferCapabilityTransfer Capability

Example of Object Definition # # 4.4 dicomDevice # # This structural object class represents a DICOM Device. # objectclass ( NAME 'dicomDevice' DESC 'DICOM Device related information' SUP top STRUCTURAL MUST ( dicomDeviceName $ dicomInstalled ) MAY ( dicomDescription $ dicomManufacturer $ dicomManufacturerModelName $ dicomVersion $ dicomVendorData $ dicomPrimaryDeviceType $ dicomRelatedDeviceReference $ dicomAuthorizedNodeCertificateReference $ dicomThisNodeCertificateReference) )

Use of LDAP Schema Schema text from the supplement Schema text from the supplement »in the format used to configure generic LDAP servers »Cut and paste from supplement into server configuration file tested and verified Local extension by modifying schema Local extension by modifying schema

Purpose of Frozen Draft Find any remaining flaws in the Frozen Draft Find any remaining flaws in the Frozen Draft »Inhouse experience at several companies revealed flaws in the public comment version. »The flaws only became apparent during the development of trial versions. Inter-company trials Inter-company trials »are expected to reveal other flaws in the Frozen Draft version »The trials are not exploring implementation compatibility, only clarity of the standard »The trials are not a compatibility connectathon »The Committee for Advancement of DICOM is organizing a small group of trial implementations.

Future additions Security parameter distribution Security parameter distribution »LDAP is one of the mechanisms for distributing PKI information for key management.