330 likes | 416 Views
E-mail Technical Coordinators Meeting. Chris Bongaarts Steve Siirila June 8, 2005. Internet Services. Directory Lookup Directory Management Authentication E-mail World Wide Web Hosting Calendaring U Card Many others!. Directory Lookup Services. Web Lookup ( www.umn.edu/lookup )
E N D
E-mail Technical Coordinators Meeting Chris Bongaarts Steve Siirila June 8, 2005
Internet Services • Directory Lookup • Directory Management • Authentication • E-mail • World Wide Web Hosting • Calendaring • U Card • Many others!
Directory Lookup Services • Web Lookup (www.umn.edu/lookup) • LDAP (ldap.umn.edu) • PH • Finger • Gopher • Whois
Directory Management • Directory Update Tools (www.umn.edu/dirtools) • Account Information • Credentials Management • E-mail Settings • E-mail Storage Usage • Blocked E-mail Display/Management • Other (URL, U Card, Modem Pool, UMCal) • Departmental Directory Population (e.g. AD)
Authentication Services • CAH (Central Authentication Hub) • Radius (Modem Pool, Wireless, etc.) • Kerberos • Authen (Internal) • Shibboleth (Future)
E-mail Services • E-mail Services (user@umn.edu) • Inbound (IMAP/POP) (username.email.umn.edu) • Outbound (SMTP) • Authenticated (smtp.umn.edu) • Smart Relay, IP-based permission (relay.tc.umn.edu)
Bulk/List E-mail Services • Listserv (lists.umn.edu) • Traditional discussion list service • Lyris (ecommunication.umn.edu) • Announcements • Marketing Campaigns • Link click-through tracking
World Wide Web Hosting Services • Web Hotel (www1.umn.edu) • Lightweight service (HTML, CGI, PHP) • Fee for service • Free virtual host redirection • JAWS offers more advanced hosting • Personal Web (www.tc.umn.edu) • CGI for interactive users, HTML only for non-interactive • Free with all central accounts
Other Services • Calendaring (UMCal) (umcal.umn.edu) • U Card Issuance • SSL Server Certificates • USENET Newsgroups (news.umn.edu) • Internet Relay Chat (IRC) (irc.umn.edu)
Virus Detection • Virus definition updates missed for some inbound and outbound servers • Affected 1 of 3 inbound servers from April 16th to June 6th (Note: spam blocking generally blocks most viruses) • Affected 2 of 3 outbound servers from April 16th to June 6th • Problem has been corrected
Hardware Upgrades • E-mail servers • Two Sun V890’s will replace four V440’s • Phased in over summer • Directory servers • Four Dual-CPU Sun V210 servers to support new Aphelion directory • Will eventually handle load of current single-CPU V210’s
Inbox Auto-filing (proposed) • Default selection criteria • Messages older than 90 days • Only mailboxes larger than 20MB • User-selectable options • Retention term (14-365 days?) • Tool to archive on-demand by message age and/or size
E-mail Enhancements (mid-June) • Auto-whitelisting of MTAs • Applies only to MTAs blocked due to rDNS • Requires at least 1 request/grant transaction • Does NOT exempt MTA from DNSBLs • Blocked mail reporting option • User may select daily or weekly reports • Reports will be sent via e-mail at 6:15am • Covers previous 24 hour period (6am-6am) or 7 day period from Mon 6am - Mon 6am • Autoreply: optional effective start date
Departmental MTA Registration • MTAs and other devices which are using the relay.tc.umn.edu service must register to guarantee uninterrupted service • Send IP address, type of device, and contact information to isgroup@umn.edu • As of 6/7, 259 IP addresses have been registered by 24 different departments • Cannot be used from dynamic IP addresses!
Phase-out of clear-text passwords • General mailings went out over the past 3 weeks to about 15,000 users • Mailings to technical coordinators went out prior to the general mailings • Non-SSL autoresponder available: • Checks current outgoing SMTP settings • Checks for recent non-SSL IMAP and POP • Mail to: ssl-test@umn.edu
Clear-text password phase-out timeline • June 8th • Pearl becomes “warehouse” server • Uses cheaper (slower) disks • Designated server for inactive users • Allows secure IMAP/POP/FTP access only • Move inactive users to Pearl daily • Move newly-active users off Pearl daily
Clear-text password phase-out timeline (cont) • June 10th • Aquamarine becomes “insecure” server • Designated server for users not yet converted to an SSL-only configuration • Will continue to allow non-SSL IMAP/POP/FTP access through at least Aug 2005 • Begin moving “secure” users off (ongoing) • Begin moving “insecure” users on • New users NOT created on Aquamarine
Clear-text password phase-out timeline (cont) • Mid-July 2005 • All servers (except Aquamarine) no longer allow insecure IMAP/POP/FTP access • August 2005 • Aquamarine becomes secure-only and is no longer special-cased
Kerberos Authentication Service • Now in production use by the new Active Directory project • Contact isgroup@umn.edu if you are interested in exploring use of Kerberos for authentication
Listserv Upgrade • Listserv upgraded to version 14.3 • Security fixes for Web interface • Web interface performance improvements • Anti-spam: Lists can be made to require confirmation for non-member messages • 72 new "message templates“ allow for more customization of system messages • http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.3-Release-Notes.html
Message Management Platform (MMP) 1.1 Upgrade • Test Aphelion Directory fully populated and updated in real-time • Testing of directory and messaging components continues • New directory will run in parallel with existing directory for several months • Finalizing licensing with vendor (BT)
Steve Siirila sfs@umn.edu 612-626-0244 Chris Bongaarts cab@umn.edu 612-625-1809 ‘Till next month…