280 likes | 492 Views
IT Briefing Agenda 2/16/06. AAIT Updates New IT Website & Governance Housing Quick Update Web Architecture Oracle Security NetCom Realignment. Karen Jenkins Karen Jenkins Karen Jenkins Eric Van Wieren Evan Ehrenhalt Paul Petersen. AAIT Reduction in Force.
E N D
IT Briefing Agenda 2/16/06 • AAIT Updates • New IT Website & Governance • Housing Quick Update • Web Architecture • Oracle Security • NetCom Realignment • Karen Jenkins • Karen Jenkins • Karen Jenkins • Eric Van Wieren • Evan Ehrenhalt • Paul Petersen
AAIT Reduction in Force • Funding need to support new services and better support under-staffed services • Overstaffed in some areas • desktop support - 1:60* ratio … industry standard is more than 1:100 … Emory is more like 1:200. • Staffed for services no longer provided by AAIT • Such as local support • Shift in AAIT support model • Transition Tier 2 to the service owners • Transition of services to other AAIT teams • Security breach process, SESA, and Managed AV to the Security team
Business Model Transition Local Support to campus departments Tier 2 support for the Help Desk Support for departmental solutions (SPSS, SAS, Novell) SESA, Manage AV, Security Breach Process Distributed model Service owner Local Support AAIT Security Team
Configuration Management • Support LSPs with complex desktop configuration issues relating to IT enterprise services • Create web-based (Software Express) and CD-based (EOL) authoring tools • Provide local support to AAIT and Clean Room services (Carlos & GDBBS) • Create gold standard images for Windows, OS X, Linux
Housing Application • Housing Director Product • Client based for occupancy management • Vendor is Adirondack Solutions • Atlanta & Oxford campuses using the same app & database • Moved from a departmental to enterprise based system
Some Features • Web product for student access and sign up • Lottery functionality based on priorities of the institution • Students can update personal information for housing preferences • Room preferences, dining plan • Targeted go-live is March 1, 2006 • Heather Mugg will present/demo next month
Web Architecture & Input Eric Van Wieren *
Oracle Advance Security ADS-DBA Team AAIT *
Data Access Security • What risks exist if accessing data on a different machine? • What can we do about this risk? • Plans for the future • Questions and answers
Points of Risk 2 Web Server Database Server 3 protected data 4 1 PC Client 2 3 Sniffing Data Sniffing Passwords
Risk Reduction 2 ASO Web Server Database Server 3 ASO SSL HTTPS protected data 1 4 PC Client ASO 2 3 ASO
What about the Core • The Administrative Core is a good concept. It keeps out most of the hackers. • The core does not protect against staff members (or student workers) with curiosity or malice.
How to use ASO • Oracle Advance Security is a feature of Oracle’s network connectivity. • It is controlled in the sqlnet.ora file. • Most machines already have what they need. • Changing a few lines in the sqlnet.ora file will do it.
Advanced Security Options • Oracle allows for four levels of security. • Reject – This machine refuses to use advanced security. • Accept – This machine will use ASO if the other machine requests/requires it. • Request – This machine will ask to use ASO, but will not demand it. • Require– This machine must use ASO or it will not connect.
SQLNET.ORA The security portion of the SQLNET.ORA looks like this: SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT= (MD5) SQLNET.ENCRYPTION_TYPES_CLIENT= (RC4_40, RC4_56) SQLNET.CRYPTO_SEED = qwertyuiop1234567890 .ORA = .ora # SQLNET.CRYPTO_CHECKSUM_CLIENT = accepted # SQLNET.ENCRYPTION_CLIENT = accepted # SQLNET.CRYPTO_CHECKSUM_CLIENT = requested # SQLNET.ENCRYPTION_CLIENT = requested # SQLNET.CRYPTO_CHECKSUM_CLIENT = required # SQLNET.ENCRYPTION_CLIENT = required # SQLNET.CRYPTO_CHECKSUM_CLIENT = rejected # SQLNET.ENCRYPTION_CLIENT = rejected Any pair of lines may be placed in the sqlnet.ora, but the computer on the server side must have compatible settings.
The Future • Over time we would like all communication to be encrypted. • All servers set to required if possible, or to requested for servers with unusual clients. • There is no timeline at this point. • Would you like to beta test for us?
Agenda • NetCom Org Charts - Old and New • Reasons for Realignment • Upcoming Projects • Questions
Reason For Realignment • Fill the vacant Senior Director position • Align Architecture, Engineering, and Operations under a unified direction • Assistant Director of Client Services created to focus on improving NetCom’s Service Level Objectives • Reduced standard work-order time from 7-10 Business days to 5-7 Business days. • Bring Architecture closer to the Engineering groups to work on upcoming challenges
Upcoming Challenges • Implementation of new Core Routers • Redundant, Low-latency, & Low-Jitter • Security – Firewalls, IPS, & VPN • Convergence of Voice and Data • Select single Voice Switch Technology • Avaya, Cisco, and Nortel • Planning for VoIP in SOM Building Summer ’07 • New Voicemail System – Unified Messaging • Wireless VoIP
Upcoming Challenges Cont… • Campus Master Plan & Strategic Plan • Infrastructure Planning • How do we keep service running during construction? • How do we help the transition from the old space to the new space? • Visioning Exercise for Clifton Road Redevelopment • What will communications look like in five years from now?