Minutes Waterloo Polaris Advisory Group October 18, 2000

Attendees:

Daniel Delattre Applied Health Science (AHS) Trevor Bain Environmental Studies
Nevil Bromley Arts Tim Farrell Information System and Technology (IST)
Bruce Campbell Engineering Computing Ray White IST (Chair)
Erick Engelke Engineering Computing Jim Johnston MFCF
Hon Tam Engineering Computing Stephen Sempson Science (Secretary)

Submitted items:

Q: (Bruce) As discussed in WPAG Jan, Feb, March of 2000, the non accounting Watstar printing conversion deadline was Sept 1, 2000, which means all non accounting print servers on Watstar now must be samba. The printers themselves can be ethernetted, or serial/parallel to a local unix/NT box.
A: (Bruce) Printer motivation, new printers won't work with the current Polaris Printer accounting servers and Windows 2000 will need the conversion mechanism to work.

(Nevil) Arts printers which are public still use WatACO as a print daemon. There is no accounting on this print server, but we are in the progress to remove.

Q: (Bruce) Mike Hurst of EC will soon be ready with ethernetted printers using the laserman accounting system. All printers will have to be converted to ethernet. Printers with only a serial/parallel port will need to be replaced, or a conversion gadget installed (and tested).
A: (Bruce) EC is almost ready to move accounting to samba. Mike Hurst is to document how to do this. He recently found some public domain software which can be used to talk to the printer, count pages, and talk to the accounting software. Thus, Mike is reworking some of what he has done to use this new software. This can be use to print from Win95 to a samba server. It does restrict jobs to only the internal domain, and there is no authentication. Therefore, we lose some flexibility.

(Erick) There is potential for using the Active Directory to add any new users if they are not in the cash database.
(Bruce) This may be a term or two to develop.
(Tim) Is there a deadline?
(Bruce) No, not yet.
(Ray) Removing jobs from the queue is a lot harder with samba.
(Tim) Will this new process still use Printers.pol in the Etc directory?
(Ray) Yes, for the enviroment. We are still not sure how to define the closest printer, but we have all the hooks in with Win95.

Q: (Bruce) Watstar development. Most Watstar programs have not been changed in over a year. To free up space in my office, I will probably be retiring my Waterloo Polaris machine soon. This means that further Watstar development will not be possible, no more changes can be made. I will also not be able to help much, if at all, with any more Watstar to netapp account moves.
A: (Bruce) Within three months, I will not be doing any more development of Watstar code. If anyone needs help, please see about it now, ie. account moves, etc. I do not want this to slide, and do not want it to be a surprise to anyone. It is real that Watstar will disappear and it is going to happen at some point soon. I will keep a DOS machine for nightly updates, but want to have the machine to sit for a while during the weening process. I suspect we should also think about doing some inventory, of machines that are Win2K capable and those that are not.

(Nevil) Arts has already done this.
(Bruce) Engineering has undertaken this already, and a document has been prepared by Beth Jewkes. We do not want to have a surprise on the hardware needed for the move. It would be best if all levels knew the cash necessary for this.
(Ray) It is approximately 1.2 million dollars for current Waterloo Polaris labs to be upgraded (Engineering ~$600 000). This is based on some assumptions, like the minimum amount of RAM, etc. The numbers
significantly change when you modify the assumptions or if you start adding Faculty, Grad and Staff workstations.
(Bruce) We should be developing on the new technology, not on keeping the Win95 Polaris.
(Erick) The change over will go smoother. All files will be in the same place. We expect just the registry to be different for the accounts.
(Bruce) There will be definately sharing of the passwords, account space, and printing.
(Ray) The 'My Documents' directory is hard coded to the local cache for the roaming profile which is on the 'C' drive. There can be some loss of documents due to inproper logouts, or problems such as going over quota. Until we get the PDC supplying authentication for the NetApp, there will continue to be two problems. Win2K uses encrypted passwords, we have a work around which is to re-export the home directories using Samba. The other problem is the Service Pack 1 release breaks the Plain Text Passwords on the NetApp.
(Jim) I am not sure if the new NetApp software fixes this, but I heard the NetApp people were looking into the authentication problem with this software.

Q: (Bruce) Scott Nicoll and Bruce Campbell will be looking at a Web based e-commerce credit card to printer account transfer system to replace/augment the existing Watcard system. We will also be looking at merging the Science and Engineering databases
A: (Bruce) This does require one to be a credit card vendor. Science has already gone through the bank's approval system and is currently using VISA for the students to buy lab equipement in the Chemistry Stores.Currently, WatCard charges 5% (and has a service fee for the hardware). The credit card charges could be lower, perhaps half the WatCard rate. WatCard has done a good service, we have no complaints. This replacement system would also allow us to merge all the cash databases. Science and Engineering are to be the starting point, with other Faculties to join in if they wish. There would be no hardware involved with this Web based solution. We have not talked to the bank yet, this is only at the discussion stage right. Check the CIBC web site to see how to become an e-commerce vendor.


Information items:

(Daniel) Is there any time frame on a working Win2K lab. AHS will have a lab ready to go by next week.

(Ray) We are hoping for having a scientific software lab ready for next term. This has not been going as well as planned. Everything has slipped back by about four months.
(Bruce) To have something working, we can do.
(Ray) If you want some features, it is a question of manpower, ie. printing, password authentication, etc. We have labs, it is just the software is not ready.

(Hon) Can we have a concensus on the Active Directory privileges and OU privileges.

(Ray) Normal user should be just a normal user. !user is to have SUW in the OU. Everyone should be using the Admin userid very sparingly. We should also rename the Administrator userid to reduce any security
holes associated with it.
(Hon) Ok, agreed. Userid is user, ! is OU and !! is admin.

(Trevor) In ES we are currently having some problems with some of our printing. Graphics Printing, which now has some printers we use with Win2K have noticed some inconsistencies. If the user is not in the domain, the print server seems to change the ID to Guest. Does this name change of userid happen with LPR.

(Bruce) Does this method you are using have any authentification, if not, you are vulnerable to ID's being faked.
(Nevil) Arts will look at what we have done, we seem to have this Win2K printing working.
(Bruce) If this is the IST ID authentication, you will also have a different problem. IST is a different domain and you will have to set a password, which will be different initially.

(Ray) When looking at fixing some of the problems from the beginning of the term, it seems that Norton AntiVirus is now working better than it was. I believe that Version 6 can be put back up. Version 7 has problems, like the required disk space where the program is installed needs to have write access. I was planning on having on the Development server in the next couple of days, and later system wide.



Created by: sempson@sciborg.uwaterloo.ca 2000/10/19
Revised by: sempson@sciborg.uwaterloo.ca 2000/10/24