Waterloo Nexus Advisory Group minutes January 19, 2005

Present

Departments Advisor names
Arts
Nevil Bromley
Applied Health Science (AHS)
Lowell Williamson (secretary)
Computer Science
Steve Nickerson
Environmental Studies (ES)
Shawn Morgan
ESAG Peter Routledge
Math Jim Johnson
Science
Steph Sempson
Engineering Computing
Bruce Campbell
  Stephen Carr
  Erick Engelke
Information System and Technology (IST)
Ray White
  Tim Farrell

GPO manipulation

  • GPOs have retained Domain Admin priviledges
  • Proper permissions did not filter through AD
  • Hon had to assign manually
  • GPMC can be used to copy and to create a link to a GPO
  • Total of 500 GPOs in AD, 3GB

Meeting times

  • Standard time and place for meetings agreed upon (Tim)

Faculty procedures

  • Stephen hoped to standardized/harmonize procedures between faculties
  • Password Synching w/ Quest to be investigated (Bruce)

Use of ! & !!

  • Current procedures, using ! whenever and wherever possible, are working well
  • Two stage process to move users in AD from Faculty to Faculty
  • Single stage for computers
  • Mike Herz's password policy, to force changes for administrators (Erick reports)
    • Option #1 - change password force date
    • Option #2 - cronjob to email when password hasn't been changed
  • WMI
    • Concern about security hole and password hacking

Workstation compromise

  • PC in Electrical Engineering
  • Windows 2000 infected with dameware
  • Injected *.dll into AD process and produced userids and hashcodes

System logging

  • Logs to be web accessible for workstations (action by Paul McKone)
  • Erick to work on syslog method and new model
  • Question of Security vs. Privacy

Other business

  • Engsus synching with engsus2 so that SP2 is deployed
  • Cerberus
    • Erick to 'guarantee' file types & signing of files
    • ngina.dll generates dll list and authenticates then addin to DCs
    • Impossible to inject into process
    • Trying to cache thread instead which is to be done on the domain