Welcome Services Getting Started Support and Tools Documentation  
 
 

CalNetAD Planning Committee

September 18, 2003

Room 60, Barrows Hall, 2-3:30 PM

Updated: 10/22/2003

 

Agenda

 

  1. Industrial Engineering and Operations Research (IEOR) Report (Jay Sparks)

  2. School of Law Migration Report (John Weber)

  3. CalNetPKI design (Eric)

  4. Forest IPSec policy? (Eric)

  5. Microsoft System Update Service (SUS) or Windows Update GPO? (Eric)

  6. GPOs to enable the Microsoft Internet Connection Firewall? (Eric)

  7. Other Business

Notes

Industrial Engineering and Operations Research (IEOR) Report

Jay Sparks reported on the migration of IEOR into Active Directory. IEOR supports about 1,500 students in 3 labs. He explained how he utilized the services of a student to help with the move and he reviewed his OU and GPO hierarchy, folder redirection, and printing configuration. A diagram of the IEOR OU structure and GPOs is available here.

School of Law Migration Report

John Weber reported on the recent migration of Boalt School of Law into Active Directory. Law has approximately 300 faculty, 1000 students, 300 workstations, 6 servers running Windows 2000, and 1 server running Server 2003. He explained their planning process for the move; their OU structure in CalNetAD; and different aspects of the actual migration which began in June. In addition to using SAMBA, they are developing an Apache Module for AWS authentication and retrieving security group information from Active Directory for use with an encrypted cookie. John's notes are available here and a picture of their OU design is available here.

CalNetPKI design

http://calnetpki.berkeley.edu/

 

Forest IPSec policy

IPSec policy is available to block off-campus inbound Microsoft traffic.

Domain Controllers now use IPSec for replication traffic between servers.

Domain Controllers will accept IPSec communication from forest member machines.

 

Microsoft System Update Service (SUS) or Windows Update GPO?

http://windowsupdate.berkeley.edu/

 

GPOs to enable the Microsoft Internet Connection Firewall?

There was a general discussion. No decision was reached.

 

Other Business

 

 

 
Contact Us