|
> facilities
> facilities information: research group management of their own
systems
Researchers can also manage machines
themselves. If you manage a machine yourself, the machine needs to be
secure and the operating systems need to be up-to-date. The following
guidelines apply.
Unix
- Research groups will not be allowed to mount dtc file systems on machines that they manage. (If this was permitted, one could easily gain access to everyone's files.) In addition to file systems for storage, this also means you will not have access to DTC software on your local machine.
- Research groups will be responsible for the software licenses for the software used on their machines.
- Research groups will need to use a local password file and separate accounts on the local machine.
- It is expected that research groups will run relatively current versions of the OS, security patches and ssh. If someone does break into the machine and causes problems, the group's systems will be disconnected from the network.
- To minimize the risk of unauthorized access to your systems, all non-necessary services such as telnet and ftp need to be turned off (use ssh instead).
- There will be periodic scans of the machines for security problems. The DTC staff will work with OIT, who performs the scans. Research groups will be expected to correct the problems that are identified.
- Researcher groups will be asked to provide a machine name. The DTC staff will then issue an IP address.
Windows/Macintosh
- Research groups will not be allowed to mount dtc file systems on machines that you manage.
- Research groups will need separate accounts on the local machine.
- It is expected that research groups will maintain relatively current versions of the OS security patches. This includes any critical Microsoft or Apple updates. If someone does break into the machine and causes problems, it will be disconnected from the network.
- In addition, virus protection software needs to be installed with up-to-date virus definitions. Symantec Norton Anti-Virus software for both Windows and Macintosh are available at no cost from ADCS: http://www1.umn.edu/adcs/help/virus/
- There will be periodic scans of the machines for security problems. The DTC staff will work with NTS, who performs the scans. Research groups are expected to correct the problems that are identified.
- You will be asked to provide a machine name. The DTC staff will then issue an IP address.
- Research groups that are utilizing any server software (NT Server, 2000 Server, OS X Server, Appleshare IP) are requested to notify the DTC staff. These machines will also require current OS and application patches.
The DTC staff will be available for consultation to those who choose to manage their own systems.
|