We are currently seeing a problem with AirBears Wireless in EECS. It seems that clients are unable to get DHCP leases on AirBears. Other EECS WLANs are not impacted. IS&T has been contacted.
[Read more…] about AirBears connectivity issues
EECS IT Town Hall meeting, Feb 21st
Dear EECS Community,
Please join us for the 2007 EECS IT Town Hall meeting, sponsored by IRIS. This will be held in Woz Lounge in Soda Hall on Feb. 21st, from 1:30 to 3:30pm.
This is a good opportunity to meet all of the EECS IT Staff, learn about upcoming changes and new deployments. It’s also a great time to ask any IT related questions and give feedback.
There will be refreshments and a limited number of Star Wars themed candy (Pez) dispensers provided.
Looking forward to seeing you there,
Eric Fraser
EECS Director of IT
Please Check That Your X Window System Is Secure
Please check that your X Window system is secure.
X Windows is a networking and display protocol environment using a GUI
(graphical user interface). Common X Window servers include XFree86
and Xorg in UNIX style systems and Exceed, WinAXE, Cygwin’s Xwin on
Microsoft Windows systems.
In January 2007, it was discovered that there were keystroke logs on a
system at another University containing data from nine systems in
EECS. Eight of the systems were running various versions of the
Microsoft Windows operating system and one was running linux. We must
assume these keystroke logs contained all passwords used on these
hosts as well as all passwords used to connect to other hosts. It is
suspected that all 9 of the systems had insecure X Window Systems.
IRIS advises usng a layered approach to securing your X Window
System. Access to the X server should be controlled. Typically UNIX
style systems by default do control access to the X server, but a user
can overide the default. Typically Exceed on Windows by default allows
any remote host access to the X server; this is a bad thing.
In addition to controlling access to the X server by utilizing proper
configuration of the X Window system and using the related tools
properly, another layer of security can be added. A properly
configured host based firewall blocking unauthorized remote
access to the X server, typically 6000/tcp, is also recommended.
John Kim from the campus SNS (System and Network Security) group has
written a good knowledge base article concerning securing X Window
systems. The article contains details about configuring Exceed, the
Microsoft Windows firewall and the Symantec Client Security firewall at
https://security.berkeley.edu/node/373
It is also recommended that X traffic be encrypted for
example through an encrypted ssh tunnel.
If you need further help with securing your X Windows system please
contact your computer support person(s) or the EECS Helpdesk
(help@eecs, 395 Cory 9am-5pm, 313 Soda 10am-5pm, 642-7777).
Monthly Patches to be Applied on Wednesday, February 14th
Microsoft will release their patches for the month on Tuesday, February 13th, 2007.
HERMES, PRINT, RIS and WINSWW will be down for patching Wednesday,
February 14th, 2007, from 3:00p to 5:00p.
macserver.eecs.berkeley.edu, which hosts the Mac software warehouse,
will be down for maintenance at this time as well.
IRIS Website Will Be Offline Briefly Due to Maintenance, Tue Feb 06, 2007
The IRIS website (https://iris.eecs.berkeley.edu) will be offline for about 30 minutes on Tuesday, February 06, 2007 beginning at 12:00pm.
We will be applying operating system patches to the machine that hosts the website and will need to reboot it in order to have the patches take effect.
Downtime shouldn’t be more than the aforementioned 30 minutes and will, most likely, be much less.
[Read more…] about IRIS Website Will Be Offline Briefly Due to Maintenance, Tue Feb 06, 2007
Services problem concerning cronus & rhea
There was a problem with services from cronus & rhea
Wednesday morning, January 31, 2007 concerning direct
communication to systems on the following networks:
128.32.40.0/24
128.32.41.0/24
128.32.47.0/24
128.32.48.0/24
128.32.112.0/24
128.32.132.0/24
128.32.153.0/24
128.32.168.0/24
NIS, DNS and time services were impacted on the 8 specified networks.
We appologize for the inconvenience. Steps have been taken
to prevent a similar failure from occuring again.
Microsoft Vista Support in EECS
Microsoft has released Windows Vista to the public, but Vista will not be officially supported within the EECS department until such time as we can overcome certain licensing and technical issues.
The EECS department purchases the Windows OS and other Microsoft applications as a volume-based purchase from academic reseller TRC (now CDW-G). While we have complete OS images for other versions of Windows, our participation in the Microsoft Consolidated Campus Agreement at this time may only provide us with upgrade versions of Vista Business. To comply with our current licensing structure, a CIF-paying user would have to upgrade to Vista from a volume-licensed version of XP which has undergone Microsoft Validation. This also prevents us from offering network installation of Vista via Windows Deployment Services (WDS).
Perhaps more importantly, Vista Business edition is currently unable to mount Windows shares from our network fileservers coeus and project, meaning that Vista clients will for now be unable to mount one’s home directory or project space. IRIS staff will be working with Microsoft and Network Appliance as needed to see resolution to this issue. It is worth noting that Windows XP was not supported within EECS and had similar incompatibilities with our NetApp fileservers until XP Service Pack 1 was released.
IRIS will not be providing Vista via download or Helpdesk loan until it is ready to be officially supported within EECS. Those who have their own copy of Vista are free to use it at their own risk; we may not be able to provide direct assistance if any problems are encountered.
[Read more…] about Microsoft Vista Support in EECS
Email bouncing problem
There was a problem during the morning of Monday January 29, 2007
that resulted in some email bouncing between 07:18 and 07:54.
One of the EECS mail servers running anti-virus software failed to
properly restart the anti-virus software (01/29/2007 07:18:31)
after it downloaded an updated pattern file.
The email server in question is configured to by default report a
transient mail problem when the anti-virus software is unavailable.
We were able to reproduce the expected transient mail problem
in our testing.
For reasons that are not currently apparent, it appears the EECS
Barracuda anti-spam appliances started bouncing some email during
the 07:18 and 07:54 time period Monday January 29, 2007. We would
have expected the transient mail problem to cause the EECS Barracuda
anti-spam appliances to try to send the messages again after a short delay.
The email problem was fixed Monday January 29, 2007 07:54 am.
We hope that any senders of email to an @EECS.Berkeley.EDU address during
the relevant time period will check their bounces and send/resend an
email if appropriate.
If you sent any email to an @EECS.Berkeley.EDU address during
the relevant time period please check to see if it bounced.
We are sorry for the inconvenience.
Urgent Network Outage Tomorrow(1/31) Morning
Tomorrow morning the core switch for Cory Hall will need to be rebooted to clear up a software failure. There will be a network outage in Cory (both wired and wireless) and BWRC for about 3 min at 7:00 AM. I regret any inconvenience this may cause.
Temporary Wireless Outage in Soda/BWRC
We need to do an emergency reboot of one of the wireless controllers.
This will cause a momentary disruption in wireless service on various floors in Soda Hall and BWRC. The outages should not last more than a few minutes. Sorry for the inconvenience.