Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

NT Security in an Open Academic Environment

Stanford Linear Accelerator Center (SLAC) was faced with the need to secure its PeopleSoft/Oracle business system in an academic environment which only has a minimal firewall. To provide protected access to the database servers for NT-based users all over the site while not hindering the lab's open connectivity with the Internet, we implemented a pseudo three-tier architecture for PeopleSoft with Windows Terminal Server and Citrix MetaFrame technology. The client application and Oracle database were placed behind a firewall, and access was granted via an encrypted link to a thin client. Authentication in the future will be through two-factor token cards. NT workstations in the business system unit were further secured through switched network ports and an automated installation process that included SMB signing and disabling LM Authentication in favor of NTLMv2. The hardened workstations then accessed the business system through the Citrix Secure ICA client. How these security measures affected our mixed environment (Windows9x, Samba, Transarc AFS clients, Pathworks, developers, researchers) is discussed.

Matthew Campbell, Stanford Linear Accelerator Center

Andrea Chan, Stanford Linear Accelerator Center

Robert Cowles, Stanford Linear Accelerator Center

Gregg Daly, Stanford Linear Accelerator Center

Ernest Denys, Stanford Linear Accelerator Center

Patrick Hancox, Stanford Linear Accelerator Center

William Johnson, Stanford Linear Accelerator Center

David Leung, Stanford Linear Accelerator Center

Jeff Lwin, Stanford Linear Accelerator Center

BibTeX
@inproceedings {271585,
author = {Matthew Campbell and Andrea Chan and Robert Cowles and Gregg Daly and Ernest Denys and Patrick Hancox and William Johnson and David Leung and Jeff Lwin},
title = {{NT} Security in an Open Academic Environment},
booktitle = {2nd Large Installation System Administration of Windows NT Conference (LISA-NT 99)},
year = {1999},
address = {Seattle, WA},
url = {https://www.usenix.org/conference/lisa-nt-99/nt-security-open-academic-environment},
publisher = {USENIX Association},
month = jul
}
Download

Links

Paper: 
http://www.usenix.org/events/lisa-nt99/full_papers/daly/daly.pdf
Paper (HTML): 
http://www.usenix.org/events/lisa-nt99/full_papers/daly/daly_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

LISA is a registered trademark of the USENIX Association.

  • Privacy Policy
  • Contact Us