User Tools

Site Tools


strw:security_enhancements

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
strw:security_enhancements [2021/07/11 15:45] – created deulstrw:security_enhancements [2021/08/30 07:54] (current) – [Measures taken] deul
Line 1: Line 1:
 ======Security Enhancements====== ======Security Enhancements======
-In view of the recent security related events we have implemented enhanced security to our web services ti make sure we are well guarded against future malicious attacks. This page describes the measures taken and the consequences for your work.+In view of the recent security related events we have implemented enhanced security to our web services to make sure we are well guarded against future malicious attacks. This page describes the measures taken and the consequences it has for your work.
  
 =====Measures taken===== =====Measures taken=====
-In order to separate public web access facilities from internal databases, the new local.strw website is now showing static pages only. This means there is no connection between the web server scripts and any database. The pages on this web site are now generated on another well-shielded server. Each night that machine builds all pages for the local.strw site using the content of our administrative databases and places those pages in the area where local.strw can display them.+In order to separate public web access facilities from internal databases, the new local.strw website has been fully recoded and is now showing static pages only. This means there is no connection between the web server scripts and any database. The pages on this web site are now generated on another well-shielded server. Each night that server builds all pages for the local.strw site using the content of our administrative databases and places those pages in the area where local.strw can display them.
  
-Also two potentially less secure applications for displaying room allocations and an integrated calendar of events have been take off this site.+Also two potentially less secure applications, one displaying room allocations and the other displaying an integrated calendar of eventshave been take off this site.
  
-This does mean that these pages are not immediately showing changes made to our administrative environment, but show those changes one day later.+This does mean that the pages on local.strw are not immediately showing changes made to our administrative environment, but show those changes one day later
 + 
 +All administrative services have been moved to a new server: intranet.strw.
  
 =====Consequences for you===== =====Consequences for you=====
-Some of you manage information through the 'Organizational Forms'. These forms have been taken away from the local.strw web site and are moved to our secure intranet.strw.leidenuniv.nl web site. This web site, however, is not accessible from the outside world, only from the Observatory Computing environment. This means that you need to run a web browser as an Observatory intern. There are several ways to do so: +Some of you manage information, or perform resource allocation requests. through the 'Organizational Forms'. These forms have been taken away from the public local.strw web site and are moved to our secure intranet.strw.leidenuniv.nl web site. This web site, however, is not accessible from the outside world, only from the Observatory Computing environment. This means that you need to run a web browser as an Observatory intern. There are several ways to do so: 
-  * Use a [[:vnc:VNC session]] to you personal desktop+  * Use a [[:vnc|VNC session]] to you personal desktop
   * Use our [[:manuals:virtualdesktopserver|Virtual Desktop Service]]   * Use our [[:manuals:virtualdesktopserver|Virtual Desktop Service]]
   * Connect using [[:vpn|openVPN]] and make your laptop part of the Observatory Computer environment   * Connect using [[:vpn|openVPN]] and make your laptop part of the Observatory Computer environment
   * Use [[:general:windows_desktop|Tunnelier]] to your personal Windows Desktop   * Use [[:general:windows_desktop|Tunnelier]] to your personal Windows Desktop
  
-Once inside the Observatory you can access the website https://intranet.strw.leidenuniv.nl and among other pages (room allocations and the Web Calendar) you can go to the 'Organizational Form' section. These forms are exactly the same as you were used to in the situation where they were located on the old local.strw web site.+Once you are inside the Observatory, logically or physical, you can access the website https://intranet.strw.leidenuniv.nl and among other pages (room allocations and the Web Calendar) you can go to the 'Organizational Form' section. These forms are exactly the same as you were used to from the time when they were located on the old local.strw web site. This way you can continue to perform, in a much more secure fashion, the necessary administrative tasks, such as COVID registration.
  
 +The intranet site is still under active development, so if you miss functionality, please contact the helpdesk.
strw/security_enhancements.1626018348.txt.gz · Last modified: 2021/07/11 15:45 by deul