Educause Security Discussion mailing list archives

Re: How to Protect Campus Sensitive Servers


From: Pete Hickey <pete () SHADOWS UOTTAWA CA>
Date: Thu, 4 Feb 2010 09:27:13 -0500

On Thu, Feb 04, 2010 at 09:00:45AM -0500, schilling wrote:

We propose a one central Information Technology Services(ITS) VPN
profile which could have access to all the resources, all employee in
ITS will have access to this VPN group.  Then In all the servers, host
based user/group authentication/authorization will decide whether a
user can login or what to do.

Defense in depth, as they say.  This is putting all your eggs in one
basket, by only depending on the host.  As time goes on and things grow,
this type of thing does not scale well.

--
Pete Hickey
The University of Ottawa                           No single raindrop beleives
Ottawa, Ontario                                    it is responsible
Canada                                             for the flood.

Current thread: