Educause Security Discussion mailing list archives

Re: Mac connection brokering solution


From: "Pete, Andrew" <000000d06e28c017-dmarc-request () LISTSERV EDUCAUSE EDU>
Date: Mon, 16 Mar 2020 14:01:51 +0000

Unfortunately something like that isn’t feasible or scalable for our needs.  Unless we had a machine to dedicate to 
each student, which we do not, it would be a nightmare to manually work out access across multiple classes and 
classrooms.  We need something that will broker access to a pool of available machines much like the brokering in 
Horizon or XenApp/XenDesktop.

From: William Enestvedt <William.Enestvedt () jwu edu>
Sent: Monday, March 16, 2020 9:40 AM
To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
Cc: Pete, Andrew <apete () neit edu>
Subject: Re: [SECURITY] Mac connection brokering solution


This message originated outside of New England Institute of Technology. Use caution when opening attachments, clicking 
links or responding to requests for information.
What about a VNC implementation, if they have VPN access to your network? Here's one:
    https://www.realvnc.com/en/connect/security/

   They would need VPN access and the IP address of the desired system, I think. Here's their article about MFA and in 
general how authentication works:
    
https://help.realvnc.com/hc/en-us/articles/360002250077-Introduction-to-Multi-Factor-Authentication-#protecting-your-remote-computers-running-vnc-server-0-1

   (ObDisc: no connection, I just know that VNC is a thing and this came up searching Google for "macos vnc secure".)

- Will
--
Will Enestvedt
Unix Team Manager & Data Center Services Manager
Johnson & Wales University, Providence, RI

From: EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of 
"Pete, Andrew" <apete () NEIT EDU<mailto:apete () NEIT EDU>>
Reply-To: EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Date: Monday, March 16, 2020 at 9:13 AM
To: EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: [SECURITY] Mac connection brokering solution

I’m trying to find a solution that could be used to grant remote access for faculty and students to the Mac endpoints 
in our classrooms.  We have a mix of software that can only be installed or accessed from our campus.  On the Windows 
side, we have an existing Horizon deployment which has the ability to grant access to physical Windows machines but 
this is not available on Mac OS.  I did some research last week and there appears to be a void in this type of solution 
when it comes to Macs.  The closest thing that I could find was Aqua Connect which is a terminal server solution for 
Mac.  We have some rather intensive applications and would need to grant faculty/students access to dedicated desktops 
so a terminal server solution isn’t going to perform well for our needs.

Andrew Pete
Information Security Architect

New England Institute of Technology
One New England Tech Boulevard
East Greenwich, RI 02818-1205
401-780-4460 (Direct)
apete () neit edu<mailto:apete () neit edu>


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: