Businesses

On Taking a Configuration Management Position? 28

Bravo_Two_Zero asks: "I've recently been offered a Configuration Management position as a lateral (with a slight incline) move. I'm darn happy as an admin, and my heart really lies with system engineering rather than the more mundane operational concerns. But, the position is new, so I would have a chance to define many parameters. Also, it could lead to a management opportunity (if I'm interested) much faster than my current admin slot. It's a hideously complex environment, but I already live through that as an admin. Mileage will vary widely, I know, but I was hoping there might be a school of thought or two from some devoted Slashdot readers who perform or have performed the position. What did you do, and what would you change? And, to the broader audience, is this something you think of as a growth field, or is this just another layer of administrivia foisted on us by an unrealistic development model? Is there a book or other resource that professional Configuration Managers consider a must-read?"
Security

How Would You Distribute Root Access? 148

dhanks asks: "I'm one of 10 administrators in our group. We're equally responsible for about 300 UNIX servers. We're having problems keeping track of all the root passwords and some of the administrators have taken it upon themselves to implement different security standards. (sudo with silly !SHELLS restrictions) How do other companies and system administrators handle the distribution of root access? I've been charged with coming up with a security policy and I would like to receive some feedback. I'm currently thinking of personal root accounts that would be locked via the /etc/passwd and would only be accessible via 'sudo su - adm_userid' that way each administrator may have full root access only using his regular user password instead of having to keep track of root passwords." While this is similar to an earlier question, this question deals with insuring authorized administrators have the access they need. How would you distribute root over hundreds of Unix machines to the administrators that need it?
Businesses

Corporate Work in the US vs. Canada? 1309

No One You Know asks: "I've been working as a sysadmin for an insurance company in the US for the past six years, and have decided to move to Canada. I've had it with corporate America, but I'm trying to keep an open mind while job hunting. How does Canadian corporate life compare to that of the US?"
Education

How Prevalent are Bogus Degrees? 141

Paul Townend asks: "The BBC are reporting that a US government investigation has found that 28 top federal employees possess bogus college degrees (usually based on 'life experience'), and the phenomenon may be much bigger. Have Slashdot readers come across or worked with people with such degrees? Does it give them an advantage? What happens when they're discovered?"

NIST Validation Of OpenSSL Algorithms 19

An anonymous reader submits "On Monday, May 10, 2004, the National Institute of Standards and Technology (NIST) posted a notice that the AES, DES, 3DES, DSA and SHA-1 algorithms for OpenSSL have been validated. The validation notices can be found at the following NIST sites: Advanced Encryption Standard (AES) Algorithm (Certification # 146); Data Encryption Standard (DES) Validated Implementations (Cert # 258); Triple Data Encryption Algorithm (TDEA, a.k.a. "Triple DES"): (Cert # 256); Digital Signature Algorithm (DSA) Validation System: (Cert # 108); Secure Hash Algorithm (SHS) Validation System: (Cert # 235). Successful validation of these algorithms does NOT mean that OpenSSL has received FIPS 140-2 validation, yet. The overall FIPS 140-2 validation effort for OpenSSL is still in process. Additional updates will be posted on the OSSI web site, www.oss-institute.org. NIST validation of these algorithms does, however, signify a major milestone in OSSI's efforts to secure the FIPS 140-2 validation for OpenSSL. Please post any questions that you might have to questions@oss-institute.org."
Communications

Does Anyone Actually Use a "Smartphone"? 101

jm2morri asks: "I am currently in the market for a new cell phone and while I'm at it I'd really like to combine my PalmOS based PDA into my new cell phone. I'd really like to keep PalmOS based so that I can sync with my wife who has a PalmOS based PDA as well. However I don't want a camera since there are new security laws being written, as I type this, to restrict the use of camera-phones. Has anyone used one of the smartphones on the market? What is the voice quality like? How often does it crash? Do you have any other observations?"
Media

Security Camera-to-DVR Setup on Linux? 36

mrperkins asks: "I have been asked to help a friend setup a Linux DVR (Digital Video Recording) system for security cameras. Previously this has been done on Windows XP using Avermedia video capture cards from the MP3000 and MP5000 series, and using their bundled software. They have a Linux version but the software is horribly broken. The Windows software allows playback/recording/backup from 4-16 cameras. This works reasonably well but certainly has it's share of problems - the PC's hardware being only one. Can this be done on Linux using Free Software and compatible hardware? I have heard that the frame rates achievable under video4linux are simply too slow, but I would like to prove otherwise! Are there any software packages that can do this kind of thing (not just a single stream but a fully featured package)? Also, what cards (pref. up to max $200US) would you recommend? If anyone is already doing this kind of thing please let me know what you're using!"
Security

Kinder, Gentler Security Scans? 54

klausner asks: "I'm working at a large company that is trying to be more thorough about things like network security scanning. When Security told Operations they were planning to do this, there were immediate screams of anguish, and insistence that scans could only be done in the maintenance window, only with prior notice, and with a bunch of other restrictions. Needless to say, this is less than ideal. Given the size of the network, it would take weeks to do a single scan set. However, it is reasonable to take steps to ensure that the scans do not interrupt business traffic, or cause undesirable side effects like crashing target systems. What sort of limits are the readers out there using to ensure safe scanning? Limiting the bandwidth to a fixed percentage? Limiting the number of simultaneous tests? What other kinds of things can I do to limit the scans effect on network performance?"
Privacy

Privacy in the Woods? 824

Rorschach1 asks: "I work with a local Search and Rescue team, and for some time I've been thinking about the possibility of installing sensors at a few critical trail junctions in the local back country. The sensors would detect passing hikers and report timestamps to an Internet gateway in near real-time. When a hiker goes missing, this information could be very valuable in determining where search efforts should be directed. However, I've spent enough time on Slashdot to know that whenever you start monitoring or tracking people and their activities, someone's going to get upset. So I'd like to hear from the tinfoil hat brigade - what are your objections to such a system, and how might your concerns be addressed?"
Music

Music Related Free and Open Source Software? 37

An anonymous reader asks: "I'm going to a demonstration of some music software products tomorrow night. The music store hosting the event may be attempting to start a users group of music software. This seems like a job for open source advocacy! Anyone know of any good F/OSS for working with music and audio? I am already aware of Audacity and (Free as in Beer) Jeskola Buzz, but what else is there in the realm of sequencers and audio manipulation?" We did another helpful article back in 2001, and another from last August. What musical creations have you put together with any of this software, and others we may have missed?
Hardware

How to Protect a Network Against Lightning? 120

RichiH asks: "The monsoon, started about a month early in India this year. While it is not sure if that is due to global warming or not, there are more pressing issues for the IT world at hand. Until about the end of July, there will be major thunderstorms in this area. How do you protect a network that is spread over 100 square kilometres in a land where the concept of a lightening arrestor is next to unknown? The network in question consists of about 2500 boxes of various kinds which are connected using 10BASE2 (aka BNC), 10BASE-T (aka RJ45) and 10BASE5 (aka thicknet), where only the last one may be new to some readers. The big question is: how can you protect yourself against these storms in a way that is both fast to implement and does not require laying of new lines?"
Communications

Non-English Programming Languages? 191

jjohnson asks: "As a coder I've been exposed to a lot of programming languages, big and small, and they're all in (pseudo) English, reflecting their invention and development in English speaking countries (or to gain traction in English speaking countries, such as Ruby). Of course, there's no reason a programming language couldn't be developed in Russian, using a cyrillic character set; or Chinese, using kanji; or Japanese, using hiragana. All three of those nations have big/advanced enough developer communities to justify the development of native-tongue programming languages, which have the obvious benefit of not requiring their developers to learn/code in a foreign language. What non-English programming languages exist, and how do they compare?"
Hardware

ACPI and S3 Sleep on the Linux Desktop? 104

niko9 asks: "After reading that development would be ramped up in the ACPI department of the 2.6 kernel series, I was hoping to finally get the one feature that Mac and Windows users have been enjoying for more than a few years: S3 Sleep, also known as Suspend-To-Ram. How important is ACPI and the sleep states on the desktop to you? Are there any ACPI S3 success stories on the Linux desktop out there? If yes, what hardware are you guys using? I would also welcome comments from Mac and Window users concerning their use of sleep on the desktop."
Programming

What's the Right Way to Accept Donations? 46

Schapht asks: "Not long ago, SourceForge.net started offering users and projects the ability to accept donations. But there doesn't seem to be much information on the legal implications of accepting donations. Should open source projects start registering themselves as businesses? Would there be fines if they didn't? Are there any options for a project that can't afford the processing fees involved in registering a business?"
Privacy

Locally Secure Email Clients? 77

Mattcelt asks: "I share my PC with my roommates, two of whom don't have their own PCs. In order to keep things simple, I have Windows98 running on it - they are used to the interface; it runs the programs they need to run from the University; and I refuse to pay the money to Microsoft to upgrade to a newer Windows OS. Unfortunately, there are some issues with privacy, and though I trust my roommates, there are work-related things I wouldn't want them to stumble into. Has anyone seen an email client other than Outlook that has -local- file security? Outlook has a feature to allow the password protecting of .pst files on the local drive, but it seems that every other email client figures that once the mail is on your machine, you don't need it protected any longer. Is there another email client with integrated password protection?"

Slashdot Top Deals