<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ben Ruset</title>
	<atom:link href="http://blog.benruset.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.benruset.com</link>
	<description>Sysadmin, etc.</description>
	<lastBuildDate>Wed, 30 Jun 2010 23:28:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Thoughts on Account Provisioning</title>
		<link>http://blog.benruset.com/2010/06/30/thoughts-on-account-provisioning/</link>
		<comments>http://blog.benruset.com/2010/06/30/thoughts-on-account-provisioning/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 23:26:30 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=209</guid>
		<description><![CDATA[A few weeks ago I gave an interview with VPNHaus (part 1) (part 2), regarding account provisioning in the enterprise. I'm writing this as a follow-up to the interview to discuss the issues in greater detail. First of all, account provisioning is probably one of the most crucial but utterly boring parts of IT. From [...]]]></description>
			<content:encoded><![CDATA[<p>A few weeks ago I gave an interview with VPNHaus (<a href="http://vpnhaus.ncp-e.com/2010/06/10/provisioning-qa-with-ben-ruset-princeton-university/" target="_blank">part 1</a>) (<a href="http://vpnhaus.ncp-e.com/2010/06/17/provisioning-qa-with-ben-ruset-princeton-university-part-2/" target="_blank">part 2</a>), regarding account provisioning in the enterprise. I'm writing this as a follow-up to the interview to discuss the issues in greater detail.</p>
<p>First of all, account provisioning is probably one of the most crucial but utterly boring parts of IT. From the perspective of the systems administrator it's a matter creating the user record and figuring out what sort of access they need to enterprise resources. In many places it's a mater of click, click, type, click, click and then press the OK button. For the new user, this will probably be the first introduction they have to the IT organization.</p>
<p>Since IT doesn't do the hiring for the company, this data needs to come from somewhere. That's where HR comes in. HR provides things such as the proper spelling of the user's name, whether they will need remote access to the network (ie: VPN), and a general overview of what the user will need rights to. Again, this is another entry level, boring task that generally requires someone to fill out a help request and then let IT deal with it.</p>
<p>I've seen, though, in many organizations where there's a breakdown in the communication that IT gets from other parts of the organization, particularly HR. The standard operating procedure at one place that I worked was that IT was informed that there was a new employee on their first day. This resulted in a mad dash to provision an account as well as provide basic resources such as a computer, phone, or in some cases even a desk.</p>
<p>Now, what happens when an employee leaves? IT is usually insulated from the rest of the organization either physically or logically, so again the request to terminate access needs to come from HR. In smaller organizations this is less of a problem because generally people will hear about a departure through the grapevine. This isn't a hard and fast rule, though. In a company of less than 50 employees I'd sometimes not be told of a departure until after the fact.</p>
<p>This presents a problem because if IT takes it upon itself to delete a user that it thinks should be deleted there's a risk that important data could be lost, or that the user has a legitimate need to retain access for one reason or another. On the other hand, if IT decides to do nothing, there's a vector for attack where, depending on the circumstances of the employees departure, they might have a motive to use the enterprises resources maliciously.</p>
<p>All this leads to the need to have strong policies in place that dictate the workflow of a user request. This is a policy that both HR and IT need to agree to, and it needs to be efficient, effective, and enforceable. Unfortunately this seems to not happen in many small to medium sized business, and if nobody knows to do anything the user walks into their first day on the job not having an email address, a login, or even a computer. By creating a workflow, there's the ability to first deliver correct information on time and provide accountability across all of the steps needed to create the account.</p>
<p>For example, the company hires a new salesperson. Presumably there will be at least a two week lead-time before they join the company. HR then fills out a request for the new account, supplies the correct spelling of the user's name, provides whatever other information is needed by IT such as contact information and necessary access levels. IT then should, with some measure of expediency, fulfill the request and confirm with HR that the account has been provisioned.</p>
<p>The process should be similar when the employee leaves. HR should notify IT that there's a departure and fill out a request to have the account disabled. Depending on the circumstances of the departure it might be necessary to escalate that to a higher priority level, or let IT know about any special requests (ie: do not delete but disable the account, forward email somewhere, etc.) IT then should expediently handle the request and again confirm with HR that the request has been completed.</p>
<p>While many folks in the trenches (including myself) bemoan the fact that IT is a "service organization," it is one that can only do it's job efficiently when given good data and good policies to follow. For the organization to work efficiently, there needs to be clear instructions and expectations on what to do, how to do it, and when. Sadly it seems that these common-sense policies generally come into effect well after there have already been issues that could have been prevented.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2010/06/30/thoughts-on-account-provisioning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clean Server Room</title>
		<link>http://blog.benruset.com/2009/11/05/clean-server-room/</link>
		<comments>http://blog.benruset.com/2009/11/05/clean-server-room/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 03:39:45 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=195</guid>
		<description><![CDATA[I spent the better part of today going through the server room and cleaning out years of accumulated junk that had been thrown in there. Highlights include: 100+ DLT backup tapes, all headed to the degausser on campus 30 heavy gauge power cables from various servers Norton Internet Security 2004, never opened Office 2000 Tons [...]]]></description>
			<content:encoded><![CDATA[<p>I spent the better part of today going through the server room and cleaning out years of accumulated junk that had been thrown in there.</p>
<p>Highlights include:</p>
<ol>
<li>100+ DLT backup tapes, all headed to the degausser on campus</li>
<li>30 heavy gauge power cables from various servers</li>
<li>Norton Internet Security 2004, never opened</li>
<li>Office 2000</li>
<li>Tons and tons and tons of empty boxes.</li>
</ol>
<p>The goal? To make it so that when I need to retreat away from the noise of my office and actually get some work done, I have a place to go that not only has a door, but a door protected by a mag reader. And, if I position myself close enough to the Liebert (which is where the table is in the room) I don't get blown on. The ambient temperature of the room is about 74 F which isn't bad, and the noise from the servers is at least better than listening to people talking loudly.</p>
<p>Oh, and Jae is a jerk.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/11/05/clean-server-room/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Productive at Work</title>
		<link>http://blog.benruset.com/2009/11/02/productive-at-work/</link>
		<comments>http://blog.benruset.com/2009/11/02/productive-at-work/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 03:30:13 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Ben]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=193</guid>
		<description><![CDATA[Over the last few days I've setup Dell Openmanage and finished tweaking our install of IPMonitor. Now, when a service goes down or there's a hardware failure I'll get an email notifying me. You'd think that this would have been setup before, but my predecessor apparently just scheduled weekly walkthroughs of the two datacenters to [...]]]></description>
			<content:encoded><![CDATA[<p>Over the last few days I've setup Dell Openmanage and finished tweaking our install of IPMonitor. Now, when a service goes down or there's a hardware failure I'll get an email notifying me. You'd think that this would have been setup before, but my predecessor apparently just scheduled weekly walkthroughs of the two datacenters to look for amber lights on the servers.</p>
<p>Tomorrow's project will be configuring tighter rules for alerting that will go right to my phone via a text message (I only want the really critical errors to come there) as well as automatically open up a helpdesk ticket. I also began sketching out a new server inventory which I will need to put into Sharepoint along with some other documentation.</p>
<p>It's a fairly slow time right now, and since I've gone to work in academia I've really enjoyed the ability to set things up the right way, rather than rush from fire to fire like I had to do in startup-land. That's not to say that I don't miss some of the fun of being in a startup - I worked with some absolutely brilliant people at Grid, and I really miss spending time with them and having debates and conversations about tech.</p>
<p>I also found a piece of software which, so far, has helped me a lot. My desk is right outside of the office that the desktop support folks work out of, and there's a lot of traffic in and out of there. It's very distracting to be troubleshooting some server or network problem and hear people BS'ing with the desktop folks. Since my desk is actually in a really nice space (although it's a bit small) and there's political reasons why I can't move into an office, it's become imperative that I find some way of isolating myself. Well, besides the big frosted Japanese privacy screen that I set up in front of my cube, I found an OSX White Noise Generator, <a href="http://code.google.com/p/noisy/">Noisy</a>. I have it set to generate <a href="http://en.wikipedia.org/wiki/Pink_noise">pink noise</a> at about 10% of my iMac's volume. It's a small app that I just keep open on my second monitor and jack up the volume if someone starts talking loudly or I really need to focus.</p>
<p>I still miss working with Jae, even if he was noisy.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/11/02/productive-at-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New stuff at www.BenRuset.com</title>
		<link>http://blog.benruset.com/2009/10/21/new-stuff-at-www-benruset-com/</link>
		<comments>http://blog.benruset.com/2009/10/21/new-stuff-at-www-benruset-com/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 03:40:03 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Ben]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=189</guid>
		<description><![CDATA[Just made a quick page for www.BenRuset.com. Has a nice minimalist feel to it. The picture is of my Touareg (the 'egg) at the Forked River Mountains.]]></description>
			<content:encoded><![CDATA[<p>Just made a quick page for <a href="http://www.benruset.com">www.BenRuset.com</a>. Has a nice minimalist feel to it.</p>
<p>The picture is of my Touareg (the 'egg) at the Forked River Mountains.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/10/21/new-stuff-at-www-benruset-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux-like bash prompt in OSX</title>
		<link>http://blog.benruset.com/2009/09/18/linux-like-bash-prompt-in-osx/</link>
		<comments>http://blog.benruset.com/2009/09/18/linux-like-bash-prompt-in-osx/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 18:13:02 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=185</guid>
		<description><![CDATA[For those of us who use bash on our MacOSX boxes as well as Linux (at least RedHat systems) and are annoyed that OSX's bash prompt doesn't look like Linux's, adding these lines to your .profile will fix it. This will enable color for ls as well as change the actual prompt to match RHEL's. [...]]]></description>
			<content:encoded><![CDATA[<p>For those of us who use bash on our MacOSX boxes as well as Linux (at least RedHat systems) and are annoyed that OSX's bash prompt doesn't look like Linux's, adding these lines to your .profile will fix it. This will enable color for ls as well as change the actual prompt to match RHEL's.</p>
<p>Add these lines to the top of your .profile:</p>
<blockquote><p>export PS1="[\u@\h \W]$"<br />
export CLICOLOR=1<br />
export LSCOLORS=ExFxCxDxBxegedabagacad</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/09/18/linux-like-bash-prompt-in-osx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Book Forward</title>
		<link>http://blog.benruset.com/2009/09/16/book-forward/</link>
		<comments>http://blog.benruset.com/2009/09/16/book-forward/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 02:17:51 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Ben]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=183</guid>
		<description><![CDATA[I was just asked to write the forward to another book. Going to have to get cracking on that this week. Goes into print really, really soon.]]></description>
			<content:encoded><![CDATA[<p>I was just asked to write the forward to another book. Going to have to get cracking on that this week. Goes into print really, really soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/09/16/book-forward/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iTunes U is Pretty Awesome</title>
		<link>http://blog.benruset.com/2009/09/15/itunes-u-is-pretty-awesome/</link>
		<comments>http://blog.benruset.com/2009/09/15/itunes-u-is-pretty-awesome/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 15:25:47 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=181</guid>
		<description><![CDATA[Just a quick blog to bring people's attention to it. iTunes 9 has been released and Apple is trying to get people to check out the material in iTunes U. For those who don't know, these are lectures from various universities in "podcast" form. I put the word "podcast" in quotes since they seem to [...]]]></description>
			<content:encoded><![CDATA[<p>Just a quick blog to bring people's attention to it. iTunes 9 has been released and Apple is trying to get people to check out the material in iTunes U. For those who don't know, these are lectures from various universities in "podcast" form. I put the word "podcast" in quotes since they seem to act more like plain mp3's than actual podcasts on the iPhone.</p>
<p>There are two courses on iTunes U that I'd like to recommend. Both come from <a href="http://www.stanford.edu" target="_blank">Stanford University</a>, and both really tie in to my love of history. The first is <a href="http://deimos3.apple.com/WebObjects/Core.woa/Browse/itunes.stanford.edu.1948870601" target="_self">Colonial and Revolutionary America</a>, a series of lectures by <a href="http://en.wikipedia.org/wiki/Jack_rakove" target="_blank">Jack Rackove</a>, which examines the political and sociological environment in the colonies before, during, and shortly after the Revolution. The second, which I have only just started yesterday, is <a href="http://deimos3.apple.com/WebObjects/Core.woa/Browse/itunes.stanford.edu.1291405182">The Historical Jesus</a>, by <a href="http://www.stanford.edu/dept/relstud/faculty/sheehan/Sheehan.html" target="_blank">Thomas Sheehan</a>, which takes a scholarly look at the life of Jesus the man, not the figure that the early Christians made him into.</p>
<p>It's nice to see Apple starting to publicize iTunes U. There's content from all sorts of educational institutions. I'd like to see some stuff from Princeton end up online.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/09/15/itunes-u-is-pretty-awesome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2007 NJ High Res Orthos &#8211; now on maps.njpinebarrens.com</title>
		<link>http://blog.benruset.com/2009/04/15/2007-nj-high-res-orthos-now-on-mapsnjpinebarrenscom/</link>
		<comments>http://blog.benruset.com/2009/04/15/2007-nj-high-res-orthos-now-on-mapsnjpinebarrenscom/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 15:00:54 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Pine Barrens]]></category>
		<category><![CDATA[Tech]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=173</guid>
		<description><![CDATA[Thanks to Doug over at the NJ State Office of Information Technology I was able to come up with a valid connection string for the new WMS server at the NJOGIS. I've added the new 2007-2008 high resolution orthography to maps.njpinebarrens.com. Enjoy, if you're into that sort of thing!]]></description>
			<content:encoded><![CDATA[<p>Thanks to Doug over at the NJ State Office of Information Technology I was able to come up with a valid connection string for the new WMS server at the NJOGIS. I've added the new 2007-2008 high resolution orthography to <a href="http://maps.njpinebarrens.com" target="_blank">maps.njpinebarrens.com</a>.</p>
<p>Enjoy, if you're into that sort of thing!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/04/15/2007-nj-high-res-orthos-now-on-mapsnjpinebarrenscom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win2k3 Server Migration</title>
		<link>http://blog.benruset.com/2009/04/08/win2k3-server-migration/</link>
		<comments>http://blog.benruset.com/2009/04/08/win2k3-server-migration/#comments</comments>
		<pubDate>Wed, 08 Apr 2009 14:23:43 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=168</guid>
		<description><![CDATA[At work I have a Windows 2003 server running on a Dell Poweredge 2650 that's just fallen out of warranty. I have a brand new Dell Poweredge 2950 that I want to bring up as a replacement. The thing is, I don't want to have to manually create the 200+ file shares, 400+/- local groups, [...]]]></description>
			<content:encoded><![CDATA[<p>At work I have a Windows 2003 server running on a Dell Poweredge 2650 that's just fallen out of warranty. I have a brand new Dell Poweredge 2950 that I want to bring up as a replacement. The thing is, I don't want to have to manually create the 200+ file shares, 400+/- local groups, and permissions on the new box. It'd be so easy to P2V the old server and turn it into a VM, but that's not an option here. So, I figured out a pretty halfway decent way to image the server over using free tools.</p>
<p>The long and short of it is that, on the old server, you need to load the drivers for the new RAID controller. You'll have to do it manually. (Add new hardware, have disk, etc.) Then I took a CentOS 4.7 rescue disk, booted it, and DD'd the disk over to an image file on an NFS share (my iMac). Then on the new server, boot the CentOS rescue disk, dd the image from NFS to the local disk, and reboot.</p>
<p>Windows comes up, and will complain about needing to find new drivers for everything. But the server is now running on new hardware. Sweet. Linux to the rescue in a Windows shop!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2009/04/08/win2k3-server-migration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Goodbye 2008</title>
		<link>http://blog.benruset.com/2008/12/31/goodbye-2008/</link>
		<comments>http://blog.benruset.com/2008/12/31/goodbye-2008/#comments</comments>
		<pubDate>Thu, 01 Jan 2009 01:22:38 +0000</pubDate>
		<dc:creator>Ben Ruset</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.benruset.com/?p=164</guid>
		<description><![CDATA[As the year winds down I figured it would be a good time to make a new blog post. I have been rather lax about posting here, spending most of my time on Facebook instead. In a few days I will be starting my new job as a Senior Sysadmin for Facilities IT at Princeton [...]]]></description>
			<content:encoded><![CDATA[<p>As the year winds down I figured it would be a good time to make a new blog post. I have been rather lax about posting here, spending most of my time on Facebook instead.</p>
<p>In a few days I will be starting my new job as a Senior Sysadmin for Facilities IT at Princeton University. I'm looking forward to the change in scenery. I leave behind a lot of friends and good memories at my last job. Despite Matt saying that I am now banned from New York I'm sure they'll see me again. Besides, if they ban me than New Jersey needs to ban all the bennies coming down from Staten Island during the summer.</p>
<p>My plans for launching the redesigned NJPB site in time for 1/1/09 probably won't come to fruition thanks to some distractions today. It was worth it, though.</p>
<p>In any event, here's to a great 2009!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.benruset.com/2008/12/31/goodbye-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
