Bug 30835 - Exam mode: GPO template
Exam mode: GPO template
Status: CLOSED FIXED
Product: UCS@school
Classification: Unclassified
Component: Samba 4
UCS@school 3.1
Other Linux
: P5 normal (vote)
: UCS@school 3.1 R2
Assigned To: Arvid Requate
Florian Best
: interim-1
: 31584 (view as bug list)
Depends on: 31186
Blocks: 31584
  Show dependency treegraph
 
Reported: 2013-03-20 11:54 CET by Sönke Schwardt-Krummrich
Modified: 2013-06-07 21:39 CEST (History)
0 users

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments
webproxy-GPOs for IE, Chrome and Firefox: Docs and ADMX-Templates (4.85 MB, application/gzip)
2013-04-23 20:08 CEST, Arvid Requate
Details
ControlRemovableMediaDriversPreWin7_ADMX.zip (2.24 KB, application/zip)
2013-04-25 21:39 CEST, Arvid Requate
Details
Updated webproxy-GPOs for IE, Chrome and Firefox: Docs and ADMX-Templates (4.90 MB, application/zip)
2013-05-06 20:19 CEST, Arvid Requate
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Sönke Schwardt-Krummrich univentionstaff 2013-03-20 11:54:39 CET
It shall be tested if it is possible to ship templates for the GPOs gathered in Bug 30384.
Comment 1 Arvid Requate univentionstaff 2013-04-23 20:08:07 CEST
Created attachment 5189 [details]
webproxy-GPOs for IE, Chrome and Firefox: Docs and ADMX-Templates

Die ADMX-Templates für Firefox sind aktuell noch nur auf Englisch.
Anleitung im tar-Archiv: proxy/webproxy-GPO-configuration.txt
Comment 2 Arvid Requate univentionstaff 2013-04-25 12:40:45 CEST
Note: ADMX templates need to be copied to the Policies/PolicyDefinitions folder in the sysvol. The Windows Group Policy Management Console then prefers these to the ADMX templates on the local machine. Thus, this requires that all the basic Windows ADMX templates need to be copied to the server folder as well (once):

http://www.microsoft.com/en-us/download/details.aspx?id=624
Comment 3 Arvid Requate univentionstaff 2013-04-25 12:47:12 CEST
For convenience: The link to the standard Windows ADMX templates updated for Windows 8 / Windows Server 2012:
 http://www.microsoft.com/de-de/download/details.aspx?id=36991
Comment 4 Arvid Requate univentionstaff 2013-04-25 21:39:30 CEST
Created attachment 5197 [details]
ControlRemovableMediaDriversPreWin7_ADMX.zip

In Windows XP and Vista two layers are needed to lock down USB-Access:
1. Disable installed USB drivers.
   This can be done with the ADMX attached, which was converted from
   the ADM code of MS KB article 555324
2. Prevent new USB drivers to be installed.
   This requires restriction of file system permissions. I did not translate
   the required steps to german yet, but they are here:
   http://www.grouppolicy.biz/tag/usb/

The link also shows the extended GPO settings for removable media access control implemented in Windows 7.
Comment 5 Arvid Requate univentionstaff 2013-04-25 21:43:16 CEST
Btw. Maybe it would be convenient to use a uniform prefix in the UCS@school example GPO ADMX-templates (i.e. web-proxy and pre-win7-usb until now), so all the new settings can be accessed via

Computer Configuration > Policies > Administrative Templates > UCS@school > etc

This would require minor changes in the ADMX files. I guess the vbs-files don't need to be adjusted, as they only read registry keys defined by the ADMX.
Comment 6 Sönke Schwardt-Krummrich univentionstaff 2013-04-25 22:03:00 CEST
(In reply to comment #4)
> In Windows XP and Vista two layers are needed to lock down USB-Access:
> 1. Disable installed USB drivers.
>    This can be done with the ADMX attached, which was converted from
>    the ADM code of MS KB article 555324
> 2. Prevent new USB drivers to be installed.
>    This requires restriction of file system permissions. I did not translate
>    the required steps to german yet, but they are here:
>    http://www.grouppolicy.biz/tag/usb/

Does this affect all kinds of USB devices or only USB storage devices?
→ What happens when USB keyboards/mouses are plugged in?
→ Other devices: USB soundcards, WebCams, ...?
Comment 7 Arvid Requate univentionstaff 2013-04-25 23:23:10 CEST
Well,  the article, registry  key and driver name is about usb storage,  so I guess that's what is affected.
Comment 8 Arvid Requate univentionstaff 2013-04-30 19:57:44 CEST
We still need to decide about how to provide the additional ADMX templates collected here. The manual section created for Bug 30834 now refers to the original upstream projects but e.g. for FirefoxADM the converted ADMX-Templates are quite useful. We should probably also send them upstream.
Comment 9 Arvid Requate univentionstaff 2013-05-06 13:45:57 CEST
The vbs scripts from firefoxADM are not working out of the box, they seem to be  unmaintained for quite a while and do not apply to paths and concepts used in recent Firefox relases, e.g.

* still uses greprefs/all.js
* no support for x64 paths.
* the firfox_shutdown.vbs script does not clean up things properly.

It would be necessary to modify the vbs scripts according to the recommendations of http://kb.mozillazine.org/Locking_preferences
Comment 10 Arvid Requate univentionstaff 2013-05-06 20:19:26 CEST
Created attachment 5212 [details]
Updated webproxy-GPOs for IE, Chrome and Firefox: Docs and ADMX-Templates

With updated firefox_startup.vbs and firefox_shutdown.vbs scripts.
Comment 11 Arvid Requate univentionstaff 2013-05-06 21:30:37 CEST
The ADMX templates and vbs files now ship as
/usr/share/doc/ucs-school-umc-exam/examples/GPO and this path is documented in
the manual.
Comment 12 Florian Best univentionstaff 2013-05-30 14:28:52 CEST
The GPO templates exists, are working and are correctly documented.
Comment 13 Arvid Requate univentionstaff 2013-05-30 17:57:30 CEST
*** Bug 31584 has been marked as a duplicate of this bug. ***
Comment 14 Sönke Schwardt-Krummrich univentionstaff 2013-06-07 21:39:10 CEST
UCS@school 3.1 R2 has been released:
http://download.univention.de/doc/release-notes-ucsschool-3.1-rev2.pdf

If this error occurs again, please use "Clone This Bug".