<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
    <channel>
        <title>Applied Information Technologies</title>
        <link>http://ait.its.psu.edu/</link>
        <description></description>
        <language>en</language>
        <copyright>Copyright 2013</copyright>
        <lastBuildDate>Wed, 13 Mar 2013 10:53:53 -0500</lastBuildDate>
        <generator>http://www.sixapart.com/movabletype/</generator>
        <docs>http://www.rssboard.org/rss-specification</docs>
        
        <item>
            <title>ITS Alerts Unavailable</title>
            <description><![CDATA[<p>
On Monday, March 11, 2013 at 6:27 p.m., AIT staff disabled the <a href="http://alerts.its.psu.edu/">ITS Alerts</a> website to prevent further exposure of a security vulnerability discovered earlier that day.  In its place, a static placeholder page was added to give status information as to the progress of service restoration.
</p><p>
By 5:10pm, Tuesday, March 12, the rss files had been restored.
</p><p>
The security vulnerability was a form of SQL injection.  While a previous attempt at defeating SQL injection of end-client inputs had been installed, it was deemed insufficient against modern methods, and the site was taken down while a more suitable correction could be installed.
</p><p>
Analysis revealed that while a remote system made an attempt to verify the vulnerability,
no data had been disclosed; any data that would have been disclosed was either public information, or otherwise not sensitive.  Further, the SQL injection vector did not have permission to modify any data due to least privilege policy.
</p><p>
When the service is restored, all original functionality and data will be intact, except for, of course, the vulnerability.
</p><p>
Please view the <a href="http://alerts.its.psu.edu/">ITS Alerts</a> site for updates as they become available.
</p>
<p>
Addendum (2013/Mar/13 1:07 p.m.): <a href="http://alerts.its.psu.edu/alert-2633">alert-2633</a> was created as the permanent alert message describing this service outage.
</p>]]></description>
            <link>http://ait.its.psu.edu/2013/03/its-alerts-unavailable.html</link>
            <guid>http://ait.its.psu.edu/2013/03/its-alerts-unavailable.html</guid>
            
            
            <pubDate>Wed, 13 Mar 2013 10:53:53 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>Dirapps Certificate Change on March 7, 2013</title>
            <description><![CDATA[<p>On March 7, 2013, the dirapps.aset.psu.edu certificate will be updated, per ITS Alert #2617 <a href="http://alerts.its.psu.edu/alert-2617">http://alerts.its.psu.edu/alert-2617</a>. The certificate authority is changing from Thawte to Comodo.</p>]]></description>
            <link>http://ait.its.psu.edu/2013/02/dirapps-certificate-change-on-march-7-2013.html</link>
            <guid>http://ait.its.psu.edu/2013/02/dirapps-certificate-change-on-march-7-2013.html</guid>
            
            
            <pubDate>Thu, 28 Feb 2013 13:26:41 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess: Registrations suspended 12/21-1/3</title>
            <description><![CDATA[<p>WebAccess registrations received after 5 p.m. on Thursday, Dec. 20,
will not be processed until Friday, Jan. 4, 2013.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/12/webaccess-registrations-suspended-1221-13.html</link>
            <guid>http://ait.its.psu.edu/2012/12/webaccess-registrations-suspended-1221-13.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Thu, 13 Dec 2012 22:30:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess QA follow-up: new hostname/port number</title>
            <description><![CDATA[<p>For the QA service, the old hostname/port combination (cosign.aittest.psu.edu/6663) have been shut down.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/09/webaccess-qa-follow-up-new-hostnameport-number.html</link>
            <guid>http://ait.its.psu.edu/2012/09/webaccess-qa-follow-up-new-hostnameport-number.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Wed, 26 Sep 2012 17:57:07 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess: old hostname and port being shut down 2013/1/2</title>
            <description><![CDATA[<p>On January 2, 2013, the WebAccess old configuration hostname and port (webaccess.psu.edu, port 6663)
to which Cosign filters connect to validate cookies, is being shut down.
The website, https://webaccess.psu.edu/, will remain the same.
An alternate configuration is available &hellip;</p>]]></description>
            <link>http://ait.its.psu.edu/2012/09/webaccess-old-hostname-and-port-being-shut-down-201312.html</link>
            <guid>http://ait.its.psu.edu/2012/09/webaccess-old-hostname-and-port-being-shut-down-201312.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">ipv6</category>
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Wed, 26 Sep 2012 13:43:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>Announcement: CosignModule 3.1.1 for IIS7 released</title>
            <description><![CDATA[<p>The following is from
<a href="http://sourceforge.net/mailarchive/message.php?msg_id=29706367">this message</a>; websites using CosignModule should be upgraded:
</p>]]></description>
            <link>http://ait.its.psu.edu/2012/08/announcement-cosignmodule-311-for-iis7-released.html</link>
            <guid>http://ait.its.psu.edu/2012/08/announcement-cosignmodule-311-for-iis7-released.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Wed, 22 Aug 2012 11:42:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess: Cosign filter configuration change</title>
            <description><![CDATA[<p>WebAccess protected websites are requested to change their Cosign filter configuration well before August 16, 2012. &hellip;</p>]]></description>
            <link>http://ait.its.psu.edu/2012/07/webaccess-cosign-filter-configuration-change.html</link>
            <guid>http://ait.its.psu.edu/2012/07/webaccess-cosign-filter-configuration-change.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Mon, 09 Jul 2012 17:00:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess QA: new hostname/port number</title>
            <description><![CDATA[<p>As a solution to the CosignModule's IPv6 bug, and to provide some flexibility in future configurations, we're switching to a new hostname and port number for Cosign filters to use.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/06/webaccess-qa-new-hostnameport-number.html</link>
            <guid>http://ait.its.psu.edu/2012/06/webaccess-qa-new-hostnameport-number.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Mon, 25 Jun 2012 16:44:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>Re: WebAccess QA: IPv6 testing</title>
            <description><![CDATA[<p>
<a href="http://ait.its.psu.edu/2012/05/webaccess-qa-ipv6-testing.html"
">QA testing</a> has revealed a problem with CosignModule (IIS 7).</p>]]></description>
            <link>http://ait.its.psu.edu/2012/05/re-webaccess-qa-ipv6-testing.html</link>
            <guid>http://ait.its.psu.edu/2012/05/re-webaccess-qa-ipv6-testing.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">ipv6</category>
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Wed, 23 May 2012 17:33:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>Non user accounts in UCS</title>
            <description><![CDATA[<p><br />
There are a number of options for non user accounts in UCS (and outside of UCS). What you request depends on the problem you are trying to solve. Below is a list and brief description of the options and how you get them.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/05/non-user-accounts-in-ucs.html</link>
            <guid>http://ait.its.psu.edu/2012/05/non-user-accounts-in-ucs.html</guid>
            
            
            <pubDate>Tue, 22 May 2012 10:30:05 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>www.work.psu.edu: Summer 2012 changes</title>
            <description><![CDATA[<p>
On 22 May, 2012, during the ITS maintenance window
(5:00&ndash;7:00 a.m.), ITS will update the www.work.psu.edu
splash page and dashboard.
</p>]]></description>
            <link>http://ait.its.psu.edu/2012/05/wwwworkpsuedu-summer-2012-changes.html</link>
            <guid>http://ait.its.psu.edu/2012/05/wwwworkpsuedu-summer-2012-changes.html</guid>
            
            
            <pubDate>Fri, 18 May 2012 10:43:47 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess QA: IPv6 testing</title>
            <description><![CDATA[<p>The WebAccess QA service now has IPv6 addresses (for browsers),
please help test.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/05/webaccess-qa-ipv6-testing.html</link>
            <guid>http://ait.its.psu.edu/2012/05/webaccess-qa-ipv6-testing.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">ipv6</category>
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Mon, 14 May 2012 16:20:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess: Systems on new hardware</title>
            <description><![CDATA[<p>During the maintenance window today (March 29, 2012),
the WebAccess production servers were moved to a newer hardware platform,
the same that has been in use by the WebAccess QA servers.</p>
<p>The moves were accomplished using the platform's live migration capability:
no downtime was necessary.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/03/webaccess-systems-on-new-hardware.html</link>
            <guid>http://ait.its.psu.edu/2012/03/webaccess-systems-on-new-hardware.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Thu, 29 Mar 2012 16:40:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess: Upgrading web server</title>
            <description><![CDATA[<p>A phased upgrade of the web server software used by the WebAccess production systems will begin on Saturday, March 31, 2012.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/03/webaccess-upgrading-web-server.html</link>
            <guid>http://ait.its.psu.edu/2012/03/webaccess-upgrading-web-server.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Thu, 29 Mar 2012 15:57:13 -0500</pubDate>
			
			



        </item>
        
        <item>
            <title>WebAccess QA: testing new web server</title>
            <description><![CDATA[<p>The WebAccess QA servers are using a new web server: please help us test it.</p>]]></description>
            <link>http://ait.its.psu.edu/2012/03/webaccess-qa-testing-new-web-server.html</link>
            <guid>http://ait.its.psu.edu/2012/03/webaccess-qa-testing-new-web-server.html</guid>
            
            
                <category domain="http://www.sixapart.com/ns/types#tag">webaccess</category>
            
            <pubDate>Thu, 22 Mar 2012 16:49:13 -0500</pubDate>
			
			



        </item>
        
    </channel>
</rss>
