Old 02-11-2011, 11:56 AM   #1 (permalink)
Untangler
 
Join Date: Nov 2010
Posts: 65
techuser is on a distinguished road
Default make AD Connector Hidden Process in Task Manager

Is it possible to make the vbscript for AD Connector a hidden process, so that users cannot simply terminate the process in task manager? This would be an excellent feature!

It would be even better if the server could obtain the AD information without having to run a vbscript in a continuous loop for reporting.
techuser is offline  
Old 02-11-2011, 12:10 PM   #2 (permalink)
Untangle Ninja
 
mrunkel's Avatar
 
Join Date: Jul 2008
Posts: 2,766
mrunkel is on a distinguished road
Default

Captive Portal
__________________
m.


Big Frickin Disclaimer:
While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
mrunkel is offline  
Old 02-11-2011, 12:33 PM   #3 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

There really isn't any other way to do it. If you want Untangle to route based on user name it has to run some kind of applet on the desktop to create a username to IP address mapping so it can do its thing.

So we either use a logon script, or we write an application that does the same thing. Somewhere on these forums I believe WebFool created an application that does what the script does so people can't edit it or guess its function as easily.

But it can still be terminated.

The answer there, is take the admin rights away from the user so they cannot terminate processes. Of course that has much larger implications.

Mrunkel is right, captive portal is your only other option. That puts the burden of authentication on the Untangle server, where the user has no control. Of course, that process is more disruptive as the users have to authenticate a certain number of times per day to build the user / ip map. Furthermore, if you create a long window of authentication, you can possibly have internal machines change addresses and either loose access, or put access violations on someone else.

Nothing's perfect.

While I'm thinking about it, I wonder how hard it would be to change up the script and have it fire as a scheduled task under the currently logged in user... That would bring up an intermittent task event, that would vanish between runs. Since the actual process would take almost no time, that would be functionally invisible.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879

Last edited by sky-knight; 02-11-2011 at 12:37 PM..
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:47 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2