|
|
|
| |
DIS Activities |
From: |
Thomas C Wood, 02/24/2003 08:36 AM |
To: |
All Water Resources Discipline Employees |
Cc: |
Karen Siderelis/DO/USGS/DOI@USGS,
|
Subject: |
Management Duties for National Water Information System Databases |
The purpose of this memo is to provide guidance and current support plans for implementing Windows 2000 Active Directory (AD) Service within the Water Resources Discipline. Two different AD deployment strategies have been discussed within USGS over the past couple of years, 1) centralized/bureau managed, and 2) local/site managed. The Distributed Information System (DIS) Program Office recommends WRD deployment of Windows 2000 Active Directory (AD) in a local/site managed model, with some caveats described later in this message. This recommendation has been reviewed and approved by the WRD Information Technology Advisory Committee (ITAC) and the Geographic Information Office (GIO).
Active Directory is Microsoft's initial offering in the area of directory services. Microsoft's AD Services are integrated into the Windows 2000 Server operating system and are repositories for environment information, such as applications, files, printers, and people. In addition, AD Services provide consistency to names, descriptions, locations, accesses, management, and security within our Windows based systems.
To date, the Bureau and DOI have put forth efforts for deploying AD throughout the Bureau and DOI, respectively. These efforts have focused on the deployments being "centralized" rather than "localized". There are several issues with centralized deployments of AD, most notably, the placement of domain controllers (DCs). The DC servers authenticate users, allowing access to the domain services, including file and printer access. The log-on request is sent over the wide area network (WAN) to the nearest DC in a centralized deployment model. This unto itself is not an issue, but the problem arises when the WAN is unavailable. In this case, the user will not be able to access files or peripherals that are not directly connected to the workstation. This problem would compound itself during the occurrence of a "hydrologic event" when access to all local computing resources is even more time-critical. The hydrologic event itself could potentially cause extended WAN outages. In addition to the connectivity issue, there are concerns about potential centralized AD security compromises, overall cost, and support required to implement an enterprise wide AD system.
At this time, one WRD Office is connected in production mode to the centralized Bureau AD model and will continue to be supported by the GIO and DIS Program Office. Other offices in WRD are advised not to participate in the Bureau or DOI centralized deployments until the issues described above are resolved. Additional details of the DIS Program Office guidance on AD deployments follow.
The DIS Program Office will support existing and future local Active Directory (AD) deployments within WRD:
The DIS Program Office does not advise, and will not support, additional centralized AD deployments until further notice:
Questions about the information contained in this message should be directed to Garry Neverdon, the DIS Systems Support Unit Chief and NT TAC Chair, at 703-648-7068, or gneverdon.
Copy to:
TOP #top Intro infor /cm/cyber/info_stats.html Cyber Seminars /cm/cyber/ WRD Internal http://water.usgs.gov/usgs/ USGS Internal http://www.usgs.gov/
Address questions or comments to: Charlie Merk
cfmerk on 703-648-5680 or
Feedback on the web page:
ITAC Webmaster