|
|
|
| |
Water Resources Division |
ITAC and Kevin,
Here is a DRAFT memo the DIS Office has developed with input from the Regional Computer Specialists and the NT TAC. Please review the memo prior to the ITAC discussion and recommendation decision next Wednesday (February 12, 2003).
Thanks, Tom (Wood)
D R A F T |
|
In Reply Refer To: |
|
MEMORANDUM |
|
February 18, 2003 |
|
To: |
All Water Resources Discipline Employees |
From: |
Thomas C. Wood |
Subject: |
DIS Infrastructure Direction Memo #14, WRD Active Directory Recommendation |
The purpose of the memo is to provide guidance and current support plans for implementing Windows 2000 Active Directory (AD) Service within the Water Resources Discipline. Two different AD deployment strategies have been discussed within USGS over the past couple of years, 1) centralized/bureau managed, and 2) local/site managed. The Distributed Information System (DIS) Program Office recommends WRD deployment of Windows 2000 Active Directory (AD) in a local/site managed model, with some caveats described later in this message. This recommendation has been reviewed and approved by the WRD Information Technology Advisory Committee (ITAC) and the Geographic Information Office (GIO).
Active Directory is Microsoft's initial offering in the area of directory services. Microsoft's AD Services are integrated into the Windows 2000 Server operating system and are repositories for environment information, such as applications, files, printers, and people. In addition, AD Services provide consistency to names, descriptions, locations, accesses, management, and security within our Windows based systems.
To date, the Bureau and DOI have put forth efforts for deploying AD throughout the Bureau and DOI, respectively. These efforts have focused on the deployments being "centralized" rather than "localized". There are several issues with centralized deployments of AD, most notably, the placement of domain controllers (DCs). The DC servers authenticate users, allowing access to the domain services, including file and printer access. The log-on request is sent over the wide area network (WAN) to the nearest DC in a centralized deployment model. This unto itself is not an issue, but the problem arises when the WAN is unavailable. In this case, the user will not be able to access files or peripherals that are not directly connected to the workstation. This problem would compound itself during the occurrence of a "hydrologic event" when access to all local computing resources is even more time-critical. The hydrologic event itself could potentially cause extended WAN outages. In addition to the connectivity issue, there are concerns about centralized AD security compromises, overall cost, and support required to implement an enterprise wide AD system.
At this time, one WRD Office is connected in production mode to the centralized Bureau AD model and will continue to be supported by the GIO and DIS Program Office. Other offices in WRD are advised not to participate in the Bureau or DOI centralized deployments until the issues described above are resolved. Additional details of the DIS Program Office guidance on AD deployments follow.
The DIS Program Office will support existing and future local Active Directory (AD) deployments within WRD:
The DIS Program Office does not advise, and will not support, additional centralized AD deployments until further notice:
Questions about the information contained in this message should be directed to Garry Neverdon, the DIS Systems Support Unit Chief and NT TAC Chair, at 703-648-7068, or gneverdon.
Address questions or comments to |
|