Saturday, September 12, 2015

SFTP Connections from PowerSchool

At my job, we store student data in a program called PowerSchool. One of PowerSchool's features is AutoSend. AutoSend can make a text file full of data and send it to another computer over SFTP. This is very useful, as it allows student data to be entered once (in PowerSchool) but appear in many systems.

Recently, I replaced and updated the FreeBSD system that runs our SFTP server. After the upgrade, PowerSchool couldn't send data to the FreeBSD SFTP server. Other SFTP programs, such as FileZilla, were able. This issue only seemed to affect PowerSchool's AutoSend. I couldn't figure it out at first. The FreeBSD community couldn't. Our tech support couldn't. They escalated the issue over and over until it reached "engineering" and I never heard back from engineering.

After working on this on-and-off through the summer and eventually found a way to make it work. Since it took me so long and confused so many other people, I wanted to put this out there for others to benefit.

The short version is this: I had to change the default settings of the SSH server.

This may sound strange to some, but SFTP on many Unix systems -- such as FreeBSD and Linux -- is based on OpenSSH. OpenSSH is a system that is all about making encrypted connections and preventing the bad guys from seeing what you're transmitting. However, its default settings moved to a more strict standard at some point and this was why I saw a difference between the old FreeBSD server and the new one.

The setting in question deals with how OpenSSH handles authentication. In plainer language, it's all about the login process. It seems that "keyboard-interactive" is the mode used by programs that interact with humans, such as FileZilla. However, "password authentication" is the kind used by automated systems, such as PowerSchool. Personally, I found the name "password authentication" to be confusing for a while, but that is what it is called.

So I edited /etc/ssh/sshd_config to allow the password authentication system. However, the OpenSSH developers disabled it for a reason. They know more about computer security than I do, so I struck a compromise. I changed the settings so that password authentication was valid if and only if the connection came from my PowerSchool server.

If you need to do this, just find your system's copy of sshd_config and add the following lines to the bottom of the file. If you have any lines beginning with "Match", this should go immediately above those.


# Turn off PasswordAuthentication in general, i.e. without a Match statement to change it.
PasswordAuthentication no
# Allow only the IP address of the PowerSchool server to use the
# PasswordAuthentication directive. Note the "PasswordAuthentication no" 
# above all Match statements.  That is part of this configuration, but 
# must be before any Match blocks.
Match Address 999.999.999.999/32
        PasswordAuthentication yes

You should change "999.999.999.999" to the IP address of your PowerSchool server. Everything else should be fine exactly as I wrote it above.

Tuesday, June 30, 2015

Free Chromebook Inventory Tool

If you manage chromebooks (or other ChromeOS devices) in a Google Apps for Education or Google Apps for Work system, you need this tool.

The Chromebook Inventory Add-On for Google Sheets allows you to quickly make a spreasheet of your managed chromebooks. You can then edits the spreadsheet and export it back to the Google servers. When the export is done, it will update those settings. This makes it a convenient tool to do bulk updates, move large numbers of chromebooks to a new OU, make inventory files, or make checklists.

I couldn't explain this system any better than the seven minute long video that they provide. So just check that out.

Tuesday, June 23, 2015

Restarting snmpd on MacOS X Server

Recently, I needed to update the SNMP settings on some old MacOS X file servers that I was monitoring. There was no GUI to change the SNMP settings on those, only to start and stop it. Since I was using the command line to reconfigure lots of other servers and switches, I didn't want to resort to the GUI just to restart the SNMP process on these Mac servers. This is what I ended up doing.

First, I made a new snmpd.conf file the Mac in the usual way.


sudo snmpconf

Then I put the new file into place and restarted the snmpd process.


sudo cp snmpd.conf /usr/share/snmp/snmpd.conf
launchctl stop org.net-snmp.snmpd

Technically, that only stopped the process. However, the org.net-snmp.snmpd.plist configuration file states that snmpd should always be running. So the launchd process in MacOS just starts it back up when it sees that it isn't running. It happens so quickly that a "stop" command is practically a restart in this case.

Its worth noting that these are older file servers running MacOS X Server 10.6.8. I don't know if the launchctl command would be the same in newer versions.

Tuesday, June 9, 2015

FreeBSD Updates (Semi-)Automatically

Keeping servers up to date with security patches is a challenging task. No one likes server outages, upgrades could break things, etc. This is what I do on FreeBSD systems to safely manage updates.

First, login as root. Then make sure that /etc/aliases is configured to forward root's email to your email address. This makes sure that you get the notifications of updates. It will also cause you to get nightly, weekly, and monthly updates about important things like how full the hard drives are and if any of the installed ports or packages have known security bugs. Once /etc/aliases is updated, type "newaliases" to activate the changes. Then email root to see if it worked.

Then, add this to /etc/crontab. (Note: Press "Tab" five times between "@daily" and "root".)

# Get OS updates every day
@daily                      root    freebsd-update cron

This will make the system check every night for important upgrades. If there are any, it will download them to a staging area and not install them. Instead, it will email you a list of the pending changes. This email will only happen when there are recommended updates to install, so you won't see it every day.

That is all the setup work. Now just wait for an email about a pending upgrade.

When you get one of these messages, read it over to make sure it wouldn't affect anything that you've customized. If it would, you might want to take a closer look at that system to put your mind at ease.

When you're ready to activate the upgrade, login as root again and type this:

freebsd-update install
shutdown -r now

This will cause it to install the pending updates and restart. If everything goes as planned, you're all set. Really. That is it.

If anything doesn't go to your liking, you can revert to the pre-update system by logging in as root and typing:

freebsd-update rollback
shutdown -r now

If the FreeBSD system is running as a virtual server in VMware, Digital Ocean, etc., then you may wish to make a snapshot of the server right before the "freebsd-update install" command. That gives a very convenient way to roll back to pre-update conditions. I haven't heard of anyone breaking their system with freebsd-update before, so this is really just an extra precaution more than a necessity. With servers, its always nice to have extra backups.

By keeping on top of updates regularly with a (mostly) automated system like this, your servers will be more secure, more trustworthy, and more stable. More importantly, you won't accidentally forget to update a random server for two years and then worry about breaking it during the next upgrade. Based on that stress-reduction alone, I highly recommend this approach.

Tuesday, June 2, 2015

PowerSchool Gradebook on Chromebook

This school year, I had a few high school teachers beginning to use chromebooks as a full-time tool. Generally, there were two complaints: They weren't able to print and they couldn't run the (Java based) PowerSchool gradebook program. The printing issue was simply because I hadn't set up any Cloud Print compatible printers yet. Accessing their gradebook, on the other hand, was a more interesting challenge.

One day, I had an idea. Its a huge "hack," but it works. We used a service called rollApp to remotely run a Firefox & Java capable environment and, from that, we could run the gradebook. Its a bit like the matryoshka Russian nesting dolls.

First, from the chromebook you visit rollApp. Then click "Login" and click on the Google logo. This will allow you to quickly login using your Google account and save you from having to remember Yet Another Password. This even works with accounts in a Google Apps for Education system.

Second, once your account is set up, run the rollApp version of Firefox. This will cause Firefox to display on your screen, but its actually running on the rollApp server and using their memory, CPU, etc.

Third, once Firefox is on your screen, go to your PowerSchool system and login. Then run the gradebook program.

The first time you do all of this, it will take a while. The next time, though, there are a few fewer steps. For example, you won't have to agree to so many things and Firefox will be in your list of recently used rollApp programs.

Important Note: As stated above, the gradebook is running on rollApp's servers and not your chromebook. Its only visible from your chromebook. This means that you've allowed rollApp to see you typing in your PowerSchool password. You have to decide if they are trustworthy enough for that. Check with your Information Technology department. There may be a district policy that could guide you on this topic.

It is my hope that PowerSchool will eventually have an HTML 5 version of their gradebook so that this hack isn't necessary. If they even came out with an Android version of the gradebook, that could be ported over to ChromeOS quickly via the Android Runtime for Chrome. So, with any luck, this idea will not be needed some day. For now, however, its an option that you can consider. Just make note of the potential security issue and check if your district has a policy on this before you begin using it.

Friday, May 22, 2015

iPads on Chromebooks

I learned an interesting thing recently. A teacher I work with connected an iPad to a chromebook's USB port. I was pretty sure that it wouldn't do much other than charge the iPad off the chromebook's battery, but I was wrong.

Trying to show the teacher that she couldn't synchronize data between the iPad and chromebook that way, I opened the Files program on the chromebook. In Files, in the same sidebar area that Google Drive and other things appear, there were two listings for the iPad. When I clicked on one, nothing showed up. When I clicked on the other, a DCIM folder showed up. Most digital cameras store their data inside a folder named DCIM and it appears that iOS follows this standard. So ChromeOS basically said, "OK, here are the photos on that camera you just connected," and offered up the files. We were able to drag-and-drop them into Google Drive, allowing her to copy them over.

Of course, she could have done this with the Google Drive app for iOS. This USB method does have a few advantages, though.

For one, it allows a teacher on a chromebook to collect photos off of their students' iPads. No accounts are required. You don't even need software from Apple's App Store. This could be useful in schools that provide iOS devices (e.g. iPads or iPod Touches) to younger students. It could also be helpful for people who have iPads but don't use Google Apps for Education. In that situation, the students wouldn't necessarily have Google Drive accounts to upload their photos into. There are also situations when students don't have Apple accounts and, therefore, can't download apps like Google Drive from the App Store.

I suspect there are other potential uses for this that I'm not thinking about right now. If you have any, please tell me about them in the comments section below so that other readers can benefit, too.

Tuesday, April 28, 2015

YouTube Use in Schools

Recently, GoGuardian published this interesting analysis of YouTube usage over a sample set of a few hundred schools. Its well worth a read, just to see how the younger crowd views computers in general and YouTube in particular.

Side note: If you use Chromebooks (or their desktop cousins, Chromeboxes) and haven't heard of GoGuardian, you should give them a look. It might not fit your institution's needs, but they have interesting enough features that they could be useful.