New EnTrust Certs for PIV Authentication for LAS/MCU

New EnTrust certs were released by Peraton and were supposed to be deployed to all MCU/LAS systems by 8/18/2023. The DOI USAccess team was just made aware of these new certificates today, 8/23/23 and have pushed through an emergency RFC to the new certificates to Active Directory just a few minutes ago.  These will take time to replicate throughout the …

Read More…

USGS SysAdmin Tools (USAT) v2.4.3

Version 2.4.3 of USAT, the USGS SysAdmin Tools PowerShell module, has been released to the Stable channel! Updates include:

  • New Get-SoftwareUsers tool for listing users set up for specific software via AD groups (Adobe, Enterprise Software Catalog, etc.)
  • Export-LapsPasswords can now pull the Windows LAPS password for machines that have migrated (which is most, at this point)
  • The USAT module should …

    Read More…

    Docker Desktop – Uninstall Directive with Exception process defined that will include POA&Ms and cost recovery for remaining installed licenses 

    To:            GS IT All 

    Subject:  [UPDATE 2] Docker Desktop – Uninstall Directive with Exception process defined that will include POA&Ms and cost recovery for remaining installed licenses 

    WHEN IT WILL HAPPEN:  Final Deadline: March 31, 2023 

    WHAT WILL HAPPEN:      Docker Desktop must be uninstalled from all systems.  Systems that require an exception will need to submit POA&M paperwork and will be cost recovered for remaining installations after …

    Read More…

    Hotfix Available for LAS/MCU systems

    USAccess has released a hotfix to address the following issue:

    USAccess is currently experiencing an issue with credential check-in, activation, and local print for some V8.1 cards.  The issue affects the ability of credentialing sites to check-in cards in the Credential Inventory Tool (CIT), with operators receiving an error message of “Credential record was not found. Reference Code AAAAA”.  …

    Read More…

    Enterprise Deployment of Disable IE11

    Internet Explorer Logo

    On Tuesday, November 8, 2022, the GPO “DI – BWTST Disable Internet Explorer 11” was linked to the following regions: CR, DI, ER, Science Centers, and WR. Links to this GPO on local site OUs were removed.  

    WHAT YOU NEED TO KNOW:    All IE11 Dependencies discovered so far have been resolved by using Internet Explorer Mode in Microsoft Edge. …

    Read More…

    RESOLVED: Do Not Use BigFix Console or WebReports – Beginning 10/14/2022 3PM Eastern

    IEM Logo

    RESOLVED

    [RESOLVED – 10/19/2022]: The DOI BigFix team reported that the environment has been stable for over 24 hours, and all scheduled reports have been re-enabled. DOI now considers the issue resolved.  The DOI BigFix team will not do maintenance on 10/20/2022.  There will be no standard downtime this Thursday. 

    Local use of the BigFix Console or Web Reports can now be resumed. 

    The BigFix shut down action for computers that were non-complaint with DAR requirements was …

    Read More…

    IP Control Device Upgrades Begin 10/26/22 at 9AM Central

    The maintenance window may last up to 8 hours. Please make any changes in IPControl before the outage begins. Once the migration is completed, Active Directory DNS forwarders will be moved from the old servers to the new servers.

    IPControl admins will need to use ipcontrol.usgs.gov for making changes once migration is completed. Please review local configurations to ensure that …

    Read More…

    Shutdowns for DAR Non-Compliance Begin 10/17/2022

    bitlocker_padlock

    The final step in moving the USGS DAR encryption project into a compliance phase is to enable automatic shutdowns of non-compliant systems. Respecting the September Fiscal Year Closeout Activities, a decision was made to move the shutdown activities that were supposed to start on August 29, 2022, to Monday, October 17, 2022 providing additional time for sites to remediate non-compliant …

    Read More…