| 19 | * Eric's [wiki:phenix-1-12-23 slides] |
| 20 | |
| 21 | * Phenix fit in map |
| 22 | - Command and initial gui implemented |
| 23 | - Gave demo |
| 24 | |
| 25 | * Computer security audit |
| 26 | - CGL primary and backup machines require 2-factor authentication for admin even within UCSF (but not for root). |
| 27 | |
| 28 | * ProofPoint email filtering |
| 29 | - CGL will get its own ProofPoint console to control filtering rules, e.g. keep Python attachments. |
| 30 | - Only Exchange email currently get email listing quarantined messages. |
| 31 | - Will use split DNS so ProofPoint not used for intra-UCSF email. |
| 32 | |
| 33 | * Network access control |
| 34 | - IT wants root access on machines for network access control because their solution is a remote management platform. |
| 35 | - They should only need control of the switches to control network access. |
| 36 | |
| 37 | * Timeline |
| 38 | 1) Switch email to use ProofPoint |
| 39 | 2) Update CGL backup and primary to Rocky 9 |
| 40 | 3) Network access control |
| 41 | |
| 42 | * Plato OS update |
| 43 | - Plato will probably update to Rocky 8 in May 2023 |
| 44 | - Need to update anything using Python 2 (e.g. CGI scripts) to Python 3 |