Open source key to Victorian schools

Victoria's Department of Education and Training is continuing to develop in-house server software it built on top of open-source tools to bring its state-wide wireless network to life.

Loris Meadows
Loris Meadows
The software -- dubbed EduPaSS -- was developed as part of the state's AU$6 million Wireless Networks for Schools (WiNS) initiative which last year saw over 1,700 Victorian schools given high-speed wireless access on their campuses.

One EduPASS server sits in each of those schools, controlling student and staff access to network and Internet services.

"EduPaSS version 2 is currently waiting for approval, it's all documented and designed. And this time around we've had more time to design and document," the department's head of ICT security Loris Meadows told a Sydney conference yesterday.

EduPaSS is built upon "best of breed" open source software, according to Meadows, including the Smoothwall Linux Distribution, FreeRADIUS, OpenSSL and a custom Linux kernel based on Red Hat.

"Microsoft weren't very impressed," she told the audience.

The software has proved its worth since WiNS went live last year. "Since June 1st 2005, we've had 17.5 million successful authentications," said Meadows.

Version 2 of the software will add advanced features like Quality of Service (QoS) for bandwidth management, the Wi-Fi Protected Access version 2 (WPA2) sercurity mechanism, and in-line intrusion detection.

"We'll be using FTWall to prevent peer to peer sharing such as Kazaa, Gnutella and Napster," said Meadows. In addition, the department has already implemented "a central view of all EduPaSS servers".

Meadows said the department would not be contributing any code back to the open source community for security reasons, but said white papers would be made publicly available in an effort to share lessons learnt.

A custom open source solution was chosen, according to Meadows, because "there was no third-party solution" to meet the department's needs.

In general, the WiNS project was an outstanding success, according to the ICT security manager, but had not been without its hiccups.

For example, she outlined how the department had persuaded hardware vendor Cisco to modify its wireless access points (WAPs) during the manufacturing process.

The change was needed to ensure the WAPs could not be reset to factory default settings. Network hardware commonly comes with a discreet button providing this function.

Meadows said her department had asked Cisco to disable this "God" button due to security concerns.

She also said ordering such a large number of WAPs -- approximately 10,000 -- was not easy. "Cisco didn't have [that many] sitting on their shelves," she said.

The vendor's hardware was chosen for its superior coverage and roaming ability, according to Meadows.

She concluded that 99 percent of state schools now had wireless under the program, with some 15 schools not yet fully cabled.

Advertisement

Talkback 2 comments

    Not giving back - Is it legal or necessary?Anonymous -- 01/03/06 (in reply to #120130032)

    I'm not familiar with the details of the licenses involved - but is it legal of them to distribute the software to external bodies (schools are external to the ministry of education, aren't they?) without giving back their modifications?

    And from another angle - she should know by now that "security through obscurity" (of the code) is just a way to get a false sense of security - instead of letting the people who wrote the software and keep improving on it to see their changes and point out the bugs.

    GPL says yesMikolaj Habryn -- 02/03/06 (in reply to #120130033)

    Yes, it is legal. They are obliged to provide the source code only to anyone who has the binaries, meaning the operators of the servers - themselves. They are under no obligation to open their changes to anyone else, under any OSDL-approved license.

Add your opinion


Latest Videos

Blogs

  • Juha Saarinen TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • More blogs »

Tags

Back to top

Featured