Categories
Pages
-

IT Center Changes

Release Notes Version 2.10.0 – Support of different time zones

January 12th, 2024 | by

Features:

  • Support for time zones in time displays has been introduced
  • A message is now displayed if no Moodle courses are available

 

Improvements and bug fixes:

  • Overlay button behavior has been improved
  • Various bug fixes

Terrapin Attack Counter Measures (SSH)

January 9th, 2024 | by

A recently discovered flaw in the implementation of the Secure Shell (SSH) protocol lead to an attack vector called “Terrapin Attack” enables an attacker to break the integrity of the “secure shell” connection in order weaken the overall security. TL;DR To implement an effective counter measure against the attack, we have disabled the affected methods in the HPC cluster’s SSH configuration. Consequently, these methods cannot be used until further notice:

  • Ciphers: ChaCha20-Poly1305
  • MACs: Any etm method (e.g. hmac-sha2-512-etm@openssh.com)

Please adapt your configuration accordingly if your configuration is  relying on the methods mentioned above.

The attack is only feasible when a using either the ChaCha20-Poly1305 Cipher or a combination of a Cipher Block Chaining (CBC) cipher (or, in theory, a Counter Mode (CTR) cipher) combined with an encrypt then MAC (etm) message authentication code (MAC) method and the attacker has the ability to act as a man-in-the-middle. (Example: A security suite on your client machine may perform a deep packet inspection (per definition a (hopefully “good”) man-in-the-middle) to protect you from other threats.)

The Galois Counter Mode (GCM) AES ciphers are not affected.

We encourage you to employ strong encryption ciphers such as aes256-gcm@openssh.com and a sufficiently strong MAC method (e.g. hmac-sha2-256 or hmac-sha2-512) immune to the attack vector.

Note:

Due to a bug in the Windows OpenSSH client employing the umac-128@openssh.com MAC as default, we disabled the problematic method in the SSH server configuration as well to minimize issues when connecting to the HPC cluster. Until further notice, only hmac-sha2-512 and hmac-sha2-256 can be employed as MAC. Please adapt your configuration accordingly, if required, e.g.:

Ciphers aes256-gcm@openssh.com,aes256-ctr
MACs hmac-sha2-512,hmac-sha2-256

 


You can track any disruptions or security advisories that may occur due to the aforementioned change in the Email category on our status reporting portal.

Added Wildcards to the Search. Added DECT Numbers to UKAcontacts

January 8th, 2024 | by

Apart from adding wildcards to the people search, the display of internal DECT numbers of the university clinic has been finalized. These can be displayed for and by university clinic organizations.

Multi-Factor Authentication Mandatory starting 15 January 2024

December 20th, 2023 | by

We will introduce a mandatory MFA only access to the HPC cluster on the 15 January 2024.
From that day on, logins to *any* login nodes will only be possible with MFA.

If not done yet, please follow this step-by-step guide to configure your MFA token in the RegApp:

https://help.itc.rwth-aachen.de/service/rhr4fjjutttf/article/475152f6390f448fa0904d02280d292d/

We will also offer three dates for a brief introduction:

* Friday, 12. January 2024 ► 13:00 – 13:45: https://blog.rwth-aachen.de/itc-events/en/event/using-multi-factor-authorization-for-claix/
* Monday, 15. January 2024 ► 15:30 – 16:15: https://blog.rwth-aachen.de/itc-events/en/event/using-multi-factor-authorization-for-claix-2/
* Monday, 22. January 2024 ► 10:00 – 10:45: https://blog.rwth-aachen.de/itc-events/en/event/using-multi-factor-authorization-for-claix-3/

Furthermore, you can use the monthly HPC consultation hours for any further questions:

HPC Consultation Hour

For more background information about HPC & 2FA, please read our blog entry:

Protecting the HPC account with MFA

Please contact servicedesk@itc.rwth-aachen.de for any further questions.

Release Notes Version 2.9.0 – Introduction of favorites icons for rooms

December 14th, 2023 | by

Features:

  • Favorite icons for new areas in the “rooms” menu have been introduced

 

Improvements and bug fixes:

  • Note regarding problems with the Android System WebView: some users experienced problems because it was too old. In these cases, a corresponding message now appears when the app is started.
  • Several minor bug fixes

OS Upgraded to Rocky 8.9

November 30th, 2023 | by

During the last cluster maintenance, the OS of the HPC cluster was upgraded to Rocky Linux 8.9 due to the EOL of Rocky 8.8 to ensure continous update support for the systems.

The upgrade provides a modernized system base and security enhancements. The user view, usage and the expectable performance of the cluster remain unchanged.


You can track any disruptions or security advisories that may occur due to the aforementioned change in the Email category on our status reporting portal.

Release Notes Version 2.8.0

November 28th, 2023 | by

Improvements and bug fixes:

  • It was not possible to click on “show directions” in the calendar details. This has now been fixed.
  • The behavior of the learning room search and learning room map has been improved
  • Copying of text and links has been improved

RWTHcontacts Expanded Person Search

November 21st, 2023 | by

The person search has been expanded in RWTHcontacts: Several pieces of information about a person are displayed together. The person directory has received a UI update and has been adapted to the design of RWTHcontacts.

CLAIX System Maintenance on 2023-11-27

November 17th, 2023 | by

Dear users of the RWTH compute cluster,

on 2023-11-27 the complete cluster will not be available from 8am to 12am due to system maintenance.

Kind regards,
Your HPC team


You can track any disruptions or security advisories that may occur due to the aforementioned change in the RWTH-HPC category on our status reporting portal.

Deletion of course rooms of the winter semester 2020/21

November 13th, 2023 | by

In line with the life cylce of course rooms with connection to RWTHonline, the winter semester 2020/21 course rooms were deleted on November 13, 2023.