<META name="ROBOTS" content="NOINDEX,NOFOLLOW">
- NSS Information Technology Infrastructure Wiki
NSS Information Technology Infrastructure Wiki
The National Space Society (NSS) does hereby establish an Information Technology Infrastructure policy which implements "known best practices" for availability, data integrity, connectivity, and infrastructure management.
Known Best Practices/Requirements
Domain Name Management
Domain names shall be registered in the name of the Society.
Domain name renewal, and designated contact information (billing, administrative, and technical) shall be up dated at least annually.
Website Management
An Secure Socket Layer (SSL) certificate from a trusted root certificate authority shall be purchased and maintained for use on all Society websites which require transfer of private financial information.
Membership Data Base Management
Access of changes to the membership data base system shall be contolled via a password protected interface with all transactions/changes being logged.
Routine access to the membership data base system shall be via a secure IPSEC encrypted link between networks.
Failure Tolerance/Availability
The NSS shall establish an availablility requirement for each required information technology function/component.
The NSS shall define, implement, and/or field the necessary failure tolerance infrastructure and support resources to met the availability requirements.
Mail Management
The NSS shall define, implement, and/or field the necessary information technology infrastructure and support resources to operate mail.nss.org and subdomain mail resources as may be deemed necessary to provide for the efficient and effective conduct of Society business.
The NSS shall define, implement, and/or field the necessary information technology infrastructure and support resources to mitigate any adverse impacts of the operation of mail.nss.org and subdomain mail resources on their respective users or others. Such measures shall include at a minimum: spam scoring/tagging, spam filtering, anti-virus scanning, and mailing list control.
The NSS shall define and prototype the necessary information technology infrastructure and support resources to transition mail.nss.org and subdomain mail resources as may be deemed necessary to a managed mail environment when deemed necessary to provide for the efficient and effective conduct of Society business.
Ecommerce Management
Credit card information stored on a National Space Society computer resource (wholely owned, contracted for, or borrowed/lent/shared) shall not be stored for longer than it takes to process and log the transaction.
The NSS shall at the earliest opportunity
Collaboration Management
The NSS shall define, implement, and/or field the necessary information technology infrastructure and support resources to operate such collaboration tools as may be deemed necessary and appropriate to provide for the efficient and effective conduct of Society business.
Implementation Requirements
Baseline Functions
Domain Name Service
Primary Domains (we have or will have the DNS Start of Authority - SOA)
nss.org
External Domains (DNS SOA is managed by others)
nsschapters.org
L5news.org
Alias Domains
adastramagazine.com ==>
http://www.nss.org/adastra isdc2006.org ==>
http://www.nsschapters.org/isdc/2006 ==>
http://www.nss.org/isdc/2006 isdc2007.org ==>
http://www.nss.org/isdc/2007 isdc2008.org ==>
http://www.nss.org/isdc/2008 isdc2009.org ==>
http://www.nss.org/isdc/2009
Placeholder Domains to be dispositioned
L5society.com
L5society.net
L5society.org
nationalspacesociety.com
nationalspacesociety.org
nodac.net
SMTP Mail Server
mail.nss.org
Internet WWW Server
www.nss.org
IPSEC Authentication and Encryption Services Platform
link between i4.xisp.net and eos.xisp.net (or replacement)
Firewall
only required if moved out from behind astra.xisp.net
Regenerative, self healing personality/code base management system
inclusion with the ghodess maintenance loop
Fail-over Connectivity/Core Services Manager
initial access can be over T1
access should be over FIOS
Unwanted Mail Filtering
spamassasin
spamassasin management tools / cron auto update
other mail mangling toolkit(s)
Remote Authentication/Management
ssh is required
==== HTTP Proxy Server ====
future/not required
==== Intranet WWW Server ====
system.nss.org
==== DHCP Server ====
future/not required
Enhanced Optional Functions
IP Print Server
future
Exported File System Server (SMB, NFS, and Netware Compatible)
future
Email/Fax Gateway
future
Backup Manager
installation by Randall
Discussion Server
future
Custom Optional Functions*
CyberTeams Director Suite
installation by Randall
Mailing List Manager
mailman mailing list manager
eCommerce Server
future
Remote Access Server
future/not applicable
Fax Server
future
Remote Offsite Backup Manager
future
Remote Control Server (CPE/Facility Status/Control/Management Server)
future/not applicable
Voice Mail Server
future/not applicable
Streaming Audio/Video Server
future
Custom functions may require additional software, hardware, and/or services
Hardware Description
* 2U Rack Mount Chassis with 6 Hot-Swappable U160 SCSI drive bays * Dual Processor Capable Mainboard w/U160 SCSI, Video, and LAN onboard * Pentium III FC PGA2 Processor (2nd Processor optional) * Hot-swappable Power Supply (2nd Power Supply optional) * Hot-swappable 18 GB U160 Hard Drive (2nd - 6th Hard Drives optional) * 256 MB Main Memory Standard (up to 6 GB optional) * Slimline Floppy/CD ROM * Tape Backup System (optional) * 256 MB USB Memory Key Non-volatile Emergency Boot Device * Internal 56K Remote Access/Fail Over Connectivity Modem, Standard (ISDN optional) * Secondary Network Interface, Standard ( 4 port optional)
Software Description
* Core Operating System SuSE Enterprise Linux 9.X
* Custom Control and Configuration Management Software, Standard
* Bind (DNS), Standard
* Sendmail (SMTP), Standard
* Apache (WWW Server), Standard
* Amanda (Backup), Standard
* Squid (http proxy), Standard
* Freeswan (IPSEC), Standard
* Open SSH (remote authentication), Standard
* Slash (discussion management), (Optional)
* Lightning Fax (Fax software/gateway) (Optional)
* Visual Pulse (CPE Monitoring) (Optional)
* StoreSense (eCommerce) (Optional)
Hosting Requirements
* Primary Internet Connectivity (sDSL is recommended, however primary connections ranging from dual analog to T1 are supported.
* At least two real routable IP addresses are required for the control net
* A subnet with a suitable number of routeable IP addresses is required for the client net
* Fail-Over Connectivity (ISDN BRI or analog telephone line)
* A dedicated or shared Uninterruptible Power Supply supporting simple signaling via serial or USB interface is required.
* Equipment must be operated in a well ventilated room where the ambient temperature is kept below 80 degrees at all times.
* Suitable physical space must be allocated to allow the operation and service of the equipment.
* Partial or Full Rack mount enclosures are recommended but not mandatory.
NSS Wiki