Best setup for Universities

Hi,
I would like to aks some importan questions. We are trying to set up MS PEAP with ACS 3.2 in our university. For that type of authentication we have to add user laptops on ouw domain, Which is fine for Staff but How can we avoide this with students laptops with out adding them to our domain. Security is the big issue.
Which other authentication method should anyone recommand to avhieve this goal.
Runnning Ap1200, Non Cisco WCards, Acs 3.2, Win xp/W2k.
I would be greatful if someone help me regarding this issue. What other issues should we consider while making the decisions?
regards
Khaleefa

I would recommend EAP/TTLS with a 3rd party supplicant, like the meetinghouse client. Certs would be a great way to deploy it, but then you need to deal with PKI.
I have not dealt with the ACS. We are going to be looking at Radiator for radius backend support. I believe it supports multiple EAP types.
Currently we are running an open network and use a custom middlebox (www.net.cmu.edu/authbridge/)
Are you trying to control access to the network, or provide data encryption. We tell users to use applications that secure their data (ssh, ssl).
If you want more details on what we are looking at, let me know. We have about 900 APs across our university and have been using wireless since the days of 900 MHz 1 Mbps.

Similar Messages

  • Best setup for a non-Mac file server?

    I have a dual xeon server, with a SATA RAID5 I want to use as a file server in a cross-platform environment.
    *What I've tried and the issues...*
    At first I considered using Windows 2003 (Win2k3) but Services for Macintosh (SFM) is an older version of AFP and thus only supports 31 character filenames. With all our Macs supporting SMB/Samba/CIFS and Apple touting that "Macs and PCs can co-exist harmoniously on the same network" I figured I would give that a try.
    SMB doesn't work.
    Sure I can create a connection, but transferring files is a completely different story. I'm trying to backup application and system data, but companies such as Adobe and Apple have named some of their files with special characters that can't be transferred over SMB. I know NTFS doesn't support these characters, but I though a Linux box using SMB would work fine. It doesn't. It's the protocol which keeps me from transferring the data. I end up with the lovely error message of "You cannot copy some of these items to the destination because their names are too long or contain invalid characters for the destination..." (what's sad is, if you google for " because their names are too long or contain invalid characters for the destination" you only get 6 results.)
    So I thought I would give NFS a try. Apple says "Viewed from Mac OS X, [connecting via NFS] is just like connecting to an Apple or Windows server." No. It's not. NFS shares don't even show up in the Finder's Network listing. There are also a pile of other hurdles which are only tackled by savvy, command-line using users.
    So that leaves me with AFP. Win2k3 doesn't support filenames longer than 31 characters, and Win2k8 is dropping SFM altogether. Off to choose a *nix flavor, but that requires Netatalk. It hasn't been updated in years, it has many bad performance reviews... and most distros have removed it. I can download and install it. Oh, but that requires I get the kernel source files. Then I have to create an RPM an that's not working... now I'm several levels deep in trying to figure out how to get Netatalk working and I'm not even sure it will work.
    *What's the best setup for a non-Mac file server?*
    FreeNAS seems promising, but it's in alpha/beta and they have all sorts of warnings regarding potential data loss. Sure there's ExtremeZ-IP, but I really don't want to spend $675 do something Apple claims OS X can already do. I can put just about any non-Mac OS on this thing... what's the best way to set it up so it works?
    Thanks much.

    Rick may be right because although i didnt think of it before i tend to have notoriuosly long classnames for my php classes and i have used samba on occasion (when rsync is out of the question for one reason or another) and never had a problem. I use kubuntu (feisty at the moment )with an ext3 filesystem. if i have a chance this evening ill give it a try and see what happens.
    You could also possibly use FUSE to use an ssh filesystem for the shares... i don tknow how that would figure in your back up though.
    Also if worse comes to worse you could tar or dmg the the necessary files... just some thoughts.
    Ill be interested to know what you end up implementing....
    OH one last thought... Compile Darwin from source and use that as your server

  • Best setup for iMac with SSD & HDD? Best location of scratch & home folders

    Best setup for iMac with SSD and HDD? Best location of scratch & home folders?
    Computer:
    iMac 2.93 GHz Quad core i7, 8GB RAM, 1 TB HDD + 256 GB SSD
    There is not much info from Apple about the best way to set up an iMac with a Hard Drive and Solid state drive. I’ve looked at a few of the forum posts across the web and came up with a plan and lots of questions. (I do use photoshop frequently, but not on a professional level):
    1. I will keep OS and Applications on SSD
    2. About moving the home folder: I saw some posts about moving the whole home folder, but it makes more sense to me to only move selected fodlers withing the home folder tomake the best use of the SSD. So will keep the home folder on SSD, but move certain folders (document /music/iphoto/download) to 1 TB HDD via instructions I found on the macintoshperformanceguide website:
    cd
    sudo cp -r Documents /Volumes/Master
    sudo rm -rf Documents
    sudo ln -s /Volumes/Master/Documents Documents
    3. I would like to get 8 more RAM when I can afford it
    4. I will attach an external hard drive for most of my documents and backup storage
    5. Now here is where I’m not sure what’s best:
    a. Should I partition my internal 1 TB hard drive and use the first partition as a scratch disc for photoshop and other applications? How much should I partition? Is there any benefit to this if the rive is partitioned?
    b. Should I use an external drive as a scratch disc?
    c. Any advice on a good 1-2 TB external drive?
    d. Should I just leave things in factory settings?
    Don't assume I know the basics - I got all the above just by searching around. Any advice and commentary is appreciatedThanks.
    Message was edited by: sfandtheworld

    Thanks for the advice and the links. yes, I would like to speed up ps as much as possible.
    I wonder if putting the scratch disc on the same drive as the OS would cause them to interfere with each other? Even if they are on different partitions, they would not be able to be accessed at the same time, or could they? That's why I was wondering if I should place scratch disc on the internal HDD -- but then I don't know how much to partition for it (or to partition at all?)
    ALso, I read on a few places that too much read/write on the SSD wears it down over time? Is this more of a theoretical concerns - it does not make sense to me since it has no moving parts!
    thanks again for the advice ... I'm gonna go digest those links

  • Need advice on best setup for Extreme and Express w/ (n only) network

    I'd like to get some advice on the best setup for my situation. I've read a number of posts on WDS, Extending a Network, etc. and, unfortunately, I'm now more confused than ever.
    We have an Airport Extreme 802.11n using WPA2 Personal, 2.4Ghz (n only connection) which I've found to give us the best range/connection speeds for the following devices (all computers running 10.5.5, Apple TV's using most current update):
    (2) MacBooks
    iMac
    (2) AppleTVs
    The good news we have a large house, the bad news we have a large house. Meaning of course that I don't get the range in parts of the house I'd like to. I also have an older Mini (G4) connected to the AEBS thru ethernet (the Mini acts as the iTunes server for the ATVs).
    I just bought a new Airport Express with the desire to place it on the other side of the house to both enhance the range of the wireless network and to provide another wired to wireless connection to the network.
    I initially merely chose to "Extend a wireless network" but that seems to have a MAJOR adverse impact on the speeds of the wireless network. dropping the streaming to one of the ATV by like 90%. I would like to maintain the security settings I have as well as the 2.4Ghz (n only) since these provide the best speed/connection range on the AEBS.
    My question then is what is the best way to use the AX (WDS? Bridge?).

    The best way to use it is the option you chose "Extend a wireless network".
    WDS forces you to the much slower 802.11g and even cuts that bandwidth in half.
    Operating as a bridge has nothing to do with wirelessly extending a network. Changing this option won't have any effect on wireless bandwidth.

  • Best Setup For Frequent File Sharing On Home Network?

    Hi guys,
    I'm setting up an office at my house with multiple computers on a network, and we'll be sharing files over the network frequently. My question is, what is the best setup for this?.. Fastest transfer of files, stable wireless connection, etc.
    All of the computers will be Macs (iMacs and Macbooks).
    We'll be editing videos/photos on the computers. (Potentially large files)
    Is the easiest setup just to have the main computer attached to a good router, setup file sharing on all other computers, and just do it that way?
    Or would it be better to create some sort of NAS?
    Also can someone reccomend a good router for this type of scenario?
    Thanks for any help given.

    NAS is the right tool for this job.
    It is expensive but the market leaders.. synology and QNAP have really been doing it for long time and the ability to do file store/sharing and most importantly backup in these is excellent. Pick the best you can afford.. and buy disks that are in the recommended list. ie the cheapest are not always the best.. indeed they seldom are.
    Plan very carefully for rotation of USB drives (easy and cheap now with 4TB single drives). Rotate backups with offsite location on weekly basis.
    I would buy a 4 disk case.. you can use 4x3TB which are the best value at the moment.. that gives you 9TB of storage.. plus redundancy for a dead drive.
    Alternatives are using a Mac Mini as a server.. with a large stack of disks on it.. generally should be thinking thunderbolt if you want speed. Hideously expensive though for now.
    You can buy an Extreme or TC.. either would work well. TC allows you easy TM backups without using your NAS..
    Edit very large files on the computer. ie copy to computer.. edit.. copy back to the NAS.
    Editing very large files over wireless.. not good. Multiply that by mutliple computers.. not even fair.
    Copy a large project to the computer.. work on it.. copy back to the NAS.. in the meantime Time Machine should be able to take care of incremental backups.
    There are heaps and heaps of solutions.. as long as it is logical and easy to you.. and covers what you need.
    Don't skimp.. spending a $1000 for a NAS with disks.. plus extra for the backup disks.. that represents how many day's work for you plus anyone you have helping.. $$$$ ????
    A mini as a server is a good alternative.. You don't need to run server OS.. but share files to the network. Very hard to build the capacity of the NAS though.
    And a Mac Pro is now a joke without internal slots and cages for drives. (nice machine but wrong for this).
    And Apple have nothing in between.. a short tower case.. been missing for a long long time.

  • Best setup for a swing application

    Hello,
    I have developed an Swing application for a EPOS machine.
    The machine has around 512 ram.
    What's the best setup for me in terms of performance, for example, which JVM to use etc.....
    Cheers
    Bobby

    bsbiran wrote:
    Hi,
    Well the app require alot of images and I parts of it do run 'slow'
    ...I'm currently going through a book about Swing and read that many times the "slowness" of a Swing-application can be credited to the programmer for not using the API efficiently/correctly (letting the app repaint too much, or repainting large parts that don't need repainting at all, to name just two things). So, I don't know how much of a Swing-guru you are, but it might be better to read a few decent Swing tutorials or pick up a good Swing book.

  • Just bought a 3TB Time Capsule for a small office. Will have 4 users with MacBooks. What would ne the best setup for time machine individual backups and internet sharing in a secure way?

    Just bought a 3TB Time Capsule for a small office. Will have 4 users with MacBooks. What would ne the best setup for time machine individual backups and internet sharing in a secure way?

    Set up each Mac for Time Machine backups in the normal way.  Time Machine will keep each backup separate on the Time Capsule, so users will only be able to see the backups of their own Mac.
    Yes....there are convoluted workarounds that might allow one user to see the backups of another.....IF...they know the administrator password of the "other" Mac.
    As far as Internet sharing, all users will have access to the Internet if they have a wired or wireless connection. If a Mac connects using wireless, it is possible to limit the time that they are allowed to connect to the network.
    For example, you might limit the ability to connect to the wireless from say each Weekday from 8 AM to 6 PM.
    With a wired Ethernet connection, you cannot limit access times to the Internet.

  • Best setup for new airport with wired connection to old airport extreme (4th gen)

    I have an AirPort Extreme (4th gen) in my basement (of a three story house) connected directly to the Fios box (I am not using the Verizon g router).  The new AirPort (ac) is connected to the old one by in-wall Cat 6e to an upstairs bedroom.  Can/should I turn off wifi on the n router for best wireless performance?  What would the optimal setup be?
    On the airport utility I selected "replace existing Airport" and the new ac router is up and running and working fine.  I wonder whether the fact that wifi on the old Airport is still on may be good for coverage around the house, but compromising the wireless bandwidth/speed?  I haven't noticed any speed issues yet, but I do a lot of video streaming so I want to ensure I have the best setup.  Range doesn't seem to be a major issue in my house.  It is more important to me to have strong wifi signal upstairs.
    Thanks in advance for advice.

    If the AirPorts are connected using Ethernet, then no bandwidth is being lost on the network. Keep the wireless functions "on" at both AirPorts for additional wireless coverage and speed.

  • Best setup for external hard drive and iMac?

    Just purchased a Seagate FreeAgent GoFlex 1TB external HD for my Mac OSX 10.5.8. Would like to use it to backup all my pics/writing (I am a writer/photog), videos, and music - about 400 gigs worth at present. As an analog person, I am confused as to how best I should format the drive:
    option 1 being to use drive with Time Machine (just now heard of it),
    option 2 to use drive for storage and backup (what's the diff) using Memeo software,
    option 3 to use for storage by reformatting with Disc Utilities.
    This, no doubt, is easy language for most of you, but Japanese to me, a Nuyorican.
    Again, I mainly would like to have backups for what's on my iMac, in case that dreaded day comes and it goes kaput. What would be the best option for me to simply transfer everything, unplug it and put it in a safe place? And if and when I do that, could I, two years, months, weeks later, plug it back in and add what pics or whatever I've accrued to it and replace it in that safe place once again? Looking for what is most practical for the safe keeping of my precious files.
    Hope my old tactile-inclined *** is making sense.
    Appreciate any and all assistance here. Thanks in advance.

    I have to agree with JG, I'd strongly recommend using Time Machine as your primary backup. BTW there is a forum specifically for TM that has a FAQ section and if you need it (most never do) a troubleshooting section. You can find that forum at:
    http://discussions.apple.com/forum.jspa?forumID=1227
    Many people like myself believe in redundant backups, in other words 2 is better than one. If you decide to go that route you will need a second external HD and then use software like SuperDuper or Carbon Copy Cloner. What these applications do is create bootable clones, so if your iMac's internal HD dies you have a bootable clone that you can use to run your machine until the internal HD is replaced. Dual backups are also good if one backup's HD dies.
    Below are links to 3 articles I found in MacWorld magazine, what they are is backup strategies of 3 individuals to give you some ideas so you can figure out what is best for your needs.
    Operating any computer without a backup plan is a recipe for disaster. Many people put their digital life on their computer (photographs, music, movies etc..) without a backup and then cry and moan when their computer dies. These days there is no reason one shouldn't be backing up their computer.
    http://www.macworld.com/article/157414/2011/02/mybackupplanlex.html
    http://www.macworld.com/article/156643/2011/01/howi_back_up_frakes.html?lsrc=top1
    http://www.macworld.com/article/141363/2009/07/backup.html
    Roger

  • Best Setup for Lion Server Time Machine Backup with Drobo?

    I've been thinking about this a lot, yet I don't feel I have a good solution for this, so I'm going to throw it out to the community.
    I have a home server setup using a Mac Mini running Lion Server 10.7.2 with a Firewire 800 Drobo attached.  The Drobo is used for both Time Machine backups and files.  I also have a Powerbook G4 running Leopard and a MacBook 2.4 GHz Intel Core 2 Duo with Lion 10.7.2 which connect to the Server and the Drobo wirelessly thorugh an Airport Extreme.
    I want to use Time Machine to have all of my computers back up to the server & Drobo, but realize there are several ways to go, each with their pluses and minuses:
    Server Time Machine Backup:
    + Centralizes backup process, rules, and other elements
    + Currently Mac Mini is backing up to the Drobo correctly using this process
    + Have setup size limit on Server backup so that it does not eat up file space
    - Would combine laptop backups with server backup into one sparse image: this would lead to the computer with the largest backup needs taking up too much space
    Client-Driven Time Machine Backup:
    + Allows for customization of backup processes by computer
    + Can setup specific space requirements for each computer
    + Backups are separate from each other
    - Wireless backup from laptops to Drobo is not functioning currently
    Any thoughts or experiences on how best to set this up?  I tend to do most of my work on the MacBook, hence I am concerned about it having it's backup space eaten up by the server, but that may be more of a theoretical issue than a real one.
    Thanks in advance for your help!

    Well I'm not sure if I am following you but I will explain how I set mine up. When I got the Drobo I inserted 2 drives and selected the highest available volume I could (16TB). My drives are 4 TB each and I knew I would soon add 2 more. Then Drobo did its thing and prepared these drives. The Drobo shows up on my mini desktop as an external drive. When I log into my server from my other computer I can see the mini server volume and the Drobo volume. I can access each no problem. They act as regular volumes. Soon after I added the second two drives and everything stayed the same meaning I could still see and access the Drobo on the desktop of my mini. So it sounds like you used the Drobo dashboard to partition yours for two volumes? Are they both showing on the desktop? 
    "Maybe the Drobo needs to be mounted on the desktop to be considered AFP feature enabled." I could be wrong and hopefully someone will correct me but I think the Drobo (or volumes) have to be mounted on the desktop to work with AFP.

  • Best setup for multiple email accounts

    I have 8 email accounts in my iphone 3G and it seems that many times it gets "hung" up on the first one (gmail) because it just says "connecting". The only way to solve it is to turn the phone off and then on again, which I'm doing several times a day. For now, I have every account set to manual fetch. Any suggestions on how to solve this issue, and the best way to setup the fetching, etc.?

    Note sure what G mail is, but if it involves another isp email provider not interested, I have multiple accounts as a garbage dump for spam possibilities too much spam on one account bye bye. Usually 2 main email accounts though. btw, not a memory issue either. still plenty left. Was looking at the contacts thread and there is receiving/sending issues with email since 2.0 update anyway.

  • Best setup for privacy?

    I have two G5s, running osx 10.4.11. They are each connected a linksys wireless router, along with a printer and the internet connection.
    My understanding is that to share, you turn file sharing to on, on both, and let them detect each other.
    I would like to leave file sharing between the two computers on all the time so I can go from one to the other. But how can I best protect myself from outside access, without buying any other software? I don't want my neighbors accessing my computer.
    Hooking them directly to each other is not an option, because it will cut off internet and printer access.
    Thanks in advance.

    The default Ethernet network connections are controlled through the
    System Preferences> Network panel> where you can look into the
    configurations and see what options are check-boxed to appear in
    the main appearing selection (where enabled options appear as either
    active or inactive) so you can shut off the wireless without removing
    wires, from the System Preferences Network panel. Once you have an
    option chosen here, you can also make changes to turn off the wi-fi.
    Later, you could physically disconnect the wireless device attached to
    the internet modem; or leave it attached and learn more about how to
    have and maintain a secure wireless network. Perhaps by using the
    MAC address of each machine to help more securely use the wi-fi.
    And, not broadcast the name of your wireless network can help slow
    down those who are simpler-minded about looking into visible networks.
    You can also choose to change the DNS address (see ethernet setting
    pane in Network) to what may be a more secure one than the ISP has.
    I have not done this, but it has been said to help prevent some issues.
    OpenDNS - Change your DNS (OS X Tiger)
    https://store.opendns.com/setup/operatingsystem/apple-osx-tiger
    Mac OS X 10.4 Help: Setting up a network connection
    http://docs.info.apple.com/article.html?path=Mac/10.4/en/mh1152.html
    Using the OS X Help section in your Finder menu bar, should allow
    you access to information on how to change network settings. In
    the Networks panel, in the area you can change the default and
    choose other options to appear, you can also drag into priority status
    what you may wish to have in an order of preference. This is basic.
    Of course, an Ethernet cable would have to be attached between the
    internet provider's cable/dsl modem and your computer for the default
    network connections to be of service, if there isn't already one available.
    The security documents cover a wider range of higher level info, if
    you should choose to get them and read them over a period of time.
    Good luck & happy computing!
    { edited }

  • Best setup for a prewired ethernet home

    Hello,
    This has probably been addressed at some point but I cannot find the best combination to search for it.  My home was prewired throughout with ethernet cables.  They all come back to a box in a closet where AT&T Uverse has service coming in and gigabit ethernet switches to feed the jacks being used.  Most everything I have is wifi but I use my imac to stream to ipads/iphones/apple tv's and also have it configured to backup wirelessly to an external harddrive plugged into an airport extreme.
    I would like to keep everything mostly as it is but to hard wire the imac.  It is in the one room in the home without good wifi coverage so backups through time machine and streaming are frequently dropped or delayed.  I could add an additional Airport Express but that seems like a half solution with an ethernet cable right there.
    My questions are 1)  is there a controller or something to plug in that would feed the signals from the imac to the apple tv in another room through the ethernet cables 2) would this same setup allow the time capsule backups to occur through ethernet instead of wifi for this computer 3) if this isn't possible or is difficult should I be able to plug ethernet into the imac so it at least benefits from faster download speeds and have it still operate the same over wifi for everything else?
    Thanks for any help or pointing me to other threads if this has been addressed somewhere I haven't found!
    Not sure if it matters but we have Apple TV, Imac, mac book, Airport Extreme and 1 Express and assorted ipads and iphones on the network.

    Matt is correct. Connecting to the Ethernet will work as he described. I might also suggest that you consider connecting other devices to the hard wired Ethernet as well. Gigabit Ethernet is faster than Wi-Fi in most instances. I have my Apple TV connected to my Ethernet along with as many other devices as I can. Only my iPad, iPhones and laptops connect through Wi-Fi. My desktop computers, DirecTV receivers, Blue Ray player and sound system are all connected to the Ethernet In my home.

  • Best setup for a small iMac network with NAS?

    Hello all,
    Any recommendations on how to setup a small network with 3 machines and mutiple users?
    We run a design studio and currently have 3 x 27" iMacs with a couple of laptops that come and go, that all connect to a Synology DS213 NAS drive. (All the iMacs are connected to the NAS via ethernet through a gigabit switch, so we have a reliable connection)
    All 3 machines have just had their HD's replaced (all backup up to the NAS) and are currently blank canvases - so I'm keen to get a decent network system up and running that works well in conjunction with the NAS drive. They're all running 10.6.8, but I'm happy to put them on Mountain Lion and install OSX server. It seems most feedback isn't great, but I'm interested to hear any ideas,
    Thanks in advance..

    Rick may be right because although i didnt think of it before i tend to have notoriuosly long classnames for my php classes and i have used samba on occasion (when rsync is out of the question for one reason or another) and never had a problem. I use kubuntu (feisty at the moment )with an ext3 filesystem. if i have a chance this evening ill give it a try and see what happens.
    You could also possibly use FUSE to use an ssh filesystem for the shares... i don tknow how that would figure in your back up though.
    Also if worse comes to worse you could tar or dmg the the necessary files... just some thoughts.
    Ill be interested to know what you end up implementing....
    OH one last thought... Compile Darwin from source and use that as your server

  • What's the best setup for a dedicated boot drive (Lion) with a separate storage drive?

    I have a 120GB SSD and 4 x 3TB drives striped together for storage on my hot off the shelf Mac Pro. This may be an elementary question and I'm sure it's like every other post in these forums but what really is the best way to maintain a dedicated OSX Lion boot drive while keeping user profile type stuff on the storage drive? A few thoughts...
    1) I know the risks with striping, which is why it will all be backed up online. Yes. Online.
    2) I am specifically curious about how to keep pretty much all of the User folder type stuff on the storage drive...at least the big stuff.
    Any recommendations? I know Win7 had some big problems with doing this kind of thing. My main goal is to be able to reinstall OS X every day if I wanted and not affect the users or their respective data. Possible? 

    The desktop is implemented by a folder by the same name in the Home folder for each user.
    Before you move it, it will be here:
    /Users/<your_shortname>/Desktop
    I would first try providing an alias in Finder to replace that Folder.
    If that does not work, you may need to use Terminal to create a Symbolic Link.
    ln -s  <desired location> <where the link should be created>
    You can open up terminal and type in man ln to see the other options and how the command works.

Maybe you are looking for

  • Synchronizing color settings in Adobe Bridge

    I want to synchronize color settings in Adobe Bridge and I've currently installed photoshop extended CS5 and InDesing CS5.5 (these programs are not installed from any Adobe Creative Suite package. I mean these are not from: Adobe Creative Suite 5.5 D

  • Hmm, to the person who asked why the store carries cover versions...

    Not sure what caused that thread to disappear... Apple don't monitor these forums for feedback nor answer questions directly. You may send your thoughts to iTunes Feedback if you wish. There is a long tradition of different artists recording the same

  • Problem of Down Payment for the Asset under Construction

    Hi All: My problem is, after do down payment for the AuC, we got an additional amount under the values booked of AuC, double checked the accounting document, found that system generated two items when doing actual settlement with t-code CJ88, for exa

  • Prefix, call and receive.

    Hi, I've a business SIM card that requires I add a code (46) in front of every phone number and sms I send. with my previous handheld, a Palm Treo, I simply added this prefix in the contacts but doing this with iPhone doesn't make it recognize incomi

  • JSF and VoiceXML

    Hi, From my reading of JSF books it appears that a JSF based VoiceXML application will need custom components and renderers in order to render the output in VoiceXML. Are there plans in the near future to extend ADF to include support for VoiceXML ?