<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Äkta Avant on Michael’s Domain</title><link>https://jeltsch.org/en/tags/%C3%A4kta-avant/</link><description>Recent content in Äkta Avant on Michael’s Domain</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright © 2002 - 2026 Michael Jeltsch.</copyright><lastBuildDate>Fri, 24 Jul 2026 00:18:18 +0300</lastBuildDate><atom:link href="https://jeltsch.org/en/tags/%C3%A4kta-avant/index.xml" rel="self" type="application/rss+xml"/><item><title>Protein Purification Course 2019</title><link>https://jeltsch.org/en/protein_purification_course_2019/</link><pubDate>Wed, 31 Jul 2019 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/protein_purification_course_2019/</guid><description>&lt;p&gt;We are again hosting the DPBM protein purification course this December in our lab. Secure your place as this practical course is popular and there are only 16 seats. You can bring your own protein and we will individualize the course program based on your needs!More information: 
 &lt;a href="http://research.med.helsinki.fi/corefacilities/b3p/teaching.htmlRegistration" target="_blank" rel="noopener noreferrer nofollow"&gt;http://research.med.helsinki.fi/corefacilities/b3p/teaching.htmlRegistration&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
: 
 &lt;a href="https://courses.helsinki.fi/en/dpbm-135/131042336" target="_blank" rel="noopener noreferrer nofollow"&gt;https://courses.helsinki.fi/en/dpbm-135/131042336&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
&lt;/p&gt;</description></item><item><title>Practical Course: Purification and Characterization of Recombinant Proteins (DPBM-135)</title><link>https://jeltsch.org/en/dpbm_135/</link><pubDate>Sun, 10 Dec 2017 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/dpbm_135/</guid><description>&lt;p&gt;Teaching material, results, etc. for the DPBM course &amp;ldquo;Purification and Characterization of Recombinant Proteins&amp;rdquo; (
 &lt;a href="https://courses.helsinki.fi/en/DPBM-135/120171139" target="_blank" rel="noopener noreferrer nofollow"&gt;https://courses.helsinki.fi/en/DPBM-135/120171139&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 ):&lt;/p&gt;</description></item><item><title>Unicorn 7-Benutzer-Einrichtung erfordert manuelle Intervention in einer Netzwerkbenutzer-Umgebung</title><link>https://jeltsch.org/en/unicorn_7_benutzer_einrichtung_erfordert_manuelle_intervention_in_einer_netzwerkbenutzer_umgebung/</link><pubDate>Fri, 17 Jun 2016 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/unicorn_7_benutzer_einrichtung_erfordert_manuelle_intervention_in_einer_netzwerkbenutzer_umgebung/</guid><description>&lt;p&gt;Unicorn, Äkta Avant, Äkta Explorer, GE Healthcare, Windows, Netzwerk-Authentifizierung, Benutzer-Einrichtung, Methode, Resultat, Wissenschaft, ProteinaufreinigungSince we are operating our Äkta Avant in a multiuser environment, we need to separate the methods and results of the different users. By default, every network user is at the moment able to see every method and every result that has been generated on the machine by any other network user. This is a considerable privancy and security issue as a malicious user could delete (or even worse: modify) methods and results.Our Äkta is set up in a way that allows users to log into the Unicorn 7 computer with their university login/password via the regular Windows network authentication mechanism. However, if several people share the responsibility of a run, this setup becomes impossible as they would need to devulge their passwords to each other. Hence we have created a local account which can be used by users who wish to share the operation of the Äkta.After logging into Winodws, users still have to log into the Unicorn 7 software, which users do with their university login and password (&amp;ldquo;Windows authentication&amp;rdquo;). Using this setup, every user is able to see all methods and results, which is not acceptable.When setting up a new user with Unicorn version Access&amp;gt;Folders&amp;quot;) and exactly which folders were accessible by that user and the user would see only his/her own methods and results. Since the folder structure under Unicorn 5 was a folder structure of the Windows file system, users could always copy methods and results from one folder to another and thereby make them available despite the limitations set by the Unicorn 5 program.When I first read that Unicorn 7 supports Windows network authentication, I had hoped that we would be able to avoid the painful user setup which we had to go thru for each user on the Äkta Explorer. However, the pain continues as setting up the user privileges once for a group doesn&amp;rsquo;t give us user isolation.Firstly, one cannot restrict access of individual users in Unicorn 7, but only access of groups. We had to create one Access Group for each network user, add the network user to this group, create a separate home folder for the group and then restrict the folder access to this home folder. Hundreds of clicks were required for a handful of users since the default is no access to anything and every single privilege check box needs to be enabled except for the admin privileges.In that respect, Windows (and every other OS) is way smarter than Unicorn. If a university employee logs into a machine that he or she has never been logging into before, it creates all the necessary default local folder structure automatically and mounts that users private home folder without granting access to everything other employees have been doing on that specific machine. I think that should be an option on Unicorn as well. Maybe it is and I just can&amp;rsquo;t figure it out?Another big drawback of the above described method of separating each user into an own access group is that login into the Unicorn program becomes a major ordeal: In addition to writing user name and password the user has to select the correct access group for the login to be successful. And even worse: In our setup we cannot avoid that every university employee belongs to two access groups: A manually created access group for each user for user separation and the &amp;ldquo;default&amp;rdquo; which works via the Windows network authentication - maybe Kerberos?). Hence, if users do choose the default access group (which is called &amp;ldquo;Users&amp;rdquo; in our case), they are able to log in, but they don&amp;rsquo;t see their methods and results.There are two reasons we cannot delete the &amp;ldquo;Users&amp;rdquo; access group: One is the mandate of the faculty and secondly (and we have tried), we cannot delete it anymore as many people have already created methods and generated results being in the access group &amp;ldquo;Users&amp;rdquo;. Thus UNICORN prevents us from deleting this account. I am working on this problem: I should be able to access directly the underlying MS-SQL database in order to change the ownership of the methods and results. However, GE was not exactly forthcoming when I was asking about access right handling. The answer was:The DB access credentials in a standalone UNICORN solution are encrypted and are not public. If you had an enterprise solution (hosting your own (SQL server) DB) you would have control of the credentials and in theory you could extract the wanted information (the format is something that you have to figure out by yourself and is not supported by us). You can upgrade your solution to an enterprise if you want.This sounds worse than it is, because we have physical access to the MS-SQL server and pulling out the access credentials seems not very difficult. But it takes my time to find the exploit to &amp;ldquo;break into our own system&amp;rdquo; and that is what annoys me. However, according to Lisa Bromark from GE, the 7.0.2 update seems to correct this issue:UNICORN can be configured to use a new database password. It is possible to generate an encrypted password or to enter an already encrypted password. This is done by running the UNICORN Service Tool after UNICORN installation.However, it is unbelievably difficult to get the update (at least it seems to take weeks). Distribution is apparently still via optical media and snail mail. I think the last time I got myself software via a CD/DVD was more than 10 years ago. However, GE told me that they are just moving UNICORN software updates to &amp;ldquo;electronic distribution&amp;rdquo;. Welcome to the 21 century!&lt;/p&gt;</description></item><item><title>Unicorn 7 user separation requires manual intervention in a network user environment</title><link>https://jeltsch.org/en/unicorn_7_user_separation_requires_manual_intervention_in_a_network_user_environment/</link><pubDate>Mon, 09 May 2016 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/unicorn_7_user_separation_requires_manual_intervention_in_a_network_user_environment/</guid><description>&lt;p&gt;Since we are operating our Äkta Avant in a multiuser environment, we need to separate the methods and results of the different users. By default, every network user is at the moment able to see every method and every result that has been generated on the machine by any other network user. This is a considerable privancy and security issue as a malicious user could delete (or even worse: modify) methods and results.Our Äkta is set up in a way that allows users to log into the Unicorn 7 computer with their university login/password via the regular Windows network authentication mechanism. However, if several people share the responsibility of a run, this setup becomes impossible as they would need to devulge their passwords to each other. Hence we have created a local account which can be used by users who wish to share the operation of the Äkta.After logging into Winodws, users still have to log into the Unicorn 7 software, which users do with their university login and password (&amp;ldquo;Windows authentication&amp;rdquo;). Using this setup, every user is able to see all methods and results, which is not acceptable.When setting up a new user with Unicorn version Access&amp;gt;Folders&amp;quot;) and exactly which folders were accessible by that user and the user would see only his/her own methods and results. Since the folder structure under Unicorn 5 was a folder structure of the Windows file system, users could always copy methods and results from one folder to another and thereby make them available despite the limitations set by the Unicorn 5 program.When I first read that Unicorn 7 supports Windows network authentication, I had hoped that we would be able to avoid the painful user setup which we had to go thru for each user on the Äkta Explorer. However, the pain continues as setting up the user privileges once for a group doesn&amp;rsquo;t give us user isolation.Firstly, one cannot restrict access of individual users in Unicorn 7, but only access of groups. We had to create one Access Group for each network user, add the network user to this group, create a separate home folder for the group and then restrict the folder access to this home folder. Hundreds of clicks were required for a handful of users since the default is no access to anything and every single privilege check box needs to be enabled except for the admin privileges.In that respect, Windows (and every other OS) is way smarter than Unicorn. If a university employee logs into a machine that he or she has never been logging into before, it creates all the necessary default local folder structure automatically and mounts that users private home folder without granting access to everything other employees have been doing on that specific machine. I think that should be an option on Unicorn as well. Maybe it is and I just can&amp;rsquo;t figure it out?Another big drawback of the above described method of separating each user into an own access group is that login into the Unicorn program becomes a major ordeal: In addition to writing user name and password the user has to select the correct access group for the login to be successful. And even worse: In our setup we cannot avoid that every university employee belongs to two access groups: A manually created access group for each user for user separation and the &amp;ldquo;default&amp;rdquo; which works via the Windows network authentication - maybe Kerberos?). Hence, if users do choose the default access group (which is called &amp;ldquo;Users&amp;rdquo; in our case), they are able to log in, but they don&amp;rsquo;t see their methods and results.There are two reasons we cannot delete the &amp;ldquo;Users&amp;rdquo; access group: One is the mandate of the faculty and secondly (and we have tried), we cannot delete it anymore as many people have already created methods and generated results being in the access group &amp;ldquo;Users&amp;rdquo;. Thus UNICORN prevents us from deleting this account. I am working on this problem: I should be able to access directly the underlying MS-SQL database in order to change the ownership of the methods and results. However, GE was not exactly forthcoming when I was asking about access right handling. The answer was:The DB access credentials in a standalone UNICORN solution are encrypted and are not public. If you had an enterprise solution (hosting your own (SQL server) DB) you would have control of the credentials and in theory you could extract the wanted information (the format is something that you have to figure out by yourself and is not supported by us). You can upgrade your solution to an enterprise if you want.This sounds worse than it is, because we have physical access to the MS-SQL server and pulling out the access credentials seems not very difficult. But it takes my time to find the exploit to &amp;ldquo;break into our own system&amp;rdquo; and that is what annoys me. However, according to Lisa Bromark from GE, the 7.0.2 update seems to correct this issue:UNICORN can be configured to use a new database password. It is possible to generate an encrypted password or to enter an already encrypted password. This is done by running the UNICORN Service Tool after UNICORN installation.However, it is unbelievably difficult to get the update (at least it seems to take weeks). Distribution is apparently still via optical media and snail mail. I think the last time I got myself software via a CD/DVD was more than 10 years ago. However, GE told me that they are just moving UNICORN software updates to &amp;ldquo;electronic distribution&amp;rdquo;. Welcome to the 21 century!&lt;/p&gt;</description></item><item><title>The logic of the Äkta Avant fraction collector</title><link>https://jeltsch.org/en/the_logic_of_the_akta_avant_fraction_collector/</link><pubDate>Mon, 02 May 2016 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/the_logic_of_the_akta_avant_fraction_collector/</guid><description>&lt;p&gt;After we solved all the [teething troubles with our Äkta Avant]((/en/akta_avant), we finally dare to let customers use it. Our customers are very heterogeneous covering complete novices to FPLC and experienced Äkta Explorer users (and everything in between). When we have been giving feedback to GE, our perspective is obviously biased towards a certain type of user. However, taking care of customers is giving us now a new perspective since we get confronted with the usability problems that they cannot solve by themselves. Here I just want to mention one stumbling stone, that has repeatedly brought up to us: the rationale behind the operating mode of the fraction collector. Unlike in the older systems, the fractions collector cannot be manually reset to &amp;ldquo;First position&amp;rdquo; or to any arbitrarily defined position as was possible e.g. under Unicorn 5.It took us ourselves quite a while to get used to the internal logic of the fraction collection process and we needed guidance from GE. The fact that the system is not behaving intuitively is underlined by the fact that some of the answers that we received from GE experts were incomplete (leading for us to some unpleasant sample losses). Finally we received from GE support a table that describes the behaviour of the fraction collector (see below). However, even that table is incomplete and we have added a few lines that describe some non-standard situations for which the table does not provide an answer. These changes and additions to GE&amp;rsquo;s description have been marked in red.&lt;/p&gt;</description></item></channel></rss>