--- loncom/interface/domainprefs.pm	2021/12/24 21:00:55	1.160.6.115
+++ loncom/interface/domainprefs.pm	2022/02/22 19:18:45	1.160.6.118.2.7
@@ -1,7 +1,7 @@
 # The LearningOnline Network with CAPA
 # Handler to set domain-wide configuration settings
 #
-# $Id: domainprefs.pm,v 1.160.6.115 2021/12/24 21:00:55 raeburn Exp $
+# $Id: domainprefs.pm,v 1.160.6.118.2.7 2022/02/22 19:18:45 raeburn Exp $
 #
 # Copyright Michigan State University Board of Trustees
 #
@@ -218,13 +218,43 @@ sub handler {
                 'serverstatuses','requestcourses','helpsettings',
                 'coursedefaults','usersessions','loadbalancing',
                 'requestauthor','selfenrollment','inststatus',
-                'passwords','wafproxy','ipaccess'],$dom);
+                'passwords','ltitools','ltisec','wafproxy','ipaccess'],$dom);
+    my %encconfig =
+        &Apache::lonnet::get_dom('encconfig',['ltitools','linkprot'],$dom,undef,1);
+    if (ref($domconfig{'ltitools'}) eq 'HASH') {
+        if (ref($encconfig{'ltitools'}) eq 'HASH') {
+            foreach my $id (keys(%{$domconfig{'ltitools'}})) {
+                if (ref($domconfig{'ltitools'}{$id}) eq 'HASH') {
+                    foreach my $item ('key','secret') {
+                        $domconfig{'ltitools'}{$id}{$item} = $encconfig{'ltitools'}{$id}{$item};
+                    }
+                }
+            }
+        }
+    }
+    if (ref($domconfig{'ltisec'}) eq 'HASH') {
+        if (ref($domconfig{'ltisec'}{'linkprot'}) eq 'HASH') {
+            if (ref($encconfig{'linkprot'}) eq 'HASH') {
+                foreach my $id (keys(%{$domconfig{'ltisec'}{'linkprot'}})) {
+                    unless ($id =~ /^\d+$/) {
+                        delete($domconfig{'ltisec'}{'linkprot'}{$id});
+                    }
+                    if ((ref($domconfig{'ltisec'}{'linkprot'}{$id}) eq 'HASH') &&
+                        (ref($encconfig{'linkprot'}{$id}) eq 'HASH')) {
+                        foreach my $item ('key','secret') {
+                            $domconfig{'ltisec'}{'linkprot'}{$id}{$item} = $encconfig{'linkprot'}{$id}{$item};
+                        }
+                    }
+                }
+            }
+        }
+    }
     my @prefs_order = ('rolecolors','login','ipaccess','defaults','wafproxy','passwords',
                        'quotas','autoenroll','autoupdate','autocreate','directorysrch',
                        'contacts','usercreation','selfcreation','usermodification',
                        'scantron','requestcourses','requestauthor','coursecategories',
                        'serverstatuses','helpsettings','coursedefaults',
-                       'selfenrollment','usersessions');
+                       'ltitools','selfenrollment','usersessions','lti');
     my %existing;
     if (ref($domconfig{'loadbalancing'}) eq 'HASH') {
         %existing = %{$domconfig{'loadbalancing'}};
@@ -506,6 +536,26 @@ sub handler {
                   print => \&print_loadbalancing,
                   modify => \&modify_loadbalancing,
                  },
+        'ltitools' =>
+                 {text => 'External Tools (LTI)',
+                  help => 'Domain_Configuration_LTI_Tools',
+                  header => [{col1 => 'Setting',
+                              col2 => 'Value',}],
+                  print => \&print_ltitools,
+                  modify => \&modify_ltitools,
+                 },
+          'lti' =>
+                 {text => 'LTI Link Protection and LTI Consumers',
+                  help => 'Domain_Configuration_LTI_Provider',
+                  header => [{col1 => 'Encryption of shared secrets',
+                              col2 => 'Settings'},
+                             {col1 => 'Rules for shared secrets',
+                              col2 => 'Settings'},
+                             {col1 => 'Link Protectors',
+                              col2 => 'Settings'},],
+                  print => \&print_lti,
+                  modify => \&modify_lti,
+                 },
          'ipaccess' =>
                        {text => 'IP-based access control',
                         help => 'Domain_Configuration_IP_Access',
@@ -521,7 +571,7 @@ sub handler {
                             header => [{col1 => 'Log-in Service',
                                         col2 => 'Server Setting',},
                                        {col1 => 'Log-in Page Items',
-                                        col2 => ''},
+                                        col2 => 'Settings'},
                                        {col1 => 'Log-in Help',
                                         col2 => 'Value'},
                                        {col1 => 'Custom HTML in document head',
@@ -701,8 +751,12 @@ sub process_changes {
         $output = &modify_usersessions($dom,$lastactref,%domconfig);
     } elsif ($action eq 'loadbalancing') {
         $output = &modify_loadbalancing($dom,%domconfig);
+    } elsif ($action eq 'lti') {
+        $output = &modify_lti($r,$dom,$action,$lastactref,%domconfig);
     } elsif ($action eq 'passwords') {
         $output = &modify_passwords($r,$dom,$confname,$lastactref,%domconfig);
+    } elsif ($action eq 'ltitools') {
+        $output = &modify_ltitools($r,$dom,$action,$lastactref,%domconfig);
     } elsif ($action eq 'wafproxy') {
         $output = &modify_wafproxy($dom,$action,$lastactref,%domconfig);
     } elsif ($action eq 'ipaccess') {
@@ -720,7 +774,7 @@ sub print_config_box {
     } elsif ($action eq 'defaults') {
         $output = &defaults_javascript($settings); 
     } elsif ($action eq 'passwords') {
-        $output = &passwords_javascript();
+        $output = &passwords_javascript($action);
     } elsif ($action eq 'helpsettings') {
         my (%privs,%levelscurrent);
         my %full=();
@@ -737,10 +791,17 @@ sub print_config_box {
         $output =
             &Apache::lonuserutils::custom_roledefs_js($context,$crstype,$formname,\%full,
                                                       \@templateroles);
+    } elsif ($action eq 'ltitools') {
+        $output .= &ltitools_javascript($settings);
+    } elsif ($action eq 'lti') {
+        $output .= &passwords_javascript('secrets')."\n".
+                   &lti_javascript($dom,$settings);
     } elsif ($action eq 'wafproxy') {
         $output .= &wafproxy_javascript($dom);
     } elsif ($action eq 'autoupdate') {
         $output .= &autoupdate_javascript();
+    } elsif ($action eq 'autoenroll') {
+        $output .= &autoenroll_javascript();
     } elsif ($action eq 'login') {
         $output .= &saml_javascript();
     } elsif ($action eq 'ipaccess') {
@@ -785,7 +846,7 @@ sub print_config_box {
         if (($action eq 'autoupdate') || ($action eq 'usercreation') || ($action eq 'selfcreation') ||
             ($action eq 'usermodification') || ($action eq 'defaults') || ($action eq 'coursedefaults') ||
             ($action eq 'selfenrollment') || ($action eq 'usersessions') || ($action eq 'directorysrch') ||
-            ($action eq 'helpsettings') || ($action eq 'contacts') || ($action eq 'wafproxy')) {
+            ($action eq 'helpsettings') || ($action eq 'contacts') || ($action eq 'wafproxy') || ($action eq 'lti')) {
             $output .= $item->{'print'}->('top',$dom,$settings,\$rowtotal);
         } elsif ($action eq 'passwords') {
             $output .= $item->{'print'}->('top',$dom,$confname,$settings,\$rowtotal);
@@ -820,7 +881,7 @@ sub print_config_box {
         if (($action eq 'autoupdate') || ($action eq 'usercreation') ||
             ($action eq 'selfcreation') || ($action eq 'selfenrollment') ||
             ($action eq 'usersessions') || ($action eq 'coursecategories') ||
-            ($action eq 'contacts') || ($action eq 'passwords')) {
+            ($action eq 'contacts') || ($action eq 'passwords') || ($action eq 'lti')) {
             if ($action eq 'coursecategories') {
                 $output .= &print_coursecategories('middle',$dom,$item,$settings,\$rowtotal);
                 $colspan = ' colspan="2"';
@@ -1056,7 +1117,7 @@ sub print_config_box {
             $output .= &print_quotas($dom,$settings,\$rowtotal,$action);
         } elsif (($action eq 'autoenroll') || ($action eq 'autocreate') || 
                  ($action eq 'serverstatuses') || ($action eq 'loadbalancing') ||
-                 ($action eq 'ipaccess')) {
+                 ($action eq 'ltitools') || ($action eq 'ipaccess')) {
             $output .= $item->{'print'}->($dom,$settings,\$rowtotal);
         }
     }
@@ -1163,6 +1224,7 @@ sub print_login {
             }
         }
         my @images = ('img','logo','domlogo','login');
+        my @alttext = ('img','logo','domlogo');
         my @logintext = ('textcol','bgcol');
         my @bgs = ('pgbg','mainbg','sidebg');
         my @links = ('link','alink','vlink');
@@ -1204,6 +1266,13 @@ sub print_login {
                     $designs{'showlogo'}{$item} = $settings->{'showlogo'}{$item};
                 }
             }
+            foreach my $item (@alttext) {
+                if (ref($settings->{'alttext'}) eq 'HASH') {
+                    if ($settings->{'alttext'}->{$item} ne '') {
+                        $designs{'alttext'}{$item} = $settings->{'alttext'}{$item};
+                    }
+                }
+            }
             foreach my $item (@logintext) {
                 if ($settings->{$item} ne '') {
                     $designs{'logintext'}{$item} = $settings->{$item};
@@ -1513,6 +1582,7 @@ sub login_choices {
             current       => "Current",
             samllanding   => "Dual login?",
             samloptions   => "Options",
+            alttext       => "Alt text",
         );
     return %choices;
 }
@@ -1858,7 +1928,7 @@ sub display_color_options {
         $css_class = $itemcount%2?' class="LC_odd_row"':'';
         $datatable .= '<tr'.$css_class.'>'.
                       '<td>'.$choices->{$img};
-        my ($imgfile,$img_import,$login_hdr_pick,$logincolors);
+        my ($imgfile,$img_import,$login_hdr_pick,$logincolors,$alttext);
         if ($role eq 'login') {
             if ($img eq 'login') {
                 $login_hdr_pick =
@@ -1866,8 +1936,13 @@ sub display_color_options {
                 $logincolors =
                     &login_text_colors($img,$role,$logintext,$phase,$choices,
                                        $designs,$defaults);
-            } elsif ($img ne 'domlogo') {
-                $datatable.= &logo_display_options($img,$defaults,$designs);
+            } else {
+                if ($img ne 'domlogo') {
+                    $datatable.= &logo_display_options($img,$defaults,$designs);
+                }
+                if (ref($designs->{'alttext'}) eq 'HASH') {
+                    $alttext = $designs->{'alttext'}{$img};
+                }
             }
         }
         $datatable .= '</td>';
@@ -1959,6 +2034,11 @@ sub display_color_options {
                 $datatable .='&nbsp;<input type="file" name="'.$role.'_'.$img.'" />';
             }
         }
+        if (($role eq 'login') && ($img ne 'login')) {
+            $datatable .= ('&nbsp;' x2).' <span class="LC_nobreak"><label>'.$choices->{'alttext'}.':'.
+                          '<input type="text" name="'.$role.'_alt_'.$img.'" size="10" value="'.$alttext.'" />'.
+                          '</label></span>';
+        }
         $datatable .= '</td></tr>';
     }
     $itemcount ++;
@@ -2835,6 +2915,108 @@ $jstext{'templates'};
 ENDSCRIPT
 }
 
+sub ltitools_javascript {
+    my ($settings) = @_;
+    my $togglejs = &ltitools_toggle_js();
+    unless (ref($settings) eq 'HASH') {
+        return $togglejs;
+    }
+    my (%ordered,$total,%jstext);
+    $total = 0;
+    foreach my $item (keys(%{$settings})) {
+        if (ref($settings->{$item}) eq 'HASH') {
+            my $num = $settings->{$item}{'order'};
+            $ordered{$num} = $item;
+        }
+    }
+    $total = scalar(keys(%{$settings}));
+    my @jsarray = ();
+    foreach my $item (sort {$a <=> $b } (keys(%ordered))) {
+        push(@jsarray,$ordered{$item});
+    }
+    my $jstext = '    var ltitools = Array('."'".join("','",@jsarray)."'".');'."\n";
+    return <<"ENDSCRIPT";
+<script type="text/javascript">
+// <![CDATA[
+function reorderLTITools(form,item) {
+    var changedVal;
+$jstext
+    var newpos = 'ltitools_add_pos';
+    var maxh = 1 + $total;
+    var current = new Array;
+    var newitemVal = form.elements[newpos].options[form.elements[newpos].selectedIndex].value;
+    if (item == newpos) {
+        changedVal = newitemVal;
+    } else {
+        changedVal = form.elements[item].options[form.elements[item].selectedIndex].value;
+        current[newitemVal] = newpos;
+    }
+    for (var i=0; i<ltitools.length; i++) {
+        var elementName = 'ltitools_'+ltitools[i];
+        if (elementName != item) {
+            if (form.elements[elementName]) {
+                var currVal = form.elements[elementName].options[form.elements[elementName].selectedIndex].value;
+                current[currVal] = elementName;
+            }
+        }
+    }
+    var oldVal;
+    for (var j=0; j<maxh; j++) {
+        if (current[j] == undefined) {
+            oldVal = j;
+        }
+    }
+    if (oldVal < changedVal) {
+        for (var k=oldVal+1; k<=changedVal ; k++) {
+           var elementName = current[k];
+           form.elements[elementName].selectedIndex = form.elements[elementName].selectedIndex - 1;
+        }
+    } else {
+        for (var k=changedVal; k<oldVal; k++) {
+            var elementName = current[k];
+            form.elements[elementName].selectedIndex = form.elements[elementName].selectedIndex + 1;
+        }
+    }
+    return;
+}
+
+// ]]>
+</script>
+
+$togglejs
+
+ENDSCRIPT
+}
+
+sub ltitools_toggle_js {
+    return <<"ENDSCRIPT";
+<script type="text/javascript">
+// <![CDATA[
+
+function toggleLTITools(form,setting,item) {
+    var radioname = '';
+    var divid = '';
+    if (setting == 'user') {
+        divid = 'ltitools_'+setting+'_div_'+item;
+        var checkid = 'ltitools_'+setting+'_field_'+item;
+        if (document.getElementById(divid)) {
+            if (document.getElementById(checkid)) {
+                if (document.getElementById(checkid).checked) {
+                    document.getElementById(divid).style.display = 'inline-block';
+                } else {
+                    document.getElementById(divid).style.display = 'none';
+                }
+            }
+        }
+    }
+    return;
+}
+// ]]>
+</script>
+
+ENDSCRIPT
+}
+
 sub wafproxy_javascript {
     my ($dom) = @_;
     return <<"ENDSCRIPT";
@@ -2950,6 +3132,140 @@ function toggleWAF() {
 ENDSCRIPT
 }
 
+sub lti_javascript {
+    my ($dom,$settings) = @_;
+    my $togglejs = &lti_toggle_js($dom);
+    my $linkprot_js = &Apache::courseprefs::linkprot_javascript();
+    return <<"ENDSCRIPT";
+<script type="text/javascript">
+// <![CDATA[
+
+$linkprot_js
+
+// ]]>
+</script>
+
+$togglejs
+
+ENDSCRIPT
+}
+
+sub lti_toggle_js {
+    my ($dom) = @_;
+    my %servers = &Apache::lonnet::get_servers($dom,'library');
+    my $primary = &Apache::lonnet::domain($dom,'primary');
+    my $course_servers = "'".join("','",keys(%servers))."'";
+    return <<"ENDSCRIPT";
+<script type="text/javascript">
+// <![CDATA[
+function toggleLTIEncKey(form) {
+    var shownhosts = new Array();
+    var hiddenhosts = new Array();
+    var forcourse = new Array($course_servers);
+    var fromdomain = '$primary';
+    var crsradio = form.elements['ltisec_crslinkprot'];
+    if (crsradio.length) {
+        for (var i=0; i<crsradio.length; i++) {
+            if (crsradio[i].checked) {
+                if (crsradio[i].value == 1) {
+                    if (forcourse.length > 0) {
+                        for (var j=0; j<forcourse.length; j++) {
+                            if (!shownhosts.includes(forcourse[j])) {
+                                shownhosts.push(forcourse[j]);
+                            }
+                        }
+                    }
+                } else {
+                    if (forcourse.length > 0) {
+                        for (var j=0; j<forcourse.length; j++) {
+                            if (!hiddenhosts.includes(forcourse[j])) {
+                                hiddenhosts.push(forcourse[j]);
+                            }
+                        }
+                    }
+                }
+            }
+        }
+    }
+    var domradio = form.elements['ltisec_domlinkprot'];
+    if (domradio.length) {
+        for (var i=0; i<domradio.length; i++) {
+            if (domradio[i].checked) {
+                if (domradio[i].value == 1) {
+                    if (!shownhosts.includes(fromdomain)) {
+                        shownhosts.push(fromdomain);
+                    }
+                } else {
+                    if (!hiddenhosts.includes(fromdomain)) {
+                        hiddenhosts.push(fromdomain);
+                    }
+                }
+            }
+        }
+    }
+    if (shownhosts.length > 0) {
+        for (var i=0; i<shownhosts.length; i++) {
+            if (document.getElementById('ltisec_info_'+shownhosts[i])) {
+                document.getElementById('ltisec_info_'+shownhosts[i]).style.display = 'block';
+            }
+        }
+        if (document.getElementById('ltisec_noprivkey')) {
+            document.getElementById('ltisec_noprivkey').style.display = 'none';
+        }
+    } else {
+        if (document.getElementById('ltisec_noprivkey')) {
+            document.getElementById('ltisec_noprivkey').style.display = 'inline-block';
+        }
+    }
+    if (hiddenhosts.length > 0) {
+        for (var i=0; i<hiddenhosts.length; i++) {
+            if (!shownhosts.includes(hiddenhosts[i])) {
+                if (document.getElementById('ltisec_info_'+hiddenhosts[i])) {
+                    document.getElementById('ltisec_info_'+hiddenhosts[i]).style.display = 'none';
+                }
+            }
+        }
+    }
+    return;
+}
+
+function togglePrivKey(form,hostid) {
+    var radioname = '';
+    var currdivid = '';
+    var newdivid = '';
+    if ((document.getElementById('ltisec_divcurrprivkey_'+hostid)) &&
+        (document.getElementById('ltisec_divchgprivkey_'+hostid))) {
+        currdivid = document.getElementById('ltisec_divcurrprivkey_'+hostid);
+        newdivid = document.getElementById('ltisec_divchgprivkey_'+hostid);
+        radioname = form.elements['ltisec_changeprivkey_'+hostid];
+        if (radioname) {
+            if (radioname.length > 0) {
+                var setvis;
+                for (var i=0; i<radioname.length; i++) {
+                    if (radioname[i].checked == true) {
+                        if (radioname[i].value == 1) {
+                            newdivid.style.display = 'inline-block';
+                            currdivid.style.display = 'none';
+                            setvis = 1;
+                        }
+                        break;
+                    }
+                }
+                if (!setvis) {
+                    newdivid.style.display = 'none';
+                    currdivid.style.display = 'inline-block';
+                }
+            }
+        }
+    }
+}
+
+// ]]>
+</script>
+
+ENDSCRIPT
+}
+
 sub autoupdate_javascript {
     return <<"ENDSCRIPT";
 <script type="text/javascript">
@@ -2985,6 +3301,41 @@ function toggleLastActiveDays(form) {
 ENDSCRIPT
 }
 
+sub autoenroll_javascript {
+    return <<"ENDSCRIPT";
+<script type="text/javascript">
+// <![CDATA[
+function toggleFailsafe(form) {
+    var radioname = 'autoenroll_failsafe';
+    var divid = 'autoenroll_failsafe_div';
+    var num = form.elements[radioname].length;
+    if (num) {
+        var setvis = '';
+        for (var i=0; i<num; i++) {
+            if (form.elements[radioname][i].checked) {
+                if ((form.elements[radioname][i].value == 'zero') || (form.elements[radioname][i].value == 'any')) {
+                    if (document.getElementById(divid)) {
+                        document.getElementById(divid).style.display = 'inline-block';
+                    }
+                    setvis = 1;
+                }
+                break;
+            }
+        }
+        if (!setvis) {
+            if (document.getElementById(divid)) {
+                document.getElementById(divid).style.display = 'none';
+            }
+        }
+    }
+    return;
+}
+// ]]>
+</script>
+
+ENDSCRIPT
+}
+
 sub saml_javascript {
     return <<"ENDSCRIPT";
 <script type="text/javascript">
@@ -3098,7 +3449,12 @@ ENDSCRIPT
 sub print_autoenroll {
     my ($dom,$settings,$rowtotal) = @_;
     my $autorun = &Apache::lonnet::auto_run(undef,$dom),
-    my ($defdom,$runon,$runoff,$coownerson,$coownersoff,$failsafe);
+    my ($defdom,$runon,$runoff,$coownerson,$coownersoff,
+        $failsafe,$autofailsafe,$failsafesty,%failsafechecked);
+    $failsafesty = 'none';
+    %failsafechecked = (
+        off => ' checked="checked"',
+    );
     if (ref($settings) eq 'HASH') {
         if (exists($settings->{'run'})) {
             if ($settings->{'run'} eq '0') {
@@ -3132,8 +3488,24 @@ sub print_autoenroll {
         if (exists($settings->{'sender_domain'})) {
             $defdom = $settings->{'sender_domain'};
         }
-        if (exists($settings->{'autofailsafe'})) {
-            $failsafe = $settings->{'autofailsafe'};
+        if (exists($settings->{'failsafe'})) {
+            $failsafe = $settings->{'failsafe'};
+            if ($failsafe eq 'zero') {
+                $failsafechecked{'zero'} = ' checked="checked"';
+                $failsafechecked{'off'} = '';
+                $failsafesty = 'inline-block';
+            } elsif ($failsafe eq 'any') {
+                $failsafechecked{'any'} = ' checked="checked"';
+                $failsafechecked{'off'} = '';
+            }
+            $autofailsafe = $settings->{'autofailsafe'};
+        } elsif (exists($settings->{'autofailsafe'})) {
+            $autofailsafe = $settings->{'autofailsafe'};
+            if ($autofailsafe ne '') {
+                $failsafechecked{'zero'} = ' checked="checked"';
+                $failsafe = 'zero';
+                $failsafechecked{'off'} = '';
+            }
         }
     } else {
         if ($autorun) {
@@ -3172,9 +3544,15 @@ sub print_autoenroll {
                   $coownersoff.' value="0" />'.&mt('No').'</label></span></td>'.
                   '</tr><tr>'.
                   '<td>'.&mt('Failsafe for no drops when institutional data missing').'</td>'.
-                  '<td class="LC_right_item"><span class="LC_nobreak">'.
-                  '<input type="text" name="autoenroll_failsafe"'.
-                  ' value="'.$failsafe.'" size="4" /></span></td></tr>';
+                  '<td class="LC_left_item"><span class="LC_nobreak">'.
+                  '<span class="LC_nobreak"><label><input type="radio" name="autoenroll_failsafe" value="off" onclick="toggleFailsafe(this.form)"'.$failsafechecked{'off'}.' />'.&mt('Not in use').'</label></span>&nbsp;&nbsp;&nbsp; '.
+                  '<span class="LC_nobreak"><label><input type="radio" name="autoenroll_failsafe" value="zero" onclick="toggleFailsafe(this.form)"'.$failsafechecked{'zero'}.' />'.&mt('Retrieved section enrollment is zero').'</label></span><br />'.
+                  '<span class="LC_nobreak"><label><input type="radio" name="autoenroll_failsafe" value="any" onclick="toggleFailsafe(this.form)"'.$failsafechecked{'any'}.' />'.&mt('Retrieved section enrollment is zero or greater').'</label></span>'.
+                  '<div class="LC_floatleft" style="display:'.$failsafesty.';" id="autoenroll_failsafe_div">'.
+                  '<span class="LC_nobreak">'.
+                  &mt('Threshold for number of students in section to drop: [_1]',
+                      '<input type="text" name="autoenroll_autofailsafe" value="'.$autofailsafe.'" size="4" />').
+                  '</span></div></td></tr>';
     $$rowtotal += 4;
     return $datatable;
 }
@@ -4432,6 +4810,552 @@ sub radiobutton_prefs {
     return ($datatable,$itemcount);
 }
 
+sub print_ltitools {
+    my ($dom,$settings,$rowtotal) = @_;
+    my $rownum = 0;
+    my $css_class;
+    my $itemcount = 1;
+    my $maxnum = 0;
+    my %ordered;
+    if (ref($settings) eq 'HASH') {
+        foreach my $item (keys(%{$settings})) {
+            if (ref($settings->{$item}) eq 'HASH') {
+                my $num = $settings->{$item}{'order'};
+                $ordered{$num} = $item;
+            }
+        }
+    }
+    my $confname = $dom.'-domainconfig';
+    my $switchserver = &check_switchserver($dom,$confname);
+    my $maxnum = scalar(keys(%ordered));
+    my $datatable;
+    my %lt = &ltitools_names();
+    my @courseroles = ('cc','in','ta','ep','st');
+    my @ltiroles = qw(Instructor ContentDeveloper TeachingAssistant Learner);
+    my @fields = ('fullname','firstname','lastname','email','roles','user');
+    if (keys(%ordered)) {
+        my @items = sort { $a <=> $b } keys(%ordered);
+        for (my $i=0; $i<@items; $i++) {
+            $css_class = $itemcount%2?' class="LC_odd_row"':'';
+            my $item = $ordered{$items[$i]};
+            my ($title,$key,$secret,$url,$lifetime,$imgsrc,%sigsel);
+            if (ref($settings->{$item}) eq 'HASH') {
+                $title = $settings->{$item}->{'title'};
+                $url = $settings->{$item}->{'url'};
+                $key = $settings->{$item}->{'key'};
+                $secret = $settings->{$item}->{'secret'};
+                $lifetime = $settings->{$item}->{'lifetime'};
+                my $image = $settings->{$item}->{'image'};
+                if ($image ne '') {
+                    $imgsrc = '<img src="'.$image.'" alt="'.&mt('Tool Provider icon').'" />';
+                }
+                if ($settings->{$item}->{'sigmethod'} eq 'HMAC-256') {
+                    $sigsel{'HMAC-256'} = ' selected="selected"';
+                } else {
+                    $sigsel{'HMAC-SHA1'} = ' selected="selected"';
+                }
+            }
+            my $chgstr = ' onchange="javascript:reorderLTITools(this.form,'."'ltitools_".$item."'".');"';
+            $datatable .= '<tr '.$css_class.'><td><span class="LC_nobreak">'
+                         .'<select name="ltitools_'.$item.'"'.$chgstr.'>';
+            for (my $k=0; $k<=$maxnum; $k++) {
+                my $vpos = $k+1;
+                my $selstr;
+                if ($k == $i) {
+                    $selstr = ' selected="selected" ';
+                }
+                $datatable .= '<option value="'.$k.'"'.$selstr.'>'.$vpos.'</option>';
+            }
+            $datatable .= '</select>'.('&nbsp;'x2).
+                '<label><input type="checkbox" name="ltitools_del" value="'.$item.'" />'.
+                &mt('Delete?').'</label></span></td>'.
+                '<td colspan="2">'.
+                '<fieldset><legend>'.&mt('Required settings').'</legend>'.
+                '<span class="LC_nobreak">'.$lt{'title'}.':<input type="text" size="20" name="ltitools_title_'.$i.'" value="'.$title.'" /></span> '.
+                ('&nbsp;'x2).
+                '<span class="LC_nobreak">'.$lt{'version'}.':<select name="ltitools_version_'.$i.'">'.
+                '<option value="LTI-1p0" selected="selected">1.1</option></select></span> '.
+                ('&nbsp;'x2).
+                '<span class="LC_nobreak">'.$lt{'msgtype'}.':<select name="ltitools_msgtype_'.$i.'">'.
+                '<option value="basic-lti-launch-request" selected="selected">Launch</option></select></span> '.
+                ('&nbsp;'x2).
+                '<span class="LC_nobreak">'.$lt{'sigmethod'}.':<select name="ltitools_sigmethod_'.$i.'">'.
+                '<option value="HMAC-SHA1"'.$sigsel{'HMAC-SHA1'}.'>HMAC-SHA1</option>'.
+                '<option value="HMAC-SHA256"'.$sigsel{'HMAC-SHA256'}.'>HMAC-SHA256</option></select></span>'.
+                '<br /><br />'.
+                '<span class="LC_nobreak">'.$lt{'url'}.':<input type="text" size="40" name="ltitools_url_'.$i.'"'.
+                ' value="'.$url.'" /></span>'.
+                ('&nbsp;'x2).
+                '<span class="LC_nobreak">'.$lt{'key'}.':'.
+                '<input type="text" size="25" name="ltitools_key_'.$i.'" value="'.$key.'" /></span> '.
+                ('&nbsp;'x2).
+                '<span class="LC_nobreak">'.$lt{'lifetime'}.':'.
+                '<input type="text" size="5" name="ltitools_lifetime_'.$i.'" value="'.$lifetime.'" /></span> '.
+                ('&nbsp;'x2).
+                '<span class="LC_nobreak">'.$lt{'secret'}.':'.
+                '<input type="password" size="20" name="ltitools_secret_'.$i.'" value="'.$secret.'" />'.
+                '<label><input type="checkbox" name="visible" onclick="if (this.checked) { this.form.ltitools_secret_'.$i.'.type='."'text'".' } else { this.form.ltitools_secret_'.$i.'.type='."'password'".' }" />'.&mt('Visible input').'</label>'.
+                '<input type="hidden" name="ltitools_id_'.$i.'" value="'.$item.'" /></span>'.
+                '</fieldset>'.
+                '<fieldset><legend>'.&mt('Optional settings').'</legend>'.
+                '<span class="LC_nobreak">'.&mt('Display target:');
+            my %currdisp;
+            if (ref($settings->{$item}->{'display'}) eq 'HASH') {
+                if ($settings->{$item}->{'display'}->{'target'} eq 'window') {
+                    $currdisp{'window'} = ' checked="checked"';
+                } elsif ($settings->{$item}->{'display'}->{'target'} eq 'tab') {
+                    $currdisp{'tab'} = ' checked="checked"';
+                } else {
+                    $currdisp{'iframe'} = ' checked="checked"';
+                }
+                if ($settings->{$item}->{'display'}->{'width'} =~ /^(\d+)$/) {
+                    $currdisp{'width'} = $1;
+                }
+                if ($settings->{$item}->{'display'}->{'height'} =~ /^(\d+)$/) {
+                     $currdisp{'height'} = $1;
+                }
+                $currdisp{'linktext'} = $settings->{$item}->{'display'}->{'linktext'};
+                $currdisp{'explanation'} = $settings->{$item}->{'display'}->{'explanation'};
+            } else {
+                $currdisp{'iframe'} = ' checked="checked"';
+            }
+            foreach my $disp ('iframe','tab','window') {
+                $datatable .= '<label><input type="radio" name="ltitools_target_'.$i.'" value="'.$disp.'"'.$currdisp{$disp}.' />'.
+                              $lt{$disp}.'</label>'.('&nbsp;'x2);
+            }
+            $datatable .= ('&nbsp;'x4);
+            foreach my $dimen ('width','height') {
+                $datatable .= '<label>'.$lt{$dimen}.'&nbsp;'.
+                              '<input type="text" name="ltitools_'.$dimen.'_'.$i.'" size="5" value="'.$currdisp{$dimen}.'" /></label>'.
+                              ('&nbsp;'x2);
+            }
+            $datatable .= '</span><br />'.
+                          '<div class="LC_left_float">'.$lt{'linktext'}.'<br />'.
+                          '<input type="text" name="ltitools_linktext_'.$i.'" size="25" value="'.$currdisp{'linktext'}.'" /></div>'.
+                          '<div class="LC_left_float">'.$lt{'explanation'}.'<br />'.
+                          '<textarea name="ltitools_explanation_'.$i.'" rows="5" cols="40">'.$currdisp{'explanation'}.
+                          '</textarea></div><div style=""></div>'.
+                          '<div style="padding:0;clear:both;margin:0;border:0"></div>';
+            $datatable .= '<span class="LC_nobreak">'.$lt{'icon'}.':&nbsp;';
+            if ($imgsrc) {
+                $datatable .= $imgsrc.
+                              '<label><input type="checkbox" name="ltitools_image_del"'.
+                              ' value="'.$item.'" />'.&mt('Delete?').'</label></span> '.
+                              '<span class="LC_nobreak">&nbsp;'.&mt('Replace:').'&nbsp;';
+            } else {
+                $datatable .= '('.&mt('if larger than 21x21 pixels, image will be scaled').')&nbsp;';
+            }
+            if ($switchserver) {
+                $datatable .= &mt('Upload to library server: [_1]',$switchserver);
+            } else {
+                $datatable .= '<input type="file" name="ltitools_image_'.$i.'" value="" />';
+            }
+            $datatable .= '</span></fieldset>';
+            my (%checkedfields,%rolemaps,$userincdom);
+            if (ref($settings->{$item}) eq 'HASH') {
+                if (ref($settings->{$item}->{'fields'}) eq 'HASH') {
+                    %checkedfields = %{$settings->{$item}->{'fields'}};
+                }
+                $userincdom = $settings->{$item}->{'incdom'};
+                if (ref($settings->{$item}->{'roles'}) eq 'HASH') {
+                    %rolemaps = %{$settings->{$item}->{'roles'}};
+                    $checkedfields{'roles'} = 1;
+                }
+            }
+            $datatable .= '<fieldset><legend>'.&mt('User data sent on launch').'</legend>'.
+                          '<span class="LC_nobreak">';
+            my $userfieldstyle = 'display:none;';
+            my $seluserdom = '';
+            my $unseluserdom = ' selected="selected"';
+            foreach my $field (@fields) {
+                my ($checked,$onclick,$id,$spacer);
+                if ($checkedfields{$field}) {
+                    $checked = ' checked="checked"';
+                }
+                if ($field eq 'user') {
+                    $id = ' id="ltitools_user_field_'.$i.'"';
+                    $onclick = ' onclick="toggleLTITools(this.form,'."'$field','$i'".')"';
+                    if ($checked) {
+                        $userfieldstyle = 'display:inline-block';
+                        if ($userincdom) {
+                            $seluserdom = $unseluserdom;
+                            $unseluserdom = '';
+                        }
+                    }
+                } else {
+                    $spacer = ('&nbsp;' x2);
+                }
+                $datatable .= '<label>'.
+                              '<input type="checkbox" name="ltitools_fields_'.$i.'" value="'.$field.'"'.$id.$checked.$onclick.' />'.
+                              $lt{$field}.'</label>'.$spacer;
+            }
+            $datatable .= '</span>';
+            $datatable .= '<div style="'.$userfieldstyle.'" id="ltitools_user_div_'.$i.'">'.
+                          '<span class="LC_nobreak"> : '.
+                          '<select name="ltitools_userincdom_'.$i.'">'.
+                          '<option value="">'.&mt('Select').'</option>'.
+                          '<option value="0"'.$unseluserdom.'>'.&mt('username').'</option>'.
+                          '<option value="1"'.$seluserdom.'>'.&mt('username:domain').'</option>'.
+                          '</select></span></div>';
+            $datatable .= '</fieldset>'.
+                          '<fieldset><legend>'.&mt('Role mapping').'</legend><table><tr>';
+            foreach my $role (@courseroles) {
+                my ($selected,$selectnone);
+                if (!$rolemaps{$role}) {
+                    $selectnone = ' selected="selected"';
+                }
+                $datatable .= '<td align="center">'.
+                              &Apache::lonnet::plaintext($role,'Course').'<br />'.
+                              '<select name="ltitools_roles_'.$role.'_'.$i.'">'.
+                              '<option value=""'.$selectnone.'>'.&mt('Select').'</option>';
+                foreach my $ltirole (@ltiroles) {
+                    unless ($selectnone) {
+                        if ($rolemaps{$role} eq $ltirole) {
+                            $selected = ' selected="selected"';
+                        } else {
+                            $selected = '';
+                        }
+                    }
+                    $datatable .= '<option value="'.$ltirole.'"'.$selected.'>'.$ltirole.'</option>';
+                }
+                $datatable .= '</select></td>';
+            }
+            $datatable .= '</tr></table></fieldset>';
+            my %courseconfig;
+            if (ref($settings->{$item}) eq 'HASH') {
+                if (ref($settings->{$item}->{'crsconf'}) eq 'HASH') {
+                    %courseconfig = %{$settings->{$item}->{'crsconf'}};
+                }
+            }
+            $datatable .= '<fieldset><legend>'.&mt('Configurable in course').'</legend><span class="LC_nobreak">';
+            foreach my $item ('label','title','target','linktext','explanation','append') {
+                my $checked;
+                if ($courseconfig{$item}) {
+                    $checked = ' checked="checked"';
+                }
+                $datatable .= '<label>'.
+                       '<input type="checkbox" name="ltitools_courseconfig_'.$i.'" value="'.$item.'"'.$checked.' />'.
+                       $lt{'crs'.$item}.'</label>'.('&nbsp;' x2)."\n";
+            }
+            $datatable .= '</span></fieldset>'.
+                          '<fieldset><legend>'.&mt('Custom items sent on launch').'</legend>'.
+                          '<table><tr><th>'.&mt('Action').'</th><th>'.&mt('Name').'</th><th>'.&mt('Value').'</th></tr>';
+            if (ref($settings->{$item}->{'custom'}) eq 'HASH') {
+                my %custom = %{$settings->{$item}->{'custom'}};
+                if (keys(%custom) > 0) {
+                    foreach my $key (sort(keys(%custom))) {
+                        $datatable .= '<tr><td><span class="LC_nobreak">'.
+                                      '<label><input type="checkbox" name="ltitools_customdel_'.$i.'" value="'.
+                                      $key.'" />'.&mt('Delete').'</label></span></td><td>'.$key.'</td>'.
+                                      '<td><input type="text" name="ltitools_customval_'.$key.'_'.$i.'"'.
+                                      ' value="'.$custom{$key}.'" /></td></tr>';
+                    }
+                }
+            }
+            $datatable .= '<tr><td><span class="LC_nobreak">'.
+                          '<label><input type="checkbox" name="ltitools_customadd" value="'.$i.'" />'.
+                          &mt('Add').'</label></span></td><td><input type="text" name="ltitools_custom_name_'.$i.'" />'.
+                          '</td><td><input type="text" name="ltitools_custom_value_'.$i.'" /></td></tr>';
+            $datatable .= '</table></fieldset></td></tr>'."\n";
+            $itemcount ++;
+        }
+    }
+    $css_class = $itemcount%2?' class="LC_odd_row"':'';
+    my $chgstr = ' onchange="javascript:reorderLTITools(this.form,'."'ltitools_add_pos'".');"';
+    $datatable .= '<tr '.$css_class.'><td><span class="LC_nobreak">'."\n".
+                  '<input type="hidden" name="ltitools_maxnum" value="'.$maxnum.'" />'."\n".
+                  '<select name="ltitools_add_pos"'.$chgstr.'>';
+    for (my $k=0; $k<$maxnum+1; $k++) {
+        my $vpos = $k+1;
+        my $selstr;
+        if ($k == $maxnum) {
+            $selstr = ' selected="selected" ';
+        }
+        $datatable .= '<option value="'.$k.'"'.$selstr.'>'.$vpos.'</option>';
+    }
+    $datatable .= '</select>&nbsp;'."\n".
+                  '<input type="checkbox" name="ltitools_add" value="1" />'.&mt('Add').'</span></td>'."\n".
+                  '<td colspan="2">'.
+                  '<fieldset><legend>'.&mt('Required settings').'</legend>'.
+                  '<span class="LC_nobreak">'.$lt{'title'}.':<input type="text" size="20" name="ltitools_add_title" value="" /></span> '."\n".
+                  ('&nbsp;'x2).
+                  '<span class="LC_nobreak">'.$lt{'version'}.':<select name="ltitools_add_version">'.
+                  '<option value="LTI-1p0" selected="selected">1.1</option></select></span> '."\n".
+                  ('&nbsp;'x2).
+                  '<span class="LC_nobreak">'.$lt{'msgtype'}.':<select name="ltitools_add_msgtype">'.
+                  '<option value="basic-lti-launch-request" selected="selected">Launch</option></select></span> '.
+                  '<span class="LC_nobreak">'.$lt{'sigmethod'}.':<select name="ltitools_add_sigmethod">'.
+                  '<option value="HMAC-SHA1" selected="selected">HMAC-SHA1</option>'.
+                  '<option value="HMAC-SHA256">HMAC-SHA256</option></select></span>'.
+                  '<br />'.
+                  '<span class="LC_nobreak">'.$lt{'url'}.':<input type="text" size="40" name="ltitools_add_url" value="" /></span> '."\n".
+                  ('&nbsp;'x2).
+                  '<span class="LC_nobreak">'.$lt{'key'}.':<input type="text" size="25" name="ltitools_add_key" value="" /></span> '."\n".
+                  ('&nbsp;'x2).
+                  '<span class="LC_nobreak">'.$lt{'lifetime'}.':<input type="text" size="5" name="ltitools_add_lifetime" value="300" /></span> '."\n".
+                  ('&nbsp;'x2).
+                  '<span class="LC_nobreak">'.$lt{'secret'}.':<input type="password" size="20" name="ltitools_add_secret" value="" />'.
+                  '<label><input type="checkbox" name="visible" onclick="if (this.checked) { this.form.ltitools_add_secret.type='."'text'".' } else { this.form.ltitools_add_secret.type='."'password'".' }" />'.&mt('Visible input').'</label></span> '."\n".
+                  '</fieldset>'.
+                  '<fieldset><legend>'.&mt('Optional settings').'</legend>'.
+                  '<span class="LC_nobreak">'.&mt('Display target:');
+    my %defaultdisp;
+    $defaultdisp{'iframe'} = ' checked="checked"';
+    foreach my $disp ('iframe','tab','window') {
+        $datatable .= '<label><input type="radio" name="ltitools_add_target" value="'.$disp.'"'.$defaultdisp{$disp}.' />'.
+                      $lt{$disp}.'</label>'.('&nbsp;'x2);
+    }
+    $datatable .= ('&nbsp;'x4);
+    foreach my $dimen ('width','height') {
+        $datatable .= '<label>'.$lt{$dimen}.'&nbsp;'.
+                      '<input type="text" name="ltitools_add_'.$dimen.'" size="5" /></label>'.
+                      ('&nbsp;'x2);
+    }
+    $datatable .= '</span><br />'.
+                  '<div class="LC_left_float">'.$lt{'linktext'}.'<br />'.
+                  '<input type="text" name="ltitools_add_linktext" size="5" /></div>'.
+                  '<div class="LC_left_float">'.$lt{'explanation'}.'<br />'.
+                  '<textarea name="ltitools_add_explanation" rows="5" cols="40"></textarea>'.
+                  '</div><div style=""></div>'.
+                  '<div style="padding:0;clear:both;margin:0;border:0"></div>';
+    $datatable .= '<span class="LC_nobreak">'.$lt{'icon'}.':&nbsp;'.
+                  '('.&mt('if larger than 21x21 pixels, image will be scaled').')&nbsp;';
+    if ($switchserver) {
+        $datatable .= &mt('Upload to library server: [_1]',$switchserver);
+    } else {
+        $datatable .= '<input type="file" name="ltitools_add_image" value="" />';
+    }
+    $datatable .= '</span></fieldset>'.
+                  '<fieldset><legend>'.&mt('User data sent on launch').'</legend>'.
+                  '<span class="LC_nobreak">';
+    foreach my $field (@fields) {
+        my ($id,$onclick,$spacer);
+        if ($field eq 'user') {
+            $id = ' id="ltitools_user_field_add"';
+            $onclick = ' onclick="toggleLTITools(this.form,'."'$field','add'".')"';
+        } else {
+            $spacer = ('&nbsp;' x2);
+        }
+        $datatable .= '<label>'.
+                      '<input type="checkbox" name="ltitools_add_fields" value="'.$field.'"'.$id.$onclick.' />'.
+                      $lt{$field}.'</label>'.$spacer;
+    }
+    $datatable .= '</span>'.
+                  '<div style="display:none;" id="ltitools_user_div_add">'.
+                  '<span class="LC_nobreak"> : '.
+                  '<select name="ltitools_userincdom_add">'.
+                  '<option value="" selected="selected">'.&mt('Select').'</option>'.
+                  '<option value="0">'.&mt('username').'</option>'.
+                  '<option value="1">'.&mt('username:domain').'</option>'.
+                  '</select></span></div></fieldset>';
+    $datatable .= '<fieldset><legend>'.&mt('Role mapping').'</legend><table><tr>';
+    foreach my $role (@courseroles) {
+        my ($checked,$checkednone);
+        $datatable .= '<td align="center">'.
+                      &Apache::lonnet::plaintext($role,'Course').'<br />'.
+                      '<select name="ltitools_add_roles_'.$role.'">'.
+                      '<option value="" selected="selected">'.&mt('Select').'</option>';
+        foreach my $ltirole (@ltiroles) {
+            $datatable .= '<option value="'.$ltirole.'">'.$ltirole.'</option>';
+        }
+        $datatable .= '</select></td>';
+    }
+    $datatable .= '</tr></table></fieldset>'.
+                  '<fieldset><legend>'.&mt('Configurable in course').'</legend><span class="LC_nobreak">';
+    foreach my $item ('label','title','target','linktext','explanation','append') {
+        $datatable .= '<label>'.
+                      '<input type="checkbox" name="ltitools_courseconfig" value="'.$item.'" checked="checked" />'.
+                      $lt{'crs'.$item}.'</label>'.('&nbsp;' x2)."\n";
+    }
+    $datatable .= '</span></fieldset>'.
+                  '<fieldset><legend>'.&mt('Custom items sent on launch').'</legend>'.
+                  '<table><tr><th>'.&mt('Action').'</th><th>'.&mt('Name').'</th><th>'.&mt('Value').'</th></tr>'.
+                  '<tr><td><span class="LC_nobreak">'.
+                  '<label><input type="checkbox" name="ltitools_add_custom" value="1" />'.
+                  &mt('Add').'</label></span></td><td><input type="text" name="ltitools_add_custom_name" />'.
+                  '</td><td><input type="text" name="ltitools_add_custom_value" /></td></tr>'.
+                  '</table></fieldset>'."\n".
+                  '</td>'."\n".
+                  '</tr>'."\n";
+    $itemcount ++;
+    return $datatable;
+}
+
+sub ltitools_names {
+    my %lt = &Apache::lonlocal::texthash(
+                                          'title'          => 'Title',
+                                          'version'        => 'Version',
+                                          'msgtype'        => 'Message Type',
+                                          'sigmethod'      => 'Signature Method',
+                                          'url'            => 'URL',
+                                          'key'            => 'Key',
+                                          'lifetime'       => 'Nonce lifetime (s)',
+                                          'secret'         => 'Secret',
+                                          'icon'           => 'Icon',
+                                          'user'           => 'User',
+                                          'fullname'       => 'Full Name',
+                                          'firstname'      => 'First Name',
+                                          'lastname'       => 'Last Name',
+                                          'email'          => 'E-mail',
+                                          'roles'          => 'Role',
+                                          'window'         => 'Window',
+                                          'tab'            => 'Tab',
+                                          'iframe'         => 'iFrame',
+                                          'height'         => 'Height',
+                                          'width'          => 'Width',
+                                          'linktext'       => 'Default Link Text',
+                                          'explanation'    => 'Default Explanation',
+                                          'crstarget'      => 'Display target',
+                                          'crslabel'       => 'Course label',
+                                          'crstitle'       => 'Course title',
+                                          'crslinktext'    => 'Link Text',
+                                          'crsexplanation' => 'Explanation',
+                                          'crsappend'      => 'Provider URL',
+                                        );
+
+    return %lt;
+}
+
+sub print_lti {
+    my ($position,$dom,$settings,$rowtotal) = @_;
+    my $itemcount = 1;
+    my ($datatable,$css_class);
+    my (%rules,%encrypt,%privkeys,%linkprot);
+    if (ref($settings) eq 'HASH') {
+        if ($position eq 'top') {
+            if (exists($settings->{'encrypt'})) {
+                if (ref($settings->{'encrypt'}) eq 'HASH') {
+                    foreach my $key (keys(%{$settings->{'encrypt'}})) {
+                        $encrypt{'ltisec_'.$key.'linkprot'} = $settings->{'encrypt'}{$key};
+                    }
+                }
+            }
+            if (exists($settings->{'private'})) {
+                if (ref($settings->{'private'}) eq 'HASH') {
+                    if (ref($settings->{'private'}) eq 'HASH') {
+                        if (ref($settings->{'private'}{'keys'}) eq 'ARRAY') {
+                            map { $privkeys{$_} = 1; } (@{$settings->{'private'}{'keys'}});
+                        }
+                    }
+                }
+            }
+        } elsif ($position eq 'middle') {
+            if (exists($settings->{'rules'})) {
+                if (ref($settings->{'rules'}) eq 'HASH') {
+                    %rules = %{$settings->{'rules'}};
+                }
+            }
+        } elsif ($position eq 'bottom') {
+            if (exists($settings->{'linkprot'})) {
+                if (ref($settings->{'linkprot'}) eq 'HASH') {
+                    %linkprot = %{$settings->{'linkprot'}};
+                    if ($linkprot{'lock'}) {
+                        delete($linkprot{'lock'});
+                    }
+                }
+            }
+        }
+    }
+    if ($position eq 'top') {
+        my @ids=&Apache::lonnet::current_machine_ids();
+        my %servers = &Apache::lonnet::get_servers($dom,'library');
+        my $primary = &Apache::lonnet::domain($dom,'primary');
+        my ($extra,$numshown);
+        foreach my $hostid (sort(keys(%servers))) {
+            my ($showextra,$divsty,$switch);
+            if ($hostid eq $primary) {
+                if ($encrypt{'ltisec_domlinkprot'}) {
+                    $showextra = 1;
+                }
+            }
+            if ($encrypt{'ltisec_crslinkprot'}) {
+                $showextra = 1;
+            }
+            unless (grep(/^\Q$hostid\E$/,@ids)) {
+                $switch = 1;
+            }
+            if ($showextra) {
+                $numshown ++;
+                $divsty = 'display:inline-block';
+            } else {
+                $divsty = 'display:none';
+            }
+            $extra .= '<fieldset id="ltisec_info_'.$hostid.'" style="'.$divsty.'">'.
+                      '<legend>'.$hostid.'</legend>';
+            if ($switch) {
+                my $switchserver = '<a href="/adm/switchserver?otherserver='.$hostid.'&amp;role='.
+                                   &HTML::Entities::encode($env{'request.role'},'\'<>"&').
+                                   '&amp;destinationurl=/adm/domainprefs">'.&mt('Switch Server').'</a>';
+                if (exists($privkeys{$hostid})) {
+                    $extra .= '<div id="ltisec_divcurrprivkey_'.$hostid.'" style="display:inline-block" />'.
+                              '<span class="LC_nobreak">'.
+                              &mt('Encryption Key').': ['.&mt('not shown').'] '.('&nbsp;'x2).'</span></div>'.
+                              '<span class="LC_nobreak">'.&mt('Change?').
+                              '<label><input type="radio" value="0" name="ltisec_changeprivkey_'.$hostid.'" onclick="javascript:togglePrivKey(this.form,'."'$hostid'".');" checked="checked" />'.&mt('No').'</label>'.
+                              ('&nbsp;'x2).
+                              '<label><input type="radio" value="1" name="ltisec_changeprivkey_'.$hostid.'" onclick="javascript:togglePrivKey(this.form,'."'$hostid'".');" />'.&mt('Yes').
+                              '</label>&nbsp;&nbsp;</span><div id="ltisec_divchgprivkey_'.$hostid.'" style="display:none" />'.
+                              '<span class="LC_nobreak"> - '.&mt('submit from server ([_1]): [_2].',$hostid,$switchserver).
+                              '</span></div>';
+                } else {
+                    $extra .= '<span class="LC_nobreak">'.
+                              &mt('Key required').' - '.&mt('submit from server ([_1]): [_2].',$hostid,$switchserver).
+                              '</span>'."\n";
+                }
+            } elsif (exists($privkeys{$hostid})) {
+                $extra .= '<div id="ltisec_divcurrprivkey_'.$hostid.'" style="display:inline-block" /><span class="LC_nobreak">'.
+                          &mt('Encryption Key').': ['.&mt('not shown').'] '.('&nbsp;'x2).'</span></div>'.
+                          '<span class="LC_nobreak">'.&mt('Change?').
+                          '<label><input type="radio" value="0" name="ltisec_changeprivkey_'.$hostid.'" onclick="javascript:togglePrivKey(this.form,'."'$hostid'".');" checked="checked" />'.&mt('No').'</label>'.
+                          ('&nbsp;'x2).
+                          '<label><input type="radio" value="1" name="ltisec_changeprivkey_'.$hostid.'" onclick="javascript:togglePrivKey(this.form,'."'$hostid'".');" />'.&mt('Yes').
+                          '</label>&nbsp;&nbsp;</span><div id="ltisec_divchgprivkey_'.$hostid.'" style="display:none" />'.
+                          '<span class="LC_nobreak">'.&mt('New Key').':'.
+                          '<input type="password" size="20" name="ltisec_privkey_'.$hostid.'" value="" autocomplete="off" />'.
+                          '<label><input type="checkbox" name="visible" onclick="if (this.checked) { this.form.ltisec_privkey_'.$hostid.'.type='."'text'".' } else { this.form.ltisec_privkey_'.$hostid.'.type='."'password'".' }" />'.&mt('Visible input').'</label>'.
+                          '</span></div>';
+            } else {
+                $extra .= '<span class="LC_nobreak">'.&mt('Encryption Key').':'.
+                          '<input type="password" size="20" name="ltisec_privkey_'.$hostid.'" value="" autocomplete="off" />'.
+                          '<label><input type="checkbox" name="visible" onclick="if (this.checked) { this.form.ltisec_privkey_'.$hostid.'.type='."'text'".' } else { this.form.ltisec_privkey_'.$hostid.'.type='."'password'".' }" />'.&mt('Visible input').'</label>';
+            }
+            $extra .= '</fieldset>';
+        }
+        my %choices = &Apache::lonlocal::texthash (
+                                                      ltisec_crslinkprot => 'Encrypt stored link protection secrets defined in courses',
+                                                      ltisec_domlinkprot => 'Encrypt stored link protection secrets defined in domain',
+                                                  );
+        my @toggles = qw(ltisec_crslinkprot ltisec_domlinkprot);
+        my %defaultchecked = (
+                               'ltisec_crslinkprot' => 'off',
+                               'ltisec_domlinkprot' => 'off',
+                             );
+        my ($onclick,$itemcount);
+        $onclick = 'javascript:toggleLTIEncKey(this.form);';
+        ($datatable,$itemcount) = &radiobutton_prefs(\%encrypt,\@toggles,\%defaultchecked,
+                                                     \%choices,$itemcount,$onclick,'','left','no');
+
+        $css_class = $itemcount%2?' class="LC_odd_row"':'';
+        my $noprivkeysty = 'display:inline-block';
+        if ($numshown) {
+            $noprivkeysty = 'display:none';
+        }
+        $datatable .= '<tr '.$css_class.'><td><span class="LC_nobreak">'.&mt('Encryption Key(s)').'</td>'.
+                      '<td><div id="ltisec_noprivkey" style="'.$noprivkeysty.'" >'.
+                      '<span class="LC_nobreak">'.&mt('Not in use').'</span></div>'.
+                      $extra.
+                      '</td></tr>';
+        $itemcount ++;
+        $$rowtotal += $itemcount;
+    } elsif ($position eq 'middle') {
+        $datatable = &password_rules('secrets',\$itemcount,\%rules);
+        $$rowtotal += $itemcount;
+    } elsif ($position eq 'bottom') {
+         $datatable .= &Apache::courseprefs::print_linkprotection($dom,'',$settings,$rowtotal,'','','domain');
+    }
+    return $datatable;
+}
+
 sub print_coursedefaults {
     my ($position,$dom,$settings,$rowtotal) = @_;
     my ($css_class,$datatable,%checkedon,%checkedoff,%defaultchecked,@toggles);
@@ -4447,6 +5371,7 @@ sub print_coursedefaults {
         postsubmit           => 'Disable submit button/keypress following student submission',
         canclone             => "People who may clone a course (besides course's owner and coordinators)",
         mysqltables          => 'Lifetime (s) of "Temporary" MySQL tables (student performance data) on homeserver',
+        ltiauth              => 'Student username in LTI launch of deep-linked URL can be accepted without re-authentication',
     );
     my %staticdefaults = (
                            anonsurvey_threshold => 10,
@@ -4568,8 +5493,12 @@ sub print_coursedefaults {
         my ($currdefresponder,%defcredits,%curruploadquota,%deftimeout,%currmysql);
         my $currusecredits = 0;
         my $postsubmitclient = 1;
+        my $ltiauth = 0;
         my @types = ('official','unofficial','community','textbook');
         if (ref($settings) eq 'HASH') {
+            if ($settings->{'ltiauth'}) {
+                $ltiauth = 1;
+            }
             $currdefresponder = $settings->{'anonsurvey_threshold'};
             if (ref($settings->{'uploadquota'}) eq 'HASH') {
                 foreach my $type (keys(%{$settings->{'uploadquota'}})) {
@@ -4715,7 +5644,16 @@ sub print_coursedefaults {
         }
         $datatable .= '</tr></table></td></tr>'."\n";
         $itemcount ++;
-
+        %defaultchecked = ('ltiauth' => 'off');
+        @toggles = ('ltiauth');
+        $current = {
+                       'ltiauth' => $ltiauth,
+                   };
+        ($table,$itemcount) =
+            &radiobutton_prefs($current,\@toggles,\%defaultchecked,
+                               \%choices,$itemcount,undef,undef,'left');
+        $datatable .= $table;
+        $itemcount ++;
     }
     $$rowtotal += $itemcount;
     return $datatable;
@@ -5231,84 +6169,7 @@ sub print_passwords {
             $itemcount ++;
         }
     } elsif ($position eq 'lower') {
-        my ($min,$max,%chars,$numsaved);
-        $min = $Apache::lonnet::passwdmin;
-        if (ref($settings) eq 'HASH') {
-            if ($settings->{min}) {
-                $min = $settings->{min};
-            }
-            if ($settings->{max}) {
-                $max = $settings->{max};
-            }
-            if (ref($settings->{chars}) eq 'ARRAY') {
-                map { $chars{$_} = 1; } (@{$settings->{chars}});
-            }
-            if ($settings->{numsaved}) {
-                $numsaved = $settings->{numsaved};
-            }
-        }
-        my %rulenames = &Apache::lonlocal::texthash(
-                                                     uc => 'At least one upper case letter',
-                                                     lc => 'At least one lower case letter',
-                                                     num => 'At least one number',
-                                                     spec => 'At least one non-alphanumeric',
-                                                   );
-        $css_class = $itemcount%2?' class="LC_odd_row"':'';
-        $datatable .= '<tr'.$css_class.'><td>'.$titles{'min'}.'</td>'.
-                      '<td class="LC_left_item"><span class="LC_nobreak">'.
-                      '<input type="text" name="passwords_min" value="'.$min.'" size="3" '.
-                      'onblur="javascript:warnIntPass(this);" />'.
-                      '<span class="LC_fontsize_small"> '.&mt('(Enter an integer: 7 or larger)').'</span>'.
-                      '</span></td></tr>';
-        $itemcount ++;
-        $css_class = $itemcount%2?' class="LC_odd_row"':'';
-        $datatable .= '<tr'.$css_class.'><td>'.$titles{'max'}.'</td>'.
-                      '<td class="LC_left_item"><span class="LC_nobreak">'.
-                      '<input type="text" name="passwords_max" value="'.$max.'" size="3" '.
-                      'onblur="javascript:warnIntPass(this);" />'.
-                      '<span class="LC_fontsize_small"> '.&mt('(Leave blank for no maximum)').'</span>'.
-                      '</span></td></tr>';
-        $itemcount ++;
-        $css_class = $itemcount%2?' class="LC_odd_row"':'';
-        $datatable .= '<tr'.$css_class.'><td>'.$titles{'chars'}.'<br />'.
-                      '<span class="LC_nobreak LC_fontsize_small">'.&mt('(Leave unchecked if not required)').
-                      '</span></td>';
-        my $numinrow = 2;
-        my @possrules = ('uc','lc','num','spec');
-        $datatable .= '<td class="LC_left_item"><table>';
-        for (my $i=0; $i<@possrules; $i++) {
-            my ($rem,$checked);
-            if ($chars{$possrules[$i]}) {
-                $checked = ' checked="checked"';
-            }
-            $rem = $i%($numinrow);
-            if ($rem == 0) {
-                if ($i > 0) {
-                    $datatable .= '</tr>';
-                }
-                $datatable .= '<tr>';
-            }
-            $datatable .= '<td><span class="LC_nobreak"><label>'.
-                          '<input type="checkbox" name="passwords_chars" value="'.$possrules[$i].'"'.$checked.' />'.
-                          $rulenames{$possrules[$i]}.'</label></span></td>';
-        }
-        my $rem = @possrules%($numinrow);
-        my $colsleft = $numinrow - $rem;
-        if ($colsleft > 1 ) {
-            $datatable .= '<td colspan="'.$colsleft.'" class="LC_left_item">'.
-                          '&nbsp;</td>';
-        } elsif ($colsleft == 1) {
-            $datatable .= '<td class="LC_left_item">&nbsp;</td>';
-        }
-        $datatable .='</table></td></tr>';
-        $itemcount ++;
-        $css_class = $itemcount%2?' class="LC_odd_row"':'';
-        $datatable .= '<tr'.$css_class.'><td>'.$titles{'numsaved'}.'</td>'.
-                      '<td class="LC_left_item"><span class="LC_nobreak">'.
-                      '<input type="text" name="passwords_numsaved" value="'.$numsaved.'" size="3" '.
-                      'onblur="javascript:warnIntPass(this);" />'.
-                      '<span class="LC_fontsize_small"> '.&mt('(Leave blank to not save previous passwords)').'</span>'.
-                      '</span></td></tr>';
+        $datatable .= &password_rules('passwords',\$itemcount,$settings);
     } else {
         my ($othertitle,$usertypes,$types) = &Apache::loncommon::sorted_inst_types($dom);
         my %ownerchg = (
@@ -5368,6 +6229,117 @@ sub print_passwords {
     return $datatable;
 }
 
+sub password_rules {
+    my ($prefix,$itemcountref,$settings) = @_;
+    my ($min,$max,%chars,$numsaved,$numinrow);
+    my %titles;
+    if ($prefix eq 'passwords') {
+        %titles = &Apache::lonlocal::texthash (
+            min            => 'Minimum password length',
+            max            => 'Maximum password length',
+            chars          => 'Required characters',
+        );
+    } elsif ($prefix eq 'secrets') {
+        %titles = &Apache::lonlocal::texthash (
+            min            => 'Minimum secret length',
+            max            => 'Maximum secret length',
+            chars          => 'Required characters',
+        );
+    }
+    $min = $Apache::lonnet::passwdmin;
+    my $datatable;
+    my $itemcount;
+    if (ref($itemcountref)) {
+        $itemcount = $$itemcountref;
+    }
+    if (ref($settings) eq 'HASH') {
+        if ($settings->{min}) {
+            $min = $settings->{min};
+        }
+        if ($settings->{max}) {
+            $max = $settings->{max};
+        }
+        if (ref($settings->{chars}) eq 'ARRAY') {
+            map { $chars{$_} = 1; } (@{$settings->{chars}});
+        }
+        if ($prefix eq 'passwords') {
+            if ($settings->{numsaved}) {
+                $numsaved = $settings->{numsaved};
+            }
+        }
+    }
+    my %rulenames = &Apache::lonlocal::texthash(
+                                                 uc => 'At least one upper case letter',
+                                                 lc => 'At least one lower case letter',
+                                                 num => 'At least one number',
+                                                 spec => 'At least one non-alphanumeric',
+                                               );
+    my $css_class = $itemcount%2?' class="LC_odd_row"':'';
+    $datatable .= '<tr'.$css_class.'><td>'.$titles{'min'}.'</td>'.
+                  '<td class="LC_left_item"><span class="LC_nobreak">'.
+                  '<input type="text" name="'.$prefix.'_min" value="'.$min.'" size="3" '.
+                  'onblur="javascript:warnInt'.$prefix.'(this);" />'.
+                  '<span class="LC_fontsize_small"> '.&mt('(Enter an integer: 7 or larger)').'</span>'.
+                  '</span></td></tr>';
+    $itemcount ++;
+    $css_class = $itemcount%2?' class="LC_odd_row"':'';
+    $datatable .= '<tr'.$css_class.'><td>'.$titles{'max'}.'</td>'.
+                  '<td class="LC_left_item"><span class="LC_nobreak">'.
+                  '<input type="text" name="'.$prefix.'_max" value="'.$max.'" size="3" '.
+                  'onblur="javascript:warnInt'.$prefix.'(this);" />'.
+                  '<span class="LC_fontsize_small"> '.&mt('(Leave blank for no maximum)').'</span>'.
+                  '</span></td></tr>';
+    $itemcount ++;
+    $css_class = $itemcount%2?' class="LC_odd_row"':'';
+    $datatable .= '<tr'.$css_class.'><td>'.$titles{'chars'}.'<br />'.
+                  '<span class="LC_nobreak LC_fontsize_small">'.&mt('(Leave unchecked if not required)').
+                  '</span></td>';
+    my $numinrow = 2;
+    my @possrules = ('uc','lc','num','spec');
+    $datatable .= '<td class="LC_left_item"><table>';
+    for (my $i=0; $i<@possrules; $i++) {
+        my ($rem,$checked);
+        if ($chars{$possrules[$i]}) {
+            $checked = ' checked="checked"';
+        }
+        $rem = $i%($numinrow);
+        if ($rem == 0) {
+            if ($i > 0) {
+                $datatable .= '</tr>';
+            }
+            $datatable .= '<tr>';
+        }
+        $datatable .= '<td><span class="LC_nobreak"><label>'.
+                      '<input type="checkbox" name="'.$prefix.'_chars" value="'.$possrules[$i].'"'.$checked.' />'.
+                      $rulenames{$possrules[$i]}.'</label></span></td>';
+    }
+    my $rem = @possrules%($numinrow);
+    my $colsleft = $numinrow - $rem;
+    if ($colsleft > 1 ) {
+        $datatable .= '<td colspan="'.$colsleft.'" class="LC_left_item">'.
+                      '&nbsp;</td>';
+    } elsif ($colsleft == 1) {
+        $datatable .= '<td class="LC_left_item">&nbsp;</td>';
+    }
+    $datatable .='</table></td></tr>';
+    $itemcount ++;
+    if ($prefix eq 'passwords') {
+        $titles{'numsaved'} = &mt('Number of previous passwords to save and disallow reuse');
+        $css_class = $itemcount%2?' class="LC_odd_row"':'';
+        $datatable .= '<tr'.$css_class.'><td>'.$titles{'numsaved'}.'</td>'.
+                      '<td class="LC_left_item"><span class="LC_nobreak">'.
+                      '<input type="text" name="'.$prefix.'_numsaved" value="'.$numsaved.'" size="3" '.
+                      'onblur="javascript:warnInt'.$prefix.'(this);" />'.
+                      '<span class="LC_fontsize_small"> '.&mt('(Leave blank to not save previous passwords)').'</span>'.
+                      '</span></td></tr>';
+        $itemcount ++;
+    }
+    if (ref($itemcountref)) {
+        $$itemcountref += $itemcount;
+    }
+    return $datatable;
+}
+
 sub print_wafproxy {
     my ($position,$dom,$settings,$rowtotal) = @_;
     my $css_class;
@@ -8357,17 +9329,26 @@ ENDSCRIPT
 }
 
 sub passwords_javascript {
-    my %intalert = &Apache::lonlocal::texthash (
-        authcheck => 'Warning: disallowing login for an authenticated user if the stored cost is less than the default will require a password reset by/for the user.',
-        authcost => 'Warning: bcrypt encryption cost for internal authentication must be an integer.',
-        passmin => 'Warning: minimum password length must be a positive integer greater than 6.',
-        passmax => 'Warning: maximum password length must be a positive integer (or blank).',
-        passexp => 'Warning: days before password expiration must be a positive integer (or blank).',
-        passnum => 'Warning: number of previous passwords to save must be a positive integer (or blank).',
-    );
+    my ($prefix) = @_;
+    my %intalert;
+    if ($prefix eq 'passwords') {
+        %intalert = &Apache::lonlocal::texthash (
+            authcheck => 'Warning: disallowing login for an authenticated user if the stored cost is less than the default will require a password reset by/for the user.',
+            authcost => 'Warning: bcrypt encryption cost for internal authentication must be an integer.',
+            passmin => 'Warning: minimum password length must be a positive integer greater than 6.',
+            passmax => 'Warning: maximum password length must be a positive integer (or blank).',
+            passnum => 'Warning: number of previous passwords to save must be a positive integer (or blank).',
+        );
+    } elsif ($prefix eq 'secrets') {
+        %intalert = &Apache::lonlocal::texthash (
+            passmin => 'Warning: minimum secret length must be a positive integer greater than 6.',
+            passmax => 'Warning: maximum secret length must be a positive integer (or blank).',
+        );
+    }
     &js_escape(\%intalert);
     my $defmin = $Apache::lonnet::passwdmin;
-    my $intauthjs = <<"ENDSCRIPT";
+    my $intauthjs;
+    if ($prefix eq 'passwords') { $intauthjs = <<"ENDSCRIPT";
 
 function warnIntAuth(field) {
     if (field.name == 'intauth_check') {
@@ -8387,11 +9368,17 @@ function warnIntAuth(field) {
     return;
 }
 
-function warnIntPass(field) {
+ENDSCRIPT
+
+     }
+
+     $intauthjs .= <<"ENDSCRIPT";
+
+function warnInt$prefix(field) {
     field.value.replace(/^\s+/,'');
     field.value.replace(/\s+\$/,'');
     var regexdigit=/^\\d+\$/;
-    if (field.name == 'passwords_min') {
+    if (field.name == '${prefix}_min') {
         if (field.value == '') {
             alert('$intalert{passmin}');
             field.value = '$defmin';
@@ -8411,29 +9398,15 @@ function warnIntPass(field) {
             field.value = '';
         }
         if (field.value != '') {
-            if (field.name == 'passwords_expire') {
-                var regexpposnum=/^\\d+(|\\.\\d*)\$/;
-                if (!regexpposnum.test(field.value)) {
-                    alert('$intalert{passexp}');
-                    field.value = '';
+            if (!regexdigit.test(field.value)) {
+                if (field.name == '${prefix}_max') {
+                    alert('$intalert{passmax}');
                 } else {
-                    var expval = parseFloat(field.value);
-                    if (expval == 0) {
-                        alert('$intalert{passexp}');
-                        field.value = '';
+                    if (field.name == '${prefix}_numsaved') {
+                        alert('$intalert{passnum}');
                     }
                 }
-            } else {
-                if (!regexdigit.test(field.value)) {
-                    if (field.name == 'passwords_max') {
-                        alert('$intalert{passmax}');
-                    } else {
-                        if (field.name == 'passwords_numsaved') {
-                            alert('$intalert{passnum}');
-                        }
-                    }
-                    field.value = '';
-                }
+                field.value = '';
             }
         }
     }
@@ -10031,13 +11004,18 @@ sub modify_colors {
             $domconfig->{$role} = {};
         }
         foreach my $img (@images) {
-            if (($role eq 'login') && (($img eq 'img') || ($img eq 'logo'))) {  
-                if (defined($env{'form.login_showlogo_'.$img})) {
-                    $confhash->{$role}{'showlogo'}{$img} = 1;
-                } else { 
-                    $confhash->{$role}{'showlogo'}{$img} = 0;
+            if ($role eq 'login') {
+                if (($img eq 'img') || ($img eq 'logo')) {  
+                    if (defined($env{'form.login_showlogo_'.$img})) {
+                        $confhash->{$role}{'showlogo'}{$img} = 1;
+                    } else { 
+                        $confhash->{$role}{'showlogo'}{$img} = 0;
+                    }
                 }
-            } 
+                if ($env{'form.login_alt_'.$img} ne '') {
+                    $confhash->{$role}{'alttext'}{$img} = $env{'form.login_alt_'.$img};
+                }
+            }
 	    if ( ! $env{'form.'.$role.'_'.$img.'.filename'} 
 		 && !defined($domconfig->{$role}{$img})
 		 && !$env{'form.'.$role.'_del_'.$img}
@@ -10112,15 +11090,29 @@ sub modify_colors {
                             $changes{$role}{'images'}{$img} = 1;
                         } 
                     }
-                    if (($role eq 'login') && (($img eq 'logo') || ($img eq 'img'))) {
-                        if (ref($domconfig->{'login'}{'showlogo'}) eq 'HASH') {
-                            if ($confhash->{$role}{'showlogo'}{$img} ne 
-                                $domconfig->{$role}{'showlogo'}{$img}) {
-                                $changes{$role}{'showlogo'}{$img} = 1; 
+                    if ($role eq 'login') {
+                        if (($img eq 'logo') || ($img eq 'img')) {
+                            if (ref($domconfig->{'login'}{'showlogo'}) eq 'HASH') {
+                                if ($confhash->{$role}{'showlogo'}{$img} ne 
+                                    $domconfig->{$role}{'showlogo'}{$img}) {
+                                    $changes{$role}{'showlogo'}{$img} = 1; 
+                                }
+                            } else {
+                                if ($confhash->{$role}{'showlogo'}{$img} == 0) {
+                                    $changes{$role}{'showlogo'}{$img} = 1;
+                                }
                             }
-                        } else {
-                            if ($confhash->{$role}{'showlogo'}{$img} == 0) {
-                                $changes{$role}{'showlogo'}{$img} = 1;
+                        }
+                        if ($img ne 'login') {
+                            if (ref($domconfig->{$role}{'alttext'}) eq 'HASH') {
+                                if ($confhash->{$role}{'alttext'}{$img} ne
+                                    $domconfig->{$role}{'alttext'}{$img}) {
+                                    $changes{$role}{'alttext'}{$img} = 1;
+                                }
+                            } else {
+                                if ($confhash->{$role}{'alttext'}{$img} ne '') {
+                                    $changes{$role}{'alttext'}{$img} = 1;
+                                }
                             }
                         }
                     }
@@ -10231,6 +11223,11 @@ sub default_change_checker {
             if ($confhash->{$role}{'showlogo'}{$img} == 0) {
                 $changes->{$role}{'showlogo'}{$img} = 1;
             }
+            if (ref($confhash->{$role}{'alttext'}) eq 'HASH') {
+                if ($confhash->{$role}{'alttext'}{$img} ne '') {
+                    $changes->{$role}{'alttext'}{$img} = 1;
+                }
+            }
         }
     }
     if ($confhash->{$role}{'font'}) {
@@ -10269,6 +11266,13 @@ sub display_colorchgs {
                             } else {
                                 $resulttext .= '<li>'.&mt("$choices{$item} set to not be displayed").'</li>';
                             }
+                        } elsif (($role eq 'login') && ($key eq 'alttext')) {
+                            if ($confhash->{$role}{$key}{$item} ne '') {
+                                $resulttext .= '<li>'.&mt("$choices{$key} for $choices{$item} set to [_1].",
+                                               $confhash->{$role}{$key}{$item}).'</li>';
+                            } else {
+                                $resulttext .= '<li>'.&mt("$choices{$key} for $choices{$item} deleted.").'</li>';
+                            }
                         } elsif ($confhash->{$role}{$item} eq '') {
                             $resulttext .= '<li>'.&mt("$choices{$item} set to default").'</li>';
                         } else {
@@ -11374,6 +12378,861 @@ sub process_textbook_image {
     return ($url,$error);
 }
 
+sub modify_ltitools {
+    my ($r,$dom,$action,$lastactref,%domconfig) = @_;
+    my %domdefaults = &Apache::lonnet::get_domain_defaults($dom,1);
+    my ($newid,@allpos,%changes,%confhash,%encconfig,$errors,$resulttext);
+    my $confname = $dom.'-domainconfig';
+    my $servadm = $r->dir_config('lonAdmEMail');
+    my ($configuserok,$author_ok,$switchserver) = &config_check($dom,$confname,$servadm);
+    my (%posslti,%possfield);
+    my @courseroles = ('cc','in','ta','ep','st');
+    my @ltiroles = qw(Instructor ContentDeveloper TeachingAssistant Learner);
+    map { $posslti{$_} = 1; } @ltiroles;
+    my @allfields = ('fullname','firstname','lastname','email','user','roles');
+    map { $possfield{$_} = 1; } @allfields;
+    my %lt = &ltitools_names();
+    if ($env{'form.ltitools_add'}) {
+        my $title = $env{'form.ltitools_add_title'};
+        $title =~ s/(`)/'/g;
+        ($newid,my $error) = &get_ltitools_id($dom,$title);
+        if ($newid) {
+            my $position = $env{'form.ltitools_add_pos'};
+            $position =~ s/\D+//g;
+            if ($position ne '') {
+                $allpos[$position] = $newid;
+            }
+            $changes{$newid} = 1;
+            foreach my $item ('title','url','key','secret','lifetime') {
+                $env{'form.ltitools_add_'.$item} =~ s/(`)/'/g;
+                if ($item eq 'lifetime') {
+                    $env{'form.ltitools_add_'.$item} =~ s/[^\d.]//g;
+                }
+                if ($env{'form.ltitools_add_'.$item}) {
+                    if (($item eq 'key') || ($item eq 'secret')) {
+                        $encconfig{$newid}{$item} = $env{'form.ltitools_add_'.$item};
+                    } else {
+                        $confhash{$newid}{$item} = $env{'form.ltitools_add_'.$item};
+                    }
+                }
+            }
+            if ($env{'form.ltitools_add_version'} eq 'LTI-1p0') {
+                $confhash{$newid}{'version'} = $env{'form.ltitools_add_version'};
+            }
+            if ($env{'form.ltitools_add_msgtype'} eq 'basic-lti-launch-request') {
+                $confhash{$newid}{'msgtype'} = $env{'form.ltitools_add_msgtype'};
+            }
+            if ($env{'form.ltitools_add_sigmethod'} eq 'HMAC-SHA256') {
+                $confhash{$newid}{'sigmethod'} = $env{'form.ltitools_add_sigmethod'};
+            } else {
+                $confhash{$newid}{'sigmethod'} = 'HMAC-SHA1';
+            }
+            foreach my $item ('width','height','linktext','explanation') {
+                $env{'form.ltitools_add_'.$item} =~ s/^\s+//;
+                $env{'form.ltitools_add_'.$item} =~ s/\s+$//;
+                if (($item eq 'width') || ($item eq 'height')) {
+                    if ($env{'form.ltitools_add_'.$item} =~ /^\d+$/) {
+                        $confhash{$newid}{'display'}{$item} = $env{'form.ltitools_add_'.$item};
+                    }
+                } else {
+                    if ($env{'form.ltitools_add_'.$item} ne '') {
+                        $confhash{$newid}{'display'}{$item} = $env{'form.ltitools_add_'.$item};
+                    }
+                }
+            }
+            if ($env{'form.ltitools_add_target'} eq 'window') {
+                $confhash{$newid}{'display'}{'target'} = $env{'form.ltitools_add_target'};
+            } elsif ($env{'form.ltitools_add_target'} eq 'tab') {
+                $confhash{$newid}{'display'}{'target'} = $env{'form.ltitools_add_target'};
+            } else {
+                $confhash{$newid}{'display'}{'target'} = 'iframe';
+            }
+            if ($env{'form.ltitools_add_image.filename'} ne '') {
+                my ($imageurl,$error) =
+                    &process_ltitools_image($r,$dom,$confname,'ltitools_add_image',$newid,
+                                            $configuserok,$switchserver,$author_ok);
+                if ($imageurl) {
+                    $confhash{$newid}{'image'} = $imageurl;
+                }
+                if ($error) {
+                    &Apache::lonnet::logthis($error);
+                    $errors .= '<li><span class="LC_error">'.$error.'</span></li>';
+                }
+            }
+            my @fields = &Apache::loncommon::get_env_multiple('form.ltitools_add_fields');
+            foreach my $field (@fields) {
+                if ($possfield{$field}) {
+                    if ($field eq 'roles') {
+                        foreach my $role (@courseroles) {
+                            my $choice = $env{'form.ltitools_add_roles_'.$role};
+                            if (($choice ne '') && ($posslti{$choice})) {
+                                $confhash{$newid}{'roles'}{$role} = $choice;
+                                if ($role eq 'cc') {
+                                    $confhash{$newid}{'roles'}{'co'} = $choice;
+                                }
+                            }
+                        }
+                    } else {
+                        $confhash{$newid}{'fields'}{$field} = 1;
+                    }
+                }
+            }
+            if (ref($confhash{$newid}{'fields'}) eq 'HASH') {
+                if ($confhash{$newid}{'fields'}{'user'}) {
+                    if ($env{'form.ltitools_userincdom_add'}) {
+                        $confhash{$newid}{'incdom'} = 1;
+                    }
+                }
+            }
+            my @courseconfig = &Apache::loncommon::get_env_multiple('form.ltitools_courseconfig');
+            foreach my $item (@courseconfig) {
+                $confhash{$newid}{'crsconf'}{$item} = 1;
+            }
+            if ($env{'form.ltitools_add_custom'}) {
+                my $name = $env{'form.ltitools_add_custom_name'};
+                my $value = $env{'form.ltitools_add_custom_value'};
+                $value =~ s/(`)/'/g;
+                $name =~ s/(`)/'/g;
+                $confhash{$newid}{'custom'}{$name} = $value;
+            }
+        } else {
+            my $error = &mt('Failed to acquire unique ID for new external tool');
+            $errors .= '<li><span class="LC_error">'.$error.'</span></li>';
+        }
+    }
+    if (ref($domconfig{$action}) eq 'HASH') {
+        my %deletions;
+        my @todelete = &Apache::loncommon::get_env_multiple('form.ltitools_del');
+        if (@todelete) {
+            map { $deletions{$_} = 1; } @todelete;
+        }
+        my %customadds;
+        my @newcustom = &Apache::loncommon::get_env_multiple('form.ltitools_customadd');
+        if (@newcustom) {
+            map { $customadds{$_} = 1; } @newcustom;
+        }
+        my %imgdeletions;
+        my @todeleteimages = &Apache::loncommon::get_env_multiple('form.ltitools_image_del');
+        if (@todeleteimages) {
+            map { $imgdeletions{$_} = 1; } @todeleteimages;
+        }
+        my $maxnum = $env{'form.ltitools_maxnum'};
+        for (my $i=0; $i<=$maxnum; $i++) {
+            my $itemid = $env{'form.ltitools_id_'.$i};
+            $itemid =~ s/\D+//g;
+            if (ref($domconfig{$action}{$itemid}) eq 'HASH') {
+                if ($deletions{$itemid}) {
+                    if ($domconfig{$action}{$itemid}{'image'}) {
+                        #FIXME need to obsolete item in RES space
+                    }
+                    $changes{$itemid} = $domconfig{$action}{$itemid}{'title'};
+                    next;
+                } else {
+                    my $newpos = $env{'form.ltitools_'.$itemid};
+                    $newpos =~ s/\D+//g;
+                    foreach my $item ('title','url','lifetime') {
+                        $confhash{$itemid}{$item} = $env{'form.ltitools_'.$item.'_'.$i};
+                        if ($domconfig{$action}{$itemid}{$item} ne $confhash{$itemid}{$item}) {
+                            $changes{$itemid} = 1;
+                        }
+                    }
+                    foreach my $item ('key','secret') {
+                        $encconfig{$itemid}{$item} = $env{'form.ltitools_'.$item.'_'.$i};
+                        if ($domconfig{$action}{$itemid}{$item} ne $encconfig{$itemid}{$item}) {
+                            $changes{$itemid} = 1;
+                        }
+                    }
+                    if ($env{'form.ltitools_version_'.$i} eq 'LTI-1p0') {
+                        $confhash{$itemid}{'version'} = $env{'form.ltitools_version_'.$i};
+                    }
+                    if ($env{'form.ltitools_msgtype_'.$i} eq 'basic-lti-launch-request') {
+                        $confhash{$itemid}{'msgtype'} = $env{'form.ltitools_msgtype_'.$i};
+                    }
+                    if ($env{'form.ltitools_sigmethod_'.$i} eq 'HMAC-SHA256') {
+                        $confhash{$itemid}{'sigmethod'} = $env{'form.ltitools_sigmethod_'.$i};
+                    } else {
+                        $confhash{$itemid}{'sigmethod'} = 'HMAC-SHA1';
+                    }
+                    if ($domconfig{$action}{$itemid}{'sigmethod'} eq '') {
+                        if ($confhash{$itemid}{'sigmethod'} ne 'HMAC-SHA1') {
+                            $changes{$itemid} = 1;
+                        }
+                    } elsif ($domconfig{$action}{$itemid}{'sigmethod'} ne $confhash{$itemid}{'sigmethod'}) {
+                        $changes{$itemid} = 1;
+                    }
+                    foreach my $size ('width','height') {
+                        $env{'form.ltitools_'.$size.'_'.$i} =~ s/^\s+//;
+                        $env{'form.ltitools_'.$size.'_'.$i} =~ s/\s+$//;
+                        if ($env{'form.ltitools_'.$size.'_'.$i} =~ /^\d+$/) {
+                            $confhash{$itemid}{'display'}{$size} = $env{'form.ltitools_'.$size.'_'.$i};
+                            if (ref($domconfig{$action}{$itemid}{'display'}) eq 'HASH') {
+                                if ($domconfig{$action}{$itemid}{'display'}{$size} ne $confhash{$itemid}{'display'}{$size}) {
+                                    $changes{$itemid} = 1;
+                                }
+                            } else {
+                                $changes{$itemid} = 1;
+                            }
+                        } elsif (ref($domconfig{$action}{$itemid}{'display'}) eq 'HASH') {
+                            if ($domconfig{$action}{$itemid}{'display'}{$size} ne '') {
+                                $changes{$itemid} = 1;
+                            }
+                        }
+                    }
+                    foreach my $item ('linktext','explanation') {
+                        $env{'form.ltitools_'.$item.'_'.$i} =~ s/^\s+//;
+                        $env{'form.ltitools_'.$item.'_'.$i} =~ s/\s+$//;
+                        if ($env{'form.ltitools_'.$item.'_'.$i} ne '') {
+                            $confhash{$itemid}{'display'}{$item} = $env{'form.ltitools_'.$item.'_'.$i};
+                            if (ref($domconfig{$action}{$itemid}{'display'}) eq 'HASH') {
+                                if ($domconfig{$action}{$itemid}{'display'}{$item} ne $confhash{$itemid}{'display'}{$item}) {
+                                    $changes{$itemid} = 1;
+                                }
+                            } else {
+                                $changes{$itemid} = 1;
+                            }
+                        } elsif (ref($domconfig{$action}{$itemid}{'display'}) eq 'HASH') {
+                            if ($domconfig{$action}{$itemid}{'display'}{$item} ne '') {
+                                $changes{$itemid} = 1;
+                            }
+                        }
+                    }
+                    if ($env{'form.ltitools_target_'.$i} eq 'window') {
+                        $confhash{$itemid}{'display'}{'target'} = $env{'form.ltitools_target_'.$i};
+                    } elsif ($env{'form.ltitools_target_'.$i} eq 'tab') {
+                        $confhash{$itemid}{'display'}{'target'} = $env{'form.ltitools_target_'.$i};
+                    } else {
+                        $confhash{$itemid}{'display'}{'target'} = 'iframe';
+                    }
+                    if (ref($domconfig{$action}{$itemid}{'display'}) eq 'HASH') {
+                        if ($domconfig{$action}{$itemid}{'display'}{'target'} ne $confhash{$itemid}{'display'}{'target'}) {
+                            $changes{$itemid} = 1;
+                        }
+                    } else {
+                        $changes{$itemid} = 1;
+                    }
+                    my @courseconfig = &Apache::loncommon::get_env_multiple('form.ltitools_courseconfig_'.$i);
+                    foreach my $item ('label','title','target','linktext','explanation','append') {
+                        if (grep(/^\Q$item\E$/,@courseconfig)) {
+                            $confhash{$itemid}{'crsconf'}{$item} = 1;
+                            if (ref($domconfig{$action}{$itemid}{'crsconf'}) eq 'HASH') {
+                                if ($domconfig{$action}{$itemid}{'crsconf'}{$item} ne $confhash{$itemid}{'crsconf'}{$item}) {
+                                    $changes{$itemid} = 1;
+                                }
+                            } else {
+                                $changes{$itemid} = 1;
+                            }
+                        }
+                    }
+                    my @fields = &Apache::loncommon::get_env_multiple('form.ltitools_fields_'.$i);
+                    foreach my $field (@fields) {
+                        if ($possfield{$field}) {
+                            if ($field eq 'roles') {
+                                foreach my $role (@courseroles) {
+                                    my $choice = $env{'form.ltitools_roles_'.$role.'_'.$i};
+                                    if (($choice ne '') && ($posslti{$choice})) {
+                                        $confhash{$itemid}{'roles'}{$role} = $choice;
+                                        if ($role eq 'cc') {
+                                            $confhash{$itemid}{'roles'}{'co'} = $choice;
+                                        }
+                                    }
+                                    if (ref($domconfig{$action}{$itemid}{'roles'}) eq 'HASH') {
+                                        if ($domconfig{$action}{$itemid}{'roles'}{$role} ne $confhash{$itemid}{'roles'}{$role}) {
+                                            $changes{$itemid} = 1;
+                                        }
+                                    } elsif ($confhash{$itemid}{'roles'}{$role}) {
+                                        $changes{$itemid} = 1;
+                                    }
+                                }
+                            } else {
+                                $confhash{$itemid}{'fields'}{$field} = 1;
+                                if (ref($domconfig{$action}{$itemid}{'fields'}) eq 'HASH') {
+                                    if ($domconfig{$action}{$itemid}{'fields'}{$field} ne $confhash{$itemid}{'fields'}{$field}) {
+                                        $changes{$itemid} = 1;
+                                    }
+                                } else {
+                                    $changes{$itemid} = 1;
+                                }
+                            }
+                        }
+                    }
+                    if (ref($confhash{$itemid}{'fields'}) eq 'HASH') {
+                        if ($confhash{$itemid}{'fields'}{'user'}) {
+                            if ($env{'form.ltitools_userincdom_'.$i}) {
+                                $confhash{$itemid}{'incdom'} = 1;
+                            }
+                            if ($domconfig{$action}{$itemid}{'incdom'} ne $confhash{$itemid}{'incdom'}) {
+                                $changes{$itemid} = 1;
+                            }
+                        }
+                    }
+                    $allpos[$newpos] = $itemid;
+                }
+                if ($imgdeletions{$itemid}) {
+                    $changes{$itemid} = 1;
+                    #FIXME need to obsolete item in RES space
+                } elsif ($env{'form.ltitools_image_'.$i.'.filename'}) {
+                    my ($imgurl,$error) = &process_ltitools_image($r,$dom,$confname,'ltitools_image_'.$i,
+                                                                 $itemid,$configuserok,$switchserver,
+                                                                 $author_ok);
+                    if ($imgurl) {
+                        $confhash{$itemid}{'image'} = $imgurl;
+                        $changes{$itemid} = 1;
+                    }
+                    if ($error) {
+                        &Apache::lonnet::logthis($error);
+                        $errors .= '<li><span class="LC_error">'.$error.'</span></li>';
+                    }
+                } elsif ($domconfig{$action}{$itemid}{'image'}) {
+                    $confhash{$itemid}{'image'} =
+                       $domconfig{$action}{$itemid}{'image'};
+                }
+                if ($customadds{$i}) {
+                    my $name = $env{'form.ltitools_custom_name_'.$i};
+                    $name =~ s/(`)/'/g;
+                    $name =~ s/^\s+//;
+                    $name =~ s/\s+$//;
+                    my $value = $env{'form.ltitools_custom_value_'.$i};
+                    $value =~ s/(`)/'/g;
+                    $value =~ s/^\s+//;
+                    $value =~ s/\s+$//;
+                    if ($name ne '') {
+                        $confhash{$itemid}{'custom'}{$name} = $value;
+                        $changes{$itemid} = 1;
+                    }
+                }
+                my %customdels;
+                my @customdeletions = &Apache::loncommon::get_env_multiple('form.ltitools_customdel_'.$i);
+                if (@customdeletions) {
+                    $changes{$itemid} = 1;
+                }
+                map { $customdels{$_} = 1; } @customdeletions;
+                if (ref($domconfig{$action}{$itemid}{'custom'}) eq 'HASH') {
+                    foreach my $key (keys(%{$domconfig{$action}{$itemid}{'custom'}})) {
+                        unless ($customdels{$key}) {
+                            if ($env{'form.ltitools_customval_'.$key.'_'.$i} ne '') {
+                                $confhash{$itemid}{'custom'}{$key} = $env{'form.ltitools_customval_'.$key.'_'.$i};
+                            }
+                            if ($domconfig{$action}{$itemid}{'custom'}{$key} ne $env{'form.ltitools_customval_'.$key.'_'.$i}) {
+                                $changes{$itemid} = 1;
+                            }
+                        }
+                    }
+                }
+                unless ($changes{$itemid}) {
+                    foreach my $key (keys(%{$domconfig{$action}{$itemid}})) {
+                        if (ref($domconfig{$action}{$itemid}{$key}) eq 'HASH') {
+                            if (ref($confhash{$itemid}{$key}) eq 'HASH') {
+                                foreach my $innerkey (keys(%{$domconfig{$action}{$itemid}{$key}})) {
+                                    unless (exists($confhash{$itemid}{$key}{$innerkey})) {
+                                        $changes{$itemid} = 1;
+                                        last;
+                                    }
+                                }
+                            } elsif (keys(%{$domconfig{$action}{$itemid}{$key}}) > 0) {
+                                $changes{$itemid} = 1;
+                            }
+                        }
+                        last if ($changes{$itemid});
+                    }
+                }
+            }
+        }
+    }
+    if (@allpos > 0) {
+        my $idx = 0;
+        foreach my $itemid (@allpos) {
+            if ($itemid ne '') {
+                $confhash{$itemid}{'order'} = $idx;
+                if (ref($domconfig{$action}) eq 'HASH') {
+                    if (ref($domconfig{$action}{$itemid}) eq 'HASH') {
+                        if ($domconfig{$action}{$itemid}{'order'} ne $idx) {
+                            $changes{$itemid} = 1;
+                        }
+                    }
+                }
+                $idx ++;
+            }
+        }
+    }
+    my %ltitoolshash = (
+                          $action => { %confhash }
+                       );
+    my $putresult = &Apache::lonnet::put_dom('configuration',\%ltitoolshash,
+                                             $dom);
+    if ($putresult eq 'ok') {
+        my %ltienchash = (
+                             $action => { %encconfig }
+                         );
+        &Apache::lonnet::put_dom('encconfig',\%ltienchash,$dom,undef,1);
+        if (keys(%changes) > 0) {
+            my $cachetime = 24*60*60;
+            my %ltiall = %confhash;
+            foreach my $id (keys(%ltiall)) {
+                if (ref($encconfig{$id}) eq 'HASH') {
+                    foreach my $item ('key','secret') {
+                        $ltiall{$id}{$item} = $encconfig{$id}{$item};
+                    }
+                }
+            }
+            &Apache::lonnet::do_cache_new('ltitools',$dom,\%ltiall,$cachetime);
+            if (ref($lastactref) eq 'HASH') {
+                $lastactref->{'ltitools'} = 1;
+            }
+            $resulttext = &mt('Changes made:').'<ul>';
+            my %bynum;
+            foreach my $itemid (sort(keys(%changes))) {
+                my $position = $confhash{$itemid}{'order'};
+                $bynum{$position} = $itemid;
+            }
+            foreach my $pos (sort { $a <=> $b } keys(%bynum)) {
+                my $itemid = $bynum{$pos};
+                if (ref($confhash{$itemid}) ne 'HASH') {
+                    $resulttext .= '<li>'.&mt('Deleted: [_1]',$changes{$itemid}).'</li>';
+                } else {
+                    $resulttext .= '<li><b>'.$confhash{$itemid}{'title'}.'</b>';
+                    if ($confhash{$itemid}{'image'}) {
+                        $resulttext .= '&nbsp;'.
+                                       '<img src="'.$confhash{$itemid}{'image'}.'"'.
+                                       ' alt="'.&mt('Tool Provider icon').'" />';
+                    }
+                    $resulttext .= '</li><ul>';
+                    my $position = $pos + 1;
+                    $resulttext .= '<li>'.&mt('Order: [_1]',$position).'</li>';
+                    foreach my $item ('version','msgtype','sigmethod','url','lifetime') {
+                        if ($confhash{$itemid}{$item} ne '') {
+                            $resulttext .= '<li>'.$lt{$item}.':&nbsp;'.$confhash{$itemid}{$item}.'</li>';
+                        }
+                    }
+                    if ($encconfig{$itemid}{'key'} ne '') {
+                        $resulttext .= '<li>'.$lt{'key'}.':&nbsp;'.$encconfig{$itemid}{'key'}.'</li>';
+                    }
+                    if ($encconfig{$itemid}{'secret'} ne '') {
+                        $resulttext .= '<li>'.$lt{'secret'}.':&nbsp;';
+                        my $num = length($encconfig{$itemid}{'secret'});
+                        $resulttext .= ('*'x$num).'</li>';
+                    }
+                    $resulttext .= '<li>'.&mt('Configurable in course:');
+                    my @possconfig = ('label','title','target','linktext','explanation','append');
+                    my $numconfig = 0;
+                    if (ref($confhash{$itemid}{'crsconf'}) eq 'HASH') {
+                        foreach my $item (@possconfig) {
+                            if ($confhash{$itemid}{'crsconf'}{$item}) {
+                                $numconfig ++;
+                                $resulttext .= ' "'.$lt{'crs'.$item}.'"';
+                            }
+                        }
+                    }
+                    if (!$numconfig) {
+                        $resulttext .= &mt('None');
+                    }
+                    $resulttext .= '</li>';
+                    if (ref($confhash{$itemid}{'display'}) eq 'HASH') {
+                        my $displaylist;
+                        if ($confhash{$itemid}{'display'}{'target'}) {
+                            $displaylist = &mt('Display target').':&nbsp;'.
+                                           $confhash{$itemid}{'display'}{'target'}.',';
+                        }
+                        foreach my $size ('width','height') {
+                            if ($confhash{$itemid}{'display'}{$size}) {
+                                $displaylist .= ('&nbsp;'x2).$lt{$size}.':&nbsp;'.
+                                                $confhash{$itemid}{'display'}{$size}.',';
+                            }
+                        }
+                        if ($displaylist) {
+                            $displaylist =~ s/,$//;
+                            $resulttext .= '<li>'.$displaylist.'</li>';
+                        }
+                        foreach my $item ('linktext','explanation') {
+                            if ($confhash{$itemid}{'display'}{$item}) {
+                                $resulttext .= '<li>'.$lt{$item}.':&nbsp;'.$confhash{$itemid}{'display'}{$item}.'</li>';
+                            }
+                        }
+                    }
+                    if (ref($confhash{$itemid}{'fields'}) eq 'HASH') {
+                        my $fieldlist;
+                        foreach my $field (@allfields) {
+                            if ($confhash{$itemid}{'fields'}{$field}) {
+                                $fieldlist .= ('&nbsp;'x2).$lt{$field}.',';
+                            }
+                        }
+                        if ($fieldlist) {
+                            $fieldlist =~ s/,$//;
+                            if ($confhash{$itemid}{'fields'}{'user'}) {
+                                if ($confhash{$itemid}{'incdom'}) {
+                                    $fieldlist .= ' ('.&mt('username:domain').')';
+                                } else {
+                                    $fieldlist .= ' ('.&mt('username').')';
+                                }
+                            }
+                            $resulttext .= '<li>'.&mt('Data sent').':'.$fieldlist.'</li>';
+                        }
+                    }
+                    if (ref($confhash{$itemid}{'roles'}) eq 'HASH') {
+                        my $rolemaps;
+                        foreach my $role (@courseroles) {
+                            if ($confhash{$itemid}{'roles'}{$role}) {
+                                $rolemaps .= ('&nbsp;'x2).&Apache::lonnet::plaintext($role,'Course').'='.
+                                             $confhash{$itemid}{'roles'}{$role}.',';
+                            }
+                        }
+                        if ($rolemaps) {
+                            $rolemaps =~ s/,$//;
+                            $resulttext .= '<li>'.&mt('Role mapping:').$rolemaps.'</li>';
+                        }
+                    }
+                    if (ref($confhash{$itemid}{'custom'}) eq 'HASH') {
+                        my $customlist;
+                        if (keys(%{$confhash{$itemid}{'custom'}})) {
+                            foreach my $key (sort(keys(%{$confhash{$itemid}{'custom'}}))) {
+                                $customlist .= $key.':'.$confhash{$itemid}{'custom'}{$key}.('&nbsp;'x2);
+                            }
+                        }
+                        if ($customlist) {
+                            $resulttext .= '<li>'.&mt('Custom items').': '.$customlist.'</li>';
+                        }
+                    }
+                    $resulttext .= '</ul></li>';
+                }
+            }
+            $resulttext .= '</ul>';
+        } else {
+            $resulttext = &mt('No changes made.');
+        }
+    } else {
+        $errors .= '<li><span class="LC_error">'.&mt('Failed to save changes').'</span></li>';
+    }
+    if ($errors) {
+        $resulttext .= &mt('The following errors occurred: ').'<ul>'.
+                       $errors.'</ul>';
+    }
+    return $resulttext;
+}
+
+sub process_ltitools_image {
+    my ($r,$dom,$confname,$caller,$itemid,$configuserok,$switchserver,$author_ok) = @_;
+    my $filename = $env{'form.'.$caller.'.filename'};
+    my ($error,$url);
+    my ($width,$height) = (21,21);
+    if ($configuserok eq 'ok') {
+        if ($switchserver) {
+            $error = &mt('Upload of Tool Provider (LTI) icon is not permitted to this server: [_1]',
+                         $switchserver);
+        } elsif ($author_ok eq 'ok') {
+            my ($result,$imageurl,$madethumb) =
+                &publishlogo($r,'upload',$caller,$dom,$confname,
+                             "ltitools/$itemid/icon",$width,$height);
+            if ($result eq 'ok') {
+                if ($madethumb) {
+                    my ($path,$imagefile) = ($imageurl =~ m{^(.+)/([^/]+)$});
+                    my $imagethumb = "$path/tn-".$imagefile;
+                    $url = $imagethumb;
+                } else {
+                    $url = $imageurl;
+                }
+            } else {
+                $error = &mt("Upload of [_1] failed because an error occurred publishing the file in RES space. Error was: [_2].",$filename,$result);
+            }
+        } else {
+            $error = &mt("Upload of [_1] failed because an author role could not be assigned to a Domain Configuration user ([_2]) in domain: [_3].  Error was: [_4].",$filename,$confname,$dom,$author_ok);
+        }
+    } else {
+        $error = &mt("Upload of [_1] failed because a Domain Configuration user ([_2]) could not be created in domain: [_3].  Error was: [_4].",$filename,$confname,$dom,$configuserok);
+    }
+    return ($url,$error);
+}
+
+sub get_ltitools_id {
+    my ($cdom,$title) = @_;
+    # get lock on ltitools db
+    my $lockhash = {
+                      lock => $env{'user.name'}.
+                              ':'.$env{'user.domain'},
+                   };
+    my $tries = 0;
+    my $gotlock = &Apache::lonnet::newput_dom('ltitools',$lockhash,$cdom);
+    my ($id,$error);
+
+    while (($gotlock ne 'ok') && ($tries<10)) {
+        $tries ++;
+        sleep (0.1);
+        $gotlock = &Apache::lonnet::newput_dom('ltitools',$lockhash,$cdom);
+    }
+    if ($gotlock eq 'ok') {
+        my %currids = &Apache::lonnet::dump_dom('ltitools',$cdom);
+        if ($currids{'lock'}) {
+            delete($currids{'lock'});
+            if (keys(%currids)) {
+                my @curr = sort { $a <=> $b } keys(%currids);
+                if ($curr[-1] =~ /^\d+$/) {
+                    $id = 1 + $curr[-1];
+                }
+            } else {
+                $id = 1;
+            }
+            if ($id) {
+                unless (&Apache::lonnet::newput_dom('ltitools',{ $id => $title },$cdom) eq 'ok') {
+                    $error = 'nostore';
+                }
+            } else {
+                $error = 'nonumber';
+            }
+        }
+        my $dellockoutcome = &Apache::lonnet::del_dom('ltitools',['lock'],$cdom);
+    } else {
+        $error = 'nolock';
+    }
+    return ($id,$error);
+}
+
+sub modify_lti {
+    my ($r,$dom,$action,$lastactref,%domconfig) = @_;
+    my %domdefaults = &Apache::lonnet::get_domain_defaults($dom,1);
+    my (%encconfig,$errors,$resulttext);
+
+    my (%currltisec,%secchanges,%newltisec,%newltienc,%keyset,%newkeyset);
+    $newltisec{'private'}{'keys'} = [];
+    $newltisec{'encrypt'} = {};
+    $newltisec{'rules'} = {};
+    $newltisec{'linkprot'} = {};
+    if (ref($domconfig{'ltisec'}) eq 'HASH') {
+        %currltisec = %{$domconfig{'ltisec'}};
+        if (ref($currltisec{'linkprot'}) eq 'HASH') {
+            foreach my $id (keys(%{$currltisec{'linkprot'}})) {
+                unless ($id =~ /^\d+$/) {
+                    delete($currltisec{'linkprot'}{$id});
+                }
+            }
+        }
+        if (ref($currltisec{'private'}) eq 'HASH') {
+            if (ref($currltisec{'private'}{'keys'}) eq 'ARRAY') {
+                $newltisec{'private'}{'keys'} = $currltisec{'private'}{'keys'};
+                map { $keyset{$_} = 1; } @{$currltisec{'private'}{'keys'}};
+            }
+        }
+    }
+    foreach my $item ('crs','dom') {
+        my $formelement = 'form.ltisec_'.$item.'linkprot';
+        if ($env{$formelement}) {
+            $newltisec{'encrypt'}{$item} = 1;
+            if (ref($currltisec{'encrypt'}) eq 'HASH') {
+                unless ($currltisec{'encrypt'}{$item}) {
+                    $secchanges{'encrypt'} = 1;
+                }
+            } else {
+                $secchanges{'encrypt'} = 1;
+            }
+        } elsif (ref($currltisec{'encrypt'}) eq 'HASH') {
+            if ($currltisec{'encrypt'}{$item}) {
+                $secchanges{'encrypt'} = 1;
+            }
+        }
+    }
+    unless (exists($currltisec{'rules'})) {
+        $currltisec{'rules'} = {};
+    }
+    &password_rule_changes('secrets',$newltisec{'rules'},$currltisec{'rules'},\%secchanges);
+
+    my @ids=&Apache::lonnet::current_machine_ids();
+    my %servers = &Apache::lonnet::get_servers($dom,'library');
+
+    foreach my $hostid (keys(%servers)) {
+        if (($hostid ne '') && (grep(/^\Q$hostid\E$/,@ids))) {
+            my $newkey;
+            my $keyitem = 'form.ltisec_privkey_'.$hostid;
+            if (exists($env{$keyitem})) {
+                $env{$keyitem} =~ s/(`)/'/g;
+                if ($keyset{$hostid}) {
+                    if ($env{'form.ltisec_changeprivkey_'.$hostid}) {
+                        if ($env{$keyitem} ne '') {
+                            $secchanges{'private'} = 1;
+                            $newkeyset{$hostid} = $env{$keyitem};
+                        }
+                    }
+                } elsif ($env{$keyitem} ne '') {
+                    unless (grep(/^\Q$hostid\E$/,@{$newltisec{'private'}{'keys'}})) {
+                        push(@{$newltisec{'private'}{'keys'}},$hostid);
+                    }
+                    $secchanges{'private'} = 1;
+                    $newkeyset{$hostid} = $env{$keyitem};
+                }
+            }
+        }
+    }
+
+    my (%linkprotchg,$linkprotoutput,$is_home);
+    my $proterror = &Apache::courseprefs::process_linkprot($dom,'',$currltisec{'linkprot'},
+                                                           \%linkprotchg,'domain');
+    my $home = &Apache::lonnet::domain($dom,'primary');
+    unless (($home eq 'no_host') || ($home eq '')) {
+        my @ids=&Apache::lonnet::current_machine_ids();
+        foreach my $id (@ids) { if ($id eq $home) { $is_home=1; } }
+    }
+
+    if (keys(%linkprotchg)) {
+        $secchanges{'linkprot'} = 1;
+        my %oldlinkprot;
+        if (ref($currltisec{'linkprot'}) eq 'HASH') {
+            %oldlinkprot = %{$currltisec{'linkprot'}};
+        }
+        foreach my $id (keys(%linkprotchg)) {
+            if (ref($linkprotchg{$id}) eq 'HASH') {
+                foreach my $inner (keys(%{$linkprotchg{$id}})) {
+                    if (($inner eq 'secret') || ($inner eq 'key')) {
+                        if ($is_home) {
+                            $newltienc{$id}{$inner} = $linkprotchg{$id}{$inner};
+                        }
+                    }
+                }
+            } else {
+                $newltisec{'linkprot'}{$id} = $linkprotchg{$id};
+            }
+        }
+        $linkprotoutput = &Apache::courseprefs::store_linkprot($dom,'','domain',\%linkprotchg,\%oldlinkprot);
+        if (keys(%linkprotchg)) {
+            %{$newltisec{'linkprot'}} = %linkprotchg;
+        }
+    }
+    if (ref($currltisec{'linkprot'}) eq 'HASH') {
+        foreach my $id (%{$currltisec{'linkprot'}}) {
+            next if ($id !~ /^\d+$/);
+            unless (exists($linkprotchg{$id})) {
+                if (ref($currltisec{'linkprot'}{$id}) eq 'HASH') {
+                    foreach my $inner (keys(%{$currltisec{'linkprot'}{$id}})) {
+                        if (($inner eq 'secret') || ($inner eq 'key')) {
+                            if ($is_home) {
+                                $newltienc{$id}{$inner} = $currltisec{'linkprot'}{$id}{$inner};
+                            }
+                        } else {
+                            $newltisec{'linkprot'}{$id}{$inner} = $currltisec{'linkprot'}{$id}{$inner};
+                        }
+                    }
+                } else {
+                    $newltisec{'linkprot'}{$id} = $currltisec{'linkprot'}{$id};
+                }
+            }
+        }
+    }
+    if ($proterror) {
+        $errors .= '<li>'.$proterror.'</li>';
+    }
+
+    my ($putresult,%keystore);
+    if (keys(%secchanges)) {
+        my %ltienchash;
+        my %ltihash = (
+                          'ltisec' => { %newltisec }
+                      );
+        $putresult = &Apache::lonnet::put_dom('configuration',\%ltihash,$dom);
+        if ($putresult eq 'ok') {
+            if ($secchanges{'private'}) {
+                my $who = &escape($env{'user.name'}.':'.$env{'user.domain'});
+                foreach my $hostid (keys(%newkeyset)) {
+                    my $storehash = {
+                                       key => $newkeyset{$hostid},
+                                       who => $env{'user.name'}.':'.$env{'user.domain'},
+                                    };
+                    $keystore{$hostid} = &Apache::lonnet::store_dom($storehash,'lti','private',
+                                                                    $dom,$hostid);
+                }
+            }
+            if (ref($lastactref) eq 'HASH') {
+                if (($secchanges{'encrypt'}) || ($secchanges{'private'})) {
+                    $lastactref->{'domdefaults'} = 1;
+                }
+            }
+            if (($secchanges{'linkprot'}) && ($is_home)) {
+                my %ltienchash = (
+                                     'linkprot' =>  { %newltienc }
+                                 );
+                &Apache::lonnet::put_dom('encconfig',\%ltienchash,$dom,undef,1);
+            }
+        }
+    } else {
+        return &mt('No changes made.');
+    }
+    if ($putresult eq 'ok') {
+        $resulttext = &mt('Changes made:').'<ul>';
+        foreach my $item (keys(%secchanges)) {
+            if ($item eq 'encrypt') {
+                my %encrypted = (
+                          crs  => {
+                                    on => &mt('Encryption of stored link protection secrets defined in courses enabled'),
+                                    off => &mt('Encryption of stored link protection secrets defined in courses disabled'),
+                                  },
+                          dom => {
+                                   on => &mt('Encryption of stored link protection secrets defined in domain enabled'),
+                                   off => &mt('Encryption of stored link protection secrets defined in domain disabled'),
+                                 },
+                );
+                foreach my $type ('crs','dom') {
+                    my $shown = $encrypted{$type}{'off'};
+                    if (ref($newltisec{$item}) eq 'HASH') {
+                        if ($newltisec{$item}{$type}) {
+                            $shown = $encrypted{$type}{'on'};
+                        }
+                    }
+                    $resulttext .= '<li>'.$shown.'</li>';
+                }
+            } elsif ($item eq 'rules') {
+                my %titles = &Apache::lonlocal::texthash(
+                                  min   => 'Minimum password length',
+                                  max   => 'Maximum password length',
+                                  chars => 'Required characters',
+                );
+                foreach my $rule ('min','max') {
+                    if ($newltisec{rules}{$rule} eq '') {
+                        if ($rule eq 'min') {
+                            $resulttext .= '<li>'.&mt('[_1] not set.',$titles{$rule});
+                                           ' '.&mt('Default of [_1] will be used',
+                                                       $Apache::lonnet::passwdmin).'</li>';
+                        } else {
+                            $resulttext .= '<li>'.&mt('[_1] set to none',$titles{$rule}).'</li>';
+                        }
+                    } else {
+                        $resulttext .= '<li>'.&mt('[_1] set to [_2]',$titles{$rule},$newltisec{rules}{$rule}).'</li>';
+                    }
+                }
+                if (ref($newltisec{'rules'}{'chars'}) eq 'ARRAY') {
+                    if (@{$newltisec{'rules'}{'chars'}} > 0) {
+                        my %rulenames = &Apache::lonlocal::texthash(
+                                            uc => 'At least one upper case letter',
+                                            lc => 'At least one lower case letter',
+                                            num => 'At least one number',
+                                            spec => 'At least one non-alphanumeric',
+                                            );
+                        my $needed = '<ul><li>'.
+                                     join('</li><li>',map {$rulenames{$_} } @{$newltisec{'rules'}{'chars'}}).
+                                     '</li></ul>';
+                        $resulttext .= '<li>'.&mt('[_1] set to: [_2]',$titles{'chars'},$needed).'</li>';
+                    } else {
+                        $resulttext .= '<li>'.&mt('[_1] set to none',$titles{'chars'}).'</li>';
+                    }
+                } else {
+                    $resulttext .= '<li>'.&mt('[_1] set to none',$titles{'chars'}).'</li>';
+                }
+            } elsif ($item eq 'private') {
+                if (keys(%newkeyset)) {
+                    foreach my $hostid (sort(keys(%newkeyset))) {
+                        if ($keystore{$hostid} eq 'ok') {
+                            $resulttext .= '<li>'.&mt('Encryption key for storage of shared secrets saved for [_1]',$hostid).'</li>';
+                        }
+                    }
+                }
+            } elsif ($item eq 'linkprot') {
+                $resulttext .= $linkprotoutput;
+            }
+        }
+        $resulttext .= '</ul>';
+    } else {
+        $errors .= '<li><span class="LC_error">'.&mt('Failed to save changes').'</span></li>';
+    }
+    if ($errors) {
+        $resulttext .= &mt('The following errors occurred: ').'<ul>'.
+                       $errors.'</ul>';
+    }
+    return $resulttext;
+}
+
 sub modify_autoenroll {
     my ($dom,$lastactref,%domconfig) = @_;
     my ($resulttext,%changes);
@@ -11387,7 +13246,7 @@ sub modify_autoenroll {
     my %title = ( run => 'Auto-enrollment active',
                   sender => 'Sender for notification messages',
                   coowners => 'Automatic assignment of co-ownership to instructors of record (institutional data)',
-                  failsafe => 'Failsafe for no drops if institutional data missing for a section');
+                  autofailsafe => 'Failsafe for no drops if institutional data missing for a section');
     my @offon = ('off','on');
     my $sender_uname = $env{'form.sender_uname'};
     my $sender_domain = $env{'form.sender_domain'};
@@ -11397,17 +13256,23 @@ sub modify_autoenroll {
         $sender_domain = '';
     }
     my $coowners = $env{'form.autoassign_coowners'};
+    my $autofailsafe = $env{'form.autoenroll_autofailsafe'};
+    $autofailsafe =~ s{^\s+|\s+$}{}g;
+    if ($autofailsafe =~ /\D/) {
+        undef($autofailsafe);
+    }
     my $failsafe = $env{'form.autoenroll_failsafe'};
-    $failsafe =~ s{^\s+|\s+$}{}g;
-    if ($failsafe =~ /\D/) {
-        undef($failsafe);
+    unless (($failsafe eq 'zero') || ($failsafe eq 'any')) {
+        $failsafe = 'off';
+        undef($autofailsafe);
     }
     my %autoenrollhash =  (
                        autoenroll => { 'run' => $env{'form.autoenroll_run'},
                                        'sender_uname' => $sender_uname,
                                        'sender_domain' => $sender_domain,
                                        'co-owners' => $coowners,
-                                       'autofailsafe' => $failsafe,
+                                       'autofailsafe' => $autofailsafe,
+                                       'failsafe' => $failsafe,
                                 }
                      );
     my $putresult = &Apache::lonnet::put_dom('configuration',\%autoenrollhash,
@@ -11435,9 +13300,12 @@ sub modify_autoenroll {
         } elsif ($coowners) {
             $changes{'coowners'} = 1;
         }
-        if ($currautoenroll{'autofailsafe'} ne $failsafe) {
+        if ($currautoenroll{'autofailsafe'} ne $autofailsafe) {
             $changes{'autofailsafe'} = 1;
         }
+        if ($currautoenroll{'failsafe'} ne $failsafe) {
+            $changes{'failsafe'} = 1;
+        }
         if (keys(%changes) > 0) {
             $resulttext = &mt('Changes made:').'<ul>';
             if ($changes{'run'}) {
@@ -11458,11 +13326,24 @@ sub modify_autoenroll {
                 }
             }
             if ($changes{'autofailsafe'}) {
-                if ($failsafe ne '') {
-                    $resulttext .= '<li>'.&mt('Failsafe for no drops if institutional data missing for a section set to: [_1]',$failsafe).'</li>';
+                if ($autofailsafe ne '') {
+                    $resulttext .= '<li>'.&mt('Failsafe for no drops if institutional data missing for a section set to: [_1]',$autofailsafe).'</li>';
                 } else {
-                    $resulttext .= '<li>'.&mt('Failsafe for no drops if institutional data missing for a section: deleted');
+                    $resulttext .= '<li>'.&mt('Failsafe for no drops if institutional data missing for a section not in use').'</li>';
                 }
+            }
+            if ($changes{'failsafe'}) {
+                if ($failsafe eq 'off') {
+                    unless ($changes{'autofailsafe'}) {
+                        $resulttext .= '<li>'.&mt('Failsafe for no drops if institutional data missing for a section not in use').'</li>';
+                    }
+                } elsif ($failsafe eq 'zero') {
+                    $resulttext .= '<li>'.&mt('Failsafe applies if retrieved section enrollment is zero').'</li>';
+                } else {
+                    $resulttext .= '<li>'.&mt('Failsafe applies if retrieved section enrollment is zero or greater').'</li>';
+                }
+            }
+            if (($changes{'autofailsafe'}) || ($changes{'failsafe'})) {
                 &Apache::lonnet::get_domain_defaults($dom,1);
                 if (ref($lastactref) eq 'HASH') {
                     $lastactref->{'domdefaults'} = 1;
@@ -12800,56 +14681,7 @@ sub modify_passwords {
             $updatedefaults = 1;
         }
     }
-    foreach my $rule ('min','max','numsaved') {
-        $env{'form.passwords_'.$rule} =~ s/^\s+|\s+$//g;
-        my $ruleok;
-        if ($rule eq 'min') {
-            if ($env{'form.passwords_'.$rule} =~ /^\d+$/) {
-                if ($env{'form.passwords_'.$rule} >= $Apache::lonnet::passwdmin) {
-                    $ruleok = 1;
-                }
-            }
-        } elsif (($env{'form.passwords_'.$rule} =~ /^\d+$/) &&
-                 ($env{'form.passwords_'.$rule} ne '0')) {
-            $ruleok = 1;
-        }
-        if ($ruleok) {
-            $newvalues{$rule} = $env{'form.passwords_'.$rule};
-            if (exists($current{$rule})) {
-                if ($newvalues{$rule} ne $current{$rule}) {
-                    $changes{'rules'} = 1;
-                }
-            } elsif ($rule eq 'min') {
-                if ($staticdefaults{$rule} ne $newvalues{$rule}) {
-                    $changes{'rules'} = 1;
-                }
-            } else {
-                $changes{'rules'} = 1;
-            }
-        } elsif (exists($current{$rule})) {
-            $changes{'rules'} = 1;
-        }
-    }
-    my @posschars = &Apache::loncommon::get_env_multiple('form.passwords_chars');
-    my @chars;
-    foreach my $item (sort(@posschars)) {
-        if ($item =~ /^(uc|lc|num|spec)$/) {
-            push(@chars,$item);
-        }
-    }
-    $newvalues{'chars'} = \@chars;
-    unless ($changes{'rules'}) {
-        if (ref($current{'chars'}) eq 'ARRAY') {
-            my @diffs = &Apache::loncommon::compare_arrays($current{'chars'},\@chars);
-            if (@diffs > 0) {
-                $changes{'rules'} = 1;
-            }
-        } else {
-            if (@chars > 0) {
-                $changes{'rules'} = 1;
-            }
-        }
-    }
+    &password_rule_changes('passwords',\%newvalues,\%current,\%changes);
     my %crsownerchg = (
                         by => [],
                         for => [],
@@ -13109,6 +14941,71 @@ sub modify_passwords {
     return $resulttext;
 }
 
+sub password_rule_changes {
+    my ($prefix,$newvalues,$current,$changes) = @_;
+    return unless ((ref($newvalues) eq 'HASH') &&
+                   (ref($current) eq 'HASH') &&
+                   (ref($changes) eq 'HASH'));
+    my (@rules,%staticdefaults);
+    if ($prefix eq 'passwords') {
+        @rules = ('min','max','numsaved');
+    } elsif ($prefix eq 'secrets') {
+        @rules = ('min','max');
+    }
+    $staticdefaults{'min'} = $Apache::lonnet::passwdmin;
+    foreach my $rule (@rules) {
+        $env{'form.'.$prefix.'_'.$rule} =~ s/^\s+|\s+$//g;
+        my $ruleok;
+        if ($rule eq 'min') {
+            if ($env{'form.'.$prefix.'_'.$rule} =~ /^\d+$/) {
+                if ($env{'form.'.$prefix.'_'.$rule} >= $staticdefaults{$rule}) {
+                    $ruleok = 1;
+                }
+            }
+        } elsif (($env{'form.'.$prefix.'_'.$rule} =~ /^\d+$/) &&
+                 ($env{'form.'.$prefix.'_'.$rule} ne '0')) {
+            $ruleok = 1;
+        }
+        if ($ruleok) {
+            $newvalues->{$rule} = $env{'form.'.$prefix.'_'.$rule};
+            if (exists($current->{$rule})) {
+                if ($newvalues->{$rule} ne $current->{$rule}) {
+                    $changes->{'rules'} = 1;
+                }
+            } elsif ($rule eq 'min') {
+                if ($staticdefaults{$rule} ne $newvalues->{$rule}) {
+                    $changes->{'rules'} = 1;
+                }
+            } else {
+                $changes->{'rules'} = 1;
+            }
+        } elsif (exists($current->{$rule})) {
+            $changes->{'rules'} = 1;
+        }
+    }
+    my @posschars = &Apache::loncommon::get_env_multiple('form.'.$prefix.'_chars');
+    my @chars;
+    foreach my $item (sort(@posschars)) {
+        if ($item =~ /^(uc|lc|num|spec)$/) {
+            push(@chars,$item);
+        }
+    }
+    $newvalues->{'chars'} = \@chars;
+    unless ($changes->{'rules'}) {
+        if (ref($current->{'chars'}) eq 'ARRAY') {
+            my @diffs = &Apache::loncommon::compare_arrays($current->{'chars'},\@chars);
+            if (@diffs > 0) {
+                $changes->{'rules'} = 1;
+            }
+        } else {
+            if (@chars > 0) {
+                $changes->{'rules'} = 1;
+            }
+        }
+    }
+    return;
+}
+
 sub modify_usercreation {
     my ($dom,%domconfig) = @_;
     my ($resulttext,%curr_usercreation,%changes,%authallowed,%cancreate,%save_usercreate);
@@ -15522,8 +17419,9 @@ sub modify_coursedefaults {
                            'uselcmath'       => 'on',
                            'usejsme'         => 'on',
                            'inline_chem'     => 'on',
+                           'ltiauth'         => 'off',
                          );
-    my @toggles = ('uselcmath','usejsme','inline_chem');
+    my @toggles = ('uselcmath','usejsme','inline_chem','ltiauth');
     my @numbers = ('anonsurvey_threshold','uploadquota_official','uploadquota_unofficial',
                    'uploadquota_community','uploadquota_textbook','mysqltables_official',
                    'mysqltables_unofficial','mysqltables_community','mysqltables_textbook');
@@ -15733,8 +17631,8 @@ sub modify_coursedefaults {
             if (($changes{'uploadquota'}) || ($changes{'postsubmit'}) ||
                 ($changes{'coursecredits'}) || ($changes{'uselcmath'}) || ($changes{'usejsme'}) ||
                 ($changes{'canclone'}) || ($changes{'mysqltables'}) || ($changes{'texengine'}) ||
-                ($changes{'inline_chem'})) {
-                foreach my $item ('uselcmath','usejsme','inline_chem','texengine') {
+                ($changes{'inline_chem'}) || ($changes{'ltiauth'})) {
+                foreach my $item ('uselcmath','usejsme','inline_chem','texengine','ltiauth') {
                     if ($changes{$item}) {
                         $domdefaults{$item}=$defaultshash{'coursedefaults'}{$item};
                     }
@@ -15899,6 +17797,12 @@ sub modify_coursedefaults {
                     } else {
                         $resulttext .= '<li>'.&mt('By default, only course owner and coordinators may clone a course.').'</li>';
                     }
+                } elsif ($item eq 'ltiauth') {
+                    if ($env{'form.'.$item} eq '1') {
+                        $resulttext .= '<li>'.&mt('LTI launch of deep-linked URL need not require re-authentication').'</li>';
+                    } else {
+                        $resulttext .= '<li>'.&mt('LTI launch of deep-linked URL will require re-authentication').'</li>';
+                    }
                 }
             }
             $resulttext .= '</ul>';
@@ -16370,7 +18274,7 @@ sub modify_wafproxy {
                 }
             }
             $output = &mt('Changes were made to Web Application Firewall/Reverse Proxy').'<ul>';
-            foreach my $item ('alias','remoteip','ipheader','trusted','vpnint','vpnext','sslopt') {
+            foreach my $item ('alias','saml','remoteip','ipheader','trusted','vpnint','vpnext','sslopt') {
                 if ($changes{$item}) {
                     if ($item eq 'alias') {
                         my $numaliased = 0;
@@ -17098,8 +19002,13 @@ sub modify_loadbalancing {
                             }
                         }
                         if ($changes{'curr'}{$balancer}{'cookie'}) {
-                            $resulttext .= '<li>'.&mt('Load Balancer: [_1] -- cookie use enabled',
-                                                      $balancer).'</li>';
+                            if ($currcookies{$balancer}) {
+                                $resulttext .= '<li>'.&mt('Load Balancer: [_1] -- cookie use disabled',
+                                                          $balancer).'</li>';
+                            } else {
+                                $resulttext .= '<li>'.&mt('Load Balancer: [_1] -- cookie use enabled',
+                                                          $balancer).'</li>';
+                            }
                         }
                     }
                 }
@@ -17877,7 +19786,7 @@ sub devalidate_remote_domconfs {
     my %servers = &Apache::lonnet::internet_dom_servers($dom);
     my %thismachine;
     map { $thismachine{$_} = 1; } &Apache::lonnet::current_machine_ids();
-    my @posscached = ('domainconfig','domdefaults','usersessions',
+    my @posscached = ('domainconfig','domdefaults','ltitools','usersessions',
                       'directorysrch','passwdconf','cats','proxyalias','proxysaml',
                       'ipaccess');
     my %cache_by_lonhost;