Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. Are the older versions actually causing a problem?
  2. Acrobat and Java are ideal candidates for GPO installation (as both are MSI based). When you tried this method, did you check the event logs for errors (on the workstations). If you got a message like 'installation source not available', it's possibly to do with the permissions on your central installation share point. You need to give 'authenticated users' RX permissions to all the folders and files that will be accessed during the install (including any parent folders up to and including the folder that is actually shared).
  3. @ric: Would you care to document the usage of DELPROF in the WIKI?
  4. This is a bit sad.... How about getting some EduGeek baseball caps with the new logo on them. Those of us going to BETT to could then congrigate in the bar and laugh at each other?!? I for one would pay quite literally several pence for one of these!
  5. Do you have HP Web JetAdmin installed on your servers at all, and if so, do you have Sophos as well. This caused me a problem recently on a 2K3 server. Disabling the Web JetAdmin service brought things back into line.
  6. @Dos_Box: I like that idea. WSUS on a virtual machine. Presumably you could use the VMWare player to run it on...
  7. @DB: Thanks. I have added a note to your note to mention that the problems described can be avoided by using redirected folders to store documents and desktop on the server and setting a limit on profile size.
  8. Are you Win2K or Win2K3? On my Win2K systems, BINLSVC logs on as local system account. Have you looked in the event logs for messages from the service? If you are Win2K, you could try running RIS in debug mode (http://support.microsoft.com/kb/q236033/) this gives you a console screen explaining what is happening. Is your RIS server also a DHCP server? There was a bug in Win2K whereby if the DHCP server service was installed on the RIS server, it had to be the active DHCP server, but the symptoms were different.
  9. The WIKI pages on User Profiles are at a stage where I would invite comments from those of you who are interested or have opinions on the way user profiles can or should be managed. I hope we can get the basic content to a level whereby it addresses the most common questions about profiles, but I'm sure it will need lots of changes first. My thanks to mark and sahmeepee for getting it all started.
  10. 'pologies free42536734. As an EduGeek member you clearly don't fall into the stupid category.
  11. Could he be referring to Windows XP Media Center edition?
  12. @free4440273: Ghosting is 'evil' and only for stoopid peepul (sorry, couldn't help myself) also, Maybe, just maybe all his machines are not exactly the same???!?!? or don't have the same software...
  13. 1 - You should never attempt to (or really need to) repackage a decent MSI file. It is possible, but 99% of the time it's not necessary. 2 - You don't need to supply any switches. If you assign the software to PCs, the install will automatically be silent. 3 - If you need to customize the installation (you don't for the Flash MSI. I use it myself and it just works), then you would use something like Install Tailor from Wise, or ORCA, to produce a transform file (.MST) which customizes certain properties. Having said all of that, there are SOME Windows Installer format files which have custom actions that require user input (thanks a lot RM), but these can often be disabled by producing a transform file which modifies the InstallExecuteSequence.
  14. Cheers Mark, I've chilled out a bit since last night. Sorry if I came over like a bit of a t**t.
  15. As it is an MSI file, you can deploy it using Group Policy Software Installation policy. Assign it to all the PCs you want.
  16. I would heartily reccomend the use of Virtual PC (or VMWare) for test environments. As long as you have a good PC (P4 2.8GHz with 1Gb RAM), you can simulate a server and two PCs running simultaneously in total isolation (or with limited network access)
  17. @mark: Whoa there! I think you're going to start a civil war. When I suggested a wiki, I was thinking more along the lines of something explaining the following; - what a profile actually is and why it is necessary (you CAN'T not have profiles, it's impossible) - the different types of profile available (temporary, local, mandatory, roaming) - pros/cons of each profile type then and only then - suggestions on suitability of each profile type to particular environments I'm only mildly interested in how other people take care of their profiles, I know what works for me. I wanted to help those who come to EduGeek looking for answers, who perhaps don't have the same experience or understanding of profiles that some members do. I'm a bit worried that all we are doing with the current wiki format (which looks a bit confrontational) is moving the debate from the forum to the wiki pages. Beginning to wish I'd kept my gob shut about the whole damn thing
  18. That's OK Ric, always happy to talk about profiles!! Basically the answer to your question is two things; 1 - User registry (HKEY_CURRENT_USER) which is stored in the NTUSER.MAN file. Some apps need settings present to work correctly. 2 - Application Data folder. Again, some apps need files here to work correctly. Before you (or anyone else) says it, yes I know I could keep these things in the Default User profiles (either at domain or worktation level), but I prefer to keep those as clean as possible. Also, every time you make a change to a Defau;t User profile, the render all existing profiles out of date. That means they have to be deleted and recreated (doable by script, I know). Using the mandatory profile means I don't have to worry about getting rid of any local profiles from PCs. As others have pointed out, it's horses for courses, but It seems to me that not using Mandatory profiles (a mechanism specifically designed for managing locked down environments) and having to fart about with scripts to delete profiles makes life a lot more complicated. A final point is that it is possible to have as many or as few different Mandatory profiles as are required. There is only one domain level Default User profile (or only one per PC). I can configure different Mandatory Profiles for different year groups if necessary. Hope this answers your question. Incidentaly, these are the sort of questions that led me to suggest the creation of a WIKI to draw together everyone's experience and knowledge of what profiles/roaming/mandatory/temporary are, how they work and how they can be used.
  19. @kingswood: If you need technical help on SIMS, there are also some very knowledgable (but independant) people on the official SIMS SupportNet site (http://www.capitaes.co.uk) in the 'Technical' forum. You'll need a logon, but I think it's quite easy to get one. I work for an LEA support unit so have had a logon for a long time. If you try to get a logon and get nowhere, let me know and I'll see what I can find out.
  20. @Geoff: Yup, tried the fix mentioned in the MS article. All the processes mentioned (that were present on the PCs) were already running as shared processes. Until the problem happens again though I can't check the event logs to look for service startup order. Thanks for the suggestions though.
  21. There's quite a lot that you can do in Ranger that you can't do with AD. - Good security features e.g. block certain dialog boxes in applications to prevent certain features from working - Security violation logging - Reporting of network activity - Reporting of user activity - License control
  22. Would Process Explorer from SysInternals be of any use?
  23. I've rebuilt all the affected PCs, and they now seem to be OK. The exact error was: Event Type: Error Event Source: Kerberos Event Category: None Event ID: 7 User: N/A Description: The Kerberos subsystem encountered a PAC verification failure. This indicates that the PAC from the client ICTSUITE-01$ in realm HB-CURRIC.INT had a PAC which failed to verify or was modified. Contact your system administrator. Data: 0000: c0000192
  24. Last week I was installing a new 2003 server and 30 odd PCs. I had set up a new domain (in an existing forest), created RIS builds and assigned my usual policies to hook it all up. Everything seemed to be working fine, but when I came in this morning, one by one, the PCs lost their group policy settings (firewall, security, software, you name it - it went). The only thing that I could find that might explain it is a Kerberos error in the PCs' system logs. Something to do with the computer account, authentication verification and a PAC ?!? I have rebuilt a few PCs and these appear to be OK so far. Has anyone had anything like this before?
  25. @Dos_Box: Basically, it comes down to what is in the user portion of the registry. If a user does not have roaming profiles, these settings are held uniquely on each PC. A roaming profile lets these settings follow the user from PC to PC. Everything else can be taken care of with a combination of redirected folders and heavily managed 'default user' profiles. The main reason for me starting this thread is that every time a user asks a question about profiles, everyone dives in with their own opinions about which is the best way to do it and how 'evil' roaming profiles are. I just want to try to formalise some kind of collective recommendations on what profiles are and the different ways of managing them. Do you want to help people or brainwash them into doing everything the same way?
×
×
  • Create New...