-
Posts
13,543 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Geoff
-
http://www.edugeek.net/forums/edugeek-minecraft/182343-edugeek-minecraft-1-7-10-pack-details-3.html
-
I introduced my girlfriend to Dwarf Fortress. I'm now single. However, what about minecraft? We have a server remember and we're a friendly bunch.
-
Group Policy to prevent staff from installing software
Geoff replied to talksr's topic in Windows 10
The following Powershell will work $userToFind = $args[0] $administratorsAccount = Get-WmiObject Win32_Group -filter "LocalAccount=True AND SID='S-1-5-32-544'" $administratorQuery = "GroupComponent = `"Win32_Group.Domain='" + $administratorsAccount.Domain + "',NAME='" + $administratorsAccount.Name + "'`"" $user = Get-WmiObject Win32_GroupUser -filter $administratorQuery | select PartComponent |where {$_ -match $userToFind} $user -
If you have any unmanaged switches you cannot control end points access via those switches using 802.1X. If they don't support SNMP traps / config either then there's no easy way round this for a remote site. The only way you could do it is to have a seperate install of packetfence at the remote site doing Arp poision / dhcp /etc. I try to avoid that these days and stick to 802.1X. Therefore I would simply CYA and write up something to your boss / powers that be that the site does not support NAC due to the switches and that I recommend an upgrade of the infrastructure at that site (besides they must be pretty rubbish / old switches if they don't do 802.1X in this day and age).
- 4 replies
-
- hotspot
- packetfence
-
(and 2 more)
Tagged with:
-
If you have having an error with syncing updates today (Apr 2017 patch day for people from the future), uncheck upgrades in the classifications tab of Software Update Point Component Properties and try re-syncing.
-
You can export the share config from the registry and re-import it after you have setup the new server. https://support.microsoft.com/en-us/help/125996/saving-and-restoring-existing-windows-shares
-
[sccm 2012] Operating System Task Sequence not showing on Client
Geoff replied to Geoff's topic in O/S Deployment
Figured this out. Funny thing, I had PC 113700 on my desk and I had mistakenly put PC 117300 in the collection. So this was working fine, I just reimaged the wrong machine. Oops. -
Windows Accounts to work on Linux Servers
Geoff replied to McChikenhanger's topic in Windows Server 2012
I'm using sssd on Ubuntu 16.04.2 LTS. My sssd.conf looks like this: [nss] filter_groups = root filter_users = root, admin reconnection_retries = 3 [pam] reconnection_retries = 3 [sssd] config_file_version = 2 reconnection_retries = 3 sbus_timeout = 30 services = nss, pam domains = domain.co.uk [domain/domain.co.uk] #With this as false, a simple "getent passwd" for testing won't work. You must do getent passwd [email protected] enumerate = false cache_credentials = true case_sensitive = false id_provider = ldap access_provider = ldap auth_provider = krb5 chpass_provider = krb5 ldap_uri = ldaps://dc1.domain.co.uk,ldaps://dc2.domain.co.uk ldap_search_base = dc=domain,dc=co,dc=uk ldap_tls_cacert = /etc/ssl/certs/ca-certificates.crt #This parameter requires that the DC present a completely validated certificate chain. If you're testing or don't care, use 'allow' or 'never'. ldap_tls_reqcert = allow krb5_realm = DOMAIN.CO.UK dns_discovery_domain = DOMAIN.CO.UK ldap_schema = rfc2307bis ldap_access_order = expire ldap_account_expire_policy = ad ldap_force_upper_case_realm = true ldap_user_search_base = dc=domain,dc=co,dc=uk ldap_group_search_base = dc=domain,dc=co,dc=uk ldap_user_object_class = user ldap_user_name = sAMAccountName ldap_user_fullname = displayName ldap_user_home_directory = unixHomeDirectory ldap_user_principal = userPrincipalName ldap_group_object_class = group ldap_group_name = sAMAccountName #Bind credentials ldap_default_bind_dn = cn=~sssd,cn=Users,dc=domain,dc=co,dc=uk ldap_default_authtok = Secret Password Change the LDAP server names, the ldap search dn's, bind dn, bind password, kerberos realm and DNS domain to match your AD config. On the Windows AD side I have Services for Unix installed. So you get an extra tab in the AD properties for users / groups. You must configure these for the above config to work. You must also configure at least one group with NIS properties. If you don't do this, you'll have no shell and no primary unix group. You'll also discover once you have the above setup you don't have a home directory. use pam_mount with the following config: And you'll find you have a working home directory mapped to you windows user share (correct the path as appropriate for your environment). -
[sccm 2012] Operating System Task Sequence not showing on Client
Geoff posted a topic in O/S Deployment
I've pushed out an OS deploy task sequence to my test Win7 machine to upgrade it to Win10. Howver nothing is showing up in the Software Centre. I feel like I've missed something obvious. Any clues? -
I found using enderio is the least laggy option for pipes.
-
[sccm 2012] SCCM on 2008 R2 Server communicating with WSUS 4.0 on 2012 Server
Geoff replied to Geoff's topic in O/S Deployment
Yep, no dice :/ PublishApplication(9380D44D-DA80-48C3-97DE-C9C528F73A2D) failed with error System.InvalidOperationException: Publishing operation failed because the console and remote server versions do not match.~~ at Microsoft.UpdateServices.Internal.BaseApi.Publisher.LoadPackageMetadata(String sdpFile)~~ at Microsoft.UpdateServices.Internal.BaseApi.UpdateServer.GetPublisher(String sdpFile)~~ at Microsoft.SystemsManagementServer.WSUS.WSUSServer.PublishApplication(String sPackageId, String sSDPFile, String sCabFile) -
[sccm 2012] SCCM on 2008 R2 Server communicating with WSUS 4.0 on 2012 Server
Geoff replied to Geoff's topic in O/S Deployment
I'm trying a little experiment. I'm building a 2012 server with WSUS and making that the SUP. @sparkeh do you have a migration guide for what you did? -
I want to know if this is a working configuration. I need to use WSUS 4.0 to get my Windows 10 servicing working properly. If I install the WSUS 3.0 admin console on the 2008 R2 server will SCCM 2012 be able to manage the remote WSUS 4.0 install on the 2012 server properly (and thus mean the servicing works).
-
Googles time service is reliable if you only use it (not in a combination with other NTP servers) and that all OS and applications are aware of the time smearing (obviously something Google can support on its platform for itself). Standard *nix NTP can handle leap seconds just fine. https://www.eecis.udel.edu/~mills/leap.html In the case of Linux NTP doesn't have to do anything other than tell the kernel there is a leap second. It is handled by the OS rather than the daemon. (The issue in the past with Linux, e.g. in the Reddit case, is because you are not supposed to use the hires timer on a server).
-
time.google.com should not be used for production systems (Google said as much themselves). It's also not RFC compliant as it fudges leap seconds. https://github.com/systemd/systemd/issues/437
-
time.windows.com seems to be sending garbage to clients. ntpdate[32691]: ntpdate [email protected] Fri Apr 10 19:04:04 UTC 2015 (1) server 40.68.115.144, stratum 16, offset -0.335147, delay 0.03069 Confirmed by twitter: https://twitter.com/search?f=tweets&vertical=default&q=time.windows.com&src=typd I'd suggest using uk.pool.ntp.org on your DCs for time sync as a replacement. w32tm /config /syncfromflags:manual /manualpeerlist:"0.uk.pool.ntp.org 1.uk.pool.ntp.org 2.uk.pool.ntp.org 3.uk.pool.ntp.org"
-
Gov.uk advice: https://www.gov.uk/change-name-deed-poll/overview
-
[sccm 2012] Unable to promote pre-production client
Geoff replied to Geoff's topic in O/S Deployment
Makes sense. I was using the console on a client PC IIRC. There's a hotfix I can install to 1606 that includes a client patch so I can test it that way (then move to 1610 regardless). -
How do you implement it in SCCM? Desired Config Management isn't a thing anymore in 2012 R2?
-
[android] 4G Smartphone on a budget - Recommendations?
Geoff replied to Dos_Box's topic in Mobile Devices & Tablets
We were looking at the Samsung J3 and A5s for staff (They can get lost if they think we are shelling out for S7s), they are both very nice phones. The J3 is exactly 5". -
[android] 4G Smartphone on a budget - Recommendations?
Geoff replied to Dos_Box's topic in Mobile Devices & Tablets
Mum as a Moto G4. Completely happy with it. A child is likely want to play games on their phone though so performance is going to be a massive problem at ~£100 mark. -
[sccm 2012] Unable to promote pre-production client
Geoff replied to Geoff's topic in O/S Deployment
Decided to live dangerously and push 1606 straight out, thus side stepping the issue. -
I've been working through the in-console upgrades to SCCM 2012 R2 as it's something that'd been neglected and I need certain fixes and features installed for some planned work. However I hit a snag. I installed the KB3174008 client hotfix for 1602 and I decided to use the 'deploy to pre-production' option for the client hotfix and just use our 'IT Dept' collection to test it. https://docs.microsoft.com/en-us/sccm/core/clients/manage/upgrade/test-client-upgrades Here's my current situation: The snag is that I've come to promote the client to production and the option is greyed out. I have googled and there a couple of things that come up. I've tried both the suggestions listed: https://foxdeploy.com/2016/06/24/sccm-1602-unable-to-upgrade-client-solved/ Henk's blog: Unable to promote pre-production client in ConfigMgr Current Branch Any other ideas?
-
Linux users can use FUSE + Dislocker to open up Bitlocker encrypted drives. https://github.com/Aorimn/dislocker
-
Rather than reinventing the wheel I'd figure I'd check here first. Is anyone pushing UltraVNC (or any VNC really) out with SCCM? Ideally with AD intergrated Auth using the Powershell App Deployment toolkit? Although any old bat or vbscript will do. Failing that I'll DIY it and post it here when I'm done.
