Jump to content

AntonioRocco

Members
  • Posts

    354
  • Joined

  • Last visited

Everything posted by AntonioRocco

  1. If the users are in your Active Directory database you won't find this out via Profile Manager/OD which means using the Server.App is of no real use to you. 'Best' place to look is locally on the macs themselves (which you don't have) but if you did or if you've enabled SSH or Remote Management you can issue "last" (without the quotes) from the command line which will give you the login history for that device.
  2. There are a number of options you could use depending on what deployment methods you have. This link provides a further option that might help you more at the stage you're at now: https://derflounder.wordpress.com/2016/09/20/blocking-siri-on-macos-sierra/
  3. Don't give up just yet as the problem may be easily fixed as well as being not that expensive? I've seen similar issues to what you're reporting being down to a failed/failing GPU and/or display? Nothing will show on the display no matter what you do with the keyboard or anything else. If you've reset the PRAM and you're not getting a boot chime then odds favour a failing/failed GPU. If you are getting the boot chime probably the display. I think on those models you could attach an external thunderbolt display or SVGA display using either a thunderbolt cable or thunderbolt to SVGA/DVI adapter assuming the display supports both connection types. If you've got some of that gear handy it's worth one last shot. If it works then you're not looking at replacing the iMac itself only the failed part which is going to be your cheapest option. Hope this helps. Antonio Rocco (ACSA)
  4. With the Photos app launched, click on the View Menu and select Show Sidebar. In the sidebar you should see a Videos option. Photos app helpfully collates all the videos you've imported in one place so as you can view them all. I'm guessing this is what you mean? You can see geolocation information by selecting a video or photo and selecting Info from the Window Menu. Command + I will do the same thing. With multiple selections you get to see pin markers on a map which you can zoom into for a more precise location. Is this what you mean also? Antonio Rocco (ACSA)
  5. Quick question: Does the image you already have work fine with the existing Mac estate? If it does then I'm guessing the iMac is a newer model? If it is the image created by RM won't work as it will have an older OS that can't boot the newer hardware. Either you or RM will need to create a new image to boot the newer model. This could involve a lot of work on your part, depending on how the workflow was planned, simply to accommodate one iMac A few (fairly loose) 'rule of thumbs' you should be aware when dealing with mac hardware: (a) Newer models won't boot with whatever works with older models (b) There are variations between laptop and desktop models which may require different images © Try and use a *thin image when planning the deployment solution. Hopefully (but doubtful) the RM guys may have done this already? The above are just a few. *By thin image I mean just the OS and very little else. That way you only need to update and/or upgrade an existing mac to a later OS, recapture that image and make it part of a workflow that should now work with your newer hardware. Hopefully this may help you although it may turn out to be something network related instead? Tony
  6. I'm guessing you're using a Windows Server to provide the DHCP (and presumably DNS) service? If that's true then remove all references in the rDNS section of the DNS service for that server apart from the one it should be. I would also amend the "scavenge stale addresses" setting to a lower value so as the potential problem does not build up again in the future. Seems odd that there should be multiple rDNS entries for it unless, at some time in the past, the server had been misconfigured in some way or it had been given a dynamic address instead a static one? Thinking about it this is probably the case now? Which would not be surprising as well as alarming. All servers in any network offering resources to workstations should be assigned static IP addresses at the very least as well as valid host names that resolve on both the forward and reverse pointers. There should be no ambiguity with DNS at all when it comes to servers. Just trying to get a sense of what your environment is like so I have some questions: Is this an AD environment with home folders for all users specified in AD? Or is their another folder, stored on the mac server that the user accesses which is not their real (Windows) home folder? Am I right in thinking your DC is providing DHCP and DNS? Antonio Rocco (ACSA)
  7. A number of things this could be from reading your post. Time and/or DNS and/or permissions or a combination of all three? To check DNS log on as the local admin on the affected Mac, launch Terminal and issue this command: host server.orchard.lan It should return that server's IP address. Then check its rDNS by issuing this command: host xxx.xxx.xxx.xxx Which should return its fully qualified domain name. If both of the above checks out OK move onto checking the permissions (yes I know you've done this but double-check all the same) of that person's home folder. These should POSIX permission by default on the top level folder which should be named the users short name. For example: asmith. POSIX permission for this folder should be: owner:asmith R/W group:staff R/O everyone: R/O Drill down to the next level and everything should be no access apart from the owner which should be the same as the top level folder. I say time because if these macs (including the mac server) are in an Active Directory environment they should not be using Apple's NTP server for their time. Apple's time servers are not great at keeping regular time. I would use your DC for time which is what Apple recommends anyway. StaffHomes should be the share and this should R/O for everyone. The other possibility is corruption in that users Library folder. You can clear out the whole of the Library folder (including itself) and try for a login again. The folder should be recreated on successful login. If this is a managed user there'd be nothing in the Library folder that's of any use anyway although I would keep a copy of at least the Preferences folder just in case. Hopefully the above might help? Antonio Rocco (ACSA)
  8. 've seen similar issues to what you've described at other sites. Installation of PaperCut was carried out by an external contractor who had set it up in the time honoured way they'd always set things up - namely for Windows. They did not realise or bothered to find out (take your pick) that the default PPD (page description language) for Macs is PostScript. Setting up a PostScript Printer Queues on the PaperCut Server fixed the 'problem'. Might be something you've already tried but it's worth checking. Hopefully this might help? Antonio Rocco (ACSA)
  9. Not sure what's happening based on what you've presented? You say the iPads enrol fine but only as placeholders and the MacBooks do the same but not as placeholders. Presumably from there you can 'push/pull' a management profile fine to the MacBooks but not the iPads? "I wonder if the iPads need a different port opening on the firewall . . .?" Perhaps? These are the ports PM needs: https://support.apple.com/en-gb/HT202487 Note port 5223. APNs is short for Apple Push Notification. This will be a set of external servers. Apple's APNS is the 'go-between' for your local server and clients, wherever they may be. Basically PM is checked in first with APNS. You should have received an email from Apple notifying you what services have been registered. You should be looking for something that looks like this: apps:apple.com.mgmt. After device enrolment, the devices check with APNS that your server is what it purports to be. Trust is established on enrolment. From there the devices 'accept' the management profile from your local server over-the-air. Things to check will be the usual suspects which you say you've already checked. DNS is absolutely crucial as is the choice of domain name suffix. DNS should properly resolve on forward and reverse pointers and .local should not be used. Of course check your Wi-Fi network is robust enough (no dead-spots wherever possible) and coverage is as good as your institution can afford. I would also make sure there's nothing 'blocking' internal traffic. You never know there may be a legacy network device that hasn't been touched in a while that's interfering in some way? There are many articles available on the web regarding PM and this one from MacWorld is quite thorough and should, hopefully, help? A primer in Profile Manager | Macworld My own preference for managing iDevices (iPads, iPhones, iPods) is to use PM and Apple Configurator combined. PM is OK so far (hopefully it will improve further) and as an MDM is good value for money. Configurator is free. However PM is not the best available IMO. Depending on the numbers involved and what you want to achieve you may want to look at AirWatch, JAMF's Casper Suite and possibly Mobile Iron. There's also a good case to be made for Cisco's System Manager (Meraki). Antonio Rocco (ASP)
  10. Thinking about this it should be possible provided whatever the mac is using for DNS can fully resolve all the domains involved? Ideally you should not be using .local on any of the domains. By default any mac bound to Active Directory will allow authentication from any domain in a forest. The domains themselves should already have a trust relationship established and simply binding to one domain should allow users on all domains to login on that mac. This Microsoft TechNet article might help? https://technet.microsoft.com/en-us/library/cc773178(v=ws.10).aspx You could try entering UNVERSITY/USER (note the forward slash) at the login window and this may be enough for the authenticating server for the forest to allow a successful login? What does the system.log say when you compare a successful login on one domain with failed logins on the other two? Unlike PCs you can bind a Mac to multiple domains. Identification, authentication and authorisation is usually handled by the authenticating server in topmost domain listed in Directory Utility's search order. If you bind the Mac to Domain A followed by Domain B and Domain C these should then be listed second and third. When a user presents their credentials at the login window, the authenticating server for Domain A will search their database and if that user does not exist, Domain B's authenticating server should then search their database etc and so-on. When the user is found and provided the three authenticating servers trust each other a successful login should then happen. That's the theory and how and if it works will depend greatly on how well it's been configured (sounds like it has been otherwise your PCs would be behaving the same way?). As ever your mileage may vary. Hopefully their may be others who have a similar situation who might help further? Antonio Rocco (ACSA)
  11. No need to use Automator simply run the command using ARD's "Send UNIX Command" feature to selected computers. You must always run commands as root. If you don't have ARD then seriously consider buying it - it's cheap anyway - as it forms one of the cornerstones of "Mac Management". Assuming you don't know what ARD is, I mean the administration part of Apple Remote Desktop that's part of the OS and built into every mac. More about ARD Admin here: Remote Desktop 3 - Apple (UK) Antonio Rocco (ACSA)
  12. You don't need to boot into DeployStudio to create a network bootloader OS for that model iMac. Install DeployStudio on that particular Mac and create one afresh. When done upload the resulting nbi to the Server's NetBootSP0 folder; enable it in the NetInstall service; uninstall DeployStudio on that iMac and, hopefully, it should boot without crashing? I could be wrong but the kernel panic screenshot does look like an incompatible hardware issue with the bootloading OS that Mac is trying to use? What is strange is you should be able to use the nbi created from your latest hardware to boot all your other hardware. But if your latest hardware is, for example, the latest model iMac and you created an nbi immediately after taking it out of the box then that may cause a problem for older hardware? Without being there it's difficult to help further but creating a hardware specific nbi for that model iMac may at least get you further than the point you're at now? Antonio Rocco (ACSA)
  13. AntonioRocco

    VPP Help

    Try a different browser and/or disable (temporarily) the proxy/web filter (if access to the internet still works without its use) and/or whatever you're using for blocking pop-ups, malware etc. Try it on a Mac instead, who knows you may get to the page it keeps looping you out of? Antonio Rocco (ACSA)
  14. Not sure why it's not working as .pac files work for me regardless of OS. Maybe there's a problem elsewhere? If yours is an IPv4 network (probably is) disable IPv6 on the affected macs and of course make sure DNS is fully resolving properly on both pointers for the server serving the file. Obviously stay clear of .local for your TLD suffix as OS X (especially the later versions) tends to be even more 'sniffy' about this than it ever was. Hopefully none of this applies to you and without being there it's difficult to help further? In the meantime it may help your situation if you were to create an 'away from your network' location that has no .pac file configured. When away from the network that requires the file, advise/train/coach the user to change their location setting after booting up and logging in. Location settings can be made part of whatever deployment workflow you're using, either baked in or as a task sequence, or you could simply configure the settings using ARD. Assuming you don't know how to manually create a location using the GUI, click on System Preferences > Network > Location > Edit Locations and once created/configured the Locations option becomes available in the Apple Menu. Hope this helps? Antonio Rocco (ACSA)
  15. Apple keep a very tight rein on all parts made by (with or without their partners) and sourced by Apple only. Anything else is either a 3rd-party refurb, copy, fake or stolen. The potential upside of 'Apple' parts sourced from China is of course their cost. The potential downside is, if they fail, will they fail by themselves or will they cause another genuine Apple part to fail also? If that happens - and I've seen it happen - you're down the proverbial creek in more ways you can imagine and all because you want to cut costs. I'm all for cutting costs but not when it's going to cost you. My 2p. Antonio Rocco (ACMT)
  16. I think it's only fair to point out that parts claiming to be from Apple available on eBay from locations in China will almost certainly be fake, copies or stolen. You may think you're getting a 'deal' in the short term because of the cost but in reality you're only going to add to your problems sooner or later. Ultimately it's choice but if you're an employee what would be the reaction if something went drastically wrong and the problem was because of the parts you bought?
  17. @ shepherd ". . . just download it on the app store and can use it with as many macs as you want?" Yes. @ pete This used to be the case with non-App store version which came on installation media. The license was for 10 or unlimited users. The current version (3.8.1) available from the App Store has no such licensing any more and you can control as many client workstations as you like. The ARD Agent (the client bit of ARD) is part of the OS. The ARD available on the App Store is the administration software and leverages what is built into the OS. ARD by itself is fine but coupled together with OS X Server, Munki and DeployStudio makes one quarter of a powerful suite of software that goes a long way in managing your Apple estate. My 2p. Antonio Rocco (ACSA)
  18. "Something similar to GP as in a centralised script . . ." If I've understood correctly that's what I kind of do. I create a script that when ran installs the relevant files and reboots the workstations. Either 'baked-in' from the beginning or 'pushed' out using ARD or DeployStudio. In theory PM should do the 'pushing' reliably but as you've discovered it's not. Maybe the next update to El Capitan will introduce the reliability and robustness we expect? Otherwise we wait until this time next year for next OS. IMHO Apple are 'dumbing' down their Server product more and more and as a consequence it's becoming less and less 'enterprise'. Unless there's a change in direction at Apple I can't see it improving any time soon. Antonio Rocco (ACN)
  19. Hi Carter Not teaching granny to suck eggs and I'm probably confirming what you already do or have done, but I generally configure one mac with the required printers then copy the relevant files to the rest using ARD or DeployStudio. Usually done at the outset (or during school breaks) as part of a deploy studio deployment workflow or as and when using ARD. Tends to work well for me with little or no fuss. Antonio Rocco (ACN)
  20. WGM has never replicated. At least not in the sense I think you mean? You should really be using Profile Manager as WGM was deprecated at least two OSes ago even though it still works after a fashion. Basically it’s very old software and has been around since Jaguar (10.2) Server days. Management settings created on MacSRV001 will only apply to the Macs that are joined to it regardless of whether managed settings are applied at Group or Computer level. For the amount of Macs you have it’s not clear why you would need two mac servers? In a classic AD-OD integration all your users and home profiles would be on AD which would also do the authentication. In such an environment the only thing that would come from the Mac Server would be managed settings. Even if you had 100s of Macs one server would still be enough as there would very little data stored (property lists are not large) and the ‘load’ - such as it is - would be minimal. You can tell which server your clients are getting their preferences from by logging into a workstation and looking in System Preferences > Users & Groups > Login Options. Click on the lock and click the button by the side of Network Account Server. You’ll see the OD Master listed with either its fqdn or IP address. If all you see as you go around them all is MacSRV001 then what’s MacSRV002 doing other than being switched on? If you see some on one and some on another I have to ask why as there’s no real sense in administering two mac servers in this way when one would do the job easily. What you could use the second server for though is hardware redundancy. Target disk mode it to the first one and use CCC to clone it on a schedule. That way if your primary server goes down you can quickly swop the ethernet cable over, power down or disconnect it and power up/reboot the secondary which will then become the primary. You’re back up and running within a couple of minutes. Repair the 'old' primary when you can and use target disk mode again to make it the secondary. Antonio Rocco (ACSA)
  21. Spoofing MAC addresses in OS X (and probably Windows) requires administrator privileges with root access as well as an understanding of the command line. I'm not saying it's impossible but seeing as students in most educational institutions log on as network users with no admin privileges by default then I doubt if they could do it even if they knew how to. Antonio Rocco (ACSA)
  22. You could use the asterisk wildcard. Something like this: sudo rm -Rf /The Volume Name/The name of the share containing all the student home folders/*/Library/Keychains/* Should save you having to visit each individual folder? But before doing any of this some words of caution! The ‘rm’ command is a very dangerous command to use in the wrong hands and before using it take appropriate precautions first. Such as: (1) making sure you have a fully working backup of all the data first, (by fully working I mean do a test restore) (2) making sure you test the above on at least a handful of test accounts you don’t particularly care about (3) so as you don’t get ‘lost’ it might be best to navigate to the desired directory first For example: if the volume name is 'NAS Drive' and the share/folder name containing all the student home folders is named 'Year 12'. cd /NAS\ Drive/Year\ 12 Followed by a carriage return followed by: sudo rm -Rf /*/Library/Keychains/* The first wildcard is for the student's name and the second one is for all of the contents of the Keychains folder. Obviously don’t blame me if you get this wrong! Try to have at least more than one back-up in case the first one goes bad for some inexplicable reason. NB: When using the sudo command you must key in the administrator's password which you won't see being typed. Antonio Rocco (ACP)
  23. The symptoms you're describing sounds very much like a failing disk causing the OS to be unresponsive. If you've ran Disk Utility and says it can't repair the problem it means you either need to use a 'stronger' disk repair utility - such as DiskWarrior - or, if that fails, replace the disk. Probably replacing the disk will be the quicker option as DiskWarrior is another program you'll need to purchase? Of course you will also need to re-install the OS if you replace the disk. Installing the OS is another problem as Apple does not offer disk media anymore and you will need a recovery disk partition to reinstall from the Internet which you won't have with a new disk. Do you know of any schools nearby that already have macs that might help? Failing that take it to your nearest Apple Repair Centre and ask them to do the work for you. Antonio Rocco (ACSA)
  24. Has this ever worked and has it ever worked with networked accounts rather than locally cached ones? Something you can quickly try is re-indexing the loops. Click the Loops menu at the top of browser and choose the option. It should be the last one in the menu? If that works but you hear no sound then go back to the Audio preferences in Logic's Preferences Menu. Sometimes the preferences get mangled for no apparent reason - usually an update will do this - and need resetting. You can push out the preferences file using ARD or MUNKI or DeployStudio. Even SCCM will do this for you assuming you have the client installed? Beyond the above there may have been a problem when downloading the content from Apple's server farms? Some proxies don't cope too well with akamai.net. If you think this may be the case then try re-downloading them again, this time using a non-proxied mac. Re-distribute them using the method described with ARD. If none of the above works try creating a non-admin (Standard) local account on any of the macs that have the problem. Launch Logic, load the additional content and see if the problem persists. If it goes away then check your home folder permissions. If students home folders are nested within other folders and the root of the share is not the one immediately downstream of individual homes, ie: server//music/year1/students, with the share being music and not year1, then make sure students have at least read/list rights all the way to the year1 folder. If that solves it then make sure you delete the local non-admin test account afterwards. If the problem still persists then use a non-proxied mac (take one home for example) and try it again. Hopefully this may help? Antonio Rocco (ACSA)
  25. Some things to be aware of when using DeployStudio. All images uploaded over the network are stored in the Deploy Studio's tmp folder. If it's successful DS Runtime will move it to the Masters folder after a short while. How long? Depends on the size of the image. There must be enough free space on the hard drive you're capturing the image from otherwise it will fail. For example if the internal hard drive is 256GB in size and the amount of data being captured is 128GB in size image creation will fail. Looks like you've accounted for this but double-check just in case. Control-clicking on the hard drive icon and selecting 'Get Info' should give you the information you need. When installing DeployStudio on the client mac you're going to use to first: create the much smaller network bootable OS from and second: capture the image from, make sure you don't start the service as well as making sure you uninstall DeployStudio prior to capturing the image. Permissions. If the account you've created to administer DeployStudio Admin with does not have read/write access to the depository, image creation will fail. If you're using a proxy (most schools do) disable the setting on the server, assuming you've put those settings in. Hopefully this will help? Antonio Rocco (ACSA)
×
×
  • Create New...