-
Posts
354 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by AntonioRocco
-
@ZeroHour ". . . why is that they are the first to fall every year at pwn to own?" What does this mean exactly? I could be wrong AFAIK an exploit is not a virus. Besides you'd still have to have express permission of an admin account as well as root (assuming BSD injection). "what if, god forbid, there is an apple virus, how would you know if you dont have any protection" How can you be protected against something that does not exist yet? Like any A/V Software it can't protect you against something new. One of the widely respected articles regarding Viruses, Malware and exploits on the platform is here: Thomas' Corner: Mac Viruses There was another thread discussing this subject not long ago: http://www.edugeek.net/forums/mac/49152-sophos-10-6-a.html#post452209 Personally I have to agree with mrweekender. My 2p. Antonio Rocco (ACSA)
-
Hi Not sure if this fully answers your question but Apple's dedicated iPad Forum is here: Apple - Support - Discussions - iPad All of Apple's dedicated Forums are here: Apple - Support - Discussions - Forum Home Depending on what you want this Forum is an especially useful one: Apple - Support - Discussions - User Tips Library For that amount of iPads you may want to consider the iPhone Configuration Utility? Assuming you have not already done so? It's freely available from Apple and is designed to deploy and manage hundreds or thousands of iPhones, iPads and iPod Touches. You can install it on either platform. Antonio Rocco (ACSA)
-
Hi "I do still see it as a major flaw, even in an all OD environment, users will still have the ability to go to Finder's "Go > Network" option" Having done a fair number of these I can assure you in an all OD environment it really is not a 'flaw' or a problem. Create one for yourself and you'll soon see. "but also the Mac Server I have attached to the Network so I can't see how this relates to an Active Directory issue. Even with no permissions the users can still see the server" This is intentional and by design. Bonjour/Rendezvous is built-into every mac (Server or Client). It's how they announce themselves as well as discover other Bonjour-aware devices on a network. It's important to note the .local suffix has been reserved for Bonjour. None of this is a 'major flaw' as its all by design. Simply explained Bonjour allows non-technical users to connect multiple computers to a switch/hub and create an ad-hoc network that does not need a DHCP Server or anything else. This kind of of network is generally referred to as ZeroConfig or Link Local Addressing (LLA). It's where the self assigned IP addressing (169.224.x.x) reserved by the IANA for just this reason comes in. Bonjour is more than this and Apple provide an FAQ which explains things a little more: Bonjour: Frequently asked questions (FAQ) It's not advisable to turn Bonjour off as it's part of the DNS Resolution daemon mDNSResponder. In an all mac environment Apple utilise Bonjour and build into their Server product Services that auto-announce themselves (if the server is configured in this way) and present Service information to workstations that will then auto-configure themselves based on that information. As you'd expect this works very well. However for some environments it can be seen as being totally useless and a 'problem'. You should also be aware that NetBIOS discovery is also built-into the daemon. That's why your PCs are displaying themselves in the Sidebar. The Sidebar is all about Bonjour and NetBIOS and has nothing much to do with DNS or TCP/IP. Prior to 10.5 the Sidebar had a problem with Single Sign On (SSO). From what I've seen this appears to be 'fixed' in 10.6. If all you're using OSX Server for is to provide MCX then simply seeing it in the Sidebar does not present a problem. You can 'fix' this as HodgeHi suggests by applying the Simple Finder MCX. I think this level of control is fine for infant and some junior schools but for further education sites I find it too restrictive and can cause issues for users trying to browse to a share so their data can be saved. Again this depends to a certain degree on what you're trying to achieve. With respect if you took a step back for a moment and approached the platform on its own merits rather than obscuring it with a Microsoft eye none of the 'problems' you're seeing need be seen as such. My 2p. Antonio Rocco (ACSA)
-
Hi "It's a massive flaw in an otherwise excellent and simple OS!" If this was an all mac environment - Open Directory - it's not even an issue. Apple - quite rightly - assume everyone wants an all Mac environment. In which case there's no flaw that needs fixing. It's only a 'flaw' from your perspective and if you see it as such you'll have to deal with it in the best way you can. From what I've seen at most sites I've been to it's not an issue, but at some (admittedly few) they see it the same way as you. Oddly and slightly irrationally - IMO - it's viewed as a problem the mac platform has generated. Whereas in fact the 'open nature' of the AD structure itself is really at fault and the platform has simply exposed it. Provided the permissions are defined correctly all that can happen is users can 'see' the other PCs and go no further. It's purely cosmetic and should present no further issues. HodgeHi has already indicated how the SideBar can be controlled with an appropriate MCX. In 10.6 and AFAIK there is no way to remove the Network Selection from the Go Menu without breaking the OS in a major way. In 10.5 it was possible but had risks attached. To pre-empt what you might be thinking you can't install a version of the OS that is older than the OS version the hardware shipped with and that was pre-installed. You could contact Apple and submit a Feature Request. If enough people want it perhaps Apple may build it into the next OS? Apple - Mac OS X Server - Feedback Antonio Rocco (ACSA)
-
@qcomer Assuming I've understood what you mean by 'cached credentials' that's not strictly true. The built-in Active Directory plug-in allows the creation of a locally cached home folder. Either as a mobile account (ideal for laptops or workstations that can move from network to network) or by forcing the creation of a local home folder - similar in some ways to the mobile account option. There is still a further 3rd option depending on how you've configured the home folder path variable in Active Directory. None of these require anything 3rd-Party. The point about Active Directory environment utilising Distributed File Services is a good one. When developing 10.6 Apple 'touted' DFS/ZFS support as being a feature. It never materialised. Perhaps we may see it in 10.7? Extemez-IP is indeed extremely expensive but if your mac takeup is a large one then the cost is justified. If your mac takeup is minimal the latest version of AdmitMac (v5) does support it. The cost of it then becomes realistic although still exorbitant when you factor in the cost of the mac hardware in the first place. Another way of looking at this is to ask yourself what is it that the platform is going to give you that you can't already do or possibly achieve using what you already have? If the answer is nothing, stick with what you have. All too often macs are purchased on a whim or because there's a perception it's all there is. That is not necessarily so. Having said that the platform stacks up pretty well in my view taking all things into consideration. Assuming the AD environment has been configured appropriately it's an opportunity to show students and others how computers can be made to work effectively in a non-Microsoft way. Choice and an alternative way at looking at things are beneficial to all ultimately. My 2p. Antonio Rocco (ACSA)
-
Hi Have you tried Command+v? Simply to see if you can access single user mode at all. It's possible there's a problem with the top case/keyboard? Try the other Command key - the one to the right of the space bar. Just to be sure you are pressing the command key aren't you? This is the key with the half eaten apple logo on it. Some get confused and hold down the ctrl (control) key thinking they are holding down the command key. If you're still having a problem try a PRAM Reset. Command+alt+p+r at reboot. This will reset the unit back to its defaults. You should hear the boot chime. Do this three times then release the keys. Let it boot normally and restart. Try single user again. Alternatively connect a USB Keyboard and try that instead. Does not have to be a mac keyboard as any USB keyboard should work. Depending on the keyboard the Windows key usually doubles for the Command key. Antonio Rocco (ACSA)
-
Hi Have you enabled a Firmware Password by any chance? If you have follow the steps outlined in this KB Article: Setting up firmware password protection in Mac OS X Antonio Rocco (ACSA)
-
Hi "I used to use Entourage 2008 and my work email worked wonderfully via OWA" I'm sorry but this does not make sense? Entourage is a dedicated mail application. OWA - or if you like Outlook Web Access - is the User Interface you see when accessing your mailbox using a Browser. There should be no need to download anything to make Outlook 2011 work with Exchange Server. Assuming a properly configured Domain infrastructure it should just work. "The issue I run into is I do not know my incoming and outgoing mail servers nor will IT tell me" Perhaps someone needs to have a word in their shell like ears? There may be another way of finding out mail server names/IP addresses? In the location where you are would there be Users accessing their mail using Outlook on a PC? If yes look at their Account Settings as whatever mail server information they have listed would probably be what you need to use? I'm not absolutely certain but I doubt if access to these settings can be denied using a Policy? HTH? Antonio Rocco (ACSA)
-
@Chris_Cool @Tricky-Dicky You can indeed bind the macs to the AD Domain. But that's not the OP's question. What you can do is bind the Mac Server or a Client Workstation (with WorkGroup Manager installed) to the AD Domain. View the /Active Directory/All Domains node using WorkGroup Manager. Select all the Users and then select Export from the Server Menu. This effectively saves the User Base as it exists in AD. However it won't export passwords. Before importing into the LDAPv3 node you'd have to unbind from the AD Domain first. To export passwords you'd need to get creative with the command line on both the Windows and Mac Servers. Basically you'd export the relevant data - user names, short names, UIDs, passwords and home folder urls - from the PDC in LDIF format and import the same file into the LDAPv3 node on the Mac Server assuming you truly want a 'full' OD Master? IIRC Passenger can work with exported passwords from an Excel file. However if that's too much work simply define a Password Policy that forces users to change their password on next login. Instruct the users to define what they use on the PCs when prompted. Hopefully that should be enough? What you can't have is a mac server bound to AD viewing and reading the User Base as it exists on the Windows Server and simultaneously having the same users in the LDAPv3 node. That would not be allowed as the same users can't exist in two separate directory servers connected to each other. This would also apply to Groups. Antonio Rocco (ACSA)
-
Hi There are a number of ways of doing this. One way is to export your user base from AD. Or if ADMWin creates a tab-delimited, comma-separated or csv file use that instead. Purchase and Download Passenger from here: Passenger: The Mac Server Account Creation Utility It's well worth the money as it does more than just parse names etc. Antonio Rocco (ACSA)
-
Hi Mac OS X v10.6: Active Directory binding lost on network transition (.local domain) If your internal domain is not based around .local then simply unbinding-rebinding should be enough. The macs will use the mdns_responderer daemon to continually query your DNS Servers so as to resolve the Primary Domain Controller on both pointers. If there's a network disconnect for whatever reason the macs will give up the ghost after a short while and revert back to Bonjour/Rendezvous - which itself uses .local. Hopefully making the repairs to the physical structure of the network should get things back on track. You could use ARD and the dsconfigad command to unbind and rebind all of your macs at the same time. If you don't have the application and depending on how many macs you have you'll be looking at some leg exercise. Antonio Rocco (ACSA)
-
Hi From the information you've provided it's possible you've misconfigured the Base Station? Is it working in Bridge Mode? Are you uplinking it via ethernet to the main network? Which network port have you connected the ethernet cable to? Look at the icons beside the ethernet ports at the rear of the Base Station. They will tell you whether it's a WAN or LAN port. You don't want ethernet connected to the WAN port. Although this does depend on what you want to achieve? Antonio Rocco (ACSA)
-
Hi No errors here as far as I can see. If you click the "Click Here to login to HomeLink" you hit SSL Port 443 which requests a valid user name and password. Perhaps their's something else going on they're not telling you about or may not even be aware of? I've seen it before where occasionally overly paranoid parents may 'fiddle' with the Content Filter or Firewall in whatever they're using at their Network's edge without any real notion of what they're doing. I would not rule out the built-in OSX Firewall either. There may even be installed 3rd-Party Applications or Utilitys - such as Little Snitch for example - thrown into the mix? Don't rule out Parental Controls either. Unless you're prepared to go to the site or their's more information forthcoming it's going to be difficult to tell. Antonio Rocco (ACSA)
-
Hi If you select the Preference Manifest and select the Dock Policy you should be able to view the relevant keys. Or if you like the Policy. You can either edit the appropriate key or add a new one in the relevant area after applying an appropriate integer value. Look for the persistent-others key. If it's there you should see a series of items. There should be an equivalent number of them depending on how many folders you've defined for the right hand side of the Dock. This part of the Dock is divided from the rest of the Dock by a line that looks a little like the white lines down the middle of a road. Except they're horizontal. If you click the disclosure triangle by the side of Item 1 - for example - you should see a tile-data entry. Again click on the disclosure triangle and you should see further keys. One of them should say displayas. The integer value for a grid would be 0. For a stack it would be 1. Alter as the value as seem appropriate to you and test. If you don't see anything like this then you should be able to add a key by selecting the New Key button. This is quite involved as you're adding keys to keys. Although if you're having to do this then there's something not quite right somewhere? Assuming I've understood you correctly customising My Applications should be fairly straightforward. Think of it as a symlink that 'points' itself to the top level Applications folder. You may not know this but you can create an Applications folder in the local admin's Home folder. Use the terminal command "mv" to move applications you don't want Users to have access to from the top level Applications folder to the newly created Applications folder in the local admin's home folder. Using this method you're achieving two things. You're controlling what other users -who are not the local admin - have access to and yet you're still allowing the local admin access to those applications. This is especially useful for applications such as Terminal, Console, Network Utility etc. IMO the above is actually a better way of managing access to applications rather than using WorkGroup Manager. This aspect of WorkGroup Manager I find slightly disappointing. If you have ARD - assuming all the workstations have the same local admin account - you can use the "mkdir" command to create the Applications folder in the relevant area as well as using the "mv" command afterwards. You can easily do this for all your workstations. Yet another approach would be to create your netboot image with those changes having already been made. Antonio Rocco (ACSA)
-
Hi It seems to me your question is about user/network usage and has nothing to do with Bootcamp per se. Whatever monitoring tools you're using on the Windows side should work. You are running Windows 'Bare Metal' after all. For OSX you can either 'roll your own' utility or use a command line utility such as 'last' or probably better still use ARD's User History Report feature. Assuming you have it? More on ARD here: Apple - Remote Desktop 3 - Resources Watch the Tutorial. It's possible 3rd-Party Utilities such as Splunk might be of further use? Splunk | IT Search for Log Management, Operations, Security and Compliance Antonio Rocco (ACSA)
-
Hi Assuming all your macs are switched on and have been added to ARD. Insert the iWorks Disk into the optical drive of the workstation that has ARD installed. Launch ARD and select all the macs from the computers list. Click on the Install icon. From the resulting window click the '+' icon. Navigate to the iWorks installer Disk. Select the iWorks installer pkg. Select all the Computers. Click Install. The 101 Course is the Support Essentials Course for the Client OS and won't necessarily cover ARD. I doubt if it will be even mentioned TBH? I don't even think it's mentioned on the Server Support Course (202) Course either? I could be wrong though. The ARD Installer Disk should contain the Admin/User Guide for ARD in pdf format. There is an ARD Resources area on Apple's website here: Apple - Remote Desktop 3 - Resources Watch the video tutorial as it will go through in detail the instructions I've given earlier on. There are further links you can click on that will outline what the application is about as well as what you can do with it. Further to this you can always search/browse the relevant ARD User-to-User Forum itself: Apple - Support - Discussions - Apple Remote Desktop It's been a while but AFAIK there are no specific structured courses for ARD. Leastways I've never seen any so far apart from the video tutorial. Apple freely make available for download Administration Manuals for all OSX Server's Services form here: Apple - Support - Manuals If all you want is AD-OD Integration with OSX Server augmenting Active Directory with mac-style GPOs the manual most relevant to you might probably be this one: http://manuals.info.apple.com/en_US/UserMgmt_v10.6.pdf Antonio Rocco (ACSA)
-
Inconsistent startup times to get to "Network Account Available"
AntonioRocco replied to chrisjako's topic in Mac
Hi Read all of the posts in this thread: http://www.edugeek.net/forums/mac/15199-active-directory-authentication-how.html It's the sticky at the top of the Forum. Antonio Rocco (ACSA) -
How to relocate mac library files onto another server?
AntonioRocco replied to wayneeaton's topic in Mac
Hi Unlike Windows one of the requirements for successful login on any Mac workstation (server or client) is the ability to not only create or access an already created home folder but also the ability to create or access (as a minimum) the Desktop and Library folders. If you move the Library folder into another container elsewhere and you don't change the home folder path in the Users AD Profile then the next time that user logs in the Library folder will be recreated again. Basically you're achieving nothing other than duplicating the Library folder as well as using up space you may - probably - never use again? If you change the path to reflect the change of Library location then when the user next logs in (assuming a home folder container) the rest of the folders will be created that are still in the original home folder. Again you're achieving nothing other than duplication. Although there are other ways of doing this I have a feeling your question is really about 'redirection' for possibly performance reasons? There are plenty of threads on this Forum and elsewhere that discuss how to achieve this. On Apple's website there may still be 'training' videos (and downloadable manuals in pdf format) you can watch that outline how to achieve this. You could also Google for John de Troye's (one of Apple's Senior Software Engineers) Tips & Tricks where Home Folder Redirection is discussed in great detail. If you have 10.6 Client Workstations you really should consider 'upgrading' the server to 10.5 or better - assuming Intel hardware? Antonio Rocco (ACSA) -
Hi Try: sudo mount_smbfs //$usrname@servername/home$/$usrname$ Antonio Rocco (ACSA)
-
@Carter Unless it's a typo it does not look like you've commented out the first line in your script. Antonio Rocco (ACSA)
-
@salinpoo If I've understood you correctly why don't you use WorkGroup Manager to achieve this? You can specify a policy to auto-mount shares at a login time by installing WorkGroup Manager on a client workstation. Use Connect to Server from the Go Menu and try to use the IP Address of the Samba share as it tends to be more reliable. There are threads that have covered this already. @Carter If you need to issue a command or login to a shell using root you really should be using any one of these: sudo -s sudo su sudo su - My personal preference is "sudo -s" however it's your choice. You could refer to the relevant manual pages if you wish: Loading… Loading… Loading… All of Apple's Manual Pages for Server and Client OS are listed here: Loading… If you want a paper copy this command will create a pdf of a desired manual and save it to your desktop: man -t binaryofyourchoice | pstopdf -i -o ~/Desktop/dscl.pdf Where binaryofyourchoice could be sudo, su, dscl and so-on. If you want to see all the binaries (commands) installed simply launch Terminal and hold down the escape (esc) key. After a few seconds you should see "Display all xxxx possibilities? (y or n)." Simply type y and you'll see all the binaries listed. Depending on which OS you have the figure listed will be either more or less. Ironic that I end the previous sentence with more and less as these are two commands that are often used. Antonio Rocco (ACSA)
-
Hi You'll be fine selling these units onwards with the original Tiger Installer Disk as well as the upgrade disk. Most people looking to purchase a second-hand machine like this would have an expectation that this would be the case. Most people who interest themselves in the mac second-hand market would recommend this as 'best practice'. It makes sense anyway as there will be less come-back on you if a problem develops later on that involves a reinstall of the OS. Besides the Leopard Disks will not be of much use to you with anything you've since purchased that came installed with an OS later than the one specified on the Disk. As a just-in-case you could create a .dmg from any one of those Disks and simply store it. You can always burn a copy (or as many as you like) to DVD (DL) in case you ever needed it again. Additionally you could create an nbi of the Installer Disk and make it available to your network via NetBoot. Antonio Rocco (ACSA)
-
Hi " . . . as standard the discs come with no RAID configured which is a bit silly for a server" Originally the MacMini "Server" came with both drives configured as a RAID 1 (Mirror). You don't need to do anything Linux as the built in Disk Utility will configure a Software RAID 0 or 1 for you. Most people would say the 'target' market for the MacMini Server is probably small corporate environments and/or businesses. The original configuration did not suit most people interested in utilizing the MacMini as their Small Business Server. Apple changed the configuration to two single drives as a result of 'feeback' from interested parties. Most wanted to use TimeMachine to 'backup' the System/Data drive to another drive. Most did not realise you could connect an external drive and use that instead. Makes more sense anyway. Additionally OSX Server in certain configurations is 'by design' meant to be an easier introduction to servers than what was and is used for more Advanced Configurations/Setups. Apple's Marketing's tag line at the time was "No IT required." As far as I know it still is? It's hard to imagine this Simpler Configuration/Setup being seriously considered when contemplating AD-OD Integration? Another way of looking at this is to utilize the two drive configuration in a slightly different way. You could download CarbonCopyCloner and configure a scheduled 'staggered' backup of the boot drive. For example every 2 days or a week or a time frame that suits. This can be useful as there is no restore on the platform. For example if you run Software Update and the latest patch or security update causes problems for what was a working server prior to the update you can easily rollback to a previous working state. I do agree with you though. It's silly to not configure at least a RAID Mirror for a Server. But I would not really describe the MacMini as a server. There's no redundancy for a start. You have to bastardize the power connector to work with a UPS and it's not the easiest thing to get into if there's a component failure. If you want a 'true' mac server you have to go with an XServe or a MacPro. If budget is the prime consideration and if all it's being asked to do is push out MCX a MacMini is a good alternative. As long as you're aware of its 'limitations' it will do the job. My 2p. Antonio Rocco (ACSA)
-
Got an imac with Snow Leopard OS which I want to join to AD
AntonioRocco replied to Muddyfox's topic in Mac
Hi Just your name and password will do. Was internet a crawl prior to you joining the domain? Would this be with Safari by any chance? Have you tried browsing with Firefox instead? Antonio Rocco (ACSA) -
Hi Ranj You actually don't need to use the command line if you don't want to as what you're asking for can be easily achieved using the interface. If you want to clear space yet still keep the same User Base then simply delete (or backup if you still need them?) home folders you're not interested in any more. Launch WorkGroup Manager and authenticate to the LDAP node. Select all the Users - apart from Directory Administrator - click on the Home Tab. Select the appropriate url. Click Create Home Folder now and click Save. Navigate to the relevant folder in the Finder and watch it populate with fresh, new home folders which should have User shortnames as the name of the folder. Each folder should have the default set of folders normally associated with a mac home folder. No need to fiddle with permissions either as these will be 'set' at their defaults as the folders are created. If you want to use Terminal, issuing this command: sudo createhomedir -a does the same thing only quicker. Antonio Rocco (ACSA)
