Jump to content

AntonioRocco

Members
  • Posts

    354
  • Joined

  • Last visited

Everything posted by AntonioRocco

  1. Hi You're not the only one having problems with the 10.6.4 update even though SUS shows it as available and downloaded. Using the Software Update Service normally (ie without a dedicated SU Server) is OK. Flushing the sucatalog index as well as the relevant files does not change anything either. This won't be the first time this has happened and no doubt it won't be the last. As ever there's no 'official' word from Apple and there probably won't be? I remember the 10.6.2 update showing similar symptoms. The 10.5.6 update was the same. It did not 'sort' itself for about 2 weeks as I recall? An important thing you have to remember regarding Apple's SU Service is it requires a lot of patience on occasion. Not definitive in any way but generally when a major revision update is available, the 'packages' that are actually usable on a dedicated SU Server are about 2-3 weeks behind what is normally available at the time the revision was initially released. An alternative way of pushing this update out to all your clients is to manually download the update .dmg on a client/administrative workstation that has ARD installed. If you have ARD installed on your server that would do equally as well. You should be able to select all your client workstations and issue "softwareupdate -i -a" and select the .pkg for the update once you've mounted the .dmg. Antonio Rocco (ACSA)
  2. Hi Disable the Managed Setting and try it for a while. Does the problem go away? Antonio Rocco (ACSA)
  3. Hi Are you applying a Managed Setting for the Energy Saver settings by any chance? Antonio Rocco (ACSA)
  4. Hi "So how is this sorted out?" Nothing to be sorted. Bind the workstation to Active Directory. That's it. The platform has no requirement for a CAL let alone a Microsoft one. "Does the price of Mac OS X include a Windows CAL, then?" How can a Windows CAL work with any other operating system other than Windows? Additionally Apple does not support Windows. Apple do however provide an environment (via BootCamp) for anyone to install Windows OS if they wanted to. BootCamp is not the Windows OS. You would still need a licence to install Windows because once you go beyond the Mac OS the hardware is effectively a PC and you would treat the same as any other PC. Antonio Rocco (ACSA)
  5. Hello Shawn Apologies for not getting back to you yet. I've been very busy. You will get a response soon :-) Screen Sharing simply opens port 5900 AFAIK. TBH I never bother with it preferring instead to use Remote Management. This option opens ARD Control Port 3283 which allows copying from desktop to desktop amongst other things. There are indeed some of the same settings but not all of them. Security Issues? Not really other than the normal ones you'd have to consider anyway whether access is private or public. I would only ever use a VPN for Remote Management over the Internet. Vine is something that's been known for a long time now. It used to be mentioned every now and then over on the OSX Server Support Forums. I can't comment as I've never used it. Antonio Rocco (ACSA)
  6. Hi From a PC any of these 3 should work: UltraVNC, TightVNC and RealVNC. I use RealVNC (the free download version) all the time and it never fails for me. The other two give mixed results. With UltraVNC you need to use Putty to issue the 'kickstart' command before it will work even though the ARDAgent is running fine on the mac. You have to make sure you change the resolution settings from their default (set quite low as I recall) on RealVNC before you can make a connection. On the mac side make sure you enable the relevant option in the Sharing Preferences Pane for Remote Management. Don't use or enable the Screen Sharing option. System Preferences > Sharing > Remote Management > Computer Settings > VNC Viewers may control screen with password. Define a password which is different from the local admin account's password. Antonio Rocco (ACSA)
  7. Hi @theeldergeek "Surely I can have a 'container' folder in which I can then have 'home' folders and make it so that container folder's contents can be seen by whoever has read only permission of its content?" Yes but only if you share the folder. Besides the Parent Container for Home folders has to be shared and set to auto-mount for User Homes. Clearly the structure you're using is not best suited to allow this to happen. If I've understood you correctly this is because you have Parent Containers for User Homes within another Parent Container. Generally this is the way you would approach this in a typical AD environment. For an OD environment this won't work well if work at all. Basically you're just creating problems for yourself. Keep the OD folder structure simple - essentially a single Parent Container shared and set to auto-mount User Homes with individual User Home Folders within that container. It's a good idea on the platform to keep things as 'flat' as possible. A tree-like structure ends up giving you problems sooner or later. You can apply an ACL for the Teacher and/or IT Group that gives that group Read/Write access to that container and the individual Homes within it. Don't be tempted to do anything with the default POSIX permissions for individual homes either. These should be left well alone. Hope this helps? Antonio Rocco (ACSA)
  8. Hi I don't know why you would assume this because the Server should not configured the same as the clients. Perhaps you've forgotten? What I do is bind the Server to AD first, verify I can access and 'read' User and Group information from Active Directory and then promote to Open Directory Master with Kerberos stopped. This is 'classic' AD-OD Integration or - if you like - Magic Triangle Deployment. Once the Server has been promoted to OD Master it places itself automatically and by default above the Active Directory/All Domains entry in the Directory Utility's Search Policy field. On the Server in a classic AD-OD Integration this is how it should be. Clearly on the client this does not happen. Clients are generally bound to AD first and then joined to OD with no requirement for any authentication or contact information when configuring the LDAP plug-in. Perhaps this is contributing to the problems you're seeing? Antonio Rocco (ACSA)
  9. Hi I mean building an environment that takes account of the platform rather than adding them to a mature/legacy environment that was only ever built to accommodate the Windows platform. In no particular order I would say it would mean: Correctly resolving DNS on both pointers Making sure there are no malformed SRV Records Not using .local for your TLD Making sure the PDC Resolve itself to itself on both pointers Not having a folder structure that nests folders within folders within folders etc Making sure time synchronization is the same for all principals in the Realm Removing 'ghost/dead' users and/or groups from Network Home Parent Container as these permissions will be honoured by the platform Star Topology rather than a Cascading One Gigabit to Desktop WAPs that are N rated The list is not exhaustive by any means. Basically all the things your PCs don't care really care about. If you build the environment 'properly' and along Microsoft's Best Practices you should not see too many problems. If all of the above seems like too much hard work you could consider using a 3rd-Party Solution such as Likewise or Centrify. Or modify the Schema yourself. Any of these methods would not necessarily involve OSX Server. Perhaps you should re-post in the main forum?That way others who've been a similar position to you will get a chance to offer some of the things they've tried that may or may not have worked. Antonio Rocco (ACSA)
  10. Hi @theeldergeek SuperDocker (Mac) - Download Antonio Rocco (ACSA)
  11. Hi Your problem is DNS. I'm surprised you could not find anything as this forum (as well as others) is full of threads such as yours. The platform will struggle and more than likely display the behaviour you're seeing if you're basing your domain around .local. Why? Because it reserves .local for Bonjour/Rendezvous Services. All macs will broadcast and discover themselves using it. It's not a good idea to switch it off either. How you name your macs could also display similar behaviour. Don't use hyphens or any other non letter/number character. Using .local can be made to work but don't be surprised if you see problems. Having said that other AD environments that don't use .local can also display similar or even different problems which could be due to something else. The most successful integrations of my experience are invariably with environments that have (a) been built to accommodate macs in the first place (b) the AD structure/organisation is fairly flat/simple © don't base the internal domain around .local (d) are not using RM. Antonio Rocco (ACSA)
  12. Hi A Search engine would be good. Have you considered these? Lobotomo Software: IPSecuritas iTerm Pref Setter Antonio Rocco (ACSA)
  13. Hi There is a way to 'hack' a 10.5 Server and 'fool' the SUS into thinking it's a 10.6 SUS and serve updates to supported client OS: Apple - Support - Discussions - Can 10.5.8 Server serve 10.6 updates ... It's worth a try but be advised as it does not work in every case. "Will 10.6.* still update 10.5.8 clients as well as 10.6.* clients?" Yes. Not only that it will also 'serve' updates to 10.4 clients. Any SU Service will 'serve' updates to any version of the client OS from 10.4 onwards. But only for common updates. Applications such as Safari, iTunes, Quicktime etc for example. A 10.4 SU Service won't provide OS revision and/or specific updates to Client OS that are 10.5 and 10.6. A 10.5 SU Server will provide OS revision and/or specific updates to Client OS that are 10.4 and 10.5 but not 10.6. I'm not certain about the pricing and that will be something Mark could help you on. Provided things are 'healthy' with your server simply inserting the 10.6 Server Installer Disk and and running the assistant should 'upgrade' everything for you without (hopefully) breaking anything. As ever make sure you have a fallback position just in case. Unlike Windows there is no Restore or Rollback or Undo to a previous OS on OSX. Once you're committed that's it. Not that desperate if it's the Client OS as you can always Archive and Install. With the Server OS there's no such facility. Although (if you know what you're doing) even this can be worked around if necessary. Does that help? Antonio Rocco (ACSA)
  14. AntonioRocco

    Backing up WGM?

    Hi In the event disaster strikes and you need to restore back to a previous known working state and assuming nothing changes in terms of the domain or the FQDN of the Server itself: Server Admin > Open Directory > Archive. The rest is fairly obvious. That's one way and the way Apple would recommend as 'Best Practice'. However there are other ways of doing this. Antonio Rocco (ACSA)
  15. Hi There's definitely something odd going on and yes I agree there are some threads regarding this. However there are some differences. I'm using 10.6 and I don't see the problem. You're using 10.5 and you are. Something that Apple needs to address I think? Antonio Rocco (ACSA)
  16. Hi @theeldergeek I don't mean to contradict or say the problem does not exist - in your environment - but it is strange? I've been using network accounts (OD environment only) successfully with Safari 5 ever since it was made available to download and I don't see any problems at all. On some laptops (early spec models) over a wireless connection the fan ramps up slightly (never did this with the previous version) and that's about it. Additionally I've not heard anything 'official' from Apple Service Source regarding the 'problem'. As for Rosetta this would imply a backward step? Perhaps the issue lies elsewhere? Antonio Rocco (ACSA)
  17. Hi OSX does not use PXE Boot unless you're prepared to work very hard at it - ie: create your own PXE Boot Disk. Even that might not work with the latest hardware? If you're going to start supporting macs in your environment you're going to have to 'learn' not to approach them as if they were PCs. You have a number of ways to manage mac workstations in an Active Directory environment. All of them will depend on your budget and how hard you want to work. Apple's Best Practices is to use any Apple hardware that meets OSX Server's minimum specification. If all you want to do is provide some form of management and little else a MacMini would be ample. However bear in mind there is no hardware redundancy in a MacMini. Additionally they're not the easiest of things to get into if there's a hardware failure. AFAIK Third-Party applications you can use to provide mac-style GPOs to the Apple platform are Centrify and Likewise which you install on your Windows Server. AdmitMac is installed on the mac workstations, or if you're feeling particularly adventurous modify the AD Schema itself. For an automated way of 'pushing' out images to the platform you're really only looking at what's built into OSX Server - NetBoot and/or DeployStudio - so far. AFAIK you can't provide the same functionality using what's built into Microsoft's Servers. If someone has found a way to make this work you would think they would have already posted? Antonio Rocco (ACSA)
  18. Hi @theeldergeek "I have also been told, you can't run server tools 10.6 on a 10.5 machine, but I need to check this out" This is correct: Mac OS X Server: Admin tools compatibility information However you can VNC from a 10.5 Machine to a 10.6 Client or Server that has the Admin tools installed and use them that way. You don't necessarily need ARD as VNC Server and Client is built into 10.5 and 10.6 Server and Client OS. You can VNC from any browser by keying in the url field vnc://IPaddressofRemoteClientyou'reinterestedin. Alternatively you can use the "Connect to Server" option from the Go Menu. Again key in vnc://IPaddressofRemoteClientyou'reinterestedin. Finally you could navigate to /System/Library/CoreServices/Screen Sharing and drop the application's icon into the Dock. In 10.6 Server the Server Setup Assistant automatically does this for you when completing the initial configuration. It's been some time but you should also be able to do the same from a 10.4 Machine that has ARD 3.x installed. Ideally WorkGroup Manager is best utilized when installed on a Client OS. Antonio Rocco (ACSA)
  19. Hi @tmcd "This software wouldn't exist if Apple didn't purposfully run the fans at a slower rpm and thus cause the problem" I agree and I use Fan Control as result. Something I should have recommended to OP when posting. Antonio Rocco (ACSA)
  20. Hi "Also is it normal for them to be nuclear hot underneath?" Not really. It depends on what you're doing or what you did when initially setting up the laptop. Apart from a mild warmth under roughly the F2-F7 keys and the 2-8 keys that should be it. This is my experience on numerous other laptops I have used. "Nuclear hot" is a slight exaggeration surely? Can you warm a cold cup of tea/coffee if placed on the keypad which would make it hot enough to be drinkable again? Doubtful? If you can there's something seriously wrong somewhere and I'd doubt if you could switch the thing on. One thing that regularly ramps up the heat and fan speed is large amounts of data. Spotlight will begin indexing - this also happens upon completion of the set up assistant. The more data there is the more the "mds" daemon works the processor. You could stop this by placing the hard drive into the Privacy section - System Preferences > Spotlight > Privacy. Browsing websites with lots of Flash animations can also ramp up the heat/fans especially if a pop up window containing the animation is not dismissed. A lot of Poker sites are guilty of this. Affects Firefox as well so it's not just Safari. As an experiment you could install Windows and see if browsing the same sites in IE causes the same effect. In addition to the mds daemon Spotlight uses the "find" utility. If you issue "find /" via the command line and have the Activity Monitor open viewing the CPU Graphs you'll see what I mean as it 'simulates' to some extent what Spotlight does. Once indexing has finished you really should see heat values return to more reasonable levels. If it does not you potentially have a problem and I would suggest you take it back to the Retailer or an Authorised Repair Specialist (yes I realise it spells ARS) and get it looked at. Antonio Rocco (ACSA)
  21. Hi @ZeroHour Apple - Find Out How - Mac Basics Although understandable it would be a mistake to approach using OSX as if it were Windows. You're just going to have to learn how to get out of your comfort zone a little. Antonio Rocco (ACSA)
  22. Hi @ BootManager It's pleasing you managed to fix your particular problem. "nobody, not even the apple experts, ever suggested that the problem is all down to DNS" Perhaps you choose to remember and understand only what you want to? These boards (as well as others) continually stress the importance of a properly configured DNS Service. An earlier post of mine (as well as others) in this thread actually mentions: "slightly iffy DNS" As being relevant to the problems the OP (and others) mention. Even if DNS is 'perfect' you can still have problems logging in that may be caused by something else. Antonio Rocco (ACSA)
  23. Hi I know of at least half-a-dozen in and around the West Midlands area as well as 3-4 in the Leicestershire area. All Open Directory Environments. Admittedly some ares mall 5-20 workstations expanding to much larger ones 60-180 workstations with multiple servers. There is also one school in the Ripley/Codner area which is all mac with roughly 6-8 servers and 300-450 workstations. Of the half dozen in the West Midlands area 3 were all PC (Active Directory) which were scrapped after 2-3 months in favour of the Mac (Open Directory) environment. If you're also counting parallel LDAP environments I know of half-a-dozen again in the West Midlands area. From others that I know working in this field there are a number in the London and Home Counties area as well as Manchester/Leeds. Some of them quite large. In addition I know of at least three Corporate environments which are also all mac. These started out as PC/Active Directory but were scrapped not long after the first macs went in. Antonio Rocco (ACSA)
  24. Hi Just to add to Mark's excellent suggestion. Probably the most dangerous command to use is the "rm" command. In my view it's best to add some options as there are no undos once the command is run and there have been many who've ran the command and ended up removing more than they bargained for! sudo rm -R -v -i /pathtowherever Would provide feedback as well as slightly safeguarding what you're about to do. The -R option in rm attempts to remove the file hierarchy rooted in the directory path. The -v option means verbose - visual feedback basically and the -i option prompts for confirmation. User either responds with y or n (yes/no). If there are hundreds and hundreds of files I would not use the -i option. To permanently remove files rooted in a Users Trash the command would be: sudo rm -R -v -i /Users/username/.Trash/* With ARD you would remove "sudo" and run the command as root. You could approach this another way? With WorkGroup Manager you can use the Mobility Preferences to "cache' the User's profile on the local drive when first logging in. User works as normal and on successful logout and sync everything would be deleted from the local drive. You use WGM to define what is synced on logout. In your case (if I've understood you correctly) define Desktop and Documents and nothing else. Whatever is in the trash will be gone. Hope this helps? Antonio Rocco (ACSA)
  25. Hi I think possibly issuing from the command line on any mac: sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -help Should list all your options. I think the ones you're probably interested in will be the -clientopts switch. This is the full list available in the manual page: -setmenuextra -menuextra yes|no ## Set whether menu extra appears in menu bar -setdirlogins -dirlogins yes|no ## Set whether directory logins are allowed -setreqperm -reqperm yes|no ## Allow VNC guests to request permission -setvnclegacy -vnclegacy yes|no ## Allow VNC Legacy password mode -setvncpw -vncpw mynewpw ## Set VNC Legacy PW -setwbem -wbem yes|no ## Allow incoming WBEM requests over IP Don't use the same password as the local admin account. I think you'll probably need the -setreqperm and -setvncpw options. For me TightVNC, UltraVNC and RealVNC have all worked in one way or another. Experiment with them all until you find one that suits. Ultimately it may have been better enabling those options as part of the NetBoot Image. Perhaps this is something you could consider when building the refresh image? Does this help? Antonio Rocco (ACSA)
×
×
  • Create New...