danboid
Members-
Posts
95 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by danboid
-
"indentd"? Is that a typo? Have you got a link to its homepage? I presuming its free? If we were to use i(n)dentd, would users have to autheticate to access the web or is this a single sign-on solution? Is indentd tied to dansguardian or will we be able to use it alongside our existing firewall? If you found any useful guides to getting this app setup I'd be grateful for any links you can provide Thanks!
- 18 replies
-
- active directory
- internet
-
(and 1 more)
Tagged with:
-
We have a Server 2003 r2 DC and a Watchguard Firebox Firewall but currently we have no way to audit internet use on a per AD user basis. Our firewalls log server does support logging web use via Active Directory user name but we are currently struggling to get it to work correctly and even when we do have it setup I still won't be entirely happy with doing it that way as users will have to login as per usual to AD and then they'll have to manually authenticate against our firewall if they want to access the internet. Ideally users would only need to login once as usual with no need to authenticate again to get out onto the net but we'd still be able to see what sites every user has visited per AD user name. I'm wondering what other options we might have and if they may work better than using our firewalls log server? We're not running squid at the moment but I suspect that might be able to do what we want? If we did use squid, would users have to manually authenticate against it before they can access the internet or can this be automated?
- 18 replies
-
- active directory
- internet
-
(and 1 more)
Tagged with:
-
I gave up on trying to set this up manually under Jaunty and I'm now working on getting this going using suse's Windows Domain Membership config tool (under Yast)- opensuse seems to be the only distro attempting to make this process relatively easy but its still far from click n' connect, there are a number of tweaks to perform before you can run the domain membership tool. I've now got Yast to configure suse as far as using openlikewise took me under 'buntu in that I can now log in using an AD members credentials and I know that I'm very close to having Yast set up automounting of the users home folders but its just not quite working yet. I can feel quite confident in saying that (unbelievably) no-one seems to have wrote an idiots guide to setting this whole thing up using yast and I believe this is why Linux isn't seeing more use in our schools and in other organisations as this functionality is a basic requirement for acceptance/ integration into the majority of our still mostly Windows dominated networks. Once we have this process nailed I'm going to write an idiots guide to doing this that anyone with basic Linux skills and enough knowledge to add a windows machine to an AD domain will be able to easily follow that can go on the opensuse and edugeek wikis. Sound good to you? Here's a summary of my current status which I posted to the opensuse forums yesterday but which I've had no response to yet: ---------------------------------- I'm testing out opensuse's (11.1 i686 GNOME) AD integration features as I'd like to have Linux used in our school outside of the server room but I need a fully-working prototype before that can happen. After a significant bit of wrestling with Yast and various config files I now have AD login/ authentication working but I've been unable to get AD users home folders to auto-mount correctly. Under Yast/ Windows Domain Membership/ Expert settings I have left the UID/GID and WINS options at their default values as I don't think they're relevant to what I'm trying to do but I added an entry to the 'Mount Server Directories' list with these values: ---------------- Server Name: server (I'm presuming I could put any name in here or must it match the DC's DNS/ realm name?) Remote Path: //192.168.0.3/student/%(DOMAIN_USER) Mount Point: /home/SERVER/%(DOMAIN_USER) Options: user=%(DOMAIN_USER) (The default) User Name: (Left Blank as I want home folder mounted for all users that log in, right?) ---------------- I have noticed that even if I uncheck 'Create Home Directory on Login' a home folder gets created under /home/SERVER/%username anyway and so thats why I have used '/home/SERVER/%(DOMAIN_USER)' for the mount point even though I'd rather just use /home/%username as the local mount point. Can I do that instead? If I log in as an AD domain user then I open nautilus and go to 'smb://192.168.0.3/student/' I can see all the home folders and I know pam is mostly working as I can access files with my users home folder but not other users but this folder isn't being auto-mounted under /home/SERVER/%(DOMAIN_USER). Any ideas? Finally, after having added the suse box to the domain I get an extra drop-down on the gdm login screen that lets me choose if I want to log in locally or to the AD domain. However, it doesn't matter whether I choose local login or domain login from this menu as I still have to login like 'server\user' for the username. I would like it if users had no need to prefix their user name with the domain name when logging in at all or at least no need to do so when they choose the domain from the menu. Can this be done? Thanks!
-
Hi! I've tried just about every guide on the net on how to get automounting of folders after a GDM login to work but I've had no luck yet and CyberNerds guide is no exception although I realise he wrote it for 'buntu 6.06 and I'm trying to get it to work under 9.04 which will have much more recent versions of samba etc. of course, no doubt with all-new config file formats and options etc. I didn't follow the guide to the letter as I joined to the domain with openlikewise first (which works fine) and I also ignored his ntp instructions in favour of setting up openntpd as was recommended in the comments that followed the guide. All went went until I got up to: root@ohgs-desktop:/etc/samba# wbinfo -u Error looking up domain users root@ohgs-desktop:/etc/samba# wbinfo -g Error looking up domain groups So at that point I gave up as I presumed samba wasn't setup properly despite the fact that the net command supposedly did join me to the domain correctly but maybe this is conflicting with openlikewise?? So, does anyone know of a complete, up-to-date AND easy to follow guide to adding a 9.04/GDM box to a w2k3 AD domain and have it so that users network home folders get automounted? Also, is there any reason I can't or shouldn't auto mount the network drives to /home/$username instead of /home/$domain/$username as most guides seem to do? Thanks!
-
We managed to get a laptop to boot to the FOG PXE menu in the problematic room as the laptop we used allowed much longer for DHCP to come up than the desktops (which all have RTL8168c/8111c NICs built onto their mobos) which only give you a max of 5s before it gives up. I read on another thread that you can supposedly extend the time-out by pushing PAUSE then unpausing with space or enter but that didn't work for me, nor did juggling the boot order. The solution for me was to boot off the latest git etherboot image for r8169:r8169 which I downloaded from: ROM-o-matic.net Funny thing with that is that etherboot finds / boots the FOG PXE menu instantly, soon as its booted. Wassatalaboot??
-
Hi 'geekers! I've posted this same prob to the FOG forums but last time I posted there I got no response and I'm in a bit of a hurry to get Fog running properly again so I can't chance not having a reply by tomorrow so I wanted to post it here as I know there a a lot of FOG fans and users on these forums. Before I ask my question- is there not an irc channel for FOG? I've not been able to find one which seems odd as FOG deserves to be massively popular from what I've seen so far. Also, I'm pretty sure STP is turned off but I'll need to double check that. I did have FOG 0.27 working very nicely on our Ubuntu 9.04 Server install until I did an dist-upgrade of Ubuntu last week and now I can only access the FOG PXE menu on a select few machines whereas before it was working on all machines on our LAN. After trying a few different things I decided to totally re-install Ubuntu server and FOG but the problem persists. We have one room full of computers that were all imaged using FOG but now none of them get issued a DHCP address so you can't access the FOG PXE menu but you can access the FOG menu on some other machines of different parts of our network still. The settings on our DHCP server have not changed from when we successfully imaged that full room and the fog server has the same static IP as when it was working. I've tried turning DHCP on and off on our switches but it hasn't made any difference to the once-working machines so I'm presuming Ubuntu have broke something in a recent update?? Thanks for your help! Dan
-
I would like to use Debian netinst (more specifically, kmuto's remaster of Lenny netinst) as the basis of a system recovery partition but I would very much like to automate to install process so that all I would have to do eventually is just boot it of a CD or USB and everything (the base system at least) would all be installed with no manual intervention. Debians solution to this is called pre-seeding but I'm not having any luck configuring it. Before I go remastering the netinst CD I want to have a preseed file working that is loaded off USB at boot with a standard (kmuto) netinst CD. The idea is that I would install windows and then leave 20GB or so unused space on the drive which the Debian installer would auto-partition into one big / partition or one big / and a swap as big as the RAM if Debian insists on having a swap partition (which I think it does). This Debian install doesn't require any net access or access to the repos. If anyone has successfully pre-seeded Debian netinst, please can you share your preseed config file and I'm also not entirely sure I'm passing the right arguments at boot to load the preseed file as I've read different examples of how it should be called. Here's my preseed file as it stands (albeit with most of the comments removed so I could post it here), which I'm trying to load by appending: file=/hd-media/preseed.cfg To the kernel boot args on the Debian netinst with this preseed.cfg located in the root of my flash drive as a unix formatted text file. Debian loads the kernel but before it starts booting the kernel I just get this on my screen: (process:1472): INFO: kdb-mode: setting console mode to Unicode (UTF-8) d-i debian-installer/locale string GB # Keyboard selection. #d-i console-tools/archs select at d-i console-keymaps-at/keymap select uk # Example for a different keyboard architecture #d-i console-keymaps-usb/keymap select mac-usb-us ### Network configuration # netcfg will choose an interface that has link if possible. This makes it # skip displaying a list if there is more than one interface. d-i netcfg/choose_interface select auto # To pick a particular interface instead: #d-i netcfg/choose_interface select eth1 # If you have a slow dhcp server and the installer times out waiting for # it, this might be useful. #d-i netcfg/dhcp_timeout string 10 # If you prefer to configure the network manually, uncomment this line and # the static network configuration below. d-i netcfg/disable_dhcp boolean true # If you want the preconfiguration file to work on systems both with and # without a dhcp server, uncomment these lines and the static network # configuration below. d-i netcfg/dhcp_failed note d-i netcfg/dhcp_options select Configure network manually # Static network configuration. d-i netcfg/get_nameservers string 192.168.1.1 d-i netcfg/get_ipaddress string 192.168.1.42 d-i netcfg/get_netmask string 255.255.255.0 d-i netcfg/get_gateway string 192.168.1.1 d-i netcfg/confirm_static boolean true # Any hostname and domain names assigned from dhcp take precedence over # values set here. However, setting the values still prevents the questions # from being shown, even if values come from dhcp. d-i netcfg/get_hostname string unassigned-hostname d-i netcfg/get_domain string unassigned-domain # Disable that annoying WEP key dialog. d-i netcfg/wireless_wep string # The wacky dhcp hostname that some ISPs use as a password of sorts. #d-i netcfg/dhcp_hostname string radish # If non-free firmware is needed for the network or other hardware, you can # configure the installer to always try to load it, without prompting. Or # change to false to disable asking. #d-i hw-detect/load_firmware boolean true d-i mirror/country string manual d-i mirror/http/hostname string http.us.debian.org d-i mirror/http/directory string /debian d-i mirror/http/proxy string # Suite to install. #d-i mirror/suite string testing # Suite to use for loading installer components (optional). #d-i mirror/udeb/suite string testing ### Clock and time zone setup # Controls whether or not the hardware clock is set to UTC. d-i clock-setup/utc boolean true # You may set this to any valid setting for $TZ; see the contents of # /usr/share/zoneinfo/ for valid values. d-i time/zone string Europe/Brussels # Controls whether to use NTP to set the clock during the install d-i clock-setup/ntp boolean true # NTP server to use. The default is almost always fine here. #d-i clock-setup/ntp-server string ntp.example.com ### Partitioning # If the system has free space you can choose to only partition that space. d-i partman-auto/init_automatically_partition select biggest_free d-i partman-auto/method string regular d-i partman-lvm/device_remove_lvm boolean true # The same applies to pre-existing software RAID array: d-i partman-md/device_remove_md boolean true # And the same goes for the confirmation to write the lvm partitions. d-i partman-lvm/confirm boolean true d-i partman-auto/choose_recipe select atomic d-i partman/confirm_write_new_label boolean true d-i partman/choose_partition select finish d-i partman/confirm boolean true ### Base system installation # Select the initramfs generator used to generate the initrd for 2.6 kernels. d-i base-installer/kernel/linux/initramfs-generators string yaird # The kernel image (meta) package to be installed; "none" can be used if no # kernel is to be installed. d-i base-installer/kernel/image string linux-image-2.6-686 # Root password, either in clear text d-i passwd/root-password password password d-i passwd/root-password-again password password # or encrypted using an MD5 hash. #d-i passwd/root-password-crypted password [MD5 hash] # To create a normal user account. d-i passwd/user-fullname string Debian User d-i passwd/username string user # Normal user's password, either in clear text d-i passwd/user-password password password d-i passwd/user-password-again password password # or encrypted using an MD5 hash. #d-i passwd/user-password-crypted password [MD5 hash] # Create the first user with the specified UID instead of the default. #d-i passwd/user-uid string 1010 # The user account will be added to some standard initial groups. To # override that, use this. #d-i passwd/user-default-groups string audio cdrom video ### Apt setup # You can choose to install non-free and contrib software. #d-i apt-setup/non-free boolean true #d-i apt-setup/contrib boolean true # Uncomment this if you don't want to use a network mirror. d-i apt-setup/use_mirror boolean false # Select which update services to use; define the mirrors to be used. # Values shown below are the normal defaults. #d-i apt-setup/services-select multiselect security, volatile #d-i apt-setup/security_host string security.debian.org #d-i apt-setup/volatile_host string volatile.debian.org tasksel tasksel/first multiselect standard d-i grub-installer/with_other_os boolean true d-i finish-install/reboot_in_progress note I've heard that RH/Fedoras kickstart system is a lot easier for creating automated installers than debs preseeding system- anyone had experience with that? Is there stripped-down RH/Fed ala Deb netinst which I could use should I not get preseeding to work? I don't need xorg etc, just a shell, the basic disc tools + partimage.
- 1 reply
-
- auto install
- debian
-
(and 1 more)
Tagged with:
-
I was all for going with sysrescue for this task but sadly sysrescue is still lacking a proper installer- you can fdisk, format, order/copy the files, write your own menu.lst before running the grub installer etc. to install it but there were more difficulties than that so I gave up on it. Great as a live recovery media but awkward for HD installs. It dawned on me that this was a perfect job for Debian netinstall. The only package I had to add to make it do exactly what I wanted was partimage. Debian netinstall with nothing added save partimage boots lighting fast- type I have 'fix' as an alias to the partimage command that restores a 10GB NTFS partition in as many minutes on an average modern laptop then reboots itself- laaaaaavely!!
-
Thanks to everyone for all their suggestions but out of them all I think dhicks did the best job of extracting my desired localised image restore system from the ether. I do already use systemrescuecd for recovery purposes anyway, I've just never installed it and didn't think of using it for this purpose but now I see its a perfect match. I won't need to put as password on grub as long as I just have a decent root password and no other users on the sysrescue partition, and I know that partimage is reliable as I've been using it for a while via clonezilla. Speaking of cz, I'm going to try FOG asap and see how that compares to the latest drbl-live aka clonezilla server.
-
sysprep, as I understand it, is used to 'genericise' images of Windows installs so that they can be depoyed via RIS or WDS- I can't see how this would help me as I want to create images specific to each machine that will reside on a special partition one each individual drive. These images would never be deployed on anything other than the machine on which it resides so why would I need sysprep?
-
Hi! We're an XP-running school and, sadly, we have a number of awkward to install/manage apps that don't play nicely with imaging in that these apps are registered over the net on a per-machine name basis. So, as it stands we have an image for these machines which we deploy when one goes titsup that includes everything but the awkward apps which we then have to install and configure separately- very annoying!! On top of that a number of these machines are away from the main site with no network to speak of and no technicians to hand. Hence, I was wondering if there may be program to put an end to our wonky windows woes. What I think would be ideal is that every machine would have a second recovery partition of 10GB or so. We would install Windows, all the normal apps + the awkward ones and fully configure everything. Once everything has been setup just as required I'd start the 'mystery app' (hopefully a free, open source one) and this would then create an image of the first partition onto the recovery partition as well as modifying the boot loader to add a new boot menu with a short time-out and a password-protected 'Restore from recovery partition' option so that the teachers can quickly and easily get the broke machines back on their feet without having to involve us (the IT staff, so long as its not a hardware failure and the boot menu still comes up, of course). I know I could just use any disc cloning software to image partition 1 onto 2 but the key point here is being able to restore from the 2nd partition very simply via a password-protected boot menu option and it would be a complete image restore - not some half-assed ASR thing. Anyone know what I'm looking for??
-
You may also want to check out winff which has a simpler GUI than SUPER and is available for Windows AND Linux, for all you techies who prefer your apps free AND cross platform WinFF - Free Video Converter
-
FN-GM: Ha! Another (Roch)'dalien replies! OK looks like I just might need the school installer and i presume i'll be ok then? I looked at the install options for my NSM and there wasn't any school option. Regardless, is there not a free tool for doing this? It wouldn't need to be a Netsupport replacement, just a simple list of machine names basically- you could install turn all on or off or just selectively disable them from a simple menu system. ??
-
Does anyone know of a free (no demos, shareware or crippleware- at least proper freeware) app for XP that allows you to simply (ie point and click) enable or disable the internet access of one or many workstations that are connected an AD domain? We're actually already running Netsupport on all the machines but not Netsupport 'school edition' which does have this feature apparently. Rather than having to both first pay them more for an upgrade and then go to the hassle of having to re-install and enter all their serials etc. I thought it might be easier just to find a free tool that does what we need and install that alongside it. If nothing like this exists already it should be easy enough to knock one together using AutoIt, beyondexec and the net command I should imagine
-
Graphical or cli? As powdarrm says, you can use putty under xp to control your ubuntu box over t'net if you have sshd running on your buntu box but seeing as you mention VNC then I presume you want to control your ubuntu box from xp over net graphically? In that case you want to use freenx. Sadly there is no freenx server in the ubuntu repos last time I checked so you'll have to go to FreeNX - the free NX or NoMachine NX - Desktop Virtualization and Remote Access Management Software for that but there is an nx client in buntu repos at least- qtnx. To access my freenx server under winbloze I use a tasty treat called portablenxclient which is what it says- a no install required XP nx client you can just run off a pendrive! Problem is that it doesn't seem to like saving your settings so you've gotta type your IP and login details every time but I'm not bothered enough about that yet to look into a solution.
-
Has anyone already created an msi package for the latest inkscape release that they'd be willing to share with myself and edugeek at large? We've had msi packages available to potentially simplify software installation and removal for Windows network admins since Win2K so is it just me who wonders why so many (big name) open source programs that are available for Windows totally neglect to have msi packages on their download pages? I don't want to sound ungrateful as that's certainly not the case but if you can code something as complex as Inkscape or FireFox surely creating an msi isn't asking too much? Its an excellent method of maximising ease of installation, program 'accessibility' and the overall userbase- hence more testers and developers. Additionally, people are more likely to trust an msi packages from the original authors over a third parties package. Win win surely?
-
Hi pscott! Never saw the original driver disk but the driver I got off the net works just fine, as admin, so I don't think its a driver but a Windows/AD issue. We've had exactly the same problem with a different machine / scanner. Whether we use GIMP or the little util that comes with the driver all we get is 'scanner not plugged in' or a similar error when not logged in as admin. Currently we have to get a teacher to log in on said machines as admin if someone wants to use the scanner. Domain controller is a server 2003 box btw
-
Nobody? I thought this would've been a pretty common task for edugeekers?
-
We've got a scanner that we would like to use attached to a WinXP AD-domain connected machine. We've got the drivers installed on that machine and they work fine if you log in as admin but if you try to access them as a student (AD login) you get an error saying the scanner isn't plugged in or something. After a bit of Googling I came up with the suggestion to use regedit on said machines and edit HKLM\SYSTEM\CurrentControl\Control\StillImage but it didn't go into detail. There is a 'REG_SZ' key at that location so my guess was that here I had to enter the name of the scanner as displayed under 'Scanners and Cameras' for its VALUE. Did that, restarted machine but no luck. I tried this on a Win XP SP3 box with a Mustek 1200 UB USB scanner under the GIMP. I would like any user who logs onto that machine to be able to use the scanner please! I should imagine there is a switch for the users server-side I will need to adjust (too)?
-
We've switched one of our classrooms over to iTALC from NetSupport- about 18 WinXP SP3 clients with a XP master and a Linux master (Ibex 64) and we're most impressed and would like to drop NS entirely. Netsupport don't offer a Linux master app. Problem with setting up iTALC is all the hassle of collecting ipconfig dumps from all the machines then copy/pasting their IP+MAC into iTALC or a hand-edited globalconfig.xml. I've got Beyondexec working with out computer labs now and hence I've already got group files containing the names of all the computers in the class rooms. I don't see why I shouldn't be able to turn such lists of network names into a fully configured (w/ MAC adresses) iTALC globalconfig.xml, which would go a long way in remedying its lack of client autodetect. Just thought I'd see if anyone has scripted this already before I attempt it myself? We still use static IPs at our school, but we'd like to move to DHCP. Problem with that of course is that we wouldn't be able to use iTALC if we did as it doesn't support DHCP far as I can tell. I think Toby has lost interest in developing iTALC in favour of (the admittedly much more exciting) LMMS- has anybody here looked into how hard it would be to add DHCP to iTALC? We've got 6 hard-wired classrooms each with 15 to 20 WinXP PCs- would this be any problem to manage on a 64-bit Intrepid master? Might our weedy 100Mb network be a stumbling block?
-
Hi mmoseley! Of course I'd be very interested in such a site. I'd definitely both use and contribute to it but powdarr has raised many good issues. There's lots of great GPL/BSD/Apache etc software out there that could be packaged without hesitation but for lots of other freeware or unknown-ware the packager would most likely need to check with the author if its OK to upload, just to be sure and quality (virus) control would need to be tight. Whether or not the packager wants to share their packaging code is a bit of a non-issue for me as 99% of people won't care about that source- they'd just want either the msi or the actual program source but of course it would be cool to have all sources. Packaging guidelines or not is the question here. Maybe we need just a few. I personally think that all packages that have a GUI should add a shortcut in the start menu but not on desktop unless desktop is requested with a switch.
-
Even though I've not personally tried it, I'm taking the website and pmnkys word that makemsi is all it says it is. There wasn't really any powerful, free tool such as this already linked on the wikis essential software page under the MSI section so I've just added it now.
-
Just had q quick look at MakeMSI and it sounds great- no doubt I'll be trying that myself soon. A shortcut just in the start menu is great. Unless you've got plans to start your own msi repo then can I suggest you contribute your MSI to the sf.net MSI repo I linked to earlier in this thread. They might be interested in adding it and it would seem to be about the closest thing there is to a good, existing free MSI repo although I'd love to be proved wrong.
-
Thanks for that powdarrM! I ended up not bothering with MSI'ing Kompozer as xcopy'ing the kompozer folder and adding a shortcut via updating the default profile with a shortcut to Kompozer on the desktop did the trick - I needed to update the profiles anyway so it was no big thing. I'm home now and currently without a windows install to try it out on. Does installing your MSI add a shortcut to Kompozer under the start menu or on the desktop or both? What program did you use to create it? Noice won Mankey san!
-
powdarrmonkey: I was actually looking for an MSI for the latest Kompozer. Thanks for the offer to package it for me! If you don't beat me to it then I'll be having a go at making an msi for it tomorrow. User3204: Yeah I know about Appdeploy - its a great resource and yes they do often include the msixexec commands to install stuff but I don't think I've seen any MSi's linked to or hosted there. That would make an already fantastic site perfect if they could provide MSis for all the free apps but I don't understand why they have a 'Package KB' and a 'Software KB' - whats the difference? You mentioned a repo on sf.net- wonder if it was this one? Open Source MSI Repository It's a nice start but theres only a dozen apps on that site at the mo and I'm sure I saw a site with many more in the last week or so. Having a good repo of MSIs with all the best free software would be a fantastically handy resource.
