Jump to content

AngryTechnician

Members
  • Posts

    3,772
  • Joined

  • Last visited

Everything posted by AngryTechnician

  1. Yep, that's it exactly. Switching to Kerberos worked for us, but it's not something you can just change over to and it instantly works. Key gotchas are: Once you set up Kerberos on the Smoothwall (i.e. when you link to your AD usaing the new, non-legacy method), all users must log off and back on before their Kerberos token will be recognised by Smoothwall. Any users logged on before you link to AD will fail to auth. Any user-specific policies will need to be edited to reflect that the username will be reported as [email protected] instead of just user The current Kerberos implementation on the Smoothwall does not correctly process usernames with spaces in. I beleive this has been raised for a future patch, but for now, the only workaround at present is to rename user accounts so tey have no space (luckily we only had 22 affected accounts). Local users on the workstation (such as the local admin account) will not be able to authenticate at all using Kerberos, and will have to use different proxy settings if you need access.
  2. Re: updates - my advice is to just let WSUS take care of it after the install. I started getting weird errors when I tried deploying updates at install time.
  3. I would just remove the one setting from Default Domain Policy that is causing problems and then have the targeted GPOs as you describe just for that setting.
  4. This is the exact problem. Developers aren't required to offer that option. I would wager that only a very small percentage of them ever will.
  5. This is by design. Internet Explorer Maintenance Replacements The comedy element here is that they regard GPP as more robust, when anyone here who has tried deploying printers with GPP will tell you it is anything but. EDIT: Even better, you actually can't specify the "Automatically detect settings" box to be ticked using GPP, that setting is greyed out. The above article says to use IEAK for this, but also says right at the top that "IEAK for Internet Explorer 10 isn't currently available."
  6. Depends on the model. We have a Vigor 2920 and it can do this with data filters, but I don't know which models have that feature.
  7. Remember that not everyone here will have met you in person and seen what a waif-like figure you actually are... for someone who did struggle with their weight, that sort of joke could be quite upsetting.
  8. Presumably only the public key, not the private key (unless someone has been monumentally thick) so you'll have to self-sign. Other than that you may be on to something here. Still utter rubbish that this is what we might be looking at as a deployment method for the next few years.
  9. I was at BP and TNMoC last month. If you can, I would advise more than one day for it, unless you can be there literally from open until close - there is a lot to see. The Insight Guided Tour is also well worth it for the museum.
  10. This is exactly what I think we all knew was going to happen. If left up to the publishers, they are not going to put the extra effort in, it's as simple as that. I would love to hear what @eduAnt from Microsoft has to say about this, given that when he popped in to the forums in September he was asking "What are the Top 5 challenges for schools"!
  11. The main thing I use VAMT for these days is getting human-readable error messages when activation doesn't work. It's pretty rare that I open it up.
  12. I hate to break it to you, but that's been in Office for a decade. It's definitely had improvements, but it was in previous versions. (source) Strict is not the default, but you can set it to be. These are the options you can set as the default in Word (via Options > Save): You can set any of these as the default by GPO. A similar list is available for Excel and PowerPoint. There do not appear to be any options regarding strict mode when you modify existing documents.
  13. I wrote ours bespoke for our Intranet using SQL Server and .NET, so a database is a reasonable way to go. I've never been asked to do any analysis of the data though.
  14. My experience of Mac use is similar: fine until you do something wrong, or until something breaks, and then you are completely boned.
  15. From my testing, it only seems to do that if you are already signed in to SkyDrive - if you aren't, it defaults to Computer. You can also force it to save to Computer by default using this option: This isn't in the Group Policy templates for Office 2013, because they only put useless cruft in the GPO templates instead of anything we might actually want to change. However, it is a simple per-user registry option: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\General REG_DWORD:PreferCloudSaveLocations Set this to 0 to default to saving to the local computer, or 1 to default to SkyDrive (if signed in).
  16. OK, just to report back: switching to Kerberos was relatively pain-free and is working well for us. Sticking with NTLM just wasn't feasible due to the above problem, so I suspect anyone who runs into the same problem will find that switching auth method is the only realistic solution.
  17. Already posted my thoughts here a couple of weeks ago: http://www.edugeek.net/forums/office-software/103374-2013-rtm-isos-available-technet-2.html#post889075 Only thing that has caught my eye since then is that when you reopen a Word document it will offer to scroll you automatically to the point you left off. Which is nice.
  18. 'Working at Height' only applies if you can hurt yourself falling from it: Source: http://www.hse.gov.uk/pubns/indg401.pdf They might be referring to H&S guidelines about having to lift heavy things above head-height, but there are no H&S regulations I am aware of that cover having to lift something as light as a whiteboard pen. Back to the real question: if the primary user of the board can reach the top and bottom edges without having to bend down or use a step, it doesn't need moving. If this is not the case, it does need moving.
  19. Well, Cisco acquired Linksys in 2003, so if they discontinue the brand after nearly 10 years that still sets a reasonable precedent for Meraki sticking around. I'm not so sure that's a danger. If you've looked at the price of Meraki wired network offerings they aren't significantly dearer than Cisco. Cloud controller licensing is certainly more of a concern, but hopefully they won't want to upset the existing install base by hiking up renewals.
  20. I'm conflicted about this. On one hand it should guarantee the future of the product line, but on the other hand, Cisco aren't renowned for giving stuff away for free, so the future of Meraki Systems Manager is a concern.
  21. If it's proxy issues you're having, I recommend getting WPAD auto-configuration working on your school network, then you can just set proxy settings to automatic and it will work at home and at school.
  22. Without the enforced security settings that you get with a domain, it's actually going to be harder to meet your obligations regarding data security. It's not just about encryption. What encryption package are you looking at? If it's TrueCrypt, I seem to recall that doesn't ask for a password when you resume from sleep (only from shutdown or hibernate), so you could be making the computers significantly less secure unless you completely disable sleep mode.
  23. Didn't have any problems over the weekend. Is it still doing this for you?
  24. I saw poor performance myself with them this summer, a year later, which was solved as soon as I forced it onto a different channel that didn't have local interference from neighbouring equipment (unlike the channel that Meraki picked on automatic). I have also seen them work brilliantly as you describe, but not when there is channel interference. What the article describes may not be representative, but it still bears some resemblance to what I saw.
  25. My copy of VLC (2.0.4) opens that one fine, where did you find it?
×
×
  • Create New...