HodgeHi
Members-
Posts
2,226 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by HodgeHi
-
What issues do you refer to? I am curious as i haven't read anything about any security concerns.
-
i Have just finished (ish) my AD - OD integration. I used the Ad-OD integration doc for some of it although i modified my setup slightly. AD-OD integration Doc What i have currently is an Xserve running 10.5.5 with a suite of iMacs runnign client 10.5.5 They authenticate against the AD for users and get their managed prefs from the OD. The iMacs are boot camped whihc means they run both Xp and OS X. Because of this i wanted a better solution to the problem of Macs not being able to update their DNS records. So i manually created the DHCP reservations and then manually created the DNS entries. This made it eaasy to manage the OS X side. This can all be automated during the imaging process using Net-restore and a flat file DB if you specify manual IP with DHCP setting. I scripted the build of my DHCP reservations using netsh and ARD to get the ethernet addresses. I have set the group policies on the AD server to redirect the my docs to the docs folder in the OS X home dir which resides on the AFP share that the clients access over AFp for AD users (set in the Directory Util). I have configured mail on the OS X server for AD users which is easy and i have a fully kerberised system for both OS X and AD users which is now easy to get thanks to the way Leopard 10.5.5 deals with this issue (about the only thing it does well). I have a mail server set up for pupils and this can send and receive mail to staff but cannot send mail out. I have also created an auto mail bundle that creates the mail account for users when they type their email and password. I am currently now in the process of trying to get the ical service working for AD users. I have beeb having a bit of an issue with this. I have managed to get this working at home with the use of augmented records and hope to re-create this success tomorrow. The kids have really gotten to grips with using both systems in school and have even started to ask the question before the beginning of the lesson "is it mac or windows miss?" We are a primary school. I feel i have managed to get a reasonably stable system set up and fully functional at the moment (don't get any thanks though) and i am happy with the way it has turned out. Oh, and i don't have a single apple or ms cert to my name
-
If you have two access points in proximity of each other and they are both on the same channel then there will be interference. According to a site survey i had done, they say if you have access points that overlap they should be on different channels. As for the rest of what you are on about i've no idea. If i rememebr right you should use 1,6 and 11. They are further apart and thus less prone to interference.
-
photoshop express? Not looked into it too much though so don't know if this is a feature.
-
The AD may not be enabled. Open Directory utility and go to Services. If this cannot be seen choose show advanced settings. make sure that there is a tick in the enabled box.
-
I only found out about this just. They don't seem to come down via software update? anyhow heres the link in case you didn't know either... Server admin tools 10.5.5
-
I don't have this issue but you may find more info here: http://www.edugeek.net/forums/mac/21932-revenge.html Its the last but one post on this page. It mentions something about the home dir mount points being different. Not too sure i knew what he meant. I have a Staff mount point and a Pupil mount point for the home dirs. They are on the same disk/RAID. I have found though that if you set kerberos only authentication for AFP and then create a new user in AD, the new user will not be able to log in. Why? I have no idea. But it seems to fail pre-authentication. If you change the AFP access method to any (you can do this without disconnecting everyone) then the new AD user seems to be able to log in fine. Then if you switch it back to kerberos only, they can still log in OK. Weird but thats what i found to happen here. PS I use AFP to mount AD user home dirs and not SMB. The SMB service on the OD is running but only so AD users can access the shares when logging into XP. I have redirected documents onto the XRAID share so they are all in one location. Seems to load a bit quicker too.
-
How did you deploy the Papercut Client for windows? I have tried and get errors each time i try to run the .exe? I know its me doing it wrong its just that i am unsure as to what the documentation is getting at. I have tried to share the folder with the client in but when i click on the .exe i get the error. But it is an ace print manager though
-
I have a print queue that prints fine. That is only if i have the actual print queue window open on the server. If i don't have it open. The jobs queue up and don't print. They stay there happily and the printer never tells me that there is an error. As SOON as i open the print queue the first job in the list spools and then prints and the rest follow as if no problem occurred. This can be replicated as soon as i close down the Print queue window. Now i don't even know where to start with this one. I haven't re-created the print queue yet but that is my next port of call after i test the print spooler but it seems that this works fine as the jobs print immediately so it must be sitting there waiting. Then i will re-install printer drivers. Anyone seen this before and know exactly what it is before i start messing with things that work-ish.
-
I'll have one I don't mind if the apps are a little out of date. Could you download them on a different machine and then install the packages from a USB Stick or DVD?
-
If you don't have the OS X CD/DVD you can log into Single user mode if its not disabled. A good reason why it should be though... Single User mode reset
-
Cool. Im downloading it right now then. Thanks :D:D
-
Does this work when the machines have ben standing so long that the screen goes black? The reason i ask is i have a script that runs the shutdown -r against all the machines in the suite at 6pm. But if the machines have a black screen then the scripts don't seem to run until you move the mouse or press a button.
-
You could have a look at this one FreeSMS Not sure what its like though as i have never used it.
- 3 replies
-
- administration
- filemaker
-
(and 2 more)
Tagged with:
-
This thread is interesting to me. We are having a new school built and at the moment we are mostly Smart (apart from some crappy things in the infants). I thought that this was to continue but a deputy here raised her voice a little over the promethean boards and how much she liked them. Now the head is looking into them. It's interesting to hear how many people have had failed boards in such a short time period. Is this just coincidence? I have been here now for two years and not one smart board or USB cable that powers the boards has failed. Is this the difference between the two? Would be interesting for some to comment on how many Smart boards they have had problems with...
-
I use a php script one called hesk. It uses a MySQL back end. It is a good little system really. Got no bells or whistles but it does work (apart from the fact that i seem to be the only on e who uses it). You can find it here: Hesk I am in the process of looking to see if i can tart it up a bit as this seems to be the only thing that lets it down if you ask me, apart from the lack of report creation.
-
The positive side to working in IT within schools.
HodgeHi replied to Dos_Box's topic in General Chat
Mine is opportunity. Working in schools has given me the opportunity to gain experience. I didn't have a lot going for me in the way of experience and didn't have any real ICT related qualifications. I was lucky enough to get a job working in Birmingham in an excellent ICT dept. The boss there showed me the sort of pressure you can be under in a school and the things i learnt from him set me in good stead. I worked hard and put a lot of hours in and learnt a ton of stuff at home. and now i work in a primary school looking after the network, website and ICT hardware as well as support the Teaching Staff. We have 3 2003 servers, 2 OS X severs, a smoothwall box and 25 imacs dual booted with 15 macbooks also dual booted with each classroom having a mac mini and a projector and whiteboard in (around ten in total). There is only me and so things can get a bit rough but generally its great. I love my job and to se how the kids develop in ICT is rewarding in itself because after all at the end of the day its fo the littlie ones The boss fully spports me and my decisions and advice. I don't think i would get this sort of respect in the ICT sector out of schools. Thanks for listening. -
I have tried the Augmented records approach. I have had some-ish success. I can enable i cal service for the AD users (the com.calender_access group is inherited). It lists all the AD users in the logs when the service ist started. It is just that i cannot get them to authenticate. The log keeps saying: 2008-09-26 12:00:46+0100 [-] caldav-8009 AMP,client Could not find the principal resource for user id: ADUser 2008-09-26 12:00:52+0100 [-] caldav-8009 http://HTTPChannel,35,127.0.0.1 GetClientAddress(host='127.0.0.1', port=50985) 2008-09-26 12:00:52+0100 [-] caldav-8009 AMP,client result = AmpBox({'_answer': '2d', 'host': '192.168.16.93', 'port': '60565'}) 2008-09-26 12:00:52+0100 [-] caldav-8009 AMP,client Unauthenticated users not enabled with the 'calendar' SACL 2008-09-26 12:00:52+0100 [-] caldav-8009 http://HTTPChannel,36,127.0.0.1 GetClientAddress(host='127.0.0.1', port=50986) 2008-09-26 12:00:52+0100 [-] caldav-8009 AMP,client result = AmpBox({'_answer': '2e', 'host': '192.168.16.93', 'port': '60566'}) 2008-09-26 12:00:52+0100 [-] caldav-8009 OpenDirectoryService Faulting record ADUser into users record cache 2008-09-26 12:00:52+0100 [-] caldav-8009 OpenDirectoryService Record (users) AD User is not enabled for calendaring but may be used in ACLs 2008-09-26 12:00:52+0100 [-] caldav-8009 OpenDirectoryService Added record /Active Directory/domain.com) 674FD9B8-4878-4059-BF28-AC7BBD47E1FD(AD User) 'AD User'> to OD record cache 2008-09-26 12:00:52+0100 [-] caldav-8009 AMP,client Could not find the principal resource for user id: ADUser This seems to suggest that it can't find the augmented record for the user. I know the ical service is working as i have created 2 OD users with ical access and they can connect just fine. I have seen the post on the apple forums about editing the caldavd.plist file t enable cleartext. I have tried this but still no luck.
-
OK. Is anyone else running iCal service for AD users fine? I am in the process of building a small AD-OD domain setup at home. I would like to know if any of you are using AD users and access the ical service to see if it is worth doing or if i am just wasting my time. Hope someone can help. I would love to get this working as it is the last thing i need to do now. Apple want to charge me $$$$$$$$$$$$$ for any support. Google has not helped resolve my issue and i don't really know where to turn for help now
-
I just whacked Server 2003 on my Macbook pro (through Boot camp) with 3gb Ram. It booted in around 30 secs to 1 minute. Not bad really for a laptop
-
Comic Life is just a .app file that can be copied. I would recommend getting a copy of ARD asap. It will make your life 1000 times easier. Deploying stuff through this is a cinch. To deploy comic life through ARD. Configure the clients for ARD access. Install the ARD admin on a separate machine and scan the network for the macs. Select the ones you want and go file> add selection to a new list or something like that. Now when the machines have been put into a group you can slect the group and click on copy. drag the comic life .app into the top window and then choose applications folder form the drop down list. Make sure inherit permissions from location folder or whatever it is and click copy. This should complete in about 5 minutes. The comic life license. The best way i found to do this is add comic life to a client and then register it. Then drag the plasq folder out of the /library/application support/ folder which is found here: drive OS is installed on > library > Application Support You can use ARD to do this and drag the file from the remote screen onto your local desktop. Then from here you can deploy the plasq folder the same way you deployed the comic life .app The preferences would be best managed through workgroup manager on an OS X Server. If you don't have one then it maybe best to get a small mac mini with a copy of server. make sure you have some decent amount of ram though as leopard needs 1gb on its own really. Good luck with it all
-
Managed or local? If a local user who just wants to stick shortcuts on the dock, just drag the application you want to add to the dock and the others should move out of the way to make space. If you mean managed, then you will want WGM and create a group for users or a group for computers or just single user. Go to the preferences and then dock. Add the apps to the list that you want the users to have. If you untick merge with users dock then they should only get yours. If you want to manage users without a server, then the best way would be to create a user, get it to how you want it set up and then copy the users home dir into the template folder found in "/System/Library/User Template/English.lproj. Any user created afterwards will use this template to create their home dir. You can edit the permissions certain files as well ie set the owner to root:wheel for the dock prefs file so they can't edit it. This is what i did for my desktop file. I have a link on how to do it here: Peachpit: How to Deploy Entire Systems in Mac OS X 10.5 > Creating a Cloned System Image This works for the desktop one. It may work for other files. I have not tried this though so cannot verify. You may want to test it first Hope this helps.
-
Hello, I hope every one is well. I have been trying to get iCal service working on my 10.5.5 Server which is connected to an AD server and is running in OD master mode. I have the users from the AD inside groups in the OD. The users can log into the clients fine and also get all their managed preferences. They are also using kerberos authentication for the shares and home dirs so all of the usual stuff i think is working fine. Now when i come to set up the iCal service on the OD Master, it configures fine and then starts. But when it starts i get the following in the logs: Thursday, 25 September 2008 16:27:49 Europe/London 2008-09-25 16:27:54+0100 [-] Log opened. 2008-09-25 16:27:54+0100 [-] twistd 2.5.0 (/System/Library/Frameworks/Python.framework/Versions/2.5/Resources/Python.app/Contents/MacOS/Python 2.5.1) starting up 2008-09-25 16:27:54+0100 [-] reactor class: 2008-09-25 16:27:54+0100 [-] 4 processors found, configuring 4 processes. 2008-09-25 16:27:54+0100 [-] Adding pydirector service with configuration: /tmp/pydirlah975 2008-09-25 16:27:54+0100 [-] twistedcaldav.logging.AMPLoggingFactory starting on "'/var/run/caldavd.sock'" 2008-09-25 16:27:54+0100 [-] [caldav-8009] [-] Log opened. 2008-09-25 16:27:54+0100 [-] [caldav-8009] [-] twistd 2.5.0 (/System/Library/Frameworks/Python.framework/Versions/2.5/Resources/Python.app/Contents/MacOS/Python 2.5.1) starting up 2008-09-25 16:27:54+0100 [-] [caldav-8009] [-] reactor class: 2008-09-25 16:27:54+0100 [-] [caldav-8009] [startup] Configuring directory service of type: twistedcaldav.directory.appleopendirectory.OpenDirectoryService 2008-09-25 16:27:54+0100 [-] [caldav-8011] [-] Log opened. 2008-09-25 16:27:54+0100 [-] [caldav-8011] [-] twistd 2.5.0 (/System/Library/Frameworks/Python.framework/Versions/2.5/Resources/Python.app/Contents/MacOS/Python 2.5.1) starting up 2008-09-25 16:27:54+0100 [-] [caldav-8011] [-] reactor class: 2008-09-25 16:27:54+0100 [-] [caldav-8010] [-] Log opened. 2008-09-25 16:27:54+0100 [-] [caldav-8010] [-] twistd 2.5.0 (/System/Library/Frameworks/Python.framework/Versions/2.5/Resources/Python.app/Contents/MacOS/Python 2.5.1) starting up 2008-09-25 16:27:54+0100 [-] [caldav-8010] [-] reactor class: 2008-09-25 16:27:54+0100 [-] [caldav-8011] [startup] Configuring directory service of type: twistedcaldav.directory.appleopendirectory.OpenDirectoryService 2008-09-25 16:27:54+0100 [-] [caldav-8010] [startup] Configuring directory service of type: twistedcaldav.directory.appleopendirectory.OpenDirectoryService 2008-09-25 16:27:54+0100 [-] [caldav-8009] [OpenDirectoryService] Matched Directory record: /LDAPv3/127.0.0.1/Computers/myserver.domain.com$ with ServicesLocator: 8C2E41DD-5075-4255-A579-A436E0F7ED73Big Grin2FCD0F5-BC65-4A7F-8362-37B2C22BAC40:calendar, state: disabled 2008-09-25 16:27:54+0100 [-] [caldav-8009] [OpenDirectoryService] Unable to locate virtual host record: Open Directory (node=/Search) no /Computers records with an enabled and valid calendar service were found matching virtual hostname: myserver.domain.com I think it has something to do with the fact that the server cannot be found or the service doesn't seem to be seen as enabled. I have the ad users with augmented records in the LDAPv3 side of the server and it has allowed me to enable calendaring service and choose the calendar server fqdn. If i refresh the setting sticks so it seems to be OK. My ical server is configured to be the fqdn of the server and has any method of authentication. If i try to conenct to the server using ical client i get and specify the Account URL as myserver.domain.com:8008 and then leave kerberos unticked and type in the username and pword of an AD user i get the following error... Account Information not found. Request to the server http://myserver.domain.com:8008/principals/users/AD User/ failed (code 30). Any ideas on how to sort this thing out? Thanks in advance.
-
How much is the sims learning gateway? A browser-based connection should be standard really. Is it not just a form that then writes the data into the right tables using an SQL statement when you click send with a page that tells of the success or not?
