HodgeHi
Members-
Posts
2,226 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by HodgeHi
-
Can you do a Windows Update using a different browser? I think the last time i tried that it wouldn't run. I love my macs. I would not go back. It's not the Bells and whistles that come with the machine, it's the stability of the OS. I have not used Vista as of yet so cannot comment on the stability of its product. I have also been having my fair few issues with leopard (the main one being my keyboard on the MBP) but even with this, Leopard was still stable when running. Someone mentioned security on OS X. If you use common sense on any platform then you will be better protected, but more common sense is needed and also a vigilant updating process (spyware,virus detection apps etc) to keep on top of this. I haven't got any virus software on my mac at the moment (is this wise?) but i don't feel i need any. I think when a serous virus comes out for the mac then EVERYONE will know about it straight away. The free apps are for each platform and they are great. Keep them coming is what i say. It's shows though that will a little effort any app can be ported across regardless. The open source movement is great and some bigger companies could learn a lot from their example. I have had big problems with the leopard DVD play back software though. One thing Apple do do which i think has one over on Microsoft is being able to take on new hardware advances like EFI. MS don't have this luxury as they need to support all hardware as best as possible. But Apple have demonstrated that you can have an EFI boot and still be backwards compatible with BIOS boots, although you don't have as much control with the hardware. Well i don't anyway. Is there a way to tinker with the boot options in EFI? This is where the PC industry is good. You have more options at your disposal. But this also gives more confusion to the more basic user. But for me, I like my macs and most people that take one up at the moment seems to be thinking the same. Apple must be doing something right, even if it is there marketing. Oh, and i forgot. Upgrades to OS X seem to be cheaper as well. With the added benefit of mot being tied to specific hardware. So if i have one copy of Leopard and install on Macbook. Don't like it can re-install tiger and install leopard on G5 powermac. PS Haw many processors can a copy of XP be installed on now? is it still 1-2 CPUs? Does this mean you have to purchase 2 licenses if you want to run it on a quad core machine?
-
How has the leopard upgrade gone so far? We are currently running boot camp and so will need to upgrade to leopard server and clients. After trialing it at home it doesn't seem too bad although i had problems logging in as a network user on my macbook pro when being automatically configured for the leopard server. The kerberos realm doesn't seem to be working right. I haven't really looked into it though as i was more interested in the calendar sharing, mail and wikis etc.
-
If its just for video chat then you may be able to use macam with any USB compatible webcam. I have installed this software on a mac mini using a logitech webcam (can't remember which one it was) and can see it it Photo Booth. Can't use the filters though but am not sure if this is because the app was copied from a different machine onto the mini. Photo Booth doesn't really come with it. Macam
-
Yeah. Thats how i did mine. I have yet to script the AD using the dscl and dsconfigad commands. I would think that the process is the same when you script with dsconfigldap that you would specify the name of the computer in the line used to join the machine. ie in dsconfigldap you use dsconfigldap -v -f -a server name -n config name -c $computerid -u bind username -p bind password So i would assume the dsconfigad would use the same method using the variable to pull in the computer name but you would need to change it at some point during the script. You could maybe include acsv file and read the information from the fields depending on which bind you were doing. ie if it were the od you could pull in the od field into the variable and if the AD that field. I'm not a scripter but i suppose it could be done since its what net-restore uses for his byhost settings i think. Anyway i resolved my issue with the authenticating. I had to re-index my slapd. The commands are as follows if interested. I removed the computer from the OD in WGM first. Removed the DirectoryServices from /library/preferences/ I then ran the following commands (found on the AFP548 site): It looks like your ldap db is corrupted. 1. Stop slapd with sudo launchctl unload /System/Library/LaunchDaemons/org.openldap.slapd.xml 2. Wait a minute to give slapd time to stop. You can see it in the OD status pane of Server Admin 3. Re-index your ladp db with sudo slapindex -v -d 1 (I like the debug output just to see what it is doing.) 4. Start slapd backup with sudo launchctl load /System/Library/LaunchDaemons/org.openldap.slapd.xml The commands are all one line. Thanks for your help and info DMcCoy. Most valuable. I will be trying a test run of OD-AD in the new academic year i think but for now i will stick with the dual domains. Thanks again.
-
no worries. Funny thing though. After i posted i have started to re-image the macbook trolley we have ready for the new year. I have done 15 so far and each one i have re-joined to the domain afterwards. I joined one to the domain and then unjoined it and created a new image from the machine. Once completed i then went to re-join it to the OD and it failed to pick up the network accounts. I was binding using AirPort so i thought it could have failed to connect in time so i used wired and it still failed. On looking in the KDC log on the server i find its failing its pre auth and decrypt integrity check was failing. I look on the client and its moaning about policies not being right. So i will re-image this machines again and see what happens. All clocks are OK so i'm not quite sure why its now failing. It was OK yesterday night and i have had no problems joining the others that i have re-imaged with the image i took from the one failing???
-
Now i can see it i guess you could be right.
-
I would check them anyway. May have a rogue dhcp service giving out different information. I found this happened with a censornet proxy that was meant to have the dhcp service disabled but still started the service during boot.
-
Maybe dns is manually configured wrongly on the clients.
-
Oh then yeah. I found that issue out with Boot camp. When adding the Mac client to the Ad i used art-01 and then when i came to do the XP partition i then thought oh dear. I can't use that name anymore. I then proceeded to name them differently for both partitions. I found that software doesn't deploy too well from GPOs as well when running boot camp especially under 1.3. I disabled the Apple time service and that seemed to resolve the issue. Software was once again being deployed. "I copy this file to the users folder when they login as part of the loginhook" what file? :-)
-
"I can also supply a preference file that makes printers for users default to A4" This one would be a life saver All the things you mentioned above I had in place. SSL was not used. DHCP came from the AD as did DNS. Manually created OD mapping. Didn't add the boot delay though as when i logged in and then logged back out prefs still did not pick up. Sharing was set to .local and OD was set to domain name. Didn't bind as that created further problems. Only have a maximum of 300 users in the DB so i've got a little distance in my records at the moment :-) I also checked the kerberos time was correct. There is a script on the AFP548 site that looks for updated passwords IIRC and then syncs with OD server? I could have that wrong though and maybe dreamt it one night The only thing i could think it coould be realted to was the network switch since apparently this could impact prefs as well. But i also had issues where the users in the AD needed to authenticate to the mail server which meant i needed to have the AD in the auth on the OS X server on top, which in turn meant i couldn't auto mount the networked home dirs. Apparently the print queues in Leopard have now been kerberised. I tried the script that was available to kerberise the print queues in Tiger but it made no difference.
-
Just re-read the OPs original post. You need to look at how OS X creates its export file. Its not so straight forward as a CSV file. Export the users and take a look at the beginning of each users' section. The Ds sections are what you need to add. Again Passenger is probably (if not the only since i couldn't find any other) the best tool for this job.
-
I have just done this. The reason i did this was because when using integration with AD, prefs just seemed to fail to come down to the clients. When changing users passwords they failed to update in WGM or ODs password server. IE one child asked to have his password changed and the one he wanted wasn't so bad so i changed it and then he failed to log into OS X. I have since moved AD users into the OD so now have two separate domains and so far have less problems. I have since purchased a new gb switch and have taken my G5 to work as the OD replica so may visit the OD-AD at a later stage when time is more of a friend. The way i did it was to export the users, groups from the AD in WGM and then re-imported them after i removed the OD from the AD network. May be better off re-installing the OD Master though. The only downside is that the UIDs for the users are the AD ones and so are everywhere. I mean everywhere in the sense that OS X server goes up in increments like 1024,025 etc. You can use passenger to add the users though if you can get hold of it. It is good software. Its shareware so you can download and use it but theres a limit on the amount of users you can import a one time. Maximum of 15 i think it was. If you rebuild the OD with new GUIDs you will also need to either re-build the homedirs or give the users the permissions again. This is because of the GUIDs being different. They will no longer have access rights to their homes. This is the point i am at at the moment. you can use Passenger to do this too. If you can get hold of Passenger then i would re-build completely and use Passenger to import the users and re-add the permissions to their home dirs.
-
I found the resolution and was indeed to do with the apple auth module. This module allows you to use realms which you specify in the server admin. Create the realm by pointing it to the folder/file you wish to protect and then drag in the group/users you wish to access the folder. Save and there you go. You may need to restart the service. I did anyway just in case.
-
Hello, I have mirrored our site on an OS X 10.4 server which we intend on having accessible by the outside world. I have a staff area currently running on a separate external site which uses .htpasswd to require authorisation for that section of the site. I would like to do the same on the OS X Server but started to think about the best way to authenticate. Does Apache connect to OpenDirectory by default out of the box (like IIS with AD) or do i have to add additional Modules or enable one. I have seen the Apple Auth module in the list but an unsure as to what it does. I am about to look it up now. Being as this means opening another port in the firewall to allow LDAP authentication would it be wise just to use .htpasswd again? All new to me this stuff. Oh the stress of new responsibilites
-
If they have useful comments then i cannot see what the problem is. Like mentioned before the information about security will most likely be found elsewhere on the internet. Letting people of that age on can sometimes be beneficial. They can still read the posts without registering can't they? If they were up to no good they probably wouldn't bother going that far. I think it's the ones that want to know more that register in the first place which means we can also get knowledge from the ones in the classroom i,e dodgy proxy sites etc. Just my opinion.
-
You mentioned a universal boot in this post. While still trying to resolve the issue about automating the OS X and XP installations i cam across this. I immediately thought of you ;-) http://www.macosxhints.com/article.php?story=20060323085045578 May be helpful i don't know. Let me know how it goes :-) PS. You may be interested in this pdf as well. http://it.ga.psu.edu/IT/helpdesk/imac/NetworkMacDeploymentHigh.pdf/view
-
Will have a read through. Thanks for the link. Must be something very wrong with my googling as I can never find any helpful links.
-
I have been trying to get this to work now for a while but cannot get it right. I have set a default image in Netboot on the Xserve and have told the Netrestore image to be fully automated. I have placed the restore_ntfs.sh in the post action folder inside the resources folder inside the netrestore folder inside the image i am trying to deploy. What should happen is this... I boot from Netboot Image (this works). It formats and partitons the drive for bootcamp (this works). It then asks me to specify the image and partition. I have told it to use full automation and use the disk called "Tiger". I am not sure if even when i set this it is suppose to run the post actions but it don't do this either. I don't know if i have got the configurations right. Has anyone else managed to deploy both OS X and XP fully automated successfully? If so...How?
-
Yep. Blocked here by RM too.
-
I will be using an OS X mail server. I will look at whether it is possible to split the 2 (webmail and mail Service) to run on separate boxes. I can't see why not. Well not yet anyway.
-
When did IT techs jobs, stop becoming male dominated?
HodgeHi replied to Pottsey's topic in General Chat
Do you mean face-wise. I usually don't get that far up the body ;-) -
When did IT techs jobs, stop becoming male dominated?
HodgeHi replied to Pottsey's topic in General Chat
I can't see a problem with women in IT at all. Beats staring at the monitor all day :-) -
excellent. The sort of information I was looking for. How do you guys do it? Is it like webman has said or a different variation
-
I could move the mail service onto the replica (dual 1.8 Ghz G5) and the demote back to a stand alone server. Just means i will have a little more work if anything happens. But how would i authenticate back to the main server correctly. I would need to open some pinhole ports in the DMZ and firewall the server itself pretty strongly i would think. This server would also act as the webmail server and possibly host our website. I thought about relaying Mail through a dyndns account to our servers at one point. This is the point where i start to get a little lost. I know what i want to achieve but lack the knowledge to get the most secure and best implementation.
