HodgeHi
Members-
Posts
2,226 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by HodgeHi
-
Ok, I have gone through your list of things with a brand new install both OS X Server and client. Have restarted the DC with Computer accounts deleted ready for the new re-bind. I have slowly gone through the list one at a time. I got to the point where it says to join kerberos when joining the AD. I did nothing. I did not use the SSO_util to join and left the OS X server running the kerberos on the OD. I then proceeded to the workgroup manager and found that i could not access the active directory users. I re-checked the directory access and it was fine. I restarted the server and this must have triggered something as i could now access the active directory users. I then proceeded to create a group on the OD and dragged one User in to the group (my username). I proceeded to configure the client at this point. I joined to AD FIRST like you said to and then proceeded to joing the OD. I logged out and found that i could not log in as my AD user. I logged back in and checked the Directory Access and everthing was in the correct order. So i restarted the client. Upon restart i logged in as admin (the other ball does not come up at first, but i think it is down to the airport connection as opposed to ethernet) then logged back out. I c hecked the info on the login screen and found a yellow ball saying some network accounts are available. Something is not right. I don't know what it is but it is really fustrating as i think it is close. But i can login as the AD user but it does not get the managed settings. One point is that when i tried to unbind from the OD it could not find it. I find this quite strange since it had no problem when binding and using Host in the terminal along with dig brings a correct response.
-
I also had a problem with this svchost.exe and upon reading this thread have probably just found the reason why. My problem was the svchost was crashing constantly throughout the day. It would suggest that it is due to the WSUS i have just implemented if these issues are Windows update related since i didn't have this problem previously.
-
Yeah, Me too. I have had quite a few problem with my network in general. So it looks to be a complete rebuild of the domain too see if it resolves the issues. I just can't seem to pin down the problems the clients are having logging in. Sometimes they pull all the information from GP other times they just get a blue screen. But thats another issue. Right now i would just settle for something to work. where did you get these from? Are they freely available? There is a integration meeting comping up in Toronto. Just need to get the boss to OK it!! This was my next port of call. Once i restart the DC (the main on as well) and then rebind the OS X Client. I have left it overnoght as well so it can't be a replication issue. Thanks for your help by the way.
-
It is said that although Tiger is supposed to be able to cope better with the different realms than Panther it is still advisable to turn off the kerberos realm for the OD so as not to have any confusion for the client swhen being biinded to both directories. So this is what i did. The doc is on the Mike Bombich site if you wish to read: - Leveraging Active Directory on Mac OS X
-
All of the preliminary tests of the DNS seem to come back positive. I checked the Host command on both the FQDN and the ip and it resolved correctly both times. I checked the Host Name using the scutil --get HostName and it came back fine. PTR and HOST records are in the AD DNS. I proceeded to promote the OS X server to OD Master and then bind the server to the AD in that order as per the leveraging doc, checking the authorisation order as i went. During the bind process i use the setting FQDN of AD server, computer id of OD server, allow administration by AD admins, no preferred servers, allow auth from any forest. This process completes OK. (Ihave noticed however that when unbinding and then re-binding i HAVE to restart the AD server since the re-bind will ALWAYS crash Directory Access and will not bind until it has been restarted). The binding to both AD and OD are now working since i can go to WGM and create Managed groups in the OD side and then use AD groups inside of these managed groups to manage preferences. When configuring the client the procedure is the same except i bind to AD first. I did not check each bind beforehand however. I proceeded to restart the client and then upon seeing the login screen scanned through the information in the menu and found that only "some network accounts were available". Once logged in with an AD user i checked the kerberos app and had indeed been granted a kerberos ticket for the AD Domain. But the managed preferences were not applied. Could it be the AD Groups inside the OD Groups? I don't imagine it could be since it suppose to support nested groups. Kerberos has been stopped on the OD as per the leveraging doc using the SSO_util. This is now where i am stuck as it were. Just need the preferences to apply then i can move onto the next part of moving the home directories to the network share and checking the kerberos services. Thanks for your help by the way. Most appreciated. PS Which apple whitepaper? Is this the one from their server documentation on open directory services?
-
Hello all, we have just taken delivery of some imacs and a macbook mobile trolley. We plan to use the laptops and imacs for both windows and OS X and that in turn means we need to be able to maintain the security of the OS X side of things. We currently have a small mac mini running the Serve side as it should do for what we need at the moment (until the new financial year anyhow). The problem i am having is integrating the OS X server into the AD domain with full kerberos support. I have setup the DNS on the AD and have set up the pointer for the OD server which is recursivley resolving. I have joined the OD server to the AD using the Directory Access and have then procedded to join the Kerberos realm which was successful (i think as i didn't get any errors). I then made the OD a Direcory Master and then moved the Active Directory above the LDAP in Directory Access in the authentication tab. I can access the Active Directory through the WGM and see the users and groups. I can also connect to the OD and create groups to add the AD users to to manage them. But the managing does not take hold. This is true to both users and computers. Upon joining a OS X tiger client to the AD and OD to manage both user and computer upon the login window it says only some accounts are available. I think this is the problem but do not know how to solve it as i don't know where the problem lies. I think it is something to do with AD OD configuration in the directory access but i don't know where. But using the AFP whitepaper to set things up i get a problem when logging into the windows box and trying to access a home share on the OD Server. It asks for a password but should not since Kerberos is working. So i have a problem on both OSes at the moment. Any help resolving these two issues would be fantastic. For more information on my setup please see this post of some more questions. AFP548 PS sorry for the long post. Cheers
-
Hello, I don't know if this is right but it sure as hell don't sound like it... I have just started to dabble in the deployment of software through AD. I have set up a GPO specifically for this and linked it to the main OU which has the OUs for the rooms where the PCs are kept. I have managed to get the software out to one computer since configuring the policy and thought it odd that it hasn't deployed to the rest. I started restarting the pcs to allow them to start installing the software during start up but they didn't so i logged into one and just restarted the machine, nothing else was touched. Once restarted the managed software started to deploy. This was the case for each machine that i logged into. Am i missing something?
-
You can also disable the service remotely as well using the sc command.
-
I do have the patience of a saint when it comes doen to something that needs to be done but also WORKS like it should. I would like an alternative to this and have been looking at creating some sort of csv file to do it. Is there not a export option for one of the command line utils for AD to export to a csv file. Not sure what the output file is like though. While on this subject i have just re-built a censornet server and created a back up of the previous server to restore to the new one. But when restoring it said it would automatically restart, but it did not. I then proceeded to restart manually but did not see the users in the list. I then re-didi the restore and again it did not restart and also i did not see the users and computers re-entered into the list so i had to have the patience of the saint and re-enter the users into their groups. Took about 15 minutes to do re-import. All you need to do is import each ou then browse the list for the (none) group users and select each one and move to appropriate groups. Not telling you thats what you should do just how i do mine at the mo.
-
I would like to help but i just imported each ou then while connected via webadmin used select all and move them into the appropriate group on censornet. I did this for each ou.
-
Psp is now currently hacked to the latest firmware (i think or at least the one before). This allows you to run all of the updates and items Sony have released and also allows users to run ISOs of their old PS1 games. And if you still have the ability to create the isos yourself then you can use those. Cool Stuff!!
-
I have called K. Chandler in to have a look at the issue that i was getting as the clients were getting the router address for dns entries instead of the dns for the main server. This was leading to the machines obviously failing to log in correctly. I tracked down the issue before he arived which ended up being that the censornet had been turned off and restarted during the hols because the pat testing had been completed. I DID NOT know about that!! But i still have issues with the clients failing the kerberos test during the net diag. I asked Keith Chandler and his response was that he didn't know. So my question is, does any one else? My clients log in fin enow but still when the room logs in there seem sto be the issue where some clients end up with just a blue screen for ages. but when restarted they seem to be fine. Is it a case of the server being bogged down with too many requests at once?
-
Have a look on the Pinnacle forums. Maybe some information on there that may help. I would also recommend checking on there anyway to see if there are A, any updates for your version and B, if they actually work. I had version 9.4.3 if i recall the version correctly which just basically broke the software and the only way to get it working was to purchase v10. Personally i would forget about pinnacle all together and run some mac software if possible, since it does the job very well, but thats just my opinion, as when i used to use it there were a tonne of dropped frames and sync issues with the software. Maybe (hopefully) these have been rectified in your version, and it does also depend on what the users plan on doing with the software as well. Just my rant on the Pinnacle stuff (which i used at home and at work for about a year and have now switched to iLife). Good luck with the deployment anyhow.
-
Hello, SInce the snow has stopped me working, i decided to get a problem of my own out of the way at home. Except i haven't managed it yet. I have been trying for a wek now and still cannot get it right. The issue is i have moved my mac mini to a seperate room from the router along with my G5. Now the macmini will be my server to test out deployments etc but my G5 needs access to the internet as well as it is my main working machine. I need to set up the server as the gateway to the interent via my router wirelessly. I have tried the gateway assistant but it doesn't give me interent access on either the server OR the g5. I have tried moving the ports around in the port configuration in sys prefs and it allows access on the server to the internet but then the g5 cannot find the server for the accounts. The nat is also blocking the serial support port but when i look at the settings on the firewall they all seem fine. Again it looks to be a dns issue but i can't see where. *Note to self* I need DNS training!!!
-
There is currently only one server now that should be listed as an srv record as the other two DCs have recently been demoted ready for -reinstall. I can't confirm at the moment as i am not at work (not in the building anyhow). But the DNS on this machine just points itself and then the forwarder is to the censornet box. Does the censornet box run its own dns? I have set the dns settings on the censornet external connection set to the router to deal with and it seemsto be working ok. Clients access the interent ia the censornet box and everything gets resolved internally. One problem i have though as mentioned 5 posts ago is the pinging resolutions. Is there any other information that is needed to help me resolve these issues? I have run nsloolkup with regards to the srv records and it resolves i think correctly with the response of one record which is the main controller.
-
No it doesn't really apply to me. I type the pevious response incorrectly it should have been the other way around as per the KB article. I have since removed the computer from the domain and the re-joined it to find that the kerberos has passed but the dns has now failed saying it is wrong on all dc's.
-
OK. Ihave managed to run the netdiag tool on a client and the server. The server just states a couple of errors regarding the netBT but on a search these seem to the norm (about a workstation service and a messenger service not running). The client on the other hand fails the kerberos test with the following: Kerberos test. . . . . . . . . . . : Failed [FATAL] Kerberos does not have a ticket for host/ICT-01.CRONEHILLS.SANDWELL.CO.UK. I have tried a search but can only find things that point to ruuni9ng win2000 server under a 2003 domain. But i ain't doing this? I have just run it on a second client with the same output. I am now trying each client.
-
Wireless bridgeing and Active directory replication
HodgeHi replied to HodgeHi's topic in Wireless Networks
Thanks for that. I have flicked through quickly but looked good. Will read it properly later. I like the "turns firewall into swiss chesse" statement. -
Wireless bridgeing and Active directory replication
HodgeHi replied to HodgeHi's topic in Wireless Networks
It is now working. The main problem i thought was security but it seems that was not the case. I don't understand why but when i went to demote the server it failed with a security warning but now it seems to have succeeded...well its started anyway, finishing remains to be seen... Thanks for your help. -
There is probably a underlying DNS issue as before i got here the servers were migrated from one domain to a new domain name and the dns still holds the old domain name entries. There is a reverse lookup for the external range that the main server used to forward requests to the router. This was used as the gateway. I do think that a fresh dns database is needed but am unsure about how i would install dns fresh without upsetting the active directory as it is integrated. Would it be just a case of uninstall and re-install? One other thing that is bugging me is when i ping an unknown computer name (one that i know doesn't exist) i get a response from an external ip of 212.227.34.3 everytime. This suggests to me a dns issue also, but there is only one dns server online that forwards requests to the censornet box for external addresses.
-
Wireless bridgeing and Active directory replication
HodgeHi replied to HodgeHi's topic in Wireless Networks
Hello, I am indeed using two dlink products mainly because they were the cheapest brdiging ap i could find. They are the DWL-2100ap's. I should have learnt my lesson from the last ones really but no... The APs are in the WDS+AP mode that they support and was relativley simple to set up, but replication across the bridge seems to fail. I thought i would just be security across the connection that was the problem but i don't really know if this holds true since i am not sure that replication traffic is secure in general on the wired network anyway. I don't run any ipsec or other means of securing network traffic other than a firewall to block any attacks. -
Thanks for that i will try netdiag tomorrow. I understand what you are saying about the curing the causes, its just difficult to do anything when everyones moaning about log in time but then won't leave the clients alone long enough to repair them. I was hoping that it was something i could do at the server end to resolve the issue. i know that machine is free.
-
Hello, I have set up a wireless bridge between two buildings (building A has main network and building B has some un-networked PCs with no internet access) which will serve as the connection to the internet. What i would like to do is place a server over in building B to allow authentication on that side of the site and use that server for profiles etc for that building. The problem i have run into however is replication across the wireless bridge. It doesn't replicate. I think it is a problem of security on the wireless bridge as using replmon it says something about being an unsecure connection?? If this is the case would IPSec over that section resolve the issue? If so how do i go about configuring it for that part of the network? Sorry for all the questions but its a first for me.
-
So is it best to leave it as unsecured?
-
i recently set up secure dynamic dns for the AD as this was set to unsecure and secure. Would this have an effect on the machines registering their dns with the active directory?
