Jump to content

kingswood

Members
  • Posts

    1,057
  • Joined

  • Last visited

Everything posted by kingswood

  1. Cool. Just set it as my Vista background- lol.
  2. So with this logic there's nothing wrong with teachers introducing things at the drop of a hat and without speaking to the technical staff that have to make them work? As a big advocate of using Macs where appropriate I'm delighted that someone is trying to do so, but the way it's been approached is shockingly unprofessional and when teachers have done pretty much exactly the same to support staff, the subject of several long rants in various forums here. In the real world it happens a lot. As those threads on here suggest. And it's no different in industry really. It is a problem and I suggested at the end of my response that there should really have been some planning. But the tone of your reply was a little harsh considering the machines are already bought and ready to use. So the best has to be made of the investment. Thus I said he needed to leverage that investment. Unprofessional, or a little naive?
  3. I think that would be a good idea. Once staff receive basic training from yourself (general system use etc) they will probably pick up a lot more than you think and run with it. Unlike others here, I believe you have made a good choice for the school (considering the goal of using them for video editing etc). That being the case, leverage your investment as much as possible and take it slowly. Repeat training sessions as much as possible and be around for support when things start going wrong. If we all buried our heads when things are new nothing would get done. And by not introducing new things into schools there would be nothing new in schools. Innovate. I admit though, a bit of planning ahead of time would have been advisable. But you have them now. So use them. Paul
  4. Without having to pop in to the Apple offices you could start here for staff who will be tasked with using the Macs every day: http://www.apple.com/uk/education/ati/ Then you could look for what are called "Regional Training Centres" and get some staff to look at short courses there: http://www.apple.com/uk/education/rtc/ If you PM me I can put you in touch with some people who sometimes offer on-site services such as training but mostly provide RTC cover. In addition to all that, get your Mac head on and start making up some simple documents and presentations to give to the staff on as many aspects of an Apple system as you think you need- comparison of Finder and Windows Explorer; System Preferences and Control Panel; web browsing; email; applications folder and what apps are in there etc. How to log on and save work blah blah. Benefit is that you will be pushing yourself out there a bit and providing support at a different level and also the training is free 8) Anyway, hope that helps a little. Good luck! Paul
  5. MacBook Pro Core 2 Duo 2.16GHz with 3GB RAM and running a few Parallels VMs for testing and running alongside the school network: a server 2003 R2 VM for training (just finished one MCP now on the other) and two XP VMs- a client for the test VM and one to actually log on to our admin network so I can test Sleuth and SIMS updates etc. The school bought the MBP. We are also probably getting an iMac in our office at some point this year for training our two new technicians on Mac bits and for management of the XServe and XServe RAID. I also just manage the Windows servers from the MBP too using RDP. Works really well. Paul
  6. Spicworks has an official limit of 250 (it is, after all, targeting the small to medium sized business market) but anecdotally it can actually support between 350-500 users/devices. It's only a monitoring tool and so offers no management features. But for free it's still good. I think for Shane's situation where he has a lot less than the 250 maximum (officially intended target range) it's a no brainer. But for me anecdotal isn't good enough. I need it to support upwards of 600 systems. Could test it though and see if it actually scales that well Paul
  7. Hell yes. We haven't got anything else to do with our time- so when MS give us some nice shiny SP to install what more could we want than to uninstall the hotfixes *they* gave us in the first place and *reinstall* these after SP2 is installed with newer *compatible* ones. Yummy.
  8. Unadulterated I told one that today in fact. They have a weird sense of humour- like asking me to teach Year 13 ICT (Excel and stuff). Freaky. Or chasing me round the school to print off ONE colour sheet of some internet safety design a student had completed. I kid you not. Or just jerking me around with fanciful requests for help with ICT in the school. Damn evil.
  9. Nope ... I have spoken to someone else who works at the school (another teacher but someone who is also *very* ICT literate) who let me know it was someone they had ranted to me about on previous occasions. It really is a case of he does not want to know what a teacher thinks ... The OP posted using that title to keep it a little tongue in cheek. Like I said ... others, with little information, jumped in and started having a go. You see this proves my point: I called so-and-so and they told me it was so-and-so who said that they/he/she wouldn't do this/that/other and so it must be true. I have heard teachers tell me that ICT staff in other schools have enquired about my own ICT decisions. Very weird. If you want to know, ask the source. In this case, we won't know for sure. So it's best to say "work together and sort something out for the benefit of the students, not your ego". :?
  10. If that was indeed your post (the original quoted at the start of this thread) then I think you are spot on sir. The enemy in schools' ICT isn't the teaching staff- it's other ICT staff! 8O
  11. http://www.amazon.co.uk/Profiles-IntelliMirror-Windows-Administrator-Library/dp/0782144470/ref=pd_ka_1/026-4353476-3567656?ie=UTF8&s=books&qid=1174339613&sr=8-1 Get it. It's bloody good. :-) Forgot to mention why! ..errmm..it covers RIS, GPSI (Group Policy Software Installation) and things like profile types, registry settings, redirected folders and a lot of the stuff you will need to know quickly. I use mine all the time. I'm not too proud to say that it's saved my bacon a few times!
  12. Definitely stay clear of RAID 5- it's better if you have a lot of sequential reads but a lot slower if you write lots to the DB. I spoke to an Oracle 10g DB admin last year and they have known for years to stay clear of RAID 5- they get a lot slower performance than they would like with that configuration. Basically, I think for a DB you really need RAID 0 or 1 or some combination (10). Enjoy.
  13. Yeah- I would find it very hard to believe that there is *nothing* of interest in the ITIdiot casts if you work in IT at all. I find them very helpful- at times very funny- but always learn something new from every episode. I guess that's the key.
  14. Great news! You are getting further every day- there's a light somewhere I'm a little perplexed that without binding your client to OD you are picking up managed settings from somewhere. Binding to AD only provides authentication/authorisation and identification. AD cannot offer any management of OS X systems or groups. But hey- if it works before you rebuild your network that's brilliant! Yes- I recently took delivery of an XServe and XServe RAID and integrated them into our AD network with the help of a very capable Apple Server Engineer. I learnt so much that day that my notes are chapters long! I had already installed several Apple servers before, but always within an OD domain. I had never integrated except at home on my own systems. The process was very easy and smooth. After the engineer had configured things we took it off the network again and I did it myself so that I could get my head around what had just happened. It's cool stuff. I now have the OD Master pull AD information into in and use that to configure groups and preferences for the Apple systems on the school network. Preferences are running great, and I am about to investigate other things that will help our media and music teams leverage their systems better than they have been. As for Bootcamp: haven't tried that, but I will at home and let you know. It's interesting but we have 10 new Macs (Macbooks and MacBook Pros) and they have gone out to staff, but none have yet been integrated into the domain. The plan was to do this over easter, so I should have fun with them at that time. Anyway, let me know how it goes for you! Paul
  15. OK. Let me try and help you with the login screen problem first. I actually think there are three mai issues here: 1. Wireless connection 2. Services are loading too quickly at startup 3. Your LDAPv3 list is populated with a reference "From Server" rather than the IP address and hostname of your LDAP (OD) server. The first isn't easy to fix, since that's really infrastructure dependent. Can't help you with that except to say look at your channel settings to see if you have overlap problems or buy an Apple Extreme station. There are some problems with Apple wireless connections to third party APs at this time. One issue I am aware of is that if your wireless password is not stored in your Keychain it can stop network services from catching up. Try the laptop with a wired connection and see if it works. If it does post back and we can look at adding your wired password to your keychain. The second is where I would really focus my attention right now. There is a value you can set called "StartupDelay" that holds the login window where it is until everything has loaded behind it properly, and be default this is set too low. It's a simple integer setting and you can edit it by opening WGM on your OS X Server, clicking on the computers button, clicking on "Guest", and then "preferences". Click on the "Details" window when there- and you should see a list of at least two or three PLIST references. Find COM.APPLE.LOGINWINDOW and click "edit". In the context window that appears there are (I think) three main areas- choose to look at "always" and add two new keys. (a) "StartupDelay" (without the quotes) type "integer" and value "30" (b) "AdminHostInfo" type is "string" and value "DSStatus" Reboot at least twice. If this doesn't work, delete the entry in the Directory Access Tool to your OD Master and re-add it, making sure to use its IP address and making sure it finds the hostname in the first field. Uncheck "Contact" if that is checked, reboot and try again. Number (3) has been covered in the above anyway so I won't go through that again. Now let's look at your wider network problems: (i) GPs not applying and causing blue screens (ii) Binding and unbinding Apple systems causing network reboots and instability (iii) OD-AD integration problems I am thinking you are right. A re-build of your AD domain would work wonders for your integration plans. I know it's easier said than done but it really does sound like there are too many underlying problems on the network to be thinking about integration at this stage. LDAP is finnicky at the best of times, let alone introducing it into a shaky underlying network. Server books: Do a search for Schoun Regan on Amazon UK and you should find a book called "Mac OS X Server Essentials". I think it is the best resource to look at and is official Apple curriculum for server training. HTH! Paul
  16. Can I ask why you stopped kerberos on the OD server? I didn't do this at all and it works fine. When you bind to AD your services (HTTP etc) are kerberised, and so long as AD is first in the authentication list AD acts as the Kerberos authority through it all- so your server and clients will use only AD as the kerberos realm and not the OD Master. I haven't read the paper you both are talking about so I'm not sure on the reasoning behind turning kerberos off at the OD Master, but I do know that all of the Apple Server training guides I have state clearly that kerberos should be running when integrating on the OD server. Not saying it's wrong! Just interested...
  17. Hi. Yeah- nested groups are *supposed* to work but I have heard bad things about them. I guess it's a "proof of concept" I have never tried them so can't be sure. What you can do to test the theory is just take out your nested group structure and instead use a dozen or so accounts from AD in an OD group. Change some preferences for said group and then log in and see if they apply. I would be a little worried about the binding process crashing your AD server and the need to reboot it when you unbind. It should be as seamless as joining and unjoining a domain from an XP machine. HTH Paul
  18. I've just finished doing this at our place and didn't have any of those kinds of issues- but it seems to me that there is definitely a problem somewhere in DNS or OD (or both). Reading your post I am assuming that you have put a reverse lookup (PTR) record in your DNS for your OD server and that you also (by inference) have an A record (Host record) in your forward lookup zone too? If you do, at the Mac Server open the terminal and type: Host (IP address of Windows AD Server) You should get a response that sends back the hostname of the server. Then type: dig (Hostname of Windows server) And you should (obviously) get back a valid response. All that being equal, here are a few caveats to operating inside both an OD and AD domain using OS X Server: 1. You really need to install OS X Server vanilla- don't install any services at the start. Just get it installed and patched first. 2. After step 1, install OS X Server as an OD Master. Make sure in the LDAPv3 component of Directory Access Tool that you are in the list of servers and that this is the same for the authentication and contacts search lists. 3. When OD is working properly, use the Directory Access Tool to bind your server to your AD. Generally you only need to put your domain name in the required field and your OS X Server name in the second field. Don't do much else with the extra options at this stage. Check those authentication and contact lists again- make sure Active Directory is first in the search path for both. If it isn't in the list, add it manually. 4. Once completed your OS X Server is a member of AD and an OD Master- which essentially means you get directory information from AD and then can manage Apple systems through OD. It can do more- but at a basic level that's what it sounds like you need for now. If you have done all that in Server Admin you should notice for Open Directory that Kerberos is running. If it doesn't say it is, check: HD > System > Core Services and look for a tool called (funnily enough) "Kerberos". Once opened, use the "Tickets > Get Tickets" command from the menu and see if you have been granted a TGT from the KDC. You only need to "kerberise services" if there are specific things you want to add to the normal kerberos TGT chain- things like SSH and FTP etc are examples of this. Open WorkGroup Manager and see if you can get it to list all of your AD users. If it doesn't then make sure you are actually looking at the Active Directory directory list rather than localhost- just change it if you are by clicking the disclosure triangle. Make sure ALL your users are coming through there. If they are, most of the battle is over. Change to localhost/local directory view in WorkGroup Manager and make a local OD group ("Test" or something) and load some users into that group from your AD list. Five or so would do for a test. Then click the Preferences icon and set a dock preference that puts the dock on the left hand side of your Mac screen and shrink it some. Just so you can test authentication and preferences. On a client make sure you bind to AD FIRST. Then log out and in as a student in your test group. If that works fine, log out and back in as a local admin and now use the same Directory Access Tool to bind to your OD for management by clicking the "Configure" button on the LDAPv3 section of the tool. Put in there the IP address of your OD Master and click continue until it tells you it has found the OD Master. Check your authentication and contacts lists again. AD must be first in the list. Log out and back in as a student. Are the preferences taking effect? Lots of things to go through right now and you have probably been through a lot of them. Sorry if that's the case. For now see if any of this helps and if not post back and I will walk you through some other things you can do to see if we can get this to work for you.
  19. Thanks people. I knew I had picked up the "way things are" correctly and wasn't going (completely) mad. Mmmmm. I think I will have an interesting meeting tomorrow then.
  20. So- here's a question: are the KS3 tests now compulsory, "up to you", or are we to continue doing them until something changes? I ask because I have been told that though they are not compulsory we are to do them for the whole year group until and unless the government change it. Any links I can look at?
  21. The *easiest* way to add the Apple machines to your 2003 network is to simply "bind" them to the AD directory using the "Directory Access" tool found on each system in Applications > Utilities. If you need specific help on how to do that let me know or just ask and I'm sure people will help. This isn't the *best* way to make them members of the AD domain, since you can't lock the systems down this way (group policy doesn't apply to Apple systems). You could run an XServe or some other OS X Server system, but for two systems only I would stick for now with just binding them to the AD domain and letting users authenticate and grab their share when they log in. If by "share" you mean home directory then make sure digital signing in SMB is turned off on your AD server and all should be fine. Like I said, if you need more help just squeel! Paul
  22. Are you testing this for your own evil and (as all techies have one) twisted imagination, or are you seriously considering this kind of complexity for what could and perhaps should be accomplished with those little logical reflections of your organisation called OUs? I'm just thinking out loud that this kind of thing is best left to multiple physical sites rather than one site where you just need a logical representation of your organisation. So, instead of having domains for Staff and Students, stick with OUs for Staff and Students. Maybe you *need* the physical rather than logical structure? I don't know your situation. But to me you are just making lots of work for yourself. Hey- good luck in any case :-)
  23. My thoughts exactly
  24. Having bought lots of new computers in the last year- and with lots more coming this month- I can second Tony's comments. Newness runs out and gives way to neanderthal tendencies :-)
×
×
  • Create New...