Jump to content

kingswood

Members
  • Posts

    1,057
  • Joined

  • Last visited

Everything posted by kingswood

  1. On mine I think it was in the config-dist.php file...might not be the same for yours. And I am trying to think back about eight months...sorry if it doesn't help any. Paul
  2. SIMS. Is. "Nice". Sounds like I am not alone in the two exhausting weeks I have had too. And that was with a patch applied over the summer and re-introduction of a server by .ICT that completely mashed up our admin network. And that's not mentioning that it never used to be my job but on becoming "senior" systems manager they have dumped me with the whole bloody lot! So even though I have had nothing to do with the management of the SIMS network- everyone blames me for inheriting something that doesn't work. Schools are mad. So I went mad. I told the Head it needs re-installing (which to my surprise .ICT are leaning towards now). Hehehe. Apparently the server hasn't been defragged for two years; it only has less than 1GB on the C: partition and our SQL database at nearly 60MB in size is *way* too big. Apparently. And now I'm going on some nice SIMS courses to bring myself right up to speed. Damn. Anyone need a technician?
  3. ...centralised administration...security....sharing of resources...the same benefits server/client network models bring to most organisations that use them. I would guess. The same reasons any school uses a centralised server/client model to cope with the demands of modern computer use in an educational environment. Might be a small school, but the three points above work for a small school, small office, or even a home network setup. Anyway- I hope your users continue to enjoy their network that you have worked hard to build Michael. Well done! Paul
  4. You tend to get the iLife suite with a purchase of any new Mac- sooooo- you should indeed have a DVD with it on somewhere. It is- AFAIK- a separate DVD too. Happy hunting!
  5. Yeah- Dell and HP are the way to go. We buy Dell mostly now and handle installation through just one RIS image- installing our main application afterwards and then Prism Deploying the remainder. Takes about two hours to do a couple of rooms on a good day. Did have problems with the Intel Pro 100 VE chipset from Dell machines- but I just stuck the drivers in the RIS directory and they worked fine from there... NS Optimum? We literally trashed them.
  6. We inherited lots of those trashy systems when we took over our second site- albeit older ones- but still....I would seriously consider doing some research on those things before diving in.
  7. It's a good SLA (as good as they are anyway ;-) but don't rush to implement this kind of thing unless you have more than little old you to carry out the work as principled. Tony has a very good, very skilled, and "on the ball" ICT support structure- they are after all a technology focused school. So it's somewhat easier to take this kind of principle and tell the staff this is how you are going to work from now on. What we have done where we are is *not* implement an SLA for a number of reasons. Primarily because having studied SLAs for an HNC a couple of years ago I had it on good information that they are like the plague- contagious when touched and eat you away quickly! You begin to goal chase. Not always- but the potential is there. Instead we have opted for a priority based support system, whereby we have a four level support structure with "whole school" issues top, schools management systems breakdown (SIMS) a close second, SMT third and fourth left for issues where one or two machines are down or passwords need changing etc. It's not perfect- but it's the same system a certain well known bank uses (I know the administrator there) and it works well for them (with variation). In the end a way of streamlining support and making it more focused and effective is always a good thing. One of my close friends is head of user support for a worldwide operation covering some 6,000 users and thousands of systems and servers. He has HDI certification and is the buck where people stop for support when escalation occurs. They require suppliers to have an SLA, but they won't touch them internally. That's the plague thing again- it might just eat you away with performance measurement, graphs, and targets rather than focusing on problem management (which is what they try and do). He said it best when he mentioned to me that support should never be seen as a service, but instead an integral component of an operation without which the whole wouldn't work. Isn't that a true picture of what we want from schools support? In any case, well done Tony for having the guts to stick your thumb out like this- hopefully it won't get too bloody sore :-) Paul
  8. That just wasn't very nice. Period. Good job other folk chose to help isn't it? As for the advice being over heads- it went right over mine too. I'm no expert at all and not afraid to say it. I learn even from the "basic" posts. Keep em coming is what I say!
  9. Documentation of the network would be better (I think). If a Systems Administrator documents the network, its settings, and password- and stores this safely- then there is no need for this "nuclear bunker" type thing where you rip open the envelope and make sure the keys match and then type in synchronicity on the count of three... I use a Network DNA type of system where telephone numbers of contacts, account details, contractors, policies, passwords etc are printerd out and stored in a folder in the server room marked "Network Documentation". It would be easy to find. Having said all that, it isn't a *bad* idea so long as the Head doesn't open the secret envelope just for the hack of it! ;-)
  10. I agree with Geoff. Doesn't make any sense from a security or technical standpoint to have people all over the place who are "administrators". The schools' network would become a mess all too quickly. Good luck!
  11. The Power User and User groups appear at will- we don't put them there. Traditionally we have used the more secure Authenticated Users, but it seems since this last update something has gone wrong with the permissions. Anyway, setting Authenticated Users with Full Control over the SIMS and IDAPI folders seems to have worked. On the other hand, adding the domain user group of Staff to the local Power User group also worked- so it's definitely permissions issues we are having. I'm now thinking that I should use something in their logon scripts that will add them to the local PU group and give that group full control... What do you think? Thanks in any case- good advice! Paul
  12. That's interesting Tony. We recently applied the latest SIMS updates and now the workstations have Power User, User and (because of our helpful Systems Manager) "Everyone" in there too. Permissions are pretty screwed. What I have been doing (because LM won't run under these farcical conditions) is taking out Power User, User and Everyone and making Authenticated Users have "Modify" access on C:. Windows and Program Files etc as per old Capita instructions to us. It works. Until the user logs off that is. Now the permissions are reset and when they are SIMS stops working...So we go around in a wicked circle of resetting permissions- works; user logs off and then on again- permissions blitzed again. Anyone have any idea what the hack is going on here? ...need coffee
  13. Easy one this: http://support.microsoft.com/kb/q231289/ That document helped me when I needed to do it (for a 2000 Server/XP Client domain- although checking the article it is valid for your setup too).
  14. Yep- I used my Beta 2 key for the RC1 download. Worked fine.
  15. :-) Shouldn't of had that last beer ;-) Quite right Ric. Apologies.
  16. Hi. 1. Should be fine through a GPO-- where are you setting this and how? 2. An update of AD? Do you mean get your Group Policy changes to apply when you set them so you can instantly check whether they are working? If so you can use: gpupdate /force at the client/server. Secedit is used for security comparisons and details can be found here: http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/secedit_cmds.mspx?mfr=true 3. Tools for AD? I'm not sure what you mean here, but so long as you have GPMC and ADUC you should be fine until you get more experience. The Server Resource Kit Tools are pretty good too- but it depends what you want to monitor/carry out with your server. There are tools for just about everything just like there are standard tools and preferential tools- depends on the admin really! 4. You can make changes to the server from a client by using RDP (Remote Desktop). Type MSTSC at the Run box on a client and if you have enabled RDP on your server you will be able to do most things "remotely". 5. Check you "all users" profile locally. Are you redirecting start menu items? 6. I think someone answered this one.. 7. Log on using a dummy (test) account and see if things are applying. Run a GPRESULT or RSOP on the local machine to see if the domain wide and other group policies are applying and that nothing is getting left out somewhere. Test, test, test and test again to make sure permissions and profiles are as good as possible before going live. Remember that with the power and scope of group policy management you can always adjust as needed- just have that test account to work with and you should be fine. Good luck! Paul
  17. Downloaded mine last night. It's good. A great improvement over the last lot- a lot faster, more stable, lot more usable. Good one MS. Might now try it on a machine at work to see how it "plays".
  18. The core OS. The stability (as a consequence of the first point really) The integration (hardware/software) The applications- the iLife suite and the Pro tools are simply better than anything you can get for Windows. The security- I don't (unlike Tony) buy the "Mac share is smaller thus less likely to be targeted" line, but because of its Unix underpinnings OS X is much harder to write viruses for and less likely to fall over if infected the way Windows does. Apple tend to patch better and faster than Microsoft anyway, so it's less of an issue. As Tony mentioned, the UI is much better. Far superior to anything Windows (even Vista) offers and only surpassed (I think) by some of the things happening in the XGL development flow. Geeks? I use VPN, OpenSSH, Apache, PHP, MySQL, Moodle, GIMP, Gunumeric, Inkscape (mostly from Darwin Ports or FINK) on OS X. I use the command line most days for many tasks, and I am learnign Objective C using XCode as a development environment. Geek factor? It's definitely there- and not even with the Unix side. You can take any of the applications that come with OS X and script them with Applescript, tune the OS, set security and firewall preferences, tweak individual applications, and be far more productive using iLife and .Mac for example than you can in Windows. Having used Windows since late DOS days, I can say OS X blows away the competition easily for an integrated platform. That's without mentioning SAMBA, networking, OS X Server and so on... But is there anything you can specifically get on OS X you can't get on any other platform? Probably not unless you are being subjective. For me the answer would be no; there is too much integration in OS X that makes my computing life so much easier than any other platform. It "gels". :-)
  19. Yeah- I initially had this problem and killed it by dropping SMB digital signing at the AD server...worked a treat.
  20. http://www.bombich.com/mactips/nbas.html And here...
  21. http://forums.bombich.com/viewforum.php?f=11&sid=e88a384a4ee27eebff7527a8959cc693 Forums are pretty good there- but there should be no problem restoring across subnets I don't think. Take a look.
  22. That would make Tony "The MacFather"
  23. The MacAFFIA are here! No problems- I dont think there is any "right" way of trying to make OS X and AD integrate with each other, or any definitive way of imaging a system. Bombich has some excellent tools out there, and of course you can use whatever method suits you. Actually you gave me some ideas... ARD would benefit you an aweful lot though Tony (as you will know), but until then you can always use Package Manager to make packages of applications you want to push out with your system images. It's not easy- as you no doubt know- but it works (read: can work). On our test LAN we are using OD > AD. I'm not sure that during the October break we will go for that. Perhaps a straight through authentication to AD would be better- and that's what I have been using on live machines up to now because media were reluctant to lose their shiny G5 tower as a server (I'm thinking Mac Mini for that now after having been told to do that by Apple Staff at the Birmingham store). I don't need anything on the server other than the ability to lock down the machines and their preferences (right now), but that might change. The Head and I are agreed that right up until the new build Macs will get a lot more attention- and they have some very cool things planned for the build that will mean expanding the Apple influence a lot more. How are you rolling your integration now then? Similar, or are you jumping in with both feet? Paul
  24. Errrmmmm...that's a lot of work there Tony! If it keeps ya happy ;-) It's not wrong, but I just wouldn't go through those hoops. I started (Ric_) running a test NetInstall image from the OS X Server using a generic image type. There are manuals on how to do this in PDF format on Apple's server pages. Then I can name the machine, bind it to AD/OD and lock down preferences for just about everything using WorkGroup Manager. I would test all this first- and it looks like Tony does the same thing. Which is good, because things on the Windows side can go wrong. And it can be more complicated than the above..depends on your configuration. By the sound of it though you just want an image you can push out from your server a la RIS. In which case NetInstall can do it fine. Of course you could use NetBoot, but I would take a look at the documentation for that one first. It has some advantages. Another recommendation I would make is that you really look at Apple Remote Desktop. I haven't seen anything like this for a time- and software deployment is a lot easier to your Macs from ARD than using any other method I know of. You can of course control Windows machines with ARD to- you just need a VNC client on the XP machine. But yes- NetInstall all the way. Want to lock it down? Use your OS X Server centrally to push out your evil plans.... Paul :-)
  25. kingswood

    Ccleaner

    It's frickin annoying! You know that it deletes the Windows prefectch folder contents. That's OK if you want XP to get slow again (prefetch is quite an important technology in XP and in Vista too with its Super Prefetch). I think they have moved this little feature to the "Advanced" section and disabled it by default, but it doesn't warn you when you do turn it on. I even know some people who delete the prefecth folder by choice--hahahah! It also has problems with messing up file extensions on some systems- do a Google search. File processing is slower than some alternatives. I refuse to use little applications like this and just go route one- re-image. I might occasaionally use it on my one windows machine at home- but I don't use that much at all now. It's a decent application if you don't mind something abstract wrking away at your file system the way it does. :-)
×
×
  • Create New...