Jump to content

kingswood

Members
  • Posts

    1,057
  • Joined

  • Last visited

Everything posted by kingswood

  1. kingswood

    Bind Mac to OD

    Missed this one- sorry! Simply open up Workgroup Manager on your server or management system and remove the offending computer object from the directory, and then try to bind your machine again. HTH Paul
  2. Great stuff. If you have multiple domains you can also add multiple paths in that domain search policy. But at least you got it sorted! Paul
  3. Hi there, Assuming you have checked all the usual suspects- which you no doubt have- I would in this case make sure to specify which domain controller I wanted the authenticate against, if only to check that it's an issue with authentication and not something more "Mac-obscure". To do that just use the Directory Utility and Services > Active Directory > Administrative where you can specify "Prefer this Domain Controller". You will have already specified a forest, so here you are just nailing down which domain in that forest you want to use for all the other stuff the Mac needs to do. Check that the box is ticked to "Allow authentication from any domain in the forest"- and in that way you are kind of saying "I want to be loose about who I authenticate against". So what we are doing is really saying, "look I *prefer* marmite, but if it's vegemite I am offered then I'm up for it" Let me know if that helps! Paul
  4. Hi, The other response you have had is a pretty good summary of all that you will need to do to get this working the way you seem to require. The MCX settings on OS X Server are actually pretty cool once you understand how and why things apply the way they do (and often don't), but you will most certainly need an OS X Server on your network to get things the way they should be. At the moment you are simply binding your Apple machines to your AD server and using that to enable authentication against that server for students and staff using the Macs. That's fair enough really- I know some schools that pretty much leave it at that and are happy with the situation. To have your Apple systems "locked down" though you will need to join them to an Open Directory Master server and define preferences to individuals, groups, and computers (and computer groups) much the same way you would with OUs and groups (and users) in AD. The reason you see all your Windows shares when you log on to a Mac with a Windows account is that by default OS X is set up to hunt out those kinds of things and place them in the "Shared" section of your Finder. Makes things great for standalone machines that need to find the wider networked world, but not so good if you are trying to lock your environment down any. With an OS X Server in place you can take out this view from the finder for all users who log on to your systems. It is indeed quite possible to do this. You can also define the "Devices" view and what your users see on their desktops. As the other post stated, you can also have "mapped drives" (called "mount points" in OS X Server) allocated to users dependent on computer group or user group etc., and these act exactly the same as mapped drives in a Windows environment do. Printers: I use our Windows print server as my basis for printers in OS X Server, and even though there are some issues if you don't have a kerberised print service (i.e. it will prompt the users for their username and password the first time they use the printer and never again if they choose to store that information in their keychain) it works. I'm not sure what you mean by "restrict access to certain components", but to give you an idea of what you can restrict simply take a look at Workgroup Manager for OS X Server if you are running Leopard on your local machine and see what it can do (Leopard runs a local Open Directory database so you can use WGM to also manage local machine preferences for users and groups). Integrating an OS X Server into a Windows environment is a tricky thing- I will be honest with you. You will be required to learn new ways of doing things and there will be times when you get frustrated at what seems to be a lack of information and/or features inside of an Apple server OS. With patience though your Macs can become a good citizen on your network and you will learn a bunch of new skills in return. There are nay-sayers even on this forum- and some of them have had a horrible time trying to get OS X Server to work how they need it to. But there are equally as many who will tell you that it works and does so well. I am one of the latter. If you need any further help I am willing to chip in, and I'm sure others would too. Best of luck mate! Paul
  5. We use their software (Network Toolkit etc). The school have been with them now for over 10 years!! We are currently looking at moving away from them, but I don't want to get specific on a public forum. I do agree with others that their staff are nice to work with (although they have lost some of their best engineers of late). We aren't interested in Fronter because we are hooked into another VLE now. If you want specifics or an insider view of CSE then give me a shout via PM and I will be happy to give my story! Paul
  6. We have been running SIMS in every classroom for years. I have been where I am for 4 years and we were running it that way for at least a year before I started. Teachers also have SIMS access on their laptops for rooms that don't have a "set" computer (PE and obscure areas like drama). The *only* issues we have are with staff leaving machines logged in (there are ways around this obviously) and letting students take the register or allowing them to use the stations for normal work! By far this is the minority of staff, but it's still a case of constantly educating the educator about the ramifications of staying logged in or letting students access all that confidential data...some actually listen When all is said it's actually very functional and an obvious evolution to have SIMS available in every room. There's no point in centralising all that data that can be looked at through fairly powerful reporting features in SIMS itself and not having it available to people. Paul
  7. ..you don't see Windows admins listing their certs? Perhaps not on this good forum, but there are some Anyway- reality time. Integration should be planned. It's perhaps not as easy as some make it appear (and that's no doubt because they are good administrators), but neither is it as hard as some responses have made it sound. I think Tony has a point though- we can only really help if we know what your role is in your current post. Even so, if you need help with integration and you are the mover and shaker of your school network I am more than willing to help. Paul
  8. Bah! Humbug! WAT still isn't working for me Paul
  9. We aren't getting the redirect issue this morning, but our bursar and head are upset that their email retrieval isn't working like it did yesterday! We had issues all week with redirect etc., but I have to say that EMBC have been great with us in the past few months- they have given us a bucket load of technical support concerning port opening and VLE setup etc. So it's not all bad (I suppose). I still can't get them to send me a password for WAT though, and that ticks me off. We too have thought about going it alone, but have never (yet) made the plunge...
  10. kingswood

    Revenge!

    Dual independent controller cards each with 128MB memory? Dual hot-swappable power units? Hot swappable cooling modules? Replaceable battery modules? Replaceable controller units? Hot swappable drive units? My XServe RAID has it all. It may not be the best on the market but it has never let me down. I would have preferred more options on a unit its price and size, but for all intents and purposes it is "fit for purpose". I just bought a 4TB Netgear NAS box that is absolutely fantastic and was a third of the price and from what I hear the new Promise gubbins are even better than the older RAID units. With a good choice of storage solutions out there it wouldn't be hard to see why Apple stopped making the RAID unit themselves! I haven't seen any of the issues you are having with AFP or SMB (but nor am I knocking them). Even so, the unit you have purchased seems a best fit for your computing comfort zone. Enjoy it!
  11. First of all, "don't panic" I think the quickest option for you right now (since there is no mention of an OS X Server in the mix) is to bite the bullet and just spend an hour or two configuring the machines the way you need them. Manually put the proxy server address into your machines, or use a script to do it for you; networksetup -setwebproxy Ethernet off networksetup -setwebproxystate Ethernet on The above can be used by utilising SSH on each of the machines? Put the comic life and Office 2008 installation packages onto a share that all your Macs can access and install them from the share (much like you would a distribution point in Windows). This isn't the best way of doing things but without ARD and some experience packaging and deploying applications and images you are a bit limited. Locking your stations down can be as easy as using parental controls to manage a local group/users on the macs (leopard) or else using an OS X Server to push out the MCX settings required (you obviously need OS X Server and at least a Mac Mini to do this from). This is very similar to group policy. Hope that helps even a little! Paul
  12. Sounds like you got a good result there- excellent!
  13. Yep- no problems here when connecting 10.4 or 10.5 clients to Server 2008.
  14. Over 150 Macs (Macbooks, Intel iMacs, G5 iMacs, MBPs, Mac Minis, 2 XServes and RAID) with the following faults: 1 Mezzanine graphics board on XServe replaced (Applecare)- works fine 1 Superdrive on G5 Powermac (Applecare) 2 Batteries on Macbooks (Applecare) That's all folks! On the other hand of a batch of some 25 Fujitsu laptops recommended by County..some *20* have needed new HDDs and some (I think three or four) new screens.
  15. Hi Matey, I haven't seen this issue at our place, but if you are encountering random login problems I would check: 1. The AFP service configuration and logs- just to make sure that nothing is being flagged there as a problem 2. Network connectivity between clients and server 3. Your flakey AD DC. It might well be that this *is* the problem- since the client can't choose (unless you specify) which DC to use it might be worth changing that setting on a couple and see if that fixes the issues. Not much to go on there that you don't already know. But if you find out what the problem is let me know- I'm always interested in logging these things! Paul
  16. Hi, I'm not sure if this is what you are looking for- but if you go here: Emoticônes 3D and simply copy and paste these into a folder on your Mac, and from there drag and drop into your emails you might find that it works. And this may let you use emoticons too (since it's a Yahoo plug): Apple - Downloads - Email & Chat - Yahoo! Zimbra Desktop HTH Paul
  17. There's a good blog entry here: Michael Kleef ::: MSFT : NTBackup is gone from Windows Server 2008? for those interested regarding backup in 2008. It kind of gives the MS thinking behind the whole move. Some of it makes sense- tape backups are a pain in the neck. But I think for now they are a necessary evil. Still, it's nice to know what the thinking was behind the decision!
  18. Well said. Running with least privilege and having the odd prompt or two (or three perhaps) is much better than running all with full access. I wouldn't run Vista this way and certainly won't run OS X this way either. It *is* an approach but a very bad idea all the same. I'll take the nagging. I'm used to it anyway
  19. I don't believe the OP mentioned anything about security not being a concern. They simply stated that the prompts were an annoyance they could do without. There's a world of difference.
  20. Very true Although I believe the main reason for this was the OD Master/Replica model? Still- it is a bit strange Of course it's probably best to change the root password as soon as the server is installed and configured..just to be safe(er). Enabling and using the "root" user in Mac OS X Paul
  21. Exactly Not sure about the DVI converter though- I thought it didn't work but I'm not sure why. Good luck with that- LOL!
  22. If you wanted gaming scores and fps and the ability to buy the latest and greatest (for two months at least) graphics cards for the latest and greatest games, you would have been better off buying an Alienware system
  23. kingswood

    Mac Login Script

    You could try a bash script and changing the extension to ".hook" without the quotes. You need to make sure that you make it executable too. There are some issues with login hooks in Leopard that I have seen floating around, and some solutions suggest copying the script to the local machine and having it start up from there rather than be assigned through WGM. I have to admit that I avoid login hooks like the plague There is an excellent Apple KB article that you can look at to: http://support.apple.com/kb/HT2420 Scarily there are also people who use launchd agent configuration files! Yikes!! HTH Paul Free Mac Support Leopard Workgroup Manager - Can’t Select Login / Logout Scripts
×
×
  • Create New...