<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jason Lee &#187; OSX Domain Integration</title>
	<atom:link href="http://jasonmlee.net/archives/category/osx-domain-integration/feed" rel="self" type="application/rss+xml" />
	<link>http://jasonmlee.net</link>
	<description>bytes about bits in church IT</description>
	<lastBuildDate>Mon, 06 Feb 2012 16:07:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Mac .ds_store Files on File Servers</title>
		<link>http://jasonmlee.net/archives/419</link>
		<comments>http://jasonmlee.net/archives/419#comments</comments>
		<pubDate>Thu, 03 Mar 2011 22:16:51 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[OSX Domain Integration]]></category>
		<category><![CDATA[OSX]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/419</guid>
		<description><![CDATA[If you have a hybrid environment of Mac and Windows File servers you probably have seen several file types that the Macs leave around the file server.&#160; Most of the time you will see .ds_store files appearing where ever a Mac has browsed the file server.&#160; These meta data files are used by the macs [...]]]></description>
			<content:encoded><![CDATA[<p>If you have a hybrid environment of Mac and Windows File servers you probably have seen several file types that the Macs leave around the file server.&#160; Most of the time you will see .ds_store files appearing where ever a Mac has browsed the file server.&#160; These meta data files are used by the macs telling the finder how to display, where to appear on the screen, what view to use etc.. but becomes problematic when you have a few users with different resolutions or systems with and without dual monitor are browsing the same file server.&#160; Some backup solutions and DFS Replication can have issues with these files as well.</p>
<p>Apple documents the ability to turn off the .ds_store files here: <a title="http://support.apple.com/kb/ht1629" href="http://support.apple.com/kb/ht1629">http://support.apple.com/kb/ht1629</a> but isn’t totally complete in the instructions so I have documented the process here.</p>
<blockquote><p>1.&#160; Open Terminal.      <br />2. Change Directory&#160; <br />&#160;&#160;&#160; cd ~/library/preferences       <br />3. Write the plist file with the following command:&#160; <br />&#160;&#160;&#160; defaults write com.apple.desktopservices DSDontWriteNetworkStores true</p>
<p>4. Read the plist with the following command      <br />&#160;&#160; defaults read com.apple.desktopservices DSDontWriteNetworkStores       <br />4. Either restart the computer or log out and back in to the user account.</p>
</blockquote>
<p>This applies the setting to the current user but does not impact any other users.&#160; To apply this to all future users who login to the machine copy the .plist file from the user directory to the user template with this command:</p>
<blockquote><p>Sudo cp ~/library/preferences/com.apple.desktopservices.plist      <br />&#160; /system/library/UserTemplate/English.lproj/Library/Preferences</p>
</blockquote>
<p>If you need to disable .ds_store files for an existing user use this command:</p>
<blockquote><p>Sudo cp ~/library/preferences/com.apple.desktopservices.plist      <br />/users/&quot;username&quot;/library/Preferences</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/419/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Apples just work?</title>
		<link>http://jasonmlee.net/archives/162</link>
		<comments>http://jasonmlee.net/archives/162#comments</comments>
		<pubDate>Mon, 11 Aug 2008 17:12:56 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[Church IT]]></category>
		<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/256</guid>
		<description><![CDATA[ Apple&#8217;s claim: &#8220;It just works&#8230;&#8221; but when it doesn&#8217;t the support is HORRIBLE!
Last week we decided to re-format a PowerPC G5 to replaced the current OS (10.3) with the the new Image we created and integrate this G5 into AD.&#160; 
When we tried to boot the G5 from the NetInstall service the big globe [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 0px 5px 0px 0px" height="162" src="http://images.apple.com/uk/business/macatwork/images/macatwork_applecare20070930.jpg" width="167" align="left"> Apple&#8217;s claim: &#8220;It just works&#8230;&#8221; but when it doesn&#8217;t the support is HORRIBLE!</p>
<p>Last week we decided to re-format a PowerPC G5 to replaced the current OS (10.3) <a href="http://jasonmlee.net/archives/244">with the the new Image we created</a> and integrate this G5 into AD.&nbsp; </p>
<p>When we tried to boot the G5 from the NetInstall service the big globe comes up, then the smaller globe, but then it goes to a window that reads: &#8220;You need to restart your computer. Hold down the Power button for several seconds or press the restart button. After the restart the same error displayed.&nbsp; I checked the image server and all the services appeared to be working correctly so I contacted AppleCare Tech support.&nbsp; </p>
<p>I have learned how to get thru to enterprise support on the AppleCare voice prompts by saying &#8220;OS X Server&#8221;.&nbsp; After waiting on hold for about 15 minutes I was greeted by the technician and gave the appropriate information and then told him about my problem.&nbsp; The tech instructed me to try booting from the CD to try installing the OS from the CD, which I did and the install prompts displayed.&nbsp; So I asked the tech, so how do we fix the issue with the NetInstall Image not working, and following conversation was worth noting:</p>
<p><em>Todd: You need to install from the CD since there was an issue with the NetInstall.&nbsp; </em></p>
<p><em>Me: I have used the NetInstall before and it worked well, what can we do to trouble shoot the NetInstall/NetBoot service so we can use our PowerPC image with applications and drivers already configured?</em></p>
<p><em>Todd: It isn&#8217;t an issue with Apple Server, but your image you created. Are you sure this is an image of a PowerPC?</em></p>
<p><em>ME: Yes its a PPC image. The image has worked on several other PPC installs, what is causing it to fail now?</em></p>
<p><em>Todd:&nbsp; I don&#8217;t know, but since the installer works from the CD, it is an issue with your Image.</em></p>
<p><em>Me: I know its an issue with the Image, but what can we do to fix the problem.</em></p>
<p><em>Todd: Install from the CD.</em></p>
<p><em>Me: (Getting annoyed) But the Image has all the configuration for our machines, and the CD install doesn&#8217;t I really would like to have you help me get the Netboot Service working, can you not help troubleshoot the image service since&#8230;. well its is part of OSX server.</em></p>
<p><em>Todd: The Install from the CD works so you should use that, I don&#8217;t know what else to tell you what to try.</em></p>
<p><em>Me:&nbsp; Is there anyone else that can assist me?</em></p>
<p><em>Todd: No, but here is my email address if you find any additional information that will help us solve the problem you can email me.</em></p>
<p><em>Me: That is ridiculous, and you aren&#8217;t able to assist me?</em></p>
<p><em>Todd: That is all I can help you with, thank you for calling apple care, I hope we can assist you in the future.</em></p>
<p>I got off the phone and began &#8216;googling&#8217; the error message and found this discussion on the apple web site: <a title="http://discussions.apple.com/thread.jspa?messageID=7698665" href="http://discussions.apple.com/thread.jspa?messageID=7698665">http://discussions.apple.com/thread.jspa?messageID=7698665</a>. After copying the images to another location, deleting the Share Point, copying the images back and restarting and reconfiguring the service all was well.</p>
<p>Then the best part is getting the support evaluation request from apple&#8230; Are you serious?&nbsp; I was tempted to ask if they were using the Abbot and Costello&#8221;Who&#8217;s on First&#8221; sketch as a training tool.</p>
<p><strong><em><u>Shame on you Apple Support</u></em></strong>&#8230;.Yeah Apple Community forums!</p>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/162/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Mac and Microsoft RDP</title>
		<link>http://jasonmlee.net/archives/160</link>
		<comments>http://jasonmlee.net/archives/160#comments</comments>
		<pubDate>Wed, 30 Jul 2008 14:19:52 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[Church IT]]></category>
		<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/255</guid>
		<description><![CDATA[With our recent push to better serve our mac users, I have used the Mac on my desk a little more&#8230;. I wish I could report that I use it a lot more but that&#8217;s just not true.&#160; 
 I have been using Microsoft&#8217;s RDP client for the Mac and it has been working well.&#160; [...]]]></description>
			<content:encoded><![CDATA[<p>With our recent push to better serve our mac users, I have used the Mac on my desk a little more&#8230;. I wish I could report that I use it a lot more but that&#8217;s just not true.&nbsp; </p>
<p> I have been using Microsoft&#8217;s RDP client for the Mac and it has been working well.&nbsp; RDP allows me to connect to a windows server while I am also remotely connected to our OSX Leopard server.&nbsp; The one issue with Mac RDP was not being able to connect to the Windows Server Console&#8230; but alas you can.&nbsp; If you enter the server name /console in the address bar it connects you to the console session of that Windows server. </p>
<p><a href="http://jasonmlee.net/wp-content/uploads/2008/07/snapshot-2008-07-30-09-17-04.jpg"><img height="129" alt="Snapshot 2008-07-30 09-17-04" src="http://jasonmlee.net/wp-content/uploads/2008/07/snapshot-2008-07-30-09-17-04-thumb.jpg" width="389" border="0"></a></p>
<p>Just chalk it up to another fact that may be totally useless.</p>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/160/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Rolling out a Monster Rig</title>
		<link>http://jasonmlee.net/archives/152</link>
		<comments>http://jasonmlee.net/archives/152#comments</comments>
		<pubDate>Mon, 14 Jul 2008 18:00:02 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[Church IT]]></category>
		<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/245</guid>
		<description><![CDATA[ As part of our OSX and AD Integration we are rolling out a new video production rig to our media dept.&#160; This project has definitely been more than just purchasing hardware and dropping it on a desk and walking away, but learning how to serve our Mac users in the process (allowing those users [...]]]></description>
			<content:encoded><![CDATA[<p> As part of our OSX and AD Integration we are rolling out a new video production rig to our media dept.&nbsp; This project has definitely been more than just purchasing hardware and dropping it on a desk and walking away, but learning how to serve our Mac users in the process (allowing those users to start to become equal citizens on the network) has been a good adventure.</p>
<p><a title="MacPro-1" href="http://www.flickr.com/photos/23086965@N05/2667196417/"><img alt="MacPro-1" src="http://static.flickr.com/2183/2667196417_d3e8fd79c6.jpg" border="0"></a></p>
<p>This new mac is a Quad Core and so far the beast works really well.<br />The Hardware: Quad Core 3 ghz Mac Pro with 10gb of memory, Dual 24 inch Dell Displays, Dual SuperDrives, a 250gb primary volume and 1TB scratch disk and 250GB TimeMachine Disk, 12&#215;6 Intuos Tablet.&nbsp; <br />The Software: Final Cut Pro, and Adobe Production&nbsp; Premium.&nbsp; Beware FCP takes about 6 hours to fully install. (We went with Adobe&#8217;s Production Suite even though we don&#8217;t use Adobe Premier since it was MUCH cheaper than purchasing Design Premium and then adding After Effects&#8230; Thanks to Nancy at CCB for that little nugget.)</p>
<p>Dave our Media director has been VERY eagerly anticipating the arrival of his new &#8216;baby&#8217;, and we delivered the hardware to his NEW office on Friday&#8230; I wish he would show some excitement <img src='http://jasonmlee.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Thanks to our campus services team Dave has a mondo huge keyboard tray that even holds his tablet and keyboard&#8230;&nbsp; </p>
<p><a title="MacPro-2" href="http://www.flickr.com/photos/23086965@N05/2668018540/"><img alt="MacPro-2" src="http://static.flickr.com/3163/2668018540_53766703c7.jpg" border="0"></a></p>
<p>Stop grinning Dave and start cranking out some more cool videos!</p>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/152/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cloning the Macs</title>
		<link>http://jasonmlee.net/archives/151</link>
		<comments>http://jasonmlee.net/archives/151#comments</comments>
		<pubDate>Thu, 26 Jun 2008 16:00:50 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[Church IT]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/244</guid>
		<description><![CDATA[Don&#8217;t think that I am a proponent of making the Macs on our network multiply, but rather making those on our network look the same&#8230; One of the keys to our AD and Mac integration was reducing the time it takes to deploy a mac on our network.&#160; Earlier this year when I had to [...]]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t think that I am a proponent of making the Macs on our network multiply, but rather making those on our network look the same&#8230; One of the keys to our AD and Mac integration was reducing the time it takes to deploy a mac on our network.&nbsp; Earlier this year when I had to reinstall a mac book pro it took over 6 hours to install the base software and drivers (items that every user gets) in addition to installing the components that each specific user needs.&nbsp; Knowing this was taking way too long I was on a quest to make this less painful.</p>
<p>Enter Apple Server&#8217;s System Image Utility&#8230; The Image utility allows for you to create a base system, prepare it for deployment over the network and distribute it to similar clients (Intel or PPC).&nbsp; There are several options for creating the image 1. Pull the image from DVD or 2. Clone an existing machine.&nbsp; The benefits of creating the image from DVD are a clean from factory default installation that can deploy fairly quickly over the network&#8230; We however we elected to clone an existing machine.&nbsp; The clone allows us to add all the base software and drivers and then push that image with the base software already installed to another machine.</p>
<p>How its done.</p>
<ul>
<li>Install from DVD on to a machine that is the same vintage of processor as the machines that you plan to deploy the image to. </li>
<ul>
<li>In our case we have both PPC and Intel so we started making an image of each on two separate machines.&nbsp; </li>
</ul>
<li>After the OSX installer is complete update the OS from Apple Updates add the software you want included and the preferences you would like configured.&nbsp; </li>
<ul>
<li>In our case our base install includes: Mac Office 2008, Canon PS and UFR II Drivers, Disabling the onboard Bluetooth, Disabling the .DS_Store for network volumes, Disable Guest Account Access. (DO NOT INSTALL SYMANTEC BEFORE YOU IMAGE THE MACHINE&#8230; for some reason this causes the image to fail)</li>
</ul>
<li>After the base software and drivers are configured, go to Disk Utility and run permissions repair.</li>
<li>Capturing the image can only be done on a secondary volume from where you are installing the OS.</li>
<ul>
<li>If the install is on a primary volume, you will have to boot the device in target mode from the Startup Disk System Preferences.</li>
<li>If it is installed on a secondary volume you can boot to the primary volume to capture the image.<br /><a href="http://jasonmlee.net/wp-content/uploads/2008/06/startupdisk.jpg"><img height="148" alt="StartupDisk" src="http://jasonmlee.net/wp-content/uploads/2008/06/startupdisk-thumb.jpg" width="244" border="0"></a> </li>
</ul>
<li>On a machine with the OS X 10.5.3 Server Admin Tools installed (downloaded from&nbsp; <a title="http://www.apple.com/support/downloads/serveradmintools1053.html" href="http://www.apple.com/support/downloads/serveradmintools1053.html">http://www.apple.com/support/downloads/serveradmintools1053.html</a> or off the OS 10.5.3 Server Disk) Start the System Image Utility and it should find the volume you just created and updated.<br /><a href="http://jasonmlee.net/wp-content/uploads/2008/06/workflow.jpg"><img height="244" alt="WorkFlow" src="http://jasonmlee.net/wp-content/uploads/2008/06/workflow-thumb.jpg" width="227" border="0"></a> </li>
<ul>
<li>Select the Volume you want to image and choose netinstall and select customize.</li>
<li>Add Enable Automated Installation and Create Image to your workflow then configure where you want to save the output files, select an index for each image you will create and choose RUN.</li>
</ul>
<li>After an hour or so the location you selected will have a folder/file ending in .nbi</li>
</ul>
<p>How to Deploy the image: (Our configuration)</p>
<ul>
<li>Enable the NetBoot service in the Server Admin Console</li>
<li>Next Configure the NetBoot Service by going to the settings </li>
<ul>
<li>On the General Tab Enable which device you want Netboot to run on (Ethernet)</li>
<li>On the General Tab Select where you want to store the Images (Volume 2 for both Images and Client Data)<br /><a href="http://jasonmlee.net/wp-content/uploads/2008/06/netboot.jpg"><img height="244" alt="NetBoot" src="http://jasonmlee.net/wp-content/uploads/2008/06/netboot-thumb.jpg" width="177" border="0"></a> </li>
</ul>
<li>Copy the .nbi to the location where you told the Netboot service to save the data.&nbsp; /NetbootServiceLocation/Library/NetBoot/NetBootSP0</li>
<li>Next Configure the Images on the Server Admin&gt;Netboot&gt;Settings&gt; Images Tab</li>
<ul>
<li>Enable the Image you would like to NetInstall from.</li>
<li>Select the Architecture that you would like to use this volume.</li>
<li>Restart the NetBoot Service<br /><a href="http://jasonmlee.net/wp-content/uploads/2008/06/images.jpg"><img height="148" alt="Images" src="http://jasonmlee.net/wp-content/uploads/2008/06/images-thumb.jpg" width="244" border="0"></a> </li>
</ul>
</ul>
<p>&nbsp;</p>
<p>How to boot the Machine and install the image:</p>
<ul>
<li>While booting the device press the &#8216;n&#8217; key or select the network Network Volume in System Preferences&gt;Startup Disk<br /><a href="http://jasonmlee.net/wp-content/uploads/2008/06/startupdisk.jpg"><img height="148" alt="StartupDisk" src="http://jasonmlee.net/wp-content/uploads/2008/06/startupdisk-thumb.jpg" width="244" border="0"></a></li>
<li>When the device boots a little world will display and then the machine will indicate that it is recovering a system image.</li>
</ul>
<p>&nbsp;</p>
<p>After the Image is restored, the machine will rename itself and add a digit to the end, so you can install this on as many machines at the same time and not worry about the issues you might have without running Sysprep on a Windows machine.&nbsp; Simply rename the machine in System Preferences&gt; Sharing and change the name and the local hostname.</p>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/151/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Symantec AV for Macintosh</title>
		<link>http://jasonmlee.net/archives/144</link>
		<comments>http://jasonmlee.net/archives/144#comments</comments>
		<pubDate>Thu, 12 Jun 2008 17:00:51 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/229</guid>
		<description><![CDATA[Brining online our Mac Server continues&#8230;.We know that there are very few viruses that are going to harm the OSX machines, but we have still decided install Symantec for Mac on all our OSX machines.&#160; The primary reason is because of the popularity of OSX there is a higher potential for viruses for OSX but [...]]]></description>
			<content:encoded><![CDATA[<p>Brining online our Mac Server continues&#8230;.We know that there are very few viruses that are going to harm the OSX machines, but we have still decided install Symantec for Mac on all our OSX machines.&nbsp; The primary reason is because of the popularity of OSX there is a higher potential for viruses for OSX but also potential for the Macs to be the onramp for harmful files to our network to cause harm to the Windows devices.We downloaded the latest version of Symantec for Mac and the Symantec Admin Console for Mac, which is version 10.2.&nbsp; The installation process was less than smooth, but that wasn&#8217;t to the fault of Apple.&nbsp; Symantec&#8217;s Administration installation guild has a lot to be desired.&nbsp; Here are some notes from the install.We used the <a href="ftp://ftp.symantec.com/public/english_us_canada/products/symantec_antivirus/macintosh/10.0/manuals">Symantec AntiVirus™ 10 for Macintosh® Installation Guide</a> and the downloaded content from the licensing.Symantec.com web site.The installs for both the Client and Server portions of the software package are fairly straight forward except the guide is not correct or omits valuable information in several areas (noted with &#8220;omitted in guide&#8221;), your mileage may very but here is the process we used.</p>
<ul>
<li>Download the .dmg from licensing.Symantec.com
<li>Extract the .dmg to the local drive.
<li>Install MySQL
<ul>
<li>When installing the Console on a Leopard 10.5.3 Server the instructions state that MySQL should be running by default, it isn&#8217;t and from what I have read this was a change from 10.4 to 10.5.&nbsp; The crazy thing is when MySQL isn&#8217;t running the installer proceeds and says completed successfully even when it hasn&#8217;t. </li>
</ul>
</li>
</ul>
<blockquote><p>To enable and configure MySQL to to Server Admin and add the MySQL service.&nbsp; Next you will need to assign the root login a password.&nbsp; The default is blank, yet Symantec will not work with a blank password.&nbsp; To change the password go to terminal and run the following command mysqladmin -u root -h localhost password <em>&#8220;newpassword&#8221; </em>(replacing <em>newpassword</em> with your selection).</p>
</blockquote>
<p><a title="MySQL" href="http://www.flickr.com/photos/23086965@N05/2571640188/"><img alt="MySQL" src="http://static.flickr.com/3098/2571640188_93298d3be4.jpg" border="0"></a></p>
<ul>
<li>Enable php on the local web server
<ul>
<li>You next need to check that php is enabled.&nbsp; The guide makes no mention of needing to use php but after the console install is complete it takes you to a php page, and well by default the OSX 10.5.3 web server does not have the php module enabled.&nbsp; You will first need to start the Web Service and then enable php5_module. </li>
</ul>
</li>
</ul>
<blockquote><p>To enable this go to Server Admin&gt;Servers&gt;OSX Server&gt;Web. Choose the Settings button and the Modules Tab and scroll down to php5_module and check the &#8216;enable&#8217; check box.</p>
</blockquote>
<p><a title="OSXWebphp" href="http://www.flickr.com/photos/23086965@N05/2571631586/"><img alt="OSXWebphp" src="http://static.flickr.com/3060/2571631586_aec0da6095.jpg" border="0"></a></p>
<ul>
<li>Assign a static IP address to your OSX server if you haven&#8217;t already.
<li>Run the Symantec Administration Console Installer
<ul>
<li>enter&nbsp; your admin credentials
<li>Name the MySQL database &#8211; the default SACM works great
<li>Enter the MySQL username: root and the password you set with the command line above.
<li>Specify the MySQL database user name the default symadmin works well.
<li>enter the credentials you want to use to login to the SAV Console for Mac
<li>Choose the Setup Style for the Console, basic works well.
<li>enter the host IP address of the OSX server.
<li>Enter the Console address and path.&nbsp; The defaults work well, except the use SSL.&nbsp; On the first install accessing the Console on port 443 didn&#8217;t work but worked on port 80.&nbsp; It isn&#8217;t a major issue in my mind to have this console using SSL so we elected to not use SSL.
<li>Enter the Multicast address, the default settings worked well.
<li>Create the Key Pairs.
<ul>
<li>Note the Key Pairs will be used to authenticate any command you send from the Console to the clients so choose something here that you will remember and is easy to type. </li>
</ul>
<li>Save the Summary if you would like to document the setup and click Finish.
<li>A terminal window will open and the commands will run.
<li>Once this is complete you may choose &#8220;Open Console&#8221; and the console should open if MySQL AND php are running correctly. </li>
</ul>
<li>Next you can proceed to install the Client application on those machines you plan to manage with this Console.
<li>The Installation guide says all you have to do is install the .pkg file found /Library/Application Support/Symantec/SMac/Symantec Administration Client.pkg&nbsp; this isn&#8217;t the whole story. Doing so installs the configuration from your server but doesn&#8217;t install the client.&nbsp; If you are familiar with the windows version of SAV when you push out the client you are doing that pushing out the client configured to check into the server.&nbsp; This isn&#8217;t the case, you must install the client .pkg AND the client application.&nbsp; Once both are installed and you reboot the machine it should show up in your console.
<li>After the client and the configuration .pkg are installed you next need to configure the scanning schedule, live updates etc., but you need to know if you are going to do a local LiveUpdate server&nbsp; to have all your mac clients check into to get the updates rather than having all your machines checking in with Symantec every time they need updates. </li>
</ul>
<p>(after having done this for as few clients as we have it might not be worth the effort, but its done so i&#8217;ll document it.)</p>
<ul>
<li>To configure the LiveUpdate server follow these steps (if not using a local update server proceed to the next step in the list) </li>
<ul>
<li>View the KB article: <a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007864499807498?Open&amp;seg=ent">How to download and install the LiveUpdate Administration Utility for Macintosh</a> and download the <a href="ftp://ftp.symantec.com/public/english_us_canada/liveupdate/mac_liveupdate/updates/LiveUpdateAdminUtility/LiveUpdateAdminInstall.zip">Live Update Admin Install Utility</a>.
<ul>
<li>I wasn&#8217;t able to extract the .zip utility on a Mac so i downloaded it to a PC and extracted the .zip and copied it to our server. </li>
</ul>
<li>When you install LiveUpdate Administration tool it creates a directory in /applications/liveupdateadminutility.&nbsp; In this location is the configuration tool and two other directories: Retrieved Updates Retrieved Updates Archives.&nbsp; These are the default locations for the updates to be stored.
<li>Since we didn&#8217;t want to store the updates on the root volume we created a directory on a second volume called &#8220;LiveUpdates&#8221; and copied the two directories: Retrieved Updates Retrieved Updates Archives to the new location.<span class="Apple-style-span"></span>
<ul>
<li><span class="Apple-style-span"><span class="Apple-style-span">Just for others knowledge i created a symbolic link from the original location to the new location just incase someone were to follow the documentation and not know where i saved the updates.</span></span> </li>
</ul>
<li>Next view the KB article: <a href="http://service1.symantec.com/support/ent-security.nsf/docid/3542">How to configure a Mac OS X Server as an internal LiveUpdate server using HTTP (Web)</a>
<ul>
<li>This KB is really out of order, you first need to decide where you are going to store the updates and note that location.
<li>Next go to the directory /library/webserver/documents/&nbsp; and create a Symbolic Link named LiveUpdate (or what ever subdir path you want to use) pointing to the volume and location where you are saving the updates.
<ul>
<li>Note what you name this Symbolic Link you should know the name of this Symbolic Link is cas<br />
e sensitive in the url for your web server.
<li>Brian H @ Symantec suggested a &#8216;better option&#8217; is to save the updates in the /library/webserver/documents/liveupdate directory but that was on the root volume and we wanted the updates saved on the Storage Volume. </li>
</ul>
<li>In step 4 setting the preferences, when prompted for the location of where you are saving the updates and the expired updates respectively to populate the paths.
<ul>
<li>This can be done by dragging the folders that you created on the Storage volume to the terminal window when prompted for the paths. </li>
</ul>
</li>
</ul>
<li>Next View the KB article: <a href="http://service1.symantec.com/support/ent-security.nsf/docid/3543">How to configure the LiveUpdate Administration Utility for Macintosh</a> </li>
<ul>
<li>Using the default settings for each of these properties works well, except for the time of day that you want the LiveUpdate server to download new updates.
<li>Brian H @ Symantec said that SAV for Mac updates are released only each Friday, but we still choose to check daily at an hour that is in the middle of the night. </li>
</ul>
</ul>
</ul>
<p><a title="LiveUpdateAdminTool" href="http://www.flickr.com/photos/23086965@N05/2570805759/"><img alt="LiveUpdateAdminTool" src="http://static.flickr.com/3276/2570805759_00728d6b52.jpg" border="0"></a></p>
<ul>
<ul>
<li>Next you will need to <a href="http://jasonmlee.net/wp-admin/How%20to%20set%20up%20clients%20to%20download%20updates%20from%20the%20internal%20LiveUpdate%20server">configure the clients to update from the LiveUpdate Server</a>. </li>
<ul>
<li>Note that the Host name doesn&#8217;t include Http:// and the path <span class="Apple-style-span" style="font-style: italic"><span class="Apple-style-span" style="font-weight: bold">is</span></span> case sensitive.
<li>After you create the command go to the Send Commands tab and choose send Package.<a title="SendCommand" href="http://www.flickr.com/photos/23086965@N05/2571631720/"></a> </li>
</ul>
</ul>
</ul>
<blockquote class="webkit-indent-blockquote"><blockquote class="webkit-indent-blockquote">
<p><a title="SendCommand" href="http://www.flickr.com/photos/23086965@N05/2571631720/"><img alt="SendCommand" src="http://static.flickr.com/3111/2571631720_c77c415bb1_m.jpg" border="0"></a></p>
</blockquote>
</blockquote>
<ul>
<ul>
<li>Finally you need to tell the clients in what interval to run a scan and live update.&nbsp; Use the KB Article: <a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007393022179698?Open&amp;seg=ent">How to remotely schedule LiveUpdate and virus scans on Symantec AntiVirus for Macintosh 10.0 clients</a>. </li>
<ul>
<li>use the Symsched version commands 4.0.1f1 where &#8220;-w 1 23:00 /Users&#8221; is 1 the day of the week and 23:00 is the time of day. To set the Scan Interval:
<li>#!/bin/sh <br />#Type your script here<br />&#8220;/Applications/Symantec Solutions/Symantec Scheduler.app/Contents/Resources/symsched&#8221; VirusScan &#8220;Weekly Virus Scan&#8221; 1 1 -w 1 23:00 /Usersexit 0 </li>
</ul>
<li>use the Symsched version commands 4.0.1f1 where &#8220;-w 4 19:00&#8243; 4 is the day of the week and 19:00 is the time</li>
<ul>
<li>#!/bin/sh<br />#Type your script here.<br />&#8220;/Applications/Symantec Solutions/Symantec Scheduler.app/Contents/Resources/symsched&#8221; LiveUpdate &#8220;Weekly VDefs Update&#8221; 1 1 -w 4 19:00 &#8220;Virus Definitions&#8221; -quietexit 0 </li>
</ul>
</ul>
<li>When we ran the scripts we changed the times to be after Friday Night since the tech support told us that most Mac AV updates are released on Fridays of each week. </li>
</ul>
<p>&nbsp;</p>
<p>After these steps are complete your Macs are Running Symantec AV.</p>
<ul>
<ul>
<li>
<ul></ul>
</li>
</ul>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/144/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Setup of Apple Software Updates</title>
		<link>http://jasonmlee.net/archives/143</link>
		<comments>http://jasonmlee.net/archives/143#comments</comments>
		<pubDate>Wed, 11 Jun 2008 18:00:04 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/223</guid>
		<description><![CDATA[One of our reasons or rather benefits of brining an OSX Open Directory server into the mix was the ability to have a local Mac Update Server.  Granted it hasn&#8217;t been a major issue lately since we added a bunch of bandwidth, but we would prefer to have the ability to hold updates until they [...]]]></description>
			<content:encoded><![CDATA[<p>One of our reasons or rather benefits of brining an OSX Open Directory server into the mix was the ability to have a local Mac Update Server.  Granted it hasn&#8217;t been a major issue lately since we <a href="http://jasonmlee.net/archives/203">added a bunch of bandwidth</a>, but we would prefer to have the ability to hold updates until they are tested (at least minimally) before we push them to our client machines.The configuration of Software Update is very simple, a good resource is the apple KB on Software <a href="http://docs.info.apple.com/article.html?path=ServerAdmin/10.5/en/c0os2.html">Update Service Overview</a>.A couple &#8220;Got Ya&#8217;s&#8221;
<ul>
<li>I started the service and started downloading the updates, but then realized that our test environment didn&#8217;t include the two additional volumes our production machine would include.  The two external FireWire drives are for Storage and for TimeMachine.  I stopped the service and created another folder on the root drive then <a href="http://docs.info.apple.com/article.html?artnum=303837">followed the instructions to store Software Update packages on another hard disk or partition</a>. When I re-enabled the service the downloads continued&#8230; to the original location.  I stopped the service and deleted the location as mentioned in the KB article and the Update Service didn&#8217;t care much for that it just re-created the folders and continued downloading.So before you start the service, run the command to relocate the downloads.In the production installation I installed the service, but before I started the service I followed the instructions to locate the updates on the Storage volume.To configure our location from a terminal window I ran:<span style="font-style: italic" class="Apple-style-span"> sudo ln -s /Volumes/Storage/SoftwareUpdates /usr/share/swupd/html<span style="font-style: normal" class="Apple-style-span"></span></span></li>
</ul>
<blockquote class="webkit-indent-blockquote"><p>Note in the Administrators guide on page 85 (Chapter 8 Setting Up<span style="font-style: italic" class="Apple-style-span"> Software Update Service</span>) the instructions to delete and/or move the updates and create the symbolic link are not correct.</p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>- the guide displays the first command which is correct: </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>   sudo rm -rf /usr/share/swupd/html</p></blockquote>
<blockquote class="webkit-indent-blockquote"><p> </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>- the guide displays the second command to move the files: </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>mv /usr/share/swupd/html <span style="font-style: italic" class="Apple-style-span">/new_storage_location</span> </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>but the command should be </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>sudo mv /usr/share/swupd/html <span style="font-style: italic" class="Apple-style-span">/new_storage_location</span></p></blockquote>
<blockquote class="webkit-indent-blockquote"><p> </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>- the last command in the guide is: </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>ln -s /<span style="font-style: italic" class="Apple-style-span">new_storage_location</span> /usr/share/swupd/html</p></blockquote>
<blockquote class="webkit-indent-blockquote"><p>but the command should be: </p></blockquote>
<blockquote class="webkit-indent-blockquote"><p> sudo ln -s /<span style="font-style: italic" class="Apple-style-span">new_storage_location</span> /user/share/swupd/html</p></blockquote>
<ul>
<li>To start the download of updates you click the Update List button.  After that it appears that nothing is happening.  Really the list of updates is downloading&#8230; and if you enable Automatically copy __ updates from Apple like I did the updates are downloading too.<a href="http://www.flickr.com/photos/23086965@N05/2561588878/" title="SoftwareUpdates"><img src="http://static.flickr.com/3085/2561588878_da0e0e6cf5.jpg" alt="SoftwareUpdates" border="0" /></a>The icon for each update will be gray, once the update is downloaded it turns blue.  Although none of the buttons are grayed out, clicking on them does nothing since well&#8230;. its downloading the updates like you said you wanted it to do.  It would be nice though if the buttons were grayed out or there was a status indicator while it was downloading.I let the download go overnight and by morning it was ready to go.To enable individual software updates, select the checkbox in the Enable column of the update.</li>
<li>We elected to push the settings out to the client OSX machines by Policy in WorkGroup Manager.  One big Got Ya&#8217; when you choose the preference it says to enter the address including /index.suscatalog when you include that the clients error out.  If you simply use http://servername.domain.org:8088 all works well.<a href="http://www.flickr.com/photos/23086965@N05/2561588902/" title="SoftwareUpdates"><img src="http://static.flickr.com/3261/2561588902_2589a358ab.jpg" alt="SoftwareUpdates" border="0" /></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/143/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows AD and Mac OD Test</title>
		<link>http://jasonmlee.net/archives/139</link>
		<comments>http://jasonmlee.net/archives/139#comments</comments>
		<pubDate>Tue, 10 Jun 2008 11:00:59 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/221</guid>
		<description><![CDATA[Our order of new Mac hardware arrived last week, so that meant we had enough gear to bring to live a small sandbox to test the roll out of what Mac calls the Magic Triangle.  This magical setup includes Windows&#8217; Active Directory, Mac&#8217;s Open Directory and our Mac Client machines.
We started our OSX and Windows [...]]]></description>
			<content:encoded><![CDATA[<p>Our order of new Mac hardware arrived last week, so that meant we had enough gear to bring to live a small sandbox to test the roll out of what Mac calls the Magic Triangle.  This magical setup includes Windows&#8217; Active Directory, Mac&#8217;s Open Directory and our Mac Client machines.</p>
<p>We started our OSX and Windows domain integration project in a test environment, with the expectations that we would mess something up and want to start over.  Since we are learning to be OD admins (and yes the concept is the same but the presentation and logic is very different from working with AD), we elected to do our first run in an environment that we can completely bomb and not cause harm to the core network.</p>
<p>The test network consisted of:</p>
<p><a href="http://jasonmlee.net/wp-content/uploads/2008/06/imag0093.jpg"><img border="0" align="left" width="244" src="http://jasonmlee.net/wp-content/uploads/2008/06/imag0093-thumb.jpg" alt="IMAG0093" height="184" style="margin: 0px 5px 0px 0px;border: 0px" /></a> &#8211; A Sonicwall SOHO Router</p>
<p>- Dell 755 workstation running VMWare Server (Functioning as our PDC)</p>
<p>- A Power PC Mac Mini as our Open Directory Server</p>
<p>- A Intel Mac Mini as our Client Machine.</p>
<p>Jeremie performed a P2V of our Domain controller using Vmware&#8217;s converter and copied this to a new Dell 755 that had not yet been deployed.  Since our PDC (or in w2k3 terms DC1) is also our DHCP server and DNS server we quickly had a total replication of our production domain online in just under an hour and a half.</p>
<p>For the Mac side of this sandbox we have a PPC Mac Mini and two Intel Mac Minis.  The PPC will eventually become our production OD Server and the Intel minis will go into production as client machines.</p>
<p>We used a hybrid of two guides to perform the installation:</p>
<p><a href="http://www.bombich.com/mactips/activedir.html" title="http://www.bombich.com/mactips/activedir.html">http://www.bombich.com/mactips/activedir.html</a> (Courtesy of Hezekiah Barns)<br />
<a href="http://www.afp548.com/filemgmt/visit.php?lid=69" title="here">http://www.afp548.com/filemgmt/visit.php?lid=69</a> (Courtesy of <a href="http://www.mytechnicallife.com/">Chris Green</a>)</p>
<p>Both documents required some customization since they are assuming you are working in a new environment, but this was easy to understand.  The process in the documentation is fairly straight forward.</p>
<blockquote><p><font>Both Documents recommend creating a Binder Account for AD, we elected not to delegate this from an Administrator login and it worked fine.  From everything we can gather the account used to Bind to AD is simply used for just Binding and isn&#8217;t used any in the future.  If this isn&#8217;t the case, please correct me.</font></p></blockquote>
<p>A few things we learned in the binding process, Bind to AD first then to OD.  This lists the Directories in the appropriate Search Policy Directory Services.  You can bind to OD first, but you will just have to change the order later.</p>
<p>After installing OSX Server we had issues with the accessing Server via the Server Admin console since it was not appearing in our Windows DNS.  This can be resolved by going to Preferences&gt;Sharing&gt;Edit&gt; and Checking the Global DNS box and entering the domain.org as the host.  <strike>In our case no user credentials were required.</strike> <strong>Correction 6/10/2008: In our case credentials were required to authenticate to the DNS server.  We used an account we have configured for continued upkeep of the network.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/139/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Category &amp; New Project</title>
		<link>http://jasonmlee.net/archives/137</link>
		<comments>http://jasonmlee.net/archives/137#comments</comments>
		<pubDate>Fri, 06 Jun 2008 12:11:41 +0000</pubDate>
		<dc:creator>jasonlee</dc:creator>
				<category><![CDATA[OSX Domain Integration]]></category>

		<guid isPermaLink="false">http://jasonmlee.net/archives/217</guid>
		<description><![CDATA[I am breaking the recent silence with this announcement&#8230; 
I am officially adding a new category to the blog, OSX Domain Integration.&#160; Ok, now that you have fallen out of your chair in shock please pick up your jaw and continue reading.
Over the past few months I have been reading and learning about how to [...]]]></description>
			<content:encoded><![CDATA[<p>I am breaking the recent silence with this announcement&#8230; </p>
<p>I am officially adding a new category to the blog, <em>OSX Domain Integration</em>.&#160; Ok, now that you have fallen out of your chair in shock please pick up your jaw and continue reading.</p>
<p>Over the past few months I have been reading and learning about how to better serve those in our user community who don&#8217;t just prefer the Fruity OS, but are required to use OSX machines because of their role.&#160; Over the past two years we have continued to say we need to learn to serve and support this segment of our users better.&#160; Well we have finally had/made the time to put those dreams into play.</p>
<p>Well, that&#8217;s the why on the new category.&#160; This project has been extremely time consuming but I am planning to post my notes in the next few days on what we are learning as we integrate OSX into our Windows Domain.</p>
]]></content:encoded>
			<wfw:commentRss>http://jasonmlee.net/archives/137/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

