Contribute  :  Advanced Search  :  Directory  :  Forum  :  FAQ's  :  My Downloads  :  Links  :  Polls  
AFP548 Changing the world one server at a time.
Welcome to AFP548
Thursday, December 04 2008 @ 01:31 am CST

Advertising

  View Printable Version 

802.1X Config - Updated

Tips

Boy howdy can 802.1X be a pain in the behind...

To help with this Jeff Dyck has created an application to help. We've had it up in the downloads section for a little while now, but it hasn't gotten the love it needs. So, if you're in an 802.1X environment it would probably be useful to take a look at this.

First read the docs.

Then download the app.

From Jeff:

I've just put up a SVN site for this on the Google Code site - I have it working and doing the essentials in my environment, but there's lots of room for improvement and to make it more flexible.  Would love to see other people contribute to it as well.

The Google code site is: http://code.google.com/p/leopard-8021xconfig/

As far as not modifying com.apple.airport.preferences.plist and adding to the keychain, that's very very very strange as it's working here...  Maybe make sure you have the newest version from the SVN as I did modify it to deal with the newer GUID based ByHost Preferences.  I also pulled some proprietary code we have that pulls user info from a database to make it easier to setup - I may have unintentionally removed something else, although I did test this version...

  View Printable Version 

Mac/Windows Integration Survey

ArticlesThe Enterprise Desktop Alliance is doing a Mac/Windows integration survey. Maybe do it for the $50 gift certifiate. Or better yet, do it because they say they'll release the results and we're all curious.
  View Printable Version 

NetRestore Retired

TipsAfter 6 years of development, Mike Bombich is retiring NetRestore, one of the most used and useful tools for OS X mass deployment. Mike cites an aging code base and other tools in the market as reasons for his descision. Read all the details here
  View Printable Version 

Open Directory Across Four Locations?

Ask AFP548

I have to set up the IT infrastructure for a company that has 4 different offices.  Two of the sites have Apple based clients and the other two have windows based clients.  All of the servers are Xserves.  I hope to set up a single Open Directory structure that can handle Mail, a Corporate Intranet Site, a Corporate Website, Home Folders (for both the OSX and Windows laptops/desktops), Job Folders, and Backup for all of these.  There will be roughly 75 users at the HQ, and less than 20 users at each of the 3 satellite offices.

Our current equipment includes 2 or more Xserves at every location (plus Xserve RAIDs at the main office), 55 iMacs / Mac Pros, 13 MacBook Pros / Airs, 30 Windows Desktops, and 7 Windows Laptops.  Our network infrastructure is gigabit at all of the locations.

Currently each office has it’s own Open Directory master and separate fileservers for Job Folders and Home Folders.  The Corporate office hosts the mail, websites, and backup for all offices.

Any help or advice for creating this infrastructure in a secure and reliable way would be greatly appreciated!

  View Printable Version 

SANS Security Checklist for Leopard

Tips

Another thing to look at when locking down systems.

http://www.sans.org/press/osxchecklist.php

  View Printable Version 

Aqua Connect Webcast

Third Party Applications

Please join Joseph Cohen, CTO of Aqua Connect, as he demonstrates Aqua Connect’s Terminal Server 3.0 while utilizing Microsoft’s Remote Desktop Clients from both Mac OS X and Windows. After the demonstration, Joseph Cohen will then instruct administrators on how to administer user sessions from Aqua Connect’s Admin Tool and Apple’s Workgroup Manager

For information on how to participate go to the participant information page. 

The login ID for October 21st Webcast : MacEnterprise

Passcode for October 21st Webcast is : 451234

10:00 - 11:30 am PST
1:00 - 2:30 pm EST
18:00 - 19:30 GMT

Slides for the Aqua Connect 3.0 Terminal Server webcast will be available prior to the event.

  View Printable Version 

Disaster Tales Part 2 - Letting the server go

ArticlesPart two in our continuing saga of getting some business continuity for ourselves. In this part we let go of the server we've configured and send it off to the co-lo, all the while keeping our fingers crossed that we didn't bone anything on the setup.

It's always been on the to do list to set up a disaster recovery site for AFP548.com there just hasn't been enough time to really do it. Well, that's all changed now. Through the generous help of MacMiniColo.net we now have a Mac Mini humming away in Vegas, perhaps having more fun then we are...

Read on for what we're doing with it...
  View Printable Version 

Configuring OD/AD Kerberos with a Disjoined Namespace

Articles

I just surfaced out of a situation with a Mac Server connected to ADwith Kerberos Authentication.  Much help was received from Apple and I was given permission to share the "fix" for anyone else out thereattempting this type of solution.  
The problem was the server name in AD and the DNS name were different(Disjointed Namespace).  This is because our external domain name[server.outside.org] differs from the AD domain [ad.inside.org] and theAD domain is not available on the internet.  Since this server isavailable to the outside world, we could not use the AD name.  TheActive Directory Plug-in cannot reconcile this difference.

Read on for more....

  View Printable Version 

Aqua Connect Does RDP

Third Party Applications

Aqua Connect has released version 3 of their terminal server for OS X. It now uses Microsoft's remote desktop protocol to remotely provide a Mac OS X experience to pretty much any client platform including thin clients like a Sun Ray. This is interesting and causes us to ask more than a few questions about how this changes things.

Get more information at their site

  View Printable Version 

DFS Testers Requested

Third Party Applications

And we're serious about testers this time...

Group Logic has an interesting solution to solving DFS connection issues on Leopard. We've played around it with it some, and must say it shows a lot of potential.

However, with DFS being as fickle of a beast as it is, Group Logic is going to need some help flushing out the edge cases. So, if you have a very hairy DFS setup, or even if it's just medium hairy, sign up for the beta here and give it a whirl. 

Ask not what DFS can do for you; ask what you can do for DFS! 

Forum Topic Last Post