<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8238903149909171748</id><updated>2012-02-28T11:09:31.983Z</updated><category term='shares'/><category term='duplicate names'/><category term='Windows 2008 Server'/><category term='PTR'/><category term='Office 2011'/><category term='DNS'/><category term='10.7.2'/><category term='SMB'/><category term='Outlook'/><category term='mobile account creation'/><category term='can&apos;t log in'/><category term='can&apos;t login'/><category term='fonts'/><category term='migrate'/><category term='Windows7'/><category term='Windows'/><category term='&quot;home folders&quot;'/><category term='Apple'/><category term='10.6.8 Server'/><category term='Exchange 2007'/><category term='OpenDirectory'/><category term='Photoshop'/><category term='bounce messages'/><category term='&quot;incorrect host names&quot;'/><category term='computer passwords'/><category term='DSCL'/><category term='Mac Binding'/><category term='&quot;OS X&quot;'/><category term='profiles'/><category term='iPod'/><category term='e-mail'/><category term='first look'/><category term='searching'/><category term='Mac'/><category term='namespace AD'/><category term='&quot;can&apos;t connect to server&quot;'/><category term='ODM'/><category term='PC'/><category term='forwarding'/><category term='_ldap'/><category term='Server Manager'/><category term='time-out'/><category term='iOS'/><category term='review'/><category term='disk full'/><category term='sync problems'/><category term='mobile account'/><category term='missing admin account'/><category term='Lion'/><category term='&quot;Snow Leopard&quot;'/><category term='authentication'/><category term='lock'/><category term='&quot;speed up directory searches&quot;'/><category term='accents in names'/><category term='Windows Serer'/><category term='ExtremeZIP'/><category term='&quot;sites and services&quot;'/><category term='screensaver'/><category term='auto-mount'/><category term='BackupExec'/><category term='Kerberos'/><category term='Server Admin'/><category term='OSX'/><category term='root'/><category term='DFS'/><category term='LDAP'/><category term='account configuration'/><category term='Tomcat'/><category term='creating a mobile account'/><category term='Casper Imaging'/><category term='iPhone'/><category term='iTunes'/><category term='UAC'/><category term='Screen Sharing'/><category term='AFP sharing'/><category term='user account conrol'/><category term='password lock'/><category term='Target Boot'/><category term='screen saver'/><category term='Apple Server'/><category term='&quot;slow login&quot;'/><category term='Mac Mail'/><category term='Macs'/><category term='SRV'/><category term='changeip'/><category term='disable'/><category term='DHCP'/><category term='launchd'/><category term='dydl'/><category term='Leopard Server'/><category term='shaky login'/><category term='Microsoft'/><category term='10.5.7'/><category term='admin'/><category term='connection'/><category term='re-IP'/><category term='DNS name'/><category term='error -50'/><category term='FW Boot'/><category term='Outlook 2011'/><category term='Directory Services'/><category term='Apple Remote Desktop'/><category term='Global Catalog Server'/><category term='sync'/><category term='Leopard'/><category term='OS X'/><category term='AFP'/><category term='Casper'/><category term='&quot;garbled text&quot;'/><category term='gpresult'/><category term='netboot'/><category term='severmgrd'/><category term='lease'/><category term='log files'/><category term='10.6'/><category term='hostnames'/><category term='on-line mailbox'/><category term='Terminal'/><category term='clients'/><category term='&quot;Workgroup Manager&quot;'/><category term='MCX'/><category term='dfsutil'/><category term='Server 2008 R2'/><category term='database'/><category term='DC'/><category term='OS X server'/><category term='&quot;A records&quot;'/><category term='GAL'/><category term='speed'/><category term='SPN'/><category term='&quot;Time Machine&quot;'/><category term='login problems'/><category term='login'/><category term='Entourage'/><category term='UPN'/><category term='scutil'/><category term='flushcache'/><category term='Win7'/><category term='cached mailbox'/><category term='Snow Leopard'/><category term='dsmemberutil'/><category term='databases'/><category term='JSS'/><category term='10.5.8'/><category term='Active Directory'/><category term='GPO'/><category term='dslocal'/><category term='Machine Passwords'/><category term='server'/><category term='ipconfig'/><category term='ARD'/><category term='iPad'/><category term='10.6.8'/><category term='AD'/><category term='iOS5'/><category term='date and time'/><category term='&quot;OS X server&quot;'/><category term='bound'/><category term='&quot;User Principal Name&quot;'/><title type='text'>IPG EMEA Deployment Knowledge Base</title><subtitle type='html'>Things we've learned the hard way</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default?start-index=101&amp;max-results=100'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>124</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-519373260722164272</id><published>2012-02-28T11:09:00.002Z</published><updated>2012-02-28T11:09:31.991Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Casper'/><category scheme='http://www.blogger.com/atom/ns#' term='JSS'/><title type='text'>Where are JSS database backups located?</title><content type='html'>sudo /private/var/backups/jss/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-519373260722164272?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/519373260722164272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=519373260722164272' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/519373260722164272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/519373260722164272'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/where-are-jss-database-backups-located.html' title='Where are JSS database backups located?'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-90638315114226191</id><published>2012-02-27T00:18:00.001Z</published><updated>2012-02-27T00:19:45.018Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='netboot'/><category scheme='http://www.blogger.com/atom/ns#' term='Casper'/><category scheme='http://www.blogger.com/atom/ns#' term='JSS'/><category scheme='http://www.blogger.com/atom/ns#' term='Casper Imaging'/><title type='text'>How to build a Casper netboot set using Apple's System Image Utility</title><content type='html'>Information directly from the Jamf site:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://jamfnation.jamfsoftware.com/article.html?id=64"&gt;https://jamfnation.jamfsoftware.com/article.html?id=64&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The instructions tell you how to create a netboot set that will automatically launch the Casper Imaging Utility.&amp;nbsp; However if you want to use your netboot set in different environments then you should not auto-launch Casper Imaging.&amp;nbsp; Rather, just put the icon in the Dock and enter the JSS info when prompted.&amp;nbsp; It's one more step but worth it if you need to share your netboot set with other sites.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-90638315114226191?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/90638315114226191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=90638315114226191' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/90638315114226191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/90638315114226191'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/how-to-build-casper-netboot-set-using.html' title='How to build a Casper netboot set using Apple&apos;s System Image Utility'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3423854173123117957</id><published>2012-02-16T20:26:00.002Z</published><updated>2012-02-16T20:27:12.931Z</updated><title type='text'>High CPU usage caused by: krb5kdc: didn't find any realms when starting</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;We have seen several instances where a computer is unable to launch applications and suffers other performance problems when edu.mit.kerberos.krb5kdc repeatedly exits and respawns.&amp;nbsp; Look in the Console log for these errors:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-fw-jLxgD9i8/Tz1kNMOlAoI/AAAAAAAACHA/9s07gpTI0J8/s1600/Screen+shot+2012-02-16+at+20.16.28.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="30" src="http://4.bp.blogspot.com/-fw-jLxgD9i8/Tz1kNMOlAoI/AAAAAAAACHA/9s07gpTI0J8/s400/Screen+shot+2012-02-16+at+20.16.28.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;To fix this, open Terminal and type:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;sudo /usr/libexec/configurLocalKDC&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;It has also been suggested that you delete all files in the following location:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;sudo /var/db/krb5kdc/&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Although some people may not have any files in that location.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3423854173123117957?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3423854173123117957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3423854173123117957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3423854173123117957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3423854173123117957'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/hi-cpu-useage-caused-by-krb5kdc-didnt.html' title='High CPU usage caused by: krb5kdc: didn&apos;t find any realms when starting'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-fw-jLxgD9i8/Tz1kNMOlAoI/AAAAAAAACHA/9s07gpTI0J8/s72-c/Screen+shot+2012-02-16+at+20.16.28.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3808366782576231345</id><published>2012-02-16T20:13:00.000Z</published><updated>2012-02-16T20:13:23.088Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='dydl'/><category scheme='http://www.blogger.com/atom/ns#' term='10.6.8'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>dyld: shared cached file was build against a different libSystem.dylib, ignoring cache</title><content type='html'>On a Mac 10.6.8 server we were experiencing poor performance and erratic behavior from Server Administrator.&amp;nbsp; Looking at the Console Logs we found that it was filled with the following error:&lt;br /&gt;&lt;br /&gt;dyld: shared cached file was build against a different libSystem.dylib, ignoring cache&lt;br /&gt;&lt;br /&gt;Apparently this is a fairly common error in 10.6.x and can affect a wide variety of applications.&amp;nbsp; The fix is pretty straightforward.&amp;nbsp; Open Terminal and type the following:&lt;br /&gt;&lt;br /&gt;sudo update_dyld_shared_cache -force&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3808366782576231345?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3808366782576231345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3808366782576231345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3808366782576231345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3808366782576231345'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/dyld-shared-cached-file-was-build.html' title='dyld: shared cached file was build against a different libSystem.dylib, ignoring cache'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1577001576225937774</id><published>2012-02-06T20:50:00.000Z</published><updated>2012-02-06T20:50:22.897Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server 2008 R2'/><category scheme='http://www.blogger.com/atom/ns#' term='user account conrol'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='UAC'/><title type='text'>Windows 2008 R2: Members of the local "Administrator" group do not have admin rights to shares</title><content type='html'>We have received many reports of a problem with Windows 2008 R2 servers where shares containing the local "Administrator" group were not accessible by members of that group.&lt;br /&gt;&lt;br /&gt;For example: we have a GPO that makes our "Domain Admin" group a member of the local Administrator group of all our servers.&amp;nbsp; However, when a Domain Admin would log onto a server he would not have access to server shares.&lt;br /&gt;&lt;br /&gt;We resolved the problem by&amp;nbsp; disabling User Account Control (UAC) on the server.&amp;nbsp; &lt;a href="http://technet.microsoft.com/en-us/library/dd759070.aspx" target="_blank"&gt;This Microsoft KB&lt;/a&gt; article describes how to turn UAC off in Server 2008 R2. &lt;br /&gt;&lt;br /&gt;For a full overview of UAC and how to turn it off/on on other servers see &lt;a href="http://technet.microsoft.com/en-us/library/cc709691%28WS.10%29.aspx" target="_blank"&gt;this KB.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Note: these changes require a restart.&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1577001576225937774?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1577001576225937774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1577001576225937774' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1577001576225937774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1577001576225937774'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/windows-2008-r2-members-of-local.html' title='Windows 2008 R2: Members of the local &quot;Administrator&quot; group do not have admin rights to shares'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-7642939961410362628</id><published>2012-02-06T20:35:00.000Z</published><updated>2012-02-06T20:35:23.088Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='AD'/><category scheme='http://www.blogger.com/atom/ns#' term='SPN'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Serer'/><category scheme='http://www.blogger.com/atom/ns#' term='ExtremeZIP'/><title type='text'>Single-Sign-On (SSO) not working for Snow Leopard clients connecting to a Windows server running ExtremeZIP</title><content type='html'>We received a report from an office that three of their Windows 2003 servers running ExtremeZIP were not allowing SSO connections from AD bound Snow Leopard Macs.&lt;br /&gt;&lt;br /&gt;After a good deep-dive into the problem, including packet traces and help from Group Logic, we resolved the problem.&amp;nbsp; Here are the steps we took:&lt;br /&gt;&lt;br /&gt;Make sure the Mac clients are using the FQDN to connect to the ExtremeZIP AFP volume on the server.&amp;nbsp; Short names should not be used (in Lion you &lt;i&gt;must&lt;/i&gt; use the FQDN or you get an error).&lt;br /&gt;&lt;br /&gt;Check that the time on the server, clients and DC match.&amp;nbsp; One of the servers' clock was out by six minutes (max Kerberos time skew is five minutes).&amp;nbsp; When the time was set correctly Lion clients were able to log in.&lt;br /&gt;&lt;br /&gt;Check that the Server Principle Name (SPN) of the servers is correct; if they are not then authentication can fail.&amp;nbsp; Read more about SPNs &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/ms677949%28v=vs.85%29.aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;To check the SPN on a Windows 2003 server you must first download and install Windows Server Support Tools.&amp;nbsp; You can get them &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=7911" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;After you have installed the tools go to Programs/Windows Server Support Tools and launch the app- it will open a command line.&lt;br /&gt;&lt;br /&gt;Both the long and the short SPN for the AFP protocol need to exists for your servers:&lt;br /&gt;afpserver/servername.company.com&lt;br /&gt;afpserver/servername&lt;br /&gt;&lt;br /&gt;To display the SPNs from the Support Tools command line type "setspn &lt;i&gt;servername&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;You should see both the FQDN and the short name.&amp;nbsp; If one is missing do the following:&lt;br /&gt;&lt;br /&gt;- To add the long name: setspn -a afpserver/servername.company.com servername&lt;br /&gt;- To add the short name: setspn -a afpserver/servername servername&lt;br /&gt;&lt;br /&gt;We also found that although the Snow Leopard clients were authenticating users correctly, they were not generating a Kerberos ticket at login (you can verify this by going to the Ticket Viewer.app located in System/Library/Core Services).&amp;nbsp; After manually generating a Kerberos ticket, SSO worked.&lt;br /&gt;&lt;br /&gt;To force a Snow Leopard client to generate a Kerberos ticket at login follow the instructions in this &lt;a href="http://support.apple.com/kb/HT4100" target="_blank"&gt;Apple KB article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;After carrying out each of these steps, the Snow Leopard clients were able to get SSO to the ExtremeZIP enabled servers.&lt;br /&gt;&lt;br /&gt;Although it wasn't necessary in this case, make sure you update ExtremeZIP to the latest version&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-7642939961410362628?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/7642939961410362628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=7642939961410362628' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7642939961410362628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7642939961410362628'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/single-sign-on-sso-not-working-for-snow.html' title='Single-Sign-On (SSO) not working for Snow Leopard clients connecting to a Windows server running ExtremeZIP'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6943735192138223484</id><published>2012-02-06T16:13:00.000Z</published><updated>2012-02-06T16:13:26.086Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='AD'/><category scheme='http://www.blogger.com/atom/ns#' term='login'/><category scheme='http://www.blogger.com/atom/ns#' term='can&apos;t login'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='login problems'/><title type='text'>How to check if an Apple server is Kerberized against AD: verify Service Principals</title><content type='html'>If Mac clients are having trouble accessing a bound OS X server, check that the server is Kerberized against AD.&amp;nbsp; First, run the following command:&lt;br /&gt;&lt;br /&gt;sudo klist -kt&lt;br /&gt;&lt;br /&gt;You should see a number of service principals with the Kerberos realm of your.domain.com&lt;br /&gt;&lt;br /&gt;Second, you need to ensure that the correct service principal is in use by the AFP service.&amp;nbsp; You can use the following command to do this:&lt;br /&gt;&lt;br /&gt;sudo serveradmin settings afp:kerberosPrincipal&lt;br /&gt;&lt;br /&gt;This should show something like "afpserver/&lt;server fqdn=""&gt;@YOUR.DOMAIN.COM".&amp;nbsp;&amp;nbsp; If it shows a value in the LKDC realm it is incorrect and will need to be fixed before you can connect using Kerberos.&lt;br /&gt;&lt;br /&gt;Here's a command you can use to fix it:&lt;br /&gt;&lt;br /&gt;sudo serveradmin settings afp:kerberosPrincipal = "afpserver/&lt;server fqdn=""&gt;@YOUR.DOMAIN.COM"&lt;/server&gt;&lt;/server&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6943735192138223484?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6943735192138223484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6943735192138223484' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6943735192138223484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6943735192138223484'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/how-to-check-if-apple-server-is.html' title='How to check if an Apple server is Kerberized against AD: verify Service Principals'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2760826398580036122</id><published>2012-02-02T17:31:00.000Z</published><updated>2012-02-02T17:31:55.619Z</updated><title type='text'>Using Snow Leopard server for Lion software updates</title><content type='html'>Here is a step-by-step guide for setting up a Snow Leopard SUS server so that it will distribute Lion updates.&lt;br /&gt;&lt;br /&gt;I do not know who originally wrote this article.&amp;nbsp; If anyone can find the author please let me know and I will credit him/her.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;First things first. Fire up Server Admin and stop the Software Update service. Next fire up a Terminal window and head to /etc/swupd.&lt;br /&gt;&lt;br /&gt;cd /etc/swupd&lt;br /&gt;&lt;br /&gt;Now let's make backups of the .plist and .conf files for swupd.&lt;br /&gt;&lt;br /&gt;cp swupd.plist swupd.plist.bak; cp swupd.conf swupd.conf.bak&lt;br /&gt;&lt;br /&gt;Great. Now we are going to add a catalog to the catalog array in the swupd.plist. When we are done it will look like this:&lt;br /&gt;&lt;br /&gt;&lt;key&gt;otherCatalogs&lt;/key&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;array&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;string&gt;index-leopard.merged-1.sucatalog&lt;/string&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;string&gt;index-leopard-snowleopard.merged-1.sucatalog&lt;/string&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;string&gt;index-lion-snowleopard-leopard.merged-1.sucatalog&lt;/string&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/array&gt;&lt;br /&gt;&lt;br /&gt;You can do this with a text editor, but PlistBuddy makes it easier.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sudo /usr/libexec/PlistBuddy -c 'add :otherCatalogs:2 string index-lion-snowleopard-leopard.merged-1.sucatalog' /etc/swupd/swupd.plist&lt;br /&gt;&lt;br /&gt;Will do it in one shot. Adding this catalog is what will tell our SUS Server to go and get the Lion updates.&lt;br /&gt;&lt;br /&gt;The next bit we need to do is to tell the server that it can provide this catalog to Lion clients. Open up swupd.conf with the editor of your choice.&lt;br /&gt;&lt;br /&gt;vi swupd.conf&lt;br /&gt;&lt;br /&gt;Go to the bottom of the file, or just search for Rewrite. Look for the Darwin/11 agent string and change the rewrite rule to look like this.&lt;br /&gt;&lt;br /&gt;RewriteCond %{HTTP_USER_AGENT} Darwin/11&lt;br /&gt;RewriteRule ^/index.sucatalog$ /index-lion-snowleopard-leopard.merged-1.sucatalog&lt;br /&gt;&lt;br /&gt;Basically we are adding the word "lion" into the sucatalog name.&lt;br /&gt;&lt;br /&gt;Now close out of the terminal and start up the Software Update Service with Server Admin again. If you watch the logs, or the updates tab, you will see the Lion updates and on-demand software appear and begin downloading. After a while they will be local and you can start updating those Lion clients!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2760826398580036122?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2760826398580036122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2760826398580036122' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2760826398580036122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2760826398580036122'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/02/using-snow-leopard-server-for-lion.html' title='Using Snow Leopard server for Lion software updates'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5169528691777788997</id><published>2012-01-31T17:49:00.000Z</published><updated>2012-01-31T17:49:43.490Z</updated><title type='text'>How to enable Directory Services debugging and packet capture at log on</title><content type='html'>When diagnosing login problems it can be very helpful to generate a packet capture during log-in.&amp;nbsp; Unfortunately tools like Wireshark or PacketPeeper do not run at start-up.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;Following are the commands to enable DS debugging and a packet capture during log-in.&amp;nbsp; You will need another computer connected via SSH to the one on which you want the packets captured.&lt;br /&gt;&lt;br /&gt;1. Run the following command to set the debug level to seven (all one line):&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;sudo defaults write /Library/Preferences/DirectoryService/DirectoryServiceDebug "Debug Logging Priority Level" -integer 7&lt;br /&gt;&lt;br /&gt;NOTE: Only run this command if you are running 10.5 or later&lt;br /&gt;&lt;br /&gt;2. Enable Directory Service Debugging by running the following command:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sudo /usr/bin/killall -USR1 DirectoryService&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;3. SSH to the client and start a packet capture:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sudo /usr/sbin/tcpdump -vvv -n -s 0 -w /Library/Logs/`date +%Y%m%d-%H%M%S`.pcap&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;4. Reproduce the issue by attempting to login.&lt;br /&gt;&lt;br /&gt;5. Stop the packet capture using Control+C.&lt;br /&gt;&lt;br /&gt;6. Disable Directory Service Debugging by running the following command again:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sudo /usr/bin/killall -USR1 DirectoryService&lt;br /&gt;&lt;br /&gt;The capture will be in the /Library/Logs with a ".pcap" extension. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5169528691777788997?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5169528691777788997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5169528691777788997' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5169528691777788997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5169528691777788997'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2012/01/how-to-enable-directory-services.html' title='How to enable Directory Services debugging and packet capture at log on'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4082306300386600899</id><published>2011-12-27T15:01:00.001Z</published><updated>2011-12-27T15:02:15.756Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='AFP'/><category scheme='http://www.blogger.com/atom/ns#' term='10.7.2'/><category scheme='http://www.blogger.com/atom/ns#' term='Lion'/><title type='text'>10.7 clients unable to connect to legacy NAS and AFP devices</title><content type='html'>In Lion Apple disabled older, less secure protocols like DHCAST128.&amp;nbsp; This has caused problems with older NAS devices running AFP and some Novell servers.&lt;br /&gt;&lt;br /&gt;Most manufactures have released updates to resolve this problem but there is also a way to re-enable the protocol from the command line.&lt;br /&gt;&lt;br /&gt;Here are the instructions from Apple's KB:&lt;br /&gt;&lt;br /&gt;Lion maintains a list of authentication methods that are not allowed. These are the older, less secure authentication methods. You may need to enable one or more of these methods to support legacy devices or protocols.&lt;br /&gt;&lt;br /&gt;Open Terminal.&lt;br /&gt;Execute the following commands:&lt;br /&gt;&lt;br /&gt;sudo chmod o+w /Library/Preferences&lt;br /&gt;sudo defaults write /Library/Preferences/com.apple.AppleShareClient afp_host_prefs_version -int 1&lt;br /&gt;&lt;br /&gt;Make an AFP connection to another system so that the AFP Client preference file will be filled in with the default set of values. Note: You must connect as a registered user, not as a guest.&lt;br /&gt;Execute the following command to see a list of the disabled User Authentication Methods (UAMs)&lt;br /&gt;&lt;br /&gt;defaults read /Library/Preferences/com.apple.AppleShareClient afp_disabled_uams&lt;br /&gt;&lt;br /&gt;By default the disabled UAMs are "Cleartxt Passwrd", "MS2.0", "2-Way Randnum exchange", and "DHCAST128". Note: if you don't see a list, restart your computer and repeat step 3.&lt;br /&gt;&lt;br /&gt;To enable one of these UAMs, remove it from the list of disabled UAMs. For example, this command enables DHCAST128 by removing it from the list of disabled authentication methods:&lt;br /&gt;&lt;br /&gt;sudo defaults write /Library/Preferences/com.apple.AppleShareClient afp_disabled_uams -array "Cleartxt Passwrd" "MS2.0" "2-Way Randnum exchange"&lt;br /&gt;After the desired changes have been made, restore the permissions on the Preferences folder with this command:&lt;br /&gt;&lt;br /&gt;sudo chmod o-w /Library/Preferences&lt;br /&gt;Additional Information&lt;br /&gt;If you want to undo the changes described above, you can either delete the /Library/Preferences/com.apple.AppleShareClient file or use the following command to re-disable the default set of older UAMs:&lt;br /&gt;&lt;br /&gt;sudo defaults write /Library/Preferences/com.apple.AppleShareClient afp_disabled_uams -array "Cleartxt Passwrd" "MS2.0" "2-Way Randnum exchange" "DHCAST128"&lt;br /&gt;&lt;br /&gt;The full article can be found here:&amp;nbsp;&lt;a href="http://support.apple.com/kb/HT4700" target="_blank"&gt; http://support.apple.com/kb/HT4700&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4082306300386600899?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4082306300386600899/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4082306300386600899' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4082306300386600899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4082306300386600899'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/12/107-clients-unable-to-connect-to-legacy.html' title='10.7 clients unable to connect to legacy NAS and AFP devices'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5226297741747567174</id><published>2011-12-23T13:59:00.000Z</published><updated>2011-12-23T13:59:02.323Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;Snow Leopard&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='10.7.2'/><category scheme='http://www.blogger.com/atom/ns#' term='10.6.8 Server'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='Lion'/><title type='text'>Lion clients unable to connect to Snow Leopard server</title><content type='html'>If you are attempting to connect from a bound Lion client to a bound Snow Leopard server you must use the FQDN for the server.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;For example:&amp;nbsp; myserver.test.network.com&lt;br /&gt;&lt;br /&gt;If you do not you may receive an error that says "The version of the server you are trying to connect to is not supproted.&amp;nbsp; Please contact your system administrator to resolve the problem."&lt;br /&gt;&lt;br /&gt;Also check what authentication method you are using.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Open Server Manager&lt;/li&gt;&lt;li&gt;Highlight "AFP"&lt;/li&gt;&lt;li&gt;Click on the "Access" tab&lt;/li&gt;&lt;li&gt;Change "Authentication" to "Any Method"&lt;/li&gt;&lt;/ul&gt;Attempt to connect from at Lion client using the FQDN of the server.&lt;br /&gt;&lt;br /&gt;Note: changing the authentication to Any Method can possibly break single-sign-on for Snow Leopard client.&amp;nbsp; If this happens change the authentication to "Kerberos".&amp;nbsp; Lion clients should still be able to access the server.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5226297741747567174?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5226297741747567174/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5226297741747567174' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5226297741747567174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5226297741747567174'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/12/lion-clients-unable-to-connect-to-snow.html' title='Lion clients unable to connect to Snow Leopard server'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-660750060312139869</id><published>2011-12-18T14:33:00.001Z</published><updated>2011-12-18T14:34:08.240Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='creating a mobile account'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac Binding'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Shaking login with console error: Could not get a user record for [username] from Directory Services</title><content type='html'>&lt;span lang="EN-US"&gt;&lt;u&gt;Symptom &lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;After binding a Mac AD account log-ins fail (shaking login).&amp;nbsp; Console logs report the following:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;SecurityAgent[735] Could not get user record for 'username' from Directory Services&lt;/span&gt;&lt;span lang="EN-US"&gt;SecurityAgent[735] User infor context values set for username&lt;/span&gt;&lt;span lang="EN-US"&gt;SecurityAgent[735] unknown-user (username) login attempt PASSED for auditing&lt;/span&gt;&lt;span lang="EN-US"&gt;SecurityAgent[735] Could not get the user record for 'username' from Directory Services&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;kinit [username] will generate a Kerberos ticket&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;id [username] will produce a list of LDAP info for the AD account&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;login [username] fails&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;u&gt;Solution&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;u&gt; &lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;u&gt; &lt;/u&gt;If you see the Console log errors as described above it generally means that the computer is not able to create a mobile account at log-in.&amp;nbsp; Try creating a mobile account from Terminal first:&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;sudo /System/Library/CoreServices/ManagedClient.app/Contents/Resources/ &lt;br /&gt;createmobileaccount -n username &lt;br /&gt;sudo createhomedir -c -u username&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;Log out and back in with the user's AD credentials. &lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-660750060312139869?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/660750060312139869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=660750060312139869' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/660750060312139869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/660750060312139869'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/12/shaking-login-with-console-error-could.html' title='Shaking login with console error: Could not get a user record for [username] from Directory Services'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6218954042906895734</id><published>2011-11-27T00:47:00.000Z</published><updated>2011-11-27T00:47:30.854Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='AD'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='duplicate names'/><title type='text'>Shaking login: duplicate accounts</title><content type='html'>We had a user who couldn't log into any bound Mac but was able to log into Windows machines.&amp;nbsp; After much swearing and consternation we found that there was already a user with the same login and pre-Windows 2000 name as our user in a different domain of our forest.&lt;br /&gt;&lt;br /&gt;Macs search forest-wide for authentication information and the PCs only look in the current domain.&amp;nbsp; Thus all user accounts must be unique everywhere within a forest or the duplicate user will be unable to log in.&amp;nbsp; By changing the login and pre-Windows 2000 names of the user in our domain he was able log in.&lt;br /&gt;&lt;br /&gt;Mac savvy readers might point out that there is a tick box in Directory Services that says "Allow authentication from any domain in the forest".&amp;nbsp; One might think that un-ticking that would force the Macs to only look to the domain it is a member in for authentication information but this is incorrect.&amp;nbsp; In practice we have found that this tick-box does nothing at all and Apple admits that it is of little use.&lt;br /&gt;&lt;br /&gt;Keep in mind that when you bind a Mac and then look in the Search Policy it displays "Active Directory/All Domains".&amp;nbsp; Therefore it will look in all available AD domains in the forest for authentication information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6218954042906895734?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6218954042906895734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6218954042906895734' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6218954042906895734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6218954042906895734'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/11/shaking-login-duplicate-accounts.html' title='Shaking login: duplicate accounts'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-862143135518128826</id><published>2011-10-21T11:59:00.000+01:00</published><updated>2011-10-21T11:59:37.179+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sync'/><category scheme='http://www.blogger.com/atom/ns#' term='iTunes'/><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='iPad'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='iPod'/><category scheme='http://www.blogger.com/atom/ns#' term='sync problems'/><category scheme='http://www.blogger.com/atom/ns#' term='iOS5'/><category scheme='http://www.blogger.com/atom/ns#' term='iOS'/><title type='text'>iOS5: The iPhone ... Could not be synced because the sync session failed to start</title><content type='html'>iOS5 continues to be a problem.&amp;nbsp; One of the main complaints is an error encountered when attempting to sync an iPhone or iPod to iTunes:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;"The iPhone [device name] Could not be synced because the sync session failed to start"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Several work-arounds have been suggested including simply restarting the iOS device. One procedure that seems to work well is to remove the device backups from iTunes.&amp;nbsp; Before you do this, make sure you backup your backups folder: &lt;/span&gt;&lt;tt&gt;~/Library/Application Support/MobileSync/Backup/&lt;/tt&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Connect your device and open iTunes&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Go to Preferences/Devices&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Delete all backups&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Click "OK"&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Restart iTunes and attempt another sync&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size: small;"&gt;Sometimes you may see duplicate backups listed.&amp;nbsp; I found that by deleting all but one backup also allows the device to sync.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Apple's iOS troubleshooting page has some good tips:&amp;nbsp;&lt;a href="http://support.apple.com/kb/ts2529"&gt; http://support.apple.com/kb/ts2529&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-862143135518128826?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/862143135518128826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=862143135518128826' title='19 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/862143135518128826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/862143135518128826'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/10/ios5-iphone-could-not-be-synced-because.html' title='iOS5: The iPhone ... Could not be synced because the sync session failed to start'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>19</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2360516420923898709</id><published>2011-10-20T19:37:00.000+01:00</published><updated>2011-10-20T19:37:13.111+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='can&apos;t log in'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>"You are unable to log in to the user account [account name] at this time.</title><content type='html'>Problem:&amp;nbsp; an AD bound Mac shakes off login attempts and returns a message that says:&lt;br /&gt;&lt;br /&gt;"You are unable to log in to the user account [account name] at this time.&amp;nbsp; Logging in to the account failed because an error occurred."&lt;br /&gt;&lt;br /&gt;There are two things to to try:&lt;br /&gt;&lt;br /&gt;First, update the Automounter master map as outlined in this Apple KB article:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.apple.com/kb/TS3346"&gt;http://support.apple.com/kb/TS3346&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Secondly, if the user has a home folder path specified in their AD profile (Profile tab), remove it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2360516420923898709?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2360516420923898709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2360516420923898709' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2360516420923898709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2360516420923898709'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/10/you-are-unable-to-log-in-to-user.html' title='&quot;You are unable to log in to the user account [account name] at this time.'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2189982054701921383</id><published>2011-09-30T20:19:00.000+01:00</published><updated>2011-09-30T20:19:09.380+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;slow login&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>How OS X uses login names to generate Kerberos tickets</title><content type='html'>AD users have two valid names that can be used for authentication: the login name and the "pre-Windows 2000", or "short" name.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;OSX recognizes both of these as valid, however in order to have a Kerberos ticket granted the user must login with the short (pre-Windows 2000) name.&amp;nbsp; Login attempts using the long name or domain\username will not be granted a Kerberos ticket.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2189982054701921383?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2189982054701921383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2189982054701921383' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2189982054701921383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2189982054701921383'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/09/how-os-x-uses-login-names-to-generate.html' title='How OS X uses login names to generate Kerberos tickets'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6569012607022771700</id><published>2011-09-30T20:10:00.002+01:00</published><updated>2011-09-30T20:20:27.844+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='can&apos;t login'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Shaking Log-on in OS X: The Ongoing Saga</title><content type='html'>Yet more things to check if a bound Mac refuses to allow authentication by an AD user:&lt;br /&gt;&lt;br /&gt;Open the user's AD profile in Active Directory Users and Computers (ADUC) and click on the "Accounts" tab.&amp;nbsp; Check that both the log-on name and pre-Windows 2000 name are the same, that both are unique on your network and that the user is entering the name exactly as it appears in the profile.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6569012607022771700?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6569012607022771700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6569012607022771700' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6569012607022771700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6569012607022771700'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/09/ad-users-cant-authenticate-shaking.html' title='Shaking Log-on in OS X: The Ongoing Saga'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2267403118303625373</id><published>2011-09-18T15:36:00.000+01:00</published><updated>2011-09-18T15:38:15.136+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Machine Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='OSX'/><category scheme='http://www.blogger.com/atom/ns#' term='login'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><category scheme='http://www.blogger.com/atom/ns#' term='computer passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='login problems'/><title type='text'>Changing the Machine Password Interval on a Mac and Windows</title><content type='html'>Sometimes when a user can not log into their computer (shaking login) the problem is with the machine password and not the user account password.&amp;nbsp; By default Windows machines reset their machine password every 30 days but Macs do so every 14.&amp;nbsp; If a computer is on the network but can not connect to a DC at its password change interval it can subsequently prevent the user from logging in and/or changing their password from the computer.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;To change the machine password interval on a Mac you must first unbind the computer and then follow these steps:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.apple.com/kb/HT3422"&gt;http://support.apple.com/kb/HT3422&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Setting the passinterval to "0" is the recommended fix.&lt;br /&gt;&lt;br /&gt;Keep in mind that having a computer never reset its password poses a potential security risk because the security channel between the computer and the DC will never be reset.&amp;nbsp; This means that if someone discovers the machine password they could perform pass-through authentication directly to a DC.&lt;br /&gt;&lt;br /&gt;Here is a good article describing the entire machine password change proces: &lt;br /&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2009/02/15/test2.aspx"&gt;http://blogs.technet.com/b/askds/archive/2009/02/15/test2.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And here is Microsoft's KB on the process for PCs:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/154501"&gt;http://support.microsoft.com/kb/154501&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2267403118303625373?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2267403118303625373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2267403118303625373' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2267403118303625373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2267403118303625373'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/09/changing-machine-password-interval-on.html' title='Changing the Machine Password Interval on a Mac and Windows'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1821691599343193816</id><published>2011-09-06T19:20:00.004+01:00</published><updated>2011-09-06T19:20:57.787+01:00</updated><title type='text'>Snow Leopard: Allowing standard users to add printers</title><content type='html'>In Snow Leopard standard users are not allowed to modify the print queues.&amp;nbsp; Apple has a work-around in this KB article:&amp;nbsp;&lt;a href="http://support.apple.com/kb/HT3511"&gt; http://support.apple.com/kb/HT3511&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Run this command:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;dseditgroup -o edit -n /Local/Default -u &lt;/span&gt;&lt;span style="color: maroon; font-family: inherit;"&gt;admin&lt;/span&gt;&lt;span style="font-family: inherit;"&gt; -p -a &lt;/span&gt;&lt;span style="color: #993300; font-family: inherit;"&gt;student&lt;/span&gt;&lt;span style="font-family: inherit;"&gt; -t user lpadmin&lt;/span&gt;&lt;br /&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: inherit;"&gt;Where "admin" is the short name for the local admin account and "student" is the name of the user&lt;/span&gt;&lt;tt&gt; &lt;/tt&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1821691599343193816?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1821691599343193816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1821691599343193816' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1821691599343193816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1821691599343193816'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/09/snow-leopard-allowing-standard-users-to.html' title='Snow Leopard: Allowing standard users to add printers'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4043400207218945419</id><published>2011-09-05T19:55:00.005+01:00</published><updated>2011-09-05T19:59:01.374+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Snow Leopard'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple Remote Desktop'/><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='ARD'/><category scheme='http://www.blogger.com/atom/ns#' term='account configuration'/><category scheme='http://www.blogger.com/atom/ns#' term='Terminal'/><category scheme='http://www.blogger.com/atom/ns#' term='DSCL'/><title type='text'>How to configure a hidden account that has ARD access and also must request control from the user</title><content type='html'>I was asked to create a hidden account that had remote control access through ARD but that also had to request permission from the user before being allowed access to the computer &lt;br /&gt;&lt;br /&gt;Running the following in ARD/Unix using the root account will create a hidden standard account called "hidden", set the password to "Hidden123", turn on "request permissions to observe/control" and add the account to the Remote Management "allowed users" list:&lt;br /&gt;&lt;br /&gt;dscl . -create /Users/hidden&lt;br /&gt;dscl . -create /Users/hidden UserShell /bin/bash&lt;br /&gt;dscl . -create /Users/hidden RealName "hidden"&lt;br /&gt;dscl . -create /Users/hidden UniqueID 499&lt;br /&gt;dscl . -create /Users/hidden PrimaryGroupID 1000&lt;br /&gt;dscl . -create /Users/hidden NFSHomeDirectory /Local/Users/hidden&lt;br /&gt;dscl . -passwd /Users/hidden Hidden123&lt;br /&gt;/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -on -users hidden -privs -none -clientopts -setreqperm -reqperm yes&lt;br /&gt;&lt;br /&gt;A "UniqueID" lower than 500 will create a hidden account.&lt;br /&gt;&lt;br /&gt;To remove the account (run as root through ARD):&lt;br /&gt;&lt;br /&gt;dscl . -delete /Users/hidden&lt;br /&gt;&lt;br /&gt;This works for Leopard and Snow Leopard&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4043400207218945419?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4043400207218945419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4043400207218945419' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4043400207218945419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4043400207218945419'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/09/how-to-configure-hidden-account-that.html' title='How to configure a hidden account that has ARD access and also must request control from the user'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2187662095409710788</id><published>2011-08-18T11:47:00.000+01:00</published><updated>2011-08-18T11:47:58.356+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='screen saver'/><category scheme='http://www.blogger.com/atom/ns#' term='AD'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Cannot exit Snow Leopard Screen Saver with AD credentials</title><content type='html'>On bound Macs there is a problem where a computer that has been left on, with the screen saver active, for more than 10 hours has its Kerberos ticket expire.&amp;nbsp; If this happens a user is unable to unlock the screen saver using their AD credentials.&lt;br /&gt;&lt;br /&gt;Here is the KB article from Apple on how to fix this problem:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.apple.com/kb/TS3287"&gt;http://support.apple.com/kb/TS3287&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2187662095409710788?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2187662095409710788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2187662095409710788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2187662095409710788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2187662095409710788'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/08/cannot-exit-snow-leopard-screen-saver.html' title='Cannot exit Snow Leopard Screen Saver with AD credentials'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3493969356411536866</id><published>2011-07-28T00:02:00.000+01:00</published><updated>2011-07-28T00:02:40.428+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ipconfig'/><category scheme='http://www.blogger.com/atom/ns#' term='DHCP'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>How to display the DHCP server in OS X</title><content type='html'>It has always frustrated me that I could never find a way to display the DHCP server on a Mac- something like ipconfig /all on a PC.&amp;nbsp; I finally discovered a way:&lt;br /&gt;&lt;br /&gt;ipconfig getpacket en0 (en1 if you are on wi-fi)&lt;br /&gt;&lt;br /&gt;Look for the line that says "server identifier" and that is the IP of your DHCP server&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3493969356411536866?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3493969356411536866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3493969356411536866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3493969356411536866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3493969356411536866'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/07/how-to-display-dhcp-server-in-os-x.html' title='How to display the DHCP server in OS X'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3903197060906769598</id><published>2011-07-23T20:14:00.005+01:00</published><updated>2011-07-23T20:22:51.133+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scutil'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>scutil to change host names</title><content type='html'>Apparently "changeip" isn't the recommended way to change DNS names in Snow Leopard so we must use "scutil" instead.&lt;br /&gt;&lt;br /&gt;Take a look at the man page but mostly we will problem use it to change computer and host names:&lt;br /&gt;&lt;br /&gt;sudo scutil --set ComputerName [new name]&lt;br /&gt;sudo scutil --set HostName [new name]&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;pre class="manpages"&gt;&lt;span style="font-size: x-small;"&gt;&lt;tt&gt;&lt;tt&gt; &lt;b&gt;--set&lt;/b&gt; &lt;u&gt;pref&lt;/u&gt; [&lt;u&gt;newval&lt;/u&gt;]&lt;br /&gt;       Updates the specified preference with the new value.&amp;nbsp;&lt;/tt&gt;&lt;/tt&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre class="manpages"&gt;&lt;span style="font-size: x-small;"&gt;&lt;tt&gt;&lt;tt&gt;       If the new value is not specified on the command&amp;nbsp;&lt;/tt&gt;&lt;/tt&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre class="manpages"&gt;&lt;span style="font-size: x-small;"&gt;&lt;tt&gt;&lt;tt&gt;       line then it will be read from standard input.&lt;br /&gt;&lt;br /&gt;         Supported preferences include:&amp;nbsp;&lt;/tt&gt;&lt;/tt&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre class="manpages"&gt;&lt;tt&gt;&lt;tt&gt;&lt;span style="font-size: x-small;"&gt;         ComputerName LocalHostName HostName&lt;br /&gt;&lt;br /&gt;         The &lt;b&gt;--set&lt;/b&gt; option requires super-user access.&lt;br /&gt;&lt;br /&gt;     &lt;b&gt;--dns&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;         &lt;span style="font-size: x-small;"&gt;Reports the current DNS configuration.&lt;/span&gt;&lt;/tt&gt;&lt;/tt&gt;&lt;/pre&gt;&lt;pre class="manpages"&gt;&lt;tt&gt;&lt;tt&gt;&amp;nbsp;&lt;/tt&gt;&lt;/tt&gt;&lt;/pre&gt;&lt;pre class="manpages"&gt;&lt;tt&gt;&lt;tt&gt;&amp;nbsp;&lt;/tt&gt;&lt;/tt&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3903197060906769598?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3903197060906769598/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3903197060906769598' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3903197060906769598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3903197060906769598'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/07/scutil-to-change-host-names.html' title='scutil to change host names'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1317362539050051997</id><published>2011-07-15T10:27:00.000+01:00</published><updated>2011-07-15T10:27:00.479+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photoshop'/><category scheme='http://www.blogger.com/atom/ns#' term='log files'/><category scheme='http://www.blogger.com/atom/ns#' term='disk full'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Mac Disk Showing 0Kb.  Disk totally full for no reason.</title><content type='html'>Several users were reporting a problem where their disks were showing 0 space free.&amp;nbsp; It turned out that Photoshop 5 was creating (and not deleting) massive log files.&amp;nbsp; Deleting the log files reclaimed the missing space.&lt;br /&gt;&lt;br /&gt;The log files are in:&lt;br /&gt;&lt;br /&gt;/var/log/asl&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1317362539050051997?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1317362539050051997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1317362539050051997' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1317362539050051997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1317362539050051997'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/07/mac-disk-showing-0kb-disk-totally-full.html' title='Mac Disk Showing 0Kb.  Disk totally full for no reason.'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3873846590932458179</id><published>2011-07-07T18:31:00.002+01:00</published><updated>2011-07-07T18:44:22.519+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ExtremeZIP'/><category scheme='http://www.blogger.com/atom/ns#' term='AFP sharing'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2008 Server'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Windows 2008 server and ExtremeZIP: AFP Shares appearing as read-only to Mac users</title><content type='html'>After moving data from a Windows 2003 server to a Windows 2008 server via robocopy Mac users were unable to write to some folders.&amp;nbsp; The files and folders appeared to copy correctly, along with the permissions and Windows users could access the folders without a problem.&lt;br /&gt;&lt;br /&gt;The Windows 2008 server is running ExtremeZIP and the problem only occurs if the clients connected via AFP- SMB connections were fine.&amp;nbsp; The problem affected both AD bound and unbound Macs.&lt;br /&gt;&lt;br /&gt;FIX: it turned out that file permissions didn't fully copy (or perhaps robocopy doesn't have the flags that Windows 2008 Server requires).&amp;nbsp; Folders that the Mac users could only see as read-only were missing a tick in "Delete subfolders and files and folders" in the Advanced folder settings.&lt;br /&gt;&lt;br /&gt;Go to the security properties of the folder and click on the "Advanced" tab &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-KWcrDaL2IyE/ThXwGn-5MyI/AAAAAAAAB54/WBQGCSgLi0o/s1600/Screen+shot+2011-07-07+at+18.22.23.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-KWcrDaL2IyE/ThXwGn-5MyI/AAAAAAAAB54/WBQGCSgLi0o/s400/Screen+shot+2011-07-07+at+18.22.23.png" width="328" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Highlight the user/group that you want to check permissions on and click "Change Permissions" &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-TFM4xwGmU-k/ThXwNfZ9wYI/AAAAAAAAB58/GzBiEp3mZnk/s1600/Screen+shot+2011-07-07+at+18.22.30.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-TFM4xwGmU-k/ThXwNfZ9wYI/AAAAAAAAB58/GzBiEp3mZnk/s400/Screen+shot+2011-07-07+at+18.22.30.png" width="327" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;Highlight the user/group again and click "Edit" &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-G2chGGc0sjM/ThXwRMS9N9I/AAAAAAAAB6A/B1GQKNoeQZ0/s1600/Screen+shot+2011-07-07+at+18.22.39.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="376" src="http://4.bp.blogspot.com/-G2chGGc0sjM/ThXwRMS9N9I/AAAAAAAAB6A/B1GQKNoeQZ0/s400/Screen+shot+2011-07-07+at+18.22.39.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;Make sure there is a tick in "Delete subfolders and files" &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-zyzUDxdLA9o/ThXrnuqAmMI/AAAAAAAAB50/NExEaw-vlTM/s1600/Screen+shot+2011-07-07+at+18.22.48.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="109" src="http://4.bp.blogspot.com/-zyzUDxdLA9o/ThXrnuqAmMI/AAAAAAAAB50/NExEaw-vlTM/s400/Screen+shot+2011-07-07+at+18.22.48.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Make sure you propagate the permissions to all child objects.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3873846590932458179?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3873846590932458179/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3873846590932458179' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3873846590932458179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3873846590932458179'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/07/windows-2008-server-and-extremezip-afp.html' title='Windows 2008 server and ExtremeZIP: AFP Shares appearing as read-only to Mac users'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-KWcrDaL2IyE/ThXwGn-5MyI/AAAAAAAAB54/WBQGCSgLi0o/s72-c/Screen+shot+2011-07-07+at+18.22.23.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-9027019505451167130</id><published>2011-07-07T11:54:00.000+01:00</published><updated>2011-07-07T11:54:07.486+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forwarding'/><category scheme='http://www.blogger.com/atom/ns#' term='Outlook 2011'/><category scheme='http://www.blogger.com/atom/ns#' term='date and time'/><category scheme='http://www.blogger.com/atom/ns#' term='e-mail'/><title type='text'>Incorrect date/time in Outlook forward and reply messages</title><content type='html'>If your mail server is in a different time zone from your mail client, e-mail Replies and Forwards in Outlook display the time zone of the mail server, not the client.&lt;br /&gt;&lt;br /&gt;To fix this open Outlook go to Preferences/Composing and under "Attribution of original message" set the "Custom attribution format" as it appears below:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JFMFAiIhnTU/ThWQDKfrI5I/AAAAAAAAB5k/77CYe76s5uw/s1600/Screen+shot+2011-07-07+at+11.28.24.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="343" src="http://1.bp.blogspot.com/-JFMFAiIhnTU/ThWQDKfrI5I/AAAAAAAAB5k/77CYe76s5uw/s400/Screen+shot+2011-07-07+at+11.28.24.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-9027019505451167130?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/9027019505451167130/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=9027019505451167130' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9027019505451167130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9027019505451167130'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/07/incorrect-datetime-in-outlook-forward.html' title='Incorrect date/time in Outlook forward and reply messages'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-JFMFAiIhnTU/ThWQDKfrI5I/AAAAAAAAB5k/77CYe76s5uw/s72-c/Screen+shot+2011-07-07+at+11.28.24.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8997776566203211151</id><published>2011-06-17T16:49:00.000+01:00</published><updated>2011-06-17T16:49:33.918+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server Admin'/><category scheme='http://www.blogger.com/atom/ns#' term='Server Manager'/><category scheme='http://www.blogger.com/atom/ns#' term='severmgrd'/><category scheme='http://www.blogger.com/atom/ns#' term='OS X server'/><title type='text'>Apple Server Admin Not Starting</title><content type='html'>Problem: OS X Server Admin will either not launch or after it has launched it will not allow connections.&lt;br /&gt;&lt;br /&gt;Fix from Apple:&lt;br /&gt;&lt;br /&gt;sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.servermgrd.plist &lt;br /&gt;&lt;br /&gt;cd /var/severmgrd&lt;br /&gt;&lt;br /&gt;Note: verify that you are in the right path, because the next command will delete everything in the current folder. &lt;br /&gt;&lt;br /&gt;rm -rf *&lt;br /&gt;&lt;br /&gt;sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.servermgrd.plist&lt;br /&gt;&lt;br /&gt;Server Manager should now launch and allow logins.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8997776566203211151?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8997776566203211151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8997776566203211151' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8997776566203211151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8997776566203211151'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/06/apple-server-admin-not-starting.html' title='Apple Server Admin Not Starting'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6620261298190853803</id><published>2011-06-17T16:44:00.000+01:00</published><updated>2011-06-17T16:44:37.660+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Casper'/><category scheme='http://www.blogger.com/atom/ns#' term='JSS'/><category scheme='http://www.blogger.com/atom/ns#' term='Tomcat'/><title type='text'>Tomcat problems on a JSS</title><content type='html'>It is important that Apple's Tomcat does not conflict with Jamf's on your JSS.&amp;nbsp; If both instances of Tomcat are trying to run at the same time you can experience an inability to access the JSS along with over all poor server performance.&lt;br /&gt;&lt;br /&gt;To disable Apple's Tomcat follow these steps:&lt;br /&gt;&lt;br /&gt;On your JSS, launch Server Admin&lt;br /&gt;Click on "Web"&lt;br /&gt;Click on the "Settings" icon&lt;br /&gt;Click on the "General" tab&lt;br /&gt;Remove the tick from "Enable Tomcat"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6620261298190853803?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6620261298190853803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6620261298190853803' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6620261298190853803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6620261298190853803'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/06/tomcat-problems-on-jss.html' title='Tomcat problems on a JSS'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6033982485542449362</id><published>2011-06-16T19:22:00.003+01:00</published><updated>2011-06-16T19:31:36.035+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='screen saver'/><category scheme='http://www.blogger.com/atom/ns#' term='screensaver'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Bound Mac Clients Can't Exit Screensaver Using AD Credentials</title><content type='html'>Bound Macs that have the screen saver set to lock after a certain amount of time and require AD credentials to unlock sometimes are unable to unlock the screen saver.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Fix&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;Open Terminal&lt;br /&gt;Type: cd /etc&lt;br /&gt;Type: pico authorization&lt;br /&gt;Find the "system.login.screensaver”&amp;nbsp;and look for this text in a string:&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;/ul&gt;&lt;span style="font-size: small;"&gt;"The &lt;/span&gt;owner or any administrator can unlock the screensaver"&lt;br /&gt;&lt;br /&gt;and change it to:&lt;br /&gt;&lt;br /&gt;"(Use SecurityAgent.) The &lt;span style="font-size: small;"&gt;The &lt;/span&gt;owner or any administrator can unlock the screensaver."&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;For full details refer to Apple KB: http:&lt;a href="http://support.apple.com/kb/TS3287"&gt;//support.apple.com/kb/TS3287&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6033982485542449362?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6033982485542449362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6033982485542449362' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6033982485542449362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6033982485542449362'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/06/bound-mac-clients-cant-exit-screensaver.html' title='Bound Mac Clients Can&apos;t Exit Screensaver Using AD Credentials'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8750701390712423876</id><published>2011-06-06T16:01:00.001+01:00</published><updated>2011-06-06T16:02:02.846+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='shares'/><category scheme='http://www.blogger.com/atom/ns#' term='disable'/><category scheme='http://www.blogger.com/atom/ns#' term='auto-mount'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>How to disable auto mounting network shares in OS X</title><content type='html'>To disable auto-mounting of network shares in OS 10.5 and 10.6 do the following:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Go to  /Users/username/Library/Favorites&lt;/li&gt;&lt;li&gt;Remove the server names or IP addresses&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8750701390712423876?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8750701390712423876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8750701390712423876' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8750701390712423876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8750701390712423876'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/06/how-to-disable-auto-mounting-network.html' title='How to disable auto mounting network shares in OS X'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4839809884110989523</id><published>2011-05-10T21:21:00.002+01:00</published><updated>2011-05-10T21:32:52.951+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;Snow Leopard&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='OSX'/><category scheme='http://www.blogger.com/atom/ns#' term='AFP'/><category scheme='http://www.blogger.com/atom/ns#' term='flushcache'/><category scheme='http://www.blogger.com/atom/ns#' term='SMB'/><category scheme='http://www.blogger.com/atom/ns#' term='dsmemberutil'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='Directory Services'/><category scheme='http://www.blogger.com/atom/ns#' term='Leopard'/><title type='text'>OS X Server: users can not connect to SMB or AFP shares</title><content type='html'>&lt;div style="text-align: justify;"&gt;We have been troubleshooting several reports from offices with bound OS X servers where Mac and PC clients are unable to connect to shares using AFP or SMB.&amp;nbsp; Additionally these offices have reported that Macs will randomly drop their AFP connections to the OS X server.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;When the connection problem occurs often times the server shares will display generic ACL GUIDs: a series of numbers and letters instead of the group name.&amp;nbsp;&amp;nbsp; In cases such as these restarting Directory Services generally resolves the problem- at least temporarily: &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;sudo /usr/bin/killall DirectoryService&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Other times the GUIDs display normally but the connection problems still persist.&amp;nbsp; In these cases two things are suggested:&lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;li&gt;Nest AD users into local groups and then use the local groups to populate the ACLs&lt;/li&gt;&lt;li&gt;Flush the group membership cache by running this command:&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;sudo dsmemberutil flushcache&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Generally these problems occur most often on Leopard servers- Snow Leopard servers have improved group membership caching.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4839809884110989523?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4839809884110989523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4839809884110989523' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4839809884110989523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4839809884110989523'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/05/osx-server-users-can-not-connect-to-smb.html' title='OS X Server: users can not connect to SMB or AFP shares'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1075813602997019442</id><published>2011-05-06T13:36:00.000+01:00</published><updated>2011-05-06T13:36:57.402+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='admin'/><category scheme='http://www.blogger.com/atom/ns#' term='missing admin account'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='root'/><title type='text'>Mac administrator account changing to a standard account</title><content type='html'>We have had several reports of Macs that have their admin account changed to a standard account.&lt;br /&gt;&lt;br /&gt;The fix is to login to the machine as root, go to "Accounts", select the admin account and put a tick in "allow user to administer this computer".&lt;br /&gt;&lt;br /&gt;If the root account is disabled or you do not know the password you will have to boot the machine from the OS DVD and enable the account/reset the root password.&lt;br /&gt;&lt;br /&gt;Full instructions can be found here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.apple.com/kb/TS1278"&gt;http://support.apple.com/kb/TS1278&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1075813602997019442?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1075813602997019442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1075813602997019442' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1075813602997019442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1075813602997019442'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/05/mac-administrator-account-changing-to.html' title='Mac administrator account changing to a standard account'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5506937687297733636</id><published>2011-04-11T14:30:00.002+01:00</published><updated>2011-09-19T11:54:14.739+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='dslocal'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Shaking Login: corrupt Kerberos file</title><content type='html'>Apple has informed us that sometimes anti-virus software can corrupt the kerberos files found in:&lt;br /&gt;&lt;br /&gt;/var/db/dslocal/nodes/Default/config/&lt;br /&gt;&lt;br /&gt;They suggest that a trouble shooting step for a shaking login should be to remove all the Kerberos files in the above directory.&lt;br /&gt;&lt;br /&gt;sudo /var/db/dslocal/nodes/Default/config/&lt;br /&gt;rm Kerberos*&lt;br /&gt;&lt;br /&gt;then restart.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5506937687297733636?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5506937687297733636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5506937687297733636' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5506937687297733636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5506937687297733636'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/04/shaking-login-corrupt-kerberos-file.html' title='Shaking Login: corrupt Kerberos file'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-750813352818840070</id><published>2011-04-05T12:44:00.000+01:00</published><updated>2011-04-05T12:44:05.304+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='Outlook 2011'/><category scheme='http://www.blogger.com/atom/ns#' term='profiles'/><category scheme='http://www.blogger.com/atom/ns#' term='Office 2011'/><title type='text'>Outlook 2011 Profiles Disappearing</title><content type='html'>There have been some reports that when a user launches Outlook their profile is no longer there.&amp;nbsp; It seems to have something to do with the database daemon thinking the user's database has vanished.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is one reported work-around: &lt;br /&gt;&lt;ul&gt;&lt;li&gt;Keep Outlook open&lt;/li&gt;&lt;li&gt;Go to Terminal&lt;/li&gt;&lt;li&gt;Type, &lt;b&gt;ps aux | grep Microsoft&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Look for the MS Office 2011 processes&lt;/li&gt;&lt;li&gt;Note the number after the user name- this is the Process ID (PID)&lt;/li&gt;&lt;li&gt;In Terminal type, &lt;b&gt;sudo kill –9 [PID number]&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Do this for each of the Microsoft processes&lt;/li&gt;&lt;li&gt;Re-launch Outlook&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-750813352818840070?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/750813352818840070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=750813352818840070' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/750813352818840070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/750813352818840070'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/04/outlook-2011-profiles-disappearing.html' title='Outlook 2011 Profiles Disappearing'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2226958633605145032</id><published>2011-03-31T09:00:00.001+01:00</published><updated>2011-03-31T09:07:40.185+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='MCX'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>How To Refresh MCX Preferences on a Mac</title><content type='html'>From Terminal type:&amp;nbsp; sudo mcxrefresh –n [user short name]&lt;br /&gt;&lt;br /&gt;eg:&amp;nbsp; sudo mcxrefresh –n tsmith&lt;br /&gt;&lt;br /&gt;For further info see the man page, "man mcxrefresh&lt;br /&gt;&lt;br /&gt;You can also delete the&amp;nbsp; /Library/Managed Preferences folder &lt;br /&gt;&lt;br /&gt;Here is a list of MCX refresh commands for each OS:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://krypted.com/mass-deployment/refreshing-managed-client-cache/"&gt;http://krypted.com/mass-deployment/refreshing-managed-client-cache/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2226958633605145032?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2226958633605145032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2226958633605145032' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2226958633605145032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2226958633605145032'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/how-to-refresh-mcx-preferences-on-mac.html' title='How To Refresh MCX Preferences on a Mac'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5445291336284726022</id><published>2011-03-29T22:21:00.001+01:00</published><updated>2011-03-29T22:21:57.654+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DC'/><category scheme='http://www.blogger.com/atom/ns#' term='LDAP'/><category scheme='http://www.blogger.com/atom/ns#' term='Global Catalog Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Serer'/><category scheme='http://www.blogger.com/atom/ns#' term='GAL'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Mac clients can not do LDAP (GAL) lookups</title><content type='html'>An office reported that Mac clients were unable to do LDAP (GAL) lookups from Entourage or Outlook 2011.&lt;br /&gt;&lt;br /&gt;All the clients were using the local DC for LDAP; if this was changed to another DC the clients could do lookups just fine.&lt;br /&gt;&lt;br /&gt;It was found that the local DC was not a global catalog server.&amp;nbsp; When this was fixed, lookups worked.&lt;br /&gt;&lt;br /&gt;Here is the TechNet article on determining whether or not a DC is a GC&amp;nbsp; it:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc786686%28WS.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/cc786686%28WS.10%29.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5445291336284726022?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5445291336284726022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5445291336284726022' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5445291336284726022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5445291336284726022'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/mac-clients-can-not-do-ldap-gal-lookups.html' title='Mac clients can not do LDAP (GAL) lookups'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-513884940891630156</id><published>2011-03-29T22:04:00.006+01:00</published><updated>2011-03-29T22:12:02.706+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='10.5.8'/><category scheme='http://www.blogger.com/atom/ns#' term='Leopard Server'/><category scheme='http://www.blogger.com/atom/ns#' term='launchd'/><title type='text'>com.apple.launchd[1] (org.samba.winbindd3733) Exited with exit code: 1</title><content type='html'>A 10.5.8 server dropped all SMB connections and the Console log was filled with these errors:&lt;br /&gt;&lt;br /&gt;Mar 29 12:36:37 ... com.apple.launchd[1] (org.samba.winbindd[98460]): Exited with exit code: 1&lt;br /&gt;Mar 29 12:36:37 ... com.apple.launchd[1] (org.samba.winbindd): Throttling respawn: Will start in 10 seconds&lt;br /&gt;Mar 29 12:36:47 ... com.apple.launchd[1] (org.samba.winbindd[98461]): Exited with exit code: 1&lt;br /&gt;Mar 29 12:36:47 ... com.apple.launchd[1] (org.samba.winbindd): Throttling respawn: Will start in 10 seconds&lt;br /&gt;&lt;br /&gt;Work-around (but not a full fix as it doesn't address the root cause)&lt;br /&gt;&lt;br /&gt;Open Terminal and log in as sudo -s and type:&lt;br /&gt;&lt;br /&gt;launchctl unload  /System/Library/LaunchDaemons/org.samba.winbindd.plist&lt;br /&gt;&lt;br /&gt;Then edit /System/Library/LaunchDaemons/org.samba.winbindd.plist&lt;br /&gt;and  the following:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-vxUpEt_Wklk/TZJK5ybecRI/AAAAAAAABuc/ouvYKeljq7E/s1600/Screen+shot+2011-03-29+at+22.10.25.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-vxUpEt_Wklk/TZJK5ybecRI/AAAAAAAABuc/ouvYKeljq7E/s1600/Screen+shot+2011-03-29+at+22.10.25.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;key&gt;&lt;key&gt;&lt;br /&gt;&lt;key&gt;&lt;/key&gt;&lt;/key&gt;&lt;/key&gt;&lt;br /&gt;&lt;key&gt;&lt;key&gt;&lt;true&gt;&lt;/true&gt;&lt;/key&gt;&lt;/key&gt;&lt;br /&gt;&lt;true&gt;&lt;/true&gt;&lt;br /&gt;&lt;div class="jive-quote"&gt;&lt;true&gt;&lt;/true&gt;&lt;/div&gt;This keeps the winbindd daemon from launching at startup, which it&amp;nbsp; isn't doing anyway, to  re-enable it&amp;nbsp; change "true" to "false".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-513884940891630156?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/513884940891630156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=513884940891630156' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/513884940891630156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/513884940891630156'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/comapplelaunchd1-orgsambawinbindd3733.html' title='com.apple.launchd[1] (org.samba.winbindd3733) Exited with exit code: 1'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-vxUpEt_Wklk/TZJK5ybecRI/AAAAAAAABuc/ouvYKeljq7E/s72-c/Screen+shot+2011-03-29+at+22.10.25.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6099980999832986255</id><published>2011-03-29T19:46:00.000+01:00</published><updated>2011-03-29T19:46:26.142+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='DSCL'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>How to check a user's password from the command line using DSCL</title><content type='html'>Here is the command for checking a user's password via DSCL:&lt;br /&gt;&lt;br /&gt;dscl /Active\ Directory/domainname authonly username&lt;br /&gt;&lt;br /&gt;(where "domainname" is the name of the AD domain and "username" is the short name of an Active Directory user)&lt;br /&gt;&lt;br /&gt;No output indicates that the user's password was verified.&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6099980999832986255?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6099980999832986255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6099980999832986255' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6099980999832986255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6099980999832986255'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/how-to-check-users-password-from.html' title='How to check a user&apos;s password from the command line using DSCL'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-871945068923007255</id><published>2011-03-29T14:33:00.002+01:00</published><updated>2011-03-29T14:35:43.678+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DHCP'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2008 Server'/><title type='text'>DHCP Error while importing scope "Option 6"</title><content type='html'>While importing a DHCP scope from a Windows 2003 to 2008 server I encountered an error:&lt;br /&gt;&lt;br /&gt;"Error while importing option "6"."&lt;br /&gt;&lt;br /&gt;This is a reference to the scope options in DHCP.&amp;nbsp; Option 6 is the DNS server, option 15 is DNS Domain Name, etc.&lt;br /&gt;&lt;br /&gt;To remedy this particular error delete the offending options form the DHCP's "Server Options" and then attempt the import again.&lt;br /&gt;&lt;br /&gt;Export (2003/2008): netsch dhcp server export c:\[filename.txt] all&lt;br /&gt;Import: netsch dhcp server import c:\[filename.txt] all&lt;br /&gt;&lt;br /&gt;More details on the error can be found here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://mykbit.blogspot.com/2010/03/error-while-importing-option-6-while.html"&gt;http://mykbit.blogspot.com/2010/03/error-while-importing-option-6-while.html&lt;/a&gt;&lt;a href="http://mykbit.blogspot.com/2010/03/error-while-importing-option-6-while.html"&gt;http://mykbit.blogspot.com/2010/03/error-while-importing-option-6-while.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-871945068923007255?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/871945068923007255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=871945068923007255' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/871945068923007255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/871945068923007255'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/dhcp-error-while-importing-scope-option.html' title='DHCP Error while importing scope &quot;Option 6&quot;'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1720930263115230439</id><published>2011-03-17T23:10:00.001Z</published><updated>2011-03-31T09:01:34.273+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>How to force a 10.6 client to generate a Kerberos ticket at login</title><content type='html'>Refer to this Apple KB article:&lt;br /&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;a href="http://support.apple.com/kb/HT4100"&gt;http://support.apple.com/kb/HT4100&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;You need to add the string:&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre style="font-family: inherit;"&gt;&lt;string&gt;builtin:krb5store,privileged&lt;/string&gt;&lt;/pre&gt;&lt;pre style="font-family: inherit;"&gt;&amp;nbsp;&lt;/pre&gt;&lt;pre style="font-family: inherit;"&gt;Under the key:&lt;/pre&gt;&lt;pre style="font-family: inherit;"&gt;&lt;/pre&gt;&lt;pre style="font-family: inherit;"&gt;&lt;key&gt;system.login.console&lt;/key&gt;&lt;/pre&gt;&lt;pre style="font-family: inherit;"&gt;&amp;nbsp;&lt;/pre&gt;&lt;pre style="font-family: inherit;"&gt;In the /etc/authorization file&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1720930263115230439?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1720930263115230439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1720930263115230439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1720930263115230439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1720930263115230439'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/how-to-force-106-client-to-generate.html' title='How to force a 10.6 client to generate a Kerberos ticket at login'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2997693284711989638</id><published>2011-03-17T21:53:00.000Z</published><updated>2011-03-17T21:53:21.432Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>Generating a kerberos ticket from the command line in OS X</title><content type='html'>kinit [user name]&lt;br /&gt;&lt;br /&gt;You will be prompted for the user's password&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2997693284711989638?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2997693284711989638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2997693284711989638' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2997693284711989638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2997693284711989638'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/03/generating-kerberos-ticket-from-command.html' title='Generating a kerberos ticket from the command line in OS X'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3363712140552635199</id><published>2011-02-26T14:54:00.001Z</published><updated>2011-02-26T14:54:52.540Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='admin'/><category scheme='http://www.blogger.com/atom/ns#' term='missing admin account'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Missing admin accounts on Mac: FIX</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Shut down the computer if it is on.&lt;br /&gt;Press the power button to start the computer.&lt;br /&gt;Immediately press and hold the Command (Apple) key and the "s" key for single-user mode.&lt;br /&gt;Type "mount -uw /" and press return.&lt;br /&gt;Type "passwd" and press return.&lt;br /&gt;&amp;nbsp;Enter new password (this will be for the root user account) and press return.&lt;br /&gt;Type "reboot" and press return.&lt;br /&gt;Enter Account settings and when prompted for administrator account and password, use the user name root and the password you just setup&lt;br /&gt;Check box for you standard account to administrate box&lt;br /&gt;&amp;nbsp;If all goes well you are admin again.&lt;br /&gt;&lt;br /&gt;Then log in as Root:&lt;br /&gt;&lt;br /&gt;dscl . -create /Groups/admin&lt;br /&gt;dscl . -create /Groups/admin RealName Administrators&lt;br /&gt;dscl . -create /Groups/admin PrimaryGroupID 80&lt;br /&gt;dscl . -create /Groups/admin Password [password]&lt;br /&gt;dscl . -create /Groups/admin GroupMembership root&lt;br /&gt;&lt;br /&gt;Original post:&amp;nbsp; &lt;a href="http://macosx.com/forums/howto-faqs/299801-howto-fix-user-lost-administrator-privileges.html%20"&gt;http://macosx.com/forums/howto-faqs/299801-howto-fix-user-lost-administrator-privileges.html &lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3363712140552635199?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3363712140552635199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3363712140552635199' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3363712140552635199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3363712140552635199'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/02/missing-admin-accounts-on-mac-fix.html' title='Missing admin accounts on Mac: FIX'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1711003836292572264</id><published>2011-02-23T23:08:00.000Z</published><updated>2011-02-23T23:08:57.299Z</updated><title type='text'>Convert plist to xml</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;pre style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;plutil -convert xml1 your_file.plist&lt;/code&gt;&lt;/span&gt;&lt;/pre&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;  To convert an XML .plist file to binary for use:&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;pre style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;plutil -convert binary1 your_file.plist&lt;/code&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1711003836292572264?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1711003836292572264/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1711003836292572264' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1711003836292572264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1711003836292572264'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/02/convert-plist-to-xml.html' title='Convert plist to xml'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2283635671033257165</id><published>2011-02-09T17:40:00.000Z</published><updated>2011-02-09T17:40:48.886Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='OpenDirectory'/><category scheme='http://www.blogger.com/atom/ns#' term='ODM'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><title type='text'>Remove an ODM from the command line</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;To remove an Open Directory Master first delete the LDAP entries in Directory Services and then open the Terminal and type:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sudo slapconfig -destroyldapserver&lt;br /&gt;&lt;br /&gt;It will take a while to complete.&amp;nbsp; After it has finished you should be able to remove the Opendirectory and DNS services from Server Manager (restart will be required). &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2283635671033257165?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2283635671033257165/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2283635671033257165' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2283635671033257165'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2283635671033257165'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2011/02/remove-odm-from-command-line.html' title='Remove an ODM from the command line'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5029236943278677703</id><published>2010-12-18T14:58:00.002Z</published><updated>2010-12-18T15:22:23.822Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='AFP'/><category scheme='http://www.blogger.com/atom/ns#' term='Leopard Server'/><category scheme='http://www.blogger.com/atom/ns#' term='SMB'/><category scheme='http://www.blogger.com/atom/ns#' term='launchd'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>Bound Leopard Server not allowing SMB or AFP connections</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;b&gt;Problem&lt;/b&gt;:&amp;nbsp; A 10.5.8 server was not allowing SMB or AFP connections.&amp;nbsp; The server was bound to AD but "id" commands were failing- &lt;i&gt;sometimes&lt;/i&gt;. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Looking at the logs I saw that they were filled with &lt;b&gt;launchd&lt;/b&gt; errors:&lt;br /&gt;&lt;br /&gt;&amp;nbsp;com.apple.launchd[1] (org.openldap.slapd): Throttling respawn: Will start in 10 &lt;br /&gt;&lt;br /&gt;These were causing very, very poor performance and pretty much preventing Directory Service from operating; that in turn prevented any logins.&lt;br /&gt;&lt;br /&gt;The first thing I attempted was to unbind the server but as it couldn't connect to the domain I did a Force Unbind, deleted the edu.mit.kerberos file and the Directory Services folder and restarted.&amp;nbsp; I then re-bound the server and immediately unbound: this ensured that the server's AD account would be removed.&lt;br /&gt;&lt;br /&gt;From the unbound server I took these actions:&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Changed the Windows role to Standalone server&lt;/li&gt;&lt;li&gt;Stopped the SMB services&lt;/li&gt;&lt;li&gt;Opened Terminal and ran "sudo –s /usr/libexec/slapd –Tt"&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;This returned:&lt;br /&gt;&lt;br /&gt;could not stat config file "/etc/openldap/slapd.conf": No such file or directory (2)&lt;br /&gt;slaptest: bad configuration file!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I then viewed the contents of the directory:&amp;nbsp; cd /etc/openldap/ls&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;There was no slapd.conf file present but there was a slapd.conf.default file so I renamed&amp;nbsp; it: "cp slapd.conf.default slapd.conf"&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I then re-ran the slapd command:&amp;nbsp; "/usr/libexec/slapd –Tt" and it returned:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;bdb_db_open: Warning - No DB_CONFIG file found in directory /private/var/db/openldap/openldap-data: (2)&lt;br /&gt;Expect poor performance for suffix dc=my-domain,dc=com.&lt;br /&gt;config file testing succeeded&lt;br /&gt;&lt;br /&gt;Since LDAPv3 is turned off in Directory Services this shouldn't be a problem &lt;/div&gt;&lt;ul&gt;&lt;li&gt;Reboot&amp;nbsp;&lt;/li&gt;&lt;li&gt;Launch Server Manager&lt;/li&gt;&lt;li&gt;Change the Windows role to Domain Member&lt;/li&gt;&lt;li&gt;Start the SMB service&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;AFP and SMB log-ins now worked.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;These steps and more info can be found here:&amp;nbsp; &lt;a href="http://discussions.apple.com/message.jspa?messageID=10613310%20"&gt;http://discussions.apple.com/message.jspa?messageID=10613310 &lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5029236943278677703?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5029236943278677703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5029236943278677703' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5029236943278677703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5029236943278677703'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/12/bound-leopard-server-not-allowing-smb.html' title='Bound Leopard Server not allowing SMB or AFP connections'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5435927431150902655</id><published>2010-12-09T12:45:00.001Z</published><updated>2010-12-09T12:47:05.220Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='AD'/><category scheme='http://www.blogger.com/atom/ns#' term='login'/><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='can&apos;t login'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac Binding'/><title type='text'>Can not log in to bound Mac using an AD account</title><content type='html'>&lt;u&gt;Symptom&lt;/u&gt;&amp;nbsp; &lt;br /&gt;A Mac that has been bound to the AD will not allow log-in from a particular AD user.&amp;nbsp; Other AD accounts are able to log-into the bound Mac and the user can log-into other computers.&lt;br /&gt;&lt;br /&gt;This is generally a symptom of a corrupt account on the computer.&amp;nbsp; You  have several options to remedy the situation.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Solutions&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Scenario One:&lt;/b&gt;&amp;nbsp; You are migrating a local account to a domain account.&amp;nbsp; You have bound the computer and are attempting to log in for the first time using the user's AD account and you get a shaking log in or an error "you are unable to log into the user's account".&amp;nbsp; Follow these steps to create a new local account, migrate the user’s data to that account then create an AD account and migrate the data to the AD account.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal"&gt;Log in as root&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Unbind the computer and      delete the entire /Library/Preferences/Directory Service folder and the      edu.mit.kerberos file&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Restart the computer&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Log in as root&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go to System Preferences/Accounts&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Create a new local account      for the user&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ul style="margin-top: 0in;" type="circle"&gt;&lt;li class="MsoNormal"&gt;Do not use the same name       as the user’s AD account&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Do not use the same name       as the existing account&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li class="MsoNormal"&gt;Go to &lt;b&gt;Users&lt;/b&gt; and locate the user’s old home folder&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Select all the folders in      the old home folder and drag them into the new home folder for the account      you just created.&amp;nbsp; When it prompts      you select &lt;b&gt;Replace All&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go back to the Desktop hit      &lt;b&gt;Shift-Apple-U &lt;/b&gt;to open the      Utilities folder&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Launch &lt;b&gt;Terminal&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Type &lt;b&gt;cd /Users&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Type &lt;b&gt;chown –R [user name]:staff /Users/[user name]. &lt;/b&gt;For      example:&amp;nbsp; &lt;b&gt;chown –R tsmith:staff /Users/mlewis&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ul style="margin-top: 0in;" type="circle"&gt;&lt;li class="MsoNormal"&gt;Remember, you are doing       the above command on the newly created home folder- the one you copied       all the data into&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Use the newly created       account name for “user name”&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li class="MsoNormal"&gt;Re-bind the computer&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Log out and then back in      with the user’s AD account&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ul style="margin-top: 0in;" type="circle"&gt;&lt;li class="MsoNormal"&gt;This will create a new       blank profile&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li class="MsoNormal"&gt;Log out and back in as      root&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go to &lt;b&gt;Users&lt;/b&gt; and locate the local home folder you created in a      previous step (the one you moved all the data into and did a “chown” on)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Select all the folders in      the folder and drag them into the newly create home folder (it will have      the user’s AD name)&amp;nbsp; When it prompts      you select &lt;b&gt;Replace All&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go back to the Desktop hit      &lt;b&gt;Shift-Apple-U &lt;/b&gt;to open the      Utilities folder&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Launch &lt;b&gt;Terminal&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Type &lt;b&gt;cd /Users&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Type &lt;b&gt;chown –R [user name]:staff /Users/[user name]. &lt;/b&gt;For      example:&amp;nbsp; &lt;b&gt;chown –R tom.smith:staff /Users/tom.smith&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Log out and back in using      the user’s AD account credentials&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Their desktop icons should      appear&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go to &lt;b&gt;Users/[user name]/Library/Keychains &lt;/b&gt;and rename the &lt;b&gt;login.keychain &lt;/b&gt;to &lt;b&gt;login.keychain.old&lt;/b&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Scenario Two:&amp;nbsp;&lt;/b&gt; Sometimes having a UNC path to a home folder in AD prevents a user from logging in.&amp;nbsp; In this case the user can not log into &lt;i&gt;any&lt;/i&gt; Mac but loggin into a PC works.&lt;br /&gt;&lt;br /&gt;Open the user's AD account and go to the Profile tab.&amp;nbsp; If there is a UNC path to a home folder, remove it.&amp;nbsp; Wait for replication and attempt to log in again.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Scenario Three:&lt;/b&gt;&amp;nbsp; You have bound the computer and are attempting to log in for the first  time using the user's AD account and you get a shaking log in or an  error "you are unable to log into the user's account".&lt;br /&gt;&lt;br /&gt;Other users can log in using their AD accounts.&amp;nbsp; Checking System Preferences/Users DOES NOT show an account for the user that is unable to log in.&lt;br /&gt;&lt;br /&gt;It is possible that the AD profile was partially created but that the process failed somewhere along the way.&amp;nbsp;&amp;nbsp; You first need to check if the profile exists on the computer even though it is not in "Users".&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Open a Terminal window&lt;/li&gt;&lt;li&gt;Type "dscl localhost"&lt;/li&gt;&lt;li&gt;Type "cd /Local/Default/Users&lt;/li&gt;&lt;li&gt;Type "ls"&lt;/li&gt;&lt;li&gt;If the problem user's account is displayed you must remove it&lt;/li&gt;&lt;/ul&gt;To remove the account you must first download and install Apple Server Admin Tools onto the client computer.&amp;nbsp; 10.6.4 admin tools can be found here:&lt;br /&gt;&lt;a href="http://support.apple.com/kb/DL1071"&gt;http://support.apple.com/kb/DL1071 &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After you have installed Admin Tools follow these steps to remove the problem account:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Go to Applications/Server &lt;/li&gt;&lt;li&gt;Launch Workgroup Manager (WGM)&lt;/li&gt;&lt;li&gt;At the connection screen enter an address of "localhost" and the UID and password of the local machine administrator&lt;/li&gt;&lt;li&gt;In WGM click on the "Accounts" icon&lt;/li&gt;&lt;li&gt;Make sure you are authenticated to /Local/Default&lt;/li&gt;&lt;li&gt;Click on the single-user icon above the search menu&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_MK3_W81wtn0/TQDNs_0xt3I/AAAAAAAABos/lw8C9yj4Dfc/s1600/Screen+shot+2010-12-09+at+12.36.07.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://1.bp.blogspot.com/_MK3_W81wtn0/TQDNs_0xt3I/AAAAAAAABos/lw8C9yj4Dfc/s320/Screen+shot+2010-12-09+at+12.36.07.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&amp;nbsp;Find the problem account in the list and click on the "Delete" icon&lt;/li&gt;&lt;li&gt;&amp;nbsp;Exit WGM and attempt to log into the machine again with the user's AD account&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5435927431150902655?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5435927431150902655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5435927431150902655' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5435927431150902655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5435927431150902655'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/12/can-not-log-in-to-bound-mac-using-ad.html' title='Can not log in to bound Mac using an AD account'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_MK3_W81wtn0/TQDNs_0xt3I/AAAAAAAABos/lw8C9yj4Dfc/s72-c/Screen+shot+2010-12-09+at+12.36.07.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8273830194258750086</id><published>2010-12-06T14:13:00.000Z</published><updated>2010-12-06T14:13:26.815Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Win7'/><category scheme='http://www.blogger.com/atom/ns#' term='gpresult'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows7'/><category scheme='http://www.blogger.com/atom/ns#' term='GPO'/><title type='text'>Check GPOs applied in Win7</title><content type='html'>This will export the results of the "gpresult" command to an html file:&lt;br /&gt;&lt;br /&gt;Gpresult /H c:\temp\[machine name].html&lt;br /&gt;&lt;br /&gt;I.g. Gprusult /H c:\temp\FRAMBW-DXP1234&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8273830194258750086?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8273830194258750086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8273830194258750086' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8273830194258750086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8273830194258750086'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/12/check-gpos-applied-in-win7.html' title='Check GPOs applied in Win7'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6248669660410982587</id><published>2010-11-02T18:13:00.001Z</published><updated>2010-11-02T18:13:59.539Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='ARD'/><category scheme='http://www.blogger.com/atom/ns#' term='Screen Sharing'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><title type='text'>ARD "Screen Sharing Available" problem</title><content type='html'>Many reports have come where ARD connections to remote computers display "Screen Sharing Available" next to the computer name and that although remote control and observation is possible, package install and file copies fail.&lt;br /&gt;&lt;br /&gt;The first thing to check is to see if the firewall on the ARD console and host computers are turned off.&amp;nbsp; By default the firewall blocks all ARD connections.&lt;br /&gt;&lt;br /&gt;Secondly, check to see if the folder  /var/db/RemoteManagement exists on the client machine.&amp;nbsp; For some reason, this folder doesn't get created and it prevents proper ARD connections.&lt;br /&gt;&lt;br /&gt;Also check A and PRT records to make sure there are no duplicate names or IPs for the client.&lt;br /&gt;&lt;br /&gt;You can also try uninstalling and reinstalling ARD.&lt;br /&gt;&lt;br /&gt;Uninstall instructions:&lt;br /&gt;&lt;ol type="1"&gt;&lt;li style="text-align: justify;" value="1"&gt;&lt;span style="font-size: small;"&gt;Open Terminal (located in /Applications/Utilities).   &lt;/span&gt;&lt;/li&gt;&lt;li style="text-align: justify;" value="2"&gt;&lt;span style="font-size: small;"&gt;Delete the client pieces from /System/Library/  using the following commands in the Terminal application:&lt;/span&gt;&lt;br /&gt;&lt;dl&gt;&lt;dt&gt;&lt;span style="font-size: small;"&gt; $ sudo rm -rf /System/Library/CoreServices/Menu\  Extras/RemoteDesktop.menu       &lt;/span&gt;&lt;/dt&gt;&lt;dt&gt;&lt;span style="font-size: small;"&gt; $ sudo rm -rf  /System/Library/CoreServices/RemoteManagement/       &lt;/span&gt;&lt;/dt&gt;&lt;dt&gt;&lt;span style="font-size: small;"&gt; $ sudo rm -rf  /System/Library/PreferencePanes/ARDPref.prefPane       &lt;/span&gt;&lt;/dt&gt;&lt;dt&gt;&lt;span style="font-size: small;"&gt; $ sudo rm -rf  /System/Library/StartupItems/RemoteDesktopAgent/     &lt;/span&gt;&lt;/dt&gt;&lt;/dl&gt;&lt;/li&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;li style="text-align: justify;" value="3"&gt;&lt;span style="font-size: small;"&gt;Delete the client preferences from  /Library/Preferences/ using the following command in the Terminal  application:&lt;/span&gt;&lt;br /&gt;&lt;dl&gt;&lt;dt&gt;&lt;span style="font-size: small;"&gt; $ sudo rm /Library/Preferences/com.apple.ARDAgent.plist       &lt;/span&gt;&lt;/dt&gt;&lt;dt&gt;&lt;span style="font-size: small;"&gt; $ sudo rm  /Library/Preferences/com.apple.RemoteManagement.plist     &lt;/span&gt;&lt;/dt&gt;&lt;/dl&gt;&lt;/li&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;li value="4"&gt;&lt;span style="font-size: small;"&gt;Delete the client installation receipts from  /Library/Receipts/ using the following command in the Terminal  application:&lt;/span&gt;&lt;br /&gt;&lt;dl&gt;&lt;dt style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt; $ sudo rm -r /Library/Receipts/RemoteDesktopClient*       &lt;/span&gt;&lt;/dt&gt;&lt;dt style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt; $ sudo rm -rf /var/db/RemoteManagement/&amp;nbsp;&lt;/span&gt;&lt;/dt&gt;&lt;dt&gt;&lt;br /&gt;&lt;/dt&gt;&lt;dt&gt;To reinstall download the latest ARD client from Apple.&lt;/dt&gt;&lt;dt&gt;&lt;br /&gt;&lt;/dt&gt;&lt;dt&gt;&lt;br /&gt;&lt;/dt&gt;&lt;dt style="text-align: left;"&gt;&lt;br /&gt;&lt;/dt&gt;&lt;/dl&gt;&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6248669660410982587?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6248669660410982587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6248669660410982587' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6248669660410982587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6248669660410982587'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/11/ard-screen-sharing-available-problem.html' title='ARD &quot;Screen Sharing Available&quot; problem'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4257614595919922623</id><published>2010-10-28T12:00:00.002+01:00</published><updated>2010-10-28T12:00:50.160+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='error -50'/><category scheme='http://www.blogger.com/atom/ns#' term='Snow Leopard'/><category scheme='http://www.blogger.com/atom/ns#' term='SMB'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Snow Leopard Error -50 when copying to an SMB share</title><content type='html'>&lt;div style="text-align: justify;"&gt;Symptom&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Snow Leopard client copying file to SMB will get a –50 unkown error and the copying will halt. This only happens to Snow Leopard and only to SMB. Copying the same files to AFP works fine. It is also only on certain files. We can take this file to another Snow Leopard machine and reproduce it every time.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Cause&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We found out that it has to do with files with resource fork. I think Snow Leopard and Leopard no longer embed resource fork into files anymore. But I am guessing these files were touched or created by older Apple OS. This explains why out of thousands of files, we only see some files with this problem. This is due to the fact that the Snow Leopard Client now defaults to using NTFS Streams rather than AppleDouble files (dot underscore files) to store the resource fork.  &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Solution&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Turn off NTFS Streams support in Snow Leopard. You can do this on the client by running this command.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;echo "[default]" | sudo tee -a /etc/nsmb.conf&lt;/div&gt;&lt;div style="text-align: justify;"&gt;echo "streams=no" | sudo tee -a /etc/nsmb.conf &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Of course this would be a pain if you have to touch every clients. An easier way is to touch the share by creating a file at the root of the share called ".com.apple.smb.streams.off".   As this is a hidden file, it is probably best to do this from the command line.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;cd /Volumes/sharename/&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;touch .com.apple.smb.streams.off&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;No reboot is needed. Client just need to dismount and mount the share again.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4257614595919922623?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4257614595919922623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4257614595919922623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4257614595919922623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4257614595919922623'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/10/snow-leopard-error-50-when-copying-to.html' title='Snow Leopard Error -50 when copying to an SMB share'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1322292900910592419</id><published>2010-10-19T17:28:00.000+01:00</published><updated>2010-10-19T17:28:32.691+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UPN'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;can&apos;t connect to server&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;User Principal Name&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Windows and Mac users unable to access server shares and printers</title><content type='html'>We received a report from several offices that users were unable to access server shares or print until their passwords were reset in AD.&lt;br /&gt;&lt;br /&gt;Users were able to log into their computers and send/receive mail.&lt;br /&gt;&lt;br /&gt;The users were receiving a "user name could not be found" error when attempting to connect to servers and the printers were showing "Unable to Connect".&lt;br /&gt;&lt;br /&gt;The problem was that the User Principal Name (UPN) was holding old cached values.  Logging into the computer using the full UPN (first.last@domain.com), restarting and logging back in with the normal AD name (first.last) resolved the issue.&lt;br /&gt;&lt;br /&gt;This problem seemed to only affect users who had had their UPN updated recently.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1322292900910592419?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1322292900910592419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1322292900910592419' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1322292900910592419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1322292900910592419'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/10/windows-and-mac-users-unable-to-access.html' title='Windows and Mac users unable to access server shares and printers'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-719274917258235880</id><published>2010-10-07T07:30:00.000+01:00</published><updated>2010-10-07T07:30:31.169+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac Binding'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Mac Binding Fails- Advice from Apple</title><content type='html'>Apple's KB regarding binding problems and possible work-arounds involving clearing out Kerberos config files and DNS config check:&lt;br /&gt;&lt;br /&gt;http://support.apple.com/kb/TS2691&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-719274917258235880?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/719274917258235880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=719274917258235880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/719274917258235880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/719274917258235880'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/10/mac-binding-fails-advice-from-apple.html' title='Mac Binding Fails- Advice from Apple'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6569594008331570145</id><published>2010-10-06T10:02:00.000+01:00</published><updated>2010-10-06T10:02:03.038+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;Snow Leopard&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='10.6'/><category scheme='http://www.blogger.com/atom/ns#' term='SMB'/><category scheme='http://www.blogger.com/atom/ns#' term='connection'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X&quot;'/><title type='text'>Snow Leopard (10.6) can not connect to server using SMB: RESOLVED</title><content type='html'>&lt;div style="text-align: justify;"&gt;Problem: AD bound 10.6.x Macs were experiencing problems connecting to SMB shares on Windows servers.&amp;nbsp; Users could not connect to the shares, or it would take several minutes to open/browse folders.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Cause:&amp;nbsp;&amp;nbsp;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;It was found that the issue happens when there is a folder or file on the share for which the security list includes an “Unknown SID”. When listing the content of the share, the OS X Directory Service plugin attempts to resolve all SIDs to AD objects. In this case, the plugin encounters a “Unknown SID” and expends 60 seconds attempting to resolve the SID. Once 60-second timeout is reached, the plugin skips the entry and will list the share contents. Now, if there are multiple files or folders of “Unknown SIDs”, the time for listing the content will multiply base on how many of these “Unknown SIDs” on there thus explaining the different delay time users are experiencing.&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;Resolution: &amp;nbsp;&lt;/span&gt;   &lt;meta content="" name="Title"&gt;&lt;/meta&gt; &lt;meta content="" name="Keywords"&gt;&lt;/meta&gt; &lt;meta content="text/html; charset=utf-8" http-equiv="Content-Type"&gt;&lt;/meta&gt; &lt;meta content="Word.Document" name="ProgId"&gt;&lt;/meta&gt; &lt;meta content="Microsoft Word 2008" name="Generator"&gt;&lt;/meta&gt; &lt;meta content="Microsoft Word 2008" name="Originator"&gt;&lt;/meta&gt; &lt;link href="file://localhost/Users/marlewis/Library/Caches/TemporaryItems/msoclip/0clip_filelist.xml" rel="File-List"&gt;&lt;/link&gt;  &lt;style&gt;&lt;!-- /* Font Definitions */@font-face	{font-family:Arial;	panose-1:2 11 6 4 2 2 2 2 2 4;	mso-font-charset:0;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:3 0 0 0 1 0;}@font-face	{font-family:Verdana;	panose-1:2 11 6 4 3 5 4 4 2 4;	mso-font-charset:0;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:3 0 0 0 1 0;} /* Style Definitions */p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-parent:"";	margin:0cm;	margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:12.0pt;	font-family:"Times New Roman";	mso-fareast-font-family:"Times New Roman";	mso-bidi-font-family:"Times New Roman";	mso-ansi-language:EN-US;}a:link, span.MsoHyperlink	{color:blue;	text-decoration:underline;	text-underline:single;}a:visited, span.MsoHyperlinkFollowed	{mso-style-noshow:yes;	color:purple;	text-decoration:underline;	text-underline:single;}@page Section1	{size:612.0pt 792.0pt;	margin:72.0pt 90.0pt 72.0pt 90.0pt;	mso-header-margin:36.0pt;	mso-footer-margin:36.0pt;	mso-paper-source:0;}div.Section1	{page:Section1;}--&gt;&lt;/style&gt;     &lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;Test indicates that once these “Unknown SIDs” are removed from the affected file/folder, the speed of SMB will return to normal. The mount and content listing of the share will take seconds instead of minutes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;Apple will take the finding back to their product engineering to determine how they might be able to mitigate the timeout issue from OS X.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;The problem of resolving this issue for server administrators is that it is not practical to identify these “Unknown SIDs” and remove them manually. After some research, it seems that Microsoft has a tool to do this.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;SUBINACL - &lt;/span&gt;&lt;span lang="EN-US"&gt;Display or modify Access Control Entries (ACEs) for file and folder Permissions, Ownership and Domain.&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&amp;amp;displaylang=en&lt;/a&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;Download the MSI and install it to your file server. You can then run it using the following syntax. It will removed all the “Unknown SIDs” from the files and folders you specify.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US"&gt;subinacl /subdirectories X:\* /cleandeletedsidsfrom=IPGNA&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Arial; font-size: 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;This will clean out all “Unknown SIDs” from the path you specify and all the directories below that. You can also use a /TESTMODE switch to test it out. It will run the command and show you the result without actually modifying anything. It is recommended that you run it under testmode once.&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.blogger.com/post-create.do" name="_GoBack"&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6569594008331570145?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6569594008331570145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6569594008331570145' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6569594008331570145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6569594008331570145'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/10/snow-leopard-106-can-not-connect-to.html' title='Snow Leopard (10.6) can not connect to server using SMB: RESOLVED'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8433435438825798311</id><published>2010-09-08T15:40:00.000+01:00</published><updated>2010-09-08T15:40:55.490+01:00</updated><title type='text'>Using ADModify to change login and pre-2000 name</title><content type='html'>&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;Launch ADModify using "run-as" and login using a DA account on the domain where the users you are modifying are. &lt;/div&gt;&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;For login name:&amp;nbsp; Under the Accounts tab enter the attribute:&amp;nbsp; %'givenName'%.%'sn'%&lt;/div&gt;&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;For pre-2000 name:&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;ul style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;li&gt;Click on "Custom" tab&lt;/li&gt;&lt;li&gt;Put a tick in "make a customized attribute modification&lt;/li&gt;&lt;li&gt;Attribute name:&amp;nbsp; sAMAccountName&lt;/li&gt;&lt;li&gt;Value:&amp;nbsp; %'givenName'%.%'sn'% &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-family: Calibri,Verdana,Helvetica,Arial;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;span style="font-size: 11pt;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; &lt;!--EndFragment--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8433435438825798311?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8433435438825798311/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8433435438825798311' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8433435438825798311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8433435438825798311'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/09/using-admodify-to-change-login-and-pre.html' title='Using ADModify to change login and pre-2000 name'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-264819218100325385</id><published>2010-08-30T19:56:00.000+01:00</published><updated>2010-08-30T19:56:34.950+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FW Boot'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='Target Boot'/><title type='text'>Target booting an Xserver to install from another computer</title><content type='html'>We found ourselves in a situation where we were unable to install from the optical drive on an Xserver.&amp;nbsp; We used the following steps to resolve the problem:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Attach a FW cable between the Xserver and another Mac (we used a Mac Book Pro)&lt;/li&gt;&lt;li&gt;Insert the Server Install DVD into the remote computer &lt;/li&gt;&lt;li&gt;Turn off both devices&lt;/li&gt;&lt;li&gt;Restart the remote computer in Target Disk Mode (holding down the "T" key)&lt;/li&gt;&lt;li&gt;Restart the Xserver holding down the Option (alt) key and select the remote install drive as the startup disk&lt;/li&gt;&lt;li&gt;Continue with the install normally&lt;/li&gt;&lt;/ol&gt;It is VITAL that you do not target boot the Xserve onto the client: put the client into Target Disk Mode first!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-264819218100325385?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/264819218100325385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=264819218100325385' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/264819218100325385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/264819218100325385'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/08/target-booting-xserver-to-install-from.html' title='Target booting an Xserver to install from another computer'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5907378303726408466</id><published>2010-08-30T19:50:00.000+01:00</published><updated>2010-08-30T19:50:36.508+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='changeip'/><category scheme='http://www.blogger.com/atom/ns#' term='re-IP'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>After a re-IP of an Xserver, XP clients could not log in using SMB</title><content type='html'>An office moved locations and in so doing upgraded their DC to Windows Server 2008 and also change the IP of their Tiger (10.4.11) Xserve.&lt;br /&gt;&lt;br /&gt;After completing the process, XP users were unable to log into the Xserve using SMB.&amp;nbsp; AFP connections were unaffected.&lt;br /&gt;&lt;br /&gt;After many long nights of troubleshooting and searching through server and WireShark logs we were still no closer to a solution.&amp;nbsp; A Leopard server was built at the location to test and it initially had the exact same problem.&lt;br /&gt;&lt;br /&gt;To get the test Leopard server to work we had to follow the steps outlined below and replace the smb.conf file with the smb.conf.template file.&amp;nbsp; After doing these steps, SMB connections to the Leopard server were successful.&lt;br /&gt;&lt;br /&gt;During the entire process we were working with Apple and they built Tiger, Leopard and Snow Leopard servers in their environment to see if they could reproduce the problem- the could not.&lt;br /&gt;&lt;br /&gt;Apple felt that contrary to our initial assumptions, changing to a 2008 DC did not cause the problem.&amp;nbsp; Rather the re-IP of the Tiger server broke SMB authentication.&amp;nbsp; They could not pinpoint the problem exactly but suggested we follow these steps to resolve the problem:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt; 1. Change the role of Windows to Standalone server. &amp;nbsp;Stop the Windows service.&lt;br /&gt;&lt;br /&gt;2. Unbind from Active Directory.&lt;br /&gt;&lt;br /&gt;3. Run the changeip script and change the IP address in System Preferences/Network. &amp;nbsp;Restart the server.&lt;br /&gt;&lt;br /&gt;4. Run the command "sudo changeip -checkhostname". &amp;nbsp;If everything is correct, bind the server to Active Directory.&lt;br /&gt;&lt;br /&gt;5. Change the role of Windows to Domain Member and start the Windows service.&lt;br /&gt;&lt;br /&gt;6. Verify the SMB shares are configured correctly (I created a new share).&lt;br /&gt;&lt;br /&gt;7. Have XP clients connect to the 10.4 server.&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;Unfortunately, the problematic Tiger server wouldn't allow us to complete the tasks- failing on step 5- changing the role back to a Domain Member.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;At that point it was decided to re-build the server as a 10.5.8 Leopard server.&amp;nbsp; 14 hours later, we finished the job!&amp;nbsp; There were problems with the mirrored set in the Xserver which forced us to break the RAID and install on a single physical drive.&lt;br /&gt;&lt;br /&gt;We were finally successful at re-building the server and when we were done XP clients could connect using SMB and get single-sign-on.&lt;br /&gt;&lt;br /&gt;One nice thing: because we only rebuild the Xserver and not the fiber channel RAIDS attached to it, all the AD file and folder permissions were retained.&amp;nbsp; This saved us a huge amount of time by not having to re-perm all the shares!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!--EndFragment--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5907378303726408466?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5907378303726408466/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5907378303726408466' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5907378303726408466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5907378303726408466'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/08/after-re-ip-of-xserver-xp-clients-could.html' title='After a re-IP of an Xserver, XP clients could not log in using SMB'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8495766990134925924</id><published>2010-08-16T08:38:00.000+01:00</published><updated>2010-08-16T08:38:11.076+01:00</updated><title type='text'>Resetting a Mac password with or without a boot disk</title><content type='html'>Boot into single user mode: hold down Command (alt) -S on startup&lt;br /&gt;&lt;br /&gt;Follow these steps:&lt;br /&gt;&lt;br /&gt;http://osxdaily.com/2010/08/10/forgot-mac-password-how-to-reset-mac-password/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8495766990134925924?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8495766990134925924/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8495766990134925924' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8495766990134925924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8495766990134925924'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/08/resetting-mac-password-with-or-without.html' title='Resetting a Mac password with or without a boot disk'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6189121005942175035</id><published>2010-07-22T19:13:00.001+01:00</published><updated>2010-07-22T19:13:26.335+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='Directory Services'/><title type='text'>Restarting Directory Servcices from the Command Line: OS X</title><content type='html'>killall -HUP DirectoryService&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6189121005942175035?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6189121005942175035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6189121005942175035' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6189121005942175035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6189121005942175035'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/07/restarting-directory-servcices-from.html' title='Restarting Directory Servcices from the Command Line: OS X'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5190816827020037026</id><published>2010-07-16T15:20:00.000+01:00</published><updated>2010-07-16T15:20:40.415+01:00</updated><title type='text'>DHCP will not authorize after a re-IP of the server</title><content type='html'>You must first unauthorize a DHCP server scope prior to re-IPing the server.&amp;nbsp; If you do not then you will be unable to re-authorize the scope after the re-IP.&lt;br /&gt;&lt;br /&gt;If you have already re-IPed the server without first authorizing the scope open DHCP from Admin Tools, right-click on "DHCP" and go to "Manage Authorized Servers."&amp;nbsp; Find the old DHCP server name/IP and click on "Unauthorize."&lt;br /&gt;&lt;br /&gt;Once you have removed the old DHCP server you can authorize the re-IPed server.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5190816827020037026?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5190816827020037026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5190816827020037026' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5190816827020037026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5190816827020037026'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/07/dhcp-will-not-authorize-after-re-ip-of.html' title='DHCP will not authorize after a re-IP of the server'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5779347056240460104</id><published>2010-06-24T13:34:00.000+01:00</published><updated>2010-06-24T13:34:05.890+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='fonts'/><title type='text'>Mac Fonts</title><content type='html'>It is a good idea to remove all the fonts from ~/Library/Fonts and /Library/Fonts but leave /System/Library/Fonts alone.&lt;br /&gt;&lt;br /&gt;Create a "My Fonts" folder, dump your fonts in there and activate when necessary.&lt;br /&gt;&lt;br /&gt;Here are two good overviews of how the OSes handle fonts:&lt;br /&gt;&lt;br /&gt;Leopard: &amp;nbsp;&lt;a href="http://www.prepressure.com/fonts/basics/leopard_fonts"&gt;http://www.prepressure.com/fonts/basics/leopard_fonts&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt; &lt;/u&gt;&lt;/span&gt;&lt;br /&gt;Snow Leopard: &amp;nbsp;&lt;span style="color: blue;"&gt;&lt;u&gt;&lt;a href="http://www.prepressure.com/fonts/basics/snow-leopard-fonts"&gt;http://www.prepressure.com/fonts/basics/snow-leopard-fonts&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5779347056240460104?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5779347056240460104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5779347056240460104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5779347056240460104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5779347056240460104'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/06/mac-fonts.html' title='Mac Fonts'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3539651147096013091</id><published>2010-06-09T21:38:00.000+01:00</published><updated>2010-06-09T21:38:56.851+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='login'/><category scheme='http://www.blogger.com/atom/ns#' term='can&apos;t login'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='SMB'/><category scheme='http://www.blogger.com/atom/ns#' term='Macs'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;home folders&quot;'/><title type='text'>Mac users can not log into a bound machine continued.  Network home folder problem</title><content type='html'>&lt;!--StartFragment--&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;Bound 10.6 machines require that all users attempting to log in with AD credentials have either a correct path to an accessible home folder or have “force local home folder” ticked in Directory Utility. &lt;br /&gt;&lt;br /&gt;Here are some things to try:&lt;br /&gt;&lt;br /&gt;Look at the user’s account and see if they have home folders listed. &amp;nbsp;If they do, make sure they are valid and remove them if they are not. &amp;nbsp;You might simply want to remove them full stop- this has resolved problems like this in the past. &amp;nbsp;Something else to keep in mind: Snow Leopard has horrible problems connecting to SMB shares so if a user has a SMB home folder defined in their AD account it could simply failing to connect and halting the login process.&lt;br /&gt;&lt;br /&gt;Use the work-around found in this TS article from Apple: &lt;a href="http://support.apple.com/kb/TS3346"&gt;http://support.apple.com/kb/TS3346&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To force a local home folder do this:&lt;br /&gt;&lt;br /&gt;Directory Utility &amp;gt; Active Directory &amp;gt; Show Advanced Options&lt;br /&gt;&lt;br /&gt;Place a checkmark in "Force local home on startup disk" and uncheck "use UNC path from AD" to force a local home and ignore what's in the directory.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;br /&gt;&lt;!--EndFragment--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3539651147096013091?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3539651147096013091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3539651147096013091' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3539651147096013091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3539651147096013091'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/06/mac-users-can-not-log-into-bound.html' title='Mac users can not log into a bound machine continued.  Network home folder problem'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-659179325280221351</id><published>2010-05-28T10:30:00.000+01:00</published><updated>2010-05-28T10:30:45.957+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Snow Leopard'/><category scheme='http://www.blogger.com/atom/ns#' term='screen saver'/><category scheme='http://www.blogger.com/atom/ns#' term='lock'/><category scheme='http://www.blogger.com/atom/ns#' term='screensaver'/><category scheme='http://www.blogger.com/atom/ns#' term='password lock'/><title type='text'>Enable Screen Saver Locking From the Command Line: Snow Leopard</title><content type='html'>&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;The settings are now stored in ~/Library/Preferences/com.apple.screensaver.plist:&lt;br /&gt;&lt;br /&gt;$ defaults read com.apple.screensaver&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;askForPassword = 1;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;askForPasswordDelay = 5;&lt;br /&gt;}&lt;br /&gt;$&lt;br /&gt;&lt;br /&gt;To turn on the screen saver lock:&lt;br /&gt;&lt;br /&gt;defaults write com.apple.screensaver askForPassword -int 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;To turn off the screen saver lock:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt; defaults write com.apple.screensaver askForPassword -int 0&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-659179325280221351?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/659179325280221351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=659179325280221351' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/659179325280221351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/659179325280221351'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/05/enable-screen-saver-locking-from.html' title='Enable Screen Saver Locking From the Command Line: Snow Leopard'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3592346763411884407</id><published>2010-05-27T14:09:00.000+01:00</published><updated>2010-05-27T14:09:28.975+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='screen saver'/><title type='text'>Turn on Mac screen saver password from command line (not for Snow Leopard)</title><content type='html'>&lt;div style="color: black;"&gt;&lt;span style="font-size: small;"&gt;Turn on the screen saver password:&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;defaults -currentHost write com.apple.screensaver askForPassword  -int 1&lt;/code&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;Turn off Screen saver password:&lt;/code&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;code&gt;&lt;span style="font-size: small;"&gt;defaults -currentHost write com.apple.screensaver askForPassword  -int &lt;/span&gt;0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;code&gt;Again, this doesn't work for Snow Leopard. &lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3592346763411884407?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3592346763411884407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3592346763411884407' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3592346763411884407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3592346763411884407'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/05/turn-on-mac-screen-saver-password-from.html' title='Turn on Mac screen saver password from command line (not for Snow Leopard)'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8017707970578077655</id><published>2010-03-19T19:17:00.002Z</published><updated>2010-03-20T01:03:03.621Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='dfsutil'/><category scheme='http://www.blogger.com/atom/ns#' term='DFS'/><title type='text'>PC: slow login - DFS refferal to wrong DC -using dfsutil</title><content type='html'>After a re-IP two sites were experiencing slow logins.&amp;nbsp; Both sites had a "shared services" network where the DC was placed.&amp;nbsp; The shared services network is on a different VLAN than the user VLANs on the sites.&lt;br /&gt;&lt;br /&gt;Start troubleshooting by logging into the local DC, going to Start\Run and typing \\full.domain.name.com\sysvol.&amp;nbsp; Once the sysvol window opens, right-click on any blank area and go to Properties/DFS.&amp;nbsp; The local DC should be set as the active referral ("Yes" next to the DC's name and a little tick on the name).&amp;nbsp; NOTE:&amp;nbsp; you can perform this check from any server or desktop on the site.&lt;br /&gt;&lt;br /&gt;If the DFS referral is pointing to anything else than the local DC chances are there is a problem with Sites and Services; additionally a cleanup of the DFS cache on the DC might be necessary. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;Make sure all the subnets at the location are in Sites and Services, INCLUDING the one the DC is in&lt;/li&gt;&lt;li&gt;Use dfsutil to clean up the DFS packets and cache&lt;/li&gt;&lt;/ul&gt;Full details of the dfsutil commands can be found &lt;a href="http://technet.microsoft.com/en-us/library/cc736784%28WS.10%29.aspx"&gt;HERE &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;On the DC run: &lt;br /&gt;&lt;ul&gt;&lt;li&gt;dfsutil /purgemupcache&lt;/li&gt;&lt;li&gt; dfsutil /pktflush&lt;/li&gt;&lt;li&gt;dfsutil /spcflush&lt;/li&gt;&lt;li&gt;dfsutil /pktinfo (shows which DC the DFS share is referring to)&lt;/li&gt;&lt;li&gt;dfsutil /spcinfo (shows the full path to the DFS share)&lt;/li&gt;&lt;/ul&gt;Typing "dfsutil" from the command prompt will get a list of commands.&lt;br /&gt;&lt;br /&gt;Restarting after running these commands.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8017707970578077655?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8017707970578077655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8017707970578077655' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8017707970578077655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8017707970578077655'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/03/pc-slow-login-dfs-refferal-to-wrong-dc.html' title='PC: slow login - DFS refferal to wrong DC -using dfsutil'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3168381683866252921</id><published>2010-03-15T14:49:00.000Z</published><updated>2010-03-15T14:49:46.337Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='login'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><title type='text'>Mac User can't log in: computer bound to AD</title><content type='html'>In the ongoing saga of Mac users unable to log into a bound machine, we add this to the list:&lt;br /&gt;&lt;br /&gt;A user could log into bound PCs but was unable to log into any bound Mac.&amp;nbsp; The user would get a shaky login screen with a cryptic message.&lt;br /&gt;&lt;br /&gt;The problem was the user's AD account had a home folder set in their AD "profile" tab that pointed to an invalid share.&lt;br /&gt;&lt;br /&gt;We have also seen the same problem with SMB shares full-stop.&amp;nbsp; Removing the home folder path in the AD account allowed the user to log in.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3168381683866252921?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3168381683866252921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3168381683866252921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3168381683866252921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3168381683866252921'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/03/mac-user-cant-log-in-computer-bound-to.html' title='Mac User can&apos;t log in: computer bound to AD'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5493811329193017602</id><published>2010-03-10T13:10:00.000Z</published><updated>2010-03-10T13:10:31.499Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='BackupExec'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;Time Machine&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='Entourage'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>Entourage database and Time Machine</title><content type='html'>&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;Time Machine and the Entourage database don’t play well together. &amp;nbsp;The problem most people have is that their Entourage profile is a massive, monolithic database and even opening Entourage causes Time Machine to back up the entire database not just the changes. &amp;nbsp;Normally the advice is to manually copy the user profile every once and a while and not let Time Machine back it up unless you have an infinite amount of disk space.&lt;br /&gt;&lt;br /&gt;You can also have problems because even if all your Office apps are closed the database daemon is still running and this can lead to corrupt database backups. &amp;nbsp;Before you backup the Office database you can run this command:&lt;br /&gt;&lt;br /&gt;tell application "Microsoft Database Daemon" to quit&lt;br /&gt;&lt;br /&gt;And after you are done you can do restart or run this command:&lt;br /&gt;&lt;br /&gt;tell application "Microsoft Database Daemon" to launch&lt;/span&gt;&lt;/span&gt; &lt;!--EndFragment--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5493811329193017602?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5493811329193017602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5493811329193017602' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5493811329193017602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5493811329193017602'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/03/entourage-database-and-time-machine.html' title='Entourage database and Time Machine'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1912832542768692253</id><published>2010-03-10T13:07:00.000Z</published><updated>2010-03-10T13:07:55.545Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;slow login&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='SRV'/><category scheme='http://www.blogger.com/atom/ns#' term='PC'/><category scheme='http://www.blogger.com/atom/ns#' term='_ldap'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;sites and services&quot;'/><title type='text'>PC slow login- Sites and Services correct but incorrect SRV record</title><content type='html'>A site that had recently been re-IPed was complaining about slow logins on their PCs- it could take a user up to 15 minutes to log in.&lt;br /&gt;&lt;br /&gt;Sites and Services was setup correctly with the proper subnet and DC assigned to the site.&lt;br /&gt;&lt;br /&gt;We found that there was an erroneous entry in DNS which was causing the machines to use the wrong DC for authentication.&amp;nbsp; The entry was found here:&lt;br /&gt;&lt;br /&gt;Forward Lookup Zones&lt;br /&gt;[our domain]&lt;br /&gt;DomainDnsZones&lt;br /&gt;_sites&lt;br /&gt;[site name]&lt;br /&gt;_tcp&lt;br /&gt;&lt;br /&gt;There were two _ldap entries in this location.&amp;nbsp; One pointing to the correct DC and one to an incorrect DC.&amp;nbsp; Removing the incorrect record resolved the issue.&lt;br /&gt;&lt;br /&gt;Note:&amp;nbsp; it is a good idea to check all the Sites entries in DNS to make sure that there are not other erroneous _ldap entries&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1912832542768692253?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1912832542768692253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1912832542768692253' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1912832542768692253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1912832542768692253'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/03/pc-slow-login-sites-and-services.html' title='PC slow login- Sites and Services correct but incorrect SRV record'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6994117718344800260</id><published>2010-02-05T16:20:00.000Z</published><updated>2010-02-05T16:20:30.617Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='DHCP'/><category scheme='http://www.blogger.com/atom/ns#' term='lease'/><title type='text'>Computer name not appearing in DHCP lease</title><content type='html'>We were seeing a problem where some DHCP leases were not showing the computer name.&amp;nbsp; None of these machines with blank lease names would show up in DNS.&lt;br /&gt;&lt;br /&gt;It turned out that each of the machines with blank DHCP lease names were Macs and they had different sharing names than the computer names there were bound to the AD with.&lt;br /&gt;&lt;br /&gt;The solution was to make the sharing name the same as the AD computer name.&amp;nbsp; As soon as this was done and the computer was restarted the machine appeared in DNS and the DHCP lease had the proper name associated with it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6994117718344800260?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6994117718344800260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6994117718344800260' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6994117718344800260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6994117718344800260'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2010/02/computer-name-not-appearing-in-dhcp.html' title='Computer name not appearing in DHCP lease'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-339404343017599104</id><published>2009-12-30T16:42:00.001Z</published><updated>2010-12-18T13:14:52.688Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='changeip'/><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='DNS name'/><title type='text'>Changeip command for updating IP and host names: OS X Server</title><content type='html'>If you need to update the IP address or host name on an OS X server you need to do a changeip command:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;First do sudo changeip –checkhostname to see what the true host name is.&lt;br /&gt;&lt;br /&gt;You can then change the IP and the host name in one fell swoop:&lt;br /&gt;&lt;br /&gt;Sudo changeip - [old IP] [new IP] [old host name] [new host name]&lt;br /&gt;&lt;br /&gt;ex: sudo changeip - 100.192.46.10 100.192.46.12 oldserver.mynetwork.com newserver.mynetwork.com&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;If you just want to change the IP then leave out the host name part. &amp;nbsp;If you want to change only the host name you still must put the IP addresses- even if they are the same.&lt;br /&gt;&lt;br /&gt;On the sever open a Terminal window and type “man changeip” for a good rundown of the command syntax and parameters.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Palatino;"&gt;&lt;span style="font-size: 11pt;"&gt;&lt;a href="http://developer.apple.com/mac/library/documentation/Darwin/Reference/ManPages/man8/changeip.8.html"&gt;Here&lt;/a&gt; is a link to the man page.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-339404343017599104?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/339404343017599104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=339404343017599104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/339404343017599104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/339404343017599104'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/12/changeip-command-for-updating-ip-and.html' title='Changeip command for updating IP and host names: OS X Server'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-6723363078694866301</id><published>2009-12-18T10:15:00.002Z</published><updated>2009-12-30T16:36:51.471Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Snow Leopard'/><category scheme='http://www.blogger.com/atom/ns#' term='screen saver'/><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='lock'/><title type='text'>Snow Leopard: Kerberos ticket not renewing coming out of Screen Saver</title><content type='html'>We had another case opened with Apple about Kerberos ticket not renewing after typing in password coming out of screen saver in Snow Leopard. They send me this instruction on modifying a file in /etc and it looks like it is resolving the problem. If you guys have Snow Leopard machine bound to AD. Please try it out too so we can confirm it does work.&lt;br /&gt;&lt;br /&gt;Please edit the "“system.login.screensaver” entry in the /etc/authorization file to read like this:&lt;br /&gt;&lt;br /&gt;&lt;key&gt;system.login.screensaver&lt;/key&gt;&lt;br /&gt;&lt;dict&gt;&lt;br /&gt;&lt;key&gt;class&lt;/key&gt;&lt;br /&gt;&lt;string&gt;rule&lt;/string&gt;&lt;br /&gt;&lt;key&gt;comment&lt;/key&gt;&lt;br /&gt;&lt;string&gt;(Use SecurityAgent.) The owner or any administrator can unlock the screensaver.&lt;/string&gt;                       &lt;br /&gt;&lt;key&gt;rule&lt;/key&gt;&lt;br /&gt;&lt;string&gt;authenticate-session-owner-or-admin&lt;/string&gt;&lt;br /&gt;&lt;/dict&gt;&lt;br /&gt;&lt;br /&gt;Note that the string: &lt;br /&gt;&lt;br /&gt;The owner or any administrator can unlock the screensaver&lt;br /&gt;&lt;br /&gt;is changed to:&lt;br /&gt;&lt;br /&gt;(Use SecurityAgent.) The owner or any administrator can unlock the screensaver&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-6723363078694866301?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/6723363078694866301/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=6723363078694866301' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6723363078694866301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/6723363078694866301'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/12/snow-leopard-kerberos-ticket-now.html' title='Snow Leopard: Kerberos ticket not renewing coming out of Screen Saver'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-7410431178182087262</id><published>2009-11-16T13:54:00.000Z</published><updated>2009-11-16T13:54:41.694Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Outlook'/><category scheme='http://www.blogger.com/atom/ns#' term='cached mailbox'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange 2007'/><category scheme='http://www.blogger.com/atom/ns#' term='on-line mailbox'/><title type='text'>To cache secondary mailboxes in Outlook</title><content type='html'>One of the problems in Outlook is that if a user wants to send/receive mail using multiple accounts it is a pain to set up.  Not only that but once you've attached the second account in Outlook it is ON-LINE and not cached.  This results in very slow performance.&lt;br /&gt;&lt;br /&gt;MS has a registry fix for this (if you are using Exchange 2007):&lt;br /&gt;&lt;br /&gt;http://support.microsoft.com/kb/955572&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-7410431178182087262?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/7410431178182087262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=7410431178182087262' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7410431178182087262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7410431178182087262'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/11/to-cache-secondary-mailboxes-in-outlook.html' title='To cache secondary mailboxes in Outlook'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-7119304276299379151</id><published>2009-10-19T17:41:00.000+01:00</published><updated>2009-10-19T17:41:54.831+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Snow Leopard'/><category scheme='http://www.blogger.com/atom/ns#' term='10.6'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac Binding'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac Mail'/><category scheme='http://www.blogger.com/atom/ns#' term='review'/><category scheme='http://www.blogger.com/atom/ns#' term='first look'/><title type='text'>Snow Leopard: first impressions</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;meta content="" name="Title"&gt;&lt;/meta&gt; &lt;meta content="" name="Keywords"&gt;&lt;/meta&gt; &lt;meta content="text/html; charset=utf-8" http-equiv="Content-Type"&gt;&lt;/meta&gt; &lt;meta content="Word.Document" name="ProgId"&gt;&lt;/meta&gt; &lt;meta content="Microsoft Word 2008" name="Generator"&gt;&lt;/meta&gt; &lt;meta content="Microsoft Word 2008" name="Originator"&gt;&lt;/meta&gt; &lt;link href="file://localhost/Users/marlewis/Library/Caches/TemporaryItems/msoclip/0clip_filelist.xml" rel="File-List"&gt;&lt;/link&gt;  &lt;style&gt;&lt;!-- /* Font Definitions */@font-face	{font-family:Cambria;	panose-1:2 4 5 3 5 4 6 3 2 4;	mso-font-charset:0;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:3 0 0 0 1 0;}@font-face	{font-family:Palatino;	panose-1:2 0 5 0 0 0 0 0 0 0;	mso-font-alt:"Book Antiqua";	mso-font-charset:0;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:50331648 0 0 0 1 0;} /* Style Definitions */p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-parent:"";	margin:0cm;	margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:12.0pt;	mso-bidi-font-size:10.0pt;	font-family:"Times New Roman";	mso-ascii-font-family:Palatino;	mso-fareast-font-family:Cambria;	mso-hansi-font-family:Palatino;	mso-bidi-font-family:"Times New Roman";}@page Section1	{size:594.95pt 841.9pt;	margin:72.0pt 90.0pt 72.0pt 90.0pt;	mso-header-margin:35.4pt;	mso-footer-margin:35.4pt;	mso-paper-source:0;}div.Section1	{page:Section1;}--&gt;&lt;/style&gt;         &lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;I did these tests using an older 1.83 GHz iMac Core Duo with 1GB of RAM&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Binding&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Logged in as “administrator” binding from the “Join” button in Accounts failed with an error “unable to add server eServerSendError -14740.”&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;When binding through Directory Utility I received a notice that the computer account already existed.&amp;nbsp; I checked the entire directory and the account was not there. &lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;In Terminal I typed “dsconfigad- show” and found that the computer name was different than the name I had specified for the computer.&amp;nbsp; I searched the AD and found the computer account listed by the “show” command and deleted it.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I also deleted all the PRT records for my subnet and reconfigured DHCP so that our DNS service account owned the DNS records.&amp;nbsp; This is our new standard DHCP/DNS setup for all subnets.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I attempted to bind again with the [binding service account] and the bind failed with “insufficient privileges.” &amp;nbsp;&amp;nbsp;Using my domain admin account, I was able to bind the computer.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The edu.mit.kerberos file generated by the binding process was incorrect (lacking realm and server information) so I replaced with a file containing the correct information.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;LDAP lookups were handled properly after the bind.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;dsconfigad- show displayed the correct computer name.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Restarted the computer and logged in with my AD account.&amp;nbsp; I was given a warning that my password would expire in 29 days (I had just changed my password) and it prompted me to set up a mobile account.&amp;nbsp; On subsequent logins I was not given the password expiration warning.&amp;nbsp; &lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Restarting the computer was very quick- it only took about 40 seconds.&amp;nbsp; Directory Services was slow to start: 30-45 seconds after the login window appeared.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;File handling and transfers&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;It has been reported that connecting to an SMB volume produces a beach ball lockup.&amp;nbsp; I was able to connect to SMB shares (using SSO) but it took about 2 minutes.&amp;nbsp; AFP connections were virtually instantiations.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;3GB transfers to/from a SMB share on a Windows 2003 server across a 100mb network took 3 minutes.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;3GB transfers to/from an AFP share on a Mac Mini running 10.5.8 server across a 100mb network took 6 minutes.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;If I enabled Secure Empty Trash I was unable to delete the 3GB file.&amp;nbsp; It would hang about halfway through the process and I was forced to restart the Finder.&amp;nbsp; Turning off Secure Empty Trash allowed me to empty the trash without a problem.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Deleting an item from an AFP or SMB server volume closed the window.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;There is now a “put back” function in Trash just like in XP.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Mac Mail&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Auto setup asked twice to trust the certificate from IPG mail server.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;There was no need to configure LDAP to do a GAL lookup.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Mail cannot access Public Folders.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;There is now an archive mail function.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Meeting invites &lt;i&gt;from&lt;/i&gt; Outlook and Entourage functioned perfectly regardless of whether or not they had attachments.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Meeting invites &lt;i&gt;to&lt;/i&gt; Outlook and Entourage functioned perfectly.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;It took a long time for mail to download and display in the Inbox window.&amp;nbsp; Both my Blackberry and Entourage received mail much faster.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Notes are now synced properly with Blackberries.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Removing signatures locks up Mail.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;There is no way to remove attachments!&amp;nbsp; You must delete the entire mail.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Calendar&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Delegates are limited to Calendar viewing only: you cannot configure shared mailboxes from the Mail client.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Free/Busy status in Calendar worked very well and it is nice that you can search for the next available time your invitees are available.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;When viewing another person’s calendar their events are merged into your calendar and displayed as a different colour.&amp;nbsp; People will either love this or hate it.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Once you’ve started to create a meeting request there is no “Cancel” button.&amp;nbsp; You have to finish the request and then delete it.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Tasks entered into Mail say they will be put into a Tasks calendar but they are not.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;There doesn’t seem to be a way to change the colour of calendar events.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Invites sent from a different time zone display the correct local time in the message header.&amp;nbsp; The body text shows time for the sender, accepting the invite puts it into Calendar at the correct time.&amp;nbsp; Entourage still has the problem where meeting invites sent from different time zones display the incorrect time when you double click on the event in your calendar.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;There is a handy button that changes the time zone for all events in your calendar.&amp;nbsp; Changing them back works too!&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Address Book&lt;/b&gt; seems to be pretty much unchanged.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-7119304276299379151?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/7119304276299379151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=7119304276299379151' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7119304276299379151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7119304276299379151'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/10/snow-leopard-first-impressions.html' title='Snow Leopard: first impressions'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3757223022225522531</id><published>2009-10-15T19:12:00.000+01:00</published><updated>2009-10-15T19:12:17.224+01:00</updated><title type='text'>Very good description of AD binding process for the Macs</title><content type='html'>&lt;a href="http://www.peachpit.com/articles/article.aspx?p=1246089&amp;amp;seqNum=2"&gt;http://www.peachpit.com/articles/article.aspx?p=1246089&amp;amp;seqNum=2&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3757223022225522531?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3757223022225522531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3757223022225522531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3757223022225522531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3757223022225522531'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/10/very-good-description-of-ad-binding.html' title='Very good description of AD binding process for the Macs'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-9170310652596095113</id><published>2009-08-18T19:13:00.002+01:00</published><updated>2009-08-18T19:22:32.181+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bounce messages'/><category scheme='http://www.blogger.com/atom/ns#' term='accents in names'/><category scheme='http://www.blogger.com/atom/ns#' term='Entourage'/><title type='text'>Accents in display names causing problems in Entourage</title><content type='html'>&lt;div style="text-align: justify;"&gt;We have seen problems in Entourage where an e-mail will arrive and have the sender's name split in two parts.  One part will contain the valid e-mail address and the other will simply have a question mark before it.  Attempting to reply to messages like this results in the message bouncing with a failure notice similar to "invalid e-mail address."&lt;br /&gt;&lt;br /&gt;We have found that users who have accents in their display names cause this problem.  Removing the accent in the user's AD display name resolves the issue.&lt;br /&gt;&lt;br /&gt;This is only a problem in Entourage 2008- Entourage Web Services Edition and Outlook do not display this behavior.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-9170310652596095113?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/9170310652596095113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=9170310652596095113' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9170310652596095113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9170310652596095113'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/08/accents-in-display-names-causing.html' title='Accents in display names causing problems in Entourage'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-9082084354234398937</id><published>2009-08-06T18:32:00.001+01:00</published><updated>2009-08-06T18:34:09.592+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='screen saver'/><category scheme='http://www.blogger.com/atom/ns#' term='Kerberos'/><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='10.5.8'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='10.5.7'/><category scheme='http://www.blogger.com/atom/ns#' term='time-out'/><title type='text'>Mac: Kerberos time-outs and locked screen saver</title><content type='html'>&lt;div style="text-align: justify;"&gt;This is an interesting little glitch.&lt;br /&gt;&lt;br /&gt;On AD bound Macs if a user has their screen-saver set to require a password to deactivate and the user leaves their computer on for more than 10 hours, they will not be able to unlock the screen-saver.  Apple has confirmed that this is a problem and advises that the user should enter their user name and password and then wait for one minute before they press “OK.”&lt;br /&gt;&lt;br /&gt;This affects all versions of OS X through 10.5.7.  The latest 10.5.8 patch is supposed to fix the issue.&lt;br /&gt;&lt;br /&gt;The default time-out for a Kerberos ticket is 10 hours but with the screen-saver password lock enabled the Mac doesn’t auto renew the ticket properly.  Normally every time you unlock your screen-saver it refreshes the Kerberos ticket back to 10 hours but this simply doesn’t happen if they machine has been sitting on and idle for over 10 hours.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-9082084354234398937?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/9082084354234398937/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=9082084354234398937' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9082084354234398937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9082084354234398937'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/08/mac-kerberos-time-outs-and-locked.html' title='Mac: Kerberos time-outs and locked screen saver'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3561488484254139322</id><published>2009-08-06T18:28:00.003+01:00</published><updated>2009-08-06T18:30:53.923+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='creating a mobile account'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile account creation'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile account'/><title type='text'>Creating a mobile account after the fact: Mac</title><content type='html'>&lt;div style="text-align: justify;"&gt;If you need to enable a mobile account after you have already set up a user's network account (and didn't create the mobile account at first log in) do the following:&lt;br /&gt;&lt;br /&gt;On the client, log in as the local Administrator, and in Terminal&lt;br /&gt;issue the command:&lt;br /&gt;&lt;br /&gt;sudo /System/Library/CoreServices/ManagedClient.app/Contents/&lt;br /&gt;Resources/createmobileaccount -vsn myusername /my/homedirectory&lt;br /&gt;&lt;br /&gt;The variables "myusername" and "/my/homedirectory" are specific to&lt;br /&gt;the account you are working with.&lt;br /&gt;&lt;br /&gt;If you don't want syncing enabled, the argument is -vSn&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3561488484254139322?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3561488484254139322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3561488484254139322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3561488484254139322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3561488484254139322'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/08/creating-mobile-account-after-fact-mac.html' title='Creating a mobile account after the fact: Mac'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-113413582117106257</id><published>2009-07-30T13:18:00.002+01:00</published><updated>2009-07-30T13:21:01.047+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='login'/><category scheme='http://www.blogger.com/atom/ns#' term='shaky login'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='can&apos;t log in'/><title type='text'>Shaky login on Mac</title><content type='html'>&lt;div style="text-align: justify;"&gt;Normally shaky logins are caused by missing or corrupt edu.mit.kerberos files so always check that first but you might also want to look at the user's e-mail address in AD too.&lt;br /&gt;&lt;br /&gt;We had a user who couldn’t log into any bound Mac using his AD account however he could log into a PC.  On the Macs, he would get a shaky login box and a cryptic error saying “you can’t log in at this time”.&lt;br /&gt;&lt;br /&gt;Checking his AD account I noticed that he didn’t have a secondary SMTP of @corp.ipgnetwork.com.  I added the SMTP, waited for replication and then he was able to log in.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-113413582117106257?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/113413582117106257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=113413582117106257' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/113413582117106257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/113413582117106257'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/07/shaky-login-on-mac.html' title='Shaky login on Mac'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-662981549373554907</id><published>2009-07-09T18:00:00.000+01:00</published><updated>2009-07-09T18:01:07.609+01:00</updated><title type='text'>Outlook 2007 command line tools</title><content type='html'>Great set of Outlook 2007 command line tools:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://office.microsoft.com/en-gb/outlook/HP012185891033.aspx"&gt;http://office.microsoft.com/en-gb/outlook/HP012185891033.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-662981549373554907?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/662981549373554907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=662981549373554907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/662981549373554907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/662981549373554907'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/07/outlook-2007-command-line-tools.html' title='Outlook 2007 command line tools'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4431552670234402971</id><published>2009-06-03T10:17:00.003+01:00</published><updated>2009-06-03T10:20:38.586+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;garbled text&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='Entourage'/><title type='text'>Garbled Text in Entourage</title><content type='html'>Problem:  Entourage displays garbled text in all fields- header, folder names and message body.&lt;br /&gt;&lt;br /&gt;Fix:  Go to /Users/[user name]/Library/Caches and delete the &lt;span style="font-family: times new roman;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:100%;color:#000000;"   &gt;com.microsoft.browserfont.cache file.&lt;br /&gt;&lt;br /&gt;Relaunch Entourage and the text should be back to normal.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4431552670234402971?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4431552670234402971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4431552670234402971' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4431552670234402971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4431552670234402971'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/06/garbled-text-in-entourage.html' title='Garbled Text in Entourage'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-7171443069170321313</id><published>2009-05-29T17:29:00.005+01:00</published><updated>2009-05-29T18:05:04.654+01:00</updated><title type='text'>Entourage not sending mail MSS and MTU packet size problem</title><content type='html'>We have had a problem in one of our Warsaw offices where their Entourage 2008 clients (connected to Exchange 2007 via OWA) were not able to send mail.&lt;br /&gt;&lt;br /&gt;After much trial and error we found that the MSS packet size was set incorrectly.  Allowing larger packets resolved the problem.&lt;br /&gt;&lt;br /&gt;We set the MSS packet size to 1300 and the internal and external MTU size to 1500&lt;br /&gt;&lt;br /&gt;Doing a tcpdump and searching for "MSS" found that the packet size was 1460.  However it looks like the tcp packet length to the OWA server is 1400.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-7171443069170321313?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/7171443069170321313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=7171443069170321313' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7171443069170321313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/7171443069170321313'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/05/entourage-not-sending-mail-mss-and-mtu.html' title='Entourage not sending mail MSS and MTU packet size problem'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5179186060645037223</id><published>2009-04-29T17:09:00.003+01:00</published><updated>2009-04-29T17:42:43.558+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='duplicate names'/><category scheme='http://www.blogger.com/atom/ns#' term='bound'/><category scheme='http://www.blogger.com/atom/ns#' term='namespace AD'/><title type='text'>Macs not logging in: duplicate AD names</title><content type='html'>Problem:  A user in EMEA can't log into their AD bound Mac.  After investigation it is found that a duplicate name exists in another forest (North America).  We have been working around this by renaming one of the accounts.&lt;br /&gt;&lt;br /&gt;Possible solution (being tested now): from a command line on the user's machine type disconfigad –namespace domain name and then log in with domain\shortname&lt;br /&gt;&lt;br /&gt;See this link for more details: http://archive.netbsd.se/?ml=macos-x-server&amp;amp;a=2008-09&amp;amp;t=8621106&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5179186060645037223?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5179186060645037223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5179186060645037223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5179186060645037223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5179186060645037223'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/04/macs-not-logging-in-duplicate-ad-names.html' title='Macs not logging in: duplicate AD names'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3897734723712877774</id><published>2009-04-29T15:33:00.005+01:00</published><updated>2009-04-29T15:38:31.306+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac'/><category scheme='http://www.blogger.com/atom/ns#' term='clients'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;A records&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='hostnames'/><category scheme='http://www.blogger.com/atom/ns#' term='PTR'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;incorrect host names&quot;'/><title type='text'>Incorrect host names on Mac clients</title><content type='html'>As many of you are no doubt aware the Mac hostname displayed on the client and in the DNS Name field of ARD are more than likely incorrect.  For example, your Mac might be named ldntam-DMX1234 but you get a hostname of OSLggk-DXP5678 or some other random name.  This is a problem for applications such as LANDesk which need accurate DNS names associated to IPs.&lt;br /&gt;&lt;br /&gt;After much research and many discussions with Apple we have finally received this definitive reply:&lt;br /&gt;&lt;br /&gt;“Mac OS X 10.5 clients do not update PTR (reverse) records.  The 10.5 Mac&lt;br /&gt;clients will register an A record and the DHCP server must register&lt;br /&gt;the Mac's PTR record.  If a PTR record already exists with the IP&lt;br /&gt;address that a Mac has, the Mac will be given the hostname of the&lt;br /&gt;previous PTR record.  That is why scavenging and choosing the option&lt;br /&gt;to discard A and PTR records when the lease is deleted is necessary.”&lt;br /&gt;&lt;br /&gt;DHCP servers can be configured to either update A and PTR records only if requested by clients or to always update DNS A and PRT records.  The problem with the later method is that the server, rather than the client, will own the record and the client’s ACL is not included in the DNS object’s security list.  This can cause problems if the client goes to another location, if the DHCP server is changed or if the A and PTR records are not released properly (which happens a lot).&lt;br /&gt;&lt;br /&gt;It is also highly recommended that DHCP servers NOT reside on domain controllers.  In such a configuration (DHCP and DNS on the same server) MS recommends using an account with DNS credentials to update the DNS records to ensure the integrity of Dynamic DNS updates.&lt;br /&gt;&lt;br /&gt;According to Apple, Snow Leopard should have the ability to dynamically update PTR records.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3897734723712877774?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3897734723712877774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3897734723712877774' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3897734723712877774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3897734723712877774'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/04/incorrect-host-names-on-mac-clients.html' title='Incorrect host names on Mac clients'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5171522774775064264</id><published>2009-03-07T22:12:00.004Z</published><updated>2010-02-20T21:41:03.808Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='databases'/><category scheme='http://www.blogger.com/atom/ns#' term='BackupExec'/><category scheme='http://www.blogger.com/atom/ns#' term='migrate'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>BEUTILITY (BackupExec Utility)</title><content type='html'>To migrate the BackupExec databases after the server has been migrated to a new domain:&lt;br /&gt;&lt;br /&gt;Make sure you change all the BackupExc services so that they  launch using a local service account not a domain or local admin  account.&amp;nbsp; DO THIS FIRST and then run the beutility.exe app.&lt;br /&gt;&lt;br /&gt;The beutility.exe file is located in the in the same folder as the main BE application.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Launch beutility.exe.&amp;nbsp; The option is not so easy to find.. You click on the List of servers, right click on the server name and select "update configuration to reflect new media server name", then fill in the new domain and server name and the old domain and server name.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5171522774775064264?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5171522774775064264/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5171522774775064264' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5171522774775064264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5171522774775064264'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/03/beutil-backupexec-utility.html' title='BEUTILITY (BackupExec Utility)'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5553095092385307643</id><published>2009-02-27T20:24:00.002Z</published><updated>2009-02-27T20:28:20.778Z</updated><title type='text'>Enable random signature in Entourage</title><content type='html'>&lt;ul&gt;&lt;li&gt;Setup your signatures in tools/signatures&lt;/li&gt;&lt;li&gt;In the signature put a tick in "Include in random list"&lt;/li&gt;&lt;li&gt;Close the signatures and go to tools/accounts/&lt;/li&gt;&lt;li&gt;Double click on your mail account and go to the Options tab&lt;br /&gt;&lt;/li&gt;&lt;li&gt;In the "Default signature" pull-down select "Random"&lt;/li&gt;&lt;li&gt;Click "OK"&lt;/li&gt;&lt;/ul&gt;Now each time you create a new mail message it will select a signature from your Random list.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5553095092385307643?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5553095092385307643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5553095092385307643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5553095092385307643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5553095092385307643'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/02/enable-random-signature-in-entourage.html' title='Enable random signature in Entourage'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8291452514452353219</id><published>2009-02-19T11:01:00.002Z</published><updated>2009-04-29T15:41:17.576+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='server'/><category scheme='http://www.blogger.com/atom/ns#' term='speed'/><category scheme='http://www.blogger.com/atom/ns#' term='OS X'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;Workgroup Manager&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;speed up directory searches&quot;'/><category scheme='http://www.blogger.com/atom/ns#' term='searching'/><category scheme='http://www.blogger.com/atom/ns#' term='&quot;OS X server&quot;'/><title type='text'>OS X Server: Speeding up directory searches</title><content type='html'>One of the major complaints about OSX Server is that once they are bound, searching for users/groups from the AD can take a long time (and sometimes times out before completion).&lt;br /&gt;&lt;br /&gt;The problem, according to Apple, is that AD doesn’t index any attributes for a substring search and therefore all records have to be searched.  The Workgroup Manager plug-in times out after 60 seconds and even an ldapsearch from the command line will only search for 120 seconds and then give up.&lt;br /&gt;&lt;br /&gt;Apple has two suggestions to speed up searches:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;In Workgroup Manager, click on the little magnifying glass in the search window and select "Name is" and enter the last, first of the user you are searching for&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;In Workgroup Manager, click on the little magnifying glass in the search window, go to “advanced” and search for “Real Name”  This will search the cn attribute and is much faster than a normal search- this works for groups too&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;I have tested both of the above work-arounds and found that they work very well.  The Real Name search is particularly fast.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8291452514452353219?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8291452514452353219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8291452514452353219' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8291452514452353219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8291452514452353219'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2009/02/os-x-server-speeding-up-directory.html' title='OS X Server: Speeding up directory searches'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8415974447525684593</id><published>2008-12-01T16:33:00.001Z</published><updated>2008-12-01T16:35:24.202Z</updated><title type='text'>Enable access rights in ARD</title><content type='html'>Run this from the Unix command in ARD as root.  It will set the user's access privileges in ARD to "all".&lt;br /&gt;&lt;br /&gt;cd /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/&lt;br /&gt;^M&lt;br /&gt;./kickstart -configure -access -on -users [USER SHORT NAME] -privs -all&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8415974447525684593?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8415974447525684593/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8415974447525684593' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8415974447525684593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8415974447525684593'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/12/enable-access-rights-in-ard.html' title='Enable access rights in ARD'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3055634864034213478</id><published>2008-12-01T13:58:00.004Z</published><updated>2008-12-01T14:09:10.561Z</updated><title type='text'>OS X: create user account from command line and ARD</title><content type='html'>For Tiger:&lt;br /&gt;&lt;br /&gt;Run the following as "root" in ARD:&lt;br /&gt;&lt;br /&gt;dscl / -create /Users/toddharris&lt;br /&gt;dscl / -create /Users/toddharris UserShell /bin/bash&lt;br /&gt;dscl / -create /Users/toddharris RealName "Dr. Todd Harris"&lt;br /&gt;dscl / -create /Users/toddharris UniqueID 503&lt;br /&gt;dscl / -create /Users/toddharris PrimaryGroupID 1000&lt;br /&gt;dscl / -create /Users/toddharris NFSHomeDirectory /Local/Users/toddharris&lt;br /&gt;dscl / -passwd /Users/toddharris PASSWORD&lt;br /&gt;dscl / -append /Groups/admin GroupMembership toddharris&lt;br /&gt;&lt;br /&gt;Replace "toddharris" with the user name and "PASSWORD" with the password you want to use.&lt;br /&gt;&lt;br /&gt;For Leopard use:&lt;br /&gt;&lt;br /&gt;dscl . -create /Users/toddharris&lt;br /&gt;dscl . -create /Users/toddharris UserShell /bin/bash&lt;br /&gt;dscl . -create /Users/toddharris RealName "Dr. Todd Harris"&lt;br /&gt;dscl . -create /Users/toddharris UniqueID 503&lt;br /&gt;dscl . -create /Users/toddharris PrimaryGroupID 1000&lt;br /&gt;dscl . -create /Users/toddharris NFSHomeDirectory /Local/Users/toddharris&lt;br /&gt;dscl . -passwd /Users/toddharris PASSWORD&lt;br /&gt;dscl . -append /Groups/admin GroupMembership toddharris&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3055634864034213478?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3055634864034213478/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3055634864034213478' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3055634864034213478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3055634864034213478'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/12/os-x-create-user-account-from-command.html' title='OS X: create user account from command line and ARD'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-8042035111988706293</id><published>2008-11-28T13:07:00.000Z</published><updated>2008-11-28T13:08:55.495Z</updated><title type='text'>Starting ARD from command line</title><content type='html'>http://docs.info.apple.com/article.html?artnum=108030&lt;br /&gt;&lt;br /&gt;This is the Apple tech reference for turning on ARD from the command line if you can ssh into a box.  NOTE:  Apple fails to note that you have to put ./ in front of the "kickstart" command.&lt;br /&gt;&lt;br /&gt;For turning on ARD using ssh and enabling it for all users type:&lt;br /&gt;/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources root# ./kickstart -activate -configure -access -on -restart&lt;br /&gt;-agent -privs -all&lt;br /&gt;&lt;br /&gt;MUST BE SUDO or ROOT&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-8042035111988706293?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/8042035111988706293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=8042035111988706293' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8042035111988706293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/8042035111988706293'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/starting-ard-from-command-line.html' title='Starting ARD from command line'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2914072363625990773</id><published>2008-11-28T13:05:00.000Z</published><updated>2008-11-28T13:06:10.274Z</updated><title type='text'>Outlook: registry change to allow connection ot a differnt mail server</title><content type='html'>After a migration, if you need to switch the user's mail back to the old server you need to delete a reg setting or Outlook will not connect to the old server.  Do this:&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER&lt;br /&gt;Software&lt;br /&gt;Microsoft&lt;br /&gt;Exchange&lt;br /&gt;Exchange Provider&lt;br /&gt;&lt;br /&gt;Delete the Closest GC key&lt;br /&gt;&lt;br /&gt;Go back into Outlook and connect to the old mail server&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2914072363625990773?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2914072363625990773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2914072363625990773' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2914072363625990773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2914072363625990773'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/outlook-registry-change-to-allow.html' title='Outlook: registry change to allow connection ot a differnt mail server'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4130008419367610085</id><published>2008-11-28T13:04:00.001Z</published><updated>2008-11-28T13:04:39.292Z</updated><title type='text'>PXE booting a Dell</title><content type='html'>•    Getting PXE boot to work on Dell machines presented problems as there was no obvious way in BIOS to enable PXE.  The internet provided the solution:&lt;br /&gt;o    Enter BIOS&lt;br /&gt;o    Go to Security Settings&lt;br /&gt;o    Disable the Deny PXE boot option.&lt;br /&gt;o    Return to main BIOS screen&lt;br /&gt;o    Enter Integrated Peripherals screen&lt;br /&gt;o    On network card settings, press right arrow to add the ‘pxe’ boot option to the setting&lt;br /&gt;o    Exit and save settings&lt;br /&gt;•    Dell machines caused a small error with the installation script due to an extra ISDN card requiring installation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4130008419367610085?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4130008419367610085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4130008419367610085' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4130008419367610085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4130008419367610085'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/pxe-booting-dell.html' title='PXE booting a Dell'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1491982128591785101</id><published>2008-11-28T13:02:00.000Z</published><updated>2008-11-28T13:03:32.065Z</updated><title type='text'>Rename a PC using netdom</title><content type='html'>You will need to install the XP Support Tools located in the Tools folder on the XP disk.  Full instructions can be found here:&lt;br /&gt;&lt;br /&gt;http://support.microsoft.com/kb/298593&lt;br /&gt;&lt;br /&gt;Here is a real-world example of renaming a computer MLNMOW-NXP1002 to MLNMOM-NXP1002&lt;br /&gt;&lt;br /&gt;netdom renamecomputer MLNMOW-DXP9001 /newname:MLNMOM-NXP1002 /userd:[domain]\[admin account] /passwordd:* /usero:administrator /passwordo:* /reboot:15 /force&lt;br /&gt;&lt;br /&gt;This will rename the computer, prompt you for your domain admin and local machine admin passwords and force a reboot after 15 seconds. You have to be using a domain account with full admin rights to the computer you are renaming.&lt;br /&gt;&lt;br /&gt;You can enter the real passwords instead of the "*" to speed up the process.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1491982128591785101?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1491982128591785101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1491982128591785101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1491982128591785101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1491982128591785101'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/rename-pc-using-netdom.html' title='Rename a PC using netdom'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-1606510612526667354</id><published>2008-11-28T13:00:00.001Z</published><updated>2008-11-28T13:01:43.601Z</updated><title type='text'>Unable to log in to a Mac (Tiger only)</title><content type='html'>Symptom:  A user on a bound Mac is unable to log in; they receive the "shaky" log-in box at each authentication attempt.  Other users can log into the machine and the same user can log into other machines.&lt;br /&gt;&lt;br /&gt;Fix:  Log on as admin and open Netinfo Manager and select "Users" in the middle column.  In the right-hand column the user should be listed ONCE.  If the user is listed TWICE, delete both users.  Restart and the user should be able to log back in.&lt;br /&gt;&lt;br /&gt;NOTE: if this does not resolve the problem then you will have to use the Kerberos file fix which is explained in another post.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-1606510612526667354?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/1606510612526667354/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=1606510612526667354' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1606510612526667354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/1606510612526667354'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/unable-to-log-in-to-mac-tiger-only.html' title='Unable to log in to a Mac (Tiger only)'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2602335357183883030</id><published>2008-11-28T12:55:00.002Z</published><updated>2008-11-28T12:59:00.174Z</updated><title type='text'>Mail problems checklist</title><content type='html'>For VPN access:&lt;br /&gt;LDN SML RAS&lt;br /&gt;There is now a VPN user group created by default in each OU but make sure it is a member of the SML RAS group&lt;br /&gt;&lt;br /&gt;For IT staff to modify Exchange settings in the user’s AD account:&lt;br /&gt;EMEA Exchange View-Only Admins&lt;br /&gt;&lt;br /&gt;For IT staff to create a new user:&lt;br /&gt;EMEA GIS Exchange2003 Reg Settings Group Admins&lt;br /&gt;&lt;br /&gt;Newly created user must be in this group:&lt;br /&gt;EMEA GIS Exchange2003 Registry settings&lt;br /&gt;&lt;br /&gt;In order for an IT guy to add computers to the Non-Restricted Workstation group, the IT guy must be a site-level full admin not a brand-level full admin.&lt;br /&gt;Example:  SHM 11ATUR Full Admins and not SHM 11ATUR MEW Full Admins&lt;br /&gt;&lt;br /&gt;If no one can send to a DL make sure the group type is set to UNIVERSAL&lt;br /&gt;&lt;br /&gt;If a user is unable to receive internal  mail make sure they have a NOTES entry in their E-mail Address tab with an address of user name@NAExchange.  Also make sure they have a tick in “Automatically update e-mail addresses based on recipient policy” under the E-mail Addresses tab (this is very important for new users especially).&lt;br /&gt;&lt;br /&gt;(Generally, not being able to receive internal mail means that they are missing or have a misspelling in their @corp.... address)&lt;br /&gt;&lt;br /&gt;If the user receives a “Mailbox Closed” message from System Administrator it means their mailbox is over the size limit.&lt;br /&gt;&lt;br /&gt;Name changes not showing in the GAL on some computers: update the GAL in Outlook.  Tools/Send&amp;amp;Receive/Update address book.  Make sure you update all entries.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2602335357183883030?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2602335357183883030/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2602335357183883030' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2602335357183883030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2602335357183883030'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/mail-problems-checklist.html' title='Mail problems checklist'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2378039239972491168</id><published>2008-11-11T08:54:00.003Z</published><updated>2008-11-11T08:59:29.522Z</updated><title type='text'>Can not search default Contacts folder in Outlook</title><content type='html'>Problem: Users are not able to search the default Contacts in Outlook.  Right-clicking and going to Properties/Outlook Address Book displays the "show this folder as an Outlook address book" field greyed out and unticked.&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;In Outlook, Choose Tools-&gt;Email Accounts...&lt;/li&gt;&lt;li&gt;Select Add a new directory or address book, then click next.&lt;/li&gt;&lt;li&gt;Select Additional Address Books, then click next.&lt;/li&gt;&lt;li&gt;Choose Outlook Address Book from the list, then click next.&lt;/li&gt;&lt;li&gt;You will have to close Outlook and open again for changes to take effect.&lt;/li&gt;&lt;li&gt;You will then be able to select the Show this folder as an email Address Book from the Outlook Address Book tab within the Contacts properties&lt;/li&gt;&lt;/ul&gt;General info about making Contacts searchable (but not specifically this fix): http://support.microsoft.com/kb/287563&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2378039239972491168?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2378039239972491168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2378039239972491168' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2378039239972491168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2378039239972491168'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/11/can-not-search-default-contacts-folder.html' title='Can not search default Contacts folder in Outlook'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5041099543962645430</id><published>2008-10-29T15:56:00.000Z</published><updated>2008-10-29T15:57:49.859Z</updated><title type='text'>User can't log into a bound mac (cont...)</title><content type='html'>On a problem Mac, check if the mit.edu.kerberos file has been modified back to a default.  We’ve been seeing machines overwriting our custom file and replacing it with a default one.  If the file has been changed try this:&lt;br /&gt;&lt;br /&gt;In the default file look for the line that says [libdefaults].  Chances are the only thing under it will be “dns_fallback = no”  or it could give you a realm list.  Either way, cut and paste from your modified edu.mit.kerberos file everything under [libdefaults] line.  Don’t replace the Kerberos file this time: cut and paste into it.&lt;br /&gt;&lt;br /&gt;After you have done this go System/Library/Core Serivces/Kerberos.app and delete any Kerberos ticket you might find.&lt;br /&gt;&lt;br /&gt;Restart and try to log in again.&lt;br /&gt;&lt;br /&gt;On a problem Mac you could also try stopping and restarting directory services:&lt;br /&gt;&lt;br /&gt;Sudo killall DirectoryServices&lt;br /&gt;&lt;br /&gt;The service will start again automatically.&lt;br /&gt;&lt;br /&gt;Then check that AD is in the search path:  dscl /Search –read / CSPSearchPath SearchPolicy&lt;br /&gt;&lt;br /&gt;It should return:&lt;br /&gt;&lt;br /&gt; /Local/Default,&lt;br /&gt;/BSD/local&lt;br /&gt;Active Directory/All Domains&lt;br /&gt;&lt;br /&gt;Lastly, if you are still having problems, turn on Directory Services logging at startup:&lt;br /&gt;&lt;br /&gt;Sudo killall –USR1 DirectoryServices&lt;br /&gt;Touch /Library/Preferences/DirectoryService/.DSLogDebugAtStart&lt;br /&gt;&lt;br /&gt;After the restart the logs can be found in:&lt;br /&gt;&lt;br /&gt;/Library/Logs/DirectoryService/DirectoryService.debug.log&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5041099543962645430?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5041099543962645430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5041099543962645430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5041099543962645430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5041099543962645430'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/user-cant-log-into-bound-mac-cont.html' title='User can&apos;t log into a bound mac (cont...)'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-4224698079770826340</id><published>2008-10-29T13:50:00.000Z</published><updated>2008-10-29T13:51:02.556Z</updated><title type='text'>Import/Export DHCP scopes on a Windows 2003 server</title><content type='html'>http://www.geekadmin.com/?p=13&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-4224698079770826340?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/4224698079770826340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=4224698079770826340' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4224698079770826340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/4224698079770826340'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/importexport-dhcp-scopes-on-windows.html' title='Import/Export DHCP scopes on a Windows 2003 server'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-3571315203332123482</id><published>2008-10-29T13:44:00.000Z</published><updated>2008-10-29T13:45:07.084Z</updated><title type='text'>Creating a Password Reset Disk for XP</title><content type='html'>Direct from Microsoft: http://support.microsoft.com/kb/305478&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-3571315203332123482?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/3571315203332123482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=3571315203332123482' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3571315203332123482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/3571315203332123482'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/creating-password-reset-disk-for-xp.html' title='Creating a Password Reset Disk for XP'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-5876843903449491685</id><published>2008-10-29T13:11:00.001Z</published><updated>2008-10-29T13:12:14.405Z</updated><title type='text'>Print spooler on client PCs (XP) falling over</title><content type='html'>In Amsterdam we had a problem where the print spooler was repeatedly stopping on the server.  The fix was to translate TT fonts to bitmap in each printer's advanced settings (right-click on the printer and go to properties)&lt;br /&gt;&lt;br /&gt;More details:&lt;br /&gt;&lt;br /&gt;The printer drivers were upgraded, and used PCL5 rather than PCL6, this&lt;br /&gt;stopped the print spooler from crashing.&lt;br /&gt;&lt;br /&gt;A symptom arised that people were getting garbage printed out when&lt;br /&gt;printing from Outlook (other apps OK).  This issue was resolved by&lt;br /&gt;forcing the default option of printing TT fonts as bitmaps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-5876843903449491685?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/5876843903449491685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=5876843903449491685' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5876843903449491685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/5876843903449491685'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/print-spooler-on-client-pcs-xp-falling.html' title='Print spooler on client PCs (XP) falling over'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-2327010766141052562</id><published>2008-10-29T13:10:00.001Z</published><updated>2008-10-29T13:10:50.262Z</updated><title type='text'>OS X Tiger slow logins: LDAPv3 fix</title><content type='html'>I can confirm that if I remove the LDAPv3 settings from my Macs, then the boot process is MUCH MUCH faster...reduced from minutes to seconds on my really fast Macs. Removing the entry completely (or disabling it by un-checking the check mark on the main Directory Access screen) will make my machines boot faster.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-2327010766141052562?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/2327010766141052562/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=2327010766141052562' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2327010766141052562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/2327010766141052562'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/os-x-tiger-slow-logins-ldapv3-fix.html' title='OS X Tiger slow logins: LDAPv3 fix'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-9067728198844721273</id><published>2008-10-29T13:06:00.000Z</published><updated>2008-10-29T13:10:18.988Z</updated><title type='text'>Mac Binding problem and fix: report from Hamburg</title><content type='html'>Problems&lt;br /&gt;&lt;br /&gt;The HAM office reported several problems:&lt;br /&gt;Slow log in on Macs (up to an hour)&lt;br /&gt;Macs which would not bind&lt;br /&gt;Macs would take a long time to bind&lt;br /&gt;Mac which were bound not having network accounts available at log in&lt;br /&gt;Users on bound Macs unable to log into the computer if it was disconnected from the network (a real problem for laptops)&lt;br /&gt;When the local DC was taken off-line the Macs could not log in&lt;br /&gt;When the office was removed from the WAN, the Macs could not log in&lt;br /&gt;&lt;br /&gt;I believe that we have now resolved all of the above issues, however the last one involves a change which the Directory Team is not in favour of.&lt;br /&gt;&lt;br /&gt;We have a full testing matrix but I’ll hit the highlights:&lt;br /&gt;&lt;br /&gt;The local DC’s error log showed a good number of replication errors; it also had the primary and secondary DNS servers reversed and 28 updates and critical patches waiting to be applied.  The DNS entries were corrected, patches applied and the DC was restarted- it seems to be operating well now.&lt;br /&gt;&lt;br /&gt;On a problem Mac (network accounts unavailable and the user couldn’t log in even if they had a mobile account) we did two things: deleted the edu.mit.kerberos file from Library/Preferences and deleted the live Kerberos ticket (sometimes, if a user was having problems logging in they did not have a Kerberos ticket at all).  After a restart, network accounts became available after about 15 seconds and after the user entered their AD credentials it took 10 seconds further to completed the login process.&lt;br /&gt;&lt;br /&gt;Checking the edu.mit.kerberos file after login we found that it had been successfully recreated and had the correct entries for the site and the EMEA realm:&lt;br /&gt;&lt;br /&gt;Kdc = hamgdc02.xxx.xxx.xxx.com.:88&lt;br /&gt;Kdc = amsgdc02.xxx.xxx.xxx.com.:88 (this entry sometimes displayed other EMEA DCs)&lt;br /&gt;Admin_server = hamgdc02.xxx.xxx.xxx.com.&lt;br /&gt;Admin_server = amsgdc02.xxx.xxx.xxx.com. (this entry sometimes displayed other EMEA DCs)&lt;br /&gt;&lt;br /&gt;All of the above entries are exactly what they should be.  Before we made changes to the DC and rebooted it, the edu.mit.kerberos files could have any random DC within the global IPG network (we found them pointing to Hong Kong, Dublin, Milan, etc.)&lt;br /&gt;&lt;br /&gt;If we disconnected this Mac from the network the user could still log in using their mobile account.&lt;br /&gt;&lt;br /&gt;If we disconnected the network cable from the DC, after about 60 seconds network accounts on the Mac became available and the user could log in (it took a while, about 90 seconds but it still worked).  If the Mac had either no Kerberos ticket and/or a edu.mit.kerberos file with improper entries, the client could never log in if the DC was unplugged from the network.&lt;br /&gt;&lt;br /&gt;If we disconnected the DC from the WAN and connected it via cross-over cable to a PC (simulating the office dropping its WAN connection) the PC was, after a while, able to authenticate an AD user and log in.  If we connected a Mac to the DC with a cross-over cable, network accounts would never become available and we could not log in using an AD account.&lt;br /&gt;&lt;br /&gt;If I added  ldap and kerberos entries into DNS/emea.xxx.xxx.com/msdcs/dc/_tcp for the local  then a Mac connected via crossover cable to the DC would, after about 60 seconds, have network accounts become available and an AD user can log in (takes about 90 seconds).&lt;br /&gt;&lt;br /&gt;If I removed the DNS entries, the Mac was unable to log in and network accounts never became available.&lt;br /&gt;&lt;br /&gt;Conclusions&lt;br /&gt;&lt;br /&gt;“Cleaning up” the DC and rebooting it allowed the Macs to generate properly configured edu.mit.kerberos files.&lt;br /&gt;&lt;br /&gt;Based on our testing it would seem that deleting the edu.mit.kerberos file along with the active Kerberos ticket and rebooting the Mac fixes the problem of unavailable network accounts and slow user log in.  It also seems to make the Macs bind faster and more reliably.&lt;br /&gt;&lt;br /&gt;Once a proper edu.mit.kerberos file has been generated, removing the Mac from the LAN or disconnecting the DC from the LAN still allows for user log in.  However, if the office loses its connectivity to the WAN, Macs which are still connected to the LAN are unable to log in at all unless we add the above mentioned DNS entries.&lt;br /&gt;&lt;br /&gt;It should be noted that none of the Macs we tested, nor any user’s Mac which had authentication problems during the time I was in the office, ever unbound themselves from the AD.  Not being able to authenticate is not necessarily a symptom of a binding problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-9067728198844721273?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/9067728198844721273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=9067728198844721273' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9067728198844721273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/9067728198844721273'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/mac-binding-problem-and-fix-report-from.html' title='Mac Binding problem and fix: report from Hamburg'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8238903149909171748.post-660225465572735721</id><published>2008-10-29T13:05:00.000Z</published><updated>2008-10-29T13:06:15.677Z</updated><title type='text'>Mac bining and SRV records (part 1)</title><content type='html'>Form MacWindows:&lt;br /&gt;&lt;br /&gt;    I recently had an issue whereby all OS X 10.4 clients/servers I tried to bind to a customer's Active directory would fail with "unknown error" at Step 5. The ADPlugin log would show the binding failing while trying to set the computer password. I found your very useful pages through googling the issue, and thought I would let you know what eventually fixed my issue.&lt;br /&gt;&lt;br /&gt;    I believe I had two issues causing this binding problem, both DNS related.&lt;br /&gt;&lt;br /&gt;    The first was that some SRV records for one of their domain controllers were missing from DNS (in particular _ldap and _kpasswd). Running "nltest /dsregdns" on the missing server should sort this, but they should also be added in automatically when the Netlogon service starts on the server, so if they are missing there could be some wider domain controller issue to investigate.&lt;br /&gt;&lt;br /&gt;    The second problem (once the SRV records were sorted), and the one that was causing the step 5 failure, was that the domain controllers were multi-homed: they each had more than one IP address, and these addresses were all registered in DNS. For some reason, the AD bind process would retrieve the correct IP from DNS for each step until step 5 when it would try and talk to the servers second IP for the kpasswd (464 UDP) part of the bind. This would fail.&lt;br /&gt;&lt;br /&gt;    To fix this, if possible remove the second IP address from the server. If you can't do this, remove the server A record in DNS that points to the second IP address (you might have to go in to the TCP/IP properties on the server and tell it "not to register this connection in DNS" if you leave more than one IP address on the server, else it will re-register it in DNS). This fixed the issue for me&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8238903149909171748-660225465572735721?l=emeadeployment.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://emeadeployment.blogspot.com/feeds/660225465572735721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8238903149909171748&amp;postID=660225465572735721' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/660225465572735721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8238903149909171748/posts/default/660225465572735721'/><link rel='alternate' type='text/html' href='http://emeadeployment.blogspot.com/2008/10/mac-bining-and-srv-records-part-1.html' title='Mac bining and SRV records (part 1)'/><author><name>Macninja</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_MK3_W81wtn0/TQy3oY8WFfI/AAAAAAAABo4/e9sSrpIpUgc/S220/Me-Pelicans_small.jpg'/></author><thr:total>0</thr:total></entry></feed>
