I had heard rumors about a feature in iOS 7 that would allow for "pulling back" applications. In essence, I can assign an app to an iPad when a student gets enrolled in a class and then I can pull the app back when they move on and no longer need the app. This would greatly ease our app management pains. As it stands now, we have to be extremely careful about application deployment. It's very tedious to make sure the correct iTunes account is logged into an iPad when we use a VPP redemption code. If we're not careful, we can "give away" our redemption codes since they follow the iTunes account and not the device. But that's all going to change now.
Apple now has added a "managed distribution" mechanism to iOS to allow the apps to be assigned to devices, and most importantly, unassigned from devices. How did this not make major headlines when it was unveiled? This is a major problem that we have faced with iOS devices and on the surface it looks to be the feature that we've always wanted. I haven't actually had a chance to play with it yet, and the only thing I've read about it comes from this this Apple support page. But so far, wow! It's about time.
I've just done a bit more searching about this feature and it looks like there are a couple of sites with a few more notes about it. It looks like enterprise iOS picked it up first with this article.
One downside that I do see is that it doesn't work for books. But that's OK. I'll happily take what I can get*.
*This isn't happily because Apple is great and wonderful and I'll love anything that comes from them. It's happily because this problem has been a real pain and with the number of iPads showing up increasing every day we'll take anything to help make management easier.
Problems and the occasional solution for technology issues encountered in a the K-12 education environment.
Tuesday, November 12, 2013
Wednesday, November 6, 2013
Silently Installing Audacity and LAME
Want to silently install Audacity and LAME?
Audacity
I learned my lesson in my previous adventures looking for silent install switches for iPrint (here's that post Removing iPrint Printers). This time I started out running audacity-win-2.0.5.exe /? to see if there are any silent install options. What do you know, there are. The "/SILENT" option looks promising for my needs. I think I'll go ahead and add the "/CLOSEAPPLICATIONS" option in there too just so I don't get any pesky, "You need to reboot" messages. I'm also going to go ahead and add the "/LOG" option too. In the past I always skipped logging stuff just to make things faster, but as of late I've decided that having some log data lying around can come in handy and is worth the extra second it takes.LAME
Unfortunately, the learned lesson with the "/?" is lost on LAME. It doesn't support that, guess I'll have to go search for this one. A quick search doesn't return an obvious answer. A lot of install guides but no body talking about installing silently. I did find a link to a WPKG package that has some command line switches burried in their XML file listed on the site. It looks like LAME will take similar options to Audacity. I'm going to pick the "/VERYSILENT", "/NORESTART", and "/LOG" options for the LAME installation.
Wrapping It Up
For both of the installations I just let it put the files in their default locations. In the past you had to point Audacity to the LAME files so I used to always install the LAME dll files inside the Audacity directory. That way when the end users tried to Export as MP3 and the window popped up asking for the dll file it was right there ready to click on. It looks like in this new version of Audacity automatically searches the default LAME install folder (C:\Program Files\LAME for Windows). Which is nice, that's one less thing for the end user to have to do.
I went ahead and built separate ZENworks installers for both Audacity and LAME. I don't know why I'd ever deploy them separately, but now I can if I need to. I'm also building a Bundle Group to include both of those installers to make it easier to assign to users.
Wednesday, October 30, 2013
Blogging about blogging
This blog has been around for a couple of years. That is if you count from the time of my first post until the time of my most recent post. If you count time spent updating it, it's only been around for a few days at most. My posting hasn't been very regular, but I'm trying to fix that. I recently found Jennifer Dewalt's blog http://blog.jenniferdewalt.com/post/56319597560/im-learning-to-code-by-building-180-websites-in-180 where she built a website a day for 180 days. If she can find the time to learn and the time build something every day surely I can find the time to come up with something to write about, the time to write it out and the time to post it here. I keep saying time time time. The time is a big deal, but the ideas to write about have been a big deal too. I have found that constantly looking for things to write about has changed how I view the things that I do during the day. Every little thing that I do I find myself asking, "How would I write about this?" I used to start out thinking about "how interesting something was" or "how novel the idea was." Then I'd get stuck with "am I going to sound like an idiot" writing about this? But I've come to the conclusion that the answer to the last questions is "yes" but it doesn't really matter. I'm writing because I'm want to write. Hopefully, you'll find something of interest here and if nothing else maybe you'll get a good laugh out of me sounding like an idiot. That gets part of the idea stumbling block out of the way, now to work on finding the time. :)
Does this post make sense? Sort of, but they say practice makes perfect, right? So, I'm going to keep at it and see where it goes.
Does this post make sense? Sort of, but they say practice makes perfect, right? So, I'm going to keep at it and see where it goes.
Troubles wth RSSOwl and Password Protected Feeds
I subscribe to a lot of feeds through RSSOwl. I should probably shrink the list of feeds because it's a lot more information coming in, way more than I can keep up with anyway. However, I haven't kicked anything off the list, I just prioritize what I read immediately and what I read when I get around to it. Because a lot of my feeds keep unread articles attached to them I don't always find feed problems immediately. What I do notice is going through the list and seeing that the dates on the articles haven't updated recently. This is what happened to me the other day with one particular feed that I subscribe to.
The particular feed that wasn't work is password protected. The dates on the articles weren't recent and the feed icon had a red X on it. Clicking on the feed and viewing the properties just showed a status of "no password provided". Ok, so I need to provide a password, how do I do that?
RSSOwl supports password protected feeds, you just have to add the username and password to the feed. Here's the box I'm looking for, but how do I get to it?
I remembered when I added this feed it popped up and asked me for my username and password (like it says it's supposed to do here http://tutorial.rssowl.org/tipstricks.html). And I remember the last time I changed my password on the site that RSSOwl asked me again for my password then. So it was smart enough to know when the stored password doesn't work, why isn't it asking me for my password now?
I tried restarting RSSOwl, no luck. Restarting the computer, no luck. Re-adding the feed, no luck. Googling for authenticated feeds and RSSOwl, password protected feeds and RSSOwl, no luck and no luck. Googling the error message (I don't know why I didn't start here), no obvious fix, but it started me down the path to a fix.
I wound up on the RSSOwl help page (here http://www.rssowl.org/help in case you're interested). They make a reference to the passwords being managed from Tools > Preferences > Passwords. I wasn't sure what I was looking for when I got there, but what I found was a blank list of sites. It looked similar to this with the section in the middle that lists sites empty.
The only button that wasn't grayed out was the "Reset" button. Figured since it wasn't working anyway, resetting it wouldn't hurt. So I clicked on Reset, it gave me a "are you sure" message and I clicked to Ok that. I went ahead and Ok'd the Password window to close it. Then I right-clicked on the Feed and selected Update. Bingo! The password window popped right up this time. I entered my username and password and it was back working, the lastest feed updates came streaming in.
The particular feed that wasn't work is password protected. The dates on the articles weren't recent and the feed icon had a red X on it. Clicking on the feed and viewing the properties just showed a status of "no password provided". Ok, so I need to provide a password, how do I do that?
RSSOwl supports password protected feeds, you just have to add the username and password to the feed. Here's the box I'm looking for, but how do I get to it?
I remembered when I added this feed it popped up and asked me for my username and password (like it says it's supposed to do here http://tutorial.rssowl.org/tipstricks.html). And I remember the last time I changed my password on the site that RSSOwl asked me again for my password then. So it was smart enough to know when the stored password doesn't work, why isn't it asking me for my password now?
I tried restarting RSSOwl, no luck. Restarting the computer, no luck. Re-adding the feed, no luck. Googling for authenticated feeds and RSSOwl, password protected feeds and RSSOwl, no luck and no luck. Googling the error message (I don't know why I didn't start here), no obvious fix, but it started me down the path to a fix.
I wound up on the RSSOwl help page (here http://www.rssowl.org/help in case you're interested). They make a reference to the passwords being managed from Tools > Preferences > Passwords. I wasn't sure what I was looking for when I got there, but what I found was a blank list of sites. It looked similar to this with the section in the middle that lists sites empty.
The only button that wasn't grayed out was the "Reset" button. Figured since it wasn't working anyway, resetting it wouldn't hurt. So I clicked on Reset, it gave me a "are you sure" message and I clicked to Ok that. I went ahead and Ok'd the Password window to close it. Then I right-clicked on the Feed and selected Update. Bingo! The password window popped right up this time. I entered my username and password and it was back working, the lastest feed updates came streaming in.
Labels:
authentication,
feed,
password protected,
rss,
rssowl
Thursday, October 24, 2013
My Aventures in Installing Cacti (Part 2)
This is a continuation of my first post about installing Cacti. You can find that post here
Now that I've got this new Cacti server up and running we need to get some data collection setup so we can get some of those pretty graphs.
But first things first. Out of the box this install is setup for DHCP. We'll need to change that to a static IP address so it doesn't go jumping around on the network. Now that I'm done with all the console part I'm going to remove the keyboard, mouse, and monitor and I don't want to lose it on the network somewhere.
Configuring an IP address from the console on a Ubuntu box is pretty easy. There are just a couple of changes that need to be made to a configuration text file. That file is /etc/network/interfaces. To edit that use the command sudo nano /etc/network/interfaces All we going to do there is change the iface eth0 inet dhcp line to iface eth0 inet static and then add a couple of lines for the actual static address. It should look similar to this when you get finished:
auto eth0
iface eth0 inet static
address 10.0.0.100
netmask 255.255.255.0
gateway 10.0.0.1
dns-server 10.0.0.2
Once those changes have been made we'll need to restart the network interfaces to make those go into affect. To restart the network interfaces just use sudo /etc/init.d/networking restart
Easy enough, right? Now we know which IP address our server will be using and we wont be at the mercy of our DHCP server.
Now let's log back into our Cacti server and get to setting that up. You'll need to use the IP address that you configure to access the server, but it will look something like http://10.0.0.100/cacti You'll log in with the username/password that you setup earlier when you went through the initial setup wizard.
Once logged into Cacti you'll want to add a new device. Just click on Devices on the left side and then click on Add over on the right side. You'll want to type in a description that's useful for you. This is what's going to show up in all the lists in Cacti. For the hostname I just entered the IP address of the switch I wanted to monitor. For host template, it defaults to None, but if you'll go ahead and select something here it'll make things a little easier later on. For me, I'm monitoring a Cisco 3750 switch so I just picked the "Generic SNMP-enabled Host" template. I left the next bit on the defaults. I did have to change the SNMP Community string. I couldn't remember what it was setup to on the switch so I had to go look through my documentation, but after I found it entered that in there. If you're not sure just stick with "public", a lot of equipment comes with that by default so it may work for you. Once you've got that in there, just click Create and then you'll be done with that page.
Your page now should have "Save Successful" at the top. Below that it shows my SNMP info from my switch. Over on the right there's a link for "Create Graphs for this Host." Go ahead and click on that. There should be a new page up that lists all of the interfaces on available on your switch. If you don't see that, go back to the last screen and check that your Host Template is set correctly (mine is Generic SNMP-enabled Host). Now for my switches I see all of my interfaces that are configured on the switches, the ports, and the stacking ports too. If you've configured descriptions on your ports those will show up too. For my interests I wanted to see how much traffic was coming and going on the WAN. So I picked the interface (by checking the box at the right-hand side of the column) that I have setup as the "outside" of my site. Then down at the bottom I picked the graph type out of the drop down box. For right now I picked "In/Out Bits with Total Bandwidth". At some point in the future I may change that to one of the bytes graphs but for now I just went with the bits graph. Now just click on Create and you'll have created your first graph in Cacti.
Wait, you just clicked Create and it doesn't look like it did anything right? Check up at the very top, you should see a line that says "Create graph: blah blah blah" I guess you want to see your graph now, right? Well, I don't want to disappoint you, so I'll tell you how to get there. Click on Devices on the left, then click on the Device that you added earlier, and then click on Graph List (toward the top right). Then just click on the graph that you just created. VoilĂ ! It's blank, right? Well that's because we just set it up and there's no data yet. By default it polls every 5 minute, so it's going to take a while to get some data. Go do something else for a little and then come back. Really, watching it doesn't make it go any faster. Trust me. I've tried.
While you wait, you can go ahead and add the graph to the "Tree". This way you can just use the "graphs" link at the top to see your.... empty... graphs. Don't worry, the data will start coming in eventually. But let's pass this time productively and add it to the Tree already. Go back to your Graph List. You can do that the same way I listed earlier, or here's a different way. Just click on Graph Management on the right, pick your host out of the drop down and you graphs should be listed there. Now we want to pick one (check the box on the right side), then select the "Place on Tree (Default: Tree)" action out of the bottom drop down list, and then click on Go. It asks for a Destination Branch, but right now we've only got one, the [root], so we're going to use it and click on Continue.
Now if you click on graphs at the top it'll take you to the graphs view (obviously, right?). It defaults to the Tree view, but I don't have a lot in there so I click on the icon at the top on the far right. I know it's a graph, but it looks like mountains to me. Since there are not many graphs setup yet, I like this view better. Later on I'll probably prefer one of the other ones, but for now I'll just stick with this one.
Still waiting for the data to show up? Let's get rid of the localhost device and graph that came with the installation. I don't really have any interesting in watching the machine that's watching everything else, so I just deleted that device. To do that go back to the console and then click on Devices. Check the box by your localhost and then select the Delete action at the bottom and click Go. Click to confirm that you want to get rid of it and then it'll be gone.
By now you might have a single column on your chart. It's not much to look at right? Well, tomorrow it will be more impressive. In the mean time you'll have to find something else to do. How about reading some of my other blog posts? That sounds like fun, right?
Now that I've got this new Cacti server up and running we need to get some data collection setup so we can get some of those pretty graphs.
But first things first. Out of the box this install is setup for DHCP. We'll need to change that to a static IP address so it doesn't go jumping around on the network. Now that I'm done with all the console part I'm going to remove the keyboard, mouse, and monitor and I don't want to lose it on the network somewhere.
Configuring an IP address from the console on a Ubuntu box is pretty easy. There are just a couple of changes that need to be made to a configuration text file. That file is /etc/network/interfaces. To edit that use the command sudo nano /etc/network/interfaces All we going to do there is change the iface eth0 inet dhcp line to iface eth0 inet static and then add a couple of lines for the actual static address. It should look similar to this when you get finished:
auto eth0
iface eth0 inet static
address 10.0.0.100
netmask 255.255.255.0
gateway 10.0.0.1
dns-server 10.0.0.2
Once those changes have been made we'll need to restart the network interfaces to make those go into affect. To restart the network interfaces just use sudo /etc/init.d/networking restart
Easy enough, right? Now we know which IP address our server will be using and we wont be at the mercy of our DHCP server.
Now let's log back into our Cacti server and get to setting that up. You'll need to use the IP address that you configure to access the server, but it will look something like http://10.0.0.100/cacti You'll log in with the username/password that you setup earlier when you went through the initial setup wizard.
Once logged into Cacti you'll want to add a new device. Just click on Devices on the left side and then click on Add over on the right side. You'll want to type in a description that's useful for you. This is what's going to show up in all the lists in Cacti. For the hostname I just entered the IP address of the switch I wanted to monitor. For host template, it defaults to None, but if you'll go ahead and select something here it'll make things a little easier later on. For me, I'm monitoring a Cisco 3750 switch so I just picked the "Generic SNMP-enabled Host" template. I left the next bit on the defaults. I did have to change the SNMP Community string. I couldn't remember what it was setup to on the switch so I had to go look through my documentation, but after I found it entered that in there. If you're not sure just stick with "public", a lot of equipment comes with that by default so it may work for you. Once you've got that in there, just click Create and then you'll be done with that page.
Your page now should have "Save Successful" at the top. Below that it shows my SNMP info from my switch. Over on the right there's a link for "Create Graphs for this Host." Go ahead and click on that. There should be a new page up that lists all of the interfaces on available on your switch. If you don't see that, go back to the last screen and check that your Host Template is set correctly (mine is Generic SNMP-enabled Host). Now for my switches I see all of my interfaces that are configured on the switches, the ports, and the stacking ports too. If you've configured descriptions on your ports those will show up too. For my interests I wanted to see how much traffic was coming and going on the WAN. So I picked the interface (by checking the box at the right-hand side of the column) that I have setup as the "outside" of my site. Then down at the bottom I picked the graph type out of the drop down box. For right now I picked "In/Out Bits with Total Bandwidth". At some point in the future I may change that to one of the bytes graphs but for now I just went with the bits graph. Now just click on Create and you'll have created your first graph in Cacti.
Wait, you just clicked Create and it doesn't look like it did anything right? Check up at the very top, you should see a line that says "Create graph: blah blah blah" I guess you want to see your graph now, right? Well, I don't want to disappoint you, so I'll tell you how to get there. Click on Devices on the left, then click on the Device that you added earlier, and then click on Graph List (toward the top right). Then just click on the graph that you just created. VoilĂ ! It's blank, right? Well that's because we just set it up and there's no data yet. By default it polls every 5 minute, so it's going to take a while to get some data. Go do something else for a little and then come back. Really, watching it doesn't make it go any faster. Trust me. I've tried.
While you wait, you can go ahead and add the graph to the "Tree". This way you can just use the "graphs" link at the top to see your.... empty... graphs. Don't worry, the data will start coming in eventually. But let's pass this time productively and add it to the Tree already. Go back to your Graph List. You can do that the same way I listed earlier, or here's a different way. Just click on Graph Management on the right, pick your host out of the drop down and you graphs should be listed there. Now we want to pick one (check the box on the right side), then select the "Place on Tree (Default: Tree)" action out of the bottom drop down list, and then click on Go. It asks for a Destination Branch, but right now we've only got one, the [root], so we're going to use it and click on Continue.
Now if you click on graphs at the top it'll take you to the graphs view (obviously, right?). It defaults to the Tree view, but I don't have a lot in there so I click on the icon at the top on the far right. I know it's a graph, but it looks like mountains to me. Since there are not many graphs setup yet, I like this view better. Later on I'll probably prefer one of the other ones, but for now I'll just stick with this one.
Still waiting for the data to show up? Let's get rid of the localhost device and graph that came with the installation. I don't really have any interesting in watching the machine that's watching everything else, so I just deleted that device. To do that go back to the console and then click on Devices. Check the box by your localhost and then select the Delete action at the bottom and click Go. Click to confirm that you want to get rid of it and then it'll be gone.
By now you might have a single column on your chart. It's not much to look at right? Well, tomorrow it will be more impressive. In the mean time you'll have to find something else to do. How about reading some of my other blog posts? That sounds like fun, right?
My Aventures in Installing Cacti (Part 1)
I wanted to do some logging of network interface usage on some of our switches so I thought I'd setup Cacti and give it a try. Why Cacti, well I had used it before (years ago) and thought I'd use it again.
Where did I start? I thought a linux box my be the easiest way to get it going. I also thought if I ran into problems help would be easier to find for a linux box than a Windows box also. So I went to Ubuntu's website and grabbed the latest LTS Server iso (which happens to be 12.04 Precise Pangolin). Then I picked up a flash drive and used unetbootin to load the iso on the drive. Waited for it to finish, then pulled the drive out and attempted to boot the system from the flash drive.
I noticed the boot loader mentioned loading some BSD files which I thought was rather odd, but I went on working on something else and waited for it to finish booting up. I checked the boot screen and it wasn't a Ubuntu install, it was an install screen for an appliance that I had recently updated using that same flash drive. Apparently UNetbootin didn't overwrite the other installer correctly. The plan was to just format the drive and try again. It seems nothing goes as easily as it should. Windows only recognizes the 4gb flash drive as a 28mb drive. Great, the appliance installer must have partitioned the drive and Windows can't read it correctly. So I downloaded BOOTICE from http://bbs.ipauly.com/ to clear off the partitions and reformat the drive.
After doing that I, I then re-ran UNetbootin and loaded the iso back on the drive. Did I mention that nothing seems to go as easy as it should? I picked USB Boot out of the boot menu on the computer and bam, an immediate "Boot Failed" message. Great...what's wrong now? The drive had been a little slow to write to, maybe it had finally died. Being in the computer business it seems there's always another flash drive lying around so I looked until I found a 1gb drive. That doesn't sound like much but it's plenty for a Ubuntu installation.
Third time's the charm, right? Run through UNetbootin to copy the iso to the flash drive, then boot the computer, and finally... a Ubuntu install screen.
This is all pretty basic stuff on the Ubuntu install. I went through and did pick to use the entire drive and install LVM. When it asked about what applications to installed I picked the LAMP option (that's Linux Apache MySQL PHP in case you wondered). There are more guides for installing Ubuntu than you can shake a stick at so I wont cover that here.
After a couple of false starts there I finally got Ubuntu installed on the machine. To get Cacti installed is pretty easy. I did a sudo apt-get install cacti and it installed cacti and all the dependencies and loaded right into the cacti setup.
Setting up cacti is pretty straight forward. Here's a link install-and-configure-cacti-monitoring-tool-in-ubuntu-9-10-karmic-server.html to a guide that's complete with screenshots. This one's pretty close to what I saw. The only difference I found is that the RRDTools version that comes with Ubuntu 12.04 is 1.4 instead of version 1.3 as indicated in the guide. Also, I haven't gotten around to chance the Spine setup as indicated towards the end of the guide and so far mine is working fine.
At this point you should have your Ubuntu server up and running with Cacti installed and also running.
Since it seems this post is getting a little long, I think I'll break it into two posts. Check back in for the second part.
Here's the link for that second part.
http://practicalschooltech.blogspot.com/2013/10/my-aventures-in-installing-cacti-part-2.html
Where did I start? I thought a linux box my be the easiest way to get it going. I also thought if I ran into problems help would be easier to find for a linux box than a Windows box also. So I went to Ubuntu's website and grabbed the latest LTS Server iso (which happens to be 12.04 Precise Pangolin). Then I picked up a flash drive and used unetbootin to load the iso on the drive. Waited for it to finish, then pulled the drive out and attempted to boot the system from the flash drive.
I noticed the boot loader mentioned loading some BSD files which I thought was rather odd, but I went on working on something else and waited for it to finish booting up. I checked the boot screen and it wasn't a Ubuntu install, it was an install screen for an appliance that I had recently updated using that same flash drive. Apparently UNetbootin didn't overwrite the other installer correctly. The plan was to just format the drive and try again. It seems nothing goes as easily as it should. Windows only recognizes the 4gb flash drive as a 28mb drive. Great, the appliance installer must have partitioned the drive and Windows can't read it correctly. So I downloaded BOOTICE from http://bbs.ipauly.com/ to clear off the partitions and reformat the drive.
After doing that I, I then re-ran UNetbootin and loaded the iso back on the drive. Did I mention that nothing seems to go as easy as it should? I picked USB Boot out of the boot menu on the computer and bam, an immediate "Boot Failed" message. Great...what's wrong now? The drive had been a little slow to write to, maybe it had finally died. Being in the computer business it seems there's always another flash drive lying around so I looked until I found a 1gb drive. That doesn't sound like much but it's plenty for a Ubuntu installation.
Third time's the charm, right? Run through UNetbootin to copy the iso to the flash drive, then boot the computer, and finally... a Ubuntu install screen.
This is all pretty basic stuff on the Ubuntu install. I went through and did pick to use the entire drive and install LVM. When it asked about what applications to installed I picked the LAMP option (that's Linux Apache MySQL PHP in case you wondered). There are more guides for installing Ubuntu than you can shake a stick at so I wont cover that here.
After a couple of false starts there I finally got Ubuntu installed on the machine. To get Cacti installed is pretty easy. I did a sudo apt-get install cacti and it installed cacti and all the dependencies and loaded right into the cacti setup.
Setting up cacti is pretty straight forward. Here's a link install-and-configure-cacti-monitoring-tool-in-ubuntu-9-10-karmic-server.html to a guide that's complete with screenshots. This one's pretty close to what I saw. The only difference I found is that the RRDTools version that comes with Ubuntu 12.04 is 1.4 instead of version 1.3 as indicated in the guide. Also, I haven't gotten around to chance the Spine setup as indicated towards the end of the guide and so far mine is working fine.
At this point you should have your Ubuntu server up and running with Cacti installed and also running.
Since it seems this post is getting a little long, I think I'll break it into two posts. Check back in for the second part.
Here's the link for that second part.
http://practicalschooltech.blogspot.com/2013/10/my-aventures-in-installing-cacti-part-2.html
Labels:
beginnger,
bootice,
cacti,
flash drive,
tutorial,
ubuntu,
unetbootin,
usb boot
Tuesday, October 22, 2013
Assigning local rights through Group policy and making it work
Trouble getting local computer rights assigned through group policy? Have you read all the articles that tell you to edit the GPO and assign the rights? Are they still not showing up on your Windows XP machines? That's the trouble I ran into.
Before I get too far into this. Let's go back to begining. We made the switch to from a Novell network (Netware servers, eDirectory, ZDM, iPrint and the Novell Client) to Microsoft network (Active Directory). After the switch we needed someway to manage the rights that local users have on machines. In the past we used ZENworks and when users logged into their computers (through the Novell Client), Zen would pick that up and create a local user for that person with the rights that we assigned and then seamlessly log the user into that account. When using AD it doesn't work the same. The users just log into the machine, because the machine is in the domain they don't get (or need) a local account. Which is great, except that some of the people need to be administrators or power users. I know I could go through group policy and assign specific rights, but we don't need that granular of control. Just making them members of the local groups is good enough.
Now there's a couple of ways to get them in as member of a group. The original way to do it with group policy was to use the Restricted Groups feature. Doing it that way makes sure people are members of the group and that only those people are members of the group. That's nice for some environments, but we don't need that level of control. For us, all we need is to add people to groups from time to time. There's a new way to do just that. Well, I say new way, it's been around for 5 or 6 years. Its through an addon to group policy called Client Side Extensions. Microsoft bought out a company that was doing some neat group policies addons and then MS built it into Windows and released it free of charge for all to use. But that's a story for a different day, the point is that I wanted to assign the group membership using this part of gorup policies. So I started doing my homework. I read a lot of posts about using them and I dug through the MS documentation. It seemed pretty straight forward, I made my own policy, I assigned it, then I tested it, and then I found out it didn't work.
What had I missed? I went back through and double-checked everything. And then I tested agian.... nothing. And I tested again and again. It just wasn't working for me. As it so often happens I got pulled away to work on something else, but I had left the policies applied. They weren't working but didn't appear to breaking anything, so what did it matter, right? A few days passed and then I got back to working on this problem again and guess what, it worked. Right... it worked. Go figure. What had changed? I went back through everything and the only thing that had changed was my test machine. Lesson learned, if at first you don't succeed, try a different test machine.
Now that I knew the problem was in my machine, I just had to figure out what exactly it was. Back to the internet to see what pieces made these group policy extensions tick. What I found was two different Windows update that make it happen.
The first one is KB915865 which covers XMLLite. If you're running XP 32-bit here's that download link so you don't have to go looking for it http://www.microsoft.com/en-us/download/details.aspx?id=13978
The second update is KB943729 which covers the actual new Group Policy preferences. If you're running XP 32-bit here's that download link as well, http://www.microsoft.com/en-us/download/details.aspx?id=3628
Now that you know what you need to you need to figure out what systems need it right? Well the fastest way for me to tell if the computer is working right is to use NET LOCALGROUP ADMINISTRATORS at a command prompt. We've got a couple of accounts that we add as local admins on all machines, if the only thing listed on that command is a "MyDomain\Domain Admins" then I know I'm missing one of the updates listed above.
How about a quick way to tell which update you're missing? Check the C:\WINDOWS\SYSTEM32 folder. The XMLLite update installs an XMLLITE.DLL file, if it's there, then the update has been installed (of course it could be corrupt or not registered correctly). To see if Group Policy preferences update has been installed look for a GPPREFCL.DLL file.
So one command to see if it's working.
NET LOCALGROUP ADMINISTRATORS
And two commands to figure out what you're missing.
DIR C:\WINDOWS\SYSTEM32\XMLLITE.DLL
DIR C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
After you install the updates just let the machine reboot and log back in. I have noticed that on the faster machines if you log back in after the reboot with a machine that's supposed to be getting admin rights that it doesn't get the rights on first log in. If you check the group memberships it shows up rights but you don't have admin rights. I think what's happening is that the system is logging the account in before the group policies have time to finish applying and since the memberships haven't assigned when the account logs in it doesn't get the rights. By time you can check the memberships it shows up correctly, but you don't have the rights because the weren't there at login. The fix is to just log out and back in and then you'll have the rights. The irony is that it seems like some of our slower machines are not affected by this, I guess the policy has time to finish applying before it actually starts processing the login. Who knows? If all it takes is a log off and back on, I'll take it.
Now there's a couple of ways to get them in as member of a group. The original way to do it with group policy was to use the Restricted Groups feature. Doing it that way makes sure people are members of the group and that only those people are members of the group. That's nice for some environments, but we don't need that level of control. For us, all we need is to add people to groups from time to time. There's a new way to do just that. Well, I say new way, it's been around for 5 or 6 years. Its through an addon to group policy called Client Side Extensions. Microsoft bought out a company that was doing some neat group policies addons and then MS built it into Windows and released it free of charge for all to use. But that's a story for a different day, the point is that I wanted to assign the group membership using this part of gorup policies. So I started doing my homework. I read a lot of posts about using them and I dug through the MS documentation. It seemed pretty straight forward, I made my own policy, I assigned it, then I tested it, and then I found out it didn't work.
What had I missed? I went back through and double-checked everything. And then I tested agian.... nothing. And I tested again and again. It just wasn't working for me. As it so often happens I got pulled away to work on something else, but I had left the policies applied. They weren't working but didn't appear to breaking anything, so what did it matter, right? A few days passed and then I got back to working on this problem again and guess what, it worked. Right... it worked. Go figure. What had changed? I went back through everything and the only thing that had changed was my test machine. Lesson learned, if at first you don't succeed, try a different test machine.
Now that I knew the problem was in my machine, I just had to figure out what exactly it was. Back to the internet to see what pieces made these group policy extensions tick. What I found was two different Windows update that make it happen.
The first one is KB915865 which covers XMLLite. If you're running XP 32-bit here's that download link so you don't have to go looking for it http://www.microsoft.com/en-us/download/details.aspx?id=13978
The second update is KB943729 which covers the actual new Group Policy preferences. If you're running XP 32-bit here's that download link as well, http://www.microsoft.com/en-us/download/details.aspx?id=3628
Now that you know what you need to you need to figure out what systems need it right? Well the fastest way for me to tell if the computer is working right is to use NET LOCALGROUP ADMINISTRATORS at a command prompt. We've got a couple of accounts that we add as local admins on all machines, if the only thing listed on that command is a "MyDomain\Domain Admins" then I know I'm missing one of the updates listed above.
How about a quick way to tell which update you're missing? Check the C:\WINDOWS\SYSTEM32 folder. The XMLLite update installs an XMLLITE.DLL file, if it's there, then the update has been installed (of course it could be corrupt or not registered correctly). To see if Group Policy preferences update has been installed look for a GPPREFCL.DLL file.
So one command to see if it's working.
NET LOCALGROUP ADMINISTRATORS
And two commands to figure out what you're missing.
DIR C:\WINDOWS\SYSTEM32\XMLLITE.DLL
DIR C:\WINDOWS\SYSTEM32\GPPREFCL.DLL
After you install the updates just let the machine reboot and log back in. I have noticed that on the faster machines if you log back in after the reboot with a machine that's supposed to be getting admin rights that it doesn't get the rights on first log in. If you check the group memberships it shows up rights but you don't have admin rights. I think what's happening is that the system is logging the account in before the group policies have time to finish applying and since the memberships haven't assigned when the account logs in it doesn't get the rights. By time you can check the memberships it shows up correctly, but you don't have the rights because the weren't there at login. The fix is to just log out and back in and then you'll have the rights. The irony is that it seems like some of our slower machines are not affected by this, I guess the policy has time to finish applying before it actually starts processing the login. Who knows? If all it takes is a log off and back on, I'll take it.
Subscribe to:
Posts (Atom)

