adamcodega: i’m going to try a blank UDID with valid SN. and then see what the JSS does when I add the device
Allister
zoooky I believe I spelunked in postgresql for that and didn't see it
might be in the newer version of Apple Configurator, tho
zoooky
i’m hoping it’s smart enough to tell. i’m guessing not, because they’re probable using UDID and not SN to identify devices per apples’ developers guidelines
Nick_ZWG
iPCU can do it.
elliotjordan joined the channel
Allister
yeah, i hate ipcu tho
zoooky
Nick_ZWG: yes, but didn’t apple quitly put iPCU to bed
Nick_ZWG
Yes, they did.
zoooky
I miss iPCU logs
bruienne
quietly, with a bullet
ssshhh no more pain
zoooky
bruienne: old yeller style
bruienne
zoooky: spoiler alert, jeez
zoooky
I don’t think apple will give me UDIDs of the devices I own…
bruienne: that’s lke complaining about romio and juliet .
Kinda sad we couldn't have gotten to this point 10 years ago
zoooky
Nick_ZWG: it was intresting to watch that evolve on reddit.
gneagle
"our standard image will only include the operating system and related software, software required to make hardware work well (for example, when we include unique hardware in our devices, like a 3D camera), security software and Lenovo applications. "
weasel
zoooky
mr weasel?
Nick_ZWG
Sure, the Lenovo crap will still be on there
gneagle
"Lenovo applications" == anything
Nick_ZWG
but hey, it's a start
foigus
"Our goal is clear: To become the leader in providing cleaner, safer PCs. "
Cleaner
Not clean
halloweenhead has quit
rtrouton
This should hopefully keep the weaseling to a minimum - Lenovo will post information about ALL software we preload on our PCs that clearly explains what each application does.
gneagle
"security software" <--- most of that is crappy adware as well
foigus
Superfish--provides guided suggestions
bruienne
also what are these "customarily expected" apps?
rtrouton
But yeah, weasel language that they can point to in future lawsuits.
Jonukas joined the channel
bruienne
much like a pain killer "Helps fight pain!"
zoooky
icnsole looks cool
adamcodega
zoooky: experimenting with it too, haven't sold the issue I was trying to fix yet though.
gbatye joined the channel
jvanosten has quit
jkimyoung joined the channel
zoooky
what was that?
jessep2
rtrouton: have you seen issues with loginwindow crashing (getting booted to the Login Window) when opening System Profiler on OS X VMs on ESXi?
adamcodega
zoooky: devices on guest network can't reach caching server, that's fine I don't care, but they aren't failing back to Apple when they timeout.
rtrouton
jessep2: I haven't seen that. 10.10 VM? Or 10.9.x?
jessep2
10.9 VM
thumpba_ joined the channel
it’s minor issue and it’s intermittent
zoooky
adamcodega: so they’re discovering the cache server, but can’t reach it?
rtrouton
jessep2: One moment, let me see if I can reproduce on my end.
adamcodega
zoooky: they are being told by Apple goto the caching server.
zoooky
and the ipads work fine from other network segments?
trifygri joined the channel
adamcodega
zoooky: yes.
rtrouton
jessep2: Nope, not seeing it.
jessep2
not that it matters but I usually access it by Apple menu->Option->Sys Pref, also this is over ARD/SS
zoooky
muliple ip segements right?
adamcodega
zoooky: yeah 192 versus 10.
Same router, same outgoing ISP
jessep2
with VMware Tools installed, FWIW
zoooky
adamcodega: sounds like a network issue
rtrouton
jessep2: That's roughly what I did. Apple menu: About this Mac: More Info: System Report.
squirke joined the channel
adamcodega
zoooky: yeah need to verify who they are trying to hit.
zoooky
adamcodega: like those segements are walled off, and they need to allow traffic to the cache server
adamcodega
zoooky: I don't want them to talk to the caching server.
jessep2
rtrouton: okay, well thanks for giving a try :)
rmanly has quit
zoooky
adamcodega: tried setting resistrct ip ranges on the server?
adamcodega
zoooky: not through advanced settings, just through "local subnets only"
abbaZaba_ joined the channel
jessep2
justinrummel: did the re work out okay?
Avatharian joined the channel
aaronc_ joined the channel
justinrummel
jessep2 no, it returns an error b/c the recipe does not like using parenthesis, and when I get a trimmed down regex with brackets it states no match found
It may be just Vivaldi's website... going to try a different one.
adamcodega: funny cause I want to move some network segements to another public IP. and I know when I do so. i’m going to have to figure out the reverse. lol
thered has quit
adamcodega
zoooky: why dont they just time out and download from Apple?
jessep2
justinrummel: i see what happened - the RE of Shea’s works okay - the download changed to an HTTPS
so just add an ’s’ to the re pattern
arrose joined the channel
downloads the dmg for me fine :)
zoooky
adamcodega: *shrug* no clue, I have to say from my perspective. timing out is probable better then going to apple. So my internet connection doesn’t get saturated with apple updates. rather have them keep trying for the local till they get it and update.
adamcodega: sounds like a good feature request to put in with apple. allow admins to set fail open or fail closed.
justinrummel
jessep2 hmm.... wonder now what I'm doing wrong as I get "No valid recipe found for Vivladi.download"
adamcodega
Yeah.
jessep2
justinrummel: was that a joke? :) VivALdi.download
zoooky
adamcodega: take it you can’t change their public IP address for those guest segements?
so tried creating a JSS asset by API with SN but without UDID. then added the asset to the JSS. It created a new asseet. instead of pairing the two records together.
adamcodega
zoooky: no, we have a primary and backup WAN
zoooky
so it deffently seems like the JSS is using UDID for device ID.
justinrummel
nope, went to the basic fundamentals and start at the first parent recipe
and I guess that is my problem. pkg works
Ugh.. doing stupid things hurt
jvanosten joined the channel
aaronc_ has quit
jvanosten has quit
squirke has quit
squirke joined the channel
DLSteve joined the channel
Nick_ZWG
Okay, I have solved the Chef bootstrap problem by doing it The Wrong Way™ but it works
arrose
Nick_ZWG are you going the FB route of bootsrapping Munki with Chef?
rtrouton
Nick_ZWG: You aren't using the private key on the clients, are you?
Nick_ZWG
No, and no.
So I guess that (private key on clients) would be The Worst Way™ and no I'm not doing that
Instead, I have a launchdaemon continually running the one specific Chef recipe until the CSR is signed
like i said
The Wrong Way
or at least a not very efficient way
until I figure out some kind of notification mechanism
jessep2
justinrummel: cool, be sure to submit an issue to Shea’s repo
Apple's License Agreement for OS X says that you can only run "up to two (2) additional copies or instances of the Apple Software within virtual operating system environments on each Mac Computer you own or control that is already running the Apple Software". How does this apply to instances run under VMware ESXi? OS X isn't "already running" on ESXi machines and only running two instances seems unreasonable.
Nick_ZWG
Rather, it is, but not using CA client certs.
gingimli joined the channel
Jonukas
I should add that I'm really talking about OS X Server.
Nick_ZWG
Jonukas: It means, technically speaking, you can't run more than 3 OS X VMs per machine.
That being said, there's no *technical* limitation.
Jonukas
So it's more of a legal limitation than a technical one.