morgsdaly: as far as i can remember (from wrangling kerberos ages ago)
morgsdaly
mosen: there is a mention in the logs of time sync, pretty sure DNS is working as far as my tests go. I will need to school up on Service Principles. Have also been having a PM Enrolment issue on this same server which I think is related to it all.
MacPrince joined the channel
mosen: I am guessing this is not good? "kinit: krb5_get_init_creds: unable to reach any KDC in realm server.internal.mic, tried 0 KDCs"
slowfranklin joined the channel
bruienne
heh mosen
whoah net fart
suddenly a whole screen of text scroll
ctdawe: yeah we did
rickardsj joined the channel
mosen
holy buffer explosion
morgsdaly: doesnt seem very good
morgsdaly
:)
mosen
morgsdaly: but I thought that server still offerred a fallback to NTLM or something basic if kerberos failed, and you're saying that it only stops sharing after 24 hours?
morgsdaly
I was talking about a different server yesterday that seems to be slowing after 24 hours... my colleague has that straw today. I started investigating this server because PM enrolment was failing and then this morning after a restart and PM working users cannot SMB.
mosen
oh right
server.app hero of the universe
morgsdaly: the fact that AFP works and SMB doesn't might be a clue
MacPrince has quit
mscottblake joined the channel
mscottblake has quit
morgsdaly
mosen: indeed
mosen
morgsdaly: because AFP should be preferring kerberos too
morgsdaly
a clue that Apple needs to let it go or get it right maybe
mosen
yeah I gave up on Server
slowfranklin has quit
thumpba_ has quit
Psychodata has quit
ctdawe
morgsdaly So long as they need a reference release of Profile Manager, there will be an OS X Server. What puzzles me is the erratic introduction of new services like Xcode Server.
diwanicki joined the channel
diwanicki has quit
loceee
morgsdaly: kdc realm server.internal.nic ?
.mic
morgsdaly
checking now loceee
loceee
morgsdaly: but i see dns name micserver1.city.internal.mic
morgsdaly
I was trying to obscure a little, can't trick you though :)
gneagle wrote some code into the pkg that createosxinstallpkg creates
checks for various things
what he didn't do, was log any of the errors so there's no way to tell what failed unless you manually extract out the post install script from the pkg and run it manually
so all I had was a general installer "package install failed. error code 1"
crcaterham joined the channel
ah well. it's sorted now
mosen
ah right
GrahamRPugh has quit
DialsMavis
bye all
DialsMavis has quit
bochoven_ has quit
Mac_Write joined the channel
bochoven_ joined the channel
pdmontreal has quit
andy______ joined the channel
macmule joined the channel
bochoven_ has quit
grahamgilbert
franton: I have a suggestion for your script - I’d randomise the admin password and then use your management tool to correct it on next boot, so then you don’t have your admin password in the clear anywhere in Munki
squirke joined the channel
makab3r joined the channel
makab3r
Hi
franton
grahamgilbert: good idea. however i'm only presenting it as a proof of concept
any suggestions as to how? (i've got the CEO's laptop heading my way so i'm dropping everything for that today)
grahamgilbert
Something like dscl . passwd /Users/administrator someRandomStringFromSomewhere
then I’d use puppet to correct the password
franton
I have no puppet
I have munki and deploy studio :(
grahamgilbert
I don’t have any server infrastructure for puppet
it’s run locally
but you could achieve the same thing with checking password hash - puppet is just wrapping shell scripts
mosen has quit
Mac_Write has quit
franton
I leave here in just over a week. That's something I don't have the time to do
mikedodge04 has quit
macmule
franton: not with that attitude.
:P
franton
macmule: i'm already working the fucking weekend
macmule: on a pilot to strip out centrify and replicate everything it does manually
and right now i'm wondering why whomever set this up has config profiles to do somethings, and scripts that partly replicate what the profiles do
grahamgilbert
I think I need a t-shirt that says “Read the Readme"
Said it four times already this morning
mikedodge04 joined the channel
zvordauk joined the channel
franton
grahamgilbert: read the "fine" manual ;)
grahamgilbert: or read the "fabulous" manual :D
grahamgilbert
yeah
You would think none of our code was in GitHub with a readme for running everything
Creops
franton: sounds like my build, I mix and match everything :)