##osx-server

/

      • foigus
        SEP seems pretty heavy handed, although I understand if idle scan was disabled it might help
      • I mean, 2 1/2 hour battery life? Awesome!
      • vader- joined the channel
      • vader-1 has quit
      • rhettelliot has quit
      • ctdawe
        Nick_ZWG I thought that I read that Sophos had introduced some sort of cloud-managed option. Did you ever note and/or review that?
      • chuckfromis joined the channel
      • jhbush
        Nick_ZWG we use Trend at the moment
      • Nick_ZWG
        Problem is, that doesn't really solve my problem
      • My goal is to _remove_ Sophos updates from bandwidth
      • and the only way to do that (supported way, at least) is to host a Sophos Enterprise Console locally
      • which is a Windows server / appliance
      • I'd love cloud management, but I really want to stop having clients download sophos updates from the intertubes
      • jhbush
        @Nick_ZWG I thought you download the definition files and push them on your own in standalone mode
      • Nick_ZWG
        jhbush: I started doing that
      • and it got to be way too much work
      • so now I don't bothert
      • jhbush
        @Nick_ZWG I learned that lesson as well
      • gneagle
        AutoSophosDefsDownloader?
      • Or less crazy, an AutoPkg recipe?
      • foigus
        The people here noticed the SEP scheduler randomization failed on the Macs when the entire fleet decided to download the defs at the same time.
      • jhbush
        @gneagle cooking with gas
      • freezig joined the channel
      • slapaglia1 has quit
      • chuckfromis has quit
      • slapaglia joined the channel
      • foigus
        Wow, Timbuktuu is finally going to stop being sold
      • slapaglia has quit
      • arekdreyer
        foigus: Yeah, but those bags last forever
      • slapaglia joined the channel
      • foigus
        Not sure if arekdreyer is being silly...
      • arekdreyer
        foigus: I'm not looking forward to trying to figure out how to fit a MacBook Air into my new ARD bag
      • foigus
        :-)
      • arekdreyer
        foigus :)
      • slapaglia has quit
      • cramey has quit
      • foigus
        We had a site license of it here for remote support (that we didn't renew for OS X). It's only been in the last year or so that users stopped using "Timbuktu" as a verb.
      • cramey joined the channel
      • ctdawe has quit
      • Frosh
        gneagle in your wisdom, which do you recommend? or which does your org uses?
      • gneagle
        I decline to answer. Sorry!
      • gmarnin has quit
      • Frosh
        gneagle in your wisdom, which do you recommend? or which does your org uses?
      • chuckfromis joined the channel
      • gneagle
        ...
      • foigus
        I'm not sure wearing him down will work here
      • grahamgilbert
        Nick_ZWG: what can I do for you?
      • natewalck
        Frosh: What is the goal?
      • Frosh
        natewalck to find the virus
      • gbatye joined the channel
      • and remove it
      • gbatye has quit
      • natewalck
        Frosh: I inherently dislike AV
      • Psychodata
        nuke and pave?
      • natewalck
        but I've had an "ok" experience with McAfee
      • Goobersmooch joined the channel
      • Sophos 9 has been a bag of pain
      • gbatye joined the channel
      • zuhl has quit
      • slapaglia joined the channel
      • ropav has quit
      • ropav joined the channel
      • zuhl joined the channel
      • rustymyers has quit
      • mikedodge04
        natewalck: https://osquery.io/ > AV
      • slapaglia has quit
      • natewalck
        mikedodge04: Once implemented, ofc ;)
      • it isn't plug and play.......yet.
      • or is it?
      • ;)
      • mikedodge04
        natewalck: no you have a point
      • but i stand by my statement!
      • natewalck
        I think it'll be there before long
      • Open source tools all the things
      • neilmartin83 has quit
      • MiMMiC has quit
      • arekdreyer
        mikedodge04: looks more like an equation than a statement ;)
      • zoocoup has quit
      • henrycoule joined the channel
      • mikedodge04
        natewalck: "Mathematics equation: A written statement indicating the equality of two expressions. It consists of a sequence of symbols that is split into left and right sides joined by an equal sign. For example, 2 + 3 + 5 = 10 is an equation."
      • equation == statement
      • ropav_ joined the channel
      • natewalck
        mikedodge04: you mean arekdreyer
      • mikedodge04
        arekdreyer ^^
      • arekdreyer
        mikedodge04 Fair enough.
      • ropav has quit
      • halloweenhead has quit
      • halloweenhead joined the channel
      • diwanicki has quit
      • halloweenhead has quit
      • halloweenhead joined the channel
      • diwanicki joined the channel
      • gbatye has quit
      • Nick_ZWG
        grahamgilbert: I kinda answered my own question, but is there an official way to search for a given serial number in Sal's interface?
      • grahamgilbert
        Nick_ZWG: all machines and then you can filter them
      • Nick_ZWG
        word
      • macdude22_work joined the channel
      • cramey has quit
      • MiMMiC joined the channel
      • jimmy_volker has quit
      • cramey joined the channel
      • GaToRAiD
        anyone have an idea of how to give an app access to a private key not through the gui?
      • Nick_ZWG
        My favorite part of Apple Configurator is when one ipad decides not to fully update and instead goes into recovery mode
      • chilcote_ has quit
      • Goobersmooch has quit
      • jimmy_volker joined the channel
      • natewalck
      • that is what I came up with (+ grahamgilbert )
      • halloweenhead has quit
      • halloweenhead joined the channel
      • macmule
        GaToRAiD: I have tried that & gave up tbh
      • GaToRAiD
        seriously?
      • macmule
        GaToRAiD: yep
      • GaToRAiD
        my whole project centers around that ;(
      • tvsutton
        GaToRAiD: Maybe more details needed
      • natewalck
        I really need to start using feature branches ;(
      • macmule
        GaToRAiD: we had some crappy VPN software that needed it. There was some other issues though too.
      • abbaZaba joined the channel
      • GaToRAiD
        macmule: would that vpn software be cisco any connect?
      • lol
      • gneagle
        natewalck: looks good; assume you tested on an AutoNBI boot?
      • macmule
        GaToRAiD: nope. Palo Alto global protect.
      • GaToRAiD
        macmule: gotcha, well this sucks
      • squirke has quit
      • lionelg joined the channel
      • natewalck
        gneagle: I tested on DeployStudio this time, about to test on AutoNBI
      • macmule
        GaToRAiD: our guy amended/fixed a policy on the firewall end & now a non-issue.
      • GaToRAiD: there are some theads on JAMFNation for that.
      • mscottblake has quit
      • gneagle
        DS NBI should behave virutally the same
      • natewalck
        indeed
      • GaToRAiD
        macmule: I'll check
      • Goobersmooch joined the channel
      • halloweenhead has quit
      • Psychodata
        Nick_ZWG: It's especially fun when the teacher whose classrooms ipads are now in recovery and she insists that you did something wrong
      • chilcote joined the channel
      • aaronc_ joined the channel
      • elvisizer
        GaToRAiD: is the private key already in the keychain, or is your thing installing the cert at the same time as needing to grant access to the private key?
      • GaToRAiD
        elvisizer: it will already be there
      • elvisizer
        yeah, that's hard, not sure that it's possible. I've only found ways to do that when installing the cert to the keychain, the -T option
      • GaToRAiD
        elvisizer: the cert will be provided by scep
      • elvisizer
        this is one of the reasons I stopped using SCEP actually
      • GaToRAiD
        arg
      • gbatye joined the channel
      • ideopathic has quit
      • beg00d joined the channel
      • mikedodg_ joined the channel
      • foigus
        Any Zendesk + Munki users here? If so, do you know the syntax for munki:// links in Zendesk tickets?
      • beg00d has quit
      • gneagle
        Why would they have special syntax in Zendesk tickets?