Showing posts with label OSX. Show all posts
Showing posts with label OSX. Show all posts

Sunday, August 7, 2011

OSX Lion first impressions

Like the last several updates to OSX, Lion is not a very exciting update to me. I like to be running the latest, but there was nothing driving me to Lion other than that. So here's my take on the things i've seen that are noticeable at least to me:

OSX Mail - PASS
I've been using Mailplane for the last several months due to the fast search, lack of sync issues, and other things you get with a more-native google mail experience. With the new updates to Apple Mail I figured i'd go back to trying a typical local client. The details of that experience are yet another post, here i'll just talk about the differences between the old OSX mail and the new one. Apple added an archive button like they did on the iPhone and the iPad to mail. Thats a nice addition, but unfortunately it doesn't work like it does on the iPad and iPhone. On those other devices the button actually archives your mail to the Google "All Mail" folder. On OSX it sticks the mail in [IMAP]/Archive so then you end up with 2 copies of archived mail from your Apple mail client if you're using google mail -- one in [IMAP]/Archive and one in "All Mail". So they added the archive concept, but for everyone and completely ignored the Google mail use case. We've seen other oddities in using Apple mail with google before and there was the option to "Use this mailbox for" junk/sent etc. Well the new Archive is not one of those. Apple did a half-baked job here. Google mail is here to stay and better integration with it would be nice. For now i'm still on OSX mail but probably not for long given how poorly it works with gmail.

Beyond that, the new conversation views are nice, again another nod and ripoff from gmail. Apples new 3 panel view is better suited to wide screens but its hit or miss with people. Probably about 50% of the people I know hate it and want it set back to the old layout.

The search seems much better now and actually finds things and to me this is the biggest improvement in mail and the reason I didn't immediately switch back to the google interface.

Still, if your mail is served up by Google, Apple Mail is a poor tool for it if you get a lot of email.

Launchpad - FAIL
This is Apples new App launcher for OSX trying to do for OSX what they did for the iPad and iPhone. Personally I still think the app launcher has a lot of maturing to do on those other devices, and here on OSX its actually much worse. First, you have more apps on OSX so you end up with more screens of them. Not only that the icons are HUGE. Multiple screen management is a pain, made somewhat easier by iTunes but you can't do that on the OSX version. You also can't remove Apps from the launcher on OSX so you have a LOT of them -- even the silly ones you don't care about. And after you upgrade you have a huge organization job to do if you want it all organized reasonably. On top of all that I crashed it frequently. I've taken it off the dock, shortcuts etc and forgotten about it. Its dead to me.

Mission Control - FAIL
This is the new replacement for spaces. To be honest I liked the old one better. It was easier to configure and use and I could better pick what ran where and in which direction I could find it. The old spaces allowed spaces in 2 dimensions, now you can only have spaces in a single dimension. Also some apps that used to run in multiple spaces fine (tell the app to be assigned to "all spaces") no longer work in multiple spaces (EyeTV for example). Perhaps those vendors need to fix them but for now its broken/worse. Another annoying thing to me is the dashboard is one of your spaces. While it may make sense for some that use the broken/worthless dashboard, for those that don't it would be nice to turn it off/forget about it. That was a failed concept, why bring it back to my attention again? Anyway, I use mission control since I have no choice, but I would have preferred if they had left it alone.

Saved App States - FAIL
OSX now saves all your open files when you quit your apps. This sounds great but its actually REALLY annoying. You're reviewing a word document someone emailed you, you quit word. 2 days later you open an unrelated document and, bam, the document you were looking at a couple days ago pops up. Thats distracting/confusing/annoying. It would be nice to have this setting only on app crashes or, better yet on a per-app basis, but otherwise i've shut it off -- it makes no sense in its current form.

Scrolling - FAIL
Everyone i've spoken to about the upgrade has complained that Apple literally inverted the scroll functionality with Lion. Few have gotten used to it and most have changed the setting to scroll the way it did before. Combine that with jumping between PC and Mac and virtualization and you have a big mess. What were they thinking?  For now i've kept it with the Lion default myself just to see if I can get used to it. Im getting there. Slowly.

File Vault - FAIL
The support for full disk encryption now is really nice, thats a great feature. But at the same time they killed home folder only encryption. This means encryption is all or nothing. Thats terrible. I have some data that needs to be encrypted and some that I do not need encrypted and don't want to pay the performance penalty for it. Data I don't need to be encrypted is large, things like iPhoto and iTunes libraries etc. Why did Apple not do the reasonable thing and add folder-level encryption in addition to whole disk. That would have been the best of both worlds. But, again, they blew it.

Auto-save - FAIL
Auto save may well save my bacon some day, but for now its been a pain. I recently opened a file, made some changes, and saved it as a new name and quit. Then when I opened the original file again I found my changes were in the original too and I had to go through a fancy and slow graphic experience to get the original file back that I had never saved. There don't seem to be any settings to turn this off either, if you could I probably would.

At this point I had to search to see what else Apple said was in there. Generally the rest was noise and I didn't see it or get excited about it:

  • Address book - new look is ugly to me, I wish they had left it alone.
  • Airdrop - At home its more work than should be needed to move files around. At work I have a shared NAS. I think the sole use case here is a small office environment where they didn't get a NAS yet.
  • FaceTime - already had it (paid for it via App store). I've only used this to play with it though. They still didn't reconcile this with the iChat video chat. Why do we need to video chats created by Apple?
  • Finder - some of the tweaks are nice. But they're tweaks. I wish they had made Finder more resilient to hangups from slow drives etc. Its still bad in that regard.
  • Full screen apps - I work with multiple apps at the same time and i'm not ADD distracted by other windows. I can't find a use for this.
  • iCal - I don't use it, its junk. I use Google Calendar wrapped in fluid. That works like magic. They could have deleted iCal for all I care.
  • iChat - this actually had some really decent updates, not the least of which is supporting other chat protocols. I was using Adium all the time and now i'm using iChat all the time. Apple may have just killed Adium for me.
  • Safari - I was using Chrome, I'm trying safari again. The big draw here is the bookmark syncing with my i-devices and the new reading list (which kills instapaper for me). The draw to chrome was better functionality, better incognito and the speed. Safari so far is pretty quick.
  • Per user screen sharing - great idea, but so far my use of this has locked up the machines in question. When it works it will be a good improvement but for now it doesn't work for me. 
Anyway, as I said at the beginning of this post, Lion is mostly a series of small updates to me. 

OSX Lion Install

I was traveling when Lion came out so I got to miss the mass rush to download it etc. But about a week after it came out I gave it a shot. I bought it and downloaded it and started the install. It gave me all sorts of not-well-defined warnings about installing on a RAIDed volume. My OS disk was an Apple Software RAID RAID-1 volume. Lion told me it wouldn't create a recovery partition for me and sort of implied there may be other things I wouldn't get if I proceeded. I didn't like that so I un-raided the volume before continuing, but it makes you wonder if Apple really supports their own software RAID.

The install went clean after that (first impressions in another post) and I moved on to my next machine. The next machine was my wife's. We're on the Apple MobileMe family pack but because Apple really has no concept of a family group etc, I couldn't just download the package from her App store account because to apple we're unrelated even though both app store accounts are tried to the same family account. Fortunately, from the broken RAID install earlier I had saved off the Lion installer. Rather than login as myself etc on her machine I just copied the installer over and ran it which worked fine. Apple really needs to figure out this family stuff -- its been a mess for years.

The next machine was my laptop from work. That one had file vault on it. I copied the installer over (rather than re-download 4GB) and ran it. The installer took 3 minutes and rebooted to continue but just came back to snow leopard. Did that another time with the same results. What was going on? Turns out I had copied the installer to the desktop and ran it from there. Well, the desktop is encrypted if you have file vault turned on so when the machine rebooted and I was not logged in it couldn't get at the installer to continue installing so it just reverted. The solution was to copy the installer to the /Applications directory (where Apple downloads it to normally) and then the install went clean. You'd think their pre-install check would look for this sort of thing.

I upgraded my desktop machine too at work with no issues after this. All in all it was pretty much what you'd expect from Apple. The edge cases have a few wrinkles but nothing disastrous and things run after you've upgraded. Being in the software industry this is no small thing although you'd think with the numbers of beta testers they have etc they could cover these not-so-edge cases a bit better.

I'll post some impressions in my next post.

Saturday, March 27, 2010

MobileMe is almost dead

At one time MobileMe kept my life together and kept all my devices in sync. The main things it did for me that I cared about were Calendars, Bookmarks, Keychains and Contacts. The other stuff I saw as nice to have but not really needed. I don't want the same preferences, email config, mail rules etc on my work computer as my home computer. So why am I getting away from it?

  • Bookmarks - with the switch to Chrome, Google provides bookmark sync through your Google account (via Google Docs). It works well and is free.
  • Calendars - I wrote a short while ago that I was done with iCal. Google Calendar is better and its web-based so its free and everywhere.
  • Keychains - Really what this is about is password management. For that 1Password rules. The 1Password guys have an odd approach to telling you how to keep your stuff in sync (they say to use DropBox and that the MobileMe iDisk stinks) but it works and is secure.
  • Contacts -This one isnt perfect. Apple added the support for Address Book to sync with Google contacts a while back. Google doesnt bring over the groups etc yet.  So you can get close but not quite there. Also the whole Google versus Google Apps piece is just plain busted in all sorts of ways. More on that later.  You could work around the mac need for MobileMe by moving your contact information to a DropBox covered directory, but as far as I can tell a good integrated iPhone, multiple mac solution isnt possible yet without MobileMe involved.
So close!

Saturday, March 13, 2010

OSX Server = FAIL

Ok, after a year of trying hard to make OSX server work for our small business (< 20 employees) i've given up. Stop reading here if you don't want the gory details.

OSX Server just doesn't work and is not ready for prime time. The straw that broke the camels back was Calendaring. We're at at point at the office where calendars and shared calendars HAVE to work. We moved to Snow Leopard server with the hopes that that update fixed calendar issues... It didn't. Internally, after the upgrade, things were great, we should share and view each others calendars. But the issue was when we tried to get invitations from people outside or send invitations to outsiders we couldn't add the invitations, people couldn't open our invitations etc. When you combine that with other calendar things like not being able to control which email account the invitations go out from it was a total disaster. 

On top of the calendar issues we saw mail getting hung up in the queue when spam filtering was enabled so we had to turn that off. Running without a spam filter, even a mediocre one, is really painful. Then there's the whole issue of a lightweight interface to DNS etc.

We thought about just using google calendar for calendaring and keeping mail the same and limping along with spam issues, but then found out that unless your invites etc arrive at the same email address (including domain name) that the calendar is at then google calendar doesn't do well with it -- invitations get confused, not added etc. So both email and calendar have to be at the same address/domain for google apps.

We looked at 2 options: Go to Exchange or try Google Apps again. Exchange is proven in very large businesses and can do it all. But its not cheap (we guessed about $20K for us to deploy) and would take time to deploy and migrate. We could go the hosted approach but still had migration issues plus the loss of control over our data. If we're letting someone else have some of our data then a hosted solution for exchange versus google apps is probably equally risky. 

So what we decided to do was go the Google Apps approach. Perhaps this will only buy us a little time or perhaps it will last for quite a while, we'll see. Essentially we changed all mail to flow through the Google Apps domain but then forwarded it on to a sub-domain for the users that don't need the calendar support. By creating all the accounts first at google and forwarding all the mail to the subdomain we essentially changed all the users over without them being involved -- the mail just flowed through google. Then for the users that need calendars we unforwarded the mail and now new mail comes into and stays at google. Here are the exact steps:

  1. Create Google mail/cal setup @ domain.com (google apps)
  2. Add mx records for sub.domain.com
  3. Rename domain.com -> sub.domain.com on your current mail server
  4. Create all users @ domain.com (google)
  5. Adjust domain.com mx to point to the new google apps setup
  6. Forward all mail from domain.com to sub.domain.com (so the move is transparent. Note there's a window between 4 and 6 where a few emails could come in so watch out. Google doesnt let you add users and forward mail until your MX records point at them)
  7. Move desired people back from sub.domain.com to domain.com by disabling forwarding and giving them their google passwords
Note that step #3 with the OSX mail server was non-disruptive to the users. We essentially changed their email addresses from user@domain.com to user@sub.somain.com without them knowing or changing their clients. Thats because on OSX server you auth with just the username and password not the full email address. That was a nice trick that avoided a lot of noise for the team.

Why not just move all users to google mail (i.e. no forwarding)? Because Google has some oddities in the way they behave as a mail server. Their labels vs. folders is one, the limit on how many clients for the same account can connect at one time is another. The data being offsite/in their hands is another.

The result?

You could literally hear the joy from the people now having working calendars. It just works and was night and day better than Apples iCal server. On top of that Google is eating spam as one of the best spam filtering services on the planet. 

While I have my issues with Google Calendar, if you can avoid the issues it does the job well.

So now that we're not using OSX server for calendaring and most of the heavy (and less technical ) mail users are off on google, we're not very dependent or tied to OSX services. We're going to move to a tried and true Linux-based DNS, DHCP and Dovecot mail setup. No fancy UIs to undo our work or hide power and functionality.

If you're thinking about OSX server -- DONT. Its a waste of your time and money. Start with Google Apps and when you grow out of it move to Exchange (hosted or not based on your security/financial constraints)

If you're following this blog to learn about OSX server, stop now. I'm taking it out back and putting it out of our misery.

Sunday, March 7, 2010

BluRay and OSX

Apple has yet to add native BluRay support to OSX. You can use Roxio's Toast Titanium with a $20 add-on package for BluRay to burn disks. Saving away 50GB at a shot is very nice but the disks are still $13+ each. The 25GB disks are a more reasonable price of $2-$3 each. 

Reading the BluRay disks is another thing. With a combination of MakeMKV (currently in a time-limited beta) and Handbrake you can copy/convert BluRay disks to a different format and with assistance from MakeMKV and VLC you can watch them by following a process that is outlined here and summarized below:

1) Open bluray disc in Makemkv and then click Stream.
2) Click http://192.168.0.180:51000 (for instance) to open your default web browser.
3) Navigate to the title, something like http://192.168.0.180:51000/stream/title0.ts
4) Then paste that link in VLC in the File | Open Network (command N) in the URL section and voila watch your bluray on Mac directly off the bluray disc in VLC.
5) Do not try to stream or play in Firefox or Safari it just won't work.

I confirmed all the above works although its all a bit touchy in terms of the quality of VLC and MakeMKV.

Your alternative is a long conversion process, or just go play them in a PS3 or other standard player. Steve Jobs evidently frowns on BluRay.


Sunday, January 17, 2010

Snow Leopard Server

So as you can tell from previous posts, we moved from Leopard Server to Snow Leopard server. The move wasn't without a TON of pain. The hope was that things would be significantly better on the new version. Some things (unlimited client licenses) are better, but most things are just.. different.

There's still plenty of signs that its a mostly untested piece of software from apple. The fact that there's a button in the mail configuration to enable antivirus but when you push it it doesnt work shows that basic testing hasn't been done. If you run into this, as we did, you can find solutions online.

There are other annoyances/totally broken areas, i'll list a few:

  • Groups don't work as mail distribution lists anymore. Not sure how they broke this, but they did
  • Calendar invites from outside your domain do not go to your domain calendar, and if you try to copy/place it on the right calendar you get: The server responded: "HTTP/1.1 403 Forbidden" to operation CalDAVWriteEntityQueueableOperation.
  • You still have to hack the server to enable RADIUS for VPN authentication. Apple has it fixed to do wifi auth and didn't think this through
  • Mail aliases still are not supported so you still have to sudo vi /etc/aliases in the terminal to manage these. Then you need to deal with any races in it overwriting on its periodic updates as you edit the file
  • They have not thought through the whole internal versus external naming/conventions around their web mail/management interface to the point that its almost impossible to make use of

Thats just the list from the top of my head. The main point being that if you're thinking about using OSX Server for your business, and as much as it hurts me to say so, i'd say don't and go use Exchange. Sure its more expensive, harder to manage, etc, but the thing works and Microsoft, unlike Apple, seems to care about it.

Leopard Server = No Time Machine

In upgrading from Leopard Server to Snow Leopard Server our IT consultant made the assumption that Time Machine had his back on the upgrade. Generally Time Machine was backing up the Leopard server, but what wasnt obvious until we poked around in the backups is that on Leopard Server it does not backup mail. I had previously looked into mail backup and had mailbfr installed, but it hadn't run recently as he prepared for the upgrade. Apple fixed this major deficiency in Snow Leopard and now mail is indeed backed up with Time Machine on Snow Leopard server. 

It makes you wonder though, Apple claims to be making business class servers and software. They include their own backup software, but it has a major omission around mail backup. This is just another point that apple is not serious about running the servers for businesses.

OSX DNS issues

Is your mac behaving oddly with regards to DNS in that its not honoring the DNS server? I found out the hard way that apple, with its mDNSResponder service, broke tried and tested DNS on OSX. There are plenty of places on the net you can find this mentioned and its surprising and frustrating that Apple hasnt fixed it yet. Anyway, if DNS is behaving oddly on your mac, start with:

sudo killall mDNSResponder

It will restart itself and refresh DNS.



Monday, September 28, 2009

DNS over VPN and Snow Leopard

Since upgrading to Snow Leopard DNS hasn't worked on VPN. A friend suggested a:

sudo killall mDNSResponder

And sure enough that fixed it. Poking around I found others suggesting that it gets scripted up to get killed every 60 seconds.

The fact that this helps and the fact that companies like Parallels have knowledge base articles on it would lead one to believe Apple should be fixing it.

At least the workaround is known until Apple gets in gear.


Saturday, September 19, 2009

ScanSnap 510M and Snow Leopard

One of the many casualties of Snow Leopard, the ScanSnap S510M software got crippled with this update. ScanSnap is an oddity to me. Such a great scanner and such poor software and support by Fujitsu. Anyway, the ScanSnap software broke in an odd way. You cant "Scan to Folder" but you can "Scan to Print". Fujitsu posted the chart of what works and what doesnt. So my new workflow is to "Scan and Print" but then from the printer settings box, do a "Save as PDF". One extra step but essentially it recreates what I had before things broke and my Scanner is functional.

Shame on Fujitsu for not fixing this before the Snow Leopard release or shortly after. Double shame on Apple for breaking so many things with a featureless release.

Saturday, September 12, 2009

Snow Leopard - wait it out

I pre-ordered Apple's latest OS, Snow Leopard and got it the day it
came out. Thanks to some FedEx fiasco's I didnt install until the next
day but I think I still qualify as an early adopter. I have to say i'm
seriously disappointed. The quality and compatibility is poor. Worse
than any other release i've experienced from Apple. Here's some of
what i've seen:

1) Many applications are incompatible and not yet updated. Perhaps you
can blame developers for not being on top of things, but I think not.
I expected PPC apps to have an issue as this is an intel only release,
but I was shocked at the number of apps that broke even though they
had intel support. Here's a short list:

Medialink, EyeTV, Growl, ScanSnap, 1Password, Contribute, and many more

Why did so many apps break? Why didn't apple warn people in advance?
The upgrade from PPC to Intel machines was smoother.

2) I've seen several "black screen of death" events where I must power
cycle the machine. I was perfectly stable before that. For the record
the machine I saw that on I did a complete wipe (disk format) and
fresh install of Snow Leopard and then only installed the latest
versions of apps I needed. Can't blame some less tested upgrade path
for that one.

3) I've had many hangs in Mail and Safari where I have to force quit
the apps. Didn't have those issues before the upgrade. This is a fresh
install, Apples apps and basic ones. Quality Control?

4) We've seen some odd behavior -- VPN to work using Apple's native
VPN to a Cisco firewall worked great before Snow Leopard. After the
upgrade DNS doesnt work. You can connect but you cant resolve anything
on the other end so you end up having to edit /etc/hosts and add
systems by hand. How'd they brake that one? And why? (multiple people
have experienced this)

5) Some vendors, like the Agile folks, makers of 1Password, have
chosen to use this as an opportunity to charge for an upgrade and not
support you unless you upgrade. Considering i'd owned 1Password for
less than 10 months I was shocked to see them require me to pay for an
upgrade. On all other fronts the Agile team is amazing but this
decision is flat out wrong. Others have gone down that route and
you'll be paying for upgrades to apps that worked fine prior to Snow
Leopard. The OS may be cheap ($29) but the time sink and the apps you
have to pay to upgrade are not.

So i've had issues, what about the good stuff? Um, what good stuff?
Frankly I haven't noticed a performance improvement and the
frustrations of a semi-stable OS wipes that out anyway. There are a
few very minor visual improvements, but fundamentally almost nothing
is noticeably different.

Its too late for me now, but I wish I had waited 6 months+ to upgrade.
Not the normal experience with Apple.

Friday, September 11, 2009

iTunes 9

I was checking out some of the cool stuff in iTunes 9. There are still
some silly things they're doing which I think are basic that need to
be addressed:

1) Finally they let you have the concept of home shared libraries with
a common iTunes account. The problem though is that if my wife and I
want to sync the same songs to our iPods we have to have them in the
local library. In other words we're being forced to copy music around.
Why?

2) The iTunes Store got a major overhaul which is cool. But they still
have a very broken behavior in that they give you NO indication that
you already own a song. Go to "iTunes Essentials" and you'll see
recommended songs and pricing but you may already have/own the songs.
Why cant they search and indicate this?

Anyway its a good app and getting better.

Thursday, July 30, 2009

Another OSX Server-ism

I was making a minor change on OSX server today, just adding another
machine to DNS. I found out the hard way that if you insert a comment
with parenthesis "()" in it in the description fields OSX server DNS
crashes in interesting ways. The GUI crashes and eventually all of DNS
comes down, specifically the line that crashed this piece of OSX server:

machinename IN HINFO "Virtual Machine running on anothermachine
(description)" "more text"

The same line without parenthesis works just fine.

Makes me wonder if anyone is using OSX Server for real prime time
operations.

Sunday, May 31, 2009

OSX Server - What works and what Doesnt

So after 2 months of using OSX server, here's the update:

What we're using it for:

1) Central file server - I often have to fix permissions on the shares as someone will copy things into a share and the file will be read only to others in the same group. Since the UI is messed in Leopard (see previous post) you have to fix this through a VNC connection on the server which means you need to be an admin. Apple really needs to fix that.

2) DHCP - this is working, although some of the engineers have complained that the OSX DHCP server seems slow.

3) DNS - no real complaints here

4) Mail - The UI around the mail setup was weak and broken. Has anyone tested that? Some things we had to do:


/etc/postfix/master.cf -> uncomment submission inet n - n - - smtpd
enables port 587

/etc/postfix/main.cf -> add tls_random_source = dev:/dev/urandom (gets rid of some error messages)
"no entropy source specified with parameter tls_random_source"

/etc/imapd.conf -> add tls_ca_file: /etc/certificates/wasabi.nasuni.net.crt (gets rid of more error messages)
"TLS server engine: No CA file specified. Client side certs may not work"

http://www.corpmac.co.uk/2008/09/30/tls-no-ca-file-specified-reason-and-solution/

They also don't let you add aliases other than Groups so you need to:


sudo vi /etc/aliases
sudo newaliases


Also note that when you stop the mail server and restart it through their UI (i.e. after you changed some settings) you often lose the first email that gets sent after restart. Nice.

Generally i'd recommend using someone else's mail server. The experience was not an "apple" one.

5) Open Directory - Apple uses this for all the user/group management and I havent had to touch it.

6) Radius - We use this for Cisco VPN authentication. Note that OSX server didn't really support this in the UI, so you need to follow some instructions.

7) Software update - saves multiple macs downloading to the same spot. Note that the first time you turn this on its really painful as it brings in a lot of updates.

8) Backups - the server time machine's itself and presents itself as a time machine target for any clients to use.

What we're NOT using it for:

1) Wiki - I used the Apple Wiki quite a bit. Its VERY limited. The WYSIWYG is nice, but you don't always get what you see and it can do some odd formatting stuff. If you want to do more advanced stuff you get thrown into HTML and the HTML is cluttered and hard to manage. You can't do a lot of basic stuff and eventually I punted and went with the tried-and-true MediaWiki which i'm very happy with. Its running as its own VM.

2) Web Hosting - I didn't really even try this. I wanted a server that wasn't hosting all the stuff above to be our external web host. So I created a standard Linux VM and am hosting the site via Apache.

3) Firewall - We have a decent Cisco firewall so I didn't try the OSX server firewall.

4) Our source code control/bug tracking etc is off on Linux VMs.

OSX Server bonding issues

We had some crazy issues with our OSX server setup. When we had clients join the server we had odd permission problems, synchronization issues with passwords etc. After much mucking around it turns out it was mostly our fault. Our OSX server is also a target for SSH from the outside (not on the normal port 22 and requiring certificates). To support logging in I had created some local user accounts on the OSX server machine, and for convenience I had given them the same names as the server accounts.

DONT DO THAT

OSX server gets very confused if you have local accounts with the same names as the server accounts. And you don't need the local accounts anyway as you can enable the server accounts to login/get a shell through the admin tools. Deleting all the local user accounts and enabling the ones we needed to login helped a lot of the issues.

The Leopard client still does odd things when you're looking at group/user permissions (and ACLs) on network shares. Seems that Apple messed this up in the UI in Leopard so that if you look at them you see things that just don't make sense as the users/groups are not getting copied over from the server and displayed correctly. Under the covers of the UI the right things seem to be happening but it can be confusing for the users.

OSX Environment and IE

In our vision for an All-Mac office we sort of expected to be able to pull that off without any bumps. I mentioned previously that I ran into early bumps of some office environment management apps that required windows. Later I found out that our bank (Silicon Valley Bank) and our payroll group (ADP) both have web sites that are not friendly to non-Windows/Internet Explorer environments. I proceeded to setup a new VM with Vista Home ($199 for the full install) for our office admin to run just for IE for these sites but otherwise to use the Mac side of things. When you run into mainstream companies that lack support for non-Windows platforms with their websites you really get a sense of the size of the Linux/OSX market on the business side of things.

Another thing i'm amazed at is that Vista Business sells for $300, but I can buy a full Netbook with Vista Home for $300, or a Dell Inspirion 531 with Vista Home for $249. Vista Home sells for $199 for a fresh install which is required for VM use. So the hardware is worth $49. You can setup a VM for $199 or you can have dedicated hardware for $249. While I went the VM approach mostly because I dont want more hardware to deal with (power, cooling, all that) the economics just don't make sense. 

Sunday, May 3, 2009

iTunes Music Video Playing Problems

If you happen to be having problems playing music videos in iTunes I
found an odd behavior: If you use multiple speakers normally for
playing music, then Videos won't play when you have multiple speakers
selected. You have to choose just the speakers of your mac and then
the videos will play. Seems like a bug to me -- there should at least
be a warning.

Saturday, April 4, 2009

OSX Server Day 1

Now that we were limping along from an IT perspective it was time to get a real server created. I took my OSX Server, 10 Client edition, popped it in my new MacPro (Nehalem) turned it on and got a white screen. Nothing. Odd. I booted off the pre-installed Leopard and it was fine. So from there I decided to just install it from the CD versus booting the CD. It installed fine and I rebooted and had OSX server. Then I was presented with a LOT of system management options and terminology and concepts I didn't know. I thought OSX server was supposed to be easy? Turns out there are 3 modes to OSX server - Standard (simple), Workgroup, and Advanced. When you install the way I had to it treats it as a server upgrade and forces advanced mode. 

Why couldn't I boot the CD? Turns out the OSX server I bought (several months ago) was older than the hardware I had just bought and was missing drivers etc and I could not swap the disk for a newer one without paying $500 to apple again. This was nuts, I got on the phone and after speaking to 5 Apple people (just to get to the correct department), I got told that since my OSX server was purchased a while back, and even though it wasn't used, they shouldn't be supporting me. Nice, so much for planning ahead. But then they said, if you do the install by booting Leopard and then running only a piece of the OSX server install package it may let me avoid advanced mode. I got one blurb from them on how to do this:

"Install OS X client onto unit, creating an admin user with the name & password that you want on the server. 
Update all SW and then insert OS X Server install disc into unit. 
Go to Finder>Go>Volumes.
The name of the metapackage file to be run is "MacOSXServerInstall.mpkg", which is located in /Volumes/Mac OS X Server Install Disc/System/Installation/Packages.
Run this metapackage file to install OS X Server on unit. "

Nevermind the fact that this information was limited and flawed, it gave me just enough to find the package I needed. The best way I found was to do this through the terminal and then "open" the referenced package. After doing this I got OSX server setup in the way it was meant to be. 

It took a great deal of time because each attempt required OSX updates (over my crazy aircard setup) as well as OSX server updates. A few times as they were setting up the rest of my network I had wrong IP addresses/configurations which were difficult to change in OSX server so I had the pleasure of doing this several times.

In the end I think the steps are something like this (none of which I could find with google searches):

1) Boot Leopard install CD (even if your new MacPro has Leopard pre-installed)
2) Go into disk utility and set up your disks the way you want (OSX server install would have had this step but you can't boot that). Your options may be more limited than OSX server but I had 4 1TB drives and created 2 mirrored 1TB volumes. One I called "OS" and one I called "Data". I'm so creative.
3) Now install Leopard and do all the updates. If you're doing this with an Aircard bring a good book.
4) Now, while logged into leopard after all the updates/reboots are done, put in the OSX server CD and run the package above. You'll walk through OSX server install. Oddly it doesnt force a reboot. 
5) Next, don't do any updates (if you do, start over at #1 - found that the hard way), eject CD and reboot.
6) Now you get the OSX server install screen asking you about standard (stand alone) vs workgroup vs advanced. I originally chose standard but later found out I should have chosen workgroup so I started over again.
7) Now once it comes up you can do the OSX server update (another 200MB+ over the aircard). Note that if you plan on making mistakes like I did its helpful to download these update packages and squirrel them away (I put them on the data drive that I wasn't wiping on each attempt).
8) Now you have an installed OSX server. Time to figure out what it can and cant do. Thats for another episode.

The alternative is to buy/get an OSX server CD that works with your hardware. My first experience with OSX server has not been pleasant.

IT early pains

With our new office we rented space and I hired a group (Rockport Technology Group) to come in and do the wiring, phones and basic network setup. They're a great bunch of guys that i've used before and they always do a first class job. What I was left with was a CISCO ASA5505 firewall, 2 Cisco 521 WAPs, a 48 port GigE switch, a Nortel BCM 50 phone system and a Keyscan card reader system for physical security. 

With that gear I have a wired and wireless network as well as phones and card access for my office which can sit about 40 people. Note that I haven't mentioned an internet connection. Thats because we don't have one yet (!). I ordered dual T1 lines from Verizon, but T1s take time (4-6 weeks). The fallback was Comcast since they were supposedly in the building already and had a 2-3 day install time. Even though they pre-certified the site/install when the guys turned up they found no Comcast in the building. They said they need to run cable to the building and they need to wait for the ground to thaw first (yes, though its April our ground is frozen after you get down a few inches -- welcome to New England). So I cancelled that order. I had had 5 phone lines installed by Verizon for the normal phone system so we asked them to convert one to DSL. You'd think that would be fast, but it takes Verizon 7-10 days to do that too. The DSL should be live next Tuesday. The T1's follow 3-4 weeks later.

So I have an office full of people that need internet access, what do I do? My crazy fallback idea from the beginning was to use my Verizon Aircard. I bought it a while back and used it to be on the net at all times, in the car, in airports, etc. Its a decent card and fast. So in the beginning I had it in my MacBookPro and was just doing internet sharing from it to the Airport. Apple makes this dead easy and it works well. The problem is the office space is 7K+ sq ft so there's no hope of covering much range that way. I could try to extend it with other network gear like Apple's airport express but i'd be buying them to use them for a week or two. I could try to bridge it to our new Cisco wifi but that was still coming online and having its own challenges. The other issue was that I needed to use my MacBookPro for stuff and so the network connection would come and go based on what I was doing which didn't help the others.

What I didn't have were any servers set up yet. I had bought 2 of the new Nehalem MacPros to be used for "IT stuff" and decided to use one of them to bridge to the net. I used one with the base Leopard install, installed the aircard and Verizon software and turned on internet sharing bridging the aircard to the wired ethernet port. Since the Cisco WAPs (wireless points) were also connected to the same network, all of a sudden everyone had internet access whether they were on Wifi or wired. The Verizon software (VZ Access Manager) just pain stinks. I have a conspiracy theory on these cell companies and the aircards -- its that when you use too much bandwidth they drop the connection just to see if they can stop the traffic, if nothing else its a brutal throttle. VZAccess doesn't automatically reconnect. But if you look in your network settings when connected with VZaccess, they have a new network location setup with the Verizon modem. In that new location I added in the ethernet port I wanted to share. I also set that location to be my location whether I was connected or not. I then when into the advanced settings of the modem through the OSX network preferences pane and set it up to auto-reconnect, never disconnect etc. With that done the network drops at times but reconnects without my involvement and we've had a productive few days downloading tools, updates, email etc. Its no speed daemon but its something you can live with.

I used that same MacPro to create the VMWare environment for the management apps for the Nortel and Keyscan pieces that I spoke about in my previous post. I also created a basic file shares so we could move things around internally.

Now I needed a real server with permissions for the different elements of the business, that was stable, could be backed up etc. More on that to come.

OSX Office Environment

I've had the fortunate experience (kidding) to become a part time IT guy for my new company. The plan is Mac's all around to limit the IT noise and then virtual machines for those that have some need of Linux/Windows. The basic setup is OSX + MS Office for the Mac + VMWare. Note that despite recent benchmarks of Parallels vs VMWare Fusion I went with VMWare, I did this because like MS Office, they're the leading VM environment and I can download more pre-configured machines etc for that environment than any other. 

The developers need Linux to do their thing and I expected that. What I didn't expect was that some basic applications like the ones to run the Keyscan card key access to the office doors and the Nortel phone system are windows only apps. For those I spent the whopping $300 on Vista Business, installed it in a Windows VM and then installed the apps in there. Generally these infrastructure apps don't need to be running all the time so that makes it even easier. Still, not having web based management or cross-platform apps in this age just shows you how far Apple has to go.

Over the next few posts i'll be talking about my experience in setting up an OSX based office environment and in the process you'll see how little I know about basic IT concepts :)