<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" version="2.0">
<channel>
	<title>Comments for Mac Admin Corner</title>
	
	<link>http://blog.macadmincorner.com</link>
	<description>General IT and Mac administration ramblings</description>
	<lastBuildDate>Wed, 10 Mar 2010 15:52:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/MacAdminCorner_Comments" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="macadmincorner_comments" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Comment on Leopard Active Directory Integration Headaches by Jared</title>
		<link>http://blog.macadmincorner.com/leopard-ad-integration-headaches/comment-page-1/#comment-406</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Wed, 10 Mar 2010 15:52:59 +0000</pubDate>
		<guid isPermaLink="false">http://170.140.189.180/blog/?p=51#comment-406</guid>
		<description>@Patrick - I have several macs bound to the domain, but after working for some time (successfully authenticating to the domain) - they stop authenticating when connected to the network.  AD account and password status are perfectly ok and verified, but when trying to authenticate with AD credentials and connected to the network, authentication fails.  If the user simply disconnects the network connection, they are able to authenticate successfully.  They are using a mobile account, and their password should be cached anyway, but something weird seems to be happening when the mac is contacting the domain controller.   Any ideas?  I was just wondering if you have come across this before.  This is happening on a couple of computers running 10.5.8 and 10.6.2.   Thanks for any suggestions!</description>
		<content:encoded><![CDATA[<p>@Patrick &#8211; I have several macs bound to the domain, but after working for some time (successfully authenticating to the domain) &#8211; they stop authenticating when connected to the network.  AD account and password status are perfectly ok and verified, but when trying to authenticate with AD credentials and connected to the network, authentication fails.  If the user simply disconnects the network connection, they are able to authenticate successfully.  They are using a mobile account, and their password should be cached anyway, but something weird seems to be happening when the mac is contacting the domain controller.   Any ideas?  I was just wondering if you have come across this before.  This is happening on a couple of computers running 10.5.8 and 10.6.2.   Thanks for any suggestions!</p>

<p><a href="http://feedads.g.doubleclick.net/~a/K384EQaVG6ONSrvJL3rr7fd41Ko/0/da"><img src="http://feedads.g.doubleclick.net/~a/K384EQaVG6ONSrvJL3rr7fd41Ko/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/K384EQaVG6ONSrvJL3rr7fd41Ko/1/da"><img src="http://feedads.g.doubleclick.net/~a/K384EQaVG6ONSrvJL3rr7fd41Ko/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Add user to admin group with Applescript by Lance Eichel</title>
		<link>http://blog.macadmincorner.com/add-user-to-admin-group-with-applescript/comment-page-1/#comment-405</link>
		<dc:creator>Lance Eichel</dc:creator>
		<pubDate>Sun, 07 Mar 2010 08:49:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.macadmincorner.com/?p=346#comment-405</guid>
		<description>This is a excellent way of seeing things, not that hard for you to learn. Thank you for finding time to share your your current thinking.</description>
		<content:encoded><![CDATA[<p>This is a excellent way of seeing things, not that hard for you to learn. Thank you for finding time to share your your current thinking.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/MMSmRoEeXBAYGBGGnmR73Pr6XC8/0/da"><img src="http://feedads.g.doubleclick.net/~a/MMSmRoEeXBAYGBGGnmR73Pr6XC8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/MMSmRoEeXBAYGBGGnmR73Pr6XC8/1/da"><img src="http://feedads.g.doubleclick.net/~a/MMSmRoEeXBAYGBGGnmR73Pr6XC8/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Allow Non-Admin users to Manage Printers by David Stewart</title>
		<link>http://blog.macadmincorner.com/allow-non-admin-users-to-manage-printers/comment-page-1/#comment-404</link>
		<dc:creator>David Stewart</dc:creator>
		<pubDate>Thu, 25 Feb 2010 20:36:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.macadmincorner.com/?p=266#comment-404</guid>
		<description>JD, what version of the OS did you apply this change to? 10.5.8 has the system.print.admin entry you refer to but 10.5.6 does not?</description>
		<content:encoded><![CDATA[<p>JD, what version of the OS did you apply this change to? 10.5.8 has the system.print.admin entry you refer to but 10.5.6 does not?</p>

<p><a href="http://feedads.g.doubleclick.net/~a/wPys-XHHQuuzqx__RE3rTlE2aak/0/da"><img src="http://feedads.g.doubleclick.net/~a/wPys-XHHQuuzqx__RE3rTlE2aak/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/wPys-XHHQuuzqx__RE3rTlE2aak/1/da"><img src="http://feedads.g.doubleclick.net/~a/wPys-XHHQuuzqx__RE3rTlE2aak/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Leopard Active Directory Integration Headaches by Patrick</title>
		<link>http://blog.macadmincorner.com/leopard-ad-integration-headaches/comment-page-1/#comment-403</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Thu, 25 Feb 2010 11:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://170.140.189.180/blog/?p=51#comment-403</guid>
		<description>@Jonathan - AD is where the user accounts are.</description>
		<content:encoded><![CDATA[<p>@Jonathan &#8211; AD is where the user accounts are.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/cAuNQCWc0HJOt-OCB8PZ6asTzHM/0/da"><img src="http://feedads.g.doubleclick.net/~a/cAuNQCWc0HJOt-OCB8PZ6asTzHM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/cAuNQCWc0HJOt-OCB8PZ6asTzHM/1/da"><img src="http://feedads.g.doubleclick.net/~a/cAuNQCWc0HJOt-OCB8PZ6asTzHM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Leopard Active Directory Integration Headaches by Jonathan Panza</title>
		<link>http://blog.macadmincorner.com/leopard-ad-integration-headaches/comment-page-1/#comment-402</link>
		<dc:creator>Jonathan Panza</dc:creator>
		<pubDate>Thu, 25 Feb 2010 03:22:16 +0000</pubDate>
		<guid isPermaLink="false">http://170.140.189.180/blog/?p=51#comment-402</guid>
		<description>I work at Yale university in the IT Dept.  We mostly don't even bother pushing the macs into AD.  Any reason why you went this way......typically mac users march to their own drummer.</description>
		<content:encoded><![CDATA[<p>I work at Yale university in the IT Dept.  We mostly don&#8217;t even bother pushing the macs into AD.  Any reason why you went this way&#8230;&#8230;typically mac users march to their own drummer.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/iSGSm_0qoBLv4g7S05SdM7UdvyM/0/da"><img src="http://feedads.g.doubleclick.net/~a/iSGSm_0qoBLv4g7S05SdM7UdvyM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/iSGSm_0qoBLv4g7S05SdM7UdvyM/1/da"><img src="http://feedads.g.doubleclick.net/~a/iSGSm_0qoBLv4g7S05SdM7UdvyM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ten blogs every Mac admin should know about by connectionfailure</title>
		<link>http://blog.macadmincorner.com/ten-blogs-every-mac-admin-should-know-about/comment-page-1/#comment-401</link>
		<dc:creator>connectionfailure</dc:creator>
		<pubDate>Mon, 22 Feb 2010 01:11:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.macadmincorner.com/ten-blogs-every-mac-admin-should-know-about/#comment-401</guid>
		<description>That's a great list. I hadn't heard of four of them, plus Jon's in the comment, so there's five new blogs to keep an eye on.
Not so fond of eWeek and ComputerWorld as they dont have any hands-on soutions. Mostly just a PC-eyed view of the Mac world. Lots of posts about what OSX *can't* do for example.
The other blogs have stuff about what it can do, or how to fix what's broke.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a great list. I hadn&#8217;t heard of four of them, plus Jon&#8217;s in the comment, so there&#8217;s five new blogs to keep an eye on.<br />
Not so fond of eWeek and ComputerWorld as they dont have any hands-on soutions. Mostly just a PC-eyed view of the Mac world. Lots of posts about what OSX *can&#8217;t* do for example.<br />
The other blogs have stuff about what it can do, or how to fix what&#8217;s broke.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/6Eo9LGAjp2zsDGR2pI_H9dmR1Co/0/da"><img src="http://feedads.g.doubleclick.net/~a/6Eo9LGAjp2zsDGR2pI_H9dmR1Co/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/6Eo9LGAjp2zsDGR2pI_H9dmR1Co/1/da"><img src="http://feedads.g.doubleclick.net/~a/6Eo9LGAjp2zsDGR2pI_H9dmR1Co/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Migrate Local User to Domain Account by rmmiles</title>
		<link>http://blog.macadmincorner.com/migrate-local-user-to-domain-account/comment-page-1/#comment-398</link>
		<dc:creator>rmmiles</dc:creator>
		<pubDate>Sat, 13 Feb 2010 00:35:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.macadmincorner.com/?p=352#comment-398</guid>
		<description>Very cool concept, just some thoughts from having run the script on a few system; you might want to add a failsafe on line 74, to confirm that the group getting deleted does not match the “admin” group name (or any other local group name), ie. if the local account’s short name is “admin”, thus causing the “admin” group to be deleted (which removes local admin access for all local and domain accounts). Also, once a local account is selected, shouldn’t the script wait to delete the local account until a domain user is entered (in case you want to close the script and not continue with the migration)? Thanks,</description>
		<content:encoded><![CDATA[<p>Very cool concept, just some thoughts from having run the script on a few system; you might want to add a failsafe on line 74, to confirm that the group getting deleted does not match the “admin” group name (or any other local group name), ie. if the local account’s short name is “admin”, thus causing the “admin” group to be deleted (which removes local admin access for all local and domain accounts). Also, once a local account is selected, shouldn’t the script wait to delete the local account until a domain user is entered (in case you want to close the script and not continue with the migration)? Thanks,</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Kd9viXw-aaVwyrYJbY7xjQELKDQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/Kd9viXw-aaVwyrYJbY7xjQELKDQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Kd9viXw-aaVwyrYJbY7xjQELKDQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/Kd9viXw-aaVwyrYJbY7xjQELKDQ/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Migrate Local User to Domain Account by Guy</title>
		<link>http://blog.macadmincorner.com/migrate-local-user-to-domain-account/comment-page-1/#comment-386</link>
		<dc:creator>Guy</dc:creator>
		<pubDate>Wed, 10 Feb 2010 16:20:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.macadmincorner.com/?p=352#comment-386</guid>
		<description>Will your script migrate user accounts from one domain to another? Just replaced an existing Exchange 2003 server with an Exchange 2010 solution, but the domain and DNS servers are different...

This was the solution we found for migrating each account in Windows: 

http://my.galagzee.com/2007/08/05/transparent-windows-workstation-domain-migration/

It would be nice if Snow Leopard had an easy solution for this as well...</description>
		<content:encoded><![CDATA[<p>Will your script migrate user accounts from one domain to another? Just replaced an existing Exchange 2003 server with an Exchange 2010 solution, but the domain and DNS servers are different&#8230;</p>
<p>This was the solution we found for migrating each account in Windows: </p>
<p><a href="http://my.galagzee.com/2007/08/05/transparent-windows-workstation-domain-migration/" rel="nofollow">http://my.galagzee.com/2007/08/05/transparent-windows-workstation-domain-migration/</a></p>
<p>It would be nice if Snow Leopard had an easy solution for this as well&#8230;</p>

<p><a href="http://feedads.g.doubleclick.net/~a/Zx4pT3yR522E0YqX-XJBTmxcGr0/0/da"><img src="http://feedads.g.doubleclick.net/~a/Zx4pT3yR522E0YqX-XJBTmxcGr0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Zx4pT3yR522E0YqX-XJBTmxcGr0/1/da"><img src="http://feedads.g.doubleclick.net/~a/Zx4pT3yR522E0YqX-XJBTmxcGr0/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ten blogs every Mac admin should know about by Jon Brown</title>
		<link>http://blog.macadmincorner.com/ten-blogs-every-mac-admin-should-know-about/comment-page-1/#comment-378</link>
		<dc:creator>Jon Brown</dc:creator>
		<pubDate>Wed, 27 Jan 2010 23:29:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.macadmincorner.com/ten-blogs-every-mac-admin-should-know-about/#comment-378</guid>
		<description>I love your blog, and I reference it almost weekly. I am a new Mac Systems Admin and have found this blog and many of those on your site to offer a wealth of information. Thanks so much! I have also started a Mac Sys Admin blog over at http://www.jonsblog.org.</description>
		<content:encoded><![CDATA[<p>I love your blog, and I reference it almost weekly. I am a new Mac Systems Admin and have found this blog and many of those on your site to offer a wealth of information. Thanks so much! I have also started a Mac Sys Admin blog over at <a href="http://www.jonsblog.org" rel="nofollow">http://www.jonsblog.org</a>.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/y4Wo6GFUlQIelI5gf_eEMyTtSac/0/da"><img src="http://feedads.g.doubleclick.net/~a/y4Wo6GFUlQIelI5gf_eEMyTtSac/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/y4Wo6GFUlQIelI5gf_eEMyTtSac/1/da"><img src="http://feedads.g.doubleclick.net/~a/y4Wo6GFUlQIelI5gf_eEMyTtSac/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
	<item>
		<title>Comment on Convert Local Account’s Home to AD account with Local Home by Patrick</title>
		<link>http://blog.macadmincorner.com/convert-local-accounts-home-to-ad-account-with-local-home/comment-page-1/#comment-377</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Wed, 27 Jan 2010 17:58:51 +0000</pubDate>
		<guid isPermaLink="false">http://170.140.189.180/blog/?p=39#comment-377</guid>
		<description>@William

No, this script would have to be re-written for Leopard or SL. Use this one instead for Tiger/Leo/SL: 
http://blog.macadmincorner.com/migrate-local-user-to-domain-account/</description>
		<content:encoded><![CDATA[<p>@William</p>
<p>No, this script would have to be re-written for Leopard or SL. Use this one instead for Tiger/Leo/SL:<br />
<a href="http://blog.macadmincorner.com/migrate-local-user-to-domain-account/" rel="nofollow">http://blog.macadmincorner.com/migrate-local-user-to-domain-account/</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/zfoO4VT9_nrPDmIHpu2qucYGvcE/0/da"><img src="http://feedads.g.doubleclick.net/~a/zfoO4VT9_nrPDmIHpu2qucYGvcE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/zfoO4VT9_nrPDmIHpu2qucYGvcE/1/da"><img src="http://feedads.g.doubleclick.net/~a/zfoO4VT9_nrPDmIHpu2qucYGvcE/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
	</item>
</channel>
</rss>
