After 10 years of Mac OS X server DNS GUI wrapper still breaking configs

WHY?
Against my better judgment I used the Server Admin's DNS tool to add a zone. Next thing I know it's going and added random data from the new zone to most if not all my zone records. It's changed the SOA for all my zones to some random concatenation of the new zone's data, it's concatenated A records to NS records. I had to go in and manually repair ALL of my records.
What's so hard about creating a functional BIND wrapper?
Lesson Learned - SAVE YOURSELF HOURS OF UNNECESSARY FRUSTRATION, NEVER USE SERVER ADMIN'S DNS TOOL, NOT EVEN TO DO SOMETHING SIMPLE LIKE ADD A NEW ZONE RECORD.
**** I wouldn't use it at all if Apple hadn't removed the means to turn the **** server on and off from the command line.

Sure there are a world full of solutions out there but I've already invested time, money, and a knowledge of how things work on OS X. Seems kind of silly for you to say that I should throw the baby out with the bath water and just find the "solution that works". I have no problems with any other service I'm running, with Apache and Postfix running smoothly, since they have the first time they were configured back in 2002.
BIND on Mac OS X server works just fine when the Apple specific components and changes aren't thrown into the mix. I've been running it this way since OS X Server was released (**** I even ran BIND on "Client" for a while without any issues back before server was available) and I've mostly enjoyed 100% uptime despite those times when I was naive to think "Apple must have fixed ServerAdmin DNS. Let me just make one minor change using the GUI tool."
Is it too much for me to ask that if they can't make the tool work right then, for the love of the great and holy Admin, don't mess with it at all? Seriously if it isn't broken don't fix it. I'll happily manually config from the command line, lovingly reseting my serial numbers for each edit, the one time every couple of year that I might need to do so. Instead of releasing a tool thats only going to break your configs, don't continue to tease us with ease of use GUI apps.

Similar Messages

  • As iMac user upgraded to Mountain Lion and lost all Legacy connection with years of Apple/Mac data storage. How can recovery since every default says "no longer supported, After years of Mac software use now it is not accessible ??????

    As iMac user upgraded to Mountain Lion lost all Legacy connection with years of Apple/Mac data storage. How can recovery since every default says "no longer supported, After years of Mac software use now it is not accessible ??????

    Please provide more details. What version OS X were you using?
    Are you saying that Mail faIled to upgrade and you lost your old mail?
    Are you asking about PowerPC applications that require Rosetta to run like AppleWorks and Microsoft Office 2004?

  • VPN Settings Gone After Update to Mac OS X Server 10.5.4

    For the second time, a point upgrade of Mac OS X Server 10.5.x Leopard has resulted in all VPN settings being wiped out and the service being shut off. Has anyone else had this experience, and if so, does anyone know if there is a known cause (which might be avoided)?

    Please open terminal and post the output of postconf -n
    Also, it would be useful to see log extracts from /var/log/mail.log and /var/log/mailaccess.log showing rejected mails.

  • Photoshop CS6 can't save to server after upgrading to Mac OS Yosemite Server from Mac Lion Server

    We recently upgraded our server from a Mac Pro 2008 with OS X Lion Server to a Mac Mini 2014 with LaCie 20TB 5Big Thunderbolt 2 RAID drive. Everything is working fine with the exception of Photoshop. It does it intermittently but once it happens it will continue to do so. We get message like "Can't save to disk because of disk error" and "Can't save file because of program error" . Sometime we are able to do a "save as" and save over it. Most of the time we have to "save as" with a different file name and then rename and recopy the file. We have check permission on all the file as well as the server HD has ignore ownership checked. Again only three things changed. 1) Sever hardware change from Mac Pro to Mac Mini. 2) Server software upgraded from 10.7 Lion to 10.10 Yosemite(both have the latest update). 3) Drive when from internal on Mac Pro to External Thunderbolt 2 LaCie drive. We have no problem with Illustrator or Indesign. Only Photoshop. Anyone with any suggestion is greatly appreciated.

    Unfortunately you seem to be using Photoshop in a way that Adobe discourages, so you may not be getting a lot of helpful advice.
    Networks, removable media | Photoshop | CS4 and later

  • After years of owning all things Mac, I am finally trying to use iChat, and can't get it to work. I see my buddy, but all I can do is send a message--the video and audio chat icons are gray, as is inviting to a video chat under Buddies.

    After years of owning all things Mac, I am finally trying to use iChat, and can't get it to work. I am using gmail, and I see my buddy (no camera icon next to her name), but all I can do is send a message--the video and audio chat icons are gray, as is inviting to a video chat under Buddies. My buddy has the same problem as I.  We are able to do video chat through gmail, but I had hoped to use iChat.  I am using OS 10.6.8, iChat v. 5.0.3.  What am I missing?

    HI,
    iChat will Video chat to another iChat in a Jabber Buddy List (Google run a Jabber server for GoogleTalk)
    However it will not Video to the Web Page login to iGoogle or the Web Mail Page login.  (where people can Google Chat as it were in a  Web Browser).
    Nor does it video to the Google Talk Stand alone app for PCs or any other Jabber apps on any platform.
    iChat uses a connection Process called SIP (Session Initiation Protocol) which is also used by other VoIP devices.
    Jabber/XMPP invited the Jingle Protocol for Jabber Applications.
    Google have included this in their Standalone app and the Plug-in for Web Browsers on both PCs and Mac (you can get this as a Standalone Plug-in or as part of Chrome)
    More on this here  This article has been changed several time in the recent months.  It now claims a greater involvement by Google in writing the Jingle Library (Although now Google's version does not work with the others)
    This tends to mean that using the web Login to Google to Chat also cannot video chat to other Jabber apps that are using Jingle.
    If your Buddy is using iChat then check the Video Menu has two items to Enable Camera/Video chat and Microphone/Audio chats are ticked.
    In the View Menu the Show Status Items should be ticked (Selecting them toggles the tick and the function On or Off)
    It could be Internet speed but at this stage I would doubt this at this stage.
    10:27 PM      Saturday; January 21, 2012
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"
      iMac 2.5Ghz 5i 2011 (Lion 10.7.2)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb (Snow Leopard 10.6.8)
     Mac OS X (10.6.8),
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • Moving DNS to Mac OS X Server

    I've been using QuickDNS on Mac OS 9 for years but am now moving to OS X Server. The administration is very different and I find the documentation from Apple not very clear. (Guess they don't know how to to a screen shot to show examples.) Can someone give me a quick, clear run down on how i can get my existing domains set up in OS X Server?
    1.6GHz PM G5 - 250GB, 1GB, ATI9600.   Mac OS X (10.4.6)  

    The easiest way to move your zone files to the Mac is to setup the Mac as a secondard DNS server and have it pull the zone files from the master QuickDNS server.
    I'm guessing from your post that you want to use the Mac as the main server moving forwards. In that case if you're used to QuickDNS I would recommend upgrading to the latest version and using that to manage your domains.
    Apple's GUI for managing DNS pales in comparison to QuickDNS.
    If you can do without the GUI and configure DNS manually you should be OK, but if you're looking for a GUI option you'll be disappointed with Server Admin.

  • Can't login to Mac OS X server website after password reset

    Hi,
    I set up Mac OS X server for our small company and tried resetting the password of my network account that is managed via profile manager.
    So, under Accounts->User->MYUSERNAME->reset Password, I typed in a new one and hit ok.
    Now I can't login to the server website anymore (for editing our wiki or using profile manager etc.), neither with the new one nor with the old one.
    I already tried different passwords (resetting it again and again), I looked at the password directive, I checked my user name, tried to login from different computers and tried logging in with another account (which worked quite fine, so it's just my account). Finally I searched the internet for a solution for quite some time but didn't find anything similar.
    It would be great, if somebody could offer some advice.
    Best regards.
    Lasse

    Solved it by deleting the user and creating a new one with the same userID.
    Maybe it occured because I marked the "user has to change password after first login" box when resetting the password but didn't yet allow him to do so in the webpages menu?!?

  • I have had 4 mac computers and after years of downloading songs from itunes, I keep recieving a message that I need to set up an account.  when I try to make a new account, i get an error that says i already have an account.  please help!

    I have had 4 mac computers and after years of downloading songs from itunes, I keep recieving a message that I need to set up an account.  when I try to make a new account, i get an error that says i already have an account.

    Have you tried checking the Store drop-down menu in the iTunes interface to see if you are signed in the existing account?

  • Firefox after 30 seconds lands me at Mac OS X Server

    Logging into a Vessel Management Site (paid) it normally loads in 5sec, after last FF update it will not load after 30 seconds and takes me to Mac OS X Server.

    If you have this model of G4 1.67 Powerbook:
    http://www.everymac.com/systems/apple/powerbookg4/stats/powerbook_g4_1.67_15hr.html
    Then 10.4.0 Server won't install. There will be drivers missing.
    If your supplied restore disks are bad, then you need to get those replaced.
    Simply don't use the Mighty Mouse during the install, there's no need.
    When installing a stock 10.4 server overtop a system that comes with a newer OS, even if it's just 10.4.1, Apple has a very specific set of procedures you must follow
    http://docs.info.apple.com/article.html?artnum=302960
    The target-mode hint won't work for installing Mac OS X client (vs. Server) because your powerbook is a G4 and the Mini is Intel-based.
    And there is no Universal Mac OS X client installer yet.
    If your Server install is the 10.4.7 Universal Binary version, then it should be new enough to install onto your Powerbook, although it is not supported hardware. In which case you might be able to use the Target-mode tip suggested. It may or may not work.
    Probably the only legal way for you to do this is to uninstall OS X Server from your mini first. You'll have to check with Apple on that one.
    At the very least, if you are only using it on one machine then in spirit if not in letter, you might be fine.

  • Not clear about dns service for new Mac 10.4 server

    Due to low budget, I am given the task to convert a powermac g4 into a Mac 10.4 server. I have already installed it as a stand alone master but will promote it to directory master as soon as I configure proper dns setup.
    Now my westell router shows that the dns is 192.168.1.1 and the domain name as myhomwestell.com, does that mean my zone name has to be westell.com? Can having both dns service conflict with each other or is it fine?

    http://discussions.apple.com/message.jspa?messageID=5409254#5409254
    lookup my posts on DNS setup to help you about. Please mention if you want to go full a Fully Qualified Domain Name Setup or just a local setup . Do you dispose of a fixed public IP address as well ?

  • Can't send mail using webmail on Mac OS X Server 10.4

    Could someone help me figure out why I can't send email via webmail on Mac Mac OS X Server 10.4. I tried in and out of my LAN but it will not work. I am pretty sure that it's no firewall issue because it won't even work inside the LAN. Another thing I have considered is DNS issues. But my SMTP and POP3 works fine. Don't they use same DNS mail exchange record. Or should I ask my ISP to create a new record for webmail?

    Hi,
    Thanks once again for your help. The log details is shown below;
    Nov 6 14:27:07 mail postfix/smtpd[336]: connect from localhost[127.0.0.1]
    Nov 6 14:27:07 mail postfix/smtpd[336]: warning: Illegal address syntax from localhost[127.0.0.1] in MAIL command: [email protected]
    Nov 6 14:27:07 mail postfix/smtpd[336]: lost connection after MAIL from localhost[127.0.0.1]
    Nov 6 14:27:07 mail postfix/smtpd[336]: disconnect from localhost[127.0.0.1]

  • Can't connect to Mac Mini (ML Server)

    I have a Mid-2009 Mac mini that's running the latest Mac OS X 10.8 Server. It's connected to my TV via HDMI.
    For a long time, I had no issues connecting to it via Screen Sharing, SSH or AFP but recently all three will mysteriously fail. I know the machine is working because I stream iTunes content to my Apple TV and it's hosting a couple of web sites that it serves up just fine. The only attached peripheral is a Drobo S (2nd Gen) attached via FW 800. Drobo Dashboard and the firmware are completely up-to-date.
    When it stops working, I have no alternative but to A) wait until I get home and B) force the machine off and reboot it. After a reboot, Screen Sharing, AFP and SSH all work fine for a while. It seems to conveniently fail when I'm away and need to get to it.
    Note that it fails on all three protocols from outside AND inside. So this isn't a network routing or port forwarding issue. I'm a Mac IT professional with 15 years under my belt, so I think I know what I'm doing in that regard. Like I said it's worked fine for years and it's only been lately that these failures have been happening.
    I can't seem to identify any rhyme or reason for this. It's a fairly clean installation with almost no 3rd party software installed on it.
    Any help or suggestions would be greatly appreciated.

    "Screen Sharing is currently being controlled by the Remote Management Service"
    I've been fidgeting between the Server.app server Settings tab and the Screen Sharing checkbox in System Preferences Sharing pane all day.
    I had tried "Share Screen" via Finder. After I tried "Share Screen" via Server.app from my client computer I noticed the above warning message when Screen Sharing in the server's System Preference Sharing pane was highlighted. I'm not sure which is cause or effect.
    Everything is checked on the server "Settings" tab in Server.app on the server. Only "FIle Sharing," "Remote Login" and "Remote Management" are checked on the Sharing pane in System Preferences on the server.
    Everything is checked on the server "Settings" tab in Server.app on the client. In this case, "Allow remote administration using Server" is checked and grayed out. "Screen Sharing" is checked on the Sharing pane in System Preferences on the client. (It may not have anything to do with a successful screen share connection, but it is on.)
    Everything is now working better than expected. Thanks to you both for your help!

  • Strange behaviour of OS X Server DNS with IPv6 reverse zones

    I am running a full IPv4 / IPv6 dual stack setup across several machiens including a server (OS X 10.9.1 / OS X Server 3.0.2). I also have IPv6 Internet access via TunnelBroker and have a /64 prefix assigned to me. All my systems have valid and correct IPv6 addresses (not temporary ones) from the range denoted by that prefix.
    I have setup IPv4 and IPv6 addresses for all my systems in OS X Server DNS and that works fine. However, when I add an IPv6 address for a system, the DNS server (or maybe the server GUI) insists on creating a reverse zone for the /127 version of the address. This means I pretty much have a separate reverse zone for every system, which seems crazy to me. it is especially annoying as I have another DNS server where all my zones are defined as slave zoes (for availability reasons) and thsi makes the process of addign a new IPv6 host somewhat tedious. I tried pre-creating a properly named reverse zone for the /64 prefix but the DNS server would not use that and still persists in creating these strange zones.
    Here is a (fictitous example)...
    My /64 prefix is 2001:fd0:f19:2ab::/64
    I have a system with an address of 2001:fd0:f19:2ab:7e6d:62ff:fe8a:a84c
    I add this to OS X Server DNS and it created the reverse DNS zone:
    4.8.a.a.8.e.f.f.f.2.6.d.6.e.7.b.a.2.0.9.1.f.0.0.d.f.0.1.0.0.2.ip6.arpa
    whereas I would expect it to instead add it to the zone
    b.a.2.0.9.1.f.0.0.d.f.0.1.0.0.2.ip6.arpa
    if that zone already exists.
    Has anyone else noticed this? Or do you have it working as one might expect?

    Chris..
    I, too, have the same problem.  I take issue with much of the OS X "Server" after it has been so completely dummed down that it is virtually useless for anyone that would actually like to utilize it as an actual, as the name implies, "SERVER."  I won't get into all of the details of everything that drives me crazy with Apple's decisions here but, suffice it to say, I am EXTREMELY DISAPPOINTED with Apple more than ever.  They should, at a minimum, offer a full-fledged server like they used to have, for an additional price, for people that need more than a nice looking interface and a worthless box.
    That being said, the DNS server, like the rest of the OS X Mavericks Server, is dummed down to the point of allowing very little customization.  Short of using the command line, which I have decided to do (I scrapped the OS X server all together, and just set up BIND, openLDAP, DHCP, Quagga, etc. from the CLI just like I do with all of my Linux servers), there is not much you can do to get the correct prefixes to show up in IPv6 reverse zones.  The reason is that when you enter the forward record, the interface does not give an option to enter the prefix.  So, it seems that for EACH AND EVERY v6 entry (AAAA record) you have (or at least every 10 entries), you will get a separate reverse zone.
    To be completely honest, I don't even know why they included IPv6 zones in this implementation because it is totally out of compliance with the RFCs and, obviously, will not provide proper and correct reverse lookups.  How could it? As you pointed out above, with a /64 prefix, you're getting a 31 digit long reverse zone (which, btw, is a /124)...***???  I've never heard of such a thing.  There should be 16 digits in a /64, 12 in a /48, 8 in /32 and so on.
    I don't think it is anything to do with your using a tunnel broker -- all of our systems are native IPv6 and all reverse queries to the Mac Server fail. 
    I can tell you how to use the CLI to manually enter the zones with the serveradmin tool, if you like, but my advice is to just move to a full fledged BIND implementation .... and, if you want some type of interface other than the console, use something like Webmin which has a GREAT DNS zone interface...and it also keeps up with the RFC compliance.
    Just message me back if you'd like the shell commands.  I hate to say this, it literally pains me, but I administer a ton of servers (physical and virtualized)... roughly 1000 +- to be exact...and WINDOWS Server has a DNS server that is so much further ahead and ADVANCED than Mac, it is disgusting.  In fact, we are running 12 Win Server 2012R2 Active Directory Domain Servers, each running synchronized DNS records and even with over 250,000 DNS records, it works like a champ.  Still, our primary and fail-safe DNS servers are all BIND v9.  Like I said, it is awful to say that about Mac, but dude, they need to wake up and either get back to the real-deal systems or just get out of the advanced product arena all together.  (one exception...my new MacPRO is AWESOME and the most advanced piece of computing equipment money can buy for the price...so kudos there)
    Sorry about the rant, but when i read your post, I was reminded how frustrated I am at all of this nonsense.
    Take care...and good luck.

  • Mac OS X Server 10.5.8 firewall question

    Hello,
    I'm a network administrator in a company, and we use Mac OS X server 10.5.8, with Mac clients.
    I have a problem with the adaptative firewall : when someone wants to connect to the server (by using the finder, and "connect as"), if the password is not correct, the adaptative firewall just cut the access of the client for all (It's a DHCP and DNS server, so there is no access anymore to the LAN and the web).
    I would like to know if there is a way to make the client blacklisted after 3 bad login attempts, not just only one. I used the afctl command, but it's apparently not possible to manage this problem with that (just the time of blacklisting).
    Thanks a lot in advance.

    I don't have a solution for you. But I do remember reading about this one. Apparently what happens is that beneath the surface, the connection attempt is repeated on failure, using differnet authentication protocols. And so one user login attempt with a bad password, leads to three attempts beneath the surface, and "the boot". But unfortunately I don't remember what the solution is, as I was researching for a completely different issue when I read this.

  • Windows PC (XP) and Mac OS X Server 10.6 print service

    Can someone tell me if it is possible for a Windows PC running XP to make use of the Mac OS X Server 10.6 print service? Following the manual does not help. After enabling SMB I don't manage to connect to one of the shared printers. How could I make use of IPP and LPR support being built into Windows XP?

    I know the problems with Time Machine on Mac OS server. In your case: Look at the log files, searching for "backupd", if that tells you anything.
    In my case, Time Machine in the last year stopped several times. Occasionally, there was a helpful message in the log files where I could identify a file where it had hung -- typically intermediate build results of Xcode. After excluding or deleting the offending files (where possible), Time Machine ran successfully.
    Another situation which has repeatedly occurred is that time machine just hangs and does not progress, and no log entry helps. In 3 such cases what helped was to delete the spotlight index (e.g., with TinkerTool System) and let it rebuild. It took inordinately long (10 hrs) and there were log entries by mdworker that it had difficulty processing files. But when the spotlight index was finally rebuilt, Time Machine worked again.
    BTW: I don't need Time Machine to backup the server system, for that I run mirrors etc., but for user files it is most convenient and has helped several times. Thus I have excluded nearly everything but /User/*.

Maybe you are looking for